Skip to main content

v0.6.1

Released October 3, 2026. Supported until April 3, 2027.

v0.6.1 ships 2 security updates, and 4 bug fixes. The most severe security issue cleared is critical.

About these release notes

A fully detailed version of these release notes (including artifact versions) is included in the Admin Console.

Click here to learn how to bring up the full release notes.

Upgrade and rollback​

  • No breaking changes. No operator action is required before upgrading.
  • The upgrade rolls through without dropping traffic.
  • Rollback to v0.6.0 is unconditional.

Security updates​

Consoles​

The management-plane application runtime includes Next.js 16.3.6, which fixes GHSA-vcvr-r3jv-pc5j.

The dashboard runtime image refresh replaces vulnerable OpenSSL packages with the patched Chainguard runtime.

Bug fixes​

Auth​

The internal authentication image includes the shared-database RBAC fix required by the 0.6.1 internal rollout.

Consoles​

The project list no longer fails when the user directory denies member lookup; it shows the user count as unavailable and exposes no directory PII.

The user directory is restricted to super administrators.

Admin Console audit logs load through the platform authorization path, so authorized administrators can view the audit-log table and stats.