·
41 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Security patch release closing four High-severity reports:
- GHSA-jpmx-7xh3-vq6v: confine local image reads in vision modules.
- GHSA-675h-j4qg-m52x: enforce dangerous permissions in nested Warroom/test steps.
- GHSA-r3jp-qf98-23v8: make browser SSRF policy operator-controlled.
- GHSA-x2qh-79wh-6w7j: confine email attachments and guard SMTP/IMAP hosts.
Also expands registry-wide filesystem and outbound boundary coverage to beta and experimental modules.