Skip to content

Agent Console v0.2.2 — security update

Choose a tag to compare

@SamSnead85 SamSnead85 released this 25 Sep 10:41
2910bca

Agent Console v0.2.2 fixes join-link command injection, prevents the console's admin key from being sent to another process holding its port, and replaces the reusable session credential with revocable per-browser sessions. Users of v0.2.0 and v0.2.1 should upgrade. Browsers must sign in again after upgrading.

This release also includes accounting conformance fixes and collector performance improvements. See CHANGELOG.md and SECURITY.md in the package for details.

Source: 2910bca. The release workflow passed and attached lockedinlabs-agent-console-0.2.2.tgz and SHA256SUMS with a GitHub build provenance attestation. The downloaded archive passed independent checksum and provenance verification, an offline clean install, console startup, sign-in and authenticated API checks. Anonymous API access was refused as expected.

This is the v0.2.2 security patch. It does not include the pending v0.3 UI redesign or private Enterprise gateway activation.