Security patch release
Fixes
- Bumps
follow-redirects1.15.6 → 1.16.0 (#45)- Closes the open Dependabot alert "follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets" (medium severity)
- Upstream fix adds a
sensitiveHeadersoption and input sanitization follow-redirectsis a dev-only transitive dependency; no runtime behavior changes
Notes
- Everything in v0.24.4 is included.
flake.nixnpmDepsHashupdated for the new lockfile.
This release exists because v0.24.4 was tagged before the security fix landed on development.