3.98.4-beta.0 (2026-08-02)
Bug Fixes
- security: backup/restore hardening — public-dir DB dump, restore path allowlist, gunzip bound, manifest keying (#956) (0d4c308)
- security: bound inbound-mail resources, redact secrets from logs (GHSA-2qf9, pgmp, r794) (#959) (1b4e5fe)
- security: enforce event ownership on the v1 API surface (GHSA-9697) (#957) (e2ce95e)
- security: escape brand tokens, block tracker redirects, trim logo diagnostic (GHSA-j347, mw76, 29vm) (#961) (164129b)
- security: scope dashboard stats/analytics/activity to the caller's events (GHSA-c2jj, gqx7, jhcf) (#958) (da855cf)