Phase 8 is the production-hardening checkpoint for RedDock's local package. It adds a host-loopback Unix-socket ingress boundary, bounded browser change protection, retained offline-maintenance locking, resource limits, clearer first-run guidance, and architecture-matched Nmap source compliance assets.
The default package remains local, account-free, and fully usable without an LLM. Optional Ollama and PostgreSQL profiles stay isolated behind explicit Compose overlays. Server mode, SSO, and shared-user deployment remain disabled.
Start with docker compose up --build, then open http://localhost:8080. Review the getting-started guide and security boundaries before use.
Published image: ghcr.io/chriswayneh/reddock:v0.8.1
Attested manifest: sha256:914253b8ed0ec09a6ab866909e7def5ba56644f4db2c3fbe1c35fdedcd719606
What's Changed
- Bump actions/checkout from 7.0.0 to 7.0.1 in the actions-minor-patch group across 1 directory by @dependabot[bot] in #8
- Bump the npm-minor-patch group across 1 directory with 7 updates by @dependabot[bot] in #5
- Bump the pip-minor-patch group across 1 directory with 4 updates by @dependabot[bot] in #4
- Bump node from 22-alpine to 26-alpine by @dependabot[bot] in #3
- Bump python from
ffb752eto9d2e555by @dependabot[bot] in #9 - Bump the npm-minor-patch group in /frontend with 6 updates by @dependabot[bot] in #10
- Phase 8: navigation, complete counts, and opt-in API docs by @chriswayneh in #11
- Phase 8: reconcile explicit Nmap service states by @chriswayneh in #13
- Complete Phase 8 list pagination by @chriswayneh in #14
- Replace vulnerable frontend test tooling by @chriswayneh in #15
- Automate fail-closed multi-platform releases by @chriswayneh in #16
- Run the product smoke path on native ARM64 by @chriswayneh in #17
- Add secure offline SQLite backup and recovery by @chriswayneh in #18
- Add dormant OIDC authentication boundary by @chriswayneh in #19
- Present RedDock as a personal project by @chriswayneh in #20
- Polish personal project wording by @chriswayneh in #21
- Polish public documentation for readability by @chriswayneh in #22
- Harden interrupted restore recovery by @chriswayneh in #23
- Make RedDock project description direct by @chriswayneh in #24
- Harden future trusted ingress boundary by @chriswayneh in #25
- Own OIDC caches for the application lifespan by @chriswayneh in #26
- Add durable authentication rate limits by @chriswayneh in #27
- Add secure browser session lifecycle by @chriswayneh in #28
- Build isolated rate limiter runtime by @chriswayneh in #29
- Harden limiter database role isolation by @chriswayneh in #30
- Compose dormant authentication boundary by @chriswayneh in #31
- Own dormant primary database runtime by @chriswayneh in #32
- Bind requests to owned database context by @chriswayneh in #33
- Clarify RedDock project purpose by @chriswayneh in #34
- Clarify that RedDock is open to explore by @chriswayneh in #35
- Tighten RedDock project introduction by @chriswayneh in #36
- Ship v0.8.1 Phase 8 production hardening by @chriswayneh in #37
New Contributors
- @dependabot[bot] made their first contribution in #8
Full Changelog: v0.8.0...v0.8.1