Skip to content

Releases: abidinberkay/Redivue

v1.0.1 — First public release

Choose a tag to compare

@abidinberkay abidinberkay released this 30 Sep 20:37

Redivue is a free, open-source, self-hosted Redis GUI: manage multiple Redis instances from one browser dashboard — no telemetry, no cloud account, no license server, no "Pro" tier.

This is the first public release. It includes everything built so far, plus security and dependency hardening done ahead of launch.

Quick start

docker run -p 127.0.0.1:8080:8080 ghcr.io/abidinberkay/redivue:1.0.1

Open http://localhost:8080 and add a connection. Images are published for linux/amd64 and linux/arm64.

Redivue has no login of its own — keep it on localhost or behind an authenticating proxy. See SECURITY.md and DEPLOYMENT.md.

What's in it

  • Connections: password, Redis 6+ ACL, redis:///rediss:// URLs, Sentinel, Cluster, Unix socket, SSH tunnels (password or key), TLS/mTLS
  • Keys: SCAN-based browser with namespace tree, full CRUD for String/Hash/List/Set/Sorted Set/Stream/RedisJSON, value formatters (JSON, HEX, binary, timestamp, GZIP/ZSTD/LZ4/Snappy decompression), bulk TTL/delete/export, copy across databases and connections
  • CLI: 150+ commands with autocomplete, history, favorites and confirmation on destructive commands; bulk command import from a file
  • Observability: live MONITOR, slow log, memory analysis with recommendations, Pub/Sub, keyspace notifications
  • Extras: stats dashboard with live config editing, Key Diff across connections, activity log with undo

Full list: README · How to use it: User Guide

Changes since v1.0.0

Security

  • DNS-rebinding protection. Requests are only accepted when the Host header is localhost, 127.0.0.1 or [::1], or a name listed in the new REDIVUE_ALLOWED_HOSTS setting. This stops a malicious web page from using a local Redivue to reach Redis instances on your network.
  • Dependency upgrades: Spring Boot 3.2.12 → 3.5.16 and Jackson 2.21.7 close 9 high-severity CVEs in the backend (including two jackson-databind remote code execution issues) plus the logback CVE-2025-11226. The container image now scans clean for HIGH/CRITICAL issues with Trivy.
  • Frontend build tooling upgraded (Vite 8, Vitest 5); npm audit is clean.
  • The Docker quick start now binds to 127.0.0.1 instead of all interfaces.

Fixes

  • Slow Log and Pub/Sub publishing now work on connections that use ACL usernames, TLS, SSH tunnels, Sentinel, Cluster, Unix sockets or URLs (they previously used only host, port and password).
  • Building the image from source with the root Dockerfile works again.
  • Opening a stream's Consumer Groups tab no longer sends the same request twice.
  • Frontend hook-dependency cleanup so views always use the currently selected database.

⚠️ Upgrade note

If you open Redivue under anything other than localhost — a server domain, a LAN IP, a Tailscale name — set that name in REDIVUE_ALLOWED_HOSTS, or requests will get 403 Host ... is not allowed:

docker run -p 8080:8080 -e REDIVUE_ALLOWED_HOSTS=redivue.example.com ghcr.io/abidinberkay/redivue:1.0.1

See DEPLOYMENT.md → Allowed hosts.

Full changelog: v1.0.0...v1.0.1