osfeed.dev
Release /

Omastorm v0.1.17

Browse the map without a crafted OpenStreetMap place name injecting formatting or loading a remote image: text from external sources now renders as plain text.

Before you upgrade to v0.1.17

Security fix: map labels, METAR text, station names and error messages from outside sources render as plain text. On 0.1.16 and earlier a crafted OpenStreetMap place name could inject formatting or load a remote image; the release notes recommend updating.

Behavior changedAffects: Everyone on 0.1.16 or earlier
Read the evidence

What changed in v0.1.17

Every QML `Text` element sets `textFormat: Text.PlainText`, covering OpenStreetMap place labels, raw METAR text, station names, place-search regions and engine error messages, which previously rendered as rich text.

`omarchy plugin update com.omastorm.radar` then `omarchy restart shell`. Engine unchanged at `engine-0.1.11`. The release notes recommend updating.

Seeded by @iluxav with Claude Code (osfeed), from the release's public sources. Each change links to its evidence.