From 92818294cf7969ad494ccc677deede40cf66760c Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Sun, 25 Jan 2026 23:18:34 +0000 Subject: [PATCH] chore(release): Update version to v1.4.395 --- CHANGELOG.md | 8 ++++++++ cmd/fabric/version.go | 2 +- cmd/generate_changelog/changelog.db | Bin 3817472 -> 3821568 bytes cmd/generate_changelog/incoming/1972.txt | 5 ----- nix/pkgs/fabric/version.nix | 2 +- 5 files changed, 10 insertions(+), 7 deletions(-) delete mode 100644 cmd/generate_changelog/incoming/1972.txt diff --git a/CHANGELOG.md b/CHANGELOG.md index 9e0333f6..d0645402 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,13 @@ # Changelog +## v1.4.395 (2026-01-25) + +### PR [#1972](https://github.com/danielmiessler/Fabric/pull/1972) by [ksylvan](https://github.com/ksylvan): More node package updates: remove cn, fix string and request vulnerabilities + +- Removed cn (Chuck Norris jokes) package to resolve security vulnerabilities +- Fixed 5 Dependabot alerts including ReDoS vulnerabilities in string package and SSRF/Remote Memory Exposure issues in request package +- Enhanced security posture by eliminating vulnerable dependencies with no available patches + ## v1.4.394 (2026-01-25) ### PR [#1971](https://github.com/danielmiessler/Fabric/pull/1971) by [ksylvan](https://github.com/ksylvan): Security fix high medium low priority dependabot alerts for npm dependencies diff --git a/cmd/fabric/version.go b/cmd/fabric/version.go index 576f8d6c..6d45e3bf 100644 --- a/cmd/fabric/version.go +++ b/cmd/fabric/version.go @@ -1,3 +1,3 @@ package main -var version = "v1.4.394" +var version = "v1.4.395" diff --git a/cmd/generate_changelog/changelog.db b/cmd/generate_changelog/changelog.db index 4d19bf08c4ebf1cda867048b4e6d228a4505d536..afafbceaa68246b66fe86c9321138faa4edd2d53 100644 GIT binary patch delta 5202 zcmcgweQXm-hIA3lE^Y)R+`Eo-JGX%T4>mWzE(uCedj zyK`C#DyQ367}Dt04!xTgwA+LjtAy5W;#58c1OAwh*cfR4Oo(;ekh(uWj8zDP_;_C1 z=cJwK+-l>GpK|fN@AE$I^ZcIY`PoZL?@>$V-lHCAuNiVU=f9hyczqH5 zXdU(2Gd~{KN&W63;~J`Kub*?0lV51agq+U$IsEoZ9UU)xQLnFE10SC~#owRKEvIvo zmCiZwcKUP9Be?dQGw*aBu^v33IBySWUBm%g z7XSga0(^jOz#V{XfbD=CmS@uck6+RsIR9J3AchZY&Fcjot0>tY2e=k{I?~N?}k&Zg9;@YJhI=;B%)bhg* zp6zf=JNar$r1r%M{Q!)#6C>4~nxE6~h@ZMl|8(#H=39=s&OvYMvclUpzQHll+xi$rWSB`d7U8D5ySveWF*Ml? z|Kax^j`36kFHO+>`4LT*k*XzRl#${K(wvO4nS^A@hKO`Itu4wZt_Dz2IgSidSJXKq zsR?*TFj_YyX^V#?Ux<}J>#Xv{21=;8+pJHlY z#n9-~qKsdDuC28P_U=)R%Lyc)U2;ZN6Vj|^A}J;7rhybSp2{Z3@nbTkHU^vV&%V6b zHCA%T_MEsjK0dZ*fH+~wXaxS~IkfwDMl-T-O~o+4Z7^28KxrqOy<44^)VPcvtiIy3khb!L@cQQY$8e05M$A&ukRfl)D z;k5h7x^LIMS=;A2LBDD>{l)bIdi-SXeHTRcbmyTR1A}$d)6dRzd>)b}lAvhd;~XLx z#-nfC5zdzgwUYf6vaRCUS9nXn+CX+H?F5!n z8bk-@fv1F(KuQA%ICw4AnHM^ z%4SD)@7i~0gcv3)F4|2J!