🚀 Release v0.30.6 - #5516
Open
github-actions[bot] wants to merge 87 commits into
Open
🚀 Release v0.30.6#5516github-actions[bot] wants to merge 87 commits into
github-actions[bot] wants to merge 87 commits into
Conversation
Self-hosted better-auth is configured with secure cookies off so plain HTTP access (http://<ip>:3000) keeps working, but that also meant the session cookie never got the Secure attribute even behind HTTPS. A cookie without Secure can be replayed over plain HTTP. Add Secure to the auth response cookies per request when X-Forwarded-Proto is https (what Traefik sends on TLS), leaving plain-HTTP requests untouched. Fixes #4709
- tar >=7.5.19 (GHSA-23hp-3jrh-7fpw): decompression DoS, pinned via pnpm override within 7.x (transitive via @mapbox/node-pre-gyp) - protobufjs >=7.5.5 (GHSA-xq3m-2v4x-88gg): arbitrary code execution, pinned via pnpm override within 7.x (transitive via @grpc/proto-loader, @opentelemetry/otlp-transformer) - shell-quote ^1.8.4 (GHSA-w7jw-789q-3m8p): quote() didn't escape newlines in object .op values (direct dep, used for docker/ssh command building) - vitest ^4.1.0 (GHSA-5xrq-8626-4rwp): arbitrary file read/execute via UI server (devDependency) - github.com/gofiber/fiber/v2 v2.52.11 (GHSA-68rr-p4fp-j59v): insecure UUIDv4 fallback on crypto/rand failure (apps/monitoring) - next (GHSA-f82v-jwr5-mffw): authorization bypass in middleware, was a transitive dep of react-email in the standalone packages/server/src/emails lockfile; regenerating against the current react-email version (6.9.3) drops next.js entirely, since it no longer uses it for the preview server Verified: typecheck (server + app) clean, full vitest suite (947 passed / 5 env-conditional skips, 0 failures), go build/vet/test clean for apps/monitoring.
Added new Railpack versions to the list.
…y-updates fix: resolve 6 critical Dependabot alerts
…nts and config Adds a Transfer action on every service page that moves an application, compose or database to another server without S3: volumes, bind mounts and deployment logs are streamed through the panel (ssh2/spawn pipe), file mounts and Traefik config are recreated on the target, the source is cleaned up and the service is deployed on the target. Failures before cleanup roll back to the source server.
…e suite does not time out in CI
…ervers feat: transfer services between servers
feat(compose): pull latest images on deploy toggle
fix(compose): move Fresh Volumes into a Danger Zone with typed confirmation
Fixes #5413. A secret brought into a folder with "Import Secrets" was reported as not found. Two reasons, and the first is easy to miss: The list endpoint takes the flag in **snake_case**. `includeImports` is silently ignored — the request still returns 200, with `imports` present but empty — so the imported secret looked like it simply did not exist. Measured against app.infisical.com with a registered import (confirmed via GET /api/v1/secret-imports): expandSecretReferences=true imports[] empty expandSecretReferences=true&includeImports=true imports[] empty expandSecretReferences=true&include_imports=true imports[] has the secret Second, imported secrets never appear in `secrets` — they come back in a separate `imports` array, one entry per source path, which the client did not read at all. Imported entries are merged before the folder's own, so a name defined in both resolves to the local value, matching how Infisical resolves it. Also measured, for whoever looks next: `/api/v4/secrets` returns imports with no flag at all, and single-secret reads (`/raw/{name}`) never see an imported key — 404 on v3, no such route on v4. So a folder listing is the only way to reach them. vault.test.ts: 57 passed. Reverting the fix fails the new merge test. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review flagged that multi-import collisions were untested. The order the code implements is the documented one — Infisical: "If two imports carry a secret with the same name, the value from the bottom-most import wins" — and the response lists imports in that order, so sequential assignment matches it. Added a case with two imports defining the same key. Reversing the merge order in the client fails it, so the test pins the behaviour rather than restating the implementation. vault.test.ts: 58 passed. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
fix(vault): read Infisical secrets pulled in through an import
chore(ci): update GitHub Actions to latest versions and harden workflows
feat: added missing Railpack versions
…newline fix(notifications): add missing newline to ntfy database backup message
feat(compose): support models in Compose specification
fix(deps): bump next to 16.3.4 to patch critical RCE advisories
…OOK_MAX_BODY_SIZE
fix: prevent add-invitation form from resetting on submission error
…-on-provider-save fix: preserve application status when saving provider settings
…e-layout feat(ui): enhance deployments layout and fix visual jumping
fix(ui): unify tab header styles across backups, schedules, volume backups and patches
fix: accept deploy webhook payloads up to 25 MB
* fix: preserve compose status when saving provider settings
* fix: count only physical disks in host Block I/O stats and skip partitioned md arrays and test the Block I/O sum
…eak-5518 fix: kill deployment log tail when the client disconnects early
…-https-4709 fix: mark session cookie as Secure when served over HTTPS
feat: account deletion for Dokploy Cloud
fix(terminal): prevent terminal from collapsing on zoom
fix(ui): resolve tooltips overlapping open modals on remote servers page
fix(libsql): validate appName like the other database kinds
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR promotes changes from
canarytomainfor version v0.30.6.🔍 Changes Include:
✅ Pre-merge Checklist:
This PR is not safe to merge until the transfer authorization, consistency, recovery, target-storage, and SSH authentication failures are addressed.
Summary
This release promotes v0.30.6 with a new cross-server service-transfer workflow, Compose image-pull and fresh-volume controls, Compose model support, Infisical import handling, billing improvements, dependency updates, and CI hardening. The transfer implementation introduces several blocking correctness and authorization issues:
Reviews (1) · Last reviewed commit: "Merge pull request #5515 from Dokploy/fi..."