Skip to content

Releases: trypando/pando

v0.3.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 03:46
e7a9333

Pando is now installed from a prebuilt, signed image rather than built on the host. An existing
installation, whether it moves to the image or keeps building from a clone, needs its data volume's
owner changed once, because the server now runs as a different user; a clone's build also needs a
Docker account now. Both are in the upgrade notes.

Security

No new advisories. The server image is new in this release: it is built on Docker Hardened Images,
runs the server as a non-root user, and is scanned with Trivy before it is published.

Added

  • A prebuilt server image, trypando/pando on Docker Hub (#52). Installing no longer means
    cloning the repository and building on the host: download the release's docker-compose.yml and
    run docker compose up -d. Built on Docker Hardened Images, with no package manager in the image
    and the server running as the base's non-root user; for linux/amd64 and linux/arm64; signed keyless with cosign,
    with an SBOM and SLSA provenance attached, and scanned with Trivy before it is pushed. Tagged with
    the exact version, the minor line, and latest for a stable release. Each release runs the
    published image from its own compose file and deploys an app on it before it counts as done.
    Verifying the image is in docs/releasing.md.
  • The release carries a docker-compose.yml that pins the image to that version.

Upgrade notes

  • An installation started from a clone of the repository can move to the published image: download
    the release's docker-compose.yml into the same directory, so the compose project and its named
    volumes stay the same, and run docker compose up -d. Keep the POSTGRES_PASSWORD it was started
    with. The server now runs as UID 65532 rather than 10001, so an existing pando-data volume needs
    its owner changed once: docker compose run --rm --user 0 --entrypoint chown pando -R 65532:65532 /var/lib/pando.
  • Building the image from source needs docker login dhi.io with a Docker account first, because its
    base images are Docker Hardened Images.

v0.2.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 01:58
11b2ff5

Detection stops asking for things the repository already told it, reads the build instructions an app
carries rather than inferring them, and plans more kinds of app itself. This release also adds a
security score for every app, optional AI screening of detection proposals, account, group and sharing
management in the console, and a launcher each person can arrange. Several changes alter what Pando
does with apps you already run — a forced delete now destroys the app's volumes, every deploy is
scanned, and administrators can manage every app — so read the upgrade notes before upgrading.

Security

No new advisories. The six open against github.com/docker/docker are unchanged and remain accepted
with their reasoning in .github/govulncheck-allowlist.txt:
all six are Moby daemon vulnerabilities, and go list -deps on the runtime adapter resolves to
api/…, client and pkg/stdcopy with no daemon/… or plugin/… package in the binary. The
module has no fixed release and will not get one.

  • An open redirect in the console's sign-in page. returnTo accepted a next parameter after
    checking it began with one / and not two — but /\evil.example passes that and the URL parser
    still reads it as //evil.example, because where an authority may begin a backslash and a slash
    mean the same thing. Following a crafted link, signing in on the real hostname with a real
    password, and landing on somebody else's site was a working attack. next is now resolved against
    the current document and accepted only when the origins match, which agrees with what the browser
    will do by construction and turns away javascript: and data: in the same breath.
  • An app created from a published image read the Pando server's own files as its source. Such
    an app has no checkout, and its source view was rooted at an empty path, which resolved against the
    filesystem root of the Pando process. Detectors read from there, so what they found could be quoted
    in the app's proposal. The app now has an empty source, and the source scan and AI screening skip
    it. Present in 0.1.x.
  • Deleting an app left its data on disk. R-204 has a delete either keep a final backup or discard
    the app's storage, and both answers removed Pando's record of the volumes while leaving the volumes
    themselves in place, where nothing could reach or reclaim them. The app's uploaded source was also
    kept. A delete now destroys the volumes once the backup, if asked for, has been taken, and removes
    the upload (R-204, R-224). Volumes left by earlier deletes are not removed by the upgrade; see the
    upgrade notes.
  • A custom role could carry a built-in role's name. Role names were unique case-sensitively, and
    the built-ins are stored lowercase and shown capitalized, so a custom role called "Administrator"
    appeared in every role picker beside the real one, looking identical. Names are now unique ignoring
    case and surrounding spaces, built-ins included (R-082); migration 000028 renames existing clashes.

