Hardened how external input is handled in Hive (0.29.3). Domain webhook drop payloads are now normalized through explicit key whitelists instead of arbitrary string-to-atom conversion, malformed OAuth registration metadata is normalized safely, and stale OAuth registration rate-limit buckets are pruned. RSS and Atom feeds also share a single set of XML escaping helpers. The Docker image is published as ghcr.io/tuist/hive:0.29.3.
Hive
Hardened external input handling for webhooks and feeds
Published
Jun 20, 2026 · 14:37 UTC
Repository
tuist/hive