Releases: tomck/WhatChanged
Release list
Pending Changes Tripwire 17.0.1.5 alpha
Pending Changes Tripwire 17.0.1.5 alpha
This maintenance alpha makes the embedded watcher's Apache installation and
health-check output less ambiguous.
The attribution-sensor installer now labels apachectl configtest as a check
of the host's complete Apache configuration. Existing virtual hosts or modules
may print warnings during that check. WhatChanged does not create or modify
Apache DocumentRoot directives, and Apache is not reloaded if validation
fails.
The command-line doctor now distinguishes sensor configuration from runtime
loading. It reports sensor_configured=yes only when the Apache PHP
configuration points to a readable sensor file and reports
sensor_loaded=not_applicable_cli, because PHP CLI cannot prove that Apache
loaded the sensor. The FreePBX Reports page remains the authoritative runtime
check.
Installation and feedback commands now resolve the command-line utility from
FreePBX's configured AMPWEBROOT. They no longer depend on a convenience
symlink that existed only in the development Docker image.
The watcher now compares protected AstDB snapshots consistently. Unchanged
sensitive entries such as AMPUSER passwords no longer appear as permanent
redacted-to-redacted changes after Apply Config. The report also provides one
button to expand or collapse all evidence panels.
A successful authenticated Apply Config breadcrumb can now refresh the applied
baseline even when FreePBX's global reload flag turns on and off between two
watcher scans.
The shared module archive supports FreePBX 14, 15, 16, and 17. The embedded
watcher is version 0.1.4. WhatChanged remains a bounded, read-only observer; it
does not Apply Config, reload Asterisk, or claim universal coverage.
Pending Changes Tripwire 17.0.1.4 alpha
Pending Changes Tripwire 17.0.1.4 alpha
This corrective release fixes the FreePBX module-signing mode used by the
17.0.1.3 archive.
The earlier release was signed with FreePBX's host-local --local mode. Its
embedded module.sig therefore referenced a PBX-specific
pendingchanges.sig sidecar that could not travel with the archive. On another
PBX, FreePBX correctly raised a red Module has been tampered warning and
reported that pendingchanges.sig was missing.
17.0.1.4 uses a normal distributable module.sig. The signing and independent
verification programs now reject any release that is host-local or references
the missing sidecar. Until the maintainer's key is certified by Sangoma, a
stock PBX may still identify the key as untrusted or invalid; that trust status
is distinct from a missing-file or tampering failure.
Watcher 0.1.3 and the configuration-drift implementation are unchanged from
17.0.1.3. One shared module archive continues to support FreePBX 14, 15, 16,
and 17.
Pending Changes Tripwire 17.0.1.3 alpha
Warning
Do not install this release. Its FreePBX module.sig was generated in
host-local mode and depends on a pendingchanges.sig sidecar that is not in
the archive. FreePBX therefore reports the installed module as tampered.
Install 17.0.1.4,
which corrects the signing mode and adds a regression check for this defect.
Pending Changes Tripwire 17.0.1.3 alpha
This security-hardening release made three assurance boundaries explicit:
- Sensitive configuration values become installation-keyed fingerprints
before either watcher or framework-fallback baseline persistence. Public
status, feedback, and rendered diffs show only[redacted]. - The framework fallback and administrator-request sensor support FreePBX's
configuredAMPWEBROOTinstead of assuming/var/www/html. - The watcher persists continuity evidence across restarts. If configuration
changes while it cannot prove continuity, the page reports Baseline
continuity uncertain until an observed successful Apply Config establishes
a new trusted baseline. - Transient database or filesystem failures are logged and retried without
terminating the watcher service.
The release added adversarial tests for generic key/value secrets, custom web
roots, and Apply Config around watcher interruptions. It remains one shared
module archive for FreePBX 14, 15, 16, and 17, with the watcher embedded.
Thank you to @kierknoby, whose ChatGPT-produced
independent static review identified these hardening targets.
WhatChanged remains a read-only observer. Anything outside its explicit
coverage contract may not be detected, and administrator attribution is
inferred rather than proven.
Pending Changes Tripwire 17.0.1.2 alpha
Pending Changes Tripwire 17.0.1.2 alpha
This compatibility release removes the assumption that every FreePBX system
uses /var/www/html. The installation instructions ask fwconsole for the
configured AMPWEBROOT, and the embedded watcher reads the same FreePBX setting
when it installs its service. Both module extraction and module-tree drift
monitoring therefore follow the PBX's actual web root.
