Skip to content

SkySend

v2.7.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

Published 2mo File Storage & Sync
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Topics

aes-256-gcm docker encryption end-to-end-encryption file-sharing privacy
+5 more
react s3-storage self-hosted typescript zero-knowledge

Affected surfaces

deps

Summary

AI summary

Updates 🐳 Docker, ✨ Features, and 🔒 Security across a mixed release.

Full changelog

Native OS Share Button, Security Patches, and Dependency Updates

✨ Features

  • web: Added a native OS Share button to the upload success screen. Uses the Web Share API (navigator.share()) and is only shown on devices that support it (iOS Safari, Android Chrome). The Copy button remains unchanged as fallback.

🔒 Security

  • server: Updated hono from 4.12.15 to 4.12.18 to patch two moderate vulnerabilities - bodyLimit() bypass for chunked requests (GHSA-9vqf-7f2p-gf9v) and unvalidated JSX tag names allowing HTML injection (GHSA-69xw-7hcm-h432).

🎨 Improvements

  • infra: Updated all dependencies to their latest compatible versions (react 19.2.6, zod 4.4.3, react-router-dom 7.15.0, vite 8.0.11, @aws-sdk/* 3.1045.0, eslint 10.3.0, dompurify 3.4.2, and others).

🐳 Docker

  • Image: skyfay/skysend:v2.7.0
  • Also tagged as: latest, v2
  • Platforms: linux/amd64, linux/arm64

Security Fixes

  • dep: GHSA-9vqf-7f2p-gf9v – Hono `bodyLimit()` bypass for chunked requests
  • dep: GHSA-69xw-7hcm-h432 – Hono unvalidated JSX tag names allowing HTML injection

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track SkySend

Get notified when new releases ship.

Sign up free

About SkySend

Encrypted file and note sharing

All releases →

Related context

Beta — feedback welcome: [email protected]