Skip to content

v1.1.3

Choose a tag to compare

@solarDev177 solarDev177 released this 19 Apr 08:16
· 33 commits to main since this release
Patches:

Hardened the app updater so GitHub release downloads must come from trusted HTTPS GitHub hosts, and asset filenames are sanitized before saving.

Replaced unsafe zip extraction in the updater with a guarded extraction path that blocks path traversal outside the temporary update folder.

Tightened the Cloudflare API client so bearer-token requests are only configured over HTTPS, removing the unnecessary plain-HTTP adapter mount.

Cleaned up token_store.py by renaming one-character variables to descriptive names and adding a best-effort restrictive file-permissions step after saving encrypted tokens.

Backout process: rollback to last version

Risk: low