Skip to content

v2.22.0

Latest

Choose a tag to compare

@kOaDT kOaDT released this 07 Oct 20:23
· 3 commits to main since this release

What's New

  • Community Resources on the Hall of Fame page. A new section lists courses, talks, videos and articles that the community has built on OopsSec Store. Entries are sorted newest first and show the author and publication date. The list lives in hall-of-fame/community-resources.json. @kOaDT

Security

  • The Docker lab no longer restarts on its own. The restart: unless-stopped policy has been removed from docker-compose.yml, so the vulnerable app stays down after a host reboot or a Docker daemon restart until you start it again. If you run the lab with Docker, start it with npm run docker:up after a reboot. Your progress is kept in the Docker volumes. @kOaDT

Improvements

  • Smaller Docker image. The image now uses a multi-stage build. The runtime image holds only production dependencies, without the native build toolchain, the Cypress binary or the Next.js build cache. Local tooling directories are excluded from the build context, so a locally built image matches the published one. Dev tooling such as Jest, ESLint and Cypress is no longer available inside the container. @kOaDT
  • Docker startup fails fast on a missing package. The entrypoint used to download a missing package from the registry during the first-run database setup. It now stops with an error instead. tsx and dotenv, which the seed and the Prisma config need at runtime, are now runtime dependencies. @kOaDT
  • Documentation. The About page on the docs site now matches the README pitch. @kOaDT

Bug Fixes

  • Accurate Juice Shop comparison. The README comparison table now describes Juice Shop's CTF mode (opt-in, per-instance flags via CTF_KEY, CTFd/RootTheBox/FBCTF export) and its CVE coverage (vulnerable npm dependencies) correctly. The table was re-checked against Juice Shop's current documentation in September 2026. @mahatsafa

Maintenance / Chore

  • CI smoke test for the Docker image. CI now starts the image with no network access and waits for the database to initialize and the API to respond. A package missing from the image now fails CI. The Docker workflow also runs when .dockerignore changes. @kOaDT
  • CI dependency. Bumped cypress-io/github-action from 7.4.4 to 7.4.6.