Security patch release. Closes 8 open code-scanning alerts (1 HIGH-severity Fastify body-schema bypass + 4 medium-severity DOMPurify sanitization issues + 1 GitHub Actions shell-injection vector + 2 transitive hono/postcss vulnerabilities) and 6 Dependabot security advisories. Also adds a small TRaSH Guides feature (migration notices for upstream CF-group restructures) and removes a class of spurious diagnostic warnings. No schema or API breaking changes.
🔒 Fixed
- Fastify body schema validation bypass via leading-space
Content-Type— CVE-2026-33806 (HIGH). Fastify 5.3.2–5.8.4 mishandledContent-Typeheaders with leading whitespace, allowing requests to skip body schema validation. Bumped to fastify 5.8.5 (#363). - DOMPurify sanitization bypasses (4 CVEs) — CVE-2026-41238/41239/41240 + GHSA-39q2-94rc-95cp covered `SAFE_FOR_TEMPLATES` bypass in `RETURN_DOM` mode, `FORBID_TAGS` bypass via function-form `ADD_TAGS`, prototype pollution → XSS via `CUSTOM_ELEMENT_HANDLING` fallback, and `ADD_TAGS` short-circuit evaluation. Bumped to dompurify 3.4.1 (#363).
- Hono JSX HTML injection in SSR (transitive) — GHSA-458j-xx4x-4375. Updated `pnpm.overrides` to require hono ≥4.12.14 (#369).
- postcss CVE-2026-41305 (transitive) — Pulled in by `next@16.2.4` which hardcodes the vulnerable version. Added `pnpm.overrides` entry pinning all sub-8.5.10 resolutions to 8.5.10 (#369).
- GitHub Actions shell-injection vector in release workflow — `${{ github.ref_name }}` used directly inside a `run:` block in `docker-combined.yml` could allow a maliciously crafted tag to inject arbitrary commands. Refactored to use `env:` block pattern (#368).
- Spurious schema-drift warnings on per-file TRaSH fetch — Per-item validation calls were misreporting sparse upstream fields as drift on every poll. Added `skipFingerprint` option + single batch fingerprint after each loop (#365).
✨ Added
- TRaSH Guides migration notices — When an upstream CF-group is restructured (e.g., the recent split of `[Optional] Miscellaneous` → `[Unwanted] Unwanted Formats`), the template diff modal now surfaces an informational notice. Notices fire on both live diff and historical-changelog paths, and are suppressed once the migration is complete. Reusable registry mechanism: future restructures only need a registry entry (#364).
- `trash_regex` declared in TRaSH custom-format schema — Long-standing upstream field on ~20 custom formats now properly typed instead of passing through `z.looseObject()` unmodeled (#367).
🔧 Changed
- Removed redundant `console.*` calls in TRaSH Guides web surface — 22 calls cleaned up across 13 files. Intentional diagnostic calls preserved (#366).
- Lint hygiene: 9 unused-imports warnings cleared — `catch (err)` parameters underscore-prefixed; ESLint config extended with `caughtErrors: "all"` + `caughtErrorsIgnorePattern: "^_"` (#371).
📦 Dependencies
- Production (23 packages) — `knip` 6.4→6.7, `@prisma/*` 7.7→7.8, `@tanstack/react-query` 5.99→5.100.5, `next` 16.2.3→16.2.4, `lucide-react` 1.8→1.11, `react-hook-form` 7.72→7.74, `postcss` / `tailwindcss` 4.2.2→4.2.4, others (#363).
- Dev (3 packages) — `@biomejs/biome` 2.4.11→2.4.13, `typescript`, `vitest` (#362).
- Trivy scan timeout 5m → 20m — Default 5-minute timeout consistently failed analyzing `@prisma/config@7.8.0` after the Prisma 7.8 bump. Applied to both `docker-dev.yml` and `docker-combined.yml` (#370).
Full Changelog: v2.16.1...v2.16.2