github greenpau/caddy-security v1.1.64

12 hours ago

Changelog

go-authcrunch changes

github.com/greenpau/go-authcrunch was updated from v1.1.40 to v1.1.41.

Compare: greenpau/go-authcrunch@v1.1.40...v1.1.41

  • ops: add indicator to release commit subject (646004f)
  • security: harden authz bypass path matching (c320a62)
  • skills: add threat hunting workflow (d0224bf)
  • security: prevent prefixed API key creation hang (65b492e)
  • security: avoid session cache deletion under read lock (95415a0)
  • security: harden profile API request parsing (89beb23)
  • security: canonicalize authz request paths (87d594b)
  • skills: expand threat hunting and sandbox test guidance (b2625d4)
  • authn: cap system API request body reads (f80387d)
  • authz: isolate token cache user state (4f1fd2a)
  • skills: classify stdlib vulns as toolchain notes (f71eec3)
  • oauth: verify access token JWTs before merging claims (7f5d3d8)
  • skills: add threat hunt report TOC guidance (45cab9b)
  • skills: clarify forwarded IP threat hunt guidance (47fe4cd)
  • redirects: require same rule for trusted redirect matches (7b9002e)
  • security: validate OAuth JWT issuer and audience claims (429779c)
  • breakfix: restore Azure OAuth login with resource tokens (bb0b253)
  • ops: released v1.1.41 (9740809)

Don't miss a new caddy-security release

NewReleases is sending notifications on new releases.