4.2.1
LatestPatchOct 7 · WedOpenNavo editorialAdded to Homebrew Sep 30 15:45
Security release hardens QuickJS module path handling and removes an exposed internal loader; upstream recommends upgrading.
- Highlights
- Resolve real module paths to prevent sandbox escapes through symlinks.Remove the internal loader from the user-script context.