This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
AI Agents & Assistants
✓ No known CVEs patched
This release patches 1 known CVE
Topics
ai
ai-agent
anthropic
ats
automation
beginner-friendly
+11 more
career
careerops
claude
claude-code
cli
go
interview-prep
job-application
job-hunting
job-search
resume
Affected surfaces
rce_ssrf
Summary
AI summaryUpdates Bug Fixes, 1.12.0, and 2026-06-18 across a mixed release.
Full changelog
1.12.0 (2026-06-18)
Features
- batch: add --status and --watch progress monitoring to batch-runner.sh (#922) (#966) (802552f)
- cli: add Antigravity CLI compatibility (61de18d)
- i18n: add Chinese language modes for China-market job seekers (#934) (#965) (207f960)
- pdf: render Japanese CVs with a lang="ja" CJK font fallback (#1053) (d0d57d1)
- providers: add Jobstreet and Glints providers for the Indonesian market (728d547), closes #1085
- providers: add RemoteOK, Remotive, Working Nomads, IBM board providers (349bacc), closes #1075
- providers: port Arbeitsagentur to an in-process provider (#1095) (504a2f0)
- scan: add content/description filter for providers (#974) (21d6c86)
Bug Fixes
- ashby: include secondaryLocations so EU-eligible roles surface (a84d3f5), closes #1073
- batch: reconcile pipeline.md inbox after batch runs (#712) (34c3d0e)
- dashboard: archetype regex matches English and Spanish reports (#977) (d619d3b)
- dashboard: open Windows targets without shell (#987) (6dc36fb)
- dashboard: report last-contact in calendar days, not hours-since-midnight (#1057) (4e05cfd)
- followup: resolve report path relative to tracker directory (752f3b9), closes #1070
- followup: use the real application date from notes, not the eval date (#1096) (#1097) (53785c8)
- gemini: validate evaluation report shape (#819) (a0aa264)
- latex: language-agnostic section validation + CJK guard (#1054) (b147504)
- merge-tracker: require company match for number-based dedup (2bb514f), closes #912
- pdf: auto-install Playwright chromium after update (eb504ad)
- pdf: use ATS-safe system fonts for clean CV text extraction (17033e8), closes #1074
- pipeline: add batch liveness sweep for unconfirmed entries (#750) (#973) (e9eba87)
- scan: sanitize external metadata before writes (#1098) (61bad36)
- security: harden local-parser against command/arg injection and scan-ats against SSRF (721f1a8)
- tracker: preserve notes column when rewriting rows without a trailing pipe (#1004) (0569518)
- update: materialize skill entrypoints without symlinks (#1067) (3ef63c8)
- updater: git-safety on abort + preserve user files on safety-violation rollback (#915) (#1099) (deef636)
Security Fixes
- Hardened local-parser against command/arg injection and scan-ats against SSRF
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About career-ops
AI-powered job search system built on Claude Code. 14 skill modes, Go dashboard, PDF generation, batch processing.
Related context
Related tools
Beta — feedback welcome: [email protected]