Immutable
release. Only release title and notes can be modified.
[1.11.1] - 2026-09-09
Security
- Update
qsto 6.16.0 to address array-limit bypass and attacker-controlled
isBufferdenial-of-service vulnerabilities. - Update
multerto 2.3.0 to fix file descriptor leaks from aborted disk-backed
multipart uploads. - Update build and lint dependencies
browserslistto 4.28.9 and
@humanfs/nodeto 0.16.8 to address unsafe custom statistics handling and
symlink-following file copies. - Update Nodemailer to 9.1.1 to address address parsing, recipient validation,
and content access-control vulnerabilities. - Update
js-yaml,brace-expansion,nanoid, Sharp, and the Vitest toolchain
to patched versions identified by the release dependency audit.
Documentation
- Published a user-facing DNS Logs performance overview connecting the
reproducible million-row SQLite results, stored-page hostname isolation, and
browser request-control measurements. The README, public documentation
navigation, beta guide, and About dialog now link operators to the results,
methodology, trade-offs, raw data, and reproduction commands.