chore(release): v1.1.1 - #24
Merged
Merged
Conversation
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Automated release PR for v1.1.1, prepared by the Prepare Release workflow.
Merging this PR triggers the Publish Release workflow, which tags
mainwith
v1.1.1and runs the Release workflow (Docker images + GitHub Release).Changelog
[1.1.1] - 2026-09-30
Security
nodemailer9.1.1 → 10.0.12 — fixes a quadratic-timeaddressparserfree-textfallback that allows remote denial of service
(GHSA-v53p-9fqp-m79j), a
process-global DNS cache that reuses the TLS
servernameacross transports and soenables cross-tenant SMTP credential disclosure
(GHSA-6vj9-mwq6-2f5v), nested
structured recipient arrays that bypass the parser depth limit and exhaust the stack
(GHSA-8vvx-rff5-p5rq), and a
quoted local-part that can produce a malformed envelope recipient through RFC 5322
comment parsing
(GHSA-g57g-f23g-4646)
multer2.3.0 → 2.4.0 — fixes a denial of service via orphaned disk writes onaborted uploads
(GHSA-3pph-fpjx-jg34)
undici8.10.0 → 8.10.2 — fixes three high-severity issues: a denial of service viaan unrequested WebSocket subprotocol
(GHSA-rfgv-xxqx-mfg5), a TLS
certificate validation bypass via dropped connect options in
BalancedPool(GHSA-w293-vg96-wgc3), and
cross-origin cache poisoning via missing origin isolation in interceptors
(GHSA-vp8m-p9jh-q5pm); five
moderate issues: denial of service via an unhandled error in WebSocket
permessage-deflatedecompression(GHSA-3wwx-pv8p-q78v), via an
orphaned
RetryHandlerresponse body(GHSA-pmjh-fq2x-6v4x), and via
unbounded decompression of compressed responses
(GHSA-3xpg-4rpp-hhhm),
cross-user cookie disclosure via
Set-Cookiecaching in shared caches(GHSA-2jfj-6hjv-fm6j), and
denial of service via an unclean
WebSocketStreamclose(GHSA-rx4f-c7p8-82vq); and three
low-severity issues: downstream response splitting via the retry interceptor
(GHSA-r53p-7pc4-xj5r), response
truncation via oversized chunked responses in the dump interceptor
(GHSA-2gqq-gqf2-x968), and
caching/replay of unsafe HTTP method responses
(GHSA-8436-99hf-9mmv). It is
pulled by
jsdom(the vitest DOM environment), which declares^8.9.0, and is pinnedby a pnpm override
brace-expansion5.0.9 → 5.0.12 — fixes two stack-exhaustion denial-of-service issuesvia uncontrolled recursion
(GHSA-qhr7-859c-m2p7,
GHSA-6j4f-fj2g-mc7p) and a
quadratic-time CPU denial of service in the
{a},b}rewrite(GHSA-q2hr-2g5m-vwhr). It is
pulled by
minimatchthrough the eslint andrimraf > globtoolchains and is pinnedby a pnpm override
fast-uri3.1.7 → 3.1.8 — fixes inconsistent host-case normalization viapercent-encoded octets
(GHSA-hrr3-gc8f-f4qj). It is
pulled by
ajvthrough the Prisma CLI and stylelint toolchains and is pinned by a pnpmoverride
ip-address10.7.0 → 10.7.2 — fixes an allow-list bypass whereisInSubnet()/isHostInSubnet()compare addresses of different families as if they shared anaddress space
(GHSA-j6r3-76f7-8jcv) and an
unbounded parse diagnostic that can stall or crash the process
(GHSA-h3mg-xc3c-68pw). It is
pulled by
express-rate-limit, which declares^10.2.0, and is pinned by a pnpmoverride
Review checklist
package.json,packages/backend/package.json,packages/frontend/package.json)pnpm cipasses on this branch