Releases: aaron9589/liverun
Releases · aaron9589/liverun
Release list
v1.12.0
Docker image
docker pull ghcr.io/aaron9589/liverun:v1.12.0
See docker-compose.yml for a ready-to-run example.
v1.11.0
What's Changed
- v1.11.0: branch groups, location aliases, terminal stop enforcement, auto-assign improvements by @aaron9589 in #16
Full Changelog: v1.10.0...v1.11.0
Docker image
docker pull ghcr.io/aaron9589/liverun:v1.11.0
See docker-compose.yml for a ready-to-run example.
v1.10.0
Docker image
docker pull ghcr.io/aaron9589/liverun:v1.10.0
See docker-compose.yml for a ready-to-run example.
v1.9.0 — Security hardening
What's changed
Security hardening
- XSS prevention —
escapeHtmlapplied to all user-controlled data in print and station report views - Security headers — Helmet adds
X-Frame-Options,X-Content-Type-Options, HSTS, and other standard headers - CORS — Locked to
ALLOWED_ORIGINenv var (wildcard retained as default for single-server deployments) - Rate limiting — 200 requests/min on all
/apiroutes - Body size cap — JSON payloads capped at 1 MB
- Path traversal protection —
DB_PATHvalidated at startup in production - URL scheme validation —
clock_broker_urlmust usews://orwss:// - Non-root container — Dockerfile creates an
appuser; entrypoint chowns the data volume then drops privileges viasu-exec - Mass assignment prevention — Import and restore endpoints use explicit field allowlists
- Swagger UI SRI — Pinned to
swagger-ui-dist@5.32.6withintegrityhashes - LAN access — Port binding changed from
127.0.0.1:3001to3001so operators, guard panels, and crew can connect from their own devices on the same network - GitHub Actions — All action tags pinned to commit SHAs
No breaking changes
Pull the new image and restart — no configuration changes required.
docker compose pull && docker compose up -dDocker image
docker pull ghcr.io/aaron9589/liverun:v1.9.0
See docker-compose.yml for a ready-to-run example.
v1.8.0
What's changed
Bug fixes
- TrainEditor: path template selector hidden when editing an existing train
- StationReport: origin stops show only departure; terminus stops show only arrival
Print improvements
- Consolidated print options into a single toolbar dropdown (printer icon)
- Full timetable: A4 landscape, dynamic column packing to fit page width, bold origin times, inline arr/dep format, no browser headers/footers
- Train graph: white background with print-friendly SVG palette, no browser headers/footers
Docker image
docker pull ghcr.io/aaron9589/liverun:v1.8.0
See docker-compose.yml for a ready-to-run example.
v1.7.0
What's Changed
- feat: cascade fix, expanded colours, OpenAPI docs, and README overhaul by @aaron9589 in #12
Full Changelog: v1.6.0...v1.7.0
v1.6.0
Docker image
docker pull ghcr.io/aaron9589/liverun:v1.6.0
See docker-compose.yml for a ready-to-run example.
v1.5.3
Docker image
docker pull ghcr.io/aaron9589/liverun:v1.5.3
See docker-compose.yml for a ready-to-run example.
v1.5.2
Docker image
docker pull ghcr.io/aaron9589/liverun:v1.5.2
See docker-compose.yml for a ready-to-run example.
v1.5.1
Docker image
docker pull ghcr.io/aaron9589/liverun:v1.5.1
See docker-compose.yml for a ready-to-run example.