Skip to content

v1.9-20260304

Latest

Choose a tag to compare

@collinschreyer-dev collinschreyer-dev released this 04 Mar 20:05
· 0 commits to main since this release
55686d2

Security Fixes

  • CVE-2026-2391 (CISA KEV / SNYK-JS-QS-15268416): Upgraded express to 4.22.1 and pinned qs to 6.14.2 to remediate Allocation of Resources Without Limits or Throttling vulnerability (CVSS 8.2 High)
  • Pen test remediations: Added HSTS header, restricted CORS origins, removed server version disclosure (#203)
  • CI/CD hardening: Replaced flaky CF CLI Debian install with direct binary download + retry (#204)

Features

  • Manual solicitation compliance check API (#198#201)
  • Agency/office filtering for predictions (#193)

Dependency Changes

Package Before After
express 4.21.1 4.22.1
qs 6.13.0 6.14.2