- Patched a security vulnerability (details withheld) and added email rate‑limit middleware for admin password resets.
- Fixed password validation bugs (byte length limits, empty values, max length) and improved form validation/error messages.
- Updated dependencies (undici), removed outdated tutorial, and applied assorted minor bug fixes and chores.