Skip to content

v0.37.0

Latest

Choose a tag to compare

@github-actions github-actions released this 18 Aug 21:38
Immutable release. Only release title and notes can be modified.
1916f88

0.37.0 (2026-08-18)

⚠ BREAKING CHANGES

  • orthrus: replace HostConfig field allowlist with full-access write mode

Features

  • add async job-tracking to BackupService (create) (3edaaa1)
  • add BackupJob model and migration (b4dc22a)
  • add job polling and DB health hooks to frontend backup API/hooks (38d1e39)
  • add Save button to BackupEncryptionCard (67ec168)
  • add shared CodeQL findings-gate script and ignore-list schema (2554c12)
  • add What's New changelog popup shown after app updates (7b5c156)
  • backend: add Dropbox and Google Drive uploaders + OAuth routes (4929033)
  • changelog: add embedded changelog package and generation pipeline (d17cff2)
  • changelog: add per-user changelog API and User model fields (643fed3)
  • changelog: add security category to changelog generation (4d0b1a4)
  • changelog: add What's New modal and Appearance Settings integration (274d7c7)
  • changelog: render Security group in WhatsNewModal (af67931)
  • Configuration Backup & Restore (Issue #32) (0abe841)
  • enable WebDAV/Dropbox/Google Drive E2E + hardening pass (fb0cee4)
  • extract lock-free restore core and add async job-tracking to BackupService (restore) (fc9a5a3)
  • fail CodeQL findings gate on any severity by default, add documented exceptions (a06ef9e)
  • frontend: add WebDAV/Dropbox/Google Drive remote-target UI (0ff122b)
  • harden CodeQL findings gate + fix cookie-suppression comment placement (b20b9dd)
  • orthrus: add CI-enforced lint, staticcheck, and coverage gates for agent module (#1161) (40d3ac2)
  • orthrus: add structural allowlist parity checker (#1161) (0ba40d1)
  • orthrus: add write-mode plumbing with zero behavior change (a4be39e)
  • orthrus: add write-mode UI, audit-log deep-linking, i18n (30cf1c0)
  • orthrus: extend PATCH/proxy-status API for write mode, wire audit logging (9326215)
  • orthrus: implement opt-in write-endpoint allowlist, body validation, rate limiting, and audit logging (8311999)
  • orthrus: notify operator when write-mode change requires an agent restart (bbcfdcb)
  • orthrus: per-agent VolumesFrom source allowlist; allow Isolation (bc5185c)
  • orthrus: replace HostConfig field allowlist with full-access write mode (fa7a534)
  • orthrus: write-mode support + muzzle allowlist parity (#1160, #1161) (ba3f576)
  • proxy-hosts: add retry button to Docker connection error banner (b2f1f98)
  • smart defaults for encryption and remote-upload in the Create Backup dialog (7650437)
  • surface backup job progress and DB corruption warnings in the Backups page (a60486e)
  • switch backup create/restore handlers to 202+job, add GetJob (1465b27)
  • thread UploadToRemote option and stored-passphrase reuse through backup creation (62c34c2)

