mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
Big release. New top-level features: - Cost Dashboard / Chargeback — per-VM/tenant rollup, price book, recommendations, PDF + CSV export - Power & Carbon Tracking — Redfish/IPMI/RAPL aggregation, kWh + CO₂e dashboard, PDF + CSV - Network Topology Visualization — interactive nodes/bridges/bonds/VLANs/VMs map - Snapshot Schedules — per-VM or per-tag cron with retention (count + age), 60s tick scheduler - Config Drift Detection — 6h fingerprint scanner with sorted-CSV normalisation (no false positives on tags/content/nodes) - SIEM Forwarder — Syslog (UDP/TCP, RFC 5424), Splunk HEC, Elasticsearch, Loki, generic webhook; per-target TLS verify, retry queue - Cloud-Init Template Library — curated upstream cloud images + custom URL/upload, hardened deploy path - PWA + Web Push — installable app, offline shell cache, VAPID push (no third-party gateway) - Insights tab — capacity ETA, fragmentation, idle/oversized VMs, power outliers + PDF export - Audit Search v2 — faceted full-text + CSV export, fail-closed HMAC chain incl. cluster + severity - DR Drill Wizard — read-only 11-check structured dry-run for Site Recovery plans, JSON + PDF report 10 new blueprints registered; 4 background workers (drift scanner, SIEM forwarder, snapshot scheduler, push handler) — all idempotent + restart-safe. Comprehensive security audit (3 rounds): - C-1: command injection in template library — shlex.quote() + URL/regex whitelist - H-1: CSRF skip on JSON POSTs — Origin/Referer enforced on every state-changing /api/* - H-2: 21 transitive CVEs — cryptography 47, requests 2.33.1, pyOpenSSL 26.1, PyJWT 2.12.1, pyasn1 0.6.3, pillow 12.2.0; pip-audit clean - M-1: VAPID private key encrypted at rest (AES-GCM, transparent migration) - M-2: audit HMAC includes cluster + severity, fail-closed (legacy 5-field fallback for pre-0.9.9 entries) - M-3: 17 str(e) leaks replaced with logging.exception() + generic message - M-4: SIEM TLS verify per-target, default true (removed hardcoded verify=False) - M-5: opaque session revocation token, constant-time compare - M-10: V2P password scrubbed on phase=completed/failed - M-11: webhook URL credential redactor before logging - M-12: push endpoint host whitelist (RFC1918/loopback/metadata refused) - B-1: api/push.py used flask.session instead of request.session (every push endpoint 401'd) — replaced with _current_user() helper Air-gap mode hardening: - /-route now injects localStorage flag prelude server-side when air_gap_mode=true so the very first page load on a fresh browser doesn't hit cdn.jsdelivr while waiting for /auth/check - html2canvas onerror handlers (4 spots) refuse CDN fallback when air-gap is on - html2canvas shipped locally (static/js/html2canvas.min.js) Bumps: - pegaprox/constants.py + web/src/constants.js → Beta 0.9.9, build 2026.05.03 - version.json → 0.9.9, update_files now 200 entries - README.md extended with new feature sections; "What's New" block dropped in favour of GitHub releases as source of truth - i18n: every new feature shipped in DE/EN/FR/ES/PT/KO/IT
13 lines
288 B
JSON
13 lines
288 B
JSON
{
|
|
"ntfy_enabled": true,
|
|
"ntfy_url": "https://ntfy.sh",
|
|
"ntfy_topic": "pegaprox-test",
|
|
"ntfy_token": "",
|
|
"ntfy_priority_map": {
|
|
"critical": "max",
|
|
"warning": "high",
|
|
"info": "default"
|
|
},
|
|
"apprise_enabled": false,
|
|
"apprise_urls": []
|
|
} |