Skip to content

🚀 Release v0.30.6 - #5516

Open
github-actions[bot] wants to merge 87 commits into
mainfrom
canary
Open

github-actions[bot] wants to merge 87 commits into
mainfrom
canary

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

This PR promotes changes from canary to main for version v0.30.6.

🔍 Changes Include:

  • Version bump to v0.30.6
  • All changes from canary branch

✅ Pre-merge Checklist:

  • All tests passing
  • Documentation updated
  • Docker images built and tested

🤖 This PR was automatically generated by GitHub Actions

RetriggerConfidence Score: 0/5

This PR is not safe to merge until the transfer authorization, consistency, recovery, target-storage, and SSH authentication failures are addressed.

Summary

This release promotes v0.30.6 with a new cross-server service-transfer workflow, Compose image-pull and fresh-volume controls, Compose model support, Infisical import handling, billing improvements, dependency updates, and CI hardening. The transfer implementation introduces several blocking correctness and authorization issues:

  • Destructive source-data removal is available without delete permission.
  • Failed Compose stops do not abort copying.
  • Compose stacks cannot be restarted by transfer recovery.
  • Retries can merge archives into stale target storage.
  • Bulk transfer streams do not authenticate SSH host keys.

Reviews (1) · Last reviewed commit: "Merge pull request #5515 from Dokploy/fi..."

Souvik-Cyclic and others added 30 commits August 9, 2026 21:05
Self-hosted better-auth is configured with secure cookies off so plain
HTTP access (http://<ip>:3000) keeps working, but that also meant the
session cookie never got the Secure attribute even behind HTTPS. A cookie
without Secure can be replayed over plain HTTP.

Add Secure to the auth response cookies per request when X-Forwarded-Proto
is https (what Traefik sends on TLS), leaving plain-HTTP requests untouched.

Fixes #4709
- tar >=7.5.19 (GHSA-23hp-3jrh-7fpw): decompression DoS, pinned via
  pnpm override within 7.x (transitive via @mapbox/node-pre-gyp)
- protobufjs >=7.5.5 (GHSA-xq3m-2v4x-88gg): arbitrary code execution,
  pinned via pnpm override within 7.x (transitive via @grpc/proto-loader,
  @opentelemetry/otlp-transformer)
- shell-quote ^1.8.4 (GHSA-w7jw-789q-3m8p): quote() didn't escape
  newlines in object .op values (direct dep, used for docker/ssh
  command building)
- vitest ^4.1.0 (GHSA-5xrq-8626-4rwp): arbitrary file read/execute via
  UI server (devDependency)
- github.com/gofiber/fiber/v2 v2.52.11 (GHSA-68rr-p4fp-j59v): insecure
  UUIDv4 fallback on crypto/rand failure (apps/monitoring)
- next (GHSA-f82v-jwr5-mffw): authorization bypass in middleware, was
  a transitive dep of react-email in the standalone
  packages/server/src/emails lockfile; regenerating against the
  current react-email version (6.9.3) drops next.js entirely, since
  it no longer uses it for the preview server

Verified: typecheck (server + app) clean, full vitest suite
(947 passed / 5 env-conditional skips, 0 failures), go build/vet/test
clean for apps/monitoring.
Added new Railpack versions to the list.
…y-updates

fix: resolve 6 critical Dependabot alerts
…nts and config

Adds a Transfer action on every service page that moves an application,
compose or database to another server without S3: volumes, bind mounts
and deployment logs are streamed through the panel (ssh2/spawn pipe),
file mounts and Traefik config are recreated on the target, the source
is cleaned up and the service is deployed on the target. Failures before
cleanup roll back to the source server.
…ervers

feat: transfer services between servers
feat(compose): pull latest images on deploy toggle
fix(compose): move Fresh Volumes into a Danger Zone with typed confirmation
Fixes #5413. A secret brought into a folder with "Import Secrets" was reported
as not found. Two reasons, and the first is easy to miss:

The list endpoint takes the flag in **snake_case**. `includeImports` is
silently ignored — the request still returns 200, with `imports` present but
empty — so the imported secret looked like it simply did not exist. Measured
against app.infisical.com with a registered import (confirmed via
GET /api/v1/secret-imports):

  expandSecretReferences=true                        imports[] empty
  expandSecretReferences=true&includeImports=true    imports[] empty
  expandSecretReferences=true&include_imports=true   imports[] has the secret

Second, imported secrets never appear in `secrets` — they come back in a
separate `imports` array, one entry per source path, which the client did not
read at all.

Imported entries are merged before the folder's own, so a name defined in both
resolves to the local value, matching how Infisical resolves it.

Also measured, for whoever looks next: `/api/v4/secrets` returns imports with
no flag at all, and single-secret reads (`/raw/{name}`) never see an imported
key — 404 on v3, no such route on v4. So a folder listing is the only way to
reach them.

vault.test.ts: 57 passed. Reverting the fix fails the new merge test.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Review flagged that multi-import collisions were untested. The order the code
implements is the documented one — Infisical: "If two imports carry a secret
with the same name, the value from the bottom-most import wins" — and the
response lists imports in that order, so sequential assignment matches it.

Added a case with two imports defining the same key. Reversing the merge order
in the client fails it, so the test pins the behaviour rather than restating
the implementation.

vault.test.ts: 58 passed.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
fix(vault): read Infisical secrets pulled in through an import
chore(ci): update GitHub Actions to latest versions and harden workflows
feat: added missing Railpack versions
…newline

fix(notifications): add missing newline to ntfy database backup message
feat(compose): support models in Compose specification
fix(deps): bump next to 16.3.4 to patch critical RCE advisories
imrja8 and others added 30 commits September 29, 2026 18:08
fix: prevent add-invitation form from resetting on submission error
…-on-provider-save

fix: preserve application status when saving provider settings
…e-layout

feat(ui): enhance deployments layout and fix visual jumping
fix(ui): unify tab header styles across backups, schedules, volume backups and patches
fix: accept deploy webhook payloads up to 25 MB
* fix: preserve compose status when saving provider settings
* fix: count only physical disks in host Block I/O stats and skip partitioned md arrays and test the Block I/O sum
…eak-5518

fix: kill deployment log tail when the client disconnects early
…-https-4709

fix: mark session cookie as Secure when served over HTTPS
feat: account deletion for Dokploy Cloud
fix(terminal): prevent terminal from collapsing on zoom
fix(ui): resolve tooltips overlapping open modals on remote servers page
fix(libsql): validate appName like the other database kinds

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.