Skip to content

Releases: aaron9589/liverun

v1.12.0

Choose a tag to compare

@github-actions github-actions released this 10 Jun 09:58
4d53a3f

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.12.0

See docker-compose.yml for a ready-to-run example.

v1.11.0

Choose a tag to compare

@aaron9589 aaron9589 released this 07 Jun 09:10
5bdf3de

What's Changed

  • v1.11.0: branch groups, location aliases, terminal stop enforcement, auto-assign improvements by @aaron9589 in #16

Full Changelog: v1.10.0...v1.11.0

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.11.0

See docker-compose.yml for a ready-to-run example.

v1.10.0

Choose a tag to compare

@github-actions github-actions released this 02 Jun 12:21
43b4c20

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.10.0

See docker-compose.yml for a ready-to-run example.

v1.9.0 — Security hardening

Choose a tag to compare

@aaron9589 aaron9589 released this 25 May 21:17
f68a313

What's changed

Security hardening

  • XSS prevention — escapeHtml applied to all user-controlled data in print and station report views
  • Security headers — Helmet adds X-Frame-Options, X-Content-Type-Options, HSTS, and other standard headers
  • CORS — Locked to ALLOWED_ORIGIN env var (wildcard retained as default for single-server deployments)
  • Rate limiting — 200 requests/min on all /api routes
  • Body size cap — JSON payloads capped at 1 MB
  • Path traversal protection — DB_PATH validated at startup in production
  • URL scheme validation — clock_broker_url must use ws:// or wss://
  • Non-root container — Dockerfile creates an app user; entrypoint chowns the data volume then drops privileges via su-exec
  • Mass assignment prevention — Import and restore endpoints use explicit field allowlists
  • Swagger UI SRI — Pinned to swagger-ui-dist@5.32.6 with integrity hashes
  • LAN access — Port binding changed from 127.0.0.1:3001 to 3001 so operators, guard panels, and crew can connect from their own devices on the same network
  • GitHub Actions — All action tags pinned to commit SHAs

No breaking changes

Pull the new image and restart — no configuration changes required.

docker compose pull && docker compose up -d

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.9.0

See docker-compose.yml for a ready-to-run example.

v1.8.0

Choose a tag to compare

@aaron9589 aaron9589 released this 25 May 11:22
d9015a6

What's changed

Bug fixes

  • TrainEditor: path template selector hidden when editing an existing train
  • StationReport: origin stops show only departure; terminus stops show only arrival

Print improvements

  • Consolidated print options into a single toolbar dropdown (printer icon)
  • Full timetable: A4 landscape, dynamic column packing to fit page width, bold origin times, inline arr/dep format, no browser headers/footers
  • Train graph: white background with print-friendly SVG palette, no browser headers/footers

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.8.0

See docker-compose.yml for a ready-to-run example.

v1.7.0

Choose a tag to compare

@aaron9589 aaron9589 released this 23 May 23:03

What's Changed

  • feat: cascade fix, expanded colours, OpenAPI docs, and README overhaul by @aaron9589 in #12

Full Changelog: v1.6.0...v1.7.0

v1.6.0

Choose a tag to compare

@github-actions github-actions released this 14 Apr 13:34

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.6.0

See docker-compose.yml for a ready-to-run example.

v1.5.3

Choose a tag to compare

@github-actions github-actions released this 14 Apr 10:23
1486759

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.5.3

See docker-compose.yml for a ready-to-run example.

v1.5.2

Choose a tag to compare

@github-actions github-actions released this 14 Apr 10:00
d445dbc

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.5.2

See docker-compose.yml for a ready-to-run example.

v1.5.1

Choose a tag to compare

@github-actions github-actions released this 14 Apr 09:05
9238d31

Docker image

docker pull ghcr.io/aaron9589/liverun:v1.5.1

See docker-compose.yml for a ready-to-run example.