- Added TOTP‑based two‑factor authentication with admin enforcement, backup codes, and rate‑limiting
- Implemented session identity stitching, session/event property filtering, board cloning, and sparklines for dashboards
- Added many security hardenings, performance improvements, UI fixes, Docker CVE patches, and migrations for 2FA and session linking