Bug Fixes

  • a11y: add accessible names to icon-only delete button and log filter selects (716e26b)
  • add aria-current to active navigation links (dac267f)
  • apply busy-timeout/WAL pragma to uptime test DB to resolve SQLite lock flake (3569525)
  • apply the encryption setting to scheduled/cron backups, correct their Type to "scheduled" (00fa7eb)
  • audit-logs: align frontend audit log response types with backend contract (ced95fd)
  • auto-revert generated changelog.json after local Docker builds (afd4de4)
  • auto-sync PLAYWRIGHT_CADDY_PROXY_PORT for local E2E rebuilds (722e574)
  • backend: eliminate buffer-reuse data race in Dropbox chunked upload (a23fb79)
  • backend: eliminate race in pending-restore-harness boot mode (67ced81)
  • backend: make backup filenames collision-proof to stop same-second overwrites (a00acdb)
  • backend: make RehydrateLiveDatabase's per-table swap transactional (H1) (2b6b5f7)
  • backend: persist explicit enabled:false on remote target creation (3870c0d)
  • backend: remove live-network dependency from OAuth callback test, add validateRemoteTargetConfig coverage (63e1bd4)
  • backend: restore missing minio-go/v7 dependency for S3 remote storage (e4d357d)
  • backend: surface RestoreBackupSafe's double-failure path as a real error instead of false success (C1) (5aacd51)
  • certificates: delete bulk certificates sequentially (781591d)
  • certificates: invalidate cache when proxy hosts change certificate links (ed644d3)
  • changelog: close non-semver gaps in seeding and permanent dismissal (75fe80d)
  • changelog: guard WhatsNewModal against null group fields (0738f67)
  • changelog: normalize nil array fields to empty on entry read (5755f31)
  • changelog: resolve WhatsNewModal session-dismissal and stale-state bugs (329393c)
  • changelog: treat non-semver running versions as dev builds (ea16544)
  • ci: inject E2E changelog fixture before Shard 4 image build (4c8a8d6)
  • ci: make Security Enforcement jobs actually run security-enforcement/ and security/ specs (8d79732)
  • ci: pin release-please target-branch to main (fe1500b)
  • close out issue #619 test-infrastructure debt (unskip Vitest suites, replace tautological E2E assertions, fix real bugs found along the way) (#1223) (020e0fc)
  • correct Access List UUID usage and CGNAT warning i18n keys (9bf37c1)
  • correct CodeQL suppression comment placement in auth, crowdsec, and backup handlers (88763c7)
  • correct stale node:24.19.0-alpine3.24 image digest (97d480e)
  • deps: add sourceUrl override for sirupsen/logrus in Renovate config (8608db6)
  • deps: bump nanoid to 3.3.18 to patch GHSA-2v37-7h3g-55p8 (edbff1e)
  • deps: bump react-hook-form to 7.84.0 and update lockfiles (7b4ec4c)
  • deps: migrate react-router-dom to react-router v8 (839f791)
  • deps: migrate react-router-dom to react-router v8 (GHSA-qwww-vcr4-c8h2) (550c5ec)
  • deps: pin gosu's golang.org/x/sys to v0.46.0 (GO-2026-5024) (0d81fc9)
  • deps: resolve brace-expansion DoS advisory (GHSA-mh99-v99m-4gvg) (95f7e76)
  • deps: resolve brace-expansion DoS advisory via jsx-a11y types pin (e95bd27)
  • deps: update dependency axios to v1.19.0 (1051bea)
  • deps: update module github.com/mattn/go-sqlite3 to v1.14.48 (bb1bf55)
  • deps: update module github.com/mattn/go-sqlite3 to v1.14.48 (2abbf11)
  • deps: update module github.com/prometheus/client_golang to v1.24.1 (a5407ab)
  • deps: update module github.com/prometheus/client_golang to v1.24.1 (3cde35b)
  • deps: update npm-non-major (173a7b0)
  • deps: update npm-non-major (c3e2c44)
  • deps: update npm-non-major (f63b9e0)
  • deps: update npm-non-major (92f0da7)
  • dep: update google.golang.org/grpc to 1.82.0 in go.work.sum (54ee310)
  • dep: update google.golang.org/grpc to 1.82.1 in go.work.sum (8527198)
  • dep: update google.golang.org/grpc to v1.82.1 and add vulnerability suppression for GHSA-hrxh-6v49-42gf (eeae8aa)
  • docker: add bounded timeout for slow ListContainers responses (88d8ccd)
  • docker: classify moby v0.5.1 permission-denied errors as connectivity errors (80a9bd8)
  • docker: replace docker-socket-proxy with Orthrus remote agent (250c630)
