Skip to content

CVForge 1.3.1 — security update

Latest

Choose a tag to compare

@gdberysan gdberysan released this 17 Sep 09:24

Security update — please upgrade from 1.3.0.

  • Next.js 16.3.0 → 16.3.5: fixes two critical remote-code-execution advisories (the image optimizer with AVIF files, and servers running on Windows, which the Windows launcher is).
  • sharp 0.35.3 → 0.35.4: fixes the libheif vulnerabilities it bundles.

No other changes. Your data folder (datos/) carries over: copy it into the new folder.

Try it first without installing: cvforge.korven.dev (sample data, no key).

Install

  1. Download cvforge-v1.3.1.zip below and check it: shasum -a 256 -c checksums.txt
  2. Unzip it, then double-click CVForge (macOS) or CVForge (Windows). On Linux: ./programa/start.sh (Node.js 20+).
  3. It opens at http://localhost:3000 and asks for your Anthropic API key.

One zip for every system: the macOS (Apple Silicon and Intel) and Windows Node runtimes ship inside, so nothing gets installed on your system.

macOS: the app isn't notarized yet. If macOS blocks it, open System Settings → Privacy & Security and click Open Anyway (macOS 15+), or right-click → Open (macOS 14 and earlier).

Windows: the launcher hasn't been tested on a physical Windows machine yet. Reports welcome.

Full notes: CHANGELOG.md.