Skip to content

v0.117.2

Choose a tag to compare

@fro-bot fro-bot released this 05 Oct 04:12
· 96 commits to release since this release

What's new

Security

The bundled Systematic plugin update includes fixes for multiple denial-of-service and unsafe-input issues, including malformed TOML parser hangs, vulnerable brace expansion, YAML merge-source processing, and devalue serialization. The update also includes a fix that keeps workflow-guard markers stable across requests. #1694

Documentation

Gateway operators and maintainers can now find the ingress trust policy in the architecture and structure guides, including how trusted proxies are configured and how forwarded addresses and host/protocol data are interpreted. The docs also cover the OAuth source-key mismatch bounce and the rule against guessing unauthenticated operator-surface client identities. #1697

The setup guide now explains that OMO Slim 2.2.25 is the default while the separate compatibility gate still accepts only version 1.1.1, and clarifies the stock OpenCode fallback. #1693

Full changelog

0.117.2 (2026-10-05)

Build System

Documentation

Continuous Integration

  • deps: update bfra-me/.github action to v4.35.0 (#1689) (a85427d)