Skip to content

Releases: gioxx/cPanelVault

cPanelVault 2.3.1

Choose a tag to compare

@gioxx gioxx released this 23 Sep 18:13
8020776

Maintenance release.

Fixes

  • Lock file names are now disambiguated with SHA-256 instead of SHA-1, resolving a CodeQL py/weak-sensitive-data-hashing alert (#20). The digest only keeps sanitized lock filenames unique (no secrets involved), so this was not an exploitable weakness.

Upgrade notes

Lock file names under LOCK_DIR change once. Avoid running 2.3.0 and 2.3.1 side by side (e.g. an old CLI next to an updated container) against the same lock directory while a backup is in progress; leftover old lock files are harmless and can be deleted.

Docker images

docker pull gfsolone/cpanelvault:2.3.1
docker pull ghcr.io/gioxx/cpanelvault:2.3.1

Full changelog: 2.3.0...2.3.1

cPanelVault 2.3.0

Choose a tag to compare

@gioxx gioxx released this 23 Sep 18:02
ccecef1

First release with official Docker images.

Docker images

Multi-arch (linux/amd64, linux/arm64):

docker pull gfsolone/cpanelvault:2.3.0
docker pull ghcr.io/gioxx/cpanelvault:2.3.0

latest tracks the newest release; dev tracks main. The bundled docker-compose.yml now uses gfsolone/cpanelvault:latest.

Highlights

  • Backups page: browse local archives per host, with retention, expiry dates, the next archives to be removed and volume usage (#18)
  • Live progress in the web UI: current phase, download progress with speed/ETA, live log; quieter container logs (#16)
  • Interprocess backup lock: CLI and web/scheduler can no longer back up the same cPanel account at the same time; config entries aliasing one account are serialized, and stale "running" states are reconciled safely at startup (#14)
  • FTP robustness: socket timeouts, retries on delete_file, no retry after a successful DELE (#9, #11)
  • Pre-flight checks: disk space check and connectivity retry before a backup (#7)
  • CI: Docker build/publish workflow for Docker Hub and GHCR, serialized per ref (#10, #12)

Upgrading

  • Docker Compose: docker compose pull && docker compose up -d
  • Portainer: Update the stack with Re-pull image enabled (see README)