-
v1.4.32
StableSome checks failedCold Analytics Image Smoke / Analytics image boot smoke (push) Successful in 44sSecret Scan / gitleaks (push) Successful in 1m18sCI / build (push) Successful in 2m44slint / lint (push) Successful in 3m2sSource Security Scan / source-security (push) Successful in 1m33sPublish Native Add-ons / publish (push) Failing after 3m32sPublish Wasm Plugins / publish (push) Failing after 3m47sImage Security Scan / image-security (push) Successful in 6m2sPublish Release Artifacts / publish (push) Failing after 5m29sPublish Release Artifacts / finalize (push) Has been skippedreleased this
2026-08-15 18:10:38 +00:00 | 0 commits to staging since this releaseServiceRadar v1.4.32
Stops core from OOM-reloading leftover provider CIDR snapshots (the demo
netflow outage), ships composite service checks, and republishes images
after Harbor dropped the v1.4.31 tags.Whats New
1.4.32
- Provider CIDR snapshots: hourly AshOban prune keeps the active snapshot
plus one inactive rollback (2-day floor) and batch-deletes child CIDR
rows.PrefixTags.ProviderSourceskips a trie rebuild when the durable
snapshot token already matches the in-memory handle, and no longer parks
a previous 410k-prefix persistent_term trie. This is the path that OOM'd
core-elx and took netflow down on demo. (PR #4994) - Composite service checks: an operator-authored decision table over
multi-vantage reachability plus device facts, with SRQL
(composite.<slug>:<verdict>,in:composite_results), a builder at
/settings/networks/composite-checks, device-list/detail surfacing, and
optional Armis northbound export of the verdict. Checks derive, they do
not probe. (PRs #4962, #4982, #4993) - Images: 14 of 16 in-scope OCI images now publish a multi-arch index.
cnpg/cnpg_analyticsstay amd64 by design;web_ngandcore_elx
remain amd64 (adbc CMake triple, Membrane*_linux_x86archives). Also
restores--config=remoteas an alias of--config=ci. (PR #4988) - Plugins: first-party Wasm trust anchors (cosign public key and upload
signers) ship in chart defaults, so a stockhelm installcan import
first-party packages. Policy-envelopeparamsare no longer validated
against the operatorconfig_schema(that made Proxmox inventory
unconfigurable since package 0.1.5). Inventory assignments accept the
policy id the materializer actually emits. (PRs #4981, #4985, #4990) - Web UI: LiveView client is vendored at 1.2.9 to match Hex (flow detail
no longer fails with an asset version mismatch). Topology cluster clicks
expand, empty-canvas clicks no longer blank the graph, and device ID/IP
in the details card are real links. Settings metrics render as a card
grid. Pasted AWX controller tokens survive LiveView validate. (PRs
#4967, #4968, #4973, #4992) - Notifications and mail: Discord test-send is allowed out of demo
NetworkPolicy and embeds an Open-in-ServiceRadar link. Email channel
Cc/Bcc are optional; the "no relay" warning points at Settings > Mail.
(PRs #4969, #4972) - Farm/ops follow-ups:
RecordEventWorkerunwraps nested Oban args so
edge onboarding events land. SRQL catalog acceptsdevice_idon flows
andinterface_uidon interfaces. SNMP reuse, banner-grab protocol
toggles, prefix-tag site/role-only save, map-click CIDR lat/long, and
agent-package latest-approved add-on versions. Capacity forecasting and
Seasonal disposition cron rows now have names in/admin/jobs. (PRs
#4966, #4977, #4974) - Build: hermetic LLVM + rules_rs, faster Erlang/Elixir rules, and
host-native Bazel database-integration lifecycle (cache_only+ local
TestRunner). (PRs #4980, #4986, #4921)
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Provider CIDR snapshots: hourly AshOban prune keeps the active snapshot
-
v1.4.31
StableAll checks were successfulSecret Scan / gitleaks (push) Successful in 47slint / lint (push) Successful in 3m43sCI / build (push) Successful in 3m53sElixir Integration Tests / serviceradar_core integration (push) Successful in 5m6sSource Security Scan / source-security (push) Successful in 6m31sPublish Native Add-ons / publish (push) Successful in 6m34sImage Security Scan / image-security (push) Successful in 18m53sPublish Release Artifacts / publish (push) Successful in 18m5sPublish Wasm Plugins / publish (push) Successful in 8m28sPublish Release Artifacts / finalize (push) Successful in 14m29sElixir Quality / Elixir Quality (push) Successful in 49m11sreleased this
2026-08-13 03:11:15 +00:00 | 206 commits to staging since this releaseServiceRadar v1.4.31
Emergency Ash 3.31.3 upgrade for CVE-2026-67579 (keyset pagination cursor
injection), plus farm-tested identity and sweep/notification fixes.Whats New
1.4.31
- Security: upgrade Ash from 3.31.2 to 3.31.3 to close CVE-2026-67579. A
