v1.1.2: install.sh reports the repository version, and the docs carry no private identifiers
Housekeeping release. No hardening rule, default, or access path changes -- every
change below is documentation, tooling, or repository hygiene. It is safe to
apply on a running server, and it changes nothing on one.
Two release commits (1.1.0 and 1.1.1) were never tagged, so the last
published release was v1.0.1 from January 2026. This release supersedes both;
v1.1.0 and v1.1.1 will not receive tags of their own.
Added
install.sh --versionanswers "which hardening level is running on this server?"
correctly again. AVERSIONfile in the repository root is now the single source of
the project version, andinstall.shreads it at runtime, falling back tounknown
instead of failing. Until now the constant ininstall.shreported1.0.0while the
changelog stood at1.1.1, two releases of drift in the one number an operator quotes.- Bug reports and pull requests arrive in a usable shape.
.github/ISSUE_TEMPLATE/(bug report, feature request, config) and
.github/PULL_REQUEST_TEMPLATE.md.
Changed
- A tagged release now carries the changelog section instead of the commit subjects.
.github/workflows/release.ymlbuilds the release notes from the matching
CHANGELOG.mdsection instead ofgenerate_release_notes: true. Release commits in
this repository carry a barevX.Y.Zline as their subject, so generated notes said
nothing the tag did not already say. The job fails loudly when a tag has no usable
changelog section rather than publishing an empty release.
softprops/action-gh-releasemoved fromv1tov2. - The ShellCheck threshold now lives where it takes effect. The
severity=warning
line was removed from.shellcheckrc. ShellCheck has noseveritykey for that file
and discards unknown keys without a diagnostic, so the line looked like a setting and
did nothing. Measured across all 40 scripts: 49 messages with the line present, 49 with
a nonsense key in its place, 37 with--severity=warningon the command line. The
binding threshold lives inlint.yml(--severity=error) and is now documented as such. - fail2ban alerts identify the host they came from, on any host.
fail2ban/actions/telegram-send.sh(2.0.0 -> 2.0.1) no longer hardcodes two specific
hostnames in the alert prefix. It defaults to the short hostname, documents how to add
per-host cases, and now honours anALERT_PREFIXset in the secrets file; the previous
assignment was unconditional and would have discarded one.
Fixed
- Four relative documentation links resolve again.
aide/README.mdand
aide/docs/SETUP.mdpointed atPROMETHEUS_INTEGRATION.mdandFAILURE_ALERTING.md
inside the component directory, while both live in the repository-leveldocs/;
fail2ban/README.mdlinkedTELEGRAM_ALERTS.md, which is named
TELEGRAM_INTEGRATION.md. - The
1.1.1release is reachable from this file. It had no link definition and no
row in the version history table; both were added. The1.1.0and1.1.1link
definitions now point at their commits rather than at compare ranges between tags that
were never created, which returned 404.
Removed
- Two marketing drafts are no longer part of the published tree.
aide/LINKEDIN_POST.mdandaide/REDDIT_POST.mdwere tracked and therefore public.
.gitignorecarries matching entries, but ignore rules only apply to untracked files,
sogit check-ignorereports them as not ignored, which reads like a different
problem. The root-level copies were removed in January 2026; these two were missed.
Security
- The published documentation no longer carries identifiers from the author's own
infrastructure. None of it affected the hardening rules, and all of it was public.
Corrected in.shellcheckrc,fail2ban/actions/telegram-send.shand its
documentation,fail2ban/docs/GEOIP_FILTERING.md,
nftables/docs/WIREGUARD_INTEGRATION.md,ufw/docs/SETUP.md,
usb-defense/docs/THREE_LAYER_DEFENSE.md, and five files undernftables/. Examples
now use RFC 2606 names, the generic accountadmin, and a target derived at runtime;
attributions read "a production gateway config". Generic references to Raspberry Pi OS
as a supported platform are deliberately kept. - The remaining German documentation is readable to the audience this repository has.
Translated into English: the whole ofufw/docs/andufw/examples/,
ufw/drop-ins/README.md, and one code comment in
security-monitoring/scripts/security-log-monitor.sh. This is not cosmetic for a
security repository: a reader who cannot read a rule's rationale applies the rule
without understanding it.
Upgrade notes
None required. No firewall rule, sshd option, sysctl value, fail2ban threshold,
or installation path changed. install.sh --version now reports the repository
version instead of 1.0.0; if any tooling parsed that constant, it will now see
1.1.2.