This release includes 3 security fixes for security teams reviewing exposed deployments.
Topics
+10 more
Affected surfaces
Summary
AI summaryActivity tab shows dollar savings of lazy discovery with selector and share button.
Full changelog
Token economics in the app
The Activity tab now shows the dollar value of what lazy discovery is saving you, not just the token count, with a model-price selector and a one-click Share button to copy your savings.
Security hardening
Three fixes from an internal security audit:
- OAuth PKCE/state generation now fails loudly instead of silently producing a constant if the OS RNG is ever unavailable.
- File writes use a unique atomic-write temp name, so two concurrent writers can't tear each other's contents.
- A saved bearer token is refused over non-HTTPS to a public host.
Under the hood
Log rotation now uses the same atomic-write path, the Rust backend is fully clippy-clean, and a regression test was added for stable tool names across a live refresh. No High or Critical findings in the audit.
Security Fixes
- OAuth PKCE/state generation now fails loudly when OS RNG unavailable
- File writes use unique atomic temp name to prevent concurrent writer tearing
- Saved bearer token rejected over non‑HTTPS to public host
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Toolport
All releases →Related context
Beta — feedback welcome: [email protected]