Skip to content

0.46.5 — h2 DoS fix + nginx security headers

Choose a tag to compare

@Dim145 Dim145 released this 22 Aug 13:22
· 54 commits to main since this release

Security + hardening

  • server — h2 0.4.14 → 0.4.18, patching RUSTSEC-2026-0258 (HTTP/2 unbounded empty DATA frames — DoS). Surgical bump: sqlx/pgvector unchanged, verified with the --release --locked build.
  • client + docs (nginx) — security headers (CSP et al.) are now re-applied on asset / service-worker / manifest responses. nginx replaces inherited add_header in any block that adds its own, so those responses had been served without the security headers.

Other RustSec transitive advisories remain accepted (no safe upstream fix; vulnerable paths unreachable here — a blanket cargo update breaks pgvector/sqlx, so they need a coordinated bump). See SECURITY-SCAN-REPORT.md.


🐳 ghcr.io/dim145/figurecollector-{server,client,docs}:0.46.5
📝 Full changelog: 0.46.4...0.46.5