Releases: MacJediWizard/PatchMon-Enhanced
Release list
v1.7.78
Changes
- Apply lint auto-fixes (Biome formatting)
- Version bump to 1.7.78
Full PR Documentation
See PR PatchMon#421 for comprehensive documentation of all features since v1.3.7:
PatchMon#421
v1.7.77 - Compliance Toggle Fix (Complete)
Bug Fixes
- Fixed compliance on-demand-only toggle not persisting - The
GET /:hostId/integrationsendpoint was not returning thecompliance_on_demand_onlyfield, causing the toggle to reset on page load. Now properly selects and returns the field from the database.
Full Change
The endpoint now includes compliance_on_demand_only in both the database query and API response.
v1.7.76 - Compliance Toggle Fix
Bug Fixes
- Fixed compliance on-demand-only toggle not persisting - The toggle was reading from the wrong data path (
integrationsData?.data?.compliance_on_demand_onlyinstead ofintegrationsData?.compliance_on_demand_only)
Migration Notes
This release includes consolidated migrations from v1.7.75. For existing installations, no migration changes are needed.
v1.7.75 - Compliance On-Demand Only Toggle
Changes
- Add compliance on-demand-only toggle in host integrations
- When enabled (default), compliance scans only run when triggered from UI, not during scheduled agent reports
- Consolidate all 64 migrations into single baseline
0001_initmigration
Database
For existing installations: You'll need to add the new column manually:
ALTER TABLE "hosts" ADD COLUMN "compliance_on_demand_only" BOOLEAN NOT NULL DEFAULT true;For new installations: The single migration handles everything automatically.
Agent Update
Requires agent v1.5.54 or later for the toggle to work.
v1.7.74 - SSH Terminal Input Fix
Bug Fixes
SSH Terminal Username Field Not Accepting Input
Fixed an issue where users could not type in the SSH terminal username field.
Root Cause: The getCachedUsername function was included in a useEffect dependency array. Since it was defined inside the component without useCallback, React recreated the function reference on every render. This caused the useEffect to execute on each keystroke, resetting the username field to the cached value immediately after each character was typed.
Fix: Inlined the localStorage lookup directly in the useEffect and removed the function from the dependency array, so it only runs when host.id changes.
Full Changelog: v1.7.73...v1.7.74
v1.7.73 - Compliance Scan Progress Fix
Bug Fixes
Compliance Scan Progress Bar Not Updating (PatchMon#179)
Fixed an issue where the compliance scan progress bar would remain stuck even after the scan completed successfully.
Root Cause: The SSE (Server-Sent Events) handler received the "completed" event from the agent but only cleared the progress display - it did not set the scan state to complete. The UI relied on polling every 10 seconds to detect completion.
Fix: When SSE receives "completed" or "failed" phase:
- Immediately sets scan as no longer in progress
- Shows success/error message from the agent
- Auto-refetches latest scan data and history
- Switches to results tab on completion
- Clears messages after 10 seconds
Test Suite Fixes
- Fixed failing backend compliance route tests (missing Prisma mocks)
- Fixed failing frontend Compliance dashboard tests (missing providers and mocks)
Full Changelog: v1.7.72...v1.7.73
v1.7.72 - Linting and Code Quality
Code Quality Improvements
This release applies comprehensive Biome linting fixes across the codebase.
Backend
- Added
biome.jsonconfiguration for consistent linting rules - Applied formatting fixes across 37 backend files
- Fixed
parseIntradix parameters for safer number parsing - Fixed template literal and Node.js import protocol suggestions
- Improved code consistency and readability
Frontend
- Fixed SidebarContext import in test file (default vs named export)
Test Status
- Backend: 88 passing, 3 failing (pre-existing complianceRoutes mock issues)
- Frontend: 32 passing (ComplianceScore), SSH terminal tests have mock setup issues
- Agent: All tests passing, build successful
Note: The failing tests are pre-existing issues with test mocks, not related to the security fixes in v1.7.71 or the linting changes in this release.
Full Changelog: v1.7.71...v1.7.72
v1.7.71 - Security Fixes
Security Fixes
This release addresses several medium-severity security issues identified during a security audit.
Backend
- SVG Sanitization - Added
sanitizeSvg()function to remove malicious content from uploaded SVG favicons (script tags, event handlers, javascript: URLs, data: URLs, foreignObject, embed, object, iframe elements) - Encryption Key Warning - Added production warning when
DATABASE_URLis used for encryption key derivation (recommends settingSESSION_SECRETorAI_ENCRYPTION_KEY)
Frontend
- Localhost Fallbacks - Fixed hardcoded
localhost:3001fallbacks that would break production deployments. Now useswindow.locationin production builds.
Other Changes
- Exported
AuthContextfor improved test mocking support - Updated frontend dependencies
Issues Fixed
- #176 - SVG favicon XSS vulnerability
- #177 - Encryption key derivation warning
- #178 - Hardcoded localhost fallbacks
Full Changelog: v1.7.70...v1.7.71
v1.7.70 - Compliance Dashboard Enhancements
What's New in v1.7.70
🎯 Compliance Dashboard Improvements
Bulk Scan Status Tracking (#174, #175)
- Added real-time status cards showing scan progress for all triggered hosts
- Visual state transitions: Pending (yellow) → Running (blue/green) → Complete
- Cards automatically disappear when scans complete
Profile-Type Color Coding
- OpenSCAP scans: Green theme (#22c55e) - consistent security visual language
- Docker Bench scans: Blue theme (#3b82f6) - distinct container security styling
- Applied consistently to scan cards, badges, and charts
Compliance Trend Chart Enhancements
- Separated trend lines by profile type (previously showed combined data)
- OpenSCAP scores displayed as green line
- Docker Bench scores displayed as blue line
- Added legend to distinguish profile types
- Custom tooltip showing scores for both types
🐛 Bug Fixes
- Fixed 500 error on
/compliance/scans/activeendpoint (missing agentWs import) - Fixed profile_id mismatch when deleting running scans
- Improved running scan record management and cleanup
- Fixed bulk scan route ordering causing 400 error
🧹 Code Quality
- Applied Biome linting fixes across 34 frontend files
- Removed debug logging from compliance routes
- Fixed unused variable warnings and import ordering
- Improved React hooks dependency arrays
📝 Related Issues
Files Modified
frontend/src/pages/Compliance.jsx- Bulk scan UI and color codingfrontend/src/components/compliance/ComplianceTrend.jsx- Dual trend linesbackend/src/routes/complianceRoutes.js- API fixes and cleanup- 34 frontend files - Linting fixes
Full Changelog: v1.7.65...v1.7.70
v1.7.65
Simplify running scan deletion - delete all running scans for host when results arrive