Security fixes: - CRIT-012: Add compile-time bounds checking in Job::setBlob() - CRIT-017: Add header count limit (64 max) to prevent DoS - HIGH-005: Disable TLSv1.0 and TLSv1.1 (BEAST/POODLE vulnerable) - HIGH-008: Document signal handler safety (libuv defers to event loop) - HIGH-011: Fix memory leak in BindHost using String copy constructor - HIGH-023: Document JSON type safety check in Client::parse() Quality improvements: - MED-002: Add security headers (X-Content-Type-Options, X-Frame-Options, CSP) - MED-007: Add URL length validation (8KB limit) - MED-009: Reduce self-signed cert validity from 10 years to 1 year 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| config | ||
| core | ||
| cuda | ||
| deps | ||
| heatmap | ||
| proxy | ||
| workers | ||
| NOTICE | ||