1.1.6 - 2026-06-07
- TAG: v1.1.6
- COVERAGE: 89.05% -- 838/941 lines in 33 files
- BRANCH COVERAGE: 60.46% -- 159/263 branches in 33 files
- 40.38% documented
Changed
- Retemplated project workflows, appraisals, and development tooling with the
currentkettle-jemtemplate. - Documented current
OAuth::Consumerconfiguration options, including token
request redirect safety settings, and corrected the OAuth 1.0a usage example. - Raised the runtime dependency floor for
auth-sanitizerto>= 0.2.1. - Raised the runtime dependency floor for
snaky_hashto>= 2.0.5.
Security
- Hardened OAuth token endpoint redirect handling after the GHSA-pp92-crg2-gfv9
review: token redirects are now bounded, resolved explicitly, and rejected
when they cross origins unless explicitly enabled.
Many paths lead to being a sponsor or a backer of this project. Are you on such a path?