Added

  • Pando builds an app the way its repository says to. Where a repository states its build — a
    .github/workflows build job, a Makefile, Taskfile.yml or justfile target, a Procfile's
    web process — the plan runs those commands instead of inferring them from the language. R-094's
    confidence ladder always ranked "the maintainer's own build commands" above convention-matching;
    this implements it.
  • A client that builds into a directory the binary embeds is built first. Where a bundler config
    names an output directory and a //go:embed directive names the same one, the ordering is stated
    by the repository rather than guessed, and the client build runs ahead of the binary's. Read from
    Vite, Astro, Vue CLI, Angular, Next.js (static exports), webpack and SvelteKit, or from an
    --outDir-style flag in the build script.
  • Pando plans more builds itself, on official images (R-095). Static sites (Astro, Vite, Angular,
    Create React App, Gatsby) are built with node and served with nginx; Node servers, Go programs
    with one main package, Gradle and Maven projects, plain Java sources and .NET projects each get a
    plan on their language's official image, with the version read from the repository where it is
    stated. Other languages stay on nixpacks. Detection also reads a Containerfile, a Dockerfile in a
    subdirectory and a site in docs/; asks for a Dockerfile ARG the build refuses to run without;
    runs Rails in production with a required SECRET_KEY_BASE; and refuses a library with an
    explanation rather than deploying it (R-021). All [P] defaults are recorded in
    docs/design/notes-deploy-qa-issue-55.md.
  • An app created from a published image is proposed as that image, rather than sent through
    repository detection over an empty checkout. The trial run finds its port, paths the image declares
    with VOLUME get a volume, and an image that serves only a database or mail protocol is refused with
    the reason (R-097, R-200).
  • A security score for every app (R-310 – R-320). A number from 0 to 100 from scanning the image
    an app deploys and the source it was built from, weighted by severity (25 per critical, 10 high,
    3 medium, 1 low), shown on the app's overview and in the apps list with the findings behind it,
    worst first. Scanning is a new adapter category; the Trivy adapter runs in a container pinned by
    digest, with no container runtime socket. A new app is scanned when it is detected, every deploy is
    scanned, and Scan now works on an app never built. Host policy can refuse deploys below a
    minimum score (min_security_score, PLAN_SECURITY_BELOW_THRESHOLD), and for a running app that
    falls below it, notify the owner and optionally stop it after a grace period (insecure_action,
    insecure_grace_hours) — never delete it. ignore_unfixable_findings scores only what can be fixed.
    Nothing is enforced until an administrator sets a threshold.
  • AI screening of detection proposals (R-106, R-330 – R-339). AI is a new adapter category; the
    first adapter uses Anthropic's API (default model claude-opus-5-5). A screener reads the
    repository and the proposal and returns amendments from a closed set — no policy, isolation,
    routing, resources, egress, grants or secrets — and Pando refuses any without a reason or evidence
    in the repository, any that overwrite what a person set, and a port the trial run observed. Any
    failure leaves the proposal as detection made it. The review marks each change "Suggested by AI",
    lists what was refused, and each run is audited as detection.screen with the files read. No AI
    adapter is configured by default; host policy's disable_ai_screening forbids it. Configured, it
    sends the repository files it reads to the provider.
  • Adapter credentials are stored encrypted (R-190). POST /adapters takes a write-only
    credentials object, sealed by the installation's secrets adapter into its own table; the database
    refuses a credentials key in an adapter's plain configuration, and GET /adapters names the
    credentials set, never their values.
  • Adapters can be added and changed from the console and the CLI, not only the API
    (GET /adapters/kinds, pando adapter list | kinds | add, credentials prompted rather than typed).
    Pando can restart itself to load them: POST /api/v1/restart, pando restart and a button on
    the Adapters screen finish the requests in flight and re-execute the binary in the same process.
    Behind install.adapters.manage and audited as install.restart. GET /adapters says which
    adapters are waiting for a restart.
  • Stop, start and restart an app from the console, the CLI (pando app stop | start | restart)
    and MCP. The API had these endpoints and no client called them, so the only way to take an app down
    was to delete it. A stopped app stays stopped across a restart of Pando.
  • Each part of an app has its own status, logs and resource use. GET /apps/{id}/status lists
    every workload with whether it is running, restarting and how often, its health and exit code;
    pando app status prints it. Logs take a workload (pando logs --workload), and the console's new
    Logs tab holds the app's output and every deploy's build log. GET /apps/{id}/usage,
    pando app usage and an In use section show each part's CPU, memory and disk against its
    limits, and each volume's size — a reading, not a history (R-245).
  • Accounts, groups and roles are managed in the console. Each account has a page with its
    details, groups, role, apps and audit history; an administrator can edit an account, reset its
    password, and add it to or remove it from groups. Groups hold an installation role and app roles
    that every member holds while in the group (R-078). Custom groups and roles can be deleted. A
    generated password (POST /passwords/generate) is offered wherever an administrator sets one, and
    by default must be changed at the next sign-in. CLI: pando user create | update | reset-password | apps, pando group list | add-member | remove-member | role | apps, pando grant role | remove.
  • A built-in Creator role (R-081): one verb, app.create. A creator manages the apps they made,
    as their owner, and nothing else.
  • Administrators manage every app. Two installation verbs, install.apps.view and
    install.apps.manage, cover every app, and the Administrator role holds both (R-080, R-081).
    Managing an app does not grant using it (R-087). GET /apps/{id} returns the caller's verbs, and the
    console hides controls the caller cannot use rather than letting them fail.
  • Sharing picks people and groups, and can make an app public behind a passcode (R-075a). The
    passcode is stored as an argon2id digest; a visitor's unlock lasts a day, r...
Read more

