Incident History
Incident reports, postmortems, and status updates from Atmos Pro and its infrastructure dependencies.
Security bulletins and vulnerability disclosures affecting Atmos Pro or the upstream components we ship. Each bulletin describes exposure, our response, and any action customers need to take.
Security Bulletin: Supply-Chain Response and Precautionary Credential Rotation
Following the April 2026 Vercel security incident and additional third-party supply-chain communications, Cloud Posse rotated credentials for integrated services out of an abundance of caution. Approximately 30 minutes of redeployment downtime. We have no evidence of unauthorized access to Cloud Posse systems, Atmos Pro infrastructure, or customer data.
Security Bulletin: Inngest TypeScript SDK Disclosure (CVE-2026-42047) — Not Technically Affected
Inngest publicly disclosed CVE-2026-42047 in their TypeScript SDK. Per the criteria published by Inngest — frameworks using explicit HTTP method mapping (such as Next.js App Router) were inherently protected — Atmos Pro was not technically affected. We received embargoed advance notice and had already upgraded to the fix version and rotated credentials before public disclosure.