Skip to content

Diffrook v0.2.0-beta.1

Pre-release
Pre-release

Choose a tag to compare

@Alexandre1116 Alexandre1116 released this 11 Oct 08:32
· 1 commit to main since this release

Diffrook 0.2.0-beta.1 is a self-hosted beta for pilot installations. Cloud Hosting remains Coming soon and cannot be purchased or activated.

Available plans

Plan Users Saved automations SSO Monthly / annual
Individual 1 3 No Free forever, personal noncommercial use
Freelancer 1 10 No EUR 9 / EUR 90
Teams 5 20 Yes EUR 29 / EUR 290
Enterprise Minimum 10 10 per purchased user, pooled Yes EUR 8 / EUR 80 per user

Prices exclude applicable tax. Customers provide their own server and AI. Enterprise can add automation packs. Payment and renewal are arranged manually; activation uses an offline signed installation-bound license.

Changes

  • Generic OpenID Connect SSO for Teams and Enterprise, with PKCE, signed-token verification and explicit administrator allowlists.
  • HTTPS deployment configuration, CSRF protections, secure cookies, host validation, bounded request handling, rate limits and webhook replay protection.
  • Atomic plan quotas, signed subscriptions, preserved over-quota data and legacy Business license support.
  • Plan catalog and license-request downloads; all Cloud purchase actions remain disabled.
  • Compatible Linux x86-64 and ARM64 update archives with license notices and SHA-256 checksum files.
  • Automatic updates select stable releases only. Pre-releases require explicit manual installation in this version.

Install or upgrade

Follow the tagged installation and upgrade instructions. Docker deployments build from this tag; no prebuilt registry image is published.

Before upgrading, choose Manual updates, stop Diffrook and back up the complete data volume including its encryption key. Older binaries can still automatically select pre-releases. Review the new license and limits before continuing commercial use. Existing data is retained when over quota, but further creation is blocked. Existing SSO identities retain verified sign-in access; new identities require Teams or Enterprise.

All users currently have administrator access. Configure the customer's HTTPS proxy and SSO allowlist before using real repositories. Cloud operation, automatic checkout, token billing, restricted member roles and an availability SLA are not included.

The OIDC dependency has a scoped exception for RUSTSEC-2023-0071, concerning RSA private-key timing leakage. Diffrook only verifies public signatures and holds no RSA private key. See the security verification scope. This beta does not claim an independent penetration-test certificate or validation with every IdP.

Validation

  • CI passed on the exact release tag: formatting, Clippy, 58 Rust tests, license issuer tests, frontend production build and dependency audit with the documented RSA exception.
  • Docker image build and all 16 container integration checks passed.
  • Both Linux release archives passed 16 integration checks against their packaged binaries and complete-volume backup restoration, including the encryption key, login, installation identity and persisted resources.
  • Both archives and checksum files were downloaded and verified against GitHub asset digests; executable architecture and bundled license notices were checked.
  • A local upgrade from the published v0.1.1-rc.1 retained login, encrypted credentials and four legacy automations; the Individual plan correctly blocked additional creation while preserving that data.

Release-tag CI ? Package validation