Repository navigation
Release v3.0.6 - #178
Release v3.0.6#178
Conversation
There was a problem hiding this comment.
Stale comment
Security review
Outcome: no medium, high, or critical findings.
Reviewed the release diff (
package.json/ changelog / demo version bump, docs refresh, anddist/rebuild). The security-relevant change packages the already-merged IPv4-mapped / IPv4-compatible IPv6 SSRF hardening into published artifacts.Validated private-address blocking for mapped forms such as
::ffff:127.0.0.1,::ffff:7f00:1,::127.0.0.1, ULA/link-local/multicast IPv6, and0.0.0.0/8. No dependency or lockfile changes; no secret leakage in the touched files.No prior unresolved automation review threads on this PR.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Stale comment
Security review
Outcome: no medium, high, or critical findings.
Re-reviewed the full release diff after the latest synchronize (changelog advisory link + prior version/docs/
distpackaging of the IPv4-mapped IPv6 SSRF fix).
- No prior unresolved automation finding threads to re-open.
- Traced attacker-controlled hosts through
normalizeHost→isPrivateAddress/ mapped+compatible IPv6 parsing in the rebuiltdist/bundles; mapped forms such as::ffff:127.0.0.1/::ffff:7f00:1are blocked as intended.- Zone-ID / malformed mapped spellings fail host parsing before fetch (not exploitable bypasses).
- No dependency or workflow supply-chain changes beyond the
package.jsonversion bump.- Changelog advisory link is intentional disclosure of the fixed issue, not a secret leak.
Sent by Cursor Automation: Find vulnerabilities
There was a problem hiding this comment.
Security review
Outcome: no medium, high, or critical findings.
Re-reviewed the full release diff through 8320974 (version bump, changelog/advisory link, docs/demo updates, and dist/ rebuild packaging the IPv4-mapped / IPv4-compatible IPv6 SSRF hardening from GHSA-fwvw-2r88-m4cv).
Validated that exploitable mapped forms (::ffff:127.0.0.1, ::ffff:7f00:1, expanded equivalents) and related private ranges (0.0.0.0/8, ::/::1, ULA/link-local/multicast IPv6) are blocked by the shipped isPrivateAddress logic. No dependency/lockfile changes and no secret leakage in touched files.
No prior unresolved automation review threads on this PR.
Sent by Cursor Automation: Find vulnerabilities


🚀 Automated Prepare Release v3.0.6
This PR contains the version bump for release v3.0.6.
✅ Release Steps Completed
✏️ Edit Release Notes
You can edit the release notes for this version in the file in this PR to curate the changelog before merging.
📋 Pending Steps (on PR merge)
🔗 Release Links
🚀 Generated with automated release workflow