This release includes 1 security fix for security teams reviewing exposed deployments.
Published 4d
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
android
calorie-counter
capacitor
docker
fitbit
food-tracker
+12 more
garmin
health
health-connect
nutrition
nutrition-tracker
oidc
pwa
self-hosted
sso
svelte
wellness
withings
Affected surfaces
deps
Summary
AI summaryFixed long‑press action sheet on iOS Safari and upgraded brace‑expansion to mitigate CVE‑2026‑13149.
Full changelog
Patch release. Fixes long-press to open the food/meal/recipe action sheet on iOS Safari, plus a high-severity brace-expansion CVE bump.
Fixed
- Long-press works on Foods/Meals/Recipes lists in iOS Safari. The Diary tab already used a manual touch timer to detect long-press; the Foods tab only listened for
contextmenu, which iOS Safari doesn't dispatch for long-press on non-text elements. Ported the same touch-timer pattern to Foods/Meals/Recipes so long-press opens the edit/clone/delete action sheet across every browser. (#102, reported by @javydekoning)
Security
- brace-expansion bumped to 5.0.7 (CVE-2026-13149, high). Regex denial-of-service in the expansion parser. Transitive dep; no direct code change required.
Security Fixes
- dep: CVE-2026-13149 (high) — Regex denial‑of‑service fixed in brace-expansion 5.0.7
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]