Skip to content

spupuz/VibeNVR

v1.30.14 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 8d Media Servers
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

ffmpeg lightweight local-storage nvr opensource privacy
+1 more
video-surveillance

Affected surfaces

auth

Summary

AI summary

Fix AI motion state persistence logic when ignoring exclusion zones.

Full changelog

What's Changed

  • 🧹 [code health: refactor complex motion detect logic and add tests] by @spupuz in https://github.com/spupuz/VibeNVR/pull/211
  • 🧹 [Remove unused crud import] by @spupuz in https://github.com/spupuz/VibeNVR/pull/213
  • 🧪 Add frontend tests for camera utils by @spupuz in https://github.com/spupuz/VibeNVR/pull/214
  • fix(engine): fix AI motion state persistence logic when ignoring exclusion zones by @spupuz in https://github.com/spupuz/VibeNVR/pull/215
  • 🎨 Palette: Keyboard Accessibility for Timeline Event Cards by @spupuz in https://github.com/spupuz/VibeNVR/pull/216
  • ⚡ Optimize N+1 Query in Restore Users by @spupuz in https://github.com/spupuz/VibeNVR/pull/219
  • ⚡ [Performance Improvement] Resolve N+1 delete query bottleneck in corrupted video cleanups by @spupuz in https://github.com/spupuz/VibeNVR/pull/220
  • ⚡ [Optimize async PTZ endpoints by unblocking event loop] by @spupuz in https://github.com/spupuz/VibeNVR/pull/225
  • 🎨 Palette: [UX improvement] Add keyboard accessibility to timeline hour filter by @spupuz in https://github.com/spupuz/VibeNVR/pull/226
  • 🛡️ Sentinel: [MEDIUM] Fix timing attack in webhook verification by @spupuz in https://github.com/spupuz/VibeNVR/pull/227
  • ⚡ Bolt: [performance improvement] by @spupuz in https://github.com/spupuz/VibeNVR/pull/228
  • 🎨 Palette: Add accessible ARIA labels to timeline filter controls by @spupuz in https://github.com/spupuz/VibeNVR/pull/200
  • 🧹 [code health: unused import removed] by @spupuz in https://github.com/spupuz/VibeNVR/pull/207
  • 🧹 [refactor start_recording method to improve readability and code health] by @spupuz in https://github.com/spupuz/VibeNVR/pull/208
  • ⚡ [Optimize N+1 queries in camera import] by @spupuz in https://github.com/spupuz/VibeNVR/pull/209
  • 🧹 [code health] Remove unused imports in migrate_captured_before.py by @spupuz in https://github.com/spupuz/VibeNVR/pull/212
  • 🧹 [remove leftover console.log from OnvifTab] by @spupuz in https://github.com/spupuz/VibeNVR/pull/217

Full Changelog: https://github.com/spupuz/VibeNVR/compare/v1.30.13...v1.30.14

Security Fixes

  • Sentinel: Fix timing attack in webhook verification (MEDIUM severity)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track spupuz/VibeNVR

Get notified when new releases ship.

Sign up free

About spupuz/VibeNVR

All releases →

Related context

Earlier breaking changes

  • v1.29.7 Removed the legacy `stream_url` schema from stream routing.
  • v1.28.3 Must update docker-compose.yml with TZ variable for all services

Beta — feedback welcome: [email protected]