This release includes 1 security fix for security teams reviewing exposed deployments.
Published 2mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
android
calorie-counter
capacitor
docker
fitbit
food-tracker
+12 more
garmin
health
health-connect
nutrition
nutrition-tracker
oidc
pwa
self-hosted
sso
svelte
wellness
withings
Affected surfaces
deps
Summary
AI summaryFramework upgrades reduce bundle size and remove Svelte 4 SSR security advisories.
Full changelog
Changed
- Framework upgrades. Svelte 4 → 5, Vite 5 → 6, Express 4 → 5, bcryptjs 2 → 3, plus the supporting Vite plugin bumps. Compat mode keeps the existing component code working without rewrites. The main app bundle drops about 22% (1.57 MB → 1.21 MB) and the underlying Svelte 4 SSR security advisories no longer apply.
Fixed
- Disabling user management was sending you back to the setup wizard on every reload. The server now remembers that user management was intentionally disabled and lets you back to the diary. (Issue #34)
- Import Nutrition History action row could visually overlap the Skip / Merge / Replace radios when re-importing a file with duplicate dates. (Issue #33)
- Wellness scores now refresh when today's sleep data finishes syncing after the morning snapshot ran, so the readiness number reflects the latest sleep input rather than getting stuck on the first incomplete value.
UI polish
- The live nutrition preview pills on the Add to Diary sheet now match the diary's macro color scheme (calories yellow, protein purple, carbs green, fat orange).
Security Fixes
- Svelte 4 SSR security advisories no longer apply after upgrade to Svelte 5.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]