- Blocked internal REST targets by default and disabled REST blacklist in local development to prevent unauthorized access.
- Patched multiple security issues: path traversal in plugin uploads and command injection in bash automation.
- Removed transitive dependencies and updated Clouseau in the database image.