Skip to content

Security hub

Security release intelligence

Breaking changes, CVEs, and upgrade notes across security-critical developer tools.

This week

0

KEV-cited releases

Most-cited: ART

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Are patches keeping up?

90 days

Action Required

View KEV feed
Config change
apko v1.2.29 Maintenance
Auth

Routine maintenance and dependency updates.

Review required
Termix release-2.6.0-tag New feature
Auth RBAC

Standalone-first + shared sessions

Upgrade now
langroid 0.65.14 Security relevant
Auth Breaking upgrade

Blocks write SELECT statements

Config change
bugsink 2.5.0 Breaking risk
Auth

Grouping upgrade + global issues

Review required
neodb 0.17.4 Breaking risk
Breaking upgrade Auth

Unified redirects

Active KEV

All KEV

No KEV-cited releases in the current window.

High EPSS

All high EPSS

No high-EPSS release patches in the current window.

Recent CVE Patches

Review required
Hi.Events v.1.10.0-beta Security relevant
Auth RBAC

Translations + Checkout improvements + Security fixes

patches CVE-2025-31125
Open
Upgrade now
recipes 2.6.12 Security relevant
Auth Breaking upgrade

Private recipe manipulation fix

patches CVE-2026-42208 patches CVE-2026-42271
Open
No immediate action
ray ray-2.56.0 Security relevant

Routine maintenance and dependency updates.

patches CVE-2023-4863
Open
Review required
Flowise [email protected] Security relevant
Auth Dependencies

Clickjacking fix + Agentflow enhancements + Observe

patches CVE-2025-31125
Open
No immediate action
blinko 1.8.8 Security relevant

Ukrainian locale + HTTP MCP + LiteLLM + MiniMax upgrade

patches CVE-2025-31125
Open

Security Tool Updates

Security feed
Upgrade now
langroid 0.65.14 Security relevant
Auth Breaking upgrade

Blocks write SELECT statements

Upgrade now
crewAI 1.15.7 Security relevant
Dependencies

CVE-2026-16796 fix

Config change
dozzle v10.6.12 Security relevant
Auth RBAC

Auth requirement + command palette + password fix

Review required
freescout 1.8.231 Security relevant
Auth RBAC

Customer visibility check

No immediate action
NPMplus 2026-07-24-r1 Security relevant

CVE fix

Response-Speed Leaderboard

No response-speed signal has been computed yet.

Supply-Chain Matrix Preview

Open matrix

Beta — feedback welcome: [email protected]