The same archive supports FreePBX 14, 15, 16, and 17 and still contains the
complete watcher payload. See the
alpha installation guide for the copy-and-paste install,
verification, feedback, and removal steps.
WhatChanged remains a read-only observer: anything outside its explicit
coverage contract may not be detected, and administrator attribution is
inferred rather than proven.
Pending Changes Tripwire 17.0.1.1 alpha
Pending Changes Tripwire 17.0.1.1 alpha
The shared FreePBX 14–17 module now includes the complete WhatChanged watcher
payload. After installing the module, a root-capable administrator can install
and configure the OS service without downloading a second artifact:
sudo /var/www/html/admin/modules/pendingchanges/bin/install-watcherThe installer detects Debian-family and RHEL/CentOS/Sangoma-family systems,
preserves existing watcher configuration and evidence during upgrades, and
refuses an unknown OS unless the operator explicitly selects a reviewed layout.
FreePBX Module Admin does not run the privileged installer automatically.
Local MariaDB installations receive a generated SELECT-only watcher account.
For a remote database, the installer places the reviewed files but deliberately
leaves the service disabled until an administrator supplies a SELECT-only
credential in /etc/what-changed-watcher.env.
Standalone Debian and portable watcher packages remain available. WhatChanged
is a read-only observer: anything outside its explicit coverage contract may
not be detected, and administrator attribution is inferred rather than proven.
Pending Changes Tripwire 17.0.1.0 alpha
Pending Changes Tripwire 17.0.1.0 alpha
One shared PHP implementation supports FreePBX 14–17. The recommended shared
archive is pendingchanges-17.0.1.0.tgz for every supported version.
See shared module compatibility.
The same archive passed disposable real-image lifecycle tests on FreePBX 14,
15, 16 and 17. FreePBX 17 coverage includes representative extensions, ring
groups, queues, SIP and Advanced Settings, AstDB, module state, User Management,
Fax Configuration, outbound routes and custom trunks. WhatChanged remains a
read-only observer: anything outside its explicit coverage contract may not be
detected, and administrator attribution is inferred rather than proven.
Install the separate watcher using the alpha guide
or legacy guide.
WhatChanged watcher 0.1.2 alpha
WhatChanged watcher 0.1.2 public alpha
This release publishes observer-health metadata with each completed snapshot so
the FreePBX module can distinguish current, delayed, and stale evidence. It also
records the expected lightweight and full-scan intervals without changing the
watcher's read-only database privileges.
FreePBX 17 uses the Debian package. FreePBX 14-16 candidates use the portable
systemd bundle. The watcher sends no telemetry, never Apply Configs or reloads
Asterisk, and observes only the explicitly listed bounded sources.
Pending Changes Tripwire 17.0.0.12 alpha
Pending Changes Tripwire 17.0.0.12 public alpha
Primary FreePBX 17 public-alpha module for the WhatChanged read-only observer.
This release adds an explicit watcher-health panel based on the age of the last
completed full observation, reports whether the administrator-request sensor is
loaded, and refuses to treat an empty degraded result as all clear.
Install it with watcher 0.1.2 using the FreePBX 17 alpha guide.
Anything outside the explicit Coverage contract may not be detected, and
administrator attribution remains correlation rather than proof.
Pending Changes Tripwire 16.0.0.12 alpha
Pending Changes Tripwire 16.0.0.12 public alpha
FreePBX 16 compatibility candidate for the WhatChanged read-only observer.
This release adds an explicit watcher-health panel and refuses to treat an
empty result as all clear when the observer is delayed, stale, invalid,
unreadable, unconfigured, or absent.
Use the matching portable watcher 0.1.2 bundle and follow the
legacy alpha guide. Test first on a backed-up,
noncritical system. Anything outside the explicit Coverage contract may not be
detected.
Pending Changes Tripwire 15.0.0.12 alpha
Pending Changes Tripwire 15.0.0.12 public alpha
FreePBX 15 compatibility candidate for the WhatChanged read-only observer.
This release adds an explicit watcher-health panel and refuses to treat an
empty result as all clear when the observer is delayed, stale, invalid,
unreadable, unconfigured, or absent.
Use the matching portable watcher 0.1.2 bundle and follow the
legacy alpha guide. FreePBX 15 and its underlying
platform may have unrelated end-of-life risks; test only on a backed-up,
noncritical system. Anything outside the explicit Coverage contract may not be
detected.