Skip to content

Release v1.1.2 - Security Fixes and Code Style Cleanup

Choose a tag to compare

@williamzujkowski williamzujkowski released this 02 Aug 15:26
· 25 commits to main since this release
8f173b1

🛡️ Security Improvements

  • Fixed CVE-2025-4517 (tarfile path traversal vulnerability)
  • Fixed CWE-502 (pickle deserialization vulnerability)
  • Implemented SecureTarExtractor for safe archive handling
  • Replaced pickle with HMAC-signed JSON serialization
  • All HIGH severity security issues resolved

🎨 Code Quality

  • Applied comprehensive code style fixes across entire codebase
  • Modernized Python type annotations
  • Enforced consistent formatting with Black, Ruff, Prettier
  • Added pre-commit hooks for automatic formatting

🚀 CI/CD Improvements

  • Fixed security scanning workflow
  • Simplified documentation build process
  • Excluded test directories from security scans
  • All CI checks now passing

📊 Stats

  • Security issues: 8 → 0 HIGH severity
  • Style violations: ~2,178 → 0
  • CI status: ✅ All green