Skip to content

PyStarter v1.0.8 — local security update

Latest

Choose a tag to compare

@E-Conners-Lab E-Conners-Lab released this 27 Sep 17:00
ace6243

Local security update

PyStarter 1.0.8 is intended for a single learner running trusted Python locally. Do not expose it to the internet or use it to execute strangers' code.

  • Fixes CSRF protection, authentication limits, refresh/logout/password-reset revocation and password handling.
  • Fixes draft-content and hidden-test-answer exposure.
  • Bounds execution output and process lifetimes, with Linux resource-limit tests.
  • Updates pinned dependencies and uses a smaller Alpine backend without high/critical image findings or exclusions.
  • Bundles the editor locally, creates separate random installation credentials and limits the database application role.
  • Corrects LICENSE to MIT.

The signed release commit is ace6243658cb16b54674ee267a5870cf597e65c2; its source tree exactly matches the tested candidate. Verification: all ten GitHub checks pass; 106 Linux backend tests and 99 browser tests pass; backend coverage is 90%; all four runtime image scans pass the high/critical gate. This is a dated review, not a guarantee against every vulnerability.

Download and run

This is a source release, not a prebuilt-image runner bundle. Download pystarter-v1.0.8-source.zip, extract it, and install Docker Desktop with Linux containers (or Docker Engine + Compose v2).

On macOS/Linux, from the extracted PyStarter-1.0.8 folder:

./init.sh
docker compose up --build -d

On Windows PowerShell:

powershell -ExecutionPolicy Bypass -File .\init.ps1
docker compose up --build -d

Open http://localhost:8080. The initial build requires internet access. AI is optional and needs your own provider configuration; do not submit secrets or confidential code. No hosted service is included. See README.md and SECURITY.md before running code.

Existing installations: back up first and follow the PostgreSQL role migration in CONTRIBUTING.md. Do not delete your database volume or replace existing database passwords to resolve an upgrade error.

The old 1.0.7 prebuilt images and runner ZIP do not contain these changes. No new prebuilt registry images are included with this source release.

The repository owner approved a one-time independent-review exception for this release. Required checks and signed commits stayed enforced, and the independent-review requirement was restored immediately after merging.