MrMasterbay 7ba2a54c5f release: PegaProx 1.0.1
Bump PEGAPROX_VERSION + PEGAPROX_BUILD (constants.py, constants.js) and
version.json (version / build / release_date) to 1.0.1 / 2026.08.09, and add
the 1.0.1 changelog entry.

version.json update_files audited for completeness: all shipped application
files (pegaprox/, web/ output, plugins/, static/, images/, misc/, docs/,
examples/, root) are listed; nothing new since 1.0 needs adding — the only
files added on this branch are a CI workflow and tests, both intentionally
not part of update_files.
2026-08-09 21:30:30 +02:00

277 lines
14 KiB
JSON
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"version": "1.0.1",
"build": "2026.08.09",
"release_date": "2026-08-09",
"changelog": [
"PegaProx 1.0.1 — a maintenance + feature release on top of 1.0. LANGUAGES: the web UI is now available in Simplified Chinese (#670, thanks @ranydb). CONSOLE: SPICE is offered in every VM console entry point — a downloadable virt-viewer .vv for audio / USB / multi-monitor sessions, alongside the built-in noVNC. SECURITY: another Aikido penetration-test pass closed a set of authorization / IDOR gaps — power- and cost-rate reads are now scoped to the caller's clusters (a scoped API token can no longer enumerate every cluster's rates), the client portal's reboot action is gated on vm.restart instead of vm.start, and further authz / validation / SSRF invariants from batches 1–2 are enforced; the CIS SSH-hardening control no longer disables TCP forwarding (which the built-in VNC console tunnels through), and applied hardening controls are now selectable for rollback. FIXES: adding a disk to a container now targets a container mountpoint (mpN) instead of a QEMU disk key, and never overwrites an occupied slot; a locked VM/CT can be unlocked even on token-authenticated clusters (falls back to qm / pct unlock over SSH); OIDC keeps the full preferred_username instead of truncating at '@' (#486); the storage / snapshot / backup / update action bars follow their backend permissions (#644); scheduled rolling and maintenance updates evacuate local disks by default (#630/#629); node-temperature parsing falls back to plain 'sensors' text when JSON is unavailable (#601); in-band BMC reads fall back key → agent → password so password-only nodes still report hardware health (#609); ESXi / cross-hypervisor migration lists route to their own handlers (#654). PLATFORM: ARM64 / aarch64 build artifacts are now published (#674, gyptazy); cryptography is pinned to 50 and pyOpenSSL to 26.4 to keep the vulnerable 49 line out (#650). QUALITY: 438 automated tests (authorization, integration, SSL-bootstrap, hardware, i18n) run on every PR, and the whole branch was re-audited before release. Thank you to everyone who filed, fixed, translated and sponsored. 💚",
"PegaProx 1.0 — out of Beta. Everything from the 0.9.x line, hardened and rounded out. SECURITY: a full post-release penetration test closed a BMC-credential exfiltration on the test-BMC endpoint, an ESXi/XCP password ever appearing on a process argv (now fed over stdin/SSHPASS), a BMC/Redfish SSRF oracle, and an SSH-amplification path in the Ceph mirror views; the TLS bootstrap now FAILS CLOSED — if TLS is the intended posture and a usable certificate cannot be loaded or generated, PegaProx refuses to start with an actionable error instead of silently serving plaintext on the TLS port (#633, thanks @SpyrosPsarras). FEATURES: cross-cluster EVPN vNets spanning multiple clusters in the same AS — create / edit / membership / drift-detection + optional reconcile and