Repository navigation
v1.1.2
Bug-fix + security release.
Fixed
- ntfy push notifications now work again. A U+2014 em-dash in the hardcoded
CookTrace —title prefix was silently failingfetch()header validation, dropping every ntfy notification since v1.1.0. Titles now arrive intact with em-dash and emoji preserved. Thanks to @clifmo (PR #35) for the diagnosis and RFC 2047 implementation.
Changed
- Default host port in the reference
docker-compose.ymlis now3003(was3000). Family sequence: NT3001, LT3002, CT3003, all off:3000. Existing installs are unaffected — container-side port unchanged; only new copy-paste installs use the new default. - Open Food Facts barcode lookup migrated to the current v3 endpoint (OFF deprecated v0/v2). Search continues on search-a-licious.
- Micronutrient units display as
mcginstead ofµgfor supplement-label / FDA consistency.
Added
- Docker Hub mirror. Images now publish to both
ghcr.io/traceapps/cooktrace(primary) andtraceapps/cooktraceon Docker Hub. Identical multi-arch tag set (:latest+:dev). - Claude Opus 5 and Claude Fable 5 available in the AI model picker.
Security
- undici 7.19.0 → 7.29.0 (1 HIGH + 4 MEDIUM: cache-directive info disclosure, retry-interceptor response desync, cookie-attribute injection, Cache-Control directive info disclosure, CRLF injection via blob-type).
- fast-uri 3.0.1 → 3.1.5 (HIGH: host confusion via backslash authority introducer).
- nanoid → 3.3.17 (HIGH: infinite loop when custom generator size is zero).
Docker
services:
cooktrace:
image: ghcr.io/traceapps/cooktrace:latest # or traceapps/cooktrace:latest
container_name: cooktrace
ports:
- "3003:3001"
volumes:
- ./data/db:/data/db
- ./data/uploads:/data/uploads
environment:
JWT_SECRET: change-me-to-a-long-random-string
DB_PATH: /data/db/cooktrace.db
UPLOADS_PATH: /data/uploads
restart: unless-stoppedFull CHANGELOG: https://github.com/traceapps/cooktrace/blob/main/CHANGELOG.md