Skip to content

v0.8.1

Choose a tag to compare

@cjohannsen81 cjohannsen81 released this 06 Sep 19:51
· 27 commits to main since this release

Security hardening from an internal review. No behavior change for existing configs.

  • DNS-rebinding protection now turns on automatically once you pin http.allowed_hosts (and an explicit http.dns_rebinding_protection: still wins), rather than staying off. Defense in depth on top of the mandatory bearer auth.
  • On-behalf-of hook no longer returns a failing command's stderr to the caller (it could carry a token or a vault error). Details are logged server-side; the caller gets a generic message.
  • Dependency floor raised to python-multipart>=0.0.18 (CVE-2024-53981).
  • Docs: note that arg_match regex runs against model-supplied argument values, so keep patterns anchored.

The scan found no high or critical issues.