OpenCATS
Open-source applicant tracking system (ATS)
OpenCATS ships PHP 8.4/8.5 compatibility, utf8mb4 migration, and country support in its most significant release in years.
◆Recent moves
- 12d ago
OpenCATS v0.11.1
v0.11.1 is a focused security and quality pass: CSV import field validation, mass-import file deletion hardening, candidate merge SQL injection fixes, installer timezone input validation, and advanced search output escaping — all targeted at closing specific attack surfaces without adding functionality.
View source ↗ - 19d ago
OpenCATS v0.11.0
⚡ SPARKv0.11.0 delivered the foundational modernization OpenCATS needed: PHP 8.4/8.5 compatibility, utf8mb4 migration, country fields across all record types, OpenStreetMap geocoding, CAPTCHA for career portal, Candidate Declined pipeline status, and CSRF protection — turning an aging PHP 5-era system into something safely runnable on current infrastructure.
View source ↗ - 2mo ago
OpenCATS v0.10.0
⚡ SPARKv0.10.0 landed the security and architecture foundations for the v0.11 work: CSRF protection for state-changing requests, XSS hardening, InnoDB migration, password storage switched to password_hash(), baseline security headers, and a substantially revamped activity system — the largest single-version commit count in the project's recent history.
View source ↗ - 2y ago
v 0.9.7.4 Bugfixes and Security fixes
v0.9.7.4 is a maintenance release from April 2024 — dependency updates, a cookie SameSite/HttpOnly flag, and minor file utility fixes while the PHP 8 work was in progress.
View source ↗ - 2y ago
0.9.7.3: RussH patch cookies (#641)
v0.9.7.3 added SameSite and HttpOnly cookie options to session configuration — a minor security hardening that preceded the larger v0.10.0 security work.
View source ↗ - 2y ago
Security release v0.9.7.2
v0.9.7.2 applied controls to internal pages to restrict authenticated XSS vulnerabilities — an early security patch that predates the systematic hardening in v0.10.0.
View source ↗