Skip to content

Oikos

v1.45.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 2d Productivity & Wikis
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

docker family family-planner home-automation planner-app privacy-first
+4 more
progressive-web-app pwa self-hosted selfhosted-apps

Affected surfaces

auth rbac

Summary

AI summary

Calendar attachment access now aligns with event visibility to prevent unauthorized exposure.

Full changelog

Added

  • Add Google Drive as an explicitly selected storage destination for new Documents files and Calendar attachments, with least-privilege OAuth connection, testing, account safeguards, and provider status. Existing files stay on their recorded backend, and SQLite backups contain Drive metadata and file IDs rather than Drive-hosted binaries.

Fixed

  • Keep Calendar attachment access aligned with event visibility and assignees, including existing linked attachments, so private or restricted files cannot become household-visible through Documents.

Security Fixes

  • Prevent private or restricted Calendar attachments from becoming household‑visible through Documents

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Oikos

Get notified when new releases ship.

Sign up free

About Oikos

Family planner for small households

All releases →

Related context

Earlier breaking changes

  • v0.71.3 Changes WebDAV backup default path from "/oikos/backups/" to "/yuvomi/backups/".
  • v0.66.0 Repository URL changed to `https://github.com/ulsklyc/yuvomi`.
  • v0.66.0 Docker image moved to `ghcr.io/ulsklyc/yuvomi`.
  • v0.66.0 Project renamed from Oikos to Yuvomi.
  • v0.62.0 Changes event dialog to unified sync target picker across Google and CalDAV calendars.

Beta — feedback welcome: [email protected]