41 minutes ago · 7 min read1467 words · Tech · hide · 0 comments

Where We Left Off Part 17 was a dashboard cosplaying as the bridge of the Enterprise. Fun, low-stakes, nothing load-bearing. This one is the opposite. A Mastodon post about Vaultwarden's 1.37.0 release sent me down a rabbit hole that ended with me swearing at a terminal for the better part of an evening, learning a genuinely useful Nix lesson the hard way, and coming out the other side with my password manager patched ahead of a security window I didn't want to be sitting in. The Post That Started It Someone on Mastodon flagged that Bitwarden clients were "scrambling" connections to self-hosted Vaultwarden servers. Turned out to be two things stacked on top of each other: Bitwarden's official clients bumped to a 2026.7.0+ protocol expectation, and Vaultwarden 1.37.0 was the first version to support it. Anything older gets exactly the kind of broken sync people were describing. 1.37.0 also closed eight medium-severity security advisories — cross-organization cipher access, an SSRF via…

No comments yet. Log in to reply on the Fediverse. Comments will appear here.