All news

Targeted security pass — advisories patched, CI hardened

Another maintenance week. We took a focused look at known advisories in our dependencies and patched what we could without breaking API or UI compatibility — a second security pass in as many weeks.

What we did

Why this matters for customers

A dependency with a known advisory sitting in production is a liability we'd rather not carry. This week we cleared several without waiting for the next major release cycle. We run this check weekly, patch what's safe to patch, and document anything that needs a larger coordinated upgrade for a later sprint.

There's no action required from you. If something is coming that will need your attention — an agent update, a new feature that requires opt-in — we'll say so clearly in advance.

For IT administrators

The Trust Center publishes our full software bill of materials on every release. It lists the exact library versions running in production — always up to date, always linkable in your compliance records.