EdgeWatch 0.19.0
Upgrade notes
EdgeWatch 0.19.0 collects the changes released since 0.18.141. Some of them change compatibility or behavior, so back up ./data before you upgrade. Database migrations are forward-only: to roll back, restore that backup.
Before you upgrade
- Database schema 47 → 50.
- The first start rebuilds the baseline host search index in resumable batches.
edgewatch healthshows the progress. - After the upgrade, older binaries refuse the database.
- The daemon and the host commands that write to the database refuse a schema newer than they support.
- The first start rebuilds the baseline host search index in resumable batches.
- Notification URLs in
config.yamlare deprecated (#830).- On first start, the daemon imports
notifications.urlsandnotifications.urls_fileonce, as encrypted destinations in the web console. Jobs, update-alert routing and queued alerts are moved to the imported destinations. - Remove the URLs from
config.yamlafterwards;edgewatch healthand the Notifications page remind you. - Back up
notification.keytogether with the database. - A later release will refuse to start while these keys are set.
- On first start, the daemon imports
Changed behavior
- Public status API:
PUT /api/v1/public-dashboardnow requires theupdated_atvalue from the GET response. An outdated editor gets 409conflict. notify test: prints a JSON summary. It exits non-zero, and the console test returns 503, when an enabled destination is locked by a missing or wrong key. Each destination now gets one test message.restore --dry-run: runs the same checks as a real restore. It reportssafeand arefusal, and exits non-zero when the restore would be refused.- Restore leases: restore clears the leases copied from the backup, so the daemon starts straight away after a restore.
- CLI logs: commands other than
daemonlog to stderr, so--output jsonprints clean JSON. edgewatch status: reports astatefor each job, and showsnext_runonly for scheduled jobs.- Second daemon: a daemon that finds another daemon's live lease exits before it migrates the database.
- Naabu SYN scans with host discovery: addresses that return no results are reported as incomplete instead of fully scanned.
- UDP open|filtered ports: ports that Nmap folds into
<extraports>are now recorded, so hosts with more than 25 such ports gain them in their baseline. - Job names: limited to 200 characters, without control characters. Existing longer names must be shortened on their next edit.
- Operators: the console no longer shows them permanent delete or high-cost scan approval, which the API always rejected.
- TOTP enrolment: a mistyped code no longer discards the enrolment; each enrolment allows five wrong codes.
All changes since 0.18.141: v0.18.141...v0.19.0. The list below covers the changes since 0.18.146.
What's Changed
- feat(store): add a foreign-keys-off runner for table rebuilds by @crypt0rr in #835
- test(web): add a route inventory with a drift test and inventory-driven permission matrix by @crypt0rr in #836
- refactor(web): resolve jobs and scans once and route live updates through audiences by @crypt0rr in #838
- chore(deps): update dependency @tanstack/react-query to v5.104.0 by @renovate[bot] in #832
- chore(deps): update dependency @types/node to v24.19.0 by @renovate[bot] in #833
- chore(deps): update dependency react-hook-form to v7.89.0 by @renovate[bot] in #837
Full Changelog: v0.18.146...v0.19.0