Skip to content

Security Release — v3.4.0

Latest

Choose a tag to compare

@thalha-a9 thalha-a9 released this 04 Jun 19:12

Security Release — v3.4.0

Addresses 11 security issues reported by the community.

Fixed: SSL/TLS (#1), path traversal (#2), Sherlock integrity (#3),
MD5→SHA256 (#4), pinned deps (#5), KeyboardInterrupt (#7),
_check_deps at import (#8), XSS in report (#10), D3 SRI (#11),
stale repo in install.sh (#13), response body cap (#14)

False positive fixes:

  • Default avatar pHash filtering (Mastodon silhouette = 25 fake 99% matches → now 0)
  • NSFW platforms excluded by default (--nsfw flag to include)
  • Hidden output directory fixed (.rxzikhx. → rxzikhx_)
  • 80+ Russian/obscure forums and dead sites added to blocklist

Full details: CHANGELOG.md