This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryFixes a potential database injection vulnerability by addressing unsafe queries.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Defaults compaction engine to DuckDB and adds catalog rebuild command. Defaults compaction engine to DuckDB and adds catalog rebuild command. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Dependency | Low |
Bump github.com/apache/thrift dependency from 0.22.0 to 0.23.0 in /src. Bump github.com/apache/thrift dependency from 0.22.0 to 0.23.0 in /src. Source: llm_adapter@2026-06-15 Confidence: high |
— |
| Bugfix | Medium |
Fixes potential code scanning alert indicating database query built from user‑controlled sources. Fixes potential code scanning alert indicating database query built from user‑controlled sources. Source: llm_adapter@2026-06-15 Confidence: low |
— |
Full changelog
What's Changed
- chore(deps): bump github.com/apache/thrift from 0.22.0 to 0.23.0 in /src in the go_modules group across 1 directory by @dependabot[bot] in https://github.com/sipcapture/homer/pull/805
- Potential fix for code scanning alert no. 40: Database query built from user-controlled sources by @adubovikov in https://github.com/sipcapture/homer/pull/806
- fix(compaction): default to duckdb engine + add catalog rebuild command by @adubovikov in https://github.com/sipcapture/homer/pull/808
Full Changelog: https://github.com/sipcapture/homer/compare/11.0.256...11.0.258
Security Fixes
- Potential fix for code scanning alert no. 40: Database query built from user‑controlled sources (mitigates injection risk)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Earlier breaking changes
- v11.0.222 The API endpoint /api/v1/config has been removed.
Beta — feedback welcome: [email protected]