Security fixes
- Make the web UI safe by default: bind to loopback and reject remote HTTP and WebSocket clients unless authentication or an explicit opt-out is configured.
- Verify SSH host keys for native and AsyncSSH connections, with fingerprint confirmation and trust-only setup support.
- Update vulnerable dependencies and audit the locked production dependency set with uv audit in CI.
- Pin and checksum remotely vendored frontend assets and verify them during wheel builds.
- Keep the container password database read-only while supporting arbitrary runtime user IDs.
- Constrain registry update requests by validating request bodies, batch sizes, image inventory, and registry destinations.
- Shell-quote compose stack paths used in remote commands.
Maintenance
- Upgrade and pin GitHub Actions to current stable releases.
- Update the Traefik example to 3.7 and the Paperless Redis example to 8.
Full changelog: v1.22.0...v1.22.1