Releases: acidflash/PatchPilot
Releases · acidflash/PatchPilot
Release list
v0.6.8
Security fixes
Fixed
- Server: Refuses to start if
APP_SECRETis unset or uses a known default placeholder (change-me), preventing CSRF token forgery via publicly known secret - Agent:
self_update_agent()now treats a missing or empty SHA256 from the server as a hard failure instead of silently skipping integrity verification - install-agent.sh: Same fix — aborts with an error if the server returns an empty SHA256 checksum
See CHANGELOG.md for full history.
v0.6.7
What's Changed
Fixed
- Agent: removed redundant
import hashlib as _hashlibinsideself_update_agent—hashlibis already imported at module level - Agent:
shutilmoved to top-level imports - Agent:
http_jsonnow catchesURLError(network errors) in addition toHTTPError, with a clear error message - Agent: response decoding uses explicit
utf-8witherrors='replace'instead of implicit default - Agent: fallback status check uses
is not Noneinstead of truthiness to avoid incorrect behaviour on empty dict
See CHANGELOG.md for full history.
v0.6.6
What's Changed
Changed
deploy.shno longer runsgit push— push is done separately before deploying
See CHANGELOG.md for full history.
v0.6.5
What's Changed
Changed
- Bumped
APP_VERSIONandAGENT_VERSIONto 0.6.5 to reflect all changes since 0.6.0
See CHANGELOG.md for full history.
v0.6.4
What's Changed
Fixed
- Caddy now correctly expands environment variables in site addresses using
envsubstand a custom entrypoint script — Caddy's native{env.VAR}syntax does not work for site addresses - Agent hostname block is only added to the generated Caddyfile if
CADDY_AGENT_HOSTNAMEis set, preventing a parse error on empty values
Changed
- Caddy is now built from a custom
caddy/Dockerfile(based oncaddy:2-alpinewithgettextforenvsubst) Caddyfilereplaced byCaddyfile.templatewith${VAR}placeholders processed at container startup
See CHANGELOG.md for full history.
v0.6.3
What's Changed
Changed
- Caddy configuration now reads
CADDY_ADMIN_HOSTNAME,CADDY_EMAIL, andCADDY_ACME_CAfrom.envinstead of being hardcoded inCaddyfile - Added
env_file: .envto the Caddy service indocker-compose.yml - Added Caddy variables to
.env.examplewith documentation
See CHANGELOG.md for full history.
v0.6.2
What's Changed
Changed
- Expanded Deployment section in README with step-by-step instructions: prerequisites,
.envreference, Caddy configuration, agent installation, agent approval flow, and ongoing deploys viadeploy.sh
See CHANGELOG.md for full history.
v0.6.1
What's Changed
Added
- GPL-3.0
LICENSEfile with copyright notice - GPL-3.0 copyright headers in all source files
deploy.env.example— template for local deploy configuration
Changed
deploy.shnow readsDEPLOY_HOSTandDEPLOY_DIRfromdeploy.env(gitignored) instead of hardcoded values- All config files sanitized for public release: replaced private hostnames, IPs, and domains with
example.complaceholders .claude/added to.gitignore
Security
- Removed accidentally committed
.envwith live credentials from git history - Scrubbed all private hostnames, IPs, and personal paths from full git history
- Repository made public on GitHub
See CHANGELOG.md for full history.
v0.6.0
What's Changed
Changed
- Translated README.md and INTERNALS.md to English
Added
deploy.shscript for one-command deploy: push local commits, pull on server, rebuild container- CHANGELOG.md
See CHANGELOG.md for full history.