=X@>s|#L4Z@Rd0ZQz&B?`Xw?AH??ic#(;SA-32(D)Ptb z+abQO`LV{D8poXu$DR1Xl9SJ$9Xu6U=Qz3Td{_H$%hAE@D5s=GOXdp;h5b zVtWf7x)N)mAj$8>I`V!Fk(>q)kL)Bs570?3BUB><&8k@gy3C_Id;k_)y%6n|LwZC~!SqH!84?^ydUV zdbqtMoU&Bjtk_3MO<(P7shbum34Hbf0VjdeHyqCk6^E<<*1@^{aRsK;SgCmSX!@KCP2NvRrU$>?O7&re6E`%5*$RH=9Tzi$L1(^?$YS${*2OS}+P#oqwxIrcdlrYSHJCoOy=)olVA2nL?rce^S zz56v#HAw~bmZTE#@-rGJgqe(*N%yDVeK04bQ>4_f)GThq?|*7jvruR!Qi=>Hfw7Cz zKuKLo7dp&pcXe4N1ncd^kHG#7MmCetbO;nVY9}a_IoZIYE#j8E*X?x^aW|%cTG}Z= zk3z$$l*$HR=IopRqBlxgbD+Y~(R3%C*ZYr=VhYD>FVn~{z zgr8{hctU8OiRPsQNoXK{*l8i!z6cDh?f!K^~TsK*2n@Uin~%L9zb_ zfWOdnA&Vp~g%D&ix|Y!upfPzTC*VoZ)F8%!*oprnh~8r2fp~?R6N(^zfhoX5!<16M zlY&vAeOGvaFAHKDZfFtfu`4WYYKJw10tRBr>@D522R}=WdX21~3ybgOxf?`jSY$)R zan4Hc8$%rQUQ~`ngb*)q;n}Dl#|4H>vQc?9%7>FtHWr)wl5c$Puut?=D-C@C--v7& z@cqFj;$KBXPri7iRb!}nWjLiysbeI}z#smf>x%rA#Nm`$=ER59;ZHU~ z`F*51oKmZohpX0Bp%2OGBPHcog+N?ooWCuFNX5j{`I0z14Ea7F>9T4XK5^0)N`#pt z7ZTV=IKf8Z5*LlnMiWc~ezW4?1sj%PTu4qZzUdPIn_1O<=U&Y$A3pmK+eDMEJ5ODW Y9sYdzSG?=pshYIYC#G*G74rS8_QjOqLf zY^AgFM%B#WZjDIg=Ni>OCY#S>5zAyTtsuMc7!@aQKOI`a61y^i-y-@bhZVk>v=MsB zAMnt=o5H1h>N;kr>*UrBvJ3yB;v8vWEpwz7Z#L7;jN;Eb7YN{i08~H(YM=pHpaXhf z00qDZBwzxCpa^UMX0R1lfE5%28z=##po}>ewtYIpYd><$R7l##B)v;Npi2~_bjOWm zo3AO_lr~q!JYxS%? zCCfz5MA_ScSg*r-Ve^?1T`TwM@)oBTR01EfIQ`%JsFMlJ{?C|K6HM6G{r*-JDxuGu zp3;0e~>mts6{vE+{=iEUG7l!Aikgy z+34Ua0!I(jF)5?0jQq!7UNQth2!ufdM44oWtrYU_G2!T4rNYL_MXR-E5W83z>-$2YsGEv8cZQml_%(IIxp5ochC{S|ME2w-O|@*&6hHc1 w&l7>upVXWe9ut8<=MT&Tl2|X5RHBbFH0VdPSJl_V52A0QXc3vuop@*c1FEAJE&u=k diff --git a/cmd/generate_changelog/incoming/1972.txt b/cmd/generate_changelog/incoming/1972.txt deleted file mode 100644 index f134dfbf..00000000 --- a/cmd/generate_changelog/incoming/1972.txt +++ /dev/null @@ -1,5 +0,0 @@ -### PR [#1972](https://github.com/danielmiessler/Fabric/pull/1972) by [ksylvan](https://github.com/ksylvan): More node package updates: remove cn, fix string and request vulnerabilities - -- Removed cn (Chuck Norris jokes) package to resolve security vulnerabilities -- Fixed 5 Dependabot alerts including ReDoS vulnerabilities in string package and SSRF/Remote Memory Exposure issues in request package -- Enhanced security posture by eliminating vulnerable dependencies with no available patches diff --git a/nix/pkgs/fabric/version.nix b/nix/pkgs/fabric/version.nix index 64a84b31..67fa2a49 100644 --- a/nix/pkgs/fabric/version.nix +++ b/nix/pkgs/fabric/version.nix @@ -1 +1 @@ -"1.4.394" +"1.4.395"