1.0.1
1.0.1 is 1.0.0 with a binary distribution that starts on Linux, and dependency updates that clear the security advisories open against 1.0.0. It adds no features and needs no configuration change.
Operating Horizon
Fixes
- The binary distribution starts on Linux. The 1.0.0 binary tarball carried a hidden macOS metadata file, named
._<file>, beside every file. Unpacked on Linux, the server stopped at boot withinvalid ELF headeron._argon2.glibc.node, andtarprintedIgnoring unknown extended header keyword 'LIBARCHIVE.xattr.com.apple.provenance'for every entry. The 1.0.1 tarball carries only the release’s own files. The 1.0.0 source release and container image were not affected. To run 1.0.0 from its tarball meanwhile, delete those files after unpacking:find <install-dir> -name '._*' -type f -delete.
Dependencies
Fastify 5.12.5 and fast-uri 3.1.8 / 4.2.1 clear the security advisories open against 1.0.0. Fastify 5.12 stopped honouring a numeric trustProxy; Horizon keeps server.trustProxy: 1 (and any other hop count) recording the same client address as on 1.0.0, so no configuration change is needed. As before, a hop count believes X-Forwarded-For from a caller that reaches Horizon without going through your proxy; where that is possible, name the proxy’s address or CIDR instead. fast-uri, which the JSON Schema validators in Fastify and the MCP server use for URI values, had several advisories, including server-side request forgery through malformed host names.
hono 4.13.12, qs 6.16.0 and ip-address 10.7.2 come with the MCP SDK and belong to parts of it Horizon does not load. They move, together with brace-expansion 5.0.12 (used by the static file server) and DOMPurify 3.4.16 (bundled with the query editor), so the release package no longer carries the flagged versions.