Security patch for the v1.7 line, clearing the findings the scheduled re-scan raised against v1.7.5.
Security
-
OpenSSL updated in the published images.
openssl,libssl3t64andopenssl-provider-legacymove from 3.5.7-1deb13u2 to 3.5.7-1deb13u3. Nothing in Terrapod changed — the fix arrives by rebuilding against the refreshed Debian base. The re-scan named the two HIGH advisories,CVE-2026-75804andCVE-2026-84782, but u3 clears 13 in total: alsoCVE-2026-35189,CVE-2026-35191,CVE-2026-42772,CVE-2026-54872,CVE-2026-54873,CVE-2026-54875,CVE-2026-72897,CVE-2026-75805,CVE-2026-75806,CVE-2026-77696andCVE-2026-84784. -
brace-expansionraised to 2.1.7, clearing three DoS advisories against 2.0.0–2.1.6:GHSA-6j4f-fj2g-mc7p,GHSA-q2hr-2g5m-vwhrandGHSA-qhr7-859c-m2p7. Stated plainly: this is a build-time dependency. It isdevin the lockfile and is not present in the publishedterrapod-webimage, so no released image ever carried it — the exposure was to the build, not to a running deployment.
An accepted risk was re-examined and kept: CVE-2025-69720 (ncurses infocmp) is still unfixed in Debian trixie, and the package is still present in the images, so there is nothing to bump to. Terrapod never invokes infocmp and no attacker-controlled terminfo reaches it.
Upgrading
Drop-in. No configuration, schema, API or wire changes; no migrations.
Status
Stable.
Full Changelog: v1.7.5...v1.7.6