1.24.8 — Production Audit lineage without MojoSec event floods
Editorial identity incomplete
2026-09-09
django-mojo 1.24.8 restores MojoSec's ability to prove scheduled firewall work from the Audit records AL2023 actually writes, so routine reconciliations no longer flood the central security stream. Missing, malformed, conflicting, stale, capacity-limited, or unrelated privileged activity still fails open and remains visible. No migrations or consumer configuration changes are required.
Fixed
- MojoSec now recognizes trusted same-event PROCTITLE when journald omits the empty EOE record and correctly normalizes quoted or hex-encoded EXECVE arguments, allowing fully proven cron-to-JobEngine firewall broker work to use the existing local-only disposition.
Security
- Late or partial Audit contradictions, conflicting receipts, journal parser loss, dead or reused process generations, and fragment-capacity pressure now remain durable negative authority and prevent privileged-event suppression.
Upgrade notes
- No migrations, REST changes, settings changes, or public wire changes are required. Deploy normally so long-lived MojoSec processes load the new framework version before evaluating event volume.