This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+2 more
Summary
AI summaryFixed a memory leak by destroying scratch Awareness objects and added sessionAwareness to provider-react.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Adds sessionAwareness exposure in provider-react HocuspocusRoom. Adds sessionAwareness exposure in provider-react HocuspocusRoom. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Medium |
Fixes memory leak by destroying scratch Awareness objects in MessageReceiver. Fixes memory leak by destroying scratch Awareness objects in MessageReceiver. Source: llm_adapter@2026-06-10 Confidence: high |
— |
| Bugfix | Low |
Fixes client-initiated broadcastStateless issue. Fixes client-initiated broadcastStateless issue. Source: granite4.1:30b@2026-06-10-audit Confidence: low |
— |
Full changelog
What's Changed
- fix: client-initiated broadcastStateless by @janthurau in https://github.com/ueberdosis/hocuspocus/pull/1103
- Fix memory leak: destroy scratch Awareness objects in MessageReceiver by @Copilot in https://github.com/ueberdosis/hocuspocus/pull/1109
- Feature: expose sessionAwareness in provider-react HocuspocusRoom by @t-schorn in https://github.com/ueberdosis/hocuspocus/pull/1104
New Contributors
- @t-schorn made their first contribution in https://github.com/ueberdosis/hocuspocus/pull/1104
Full Changelog: https://github.com/ueberdosis/hocuspocus/compare/v4.1.0...v4.1.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Hocuspocus 4
All releases →Beta — feedback welcome: [email protected]