Cronicle
Distributed task scheduler and job runner with web based control panel
Cronicle is closing privilege escalation gaps in its cluster and job visibility layer through a sustained security hardening push.
◆Recent moves
- 5d ago
Cronicle 0.9.133: nodemailer vuln fix
v0.9.133 bumps pixl-mail to patch a nodemailer vulnerability upstream. No functionality changes — pure security dependency maintenance.
View source ↗ - 8d ago
Cronicle 0.9.132: Node v24 compat + HTTP status preservation
v0.9.132 bumps pixl-request for a Node.js v24 warning and adds HTTP status code preservation when response matching fails. The status code fix is a correctness improvement for HTTP Client jobs, but too narrow to affect most deployments.
View source ↗ - 18d ago
Version 0.9.131
v0.9.131 applies category and server-group visibility checks to the active job API, login bootstrap, and WebSocket status payloads, ensuring users only see jobs they're authorized to view. This is a meaningful access control addition for multi-user or team deployments where job isolation matters.
View source ↗ - 19d ago
Cronicle 0.9.130: HTML encoding fix in job labels
v0.9.130 fixes HTML encoding in job labels — an XSS-class correctness fix with no feature impact.
View source ↗ - 1mo ago
Cronicle 0.9.129: Node.js v22 requirement formalized
v0.9.129 formalizes Node.js v22 as the minimum runtime requirement in docs and installer scripts. An administrative change with no code changes — sets the baseline for future runtime API use.
View source ↗ - 1mo ago
Cronicle 0.9.128: security dep bumps
v0.9.128 bumps nanoid for a vulnerability fix and bumps pixl-server-user to v2, closing a related issue. Routine dependency maintenance in Cronicle's ongoing security upkeep cycle.
View source ↗