Skip to content

v1.1.2: install.sh reports the repository version, and the docs carry no private identifiers

Choose a tag to compare

@github-actions github-actions released this 09 Aug 10:44
· 4 commits to main since this release

Housekeeping release. No hardening rule, default, or access path changes -- every
change below is documentation, tooling, or repository hygiene. It is safe to
apply on a running server, and it changes nothing on one.

Two release commits (1.1.0 and 1.1.1) were never tagged, so the last
published release was v1.0.1 from January 2026. This release supersedes both;
v1.1.0 and v1.1.1 will not receive tags of their own.

Added

  • install.sh --version answers "which hardening level is running on this server?"
    correctly again.
    A VERSION file in the repository root is now the single source of
    the project version, and install.sh reads it at runtime, falling back to unknown
    instead of failing. Until now the constant in install.sh reported 1.0.0 while the
    changelog stood at 1.1.1, two releases of drift in the one number an operator quotes.
  • Bug reports and pull requests arrive in a usable shape.
    .github/ISSUE_TEMPLATE/ (bug report, feature request, config) and
    .github/PULL_REQUEST_TEMPLATE.md.

Changed

  • A tagged release now carries the changelog section instead of the commit subjects.
    .github/workflows/release.yml builds the release notes from the matching
    CHANGELOG.md section instead of generate_release_notes: true. Release commits in
    this repository carry a bare vX.Y.Z line as their subject, so generated notes said
    nothing the tag did not already say. The job fails loudly when a tag has no usable
    changelog section rather than publishing an empty release.
    softprops/action-gh-release moved from v1 to v2.
  • The ShellCheck threshold now lives where it takes effect. The severity=warning
    line was removed from .shellcheckrc. ShellCheck has no severity key for that file
    and discards unknown keys without a diagnostic, so the line looked like a setting and
    did nothing. Measured across all 40 scripts: 49 messages with the line present, 49 with
    a nonsense key in its place, 37 with --severity=warning on the command line. The
    binding threshold lives in lint.yml (--severity=error) and is now documented as such.
  • fail2ban alerts identify the host they came from, on any host.
    fail2ban/actions/telegram-send.sh (2.0.0 -> 2.0.1) no longer hardcodes two specific
    hostnames in the alert prefix. It defaults to the short hostname, documents how to add
    per-host cases, and now honours an ALERT_PREFIX set in the secrets file; the previous
    assignment was unconditional and would have discarded one.

Fixed

  • Four relative documentation links resolve again. aide/README.md and
    aide/docs/SETUP.md pointed at PROMETHEUS_INTEGRATION.md and FAILURE_ALERTING.md
    inside the component directory, while both live in the repository-level docs/;
    fail2ban/README.md linked TELEGRAM_ALERTS.md, which is named
    TELEGRAM_INTEGRATION.md.
  • The 1.1.1 release is reachable from this file. It had no link definition and no
    row in the version history table; both were added. The 1.1.0 and 1.1.1 link
    definitions now point at their commits rather than at compare ranges between tags that
    were never created, which returned 404.

Removed

  • Two marketing drafts are no longer part of the published tree.
    aide/LINKEDIN_POST.md and aide/REDDIT_POST.md were tracked and therefore public.
    .gitignore carries matching entries, but ignore rules only apply to untracked files,
    so git check-ignore reports them as not ignored, which reads like a different
    problem. The root-level copies were removed in January 2026; these two were missed.

Security

  • The published documentation no longer carries identifiers from the author's own
    infrastructure.
    None of it affected the hardening rules, and all of it was public.
    Corrected in .shellcheckrc, fail2ban/actions/telegram-send.sh and its
    documentation, fail2ban/docs/GEOIP_FILTERING.md,
    nftables/docs/WIREGUARD_INTEGRATION.md, ufw/docs/SETUP.md,
    usb-defense/docs/THREE_LAYER_DEFENSE.md, and five files under nftables/. Examples
    now use RFC 2606 names, the generic account admin, and a target derived at runtime;
    attributions read "a production gateway config". Generic references to Raspberry Pi OS
    as a supported platform are deliberately kept.
  • The remaining German documentation is readable to the audience this repository has.
    Translated into English: the whole of ufw/docs/ and ufw/examples/,
    ufw/drop-ins/README.md, and one code comment in
    security-monitoring/scripts/security-log-monitor.sh. This is not cosmetic for a
    security repository: a reader who cannot read a rule's rationale applies the rule
    without understanding it.

Upgrade notes

None required. No firewall rule, sshd option, sysctl value, fail2ban threshold,
or installation path changed. install.sh --version now reports the repository
version instead of 1.0.0; if any tooling parsed that constant, it will now see
1.1.2.