Bender v0.1.1-1 (Security Update)
·
7 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Critical Security Release
This release addresses critical vulnerability vectors and implements hardened rules.
Changes in v0.1.1-1:
- Security Updates: Remediated remote command injection vulnerabilities inside Network Toolkit (dig/whois) and Proxy Manager (domain blocklist insertion).
- Hardened Subprocess Calls: Completely eliminated unsafe
shell=Truebash invocation in background jobs; adopting strict array argument execution. - Enhanced Accountability: Added robust application-wide logging to
~/.local/state/bender/bender.logfor operations auditing. - Rule Adherence: Updated copyright references and metadata to enforce new
chuck@nordheim.onlinecredentials across all control configurations.