Auth.js + Next.js fixes
Supply Chain Security
SBOM generation, software signing, policy-as-code, and dependency vulnerability scanning.
Upgrade now
Auth
RCE / SSRF
Dependencies
Review required
Dependencies
CodeQL fix + Slack YAML repair
Review required
Auth
RCE / SSRF
Dependencies
Security fixes + Golden Crucible
Upgrade now
RCE / SSRF
Dependencies
Breaking upgrade
CVE-2026-49252 + CVE-2026-55698
v3.28.0
(1mo)
i18next prototype pollution fixes
v3.24.0
(1mo)
CVE-2024-22206 fix
v3.21.0
(1mo)
Hono CORS fix
v3.20.0
(1mo)
Security fixes
v3.14.0
(1mo)
CVE-2024-52011 fix
v3.1.26
(1mo)
CVE fixes + SQL injection
v3.1.25
(2mo)
Malicious node-ipc detection + CI npm hardening
Upgrade now
Dependencies
Go 1.26.3 upgrade + retract detection
Review required
Auth
RCE / SSRF
React CVE-2025-55182
Security fixes
- DAPI callable resolution restriction
- Buffer overflow in analysisd regex match
- Path traversal in authd via agent group name
v3.0.21
(3mo)
Security fixes
v0.74.1
(4mo)
Security hardening
v0.71.3
(4mo)
OS CVE patches + attestations
Security fixes
- Fixed heap-based null WRITE Buffer Underflows
Review required
Auth
Dependencies
Credential security hardening
v0.70.4
(4mo)
Vuln DB hardening
v0.66.0
(4mo)
Security hardening
v0.59.3
(4mo)
Audit & security fixes
v0.59.0
(4mo)
Security hardening
v0.58.1
(4mo)
ClawHub trust hardening
v0.31.3
(5mo)
ClawHub trust hardening
Security fixes
- Buffer overflow fixes in SCA decoder
- Memory leak fix in CIS-CAT decoder
Notable features
- Added hostname and architecture metadata to Windows keep-alive messages
Upgrade now
Crypto / TLS
TweetNaCl memory exhaustion fix
Get this as a security brief. Track Supply Chain Security releases straight to your inbox.