- Patched several high‑severity security flaws, including unrestricted SSO redirects, CockroachDB auth bypass, expired‑certificate connection persistence, PagerDuty and SAML IdP privilege escalations, and forced HTTPS localhost callbacks f...
- Added hardening such as read‑only cluster‑maintenance permissions and blocked SSO users from local logins or password changes.
- Implemented numerous bug fixes and improvements (session upload completion, smaller Windows binaries, MySQL DB version sync, Kubernetes watch ordering, Ubuntu 24.04 installer support, systemd restart handling, audit‑log enhancements, etc.).