Skip to content

Releases: pstoute/queuefix

v1.1.2 — Security and reliability hardening

Choose a tag to compare

@pstoute pstoute released this 15 Sep 17:36
Immutable release. Only release title and notes can be modified.
8b42215

Changed

  • Hardened inbound email ingestion across IMAP, Gmail, and Microsoft Graph with bounded provider hydration, safer attachment handling, stable idempotency, and stricter ticket-thread authorization.
  • Strengthened authentication and recovery flows with single-use links, account-scoped rate limits, reauthentication for identity changes, and consistent session and credential revocation.
  • Reduced sensitive data exposure in agent and customer responses, rendered stored message content inertly, and tightened ticket and portal authorization.
  • Hardened Docker deployment and update workflows, including private service topology, per-installation database credentials, protected backups, verified immutable release tags, secret-safe build contexts, and pinned build inputs.
  • Fixed Docker first boot, PHP IMAP availability, mailbox credential access, mailbox type hydration, and frontend dependency builds.
  • Resolved known JavaScript dependency advisories and made the installed version code-owned so existing environment files cannot report a stale release.

Upgrade

For supported Docker Compose installations, review the upgrade guide and run ./deploy/update-docker.sh v1.1.2 from a clean QueueFix checkout while the current app service is running. The updater verifies this immutable release, creates a restricted PostgreSQL backup, rebuilds services, installs locked dependencies, and runs migrations.

An existing QUEUEFIX_VERSION entry may remain in .env; v1.1.2 ignores it so the installed version always follows the checked-out release.

Verification

The release commit passed PostgreSQL, MySQL, frontend, Docker build, deployment security, formatting, and static-analysis checks. The full local suite passed 543 tests with 2,799 assertions; dependency audits reported no known vulnerabilities.

v1.1.1 — Dependency maintenance

Choose a tag to compare

@pstoute pstoute released this 04 Sep 15:08
cd1f821

Changed

  • Updated league/commonmark from 2.9.0 to 2.10.0, including its required nette/schema update.
  • Aligned the update notifier, sample configuration, and version endpoint with v1.1.1.

Upgrade

Use your normal deployment process. No database migrations or configuration changes are required beyond the existing optional update-check settings.

Verification

CI passed on the release commit with PostgreSQL, MySQL, frontend, lint, and static-analysis checks.

v1.1.0 — Safe update notifications

Choose a tag to compare

@pstoute pstoute released this 30 Aug 17:14
5343f13

Safe update notifications

  • Adds an admin-only Settings → Updates page that compares the installed version with the latest QueueFix GitHub release.
  • Adds GET /version, exposing only the installed application version for deployment checks.
  • Update checks are cached for 12 hours and request public release metadata only; no ticket, mailbox, user, or account content is sent.

Safer upgrades

  • Adds a tag-pinned Docker Compose updater that takes a PostgreSQL backup before code/dependency/migration changes.
  • Adds explicit backup, rollback, and smoke-test documentation. The application never installs a release automatically.

Security

  • Settings routes now enforce the intended administrator authorization boundary.

Verification

  • CI passed on PostgreSQL and MySQL, plus static analysis and frontend checks.

v1.0.0 — Security updates

Choose a tag to compare

@pstoute pstoute released this 01 Aug 16:36
e3fd138

Security updates

This release incorporates the dependency remediation merged in #2.

  • Updated Composer dependencies to patched releases, including Laravel, Symfony, Guzzle, phpseclib, and CommonMark.
  • Updated pnpm dependencies to patched releases, including Axios, DOMPurify, Vite, Vitest, PostCSS and their vulnerable transitive dependencies.
  • Added a direct esbuild 0.28.1 development dependency to remediate the remaining transitive advisory.
  • Dependency audits after the update report no known npm/pnpm vulnerabilities and no Composer security advisories.

Reliability and CI

  • Restored PostgreSQL/MySQL CI by persisting paused SLA durations as integers.
  • Restored lint/static-analysis checks with formatting cleanup and a path-scoped baseline for pre-existing PHPStan diagnostics.
  • CI now passes on PostgreSQL, MySQL, lint/static analysis, and frontend checks.

Note: Composer continues to report doctrine/annotations as abandoned; it has no listed security advisory in this release.