Skip to content

spupuz/VibeNVR

v1.28.2 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 29d Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ffmpeg lightweight local-storage nvr opensource privacy
+1 more
video-surveillance

Summary

AI summary

Implemented automatic enforcement of restrictive storage quotas, added a 1‑hour expiration limit on configuration fallbacks, and overhauled UI state propagation for accurate AI engine visibility.

Full changelog

Full Changelog: https://github.com/spupuz/VibeNVR/compare/v1.28.1...v1.28.2

🚀 Release v1.28.2

📝 Summary

This patch release brings critical stability enhancements to the VibeNVR system configuration and storage management architectures. By resolving state synchronization issues between the database, the global AI engine, and the frontend interface, VibeNVR now delivers a flawlessly coherent user experience. Furthermore, we've fortified the core with a zero-trace fallback protection system, completely eliminating the risk of accidental time-travel regressions during automated testing or unexpected system failures.

🛠️ Key Improvements

  • 🚀 Storage Management: Implemented an advanced Reactive "Effective Limit" logic that automatically enforces the most restrictive parameter between camera-level quotas and global system caps, dramatically improving space utilization and cleanup accuracy.
  • 🛡️ Zero-Trace Security: Engineered a bulletproof 1-hour expiration limit on automated configuration fallbacks, shielding the core database from accidental regressions and stale state restorations.
  • 🎨 UI State Cohesion: Overhauled the frontend parameter parsing to ensure the Global AI engine state seamlessly propagates to individual camera configurations, preventing false-negative "Disabled" warnings and maintaining crystal-clear visual feedback.

Security Fixes

  • Added 1‑hour automatic expiry for configuration fallbacks, eliminating risk of stale state restorations and zero‑trace regression attacks

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track spupuz/VibeNVR

Get notified when new releases ship.

Sign up free

About spupuz/VibeNVR

All releases →

Related context

Earlier breaking changes

  • v1.28.3 Must update docker-compose.yml with TZ variable for all services

Beta — feedback welcome: [email protected]