2.10.1
tremorlabs/tremor2.10.1Mar 27, 2026by asvishnyakov
AI Summary
A security patch for Chainlit that validates session ownership on websocket restore to prevent unauthorized access.
Key Highlights
- Fix for a security vulnerability
- Session ownership validation on websocket restore
New Features
- Validate session ownership on websocket restore
Full Release Notes
## What's Changed * chore: move to oidc for npm publishing by @willydouhard in https://github.com/Chainlit/chainlit/pull/2854 * fix: validate session ownership on websocket restore by @willydouhard in https://github.com/Chainlit/chainlit/pull/2857 * ⚠️ This is a **fix for a security vulnerability** in Chainlit **Full Changelog**: https://github.com/Chainlit/chainlit/compare/2.10.0...2.10.1