This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+6 more
Affected surfaces
Summary
AI summaryUpdates Bug Fixes, 25.0.8, and 2026-07-18 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
Mask sensitive environment variables in logs and outputs. Mask sensitive environment variables in logs and outputs. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Handle potential null values when trimming commit messages and git tags. Handle potential null values when trimming commit messages and git tags. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Medium |
Prevent template evaluation syntax in branch expansion and tag formatting. Prevent template evaluation syntax in branch expansion and tag formatting. Source: llm_adapter@2026-07-18 Confidence: high |
— |
| Bugfix | Low |
Mask sensitive environment variables such as keys, auth tokens, and webhook URLs. Mask sensitive environment variables such as keys, auth tokens, and webhook URLs. Source: granite4.1:30b@2026-07-18-audit Confidence: low |
— |
Full changelog
25.0.8 (2026-07-18)
Bug Fixes
- handle potential null values in commit message and gitTags trimming (0a60004)
- hide-sensitive: mask key/auth/webhook env vars (973d763)
- mask sensitive environment variables and improve commit handling (#4252) (1bfdc52)
- prevent template evaluation syntax in branch expansion and tag formatting (f121540)
Security Fixes
- **hide-sensitive:** mask key/auth/webhook env vars
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About semantic-release
package::rocket: Fully automated version management and package publishing
Related context
Related tools
Beta — feedback welcome: [email protected]