<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[A new Rig cloud release is available: v0.18.0]]></title><description><![CDATA[<h2>Cloud v0.18.0</h2>
<p dir="auto">Security batch: XSS hardening, email HTML escaping, path containment on static serving, non-root Docker, and dependency bumps.<br />
<strong>Shipped</strong> 12 Aug 2026 · <a href="https://userig.app/changelog?tab=shipping#cloud" rel="nofollow ugc">Full changelog</a></p>
<h3>Added</h3>
<ul>
<li>Profile URL scheme allowlist (http/https/mailto) in public profiles and API sanitize</li>
<li>Stripe hostname allowlist before billing redirects</li>
<li>Non-root <code>USER node</code> in API and web Docker images</li>
<li>Path containment for web static file serving (<code>safePath.mjs</code>)</li>
</ul>
<h3>Fixed</h3>
<ul>
<li>Account dashboard <code>$</code> helper renamed to <code>byId</code> (Aikido jQuery false positive)</li>
<li>Legacy marketing HTML no longer assigns untrusted strings via <code>innerHTML</code></li>
<li>Invitation / welcome / change-email HTML escapes untrusted fields</li>
<li><code>@hono/node-server</code> bumped to 2.x; <code>jose</code> / <code>fast-uri</code> / <code>better-auth</code> resolved to patched versions</li>
</ul>
<hr />
<p dir="auto"><em>Posted by Rig when this cloud release hit <a href="https://userig.app/changelog" rel="nofollow ugc">userig.app/changelog</a>. Feedback welcome in Bugs / Feature ideas — private tickets still go to <a href="https://help.userig.app" rel="nofollow ugc">Support</a>.</em></p>
]]></description><link>https://community.userig.app/topic/134/a-new-rig-cloud-release-is-available-v0.18.0</link><generator>RSS for Node</generator><lastBuildDate>Sat, 19 Sep 2026 02:23:19 GMT</lastBuildDate><atom:link href="https://community.userig.app/topic/134.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 12 Aug 2026 21:37:57 GMT</pubDate><ttl>60</ttl></channel></rss>