  • docker: resolve blank/failing container list on slow or permission-denied local Docker sockets (d58ee0a)
  • don't record failed test status for unattempted OAuth-precondition probes (f9fc4ea)
  • e2e: avoid redundant login for rate-limit test's new user (751eafc)
  • e2e: extend gotoTolerant() coverage to theme/appearance nav helpers (195dc44)
  • e2e: fix test-side hangs and wrong-origin WAF assertion in security specs (b7aef5b)
  • e2e: guard remaining unprotected page.goto() after login in user-management.spec.ts (5862fd1)
  • e2e: handle stale post-login navigation in shared loginUser helper (b7f9c4f)
  • e2e: log in before logoutUser() in navigation-settle regression test (89af6db)
  • e2e: mock OAuth callback redirect via JS navigation, not HTTP 3xx fulfill (07859e3)
  • e2e: remap local Caddy proxy port to avoid host port 80 conflict (7267d70)
  • e2e: repair pre-existing certificate, proxy-group, and logout test bugs (afbce2b)
  • e2e: replace CSS-class-guessing locators and too-tight timeout in security specs (b7c9cc1)
  • e2e: replace ineffective navigation-race guard with tolerant goto helper (127b8fa)
  • e2e: replace strict-mode-unsafe dialog locator in ACL integration tests (988f280)
  • e2e: resolve Security Enforcement failures in auth/ACL/WAF/rate-limit specs (1dcf858)
  • e2e: stop racing back-to-back same-URL navigation in data-consistency test (a561626)
  • e2e: stop racing page.goto() against still-settling navigations (d537476)
  • e2e: suppress What's New changelog modal for shared/auto-created test users (29514c0)
  • e2e: suppress What's New modal for ad-hoc raw-API test users (b2d7288)
  • e2e: target Caddy proxy port for WAF/ACL checks, stop shared-session logout (1412a7a)
  • e2e: tolerate Firefox navigation-commit race in reload(), not just goto() (7503c01)
  • e2e: unique per-test proxy domain and correct dialog-dismiss timing (93b9a09)
  • e2e: use API-based cleanup in auth-middleware-cascade afterEach (4d032b6)
  • e2e: use rendered content instead of page.url() to detect access denial (20da6be)
  • e2e: widen WebKit visibility timeout for manual DNS challenge button (f21b028)
  • e2e: wrap WAF-check requests in retryAction for CI network resilience (82e5d14)
  • frontend: complete react-router-dom to react-router migration (4ac6586)
  • frontend: keep toast notifications accessible while a modal dialog is open (398b336)
  • frontend: route restore-failure toasts through backups.restoreFailed template (0a1ec51)
  • guard Login.tsx state update against unmount race condition (9acd86d)
  • hide remote-target Test button until OAuth target is connected (297872a)
  • inject What's New changelog fixture in local E2E rebuild script (4e6d316)
  • lefthook: stop auto-restaging files fixed by pre-commit hooks (5a2df27)
  • make auth cookie Secure flag scheme/network-aware, close Tailscale CGNAT gap (6e4d2c0)
  • muzzle: allow CapDrop and safe UsernsMode values in container create (c43087f)
  • orthrus-agent: match namespaced image references in remote agent muzzle allowlist (eabf358)
  • orthrus: align agent muzzle normalization order with backend (#1160) (043f9e5)
  • orthrus: allow CgroupnsMode and Windows-only resource-limit fields in muzzle allowlist (585186b)
  • orthrus: allow container rename in write-mode allowlist (6fde74d)
  • orthrus: allow PidMode, IpcMode, UTSMode via value-level checks (148e89d)
  • orthrus: allow read-only image/distribution inspect through Docker proxy muzzle (98a68b6)
  • orthrus: exempt GET/HEAD from the write-path rate limiter (3ae1cd0)
  • orthrus: match namespaced image references in muzzle allowlist (b71cbd6)
  • orthrus: remove hardcoded "charon" hostname from ExternalProxyStatus (1eb266d)
  • orthrus: resolve external proxy hostname from request context instead of hardcoding it (7f307c3)
  • orthrus: resolve patch-coverage baseline against real PR base and enforce threshold locally (21954ce)
  • prevent null Docker container list from crashing proxy host form (6825676)
  • prevent null Docker container list from crashing proxy host form (d09d243)
  • proxy-hosts: fix Containers dropdown resetting to placeholder after selection (a04be65)
