You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Community Resources on the Hall of Fame page. A new section lists courses, talks, videos and articles that the community has built on OopsSec Store. Entries are sorted newest first and show the author and publication date. The list lives in hall-of-fame/community-resources.json. @kOaDT
Security
The Docker lab no longer restarts on its own. The restart: unless-stopped policy has been removed from docker-compose.yml, so the vulnerable app stays down after a host reboot or a Docker daemon restart until you start it again. If you run the lab with Docker, start it with npm run docker:up after a reboot. Your progress is kept in the Docker volumes. @kOaDT
Improvements
Smaller Docker image. The image now uses a multi-stage build. The runtime image holds only production dependencies, without the native build toolchain, the Cypress binary or the Next.js build cache. Local tooling directories are excluded from the build context, so a locally built image matches the published one. Dev tooling such as Jest, ESLint and Cypress is no longer available inside the container. @kOaDT
Docker startup fails fast on a missing package. The entrypoint used to download a missing package from the registry during the first-run database setup. It now stops with an error instead. tsx and dotenv, which the seed and the Prisma config need at runtime, are now runtime dependencies. @kOaDT
Documentation. The About page on the docs site now matches the README pitch. @kOaDT
Bug Fixes
Accurate Juice Shop comparison. The README comparison table now describes Juice Shop's CTF mode (opt-in, per-instance flags via CTF_KEY, CTFd/RootTheBox/FBCTF export) and its CVE coverage (vulnerable npm dependencies) correctly. The table was re-checked against Juice Shop's current documentation in September 2026. @mahatsafa
Maintenance / Chore
CI smoke test for the Docker image. CI now starts the image with no network access and waits for the database to initialize and the API to respond. A package missing from the image now fails CI. The Docker workflow also runs when .dockerignore changes. @kOaDT
CI dependency. Bumped cypress-io/github-action from 7.4.4 to 7.4.6.