This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryDashboard skips NextAuth initialization unless AUTH_REQUIRED=true.
Full changelog
Patch release for the open-source dashboard auth boundary.
Highlights:
- Dashboard no longer initializes NextAuth unless
AUTH_REQUIRED=true. - Local OSS mode returns
auth_disabledfor/api/auth/sessioninstead of surfacing server configuration errors. - Billing page no longer auto-fetches account-only billing state or displays sign-in prompts when auth is disabled.
- Public README baseline remains current at
v3.6.2+/ v3.6 runtime stack language from the prior docs fix.
Validated locally before release:
- TypeScript, dashboard tests, production build.
- Runtime
/api/auth/sessionsmoke returns404 {"ok":false,"error":"auth_disabled","authRequired":false}. - Playwright
/billingsmoke renders with no/api/authrequests, no console errors, and no sign-in/create-account UI.
Breaking Changes
- Dashboard no longer initializes NextAuth unless `AUTH_REQUIRED=true`.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About sheawinkler/ContextLattice
Private-by-default memory and context layer for agents with Go/Rust runtime, staged retrieval across fused data backends, and long-horizon context continuity.
Related context
Related tools
Beta — feedback welcome: [email protected]