Security hub
Security release intelligence
Breaking changes, CVEs, and upgrade notes across security-critical developer tools.
This week
0
KEV-cited releases
Most-cited: ART
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Are patches keeping up?
90 days
—
Review required
RCE / SSRF
Hook script hardening + interpreter embedding
Review required
Auth
RBAC
Routine maintenance and dependency updates.
Upgrade now
Dependencies
Routine maintenance and dependency updates.
Review required
Auth
RBAC
desktop, terminal, billing, api, relay, projects, pty
Review required
Auth
RBAC
Breaking upgrade
Routine maintenance and dependency updates.
No KEV-cited releases in the current window.
No high-EPSS release patches in the current window.
Recent CVE Patches
Review required
etcd
v3.4.45
Breaking risk
·
Breaking upgrade
Linux, macOS, Docker update
No immediate action
pastefy
7.2.2
Security relevant
·
Language support + OAuth fix
Review required
Auth
RBAC
Breaking removals + new features
Review required
ActiveMQ
activemq-6.2.6
Breaking risk
·
Auth
RBAC
RCE / SSRF
Serializable package removal + hardened access
patches CVE-2016-3088
patches CVE-2016-4437
patches CVE-2021-39144
+5 more
Open
No immediate action
Model Router + Scheduled Jobs + Memories
Upgrade now
doco-cd
v0.90.1
Security relevant
·
Auth
RBAC
OCI security fix
Monitor
Go action min version bump
Upgrade now
mastodon
v4.4.18
Security relevant
·
Auth
RCE / SSRF
Security fixes + media description handling
Upgrade now
Auth
RBAC
Security disclosures fixed
Review required
caddy
v2.11.4
Security relevant
·
Auth
RBAC
Security patches + deps upgrade
Response-Speed Leaderboard
No response-speed signal has been computed yet.