v0.1.1

Choose a tag to compare

@github-actions github-actions released this 14 Sep 17:47
9206240

Security

  • Base images, GitHub Actions and the two scanners CI installs are pinned by digest or exact version
    rather than by a mutable tag.
  • containerd/v2 to 2.3.5 (GHSA-7jxh-36q5-gcqv) and moby/go-archive to 0.3.0 (GO-2026-6253, a
    crafted tar writing outside the extraction directory).
  • The console's vite to 8.3.0, with @vitejs/plugin-react 6.1.1 alongside it, clearing six
    high-severity dev-server advisories.
  • A malformed stored credential hash no longer crashes the sign-in path or verifies against an
    arbitrary password. argon2.IDKey panics rather than returning an error on a zero time cost or
    zero parallelism, and an empty key field compared equal to an empty candidate, so a corrupted or
    hand-edited row could take the process down or accept anything. Both are now rejected during
    decoding. Found by fuzzing; covered by TestR042_AMalformedStoredHashDeniesRatherThanPanics.
  • Session cookies are marked Secure behind a TLS-terminating reverse proxy. Pando sees plain HTTP
    in that topology, so it could not tell an encrypted browser connection from an unencrypted one and
    sent the cookie without the attribute; one plaintext request to the hostname put a live session on
    the wire. Set PANDO_SERVER_EXTERNAL_URL to the address browsers use. Upgrade note: an
    installation behind a proxy should set it — unset keeps the previous behavior, which is correct
    only when Pando serves TLS itself or runs on localhost. (O-19)
  • The API server sets ReadHeaderTimeout and IdleTimeout. Without them a client dribbling header
    bytes held a connection open indefinitely. The proxy's per-app listeners already did this; the API
    server was the one that did not. Found by gosec.

Added

  • Security policy, coordinated disclosure process and documented security model
    (SECURITY.md).
  • Checksums signed with cosign on every release, and the verification procedure that goes with them
    (docs/releasing.md).
  • CodeQL, gosec, govulncheck, gitleaks and OpenSSF Scorecard in continuous integration.
  • Fuzz targets over the parsers that see untrusted input, run in continuous integration.
  • Issue and pull request templates, a code of conduct, Dependabot, and a reference index of the
    external interfaces (docs/reference.md).

Fixed

  • The Docker image ships with the console in it. docker compose up -d built an image whose binary
    had no UI embedded, so it served the API and returned 404 for every console route.

v0.1.0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 01:02
98084b5

Changelog

Read more