pREST v2.4.1 closes an 8.6 SQL injection in _QUERIES templates and an /_mcp catalog-exposure bypass — then its SQL-keyword blacklist silently blanked 17.5% of one production catalog. v2.4.2 replaces screening with real parameter binding, adds script path-traversal containment, and enforces RFC 7518 minimum JWT key sizes.
Vault is a minimal, cross-platform file manager built around search instead of folder trees — Go and Wails under a React UI, 353ms cold start, ~80MB idle RAM, OS-trash-only deletes, and an MCP server so an AI client can drive it.
pREST v2.4.0 adds pgvector nearest-neighbor search and distance filtering, opt-in OpenTelemetry tracing/metrics/logs with a local SigNoz stack, and closes six SQL-injection-adjacent security gaps found via advisory review — including a sibling of the v2.3.0 _select fix living in _groupby.
pREST v2.3.0 closes an unauthenticated SQL injection in the _select parameter (CVSS 9.8), migrates JWKS handling to jwx v3, and completes the multi-adapter registry that isolates TimescaleDB features from the base Postgres adapter.
pREST 2.2.0 ships an embedded Studio UI, database-backed custom queries, and first-class TimescaleDB support—making instant Postgres APIs easier to explore and operate.
pREST AI tooling ships prest-mcp stdio adapter, Cursor plugin rules/skills, and OpenClaw ClawHub skills — read-only PostgreSQL access for agents via the /_mcp endpoint.