Skip to content

Releases: Cloudopsshell/deaconguard

deaconguard v0.9.2

Choose a tag to compare

@github-actions github-actions released this 11 Oct 00:52
541383f

Fixed

  • On the Hosts page, the This server label now sits beside the host name, as on the Agents page. A host with many check results made the Findings column wide and pushed the label onto the next line.
  • A table wider than the screen scrolls inside its card instead of widening the whole page.

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.9.2-rc.1

Pre-release

Choose a tag to compare

@github-actions github-actions released this 11 Oct 00:46
541383f

Pre-release of 0.9.2 for testing. Do not use in production.

Fixed

  • On the Hosts page, the This server label now sits beside the host name, as on the Agents page. A host with many check results made the Findings column wide and pushed the label onto the next line.
  • A table wider than the screen scrolls inside its card instead of widening the whole page.

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.9.1

Choose a tag to compare

@github-actions github-actions released this 11 Oct 00:29
ae1ef72

Fixed

  • The This server label broke across two lines when the host column was narrow. It now stays in one piece and moves to the next line as a whole.
  • The Agents page now marks the server's own agent with This server, and says its token came from server setup rather than "deaconguard (cli)".

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.9.1-rc.1

Pre-release

Choose a tag to compare

@github-actions github-actions released this 11 Oct 00:23
ae1ef72

Pre-release of 0.9.1 for testing. Do not use in production.

Fixed

  • The This server label broke across two lines when the host column was narrow. It now stays in one piece and moves to the next line as a whole.
  • The Agents page now marks the server's own agent with This server, and says its token came from server setup rather than "deaconguard (cli)".

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.9.0

Choose a tag to compare

@github-actions github-actions released this 10 Oct 23:30
bb892bd

Added

  • The server's own machine is scanned as root, by an agent of its own. The server runs without root, as the deaconguard user, and systemd's NoNewPrivileges keeps it from using sudo, so scans of its own machine were always partial. deaconguard setup server, which the install script runs, now installs and enrolls an agent on the server's machine over 127.0.0.1. It appears on the Hosts page as This server, and its scans have full coverage, scheduled or not. The server still runs without root, and the agent listens on nothing.
  • --no-agent skips it (and is remembered by later runs); --with-agent adds it later.
  • Setup ends by saying what runs on the machine, and how.
  • A host the server scans itself shows why its results are partial and how to fix it.

Changed

  • The server never scans anything itself. In the dashboard on a server, Add this machine gives way to Enroll a machine; the local dashboard (deaconguard serve) keeps it.
  • Upgrading: running the install script on a server adds the agent. If this machine was added as a host earlier, its scans, log entries, and schedules move to the agent host. The install script now recognizes a server's machine as a server even though it also has an agent.

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.9.0-rc.1

Pre-release

Choose a tag to compare

@github-actions github-actions released this 10 Oct 23:23
bb892bd

Pre-release of 0.9.0 for testing. Do not use in production.

Added

  • The server's own machine is scanned as root, by an agent of its own. The server runs without root, as the deaconguard user, and systemd's NoNewPrivileges keeps it from using sudo, so scans of its own machine were always partial. deaconguard setup server, which the install script runs, now installs and enrolls an agent on the server's machine over 127.0.0.1. It appears on the Hosts page as This server, and its scans have full coverage, scheduled or not. The server still runs without root, and the agent listens on nothing.
  • --no-agent skips it (and is remembered by later runs); --with-agent adds it later.
  • Setup ends by saying what runs on the machine, and how.
  • A host the server scans itself shows why its results are partial and how to fix it.

Changed

  • The server never scans anything itself. In the dashboard on a server, Add this machine gives way to Enroll a machine; the local dashboard (deaconguard serve) keeps it.
  • Upgrading: running the install script on a server adds the agent. If this machine was added as a host earlier, its scans, log entries, and schedules move to the agent host. The install script now recognizes a server's machine as a server even though it also has an agent.

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.8.1

Choose a tag to compare

@github-actions github-actions released this 10 Oct 22:41
ea2784b

Fixed

  • Editing a schedule, and turning it off or on, failed with "invalid request body: json: unknown field "id"". The dashboard sent the whole schedule back, including read-only fields the server rightly refuses; it now sends only the fields you can change.

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.8.1-rc.1

Pre-release

Choose a tag to compare

@github-actions github-actions released this 10 Oct 22:36
ea2784b

Pre-release of 0.8.1 for testing. Do not use in production.