drift→alert fan-out (#612 cybrwerk); V2P/ESXi migrations gain an opt-in 'wait for confirmation before cutover' gate (#562 ajoergensen); the Top Resources table is now sortable by any column (#621 ccesario); scheduled rolling updates carry a per-schedule reboot/online timeout instead of a fixed 10 minutes (#630). FIXES: nested / hierarchical resource pools now show their members and VM counts (#634 prasannak81); ESXi→PVE migrations of multi-disk VMs to classic LVM no longer abort when a target volume already exists (#636 shepart); XCP-ng→PVE transfers resume by HTTP range instead of failing on a broken pipe (#546). QUALITY: the SSL-bootstrap, authorization and integration test suites continue to run on every PR. Thank you to everyone who filed, fixed and sponsored along the way. 💚"
],
"min_python": "3.8",
"download_url": "https://github.com/PegaProx/project-pegaprox/releases/latest",
"update_archive": "https://github.com/PegaProx/project-pegaprox/archive/refs/heads/main.tar.gz",
"update_mirror": "https://updates.pegaprox.com",
"update_files": [
"Dockerfile",
"LICENSE",
"README.md",
"SECURITY.md",
"deploy.sh",
"docker-compose.yml",
"docs/SECURITY.md",
"examples/nginx.conf",
"images/favicon.ico",
"images/favicon-16x16.png",
"images/favicon-32x32.png",
"images/apple-touch-icon.png",
"images/oc_contribute_button.png",
"images/pegaprox-logo-dark.png",
"images/pegaprox-logo-light.png",
"images/pegaprox-logo-square-dark.png",
"images/pegaprox-logo-square-light.png",
"images/pegaprox.png",
"images/sponsors/banner_oranje.png",
"images/sponsors/idkmanager.png",
"images/sponsors/sponsor1.png",
"images/sponsors/sponsor2.png",
"images/sponsors/sponsor3-icon.png",
"images/sponsors/sponsor3-mark.png",
"images/sponsors/sponsor3.png",
"images/sponsors/sponsor4.png",
"images/sponsors/netzware-icon.png",
"images/sponsors/uvensys.png",
"images/sponsors/datimo.png",
"images/sponsors/occentus.png",
"images/sponsors/sponsor5.png",
"images/sponsors/netzware.png",
"images/sponsors/technidata.png",
"images/sponsors/linet.png",
"misc/grafana/README.md",
"misc/grafana/pegaprox_grafana_dashboard_v1.0.json",
"misc/grafana/pegaprox_grafana_dashboard_v1.1.json",
"misc/proxmox-lxc-appliance-creator.sh",
"pegaprox/__init__.py",
"pegaprox/api/.ssh_ws_server.py",
"pegaprox/api/__init__.py",
"pegaprox/api/alerts.py",
"pegaprox/api/audit_search.py",
"pegaprox/api/auth.py",
"pegaprox/api/ceph.py",
"pegaprox/api/clusters.py",
"pegaprox/api/costs.py",
"pegaprox/api/datacenter.py",
"pegaprox/api/dr_drill.py",
"pegaprox/api/drift.py",
"pegaprox/api/groups.py",
"pegaprox/api/helpers.py",
"pegaprox/api/history.py",
"pegaprox/api/insights.py",
"pegaprox/api/metrics_exporter.py",
"pegaprox/api/multi_sdn.py",
"pegaprox/api/nodes.py",
"pegaprox/api/pbs.py",
"pegaprox/api/plugins.py",
"pegaprox/api/power.py",
"pegaprox/api/push.py",
"pegaprox/api/realtime.py",
"pegaprox/api/reports.py",
"pegaprox/api/schedules.py",
"pegaprox/api/search.py",
"pegaprox/api/settings.py",
"pegaprox/api/siem.py",
"pegaprox/api/site_recovery.py",
"pegaprox/api/snapshots.py",
"pegaprox/api/static_files.py",
"pegaprox/api/storage.py",
"pegaprox/api/templates_lib.py",
"pegaprox/api/topology.py",
"pegaprox/api/users.py",
"pegaprox/api/vms.py",
"pegaprox/api/vmware.py",
"pegaprox/api/webauthn.py",
"pegaprox/api/xhm.py",
"pegaprox/app.py",
"pegaprox/background/__init__.py",
"pegaprox/background/alerts.py",
"pegaprox/background/broadcast.py",
"pegaprox/background/cross_cluster_lb.py",
"pegaprox/background/cross_cluster_replication.py",
"pegaprox/background/metrics.py",
"pegaprox/background/password_expiry.py",
