This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+13 more
Affected surfaces
Summary
AI summaryUpdates Privacy hardening, Tests, and privacy.html across a mixed release.
Full changelog
Patch release on v1.34.3 — no API surface change (54 MCP tools, 7 Resources, 3 Prompts unchanged).
Privacy hardening
- The request-path log sanitizer now covers every path-param route (scan, redirect, robots, brand, seo, audit, email/verify, email/security-posture, threat-report, kev, atlas, d3fend, sigma, cwe) — logged paths show a redacted placeholder instead of the queried value, matching the documented privacy contract (privacy.html).
- Fetch-failure and scanner log lines record only the coarse exception kind — the queried target and full exception text no longer appear in log output.
- The per-target throttle alert masks the target; the disclosed per-target counter remains the operator's lookup source.
Tests
- 2591 → 2599 pytest (sanitizer coverage, alert masking, and log-content regression assertions that fail if a target or exception message reappears in log output).
No schema or cache migration; fully wire-compatible.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About UPinar/contrastapi
Security intelligence API with 31 MCP tools for CVE/EPSS/KEV lookup, domain recon (DNS/WHOIS/SSL/subdomains/CT logs), IOC/threat intel, OSINT (email/phone/username), and code security scanning (secrets, injection). Free 100 req/hr.
Related context
Related tools
Earlier breaking changes
- v1.33.11 `bulk_sigma_rule_lookup` now costs 1 credit per `rule_id`, changing from flat 1 credit/call.
Beta — feedback welcome: [email protected]