Skip to content

EdgeWatch 0.19.0

Choose a tag to compare

@github-actions github-actions released this 26 Sep 08:56
· 78 commits to main since this release
321c8a6

Upgrade notes

EdgeWatch 0.19.0 collects the changes released since 0.18.141. Some of them change compatibility or behavior, so back up ./data before you upgrade. Database migrations are forward-only: to roll back, restore that backup.

Before you upgrade

  • Database schema 47 → 50.
    • The first start rebuilds the baseline host search index in resumable batches. edgewatch health shows the progress.
    • After the upgrade, older binaries refuse the database.
    • The daemon and the host commands that write to the database refuse a schema newer than they support.
  • Notification URLs in config.yaml are deprecated (#830).
    • On first start, the daemon imports notifications.urls and notifications.urls_file once, as encrypted destinations in the web console. Jobs, update-alert routing and queued alerts are moved to the imported destinations.
    • Remove the URLs from config.yaml afterwards; edgewatch health and the Notifications page remind you.
    • Back up notification.key together with the database.
    • A later release will refuse to start while these keys are set.

Changed behavior

  • Public status API: PUT /api/v1/public-dashboard now requires the updated_at value from the GET response. An outdated editor gets 409 conflict.
  • notify test: prints a JSON summary. It exits non-zero, and the console test returns 503, when an enabled destination is locked by a missing or wrong key. Each destination now gets one test message.
  • restore --dry-run: runs the same checks as a real restore. It reports safe and a refusal, and exits non-zero when the restore would be refused.
  • Restore leases: restore clears the leases copied from the backup, so the daemon starts straight away after a restore.
  • CLI logs: commands other than daemon log to stderr, so --output json prints clean JSON.
  • edgewatch status: reports a state for each job, and shows next_run only for scheduled jobs.
  • Second daemon: a daemon that finds another daemon's live lease exits before it migrates the database.
  • Naabu SYN scans with host discovery: addresses that return no results are reported as incomplete instead of fully scanned.
  • UDP open|filtered ports: ports that Nmap folds into <extraports> are now recorded, so hosts with more than 25 such ports gain them in their baseline.
  • Job names: limited to 200 characters, without control characters. Existing longer names must be shortened on their next edit.
  • Operators: the console no longer shows them permanent delete or high-cost scan approval, which the API always rejected.
  • TOTP enrolment: a mistyped code no longer discards the enrolment; each enrolment allows five wrong codes.

All changes since 0.18.141: v0.18.141...v0.19.0. The list below covers the changes since 0.18.146.

What's Changed

  • feat(store): add a foreign-keys-off runner for table rebuilds by @crypt0rr in #835
  • test(web): add a route inventory with a drift test and inventory-driven permission matrix by @crypt0rr in #836
  • refactor(web): resolve jobs and scans once and route live updates through audiences by @crypt0rr in #838
  • chore(deps): update dependency @tanstack/react-query to v5.104.0 by @renovate[bot] in #832
  • chore(deps): update dependency @types/node to v24.19.0 by @renovate[bot] in #833
  • chore(deps): update dependency react-hook-form to v7.89.0 by @renovate[bot] in #837

Full Changelog: v0.18.146...v0.19.0