v0.8.1
Security hardening from an internal review. No behavior change for existing configs.
- DNS-rebinding protection now turns on automatically once you pin
http.allowed_hosts(and an explicithttp.dns_rebinding_protection:still wins), rather than staying off. Defense in depth on top of the mandatory bearer auth. - On-behalf-of hook no longer returns a failing command's stderr to the caller (it could carry a token or a vault error). Details are logged server-side; the caller gets a generic message.
- Dependency floor raised to
python-multipart>=0.0.18(CVE-2024-53981). - Docs: note that
arg_matchregexruns against model-supplied argument values, so keep patterns anchored.
The scan found no high or critical issues.