This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
Affected surfaces
ReleasePort's take
Moderate signalPatch over 40 curl vulnerabilities in the build workflow and align reverse share size limits with settings.
Why it matters: Patching resolves >40 high‑severity curl flaws affecting package builds; alignment fixes UI mismatch for share size limits.
Summary
AI summaryPatch over 40 curl vulnerabilities and align reverse share size limits with settings.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Patches 40+ curl vulnerabilities in the build workflow Patches 40+ curl vulnerabilities in the build workflow Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Correctly detect disk usage on mounted Linux filesystems Correctly detect disk usage on mounted Linux filesystems Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Align max share size modal with user/global settings Align max share size modal with user/global settings Source: llm_adapter@2026-07-17 Confidence: high |
— |
Full changelog
What's Changed
- fix(system): correctly detect disk usage on mounted filesystems (linux) by @patrickpilotti in https://github.com/smp46/pingvin-share-x/pull/126
- fix(reverseShares): align max share size in modal with user/global settings by @AlekseyLapunov in https://github.com/smp46/pingvin-share-x/pull/136
- chore(translations): update translations via Crowdin in https://github.com/smp46/pingvin-share-x/pull/117
This release will patch many (40+) related curl vulnerabilities left as a result of aggressive caching, changes to the build workflow mean from now on it will always fetch the most up-to-date packages for the final image. As well as patching all non NextJS 14 Vulnerabilities (majority of which are irrelevant to this project). 🎉
New Contributors
- @patrickpilotti made their first contribution in https://github.com/smp46/pingvin-share-x/pull/126
- @AlekseyLapunov made their first contribution in https://github.com/smp46/pingvin-share-x/pull/136
Full Changelog: https://github.com/smp46/pingvin-share-x/compare/v1.21.0...v1.21.1
Security Fixes
- Patch >40 curl vulnerabilities caused by aggressive caching; ensure latest secure curl version is used in the build
- Address all non NextJS 14 vulnerabilities applicable to this project
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]