Skip to content
release
BETA
Releases
Tools
Vendors
Trending
$refs.securityHub.focus())"
:aria-expanded="open"
aria-haspopup="menu"
class="inline-flex items-center gap-1 px-3 py-1.5 rounded text-[13px] font-medium transition-colors text-[var(--text-secondary)] dark:text-[var(--text-muted)] hover:text-[var(--text-primary)] dark:hover:text-[var(--text-primary)] hover:bg-[var(--surface-hover)] dark:hover:bg-[var(--surface-elevated)]"
>
Security
Tools
/
v2
V
v2
Dashboards & Home Pages
A minimalist, privacy‑focused feed reader that’s simple, fast and easy to install.
Go
·
Latest 2.3.1 · 5d ago
Security brief →
Features
Supports Atom, RSS and JSON Feed formats with OPML import/export
Privacy features: strips trackers, sanitizes content, blocks external scripts, provides a media proxy
Extensive integrations (Discord, Slack, Matrix, Notion, etc.) and REST API with Go/Python clients
Upgrade now
2.3.1
Security relevant
·
5d
Auth
RCE / SSRF
Security fixes
Review required
2.3.0
Breaking risk
·
19d
Auth
RBAC
WebAuthn credential restriction
2.2.19
Security relevant
·
2mo
Sensitive data was stripped from logs, OAuth2 flows were hardened, token validation switched to constant-time HMAC-SHA256, DoS risks in template truncation were mitigated, and large favicons were rejected, improving overall security posture.
2.2.18
Breaking risk
·
2mo
Breaking changes
Private network access blocked by default—requires FETCHER_ALLOW_PRIVATE_NETWORKS=1 and INTEGRATION_ALLOW_PRIVATE_NETWORKS=1 environment variables
Security fixes
SSRF protection for private networks DNS-rebinding TOCTOU mitigation RFC 6598 shared address space protection
Notable features
SSRF protection for fetcher and integrations Entry blocking rules applied pre/post scraping ignore_entry_updates feed option
2.2.17
Security relevant
·
3mo
Security fixes
Version hiding on unauthenticated endpoints Improved HTML sanitizer to prevent injection issues Blocked resource enforcement on srcset URLs
Notable features
HTML sanitizer using golang.org/x/net/html parser srcset parser following HTML specifications Blocked resource enforcement on srcset URLs
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Releases per month
Releases per month, last 12 months.
Cadence
0.3 / wk
Last release
5d
Churn
+1568 / −672 lines · 73 files · 32 commits
Tracked
6
Security score
6.2/10
OpenSSF
7.3/10
Open CVEs
0
SECURITY.md
Active maintainer
Community
GitHub stars
9,309
Forks
887
Open issues
280
Open PRs
26
Stars/wk velocity
0.0
About
Languages
Go
·
HTML
·
JavaScript
View on GitHub
Homepage
Documentation
{ copied = true; setTimeout(() => copied = false, 2000) })"
class="flex items-center gap-1.5 text-[12px] text-[var(--text-muted)] dark:text-[var(--text-muted)] hover:text-[var(--accent)] dark:hover:text-[var(--accent)] transition-colors"
>
About
Languages
Go
·
HTML
·
JavaScript
View on GitHub
Homepage
Documentation
{ copied = true; setTimeout(() => copied = false, 2000) })"
class="flex items-center gap-1.5 text-[12px] text-[var(--text-muted)] dark:text-[var(--text-muted)] hover:text-[var(--accent)] dark:hover:text-[var(--accent)] transition-colors"
>
© 2026 releaseport. All rights reserved.
Feed
Tools
Feeds
Security
Brief
Search tools, categories, lists, and users
Use ↑↓ to navigate, Enter to open, Esc to close
No results for " "
⌘K to open
↑↓ navigate
⏎ open