- Fixed multiple high‑severity security flaws, including unrestricted SSO redirects, CockroachDB authorization bypass, long‑lived connections with expired certificates, and privilege escalation via PagerDuty and SAML IdP integrations.
- Added hardening for SSO callbacks (non‑localhost URLs blocked, HTTPS required) and delivered numerous bug fixes such as correct annotation handling, session upload stability, smaller Windows binaries, read‑only maintenance config, Bot UI...