Skip to content

Releases: acidflash/PatchPilot

v0.6.8

Choose a tag to compare

@acidflash acidflash released this 30 May 14:24

Security fixes

Fixed

  • Server: Refuses to start if APP_SECRET is unset or uses a known default placeholder (change-me), preventing CSRF token forgery via publicly known secret
  • Agent: self_update_agent() now treats a missing or empty SHA256 from the server as a hard failure instead of silently skipping integrity verification
  • install-agent.sh: Same fix — aborts with an error if the server returns an empty SHA256 checksum

See CHANGELOG.md for full history.

v0.6.7

Choose a tag to compare

@acidflash acidflash released this 30 May 12:26

What's Changed

Fixed

  • Agent: removed redundant import hashlib as _hashlib inside self_update_agent — hashlib is already imported at module level
  • Agent: shutil moved to top-level imports
  • Agent: http_json now catches URLError (network errors) in addition to HTTPError, with a clear error message
  • Agent: response decoding uses explicit utf-8 with errors='replace' instead of implicit default
  • Agent: fallback status check uses is not None instead of truthiness to avoid incorrect behaviour on empty dict

See CHANGELOG.md for full history.

v0.6.6

Choose a tag to compare

@acidflash acidflash released this 30 May 12:19

What's Changed

Changed

  • deploy.sh no longer runs git push — push is done separately before deploying

See CHANGELOG.md for full history.

v0.6.5

Choose a tag to compare

@acidflash acidflash released this 30 May 12:10

What's Changed

Changed

  • Bumped APP_VERSION and AGENT_VERSION to 0.6.5 to reflect all changes since 0.6.0

See CHANGELOG.md for full history.

v0.6.4

Choose a tag to compare

@acidflash acidflash released this 30 May 12:00

What's Changed

Fixed

  • Caddy now correctly expands environment variables in site addresses using envsubst and a custom entrypoint script — Caddy's native {env.VAR} syntax does not work for site addresses
  • Agent hostname block is only added to the generated Caddyfile if CADDY_AGENT_HOSTNAME is set, preventing a parse error on empty values

Changed

  • Caddy is now built from a custom caddy/Dockerfile (based on caddy:2-alpine with gettext for envsubst)
  • Caddyfile replaced by Caddyfile.template with ${VAR} placeholders processed at container startup

See CHANGELOG.md for full history.

v0.6.3

Choose a tag to compare

@acidflash acidflash released this 30 May 11:40

What's Changed

Changed

  • Caddy configuration now reads CADDY_ADMIN_HOSTNAME, CADDY_EMAIL, and CADDY_ACME_CA from .env instead of being hardcoded in Caddyfile
  • Added env_file: .env to the Caddy service in docker-compose.yml
  • Added Caddy variables to .env.example with documentation

See CHANGELOG.md for full history.

v0.6.2

Choose a tag to compare

@acidflash acidflash released this 30 May 11:10

What's Changed

Changed

  • Expanded Deployment section in README with step-by-step instructions: prerequisites, .env reference, Caddy configuration, agent installation, agent approval flow, and ongoing deploys via deploy.sh

See CHANGELOG.md for full history.

v0.6.1

Choose a tag to compare

@acidflash acidflash released this 30 May 11:08

What's Changed

Added

  • GPL-3.0 LICENSE file with copyright notice
  • GPL-3.0 copyright headers in all source files
  • deploy.env.example — template for local deploy configuration

Changed

  • deploy.sh now reads DEPLOY_HOST and DEPLOY_DIR from deploy.env (gitignored) instead of hardcoded values
  • All config files sanitized for public release: replaced private hostnames, IPs, and domains with example.com placeholders
  • .claude/ added to .gitignore

Security

  • Removed accidentally committed .env with live credentials from git history
  • Scrubbed all private hostnames, IPs, and personal paths from full git history
  • Repository made public on GitHub

See CHANGELOG.md for full history.

v0.6.0

Choose a tag to compare

@acidflash acidflash released this 30 May 11:06

What's Changed

Changed

  • Translated README.md and INTERNALS.md to English

Added

  • deploy.sh script for one-command deploy: push local commits, pull on server, rebuild container
  • CHANGELOG.md

See CHANGELOG.md for full history.