3.134.2 (2026-10-08)
Bug Fixes
- analytics: isolate telemetry from application credentials (stable) (#1857) (88df84d)
- auth: harden client links and transfer upload codes (stable) (#1846) (f444238)
- auth: protect account recovery secrets at rest (#1849) (fed4ec4)
- backup: authenticate standard recovery manifests (stable) (#1864) (78077d3)
- backup: create complete standalone restore points (stable) (#1860) (5e89b2b)
- backup: pin rsync SSH destinations and require approved host keys (stable) (#1869) (0418c15)
- db: verify PostgreSQL TLS across pools and native clients (stable) (#1853) (74ac75f)
- deps: close the six open Trivy findings (stable) (#1842) (6d4ef05)
- enforce gallery original-asset authorization (#1879) (e076618)
- installer: verify pinned bootstrap scripts before execution (stable) (#1862) (67ed33b)
- mail: bind SMTP and IMAP connections to vetted DNS answers (stable) (#1873) (576e8aa)
- mail: bound retained intake bytes and lifecycle (#1886) (bd63a3c)
- scope external media sources to their owners (stable) (#1881) (720980e)
- security: enforce CRM document ownership (stable) (#1885) (09372a3)
- security: tighten production network and cookie defaults (stable) (#1851) (2b6f6a5)
- stable: bound public upload ingress and lifetime capacity (#1874) (fb6567d)
- upload: bound authenticated upload admission (stable) (#1877) (a64defc)
- workflows: enforce owner scope on execution data (stable) (#1844) (2b3fdba)