Skip to content

Release v3.0.6 - #178

Merged
silverbucket merged 2 commits into
masterfrom
release/v3.0.6
Aug 12, 2026
Merged

silverbucket merged 2 commits into
masterfrom
release/v3.0.6

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

🚀 Automated Prepare Release v3.0.6

This PR contains the version bump for release v3.0.6.

✅ Release Steps Completed

  • Tests & linting passed
  • Project built successfully
  • API documentation generated
  • Demo page updated and tested
  • Release notes generated in

✏️ Edit Release Notes

You can edit the release notes for this version in the file in this PR to curate the changelog before merging.

📋 Pending Steps (on PR merge)

  • 🏷️ Git tag creation - will happen automatically via GitHub Actions
  • 📋 GitHub release creation - will use edited notes from
  • 📦 NPM publishing - will happen automatically via GitHub Actions

🔗 Release Links


🚀 Generated with automated release workflow

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review

Outcome: no medium, high, or critical findings.

Reviewed the release diff (package.json / changelog / demo version bump, docs refresh, and dist/ rebuild). The security-relevant change packages the already-merged IPv4-mapped / IPv4-compatible IPv6 SSRF hardening into published artifacts.

Validated private-address blocking for mapped forms such as ::ffff:127.0.0.1, ::ffff:7f00:1, ::127.0.0.1, ULA/link-local/multicast IPv6, and 0.0.0.0/8. No dependency or lockfile changes; no secret leakage in the touched files.

No prior unresolved automation review threads on this PR.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@silverbucket silverbucket reopened this Aug 12, 2026
@silverbucket silverbucket self-assigned this Aug 12, 2026

@cursor cursor Bot left a comment •

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Security review

Outcome: no medium, high, or critical findings.

Re-reviewed the full release diff after the latest synchronize (changelog advisory link + prior version/docs/dist packaging of the IPv4-mapped IPv6 SSRF fix).

  • No prior unresolved automation finding threads to re-open.
  • Traced attacker-controlled hosts through normalizeHost → isPrivateAddress / mapped+compatible IPv6 parsing in the rebuilt dist/ bundles; mapped forms such as ::ffff:127.0.0.1 / ::ffff:7f00:1 are blocked as intended.
  • Zone-ID / malformed mapped spellings fail host parsing before fetch (not exploitable bypasses).
  • No dependency or workflow supply-chain changes beyond the package.json version bump.
  • Changelog advisory link is intentional disclosure of the fixed issue, not a secret leak.
Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security review

Outcome: no medium, high, or critical findings.

Re-reviewed the full release diff through 8320974 (version bump, changelog/advisory link, docs/demo updates, and dist/ rebuild packaging the IPv4-mapped / IPv4-compatible IPv6 SSRF hardening from GHSA-fwvw-2r88-m4cv).

Validated that exploitable mapped forms (::ffff:127.0.0.1, ::ffff:7f00:1, expanded equivalents) and related private ranges (0.0.0.0/8, ::/::1, ULA/link-local/multicast IPv6) are blocked by the shipped isPrivateAddress logic. No dependency/lockfile changes and no secret leakage in touched files.

No prior unresolved automation review threads on this PR.

Open in Web View Automation 

Sent by Cursor Automation: Find vulnerabilities

@silverbucket
silverbucket merged commit a17d313 into master Aug 12, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants