Releases: crypt0rr/EdgeWatch
Release list
EdgeWatch 0.20.1
What's Changed
Full Changelog: v0.20.0...v0.20.1
EdgeWatch 0.20.0
Highlights
Business units. Several internal teams can now share one EdgeWatch deployment and its database. Each unit has its own accounts, jobs, scans, baselines, incidents, notification destinations, custom scanner profiles and public status page, and the application keeps them apart.
- Every installation becomes the Default unit on upgrade and keeps working as before. Administrators get a new read-only Audit page, and the public page is also served at
/public/default. - A platform administrator is a separate account created from the host (
edgewatch admin platform-setup-token). It creates units, sets their capacity, invites their first administrators and reads the platform audit, and sees units only as counts, never their data. - Once a second unit exists, every administrator must use TOTP.
- New units start with update alerts off, publish their own page at
/public/<slug>, and can be capped in scan slots and probe budgets. - Disabling a unit pauses it; deleting a disabled unit erases its data with a resumable purge.
See the README section "Business units", and SECURITY.md for the trust boundary: isolation is enforced in the application, and host, container, CLI, database and backup access reach every unit.
Upgrading from v0.19.0
- Back up
./datafirst. The first start migrates the database through schemas 51–54, including a one-time rebuild of the users, jobs, scanner profiles and notification destinations tables and a resumable re-keying of the latest-host view.edgewatch healthreports progress. - The upgrade is one-way: a v0.19.0 binary cannot open the upgraded database. Roll back by restoring the backup.
- If you tried the business units preview, remove
experimental.business_unitsfrom config.yaml; EdgeWatch still starts with it and logs a warning.
What's Changed
- feat(app): schedule scans through a fair per-key slot pool by @crypt0rr in #840
- feat(store): add tenants and move singletons to the default tenant (schema 51) by @crypt0rr in #841
- feat(store): rebuild root tables with tenant ownership (schema 52) by @crypt0rr in #842
- feat(store): attribute scans, events and deliveries to tenants (schema 53) by @crypt0rr in #843
- feat(store): key the latest host projection by tenant (schema 54) by @crypt0rr in #844
- test: open fresh databases from a migrated template by @crypt0rr in #846
- feat(store): add tenant scopes, a table registry and a tenant SQL lint by @crypt0rr in #845
- refactor(web): pass the tenant store to every tenant handler by @crypt0rr in #847
- refactor(store): scope scan and host reads by tenant by @crypt0rr in #848
- refactor(store): scope history and incident methods by tenant by @crypt0rr in #849
- refactor(store): scope job methods by tenant by @crypt0rr in #850
- refactor(store): scope scanner profiles by tenant by @crypt0rr in #851
- refactor(store): scope runtime and baseline methods by tenant by @crypt0rr in #852
- refactor(store): scope scan cycle reads by tenant by @crypt0rr in #853
- refactor(store): scope notification destinations and routing by tenant by @crypt0rr in #854
- refactor(store): scope public status by tenant by @crypt0rr in #855
- refactor(store): move daemon methods to the system store by @crypt0rr in #856
- test(store): stop the backup snapshot test timing out under load by @crypt0rr in #857
- refactor(store): scope accounts and audit by tenant by @crypt0rr in #858
- refactor(cli): use scoped stores in host commands by @crypt0rr in #859
- refactor(app): run every tenant's jobs through its own tenant store by @crypt0rr in #860
- refactor(store): delete the unscoped store wrappers and enforce the tenant lint by @crypt0rr in #861
- feat(config): add an experimental.business_units flag by @crypt0rr in #863
- feat(app): cap scan slots and probe budgets per business unit by @crypt0rr in #864
- feat(auth): add the platform administrator and business unit account rules by @crypt0rr in #865
- feat(store): add unit and platform audit views by @crypt0rr in #866
- feat(store): add business unit lifecycle and a resumable purge by @crypt0rr in #867
- feat(app): fan update alerts out per business unit and scope active scans by @crypt0rr in #868
- feat: add business units by @crypt0rr in #884
- fix(ci): read diffs larger than 1 MiB in the diff coverage gate by @crypt0rr in #885
Full Changelog: v0.19.0...v0.20.0
EdgeWatch 0.19.0
Upgrade notes
EdgeWatch 0.19.0 collects the changes released since 0.18.141. Some of them change compatibility or behavior, so back up ./data before you upgrade. Database migrations are forward-only: to roll back, restore that backup.
Before you upgrade
- Database schema 47 → 50.
- The first start rebuilds the baseline host search index in resumable batches.
edgewatch healthshows the progress. - After the upgrade, older binaries refuse the database.
- The daemon and the host commands that write to the database refuse a schema newer than they support.
- The first start rebuilds the baseline host search index in resumable batches.
- Notification URLs in
config.yamlare deprecated (#830).- On first start, the daemon imports
notifications.urlsandnotifications.urls_fileonce, as encrypted destinations in the web console. Jobs, update-alert routing and queued alerts are moved to the imported destinations. - Remove the URLs from
config.yamlafterwards;edgewatch healthand the Notifications page remind you. - Back up
notification.keytogether with the database. - A later release will refuse to start while these keys are set.
