Skip to content

v0.5.0 - Security Update & Russian Bot Shield

Latest

Choose a tag to compare

@weby-homelab weby-homelab released this 26 Jun 19:01
· 12 commits to master since this release
681073a

This release contains dependencies updates and a comprehensive June 2026 anti-spam, anti-scam, and anti-Russian aggression dictionary to protect Ukrainian chats.

What's New:

  1. Resolved Dependabot Security Alerts:
    • Upgraded aiohttp to 3.14.1 (patches various request smuggling and memory issues).
    • Upgraded pydantic-settings to 2.14.2 (patches symbolic link local file read vulnerability).
  2. June 2026 Ukrainian Chat Protection Dictionary:
    • Blocked fake military/charity payout scams (UN, Red Cross, єПідтримка).
    • Blocked Russian aggression keywords, insults, and military narratives.
    • Blocked crypto scams and spam remote job keywords.
  3. Smart DB Seeding & Normalization:
    • Added incremental database seeding logic (avoids overwriting custom settings while introducing new default keywords).
    • Upgraded heuristic normalization including homoglyph mapping (anti-obfuscation) and noise removal.