From 32a1257274dd435108c5498e2259e2c06cfd074d Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Fri, 12 Jun 2026 21:49:12 +0000 Subject: [PATCH] Version packages --- .changeset/smtp-injection-guard.md | 5 ----- packages/email-sdk/CHANGELOG.md | 6 ++++++ packages/email-sdk/package.json | 2 +- 3 files changed, 7 insertions(+), 6 deletions(-) delete mode 100644 .changeset/smtp-injection-guard.md diff --git a/.changeset/smtp-injection-guard.md b/.changeset/smtp-injection-guard.md deleted file mode 100644 index 3974fc5..0000000 --- a/.changeset/smtp-injection-guard.md +++ /dev/null @@ -1,5 +0,0 @@ ---- -"@opencoredev/email-sdk": patch ---- - -Reject SMTP envelope addresses and header names that contain control characters, whitespace, or angle brackets before connecting. This closes an SMTP command/header injection vector where a crafted recipient address or header name could smuggle extra SMTP commands or headers into the session. diff --git a/packages/email-sdk/CHANGELOG.md b/packages/email-sdk/CHANGELOG.md index 062af95..1d15a2d 100644 --- a/packages/email-sdk/CHANGELOG.md +++ b/packages/email-sdk/CHANGELOG.md @@ -1,5 +1,11 @@ # @opencoredev/email-sdk +## 0.6.2 + +### Patch Changes + +- 9c8ff24: Reject SMTP envelope addresses and header names that contain control characters, whitespace, or angle brackets before connecting. This closes an SMTP command/header injection vector where a crafted recipient address or header name could smuggle extra SMTP commands or headers into the session. + ## 0.6.1 ### Patch Changes diff --git a/packages/email-sdk/package.json b/packages/email-sdk/package.json index 32130d3..cb834cd 100644 --- a/packages/email-sdk/package.json +++ b/packages/email-sdk/package.json @@ -1,6 +1,6 @@ { "name": "@opencoredev/email-sdk", - "version": "0.6.1", + "version": "0.6.2", "description": "A TypeScript email SDK for unified transactional sending.", "keywords": [ "bun",