This release includes 1 security fix for security teams reviewing exposed deployments.
Published 2mo
Productivity & Wikis
✓ No known CVEs patched
This release patches 1 known CVE
Topics
appointment
appointment-booking
appointment-scheduling
appointments
calendar
calendars
+6 more
calendly-alternative
docker
elixir
phoenix-liveview
postgresql
scheduling
Affected surfaces
auth
Summary
AI summarySanitize CSS class names to prevent XSS and add a Quill flag‑height design token.
Full changelog
[0.98.1] — 2026-02-16
Bug Fixes
- security: Sanitize CSS class names in icon rendering to prevent XSS
- coverage: Replace .coveralls.exs with coveralls.json for proper exclusions
- brand: Add w-auto to logo images to preserve dimensions while fixing layout
- brand: Add explicit dimensions to logo images to prevent layout shift
- rhythm theme: Improve language dropdown text contrast
- test: Correct error message expectation in ErrorHandler test
- test: Use dynamic future date in quill meeting tests
- quill: Improve step navigation contrast on bright backgrounds
- scheduling: Hide language dropdown after slide 1 and fix layout jump
- Correct CAStore API usage in SMTP config
- Remove unreachable pattern match in meeting settings card
- onboarding: Remove unreachable pattern match clauses
- Correct CAStore API usage in mailer health check
Features
- quill: Add --flag-height design token for consistency
Security Fixes
- Sanitize CSS class names in icon rendering to prevent XSS
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]