Releases: pstoute/queuefix
Release list
v1.1.2 — Security and reliability hardening
Changed
- Hardened inbound email ingestion across IMAP, Gmail, and Microsoft Graph with bounded provider hydration, safer attachment handling, stable idempotency, and stricter ticket-thread authorization.
- Strengthened authentication and recovery flows with single-use links, account-scoped rate limits, reauthentication for identity changes, and consistent session and credential revocation.
- Reduced sensitive data exposure in agent and customer responses, rendered stored message content inertly, and tightened ticket and portal authorization.
- Hardened Docker deployment and update workflows, including private service topology, per-installation database credentials, protected backups, verified immutable release tags, secret-safe build contexts, and pinned build inputs.
- Fixed Docker first boot, PHP IMAP availability, mailbox credential access, mailbox type hydration, and frontend dependency builds.
- Resolved known JavaScript dependency advisories and made the installed version code-owned so existing environment files cannot report a stale release.
Upgrade
For supported Docker Compose installations, review the upgrade guide and run ./deploy/update-docker.sh v1.1.2 from a clean QueueFix checkout while the current app service is running. The updater verifies this immutable release, creates a restricted PostgreSQL backup, rebuilds services, installs locked dependencies, and runs migrations.
An existing QUEUEFIX_VERSION entry may remain in .env; v1.1.2 ignores it so the installed version always follows the checked-out release.
Verification
The release commit passed PostgreSQL, MySQL, frontend, Docker build, deployment security, formatting, and static-analysis checks. The full local suite passed 543 tests with 2,799 assertions; dependency audits reported no known vulnerabilities.
v1.1.1 — Dependency maintenance
Changed
- Updated
league/commonmarkfrom 2.9.0 to 2.10.0, including its requirednette/schemaupdate. - Aligned the update notifier, sample configuration, and version endpoint with
v1.1.1.
Upgrade
Use your normal deployment process. No database migrations or configuration changes are required beyond the existing optional update-check settings.
Verification
CI passed on the release commit with PostgreSQL, MySQL, frontend, lint, and static-analysis checks.
v1.1.0 — Safe update notifications
Safe update notifications
- Adds an admin-only Settings → Updates page that compares the installed version with the latest QueueFix GitHub release.
- Adds
GET /version, exposing only the installed application version for deployment checks. - Update checks are cached for 12 hours and request public release metadata only; no ticket, mailbox, user, or account content is sent.
Safer upgrades
- Adds a tag-pinned Docker Compose updater that takes a PostgreSQL backup before code/dependency/migration changes.
- Adds explicit backup, rollback, and smoke-test documentation. The application never installs a release automatically.
Security
- Settings routes now enforce the intended administrator authorization boundary.
Verification
- CI passed on PostgreSQL and MySQL, plus static analysis and frontend checks.
v1.0.0 — Security updates
Security updates
This release incorporates the dependency remediation merged in #2.
- Updated Composer dependencies to patched releases, including Laravel, Symfony, Guzzle, phpseclib, and CommonMark.
- Updated pnpm dependencies to patched releases, including Axios, DOMPurify, Vite, Vitest, PostCSS and their vulnerable transitive dependencies.
- Added a direct
esbuild0.28.1 development dependency to remediate the remaining transitive advisory. - Dependency audits after the update report no known npm/pnpm vulnerabilities and no Composer security advisories.
Reliability and CI
- Restored PostgreSQL/MySQL CI by persisting paused SLA durations as integers.
- Restored lint/static-analysis checks with formatting cleanup and a path-scoped baseline for pre-existing PHPStan diagnostics.
- CI now passes on PostgreSQL, MySQL, lint/static analysis, and frontend checks.
Note: Composer continues to report
doctrine/annotationsas abandoned; it has no listed security advisory in this release.