You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Updated bundled OpenCode to 1.18.34, Claude Code to 2.1.286, OpenSpec to 1.14.0, npm to 12.2.0, pnpm to 12.8.1, Vite to 8.3.2, and GitHub CLI to 2.102.0.
Updated Wrangler to 4.145.0 with its matching Miniflare and workerd packages, refreshed the Go builder image, and updated the release scanners and Renovate validator. The dependency audit lists the selected updates and compatibility holds.
Kept Claude Auth at 2.2.1. This release does not fix the credential-refresh report in issue #11, which remains open.
Known issues
The ARM64 image includes Chromium 154.0.8037.57-1~deb13u1. The 11 known CVEs include code-execution and sandbox-escape risks. The 33 exact package/CVE/version exceptions expire October 8, 2026. Avoid untrusted browser content and automation on ARM64. Existing sandbox and container controls do not make this safe. A follow-up release must replace the affected packages and remove the exceptions. Pull the corrected image and restart the container to apply it.
Fixed
Removed Paperclip's obsolete Undici override after its dependency graph changed. The image now checks the current package owners and exercises jsdom's fetch path without adding an unused dependency.
Updated npm's node-gyp and Undici packages, PM2's FTP dependency, and pip's vendored urllib3 to address the security findings in those bundled copies.
Repaired the offline pip seed as well, so a new Python environment gets the same fixes. Source records, licenses, and the patched package metadata stay in sync.