forged keysetpage[:after]/page[:before]cursor could inject an
Ash.Query.Callfilter, which AshPostgres inlined as SQL and ETS/Simple
evaluated in-process. The floor is now~> 3.31.3inserviceradar_core. - Hex lock updates that came with the Ash bump: reactor 1.0.6, splode 0.3.2,
and stream_data 1.4.0 across the Elixir apps; web-ng also takes Req 0.7.2,
igniter 0.8.3, and related compiler-tool patches; core-elx takes Phoenix
1.8.11 and ex_sdp 1.2.0. - UniFi/SNMP identity: stamp the UniFi controller host as an alternate IP on
the named gateway, and treat IEEE UAA/LAA NIC siblings as one DIRE device
so WAN UniFi and LAN SNMP identities converge. Recursive SNMP now includes
UniFi wired clients that already have a management IPv4. - Mapper SNMP skip and failure logs now name the target IP and any known
hostname so a timeout is not an anonymous "Failed to query system info". - Sweep Groups stamp
last_run_atwhen results land and show the latest
execution time/status. Scanner profiles no longer compile TCP without
ports, drop unsupported ARP before it reaches the agent, and strip LiveView
_unused_*keys so Discord notification-channel save is not rejected by
additionalProperties: false. - Discord Send test no longer treats a typed webhook URL as a missing
credential reference. The persist contract still requires a stored
reference; the test path accepts the just-typed secret (or the saved
reference if the password box is left blank) and does not run the
outbound URL policy against asecretref:handle. - MTR History Retention now converts
mtr_traces/mtr_hopsto hypertables
and attaches Timescale policies, so Save no longer reports "policy missing"
after a successful write (fj#4955). Dashboard Latency/Packet Loss read
those tables instead of OTELtraces_stats_5m. Events Over Time falls
back to rawocsf_eventswhen the hourly rollup is an empty leftover
view, and a repair migration replaces that view with a real CAGG.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Security: upgrade Ash from 3.31.2 to 3.31.3 to close CVE-2026-67579. A
-
v1.4.30
StableSome checks failedSecret Scan / gitleaks (pull_request) Successful in 1m27slint / lint (pull_request) Successful in 3m11sCI / build (pull_request) Successful in 3m21sSource Security Scan / source-security (push) Successful in 1m28sPublish Native Add-ons / publish (push) Failing after 3m42sImage Security Scan / image-security (push) Successful in 21m16sPublish Release Artifacts / publish (push) Successful in 20m43sPublish Release Artifacts / finalize (push) Failing after 44sPublish Wasm Plugins / publish (push) Successful in 14m29sreleased this
2026-08-09 00:48:10 +00:00 | 393 commits to staging since this releaseServiceRadar v1.4.30
Rebuilt the CNPG database image so its compiled extensions actually load, and
made ahelm upgradeacross a database image bump need no manual steps. Adds
opt-in cold-storage tiering, reusable credentials for SNMP, plugins and
integrations, Kubernetes public endpoint inventory, and a Teleport-style SSO
certificate SSH console. Fixes a live data-loss defect in which continuous
aggregates progressively deleted their own materialized history, and clears
eight dependency advisories.Whats New
1.4.30
- Continuous aggregates no longer delete their own history.
drop_chunks
records an invalidation covering every dropped chunk, and any refresh whose
window reaches into that region recomputes those buckets from now-empty raw
-- so a policy refreshing 32 days back over 7-day-retained raw silently wiped
every pre-retention bucket, verified on TimescaleDB 2.24.0. Nine aggregates
were refreshing further back than their source retains; their windows are now
clamped, and the retention worker alerts on any deployment that drifts back
into the hazard. Already-lost buckets are not resurrected -- the raw data is
gone. (PR #4874) - Cold-storage tiering, entirely opt-in. Raw telemetry past the hot window can
be exported to Parquet in object storage and queried through a dedicated
pg_duckdb analytics head, with retention gated on verified export so nothing
is dropped before it is archived. A deployment that does not enable it runs
no additional processes or jobs, gains two empty tables and aNOLOGINrole,
and sees no change to retention or query behaviour. (PR #4881) - Security: eight dependency advisories cleared, including two HIGH and a
Postgrex SQL-injection issue reachable through the:commentoption of
Postgrex.stream/4. (PRs #4867, #4879) - Agents no longer require NATS credentials to be provisioned for OTEL
forwarding; the collector relays through the supervising agent over the acked
otlp-relay:v1stream, and sites with a local NATS leaf opt in explicitly.
