Skip to content

Releases: MacJediWizard/PatchMon-Enhanced

v1.7.78

Choose a tag to compare

@MacJediWizard MacJediWizard released this 08 Jan 04:46

Changes

  • Apply lint auto-fixes (Biome formatting)
  • Version bump to 1.7.78

Full PR Documentation

See PR PatchMon#421 for comprehensive documentation of all features since v1.3.7:
PatchMon#421

v1.7.77 - Compliance Toggle Fix (Complete)

Choose a tag to compare

@MacJediWizard MacJediWizard released this 08 Jan 04:05

Bug Fixes

  • Fixed compliance on-demand-only toggle not persisting - The GET /:hostId/integrations endpoint was not returning the compliance_on_demand_only field, causing the toggle to reset on page load. Now properly selects and returns the field from the database.

Full Change

The endpoint now includes compliance_on_demand_only in both the database query and API response.

v1.7.76 - Compliance Toggle Fix

Choose a tag to compare

@MacJediWizard MacJediWizard released this 08 Jan 03:58

Bug Fixes

  • Fixed compliance on-demand-only toggle not persisting - The toggle was reading from the wrong data path (integrationsData?.data?.compliance_on_demand_only instead of integrationsData?.compliance_on_demand_only)

Migration Notes

This release includes consolidated migrations from v1.7.75. For existing installations, no migration changes are needed.

v1.7.75 - Compliance On-Demand Only Toggle

Choose a tag to compare

@MacJediWizard MacJediWizard released this 08 Jan 03:46

Changes

  • Add compliance on-demand-only toggle in host integrations
  • When enabled (default), compliance scans only run when triggered from UI, not during scheduled agent reports
  • Consolidate all 64 migrations into single baseline 0001_init migration

Database

For existing installations: You'll need to add the new column manually:

ALTER TABLE "hosts" ADD COLUMN "compliance_on_demand_only" BOOLEAN NOT NULL DEFAULT true;

For new installations: The single migration handles everything automatically.

Agent Update

Requires agent v1.5.54 or later for the toggle to work.

v1.7.74 - SSH Terminal Input Fix

Choose a tag to compare

@MacJediWizard MacJediWizard released this 07 Jan 22:28

Bug Fixes

SSH Terminal Username Field Not Accepting Input

Fixed an issue where users could not type in the SSH terminal username field.

Root Cause: The getCachedUsername function was included in a useEffect dependency array. Since it was defined inside the component without useCallback, React recreated the function reference on every render. This caused the useEffect to execute on each keystroke, resetting the username field to the cached value immediately after each character was typed.

Fix: Inlined the localStorage lookup directly in the useEffect and removed the function from the dependency array, so it only runs when host.id changes.

Full Changelog: v1.7.73...v1.7.74

v1.7.73 - Compliance Scan Progress Fix

Choose a tag to compare

@MacJediWizard MacJediWizard released this 07 Jan 22:08

Bug Fixes

Compliance Scan Progress Bar Not Updating (PatchMon#179)

Fixed an issue where the compliance scan progress bar would remain stuck even after the scan completed successfully.

Root Cause: The SSE (Server-Sent Events) handler received the "completed" event from the agent but only cleared the progress display - it did not set the scan state to complete. The UI relied on polling every 10 seconds to detect completion.

Fix: When SSE receives "completed" or "failed" phase:

  • Immediately sets scan as no longer in progress
  • Shows success/error message from the agent
  • Auto-refetches latest scan data and history
  • Switches to results tab on completion
  • Clears messages after 10 seconds

Test Suite Fixes

  • Fixed failing backend compliance route tests (missing Prisma mocks)
  • Fixed failing frontend Compliance dashboard tests (missing providers and mocks)

Full Changelog: v1.7.72...v1.7.73

v1.7.72 - Linting and Code Quality

Choose a tag to compare

@MacJediWizard MacJediWizard released this 07 Jan 18:31

Code Quality Improvements

This release applies comprehensive Biome linting fixes across the codebase.

