DockFlare v2.1.6 - Security Hardening & The Dawn of Animated Logos #208
ChrispyBacon-dev
announced in
Announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
This release bundles security enhancements from v2.1.6 with the feature and bug fixes from the previously unreleased v2.1.5.
The security vulnerabilities were identified by GitHub's automated Dependabot and code scanning services.
What's New
It's time to start thinking in tunnels. The old DockFlare logo has been retired and replaced with a brand new animated version in the web UI.
Security (v2.1.6)
This release resolves several security issues to harden the application and its deployment pipeline.
brace-expansion
npm package by updating it to version 2.0.2, addressing a CVE related to inefficient regex./help/<path:page>
route was hardened against path traversal attacks by implementing stricter path validation usingos.path.abspath
.next
parameter, preventing redirects to external, malicious sites./cloudflare-ping
,/debug
, and/api/v2/debug-info
endpoints.contents: read
.Features & Fixes (from v2.1.5)
How to Upgrade
docker pull alplat/dockflare:stable
As always, thank you for using DockFlare and for your feedback!
Cheers, Chris
This discussion was created from the release DockFlare v2.1.6 - Security Hardening & The Dawn of Animated Logos.
Beta Was this translation helpful? Give feedback.
All reactions