Skip to content

PortfolioDB 1.3.0

Choose a tag to compare

@amosgeva amosgeva released this 02 Sep 19:35
· 106 commits to main since this release
0aaa3e9

A security and hygiene release. No figure changes and no migration — see
Upgrading — but one shipped default is different, and if you reach the MCP
server from another machine you need to know which.

Changed

  • The MCP server's ad-hoc runner now binds localhost by default instead of
    all interfaces. python -m app.mcp.server is what someone types to try the
    server out, and a default that reaches the LAN is the wrong one for a process
    that answers questions about your ledger. Bearer auth sits in front either
    way — this narrows the blast radius of a misconfigured token, it does not
    close a hole.
    • If you rely on reaching the MCP server from another machine, set
      PORTFOLIODB_MCP_HOST=0.0.0.0.
      The shipped compose file already does,
      and passes --host to uvicorn itself rather than going through the runner,
      so containerised deployments are unaffected either way.

Security

  • python-dotenv floor raised to 1.2.2 (CVE-2026-28684, arbitrary file
    overwrite via symlink following). The old >=1.0 range permitted affected
    versions; a fresh install resolves to the newest match, so this closes the
    case where a resolver, a stale mirror, or an old lockfile lands on one that
    is vulnerable.
  • The drift-checking tool refuses non-HTTP(S) URLs rather than handing whatever
    it is given to urlopen, which would otherwise read a local file and report
    on it as though it were the live site.
  • .gitignore now covers every .env sidecar, not just the known suffixes.
    Copying your .env before editing it — cp .env .env.bak — is the obvious
    precaution, and under the old exact-match rules that copy was untracked but
    not ignored
    , one git add -A away from committing your credentials.
    .env.template stays visible.

Fixed

  • Nine try/except/pass blocks replaced with contextlib.suppress. All
    were best-effort cleanup — returning a connection, closing a handle, dropping
    a query parameter — and behave identically; the intent is now legible at a
    glance rather than inferred from an empty handler.

Upgrading

No migration. docker compose pull && docker compose up -d.

No figure changes. No schema, no stored value and no computation was
touched.

Read this if you reach the MCP server from another machine. Two cases:

  • Running it through the shipped compose file — nothing to do. Compose sets
    PORTFOLIODB_MCP_HOST and passes --host to uvicorn itself, so it never uses
    the changed default.
  • Running python -m app.mcp.server directly — set
    PORTFOLIODB_MCP_HOST=0.0.0.0 in your .env
    , or the server will answer
    only on localhost after this upgrade and remote clients will fail to connect.

Minor rather than patch because that default is a behaviour change someone can
be relying on, even though it is a default and overridable. The compose default
floats the major line, so a pull crosses this boundary on its own — which is
exactly why the case above is called out rather than left to be discovered.

Host installs (not compose) should re-run pip install -r app/requirements.txt
to pick up the python-dotenv floor.