Backend

  • Added biome.json configuration for consistent linting rules
  • Applied formatting fixes across 37 backend files
  • Fixed parseInt radix parameters for safer number parsing
  • Fixed template literal and Node.js import protocol suggestions
  • Improved code consistency and readability

Frontend

  • Fixed SidebarContext import in test file (default vs named export)

Test Status

  • Backend: 88 passing, 3 failing (pre-existing complianceRoutes mock issues)
  • Frontend: 32 passing (ComplianceScore), SSH terminal tests have mock setup issues
  • Agent: All tests passing, build successful

Note: The failing tests are pre-existing issues with test mocks, not related to the security fixes in v1.7.71 or the linting changes in this release.

Full Changelog: v1.7.71...v1.7.72

v1.7.71 - Security Fixes

Choose a tag to compare

@MacJediWizard MacJediWizard released this 07 Jan 18:00

Security Fixes

This release addresses several medium-severity security issues identified during a security audit.

Backend

  • SVG Sanitization - Added sanitizeSvg() function to remove malicious content from uploaded SVG favicons (script tags, event handlers, javascript: URLs, data: URLs, foreignObject, embed, object, iframe elements)
  • Encryption Key Warning - Added production warning when DATABASE_URL is used for encryption key derivation (recommends setting SESSION_SECRET or AI_ENCRYPTION_KEY)

Frontend

  • Localhost Fallbacks - Fixed hardcoded localhost:3001 fallbacks that would break production deployments. Now uses window.location in production builds.

Other Changes

  • Exported AuthContext for improved test mocking support
  • Updated frontend dependencies

Issues Fixed

  • #176 - SVG favicon XSS vulnerability
  • #177 - Encryption key derivation warning
  • #178 - Hardcoded localhost fallbacks

Full Changelog: v1.7.70...v1.7.71

v1.7.70 - Compliance Dashboard Enhancements

Choose a tag to compare

@MacJediWizard MacJediWizard released this 07 Jan 07:56

What's New in v1.7.70

🎯 Compliance Dashboard Improvements

Bulk Scan Status Tracking (#174, #175)

  • Added real-time status cards showing scan progress for all triggered hosts
  • Visual state transitions: Pending (yellow) → Running (blue/green) → Complete
  • Cards automatically disappear when scans complete

Profile-Type Color Coding

  • OpenSCAP scans: Green theme (#22c55e) - consistent security visual language
  • Docker Bench scans: Blue theme (#3b82f6) - distinct container security styling
  • Applied consistently to scan cards, badges, and charts

Compliance Trend Chart Enhancements

  • Separated trend lines by profile type (previously showed combined data)
  • OpenSCAP scores displayed as green line
  • Docker Bench scores displayed as blue line
  • Added legend to distinguish profile types
  • Custom tooltip showing scores for both types

🐛 Bug Fixes

  • Fixed 500 error on /compliance/scans/active endpoint (missing agentWs import)
  • Fixed profile_id mismatch when deleting running scans
  • Improved running scan record management and cleanup
  • Fixed bulk scan route ordering causing 400 error

🧹 Code Quality

  • Applied Biome linting fixes across 34 frontend files
  • Removed debug logging from compliance routes
  • Fixed unused variable warnings and import ordering
  • Improved React hooks dependency arrays

📝 Related Issues

  • #174 - Compliance Dashboard Improvements
  • #175 - Bulk Compliance Scan Trigger

Files Modified

  • frontend/src/pages/Compliance.jsx - Bulk scan UI and color coding
  • frontend/src/components/compliance/ComplianceTrend.jsx - Dual trend lines
  • backend/src/routes/complianceRoutes.js - API fixes and cleanup
  • 34 frontend files - Linting fixes

Full Changelog: v1.7.65...v1.7.70

v1.7.65

Choose a tag to compare

@MacJediWizard MacJediWizard released this 07 Jan 05:50

Simplify running scan deletion - delete all running scans for host when results arrive