Releases: gioxx/cPanelVault
Releases · gioxx/cPanelVault
Release list
cPanelVault 2.3.1
Maintenance release.
Fixes
- Lock file names are now disambiguated with SHA-256 instead of SHA-1, resolving a CodeQL
py/weak-sensitive-data-hashingalert (#20). The digest only keeps sanitized lock filenames unique (no secrets involved), so this was not an exploitable weakness.
Upgrade notes
Lock file names under LOCK_DIR change once. Avoid running 2.3.0 and 2.3.1 side by side (e.g. an old CLI next to an updated container) against the same lock directory while a backup is in progress; leftover old lock files are harmless and can be deleted.
Docker images
docker pull gfsolone/cpanelvault:2.3.1
docker pull ghcr.io/gioxx/cpanelvault:2.3.1Full changelog: 2.3.0...2.3.1
cPanelVault 2.3.0
First release with official Docker images.
Docker images
Multi-arch (linux/amd64, linux/arm64):
docker pull gfsolone/cpanelvault:2.3.0
docker pull ghcr.io/gioxx/cpanelvault:2.3.0latest tracks the newest release; dev tracks main. The bundled docker-compose.yml now uses gfsolone/cpanelvault:latest.
Highlights
- Backups page: browse local archives per host, with retention, expiry dates, the next archives to be removed and volume usage (#18)
- Live progress in the web UI: current phase, download progress with speed/ETA, live log; quieter container logs (#16)
- Interprocess backup lock: CLI and web/scheduler can no longer back up the same cPanel account at the same time; config entries aliasing one account are serialized, and stale "running" states are reconciled safely at startup (#14)
- FTP robustness: socket timeouts, retries on
delete_file, no retry after a successfulDELE(#9, #11) - Pre-flight checks: disk space check and connectivity retry before a backup (#7)
- CI: Docker build/publish workflow for Docker Hub and GHCR, serialized per ref (#10, #12)
Upgrading
- Docker Compose:
docker compose pull && docker compose up -d - Portainer: Update the stack with Re-pull image enabled (see README)