Fixed

  • Editing a schedule, and turning it off or on, failed with "invalid request body: json: unknown field "id"". The dashboard sent the whole schedule back, including read-only fields the server rightly refuses; it now sends only the fields you can change.

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.8.0

Choose a tag to compare

@github-actions github-actions released this 10 Oct 22:02
a0f2445

Added

  • Scheduled scans. A new Schedules page scans hosts automatically, so results no longer go stale when nobody presses Scan now:
    • choose the days (every day, weekdays, or any days of the week), a time and a time zone; daylight saving changes are handled, and a schedule runs once per day even when the clocks go back;
    • choose all hosts (including hosts added later) or specific hosts, and the checks, including the advanced antivirus scan;
    • Run now, Turn off and Turn on, edit and delete.
  • The server starts each run's scans like Scan now. It skips a host that is already being scanned, or whose agent is too old for a chosen check, and says why in the Logs page. A run missed while the server was stopped happens once when it starts again.
  • Schedules run with root privileges by default. Agents run as root; the server's own machine uses sudo where it needs no password, since a scheduled scan never waits for one. A schedule can turn root off, and the dialog then reminds you that results will show partial coverage.
  • Each host's page shows its next scheduled scan, or that it is not on a schedule. The dashboard flags hosts whose latest results are more than 7 days old.
  • The audit log records creating, changing, running and deleting schedules, and names the schedule that started each scan. It now also names viewing and downloading the log.

Changed

  • Upgrading: the database gains a schedules table (schema 9). No schedule exists until you create one.

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).

deaconguard v0.8.0-rc.1

Pre-release

Choose a tag to compare

@github-actions github-actions released this 10 Oct 21:53
a0f2445

Pre-release of 0.8.0 for testing. Do not use in production.

Added

  • Scheduled scans. A new Schedules page scans hosts automatically, so results no longer go stale when nobody presses Scan now:
    • choose the days (every day, weekdays, or any days of the week), a time and a time zone; daylight saving changes are handled, and a schedule runs once per day even when the clocks go back;
    • choose all hosts (including hosts added later) or specific hosts, and the checks, including the advanced antivirus scan;
    • Run now, Turn off and Turn on, edit and delete.
  • The server starts each run's scans like Scan now. It skips a host that is already being scanned, or whose agent is too old for a chosen check, and says why in the Logs page. A run missed while the server was stopped happens once when it starts again.
  • Schedules run with root privileges by default. Agents run as root; the server's own machine uses sudo where it needs no password, since a scheduled scan never waits for one. A schedule can turn root off, and the dialog then reminds you that results will show partial coverage.
  • Each host's page shows its next scheduled scan, or that it is not on a schedule. The dashboard flags hosts whose latest results are more than 7 days old.
  • The audit log records creating, changing, running and deleting schedules, and names the schedule that started each scan. It now also names viewing and downloading the log.

Changed

  • Upgrading: the database gains a schedules table (schema 9). No schedule exists until you create one.

Dependencies

DeaconGuard is one statically linked binary: it needs no libraries on the machine. The release was built with:

Component Version
Go 1.26.9
SQLite driver (modernc.org/sqlite) v1.60.1
golang.org/x/net v0.60.0
golang.org/x/term v0.46.0
React (web UI) 19.3.0
React Router (web UI) 8.4.0
TanStack Query (web UI) 5.104.1

The install script (curl -fsSL https://get.deaconguard.io | sudo sh -) installs these on every server and agent, from the distribution's own signed repositories at the version the distribution currently ships:

For Debian, Ubuntu RHEL 8/9, Amazon Linux 2023
Malware check (ps, find) procps, findutils procps-ng, findutils
Security configuration check (ss) iproute2 iproute
Pending-reboot check (not needed) needs-restarting (dnf-utils / yum-utils)
Antivirus check (basic scan) clamav, clamav-freshclam (signature updates switched on) clamav, clamav-freshclam / clamav-update; on RHEL from EPEL, which the script enables
Advanced antivirus scan YARA-X 1.21.0 (yr), downloaded from VirusTotal's GitHub release and checked against a pinned checksum the same
Release signature check cosign 3.1.3, downloaded from Sigstore's GitHub release and checked against a pinned checksum the same

The advanced antivirus scan runs the YARA Forge core rules. They are not installed on machines: the server downloads the latest weekly package from GitHub, keeps it for 12 hours, and sends it to agents with each advanced scan.

Every dependency of the binary and the web UI, with versions and licenses, is listed in the SBOM files attached to this release (SPDX JSON).