Skip to content

Bender v0.1.1-1 (Security Update)

Choose a tag to compare

@TaliskerMan TaliskerMan released this 27 Mar 10:57
· 7 commits to main since this release
Immutable release. Only release title and notes can be modified.

Critical Security Release

This release addresses critical vulnerability vectors and implements hardened rules.

Changes in v0.1.1-1:

  • Security Updates: Remediated remote command injection vulnerabilities inside Network Toolkit (dig/whois) and Proxy Manager (domain blocklist insertion).
  • Hardened Subprocess Calls: Completely eliminated unsafe shell=True bash invocation in background jobs; adopting strict array argument execution.
  • Enhanced Accountability: Added robust application-wide logging to ~/.local/state/bender/bender.log for operations auditing.
  • Rule Adherence: Updated copyright references and metadata to enforce new chuck@nordheim.online credentials across all control configurations.