Security
- security: resolve real path in QuickJS sandbox by @prateek-bruno in #9226
Local module paths are now resolved to their real path in the QuickJS runtime, preventing scripts from reaching files outside the intended location (e.g. via symlinks or path tricks). Credits to @wpframe for reporting this. - security: stop exposing
__brunoLoadLocalModuleto scripts by @prateek-bruno in #9277
Internal module loader is no longer accessible from user scripts, reducing the sandbox's attack surface. Credits to @wpframe for reporting this.
We recommend all users upgrade to this release.
Full Changelog: v4.2.0...v4.2.1