Coop 1.0.2
This release addresses reported security advisories, improves NCMEC CyberTipline reporting, and includes front-end quality-of-life improvements.
Security
Note
For security announcements, we encourage adopters to subscribe to the security-announce@roost.tools mailing list.
- Routine dependency package upgrades to address vulnerabilities
This release also addresses three reported security vulnerabilities; see the following advisories for details:
- GHSA-2v93-383c-9fw2: SAML cross-tenant authentication bypass
- GHSA-mf74-gf5j-hxr9: Cross-org IDOR in addAccessibleQueuesForUser / removeAccessibleQueuesForUser
- GHSA-g5xq-67g7-36r2: Sessions are not invalidated on password reset
NCMEC
- Added
emailas a supported schema field role for user items, ensuring inclusion and validation for NCMEC reports (#840, #842) EMAIL_ADDRESSadded as a first-class scalar in@roostorg/coop-types(v2.4.0) (#841)- Auto-populate
originalFileName(from the media URL) andfileRelevance(defaults toReported) for NCMEC reports (#855) - Fixed
fileDetails.ipCaptureEventXSD element ordering (#856)
Review Console
- Added User Strikes count to job and item investigation views (#766)
- Added decision reasons to recent decisions view and CSV exports (#772)
- Split "require decision reason" into separate action and ignore settings (#780)
- Fixed duplicate entries in recent decisions (#774)
- Empty threads are no longer hidden (#804)
- Improved Review Console dashboard display by ellipsizing long queue IDs (#849)
- Improved moderator textarea placeholder for clarity (#711)
- Fixed content URL rendering in the review iframe when no content proxy is configured (#777)
Actions
- Parameterized actions now work with proactive rules and user strikes (#792)
- New per-queue "clear other reports for a user" sweep action; sweep now also handles related items (#817, #835)
- Added
creatorfield to action webhook callbacks (#755)
Investigations
- Added IP address lookup to investigation view (#754)
Other fixes
- Added client-side email validation for invites (#786)
- Express session store now properly closed on API shutdown (#825)
CI & infrastructure
- Server integration tests now run in CI (#827); basic Playwright E2E test suite added (#823)
- Server tests isolated via transaction rollback (#732)
- TypeScript type-checking added for
dbandmigratorin CI (#782) - Prettier enforced globally in CI (#834)
- GitHub Actions updated to Node 24 runtime (#795)
zizmoradded to lint CI workflows for security issues (#721)- Knip added across all packages to remove unused dependencies (#734, #760, #761, #762)
- Redis user/password now correctly set in no-cluster mode (#747)
New contributors
- @reitblatt made their first contribution in #785
- @jess-upscrolled made their first contribution in #804
- @ltianyi992 made their first contribution in #711
Full Changelog: 1.0.1...1.0.2