(PR #4705) - Database image: TimescaleDB and Apache AGE are now compiled and linked
against the runtime's glibc rather than the build executor's, so the shipped
.sofiles load instead of stopping PostgreSQL at startup. Both are in
shared_preload_libraries, so a mis-linked build was never a degraded image
-- the database did not come up. The base is pinned to18.4-system-bookworm
(the plain18.4tag is a bullseye build, on which PostGIS alone fails to
load), asserted at build time, and every produced library is now checked
against the image that ships it for both a too-new glibc reference and an
unresolved symbol. (PR #4850) - Database upgrades: the chart moves to PostgreSQL 18.4 and converges extension
catalogs automatically. Our image ships onetimescaledb-<version>.soand
PostgreSQL loads the version named in each database's catalog, so an image
missing that file cannot open the database -- andALTER EXTENSIONis then
unreachable to recover. A pre-upgrade hook now updates catalogs while the old
image is still serving, verifies every database against the module set the
incoming image actually carries, and aborts the upgrade with the cluster
untouched rather than letting a rollout strand a database. The default image
pin also had two copies that had drifted apart, leaving one environment on an
older PostgreSQL; both now read a single definition. (PR #4853) - Reusable credentials: SNMP, plugin secret fields and integration sources can
select an existing stored credential instead of re-entering secrets, Ansible
accepts pasted execution and callback tokens, plugin delivery mode governs
what is assignable, and only producer-schedule profiles are reconciled.
Credential broker grants and resolution audits are now retained rather than
growing unbounded. (PRs #4813, #4816, #4818, #4834, #4839, #4841, #4847) - SRQL and query UX: bidirectional
ip:/cidr:flow filters,cidr:now
supported on downsampled flows,%wildcards honoured on flow IP filters,
sort:respected when truncating downsample buckets, downsample and stats
tokens no longer flagged as unknown, address filters default to equals instead
of contains, and the query bar keeps recent query history. (PRs #4827, #4830,
#4832, #4836, #4838, #4856, #4859) - Web UI: ops navbars are pinned and the device breakdown focus bug is fixed.
(PR #4858) - Authentication: a closed pooled connection during the OIDC token exchange is
retried once instead of surfacing as a login failure. (PR #4797) - Credentials: the agent credential reconciler no longer halts its outer reduce
early, so every matching rule is processed. (PR #4794) - Kubernetes inventory: public endpoints are collected through the agent, with
VIP flow joins and attribution fixes so traffic resolves to the right service.
(PR #4854) - Remote access: the SSH console defaults to a Teleport-style SSO certificate
flow. (PR #4848) - Plugins: pending package approvals are surfaced in the settings navigation.
(PR #4835) - Build and CI: OCI base images are mirrored to
registry.carverauto.dev, Hex
dependencies compile against thecompile_envthe release applies, add-on
task-size hints are centralized so tuning no longer forces version bumps, the
release tag is no longer derived from the container image tag, React is pinned
to 19.2.8 with dual installs eliminated, and the BuildBuddy workflow and
Elixir integration tests were reworked. (PRs #4774, #4790, #4792, #4801,
#4810, #4814, #4815, #4824, #4825, #4826, #4843, #4844, #4846) - Gates that were passing without checking anything: the add-on version gate
matched vacuously on every push to staging,make lint-elixirwas inert,
migration compilation was never exercised by any test tier (a migration that
does not compile blocks the entire migration run, not just itself), and the
integration suite could not reach its database fixture from a remote executor
at all. Each is now enforced, andmake testruns the unit suite the way CI
does. (PRs #4860, #4864, #4866, #4872, #4888) - Fixes: scan and CLI tests establish closed ports and bound NSS shell-outs;
a stray kubeconfig committed as a file named~was removed. (PRs #4793,
#4812)
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Continuous aggregates no longer delete their own history.
-
v1.4.29
StableSome checks failedSecret Scan / gitleaks (pull_request) Successful in 4m4sHelm Lint / Helm Lint (pull_request) Successful in 4m44sSource Security Scan / source-security (push) Successful in 6m6sPublish Native Add-ons / publish (push) Successful in 7m22sCI / build (pull_request) Failing after 7m34slint / lint (pull_request) Successful in 8m28sPublish Wasm Plugins / publish (push) Successful in 10m1sPublish Release Artifacts / publish (push) Successful in 27m30sImage Security Scan / image-security (push) Successful in 28m37sPublish Release Artifacts / finalize (push) Successful in 1m1sreleased this
2026-08-02 04:26:04 +00:00 | 713 commits to staging since this releaseServiceRadar v1.4.29
Fixed camera live feeds reattaching to zombie relay sessions that stayed
status=activeafter the edge pull was dead, by requiring a still-valid lease
before reusing an active session.Whats New
1.4.29
- Camera relay: core no longer reuses
activerelay sessions whose lease has
expired (or was never stamped). Zombie DB rows from gateway restarts, agent
source failures, or abandoned July sessