Skip to content

Z3r0

v0.2.1 Feature

This release adds 3 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

penetration-testing pentesting security-audit security-automation security-tools

Summary

AI summary

Fixed default database port mismatch between runtime configuration and Docker Compose.

Full changelog

Added

  • Added host management with SSH terminal access and Docker TLS certificate support for managed hosts.
  • Added dynamic sandbox egress proxy management, Tor-only sandbox egress, image-scoped sandbox control ports,
    and proxied noVNC access with container ownership control.
  • Added bilingual product documentation and a manual GitHub Pages deployment script.
  • Added sandbox artifact triage skills and a quick-open action for sub-agent messages.

Changed

  • Reworked the sandbox proxy into a modular Go proxy with shell, files, WebSocket, entry proxy, egress proxy,
    and PTY resize handling.
  • Replaced the WorkProject graph renderer with Cytoscape.
  • Strengthened coordinator and specialist agent instructions around coverage, retesting, MITRE ATT&CK-aligned
    methodology, and failure-seeking completion review.
  • Refined frontend layout, resource styling, playground streaming behavior, sandbox controls, and admin resource
    interactions.

Fixed

  • Fixed the default database port mismatch between runtime configuration and Docker Compose.
  • Fixed first-message playground streaming so REST-submitted turns render immediately.
  • Fixed host password field display, sandbox container hash display, Select prefix icon spacing, and Semi UI
    button usage.
  • Hardened git ignore coverage and normalized sandbox skill resource path handling.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Z3r0

Get notified when new releases ship.

Sign up free

Related context

Earlier breaking changes

  • v0.2.0 Moves JWT authentication from bearer header to custom access-token header.

Beta — feedback welcome: [email protected]