<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Bumplog — is it safe to update Frigate?</title>
    <link>https://bumplog.org/apps/frigate/</link>
    <description>Update-safety verdicts for Frigate (blakeblackshear/frigate), traceable to the GitHub release.</description>
    <language>en</language>
    <atom:link href="https://bumplog.org/apps/frigate/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Frigate v0.17.2 — Update with care</title>
      <link>https://bumplog.org/apps/frigate/</link>
      <guid isPermaLink="false">bumplog:app:frigate:v0.17.2:caution</guid>
      <pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate>
      <description>Update with care. The release contains no breaking config changes or required migrations, making the update itself straightforward. However, the security advisories — particularly the three unresolved issues around viewer-role privilege escalation and camera ACL bypasses — mean operators with publicly exposed instances or mixed-role user setups should review the advisories carefully before and after updating to understand residual risk. What changed: v0.17.2 is a maintenance release that patches six security vulnerabilities, several of them critical — including two remote code execution issues via go2rtc stream handling, RTSP credential leaks through nginx proxy caching, and authorization bypasses affecting viewer-role users. Three additional security issues affecting viewer-role privilege escalation and camera ACL enforcement are acknowledged but deferred to future releases. On the feature side, MP4 exports can now optionally embed recording segment chapter metadata, live page preview performance has been improved, and non-admin users can now use PTZ controls for cameras they have access to. Source release: https://github.com/blakeblackshear/frigate/releases/tag/v0.17.2</description>
    </item>
  </channel>
</rss>
