Changelog
Released versions, newest first. Source of truth is the GitHub releases page.
The repository CHANGELOG.md is out of step
CHANGELOG.md in the repository root describes a 2.0.0 release. No v2.0.0 tag exists — the published tags are v1.0.0, v1.1.0, v1.1.2 and v1.1.3. Its feature list is accurate; its version numbers are not. This page reflects the tags that were actually cut.
Unreleased
On main, not yet tagged.
Security
pillow→ 12.3.0 (closes 11 advisories: heap out-of-bounds writes inImageCmsTransform.apply(),Image.paste()/crop()andImageFilter.RankFilter; decompression-bomb bypasses viaPdfParser,GdImageFile, and the BDF/PCF/FontFilefont paths; an EPS infinite loop; a TGA heap-disclosure; andWindowsViewer.get_command()command injection)rembg→ 2.0.75 (SSRF and weak default CORS in the rembg server; path traversal via custom model loading — neither reachable from BrandKit's usage, which only callsremove()/new_session()with hard-coded model names, but pinned forward regardless)Flask→ 3.1.3 (missingVary: Cookie)Pygments→ 2.20.0 (ReDoS in the GUID regex)numpy→ 2.3.5,scikit-image→ 0.26.0,opencv-python/opencv-python-headless→ 4.14.0.94 — required to satisfy the newrembgfloor while staying insidenumba'snumpy<2.4ceiling- Removed
zipfile36, pinned but never imported and unmaintained since 2017 - CSP tightened:
cdn.tailwindcss.comandcdn.jsdelivr.netdropped fromscript-src. They had been left behind when the libraries were vendored in v1.1.3, so no third-party script origin is permitted any more. /download-zip/<filename>hardened: the name must survivesecure_filename()unchanged and end in.zip, and the resolved path is confirmed to be inside the upload folder before anything is served.
Fixed
BRANDKIT_SECRET_KEYis now read from the environment (FLASK_SECRET_KEYaccepted as an alias). The key was previouslyos.urandom(24)on every import, so sessions broke on restart and multiple gunicorn workers rejected each other's CSRF tokens. When it is unset the behaviour is unchanged but a warning is logged.- The cleanup thread now runs under gunicorn. It lived inside
if __name__ == '__main__':, which gunicorn never executes, so the Docker deployment never deleted anything andstatic/uploads/grew without bound. It is started at import time and configurable viaBRANDKIT_CLEANUP_ENABLED,BRANDKIT_CLEANUP_INTERVAL_HOURSandBRANDKIT_RETENTION_HOURS. A failing sweep is logged instead of killing the thread. python app.pynow honoursPORT, which it previously ignored whileentrypoint.shrespected it.- Logging is configured before the app is created, so startup warnings are formatted like every other log line.
Changed
FLASK_ENV=productionno longer gates anything and can be removed fromdocker-compose.yml.
v1.1.3 — 8 July 2026
Current release. A security and infrastructure pass with no user-facing feature changes.
Security
pillow→ 12.2.0 (high)urllib3→ 2.7.0 (high)protobuf→ 6.33.5 (high)requests→ 2.33.0 (medium)Werkzeug→ 3.1.6 (medium)idna→ 3.15 (medium)
Changed
- Tailwind and Alpine.js are now vendored and served same-origin (#19). Previously they were pulled from
cdn.tailwindcss.comandcdn.jsdelivr.neton every page load. The app now makes no third-party requests at all — it works on an air-gapped host, and nobody outside your network learns that you loaded the page. - CI replaced. The repository shipped a "Django CI" workflow that had nothing to do with this project; it is now a real matrix build against Python 3.11 and 3.12 that installs dependencies and imports the app (#18).
v1.1.2 — 6 December 2025
Fixed
- rembg import failure, and Flask now binds so the container is reachable from outside (#2, thanks @utkarshainos)
Changed
- Documentation audit and synchronisation (#1)
urllib3→ 2.6.0,werkzeug→ 3.1.4
v1.1.0 — 25 June 2025
The release that made BrandKit what it is now.
Added
- AI background removal via rembg, with model selection: auto, person, object, anime
- Background colour replacement — transparent, solid, or a smart radial gradient built from the image's prominent colour
- Edge smoothing on cutouts
- The full preprocessing suite: grayscale, B&W, invert, contrast, hue shift, temperature, saturation, brightness, auto-crop, noise reduction, sharpen, blur, vignette, drop shadow, watermarking
- Variations mode — ten colour treatments per format
- Format search and category grouping
- Keyboard shortcuts, with Shift+? for help
- WebP and ICO output alongside PNG and JPG
- Bulk ZIP download
Enhanced
- CSRF protection, rate limiting, CSP and security headers via Flask-WTF, Flask-Limiter and Flask-Talisman
- Metadata stripping on upload
- Disk cache keyed by content hash,
psutil-backed memory monitoring, scheduled cleanup - Rebuilt interface on Tailwind CSS and Alpine.js
v1.0.0 — 25 April 2025
Initial release.
Added
- Image upload and multi-format generation from a single source
- PNG and JPG output
- Resizing and padding
- Docker containerisation
- Basic format selection UI
Versioning
Semantic Versioning. Major for breaking changes, minor for backward-compatible features, patch for fixes and dependency bumps.
Changes are grouped as Added, Changed, Deprecated, Removed, Fixed and Security, following Keep a Changelog.