What's fixed
Patch release on top of 2.5.0 — security hardening and operator docs (no feature changes).
- Safer API / health error responses (no Flask debug by default; short controlled messages)
- Log sanitization for CodeQL
py/log-injectionfindings - Docker image
pipbump to clear image CVEs (Trivy) - Document required Proxmox API privileges in
docs/INSTALL.md - CodeQL / security CI polish (query filters, Trivy Action pin)
Code scanning: open alerts cleared on main after this series.
Verify artifacts
sha256sum -c SHA256SUMSFull changelog
Not an official Proxmox product — community support via GitHub issues.