PacificDB Community · v1.1.2

The Community security
and reliability patch.

Open source and self-hosted. Engine, CLI, SDKs and Workbench source versions now align at 1.1.2. No subscriptions, paid feature limits or commercial control plane are added.

What is in this patch?

Added

Removed

Improved

Workbench and upgrade

Workbench bundles the security-remediated 1.1.2 components. Runtime checks exercise sandboxed GUI launch, CRUD/media, backups/restore and restart persistence; final artifacts must match their revision/hash manifest.

Before upgrading real data, verify an external backup and restore, retain the previous binaries, and test a copy in an isolated data directory. Existing authenticated databases without ownership metadata require explicit superadmin owner assignment. Query regex now uses RE2; backreferences/lookarounds are rejected. RE2 libraries are required for source/native builds.

Real-data and production-readiness statement

Maintainer-reported verification is complete. This is an attestation, not an independently validated certification. The patch is designed for self-hosted production operation with documented safeguards; no unconditional safety or zero-data-loss guarantee is made.

Retained evidence covers scoped security regressions, Linux sandboxed runtime and container checks, Helm/schema validation and actual local alert firing, retry and resolution. Historical eight-hour and power-cut results retain their original revision; they are not automatically proof for the final patch.

Independent exact-release review, real production deployment/operator delivery proof and final signed/notarized Windows/macOS artifacts still require attached evidence and validation. Release gates remain fail-closed. Do not use an older unsigned-release exception as approval for this version.

Enable authentication/TLS, review grants, verify backups and restore, monitor audit health, and validate your deployment before storing real data.

Dependency exception

The retained runtime npm audit reports zero advisories. Eight moderate build-only package entries have a documented, exact-version risk acceptance expiring 6 November 2026 at 00:00 UTC. They are accepted, not patched. CI rejects new/runtime/unreviewed/expired findings; reviewed build tools are excluded from application runtime code. This is not a complete native/JVM/Python/container vulnerability assessment.

Read the complete patch notes and evidence requirements. Previous 1.1.1 release.