This repository was archived by the owner on Apr 8, 2026. It is now read-only.
v3.2.0 — Security Hardening & Angular 21
🔒 Security Hardening
- Path traversal guards — realpath-based validation prevents directory traversal attacks
- Config file permission hardening — config files locked to
0600on write - SSH topology redaction — sensitive SSH connection details stripped from API responses
- API token config field — new
api_tokenfield with automatic redaction in config API - Webhook payload size cap — prevents oversized webhook payloads
- Startup security warnings — alerts on insecure configuration at launch
- Restart endpoint CSRF fix — restart endpoint changed from GET to POST
- Secure temp files — replaced insecure
tempfile.mktempwithNamedTemporaryFile - Resolved 13 dependency security alerts (Dependabot)
- Resolved undici CVE via npm override
⬆️ Angular 21 Migration
- Upgraded Angular 19 → 21 with full dependency refresh
- Migrated to application builder (esbuild)
- Added change detection waits for esbuild builder in E2E tests
🐛 Fixes
- First-run SSH timeouts are now recoverable instead of fatal
- Fixed race condition in extract integration tests
🔧 CI/CD
- Dependabot config tuned to ignore minor+ bumps for webpack, TypeScript, and zone.js
- Migrated to application builder to fix Karma test hang in Docker
Full Changelog: v3.1.2...v3.2.0