- On first start, the daemon imports
Changed behavior
- Public status API:
PUT /api/v1/public-dashboardnow requires theupdated_atvalue from the GET response. An outdated editor gets 409conflict. notify test: prints a JSON summary. It exits non-zero, and the console test returns 503, when an enabled destination is locked by a missing or wrong key. Each destination now gets one test message.restore --dry-run: runs the same checks as a real restore. It reportssafeand arefusal, and exits non-zero when the restore would be refused.- Restore leases: restore clears the leases copied from the backup, so the daemon starts straight away after a restore.
- CLI logs: commands other than
daemonlog to stderr, so--output jsonprints clean JSON. edgewatch status: reports astatefor each job, and showsnext_runonly for scheduled jobs.- Second daemon: a daemon that finds another daemon's live lease exits before it migrates the database.
- Naabu SYN scans with host discovery: addresses that return no results are reported as incomplete instead of fully scanned.
- UDP open|filtered ports: ports that Nmap folds into
<extraports>are now recorded, so hosts with more than 25 such ports gain them in their baseline. - Job names: limited to 200 characters, without control characters. Existing longer names must be shortened on their next edit.
- Operators: the console no longer shows them permanent delete or high-cost scan approval, which the API always rejected.
- TOTP enrolment: a mistyped code no longer discards the enrolment; each enrolment allows five wrong codes.
All changes since 0.18.141: v0.18.141...v0.19.0. The list below covers the changes since 0.18.146.
What's Changed
- feat(store): add a foreign-keys-off runner for table rebuilds by @crypt0rr in #835
- test(web): add a route inventory with a drift test and inventory-driven permission matrix by @crypt0rr in #836
- refactor(web): resolve jobs and scans once and route live updates through audiences by @crypt0rr in #838
- chore(deps): update dependency @tanstack/react-query to v5.104.0 by @renovate[bot] in #832
- chore(deps): update dependency @types/node to v24.19.0 by @renovate[bot] in #833
- chore(deps): update dependency react-hook-form to v7.89.0 by @renovate[bot] in #837
Full Changelog: v0.18.146...v0.19.0
EdgeWatch 0.18.146
What's Changed
Full Changelog: v0.18.145...v0.18.146
EdgeWatch 0.18.145
What's Changed
Full Changelog: v0.18.144...v0.18.145
EdgeWatch 0.18.144
What's Changed
- fix(notify): make notification tests, delivery passes, and queued alerts reliable by @crypt0rr in #829
Full Changelog: v0.18.143...v0.18.144
EdgeWatch 0.18.143
What's Changed
- test(store): bound each discard separately in the unpromoted-cycle test by @crypt0rr in #813
- fix(store): keep baseline search, incident views and scope hashes consistent by @crypt0rr in #812
- test(e2e): honor PLAYWRIGHT_PORT in the role matrix spec by @crypt0rr in #815
- fix(notify): keep job routing valid when a destination disappears by @crypt0rr in #814
- feat(ui): link the console version to its GitHub release by @crypt0rr in #817
- fix(store): keep live SQLite sidecars and refuse unsafe writable opens by @crypt0rr in #818
- fix(cli): align restore dry run, status, JSON output, and scan audit by @crypt0rr in #820
- fix(scanner): keep scan coverage and probe budgets truthful by @crypt0rr in #819
- ci: give race tests headroom on slow runners and fix a run-conflict flake by @crypt0rr in #822
- fix(web): tighten write error mapping, account mutations, and public status by @crypt0rr in #824
- fix(app): keep resumable cycles, queued runs and the silence watchdog truthful by @crypt0rr in #823
- fix(store): key baseline host search by rowid by @crypt0rr in #825
- fix(ui): keep console state and controls consistent with the API by @crypt0rr in #827
- fix: clear restored leases and release run reservations before completion by @crypt0rr in #828
Full Changelog: v0.18.142...v0.18.143
EdgeWatch 0.18.142
What's Changed
- ci: shorten artifact retention and skip Docker build records by @crypt0rr in #761
- fix(auth): apply web.auth_key_file before the admin TOTP migration by @crypt0rr in #800
- fix(engine): stop new-port fingerprint flapping and total-loss re-guarding by @crypt0rr in #811
Full Changelog: v0.18.141...v0.18.142
EdgeWatch 0.18.141
What's Changed
- feat(config): follow a deployment timezone from config.yaml by @crypt0rr in #758
- fix(e2e): start a fresh preview server unless reuse is requested by @crypt0rr in #760
Full Changelog: v0.18.140...v0.18.141
EdgeWatch 0.18.140
What's Changed
- [P3] Remove obsolete auth paths and align role documentation by @crypt0rr in #752
- [P3] Restrict the notification provider child environment by @crypt0rr in #753
- [P3] Correct Nmap profile durations and scanner diagnostics by @crypt0rr in #754
- [P3] Make authentication reads read-only by @crypt0rr in #755
- [P3] Batch job-list state reads by @crypt0rr in #756
Full Changelog: v0.18.139...v0.18.140