Repository navigation
WebSSH 2.5.0 improves everyday connection and workspace workflows and adds optional Warpgate SSH gateway support.
Highlights
- Connect through Warpgate using
user:targetprofiles or Quick SFTP, with interactive authentication, approval prompts and cancellation. Administrators must enable the integration under Settings → Administration → Integrations; it is disabled by default. - Warn before a WebSSH login expires and restore workspace presentation, drafts, layout and surviving sessions after signing in again.
- Manage saved hosts with a persistent compact view, collapsible advanced settings and Save & connect. Reuse groups, favorites, search and connection readiness in the file connection chooser.
- Find commands more easily with target-OS ordering, account-scoped favorites and recent commands, and a remembered command section.
- Navigate Terminal, Files, Commands and Hosts directly on mobile, with more accessible file actions and usable split-pane toolbars.
- Load theme backgrounds faster.
Fixes and maintenance
- Improve tmux directory synchronization after manual input and folder navigation, including compatibility with older tmux formats.
- Preserve multiline paste, terminal control keys and saved transcript line breaks.
- Explain unavailable saved SSH keys and common SFTP failures with clear, sanitized messages.
- Refresh Python and frontend dependencies, including cryptography, Werkzeug, WebAuthn and Socket.IO; regenerate reproducible dependency locks and browser assets.
- Update CI action pins, repository documentation and release history.
Warpgate compatibility
Existing SSH connections keep their normal workflow. Warpgate needs no new WebSSH Compose service or database migration. Gateway terminal targets require PTY and exec support; Quick SFTP requires a temporary PTY and a separate SFTP channel. See the integration guide for activation and limits.
Validation and rollout
The release passed the required CI, browser, integration and native AMD64/ARM64 image-security gates. Real Warpgate acceptance, deployment canaries, upgrade/restore/rollback rehearsal and environment-specific LDAP, Tailscale, Windows SMB and Firefox/Safari checks were not repeated on the final revision. They remain tracked in #254. Warpgate remains disabled by default.
Container
Available as ghcr.io/bifrost0x/webssh:2.5.0 for Linux AMD64 and ARM64, with SBOM and provenance attestations.
Full Changelog: v2.4.0...v2.5.0