| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-20 | 1.4 kB | |
| v5.3.2 source code.tar.gz | 2026-09-20 | 8.2 MB | |
| v5.3.2 source code.zip | 2026-09-20 | 8.8 MB | |
| Totals: 3 Items | 17.0 MB | 1 | |
Changelog
[!WARNING] This version includes important security improvements. Please update as soon as possible.
🔐 Security patches
- Strengthened team boundaries for chart previews, template imports, and dataset queries.
- Prevented unauthorized team ownership changes through role updates and invitations.
- Enforced share policy restrictions on public report variables.
- Required valid signatures for Slack requests.
- Protected Slack credentials and restricted integration settings updates.
- Cleared previous team connections when reinstalling the Slack app.
- Restricted MongoDB queries to supported read-only operations.
- Blocked additional private-network bypasses.
- Applied outbound network restrictions to alert and snapshot webhooks.
🐛 Bug fixes
- Fixed chart minimum and maximum values being ignored.
- Fixed zero-value limits and clearing saved limits.
- Applied value limits to the correct axis for horizontal bar charts.
⚙️ Configuration changes
- Slack requires
CB_SLACK_SIGNING_SECRETto process incoming requests. - After reinstalling the Slack app, run
/chartbrew connectand select the allowed channels again. - Alert and snapshot webhooks now follow the existing
CB_ALLOW_PRIVATE_NETWORK_CALLSsetting. - No new environment variables or database migrations are required.