  • redirect OAuth callback to /tasks/backups, not nonexistent /backups route (e01b63d)
  • reject dangerous ContainerIDFile, expand muzzle safe key allowlist (710898d)
  • remove unused imports/variables flagged by CodeQL in core E2E specs and fixtures (1cc19cd)
  • remove unused imports/variables flagged by CodeQL in security E2E specs (5ec7771)
  • remove unused imports/variables flagged by CodeQL in settings/tasks E2E specs (1049d8f)
  • repair stale postcss@8.5.17 integrity hash in lockfiles (a2b9741)
  • replace tautological assertions in certificates.spec.ts with real backend-verified checks (8f1c7bc)
  • replace tautological assertions in proxy-hosts and access-lists E2E specs (f1f2a41)
  • replace tautological assertions in remaining security-UI and settings E2E specs (e581192)
  • retry create-user-then-login race in test fixtures on 401 (500ce8f)
  • retry transient SQLite lock errors when creating uptime monitors (b748145)
  • return empty slice instead of nil from Docker ListContainers (bf5384d)
  • run DB integrity checks on a dedicated connection, not the shared pool (aa6cd5e)
  • scope local CodeQL/Trivy scans to feature-adding changes (71cefa2)
  • scope proxy-hosts heading locator and seed test data for bulk-selection test (b1145b9)
  • scripts: pin typescript to ^6.0.3 in dep_update.sh (def7251)
  • security: gate X-Forwarded-Proto/X-Forwarded-Host trust behind an explicit CHARON_TRUSTED_PROXIES allowlist, remove Origin/Referer from cookie-security decisions (3b1cd2b)
  • security: patch kin-openapi CRITICAL auth-bypass in crowdsec-builder (2574257)
  • security: strengthen file path safety checks in system administration handler (379a640)
  • security: strengthen file path safety checks in system administration handler (0d7c3e4)
  • security: suppress unreachable cel-go MEDIUM finding blocking PR image scan (9691fab)
  • skip redundant pull_request docker-build run for main/development-head PRs (f11b4be)
  • skip redundant pull_request docker-build run for main/development-head PRs (#1236) (6ed08db)
  • split docker-build.yml concurrency group by event_name to eliminate push/pull_request race (365f34f)
  • split docker-build.yml concurrency group by event_name to eliminate push/pull_request race (#1239) (67b4f2d)
  • split docker-build.yml multi-arch build to fix arm64 QEMU timeout (f55ac5d)
  • split docker-build.yml multi-arch build to fix arm64 QEMU timeout (#1232) (3bdd618)
  • standardize all SQLite file access on a single driver, drop mattn/go-sqlite3 (e968674)
  • stop full local 3-browser Playwright runs, defer to CI (75c6369)
  • stop inferring CrowdSec install state from incidental file presence (d1fecd5)
  • stop logging raw restore-job error text (CodeQL go/log-injection) (a87bdcf)
  • test: bound and catch networkidle waits in modal-dropdown-triage (fdca27c)
  • test: bound and catch networkidle waits in theme/banner spec helpers (d1b2add)
  • test: give the manual-challenge panel heading the same WebKit headroom as its button (1fe9d09)
  • test: match established 10s WebKit headroom for reload-then-verify in ntfy token security test (52bdc67)
  • test: raise close-modal assertion timeouts in caddy-import gap test (c5b34af)
  • test: raise invalid-syntax error banner timeout (webkit) (887870e)
  • test: raise session-resume banner timeout to match file convention (68a7103)
  • test: recognize Firefox's NS_BINDING_ABORTED as an expected navigation race (e215750)
  • test: serialize proxy-host-drag-drop suite to remove group-state race (5784b48)
  • tests: sync SQLite integrity check in handlers TestMain to fix TempDir race (2c8651b)
  • test: wait for API response before asserting whitelist conflict error (b10191a)
  • test: wait for dropdown option visibility before focusing in DNS provider type tests (4b53e0f)
  • test: wait for login form before filling on empty-password test (79b1073)
  • unskip Security.* Vitest suites now that undici/jsdom WebSocket bug is fixed (34d5553)
  • update dependencies for axe-core, electron-to-chromium, and immer to latest versions (4a2f951)
  • update opentelemetry http instrumentation to v0.70.0 (bb567da)
  • vscode: add Docker Compose task for Charon container (7bf7a4a)