v1.0.9
v1.0.9 hotfix
π Security
Critical dependency updates β strongly recommended upgrade
This release fixes 7 security vulnerabilities in npm dependencies.
| Package | Severity | Vulnerability Description |
|---|---|---|
| rollup | Critical | Arbitrary file write via path traversal |
| serialize-javascript | High | Remote code execution via RegExp.flags |
| basic-ftp | High | Path traversal in downloadToDir() |
| minimatch | High | ReDoS via GLOBSTAR segments |
| ajv | Moderate | ReDoS when using the $data option |
| hono | Moderate | Prototype pollution via __proto__ |
rollup is rated Critical, and three other packages are rated High severity.
Upgrading is strongly recommended to eliminate these vulnerabilities.
π¦ How to Upgrade
# Pull latest images and restart services (recommended)
docker compose pull && docker compose up -d