Skip to content

v0.5.2

Choose a tag to compare

@github-actions github-actions released this 25 Jul 13:37
926598c

0.5.2 (2026-07-25)

Bug Fixes

  • correct release-please output name for dispatch (#100) (9c1d75d)
  • security: harden 7 audit findings — npm shim, logging, cross-DB authz (#102) (7649383)

Security clarification (added 2026-10-02)

The public hardening report identifies these security fixes in this release:

  • F1: reject archive traversal, absolute paths and symlink/hardlink entries before npm-shim extraction.
  • F2: require database access in the database-parameter validation used by discovery tools. This does not turn Restricted mode into a database-authorization boundary.
  • F3: reject log-path traversal and linked final log targets.
  • F5: verify cached binary SHA-256 against its sidecar before reuse. This is integrity verification, not independent publisher authentication.
  • F6: redact malformed credential values completely and return redaction rather than raw input on regex timeout.
  • F7: reject download redirects outside the allowed GitHub hosts.

See the public hardening report and fixing PR #102. The identifiers above are those actually listed in the historical report; they are not CVE assignments. The later linked-parent/rotation hardening in PR #150 is not part of this release.