Skip to content

cleanslate

v4.22.0 Security

This release includes 2 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 2 known CVEs

Affected surfaces

deps

Summary

AI summary

Update dependency js-cookie to v3.0.7 and protobufjs to 7.6.0 for security fixes.

Changes in this release

Security High

Security update: upgraded js-cookie due to a vulnerability.

Security update: upgraded js-cookie due to a vulnerability.

Source: granite4.1:30b@2026-05-26-audit

Confidence: high

Dependency Low

Updated js-cookie dependency to version 3.0.7.

Updated js-cookie dependency to version 3.0.7.

Source: llm_adapter@2026-05-26

Confidence: high

Dependency Low

Updated protobufjs dependency from 7.5.7 to 7.6.0 in /functions.

Updated protobufjs dependency from 7.5.7 to 7.6.0 in /functions.

Source: llm_adapter@2026-05-26

Confidence: high

Full changelog

What's Changed

Security: Admins should update their instance of Clean Slate

  • Update dependency js-cookie to v3.0.7 [SECURITY] by @renovate[bot] in https://github.com/successible/cleanslate/pull/524
  • Bump protobufjs from 7.5.7 to 7.6.0 in /functions in the npm_and_yarn group across 1 directory by @dependabot[bot] in https://github.com/successible/cleanslate/pull/525

Enhancements:

  • Update all non-major dependencies by @renovate[bot] in https://github.com/successible/cleanslate/pull/521
  • Lock file maintenance by @renovate[bot] in https://github.com/successible/cleanslate/pull/522
  • Lock file maintenance by @renovate[bot] in https://github.com/successible/cleanslate/pull/528
  • Update all non-major dependencies by @renovate[bot] in https://github.com/successible/cleanslate/pull/527

Full Changelog: https://github.com/successible/cleanslate/compare/v4.21.0...v4.22.0

Security Fixes

  • dep: js-cookie updated to v3.0.7 — security patch
  • dep: protobufjs bumped from 7.5.7 to 7.6.0 — includes security improvements

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track cleanslate

Get notified when new releases ship.

Sign up free

About cleanslate

☀ Track food without judgment

All releases →

Related context

Beta — feedback welcome: [email protected]