"pegaprox/background/scheduler.py",
"pegaprox/background/site_recovery.py",
"pegaprox/background/syslog_server.py",
"pegaprox/cli/__init__.py",
"pegaprox/cli/migrate_db.py",
"pegaprox/constants.py",
"pegaprox/core/__init__.py",
"pegaprox/core/acme.py",
"pegaprox/core/backup_verify.py",
"pegaprox/core/bmc.py",
"pegaprox/core/cache.py",
"pegaprox/core/compliance_mapping.py",
"pegaprox/core/config.py",
"pegaprox/core/db.py",
"pegaprox/core/dbcrypto.py",
"pegaprox/core/esxi_cluster.py",
"pegaprox/core/incremental_repl.py",
"pegaprox/core/keystore.py",
"pegaprox/core/manager.py",
"pegaprox/core/pbs.py",
"pegaprox/core/redfish.py",
"pegaprox/core/v2p.py",
"pegaprox/core/vmware.py",
"pegaprox/core/xcpng.py",
"pegaprox/core/xhm.py",
"pegaprox/globals.py",
"pegaprox/models/__init__.py",
"pegaprox/models/permissions.py",
"pegaprox/models/tasks.py",
"pegaprox/utils/__init__.py",
"pegaprox/utils/audit.py",
"pegaprox/utils/auth.py",
"pegaprox/utils/concurrent.py",
"pegaprox/utils/email.py",
"pegaprox/utils/ldap.py",
"pegaprox/utils/log_handler.py",
"pegaprox/utils/oidc.py",
"pegaprox/utils/rbac.py",
"pegaprox/utils/realtime.py",
"pegaprox/utils/sanitization.py",
"pegaprox/utils/ssh.py",
"pegaprox/utils/ssh_pool.py",
"pegaprox/utils/ssh_security.py",
"pegaprox/utils/url_security.py",
"pegaprox/utils/vnc_crypto.py",
"pegaprox/utils/vnc_grab.py",
"pegaprox/utils/vnc_polling.py",
"pegaprox/utils/vnc_tunnel.py",
"pegaprox/utils/webhooks.py",
"pegaprox/utils/ws_lenient.py",
"pegaprox_multi_cluster.py",
"plugins/client_portal/__init__.py",
"plugins/client_portal/config.json",
"plugins/client_portal/manifest.json",
"plugins/client_portal/portal.html",
"plugins/hello_world/__init__.py",
"plugins/hello_world/manifest.json",
"plugins/notifications/__init__.py",
"plugins/notifications/config.json",
"plugins/notifications/manifest.json",
"plugins/proxmox-ha/README.md",
"plugins/proxmox-ha/__init__.py",
"plugins/proxmox-ha/manifest.json",
"plugins/status_page/__init__.py",
"plugins/status_page/config.json",
"plugins/status_page/manifest.json",
"plugins/status_page/status.html",
"requirements.txt",
"static/css/tailwind.min.css",
"static/css/xterm.min.css",
"static/js/babel.min.js",
"static/js/chart.umd.min.js",
"static/js/html2canvas.min.js",
"static/js/jspdf.plugin.autotable.min.js",
"static/js/jspdf.umd.min.js",
"static/js/marked.min.js",
"static/js/novnc/core/base64.js",
"static/js/novnc/core/decoders/copyrect.js",
"static/js/novnc/core/decoders/hextile.js",
"static/js/novnc/core/decoders/jpeg.js",
"static/js/novnc/core/decoders/raw.js",
"static/js/novnc/core/decoders/rre.js",
"static/js/novnc/core/decoders/tight.js",
"static/js/novnc/core/decoders/tightpng.js",
"static/js/novnc/core/decoders/zrle.js",
"static/js/novnc/core/deflator.js",
"static/js/novnc/core/des.js",
"static/js/novnc/core/display.js",
"static/js/novnc/core/encodings.js",
"static/js/novnc/core/inflator.js",
"static/js/novnc/core/input/domkeytable.js",
"static/js/novnc/core/input/fixedkeys.js",
"static/js/novnc/core/input/gesturehandler.js",
"static/js/novnc/core/input/keyboard.js",
"static/js/novnc/core/input/keysym.js",
"static/js/novnc/core/input/keysymdef.js",
"static/js/novnc/core/input/util.js",
"static/js/novnc/core/input/vkeys.js",
"static/js/novnc/core/input/xtscancodes.js",
"static/js/novnc/core/ra2.js",
"static/js/novnc/core/rfb.js",
"static/js/novnc/core/util/browser.js",
"static/js/novnc/core/util/cursor.js",
"static/js/novnc/core/util/element.js",
"static/js/novnc/core/util/events.js",
"static/js/novnc/core/util/eventtarget.js",
