What's Changed
- chore(deps): bump the production-dependencies group across 1 directory with 9 updates by @dependabot[bot] in #324
- feat(ops): production install wizard (Docker + Redis + Postgres) by @RaminNietzsche in #330
- fix(security): refuse production start without API auth (#344) by @RaminNietzsche in #414
- fix(ops): require JOB_QUEUE_ENABLED + compose worker (#375) by @RaminNietzsche in #413
- feat(ops): split live/ready/startup health probes (#354) by @RaminNietzsche in #416
- feat(helm): optional BullMQ worker Deployment (#382) by @RaminNietzsche in #417
- fix(security): harden SSRF with DNS + redirect revalidation (#374) by @RaminNietzsche in #415
- fix(security): gate detailed health behind auth (#355) by @RaminNietzsche in #422
- fix(ui): expand vuln rows by CVE+tool key (#387) by @RaminNietzsche in #411
- feat(security): encrypt tenant notification secrets at rest (#351) by @RaminNietzsche in #423
- fix(ui): dashboard severity tiles filter correctly (#386) by @RaminNietzsche in #410
- fix(ui): tenant-scope scan cache + history refresh (#388, #389) by @RaminNietzsche in #412
- feat(security): bind tenant to identity + job isolation (#345, #346) by @RaminNietzsche in #418
- docs: refresh backlog tracker for milestones + C01–C30 (#383) by @RaminNietzsche in #420
- fix(security): session-first API key storage (#350) by @RaminNietzsche in #421
- test: cross-tenant negative suite (#377) by @RaminNietzsche in #419
- ci(sonar): drop scanner qualitygate.wait to avoid timeouts by @RaminNietzsche in #424
- chore: release v1.6.0 by @RaminNietzsche in #425
Full Changelog: v1.5.0...v1.6.0