Skip to content

Z3r0

v0.2.0 Breaking

This release includes 1 breaking change for platform teams planning a safe upgrade.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

penetration-testing pentesting security-audit security-automation security-tools

Affected surfaces

auth

ReleasePort's take

Moderate signal
editorial:auto 1mo

Release v0.2.0 changes JWT authentication from the bearer header to a custom access‑token header.

Why it matters: All existing integrations must update request headers within one week or authentication will fail; severity labeled high due to breaking change impact.

Summary

AI summary

Moved JWT authentication to a custom access‑token header.

Changes in this release

Breaking High

Moves JWT authentication from bearer header to custom access-token header.

Moves JWT authentication from bearer header to custom access-token header.

Source: llm_adapter@2026-06-12

Confidence: high

Feature Low

Adds WorkProject attack-chain graphing with assets, findings, paths, and snapshots.

Adds WorkProject attack-chain graphing with assets, findings, paths, and snapshots.

Source: llm_adapter@2026-06-12

Confidence: high

Feature Low

Adds project workspace views for graph exploration, record review, and editing.

Adds project workspace views for graph exploration, record review, and editing.

Source: llm_adapter@2026-06-12

Confidence: high

Feature Low

Adds Mermaid diagram enforcement and rendering in playground transcripts.

Adds Mermaid diagram enforcement and rendering in playground transcripts.

Source: llm_adapter@2026-06-12

Confidence: high

Performance Medium

Improves project graph layout, task label wrapping, and frontend resource presentation.

Improves project graph layout, task label wrapping, and frontend resource presentation.

Source: llm_adapter@2026-06-12

Confidence: high

Bugfix Medium

Consolidates WorkProject record snapshot flow and hardens record persistence.

Consolidates WorkProject record snapshot flow and hardens record persistence.

Source: llm_adapter@2026-06-12

Confidence: high

Bugfix Medium

Aligns generated API contracts, frontend constants, and backend schemas for WorkProject records.

Aligns generated API contracts, frontend constants, and backend schemas for WorkProject records.

Source: llm_adapter@2026-06-12

Confidence: high

Refactor Low

Refines WorkProject tool contracts for assets, findings, tasks, graph edges, and paths.

Refines WorkProject tool contracts for assets, findings, tasks, graph edges, and paths.

Source: llm_adapter@2026-06-12

Confidence: high

Full changelog

Added

  • Added WorkProject attack-chain graphing with assets, findings, attack paths, and auditable record snapshots.
  • Added project workspace views for graph exploration, record review, and richer project editing.
  • Added Mermaid diagram enforcement and rendering in playground transcripts.

Changed

  • Refined WorkProject tool contracts around assets, findings, task summaries, shared task updates, graph edges, and attack paths.
  • Improved project graph layout, task label wrapping, and frontend resource presentation.
  • Repositioned README and landing copy around authorized red-team research and controlled multi-agent workflows.

Fixed

  • Consolidated WorkProject record snapshot flow and hardened record persistence.
  • Aligned generated API contracts, frontend constants, and backend tool schemas for WorkProject records.
  • Moved JWT authentication from bearer authorization to the custom access-token header contract.

Breaking Changes

  • Moved JWT authentication from Bearer Authorization header to a custom access‑token header.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Z3r0

Get notified when new releases ship.

Sign up free

Related context

Beta — feedback welcome: [email protected]