v2026.09.12.02 — 2026-09-12
- fix(security-advisor): stop reporting end-of-life PHP as supported
- Revert "feat(security): application CVE scan" — built, measured, not shipped
- fix(nginx): serve compressed assets — the panel bundle went out at full size
- docs: record the application CVE scan in the security model
- feat(security): email the site owner when new serious vulnerabilities appear
- feat(security): show a website's own vulnerabilities to its owner
- feat(dashboard): report CVEs from every source, not just WordPress
- feat(security): Security Advisor card for application vulnerabilities
- docs(security): record end-to-end validation of the app CVE scan on .99
- feat(security): admin API for the application CVE scan
- feat(security): match customer applications against OSV and NVD
- refactor(security): extract vulnfeed package, add NVD as second CVE source
- feat(security): agent-side application inventory for the app CVE scan
- fix(ui): drop the arrow from the license-key button label