What's Changed
- chore: upgrade brace-expansion to ^5.0.8 to address CVE-2026-14257 by @brendan-kellam in #1527
- chore: upgrade golang.org/x/text to v0.39.0 to address CVE-2026-56852 by @brendan-kellam in #1535
- chore: upgrade tar to ^7.5.22 to address CVE-2026-59874 and GHSA-r292-9mhp-454m by @linear-code[bot] in #1472
- fix(backend): match GitLab topics case-insensitively by @DivyamTalwar in #1393
- chore: add lint:fix script for ESLint auto-fixes by @var-raphael in #1510
- fix(web): return graceful error for unknown search context by @rachit367 in #1362
- fix(query-language): don't treat dash before a non-prefix colon word as negation by @devteamaegis in #1301
- fix: handle Ask GitHub rate limits by @brendan-kellam in #1476
- chore(web): resolve outstanding ESLint warnings by @brendan-kellam in #1537
- fix(review-agent): fetch private GitHub PR diffs via API by @BashOpsDev in #1352
- chore: remove langfuse integration by @brendan-kellam in #1536
- chore: automate CVE remediation by @brendan-kellam in #1538
- fix: pass reusable workflow input from event by @brendan-kellam in #1539
- chore: upgrade ip-address to ^10.4.0 to address CVE-2026-54272, CVE-2026-69192, CVE-2026-69198 by @claude[bot] in #1540
- chore: upgrade fast-uri to ^3.1.5 to address CVE-2026-18446 by @claude[bot] in #1541
- chore: upgrade socket.io-parser to ^4.2.7 to address CVE-2026-69185 by @claude[bot] in #1542
- chore: upgrade postcss to ^8.5.25 to address CVE-2026-69153 by @claude[bot] in #1543
- chore: upgrade hono to ^4.13.0 to address CVE-2026-69207 by @claude[bot] in #1544
- fix: support MCP JSON Schema dialects by @jsourcebot in #1547
- feat(web): recover from MCP connector authentication failures by @jsourcebot in #1548
- chore: upgrade js-yaml to ^4.3.1 to address GHSA-5p4m-2wfm-xmqj by @claude[bot] in #1552
- chore: update reo-census to 1.2.10 by @msukkari in #1554
- fix: allow bot-triggered license audits by @brendan-kellam in #1559
- chore: upgrade mermaid to ^11.16.1 to address CVE-2026-50159, CVE-2026-71436, CVE-2026-71437, CVE-2026-71438, CVE-2026-71439 by @claude[bot] in #1555
- chore: upgrade dompurify to ^3.4.13 to address GHSA-55q2-fjhq-7xh7 by @claude[bot] in #1556
- chore: upgrade nanoid to ^3.3.18 to address CVE-2026-67213 by @claude[bot] in #1557
- chore: automate Zoekt submodule sync by @brendan-kellam in #1560
- fix: use release app for Zoekt sync by @brendan-kellam in #1561
- fix: scope Zoekt changelog updates to Unreleased by @brendan-kellam in #1563
- chore: update bundled Zoekt by @sourcebot-release-bot[bot] in #1564
- fix(web): support ports in chat file references by @brendan-kellam in #1565
New Contributors
- @DivyamTalwar made their first contribution in #1393
- @var-raphael made their first contribution in #1510
- @rachit367 made their first contribution in #1362
- @devteamaegis made their first contribution in #1301
- @BashOpsDev made their first contribution in #1352
- @claude[bot] made their first contribution in #1540
- @sourcebot-release-bot[bot] made their first contribution in #1564
Full Changelog: v5.1.5...v5.1.6