"static/js/novnc/core/util/int.js",
"static/js/novnc/core/util/logging.js",
"static/js/novnc/core/util/md5.js",
"static/js/novnc/core/util/strings.js",
"static/js/novnc/core/websock.js",
"static/js/novnc/rfb.min.js",
"static/js/novnc/vendor/pako/lib/utils/common.js",
"static/js/novnc/vendor/pako/lib/zlib/adler32.js",
"static/js/novnc/vendor/pako/lib/zlib/crc32.js",
"static/js/novnc/vendor/pako/lib/zlib/deflate.js",
"static/js/novnc/vendor/pako/lib/zlib/inffast.js",
"static/js/novnc/vendor/pako/lib/zlib/inflate.js",
"static/js/novnc/vendor/pako/lib/zlib/inftrees.js",
"static/js/novnc/vendor/pako/lib/zlib/messages.js",
"static/js/novnc/vendor/pako/lib/zlib/trees.js",
"static/js/novnc/vendor/pako/lib/zlib/zstream.js",
"static/js/purify.min.js",
"static/js/react-dom.production.min.js",
"static/js/react.production.min.js",
"static/js/tailwind.min.js",
"static/js/xterm-addon-fit.min.js",
"static/js/xterm.min.js",
"update.sh",
"version.json",
"web/Dev/_Normal_Users_No_Touchies_Devs_always_welcome",
"web/Dev/build.sh",
"web/Dev/patch.sh",
"web/Dev/static/js/html2canvas.min.js",
"web/assets/world-countries.svg",
"web/index.html",
"web/index.html.original",
"web/manifest.webmanifest",
"web/src/auth.js",
"web/src/constants.js",
"web/src/contexts.js",
"web/src/create_modals.js",
"web/src/dashboard.js",
"web/src/cloud.js",
"web/src/datacenter.js",
"web/src/icons.js",
"web/src/networking.js",
"web/src/node_modals.js",
"web/src/security.js",
"web/src/settings_modal.js",
"web/src/storage.js",
"web/src/tables.js",
"web/src/translations.js",
"web/src/ui.js",
"web/src/vm_config.js",
"web/src/vm_modals.js",
"web/src/vnc_secure_socket.js",
"web/src/worldmap.js",
"web/sw.js"
],
"prev_changelog": [
"v0.9.15 — a large security-hardening pass (per-VM ACL enforcement, tenant-isolation IDOR/BOLA gates, SSRF guards, RCE-hardening of ISO/template + ESXi-VMDK paths, CSRF/CSP tightening, dependency CVE bumps + AGPL §7(b) attribution), full Cloud-layout parity with Corporate, per-host temperature monitoring with history + alert metric (#601), and scale/perf work (sidebar windowing for 1000+ VMs, TTL caches). Adds a full-stack integration + authz test harness. Community PR #617 snapshot-name validation (thanks @MatrixNeoKozak); welcome TechniData AG Limited (Silver).",
"v0.9.14.1 — per-disk aio-mode selector in the ESXi→PVE wizard (#598), maintenance-mode RAM pre-flight (#611), Client Portal self-service teardown (#556), OVMF quick-template + reverse-proxy fixes (#607/#614), dependency floors + Site-Recovery log sanitisation; welcome Occentus Network (Platinum)",
"v0.9.13.3 — flexible snapshot schedules (#586) + replication overview tab (#430) + offline-lag/rolling-update fixes + CIS log-bounds hardening",
"Italian translation — thanks @fabriziosalmi (#332)",
"PBS Reports tab: executive summary, inventory, gap analysis + PDF/PNG export (#273)",
"Rolling update: optional --with-local-disks evacuation, HA-rerouted migrations no longer false-fail (#330, #340)",
"Scheduled actions: name and vm_type actually persist now (#337)",
"Site Recovery: OVS bridges + SDN vnets show up in the network mapping dropdown (#329)",
"SSH reachability: corosync-VLAN setups now resolve the real mgmt IP for all node ops (#324)",
"Node Hardening: PDF/PNG export of CIS/Lynis/STIG/PegaProx audit reports",
"KSM Sharing visible in Node Summary, always shown (matches native PVE UI)",
"Corporate dashboard: single-node clusters show 'Standalone' badge instead of 'Quorum verloren' (#326)",
"Disk Create modal: dropdown click no longer dismisses the modal (#323)"
],
"breaking_changes": []
}