Skip to content
This repository was archived by the owner on Apr 8, 2026. It is now read-only.

v3.2.0 — Security Hardening & Angular 21

Choose a tag to compare

@thejuran thejuran released this 26 Mar 00:19
· 59 commits to master since this release

🔒 Security Hardening

  • Path traversal guards — realpath-based validation prevents directory traversal attacks
  • Config file permission hardening — config files locked to 0600 on write
  • SSH topology redaction — sensitive SSH connection details stripped from API responses
  • API token config field — new api_token field with automatic redaction in config API
  • Webhook payload size cap — prevents oversized webhook payloads
  • Startup security warnings — alerts on insecure configuration at launch
  • Restart endpoint CSRF fix — restart endpoint changed from GET to POST
  • Secure temp files — replaced insecure tempfile.mktemp with NamedTemporaryFile
  • Resolved 13 dependency security alerts (Dependabot)
  • Resolved undici CVE via npm override

⬆️ Angular 21 Migration

  • Upgraded Angular 19 → 21 with full dependency refresh
  • Migrated to application builder (esbuild)
  • Added change detection waits for esbuild builder in E2E tests

🐛 Fixes

  • First-run SSH timeouts are now recoverable instead of fatal
  • Fixed race condition in extract integration tests

🔧 CI/CD

  • Dependabot config tuned to ignore minor+ bumps for webpack, TypeScript, and zone.js
  • Migrated to application builder to fix Karma test hang in Docker

Full Changelog: v3.1.2...v3.2.0