This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
Summary
AI summaryImproved endpoint URL validation and added OCI metadata to Docker images.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Set OCI metadata on Docker images for CLI, Server, Bridge. Set OCI metadata on Docker images for CLI, Server, Bridge. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Feature | Low |
Embed package metadata in compiled Linux binaries for CLI, Server, Bridge. Embed package metadata in compiled Linux binaries for CLI, Server, Bridge. Source: llm_adapter@2026-07-17 Confidence: high |
— |
| Bugfix | Medium |
Improve validation of endpoint URLs in Server (SVIXSEC-2026-0001). Improve validation of endpoint URLs in Server (SVIXSEC-2026-0001). Source: llm_adapter@2026-07-17 Confidence: low |
— |
Full changelog
Changes
- CLI, Server, Bridge: Set OCI metadata on Docker images
- CLI, Server, Bridge: Embed package metadata in compiled binaries on Linux
- Server: Improve validation of endpoint URLs (SVIXSEC-2026-0001)
Full Changelog: https://github.com/svix/svix-webhooks/compare/v1.97.0...v1.98.0
Security Fixes
- SVIXSEC-2026-0001 — Improved validation of endpoint URLs to prevent malformed URL attacks
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Svix
Open-source webhooks as a service that makes it super easy for API providers to send webhooks.
Beta — feedback welcome: [email protected]