Repository navigation
PortfolioDB 1.3.0
A security and hygiene release. No figure changes and no migration — see
Upgrading — but one shipped default is different, and if you reach the MCP
server from another machine you need to know which.
Changed
- The MCP server's ad-hoc runner now binds localhost by default instead of
all interfaces.python -m app.mcp.serveris what someone types to try the
server out, and a default that reaches the LAN is the wrong one for a process
that answers questions about your ledger. Bearer auth sits in front either
way — this narrows the blast radius of a misconfigured token, it does not
close a hole.- If you rely on reaching the MCP server from another machine, set
PORTFOLIODB_MCP_HOST=0.0.0.0. The shipped compose file already does,
and passes--hostto uvicorn itself rather than going through the runner,
so containerised deployments are unaffected either way.
- If you rely on reaching the MCP server from another machine, set
Security
python-dotenvfloor raised to 1.2.2 (CVE-2026-28684, arbitrary file
overwrite via symlink following). The old>=1.0range permitted affected
versions; a fresh install resolves to the newest match, so this closes the
case where a resolver, a stale mirror, or an old lockfile lands on one that
is vulnerable.- The drift-checking tool refuses non-HTTP(S) URLs rather than handing whatever
it is given tourlopen, which would otherwise read a local file and report
on it as though it were the live site. .gitignorenow covers every.envsidecar, not just the known suffixes.
Copying your.envbefore editing it —cp .env .env.bak— is the obvious
precaution, and under the old exact-match rules that copy was untracked but
not ignored, onegit add -Aaway from committing your credentials.
.env.templatestays visible.
Fixed
- Nine
try/except/passblocks replaced withcontextlib.suppress. All
were best-effort cleanup — returning a connection, closing a handle, dropping
a query parameter — and behave identically; the intent is now legible at a
glance rather than inferred from an empty handler.
Upgrading
No migration. docker compose pull && docker compose up -d.
No figure changes. No schema, no stored value and no computation was
touched.
Read this if you reach the MCP server from another machine. Two cases:
- Running it through the shipped compose file — nothing to do. Compose sets
PORTFOLIODB_MCP_HOSTand passes--hostto uvicorn itself, so it never uses
the changed default. - Running
python -m app.mcp.serverdirectly — set
PORTFOLIODB_MCP_HOST=0.0.0.0in your.env, or the server will answer
only on localhost after this upgrade and remote clients will fail to connect.
Minor rather than patch because that default is a behaviour change someone can
be relying on, even though it is a default and overridable. The compose default
floats the major line, so a pull crosses this boundary on its own — which is
exactly why the case above is called out rather than left to be discovered.
Host installs (not compose) should re-run pip install -r app/requirements.txt
to pick up the python-dotenv floor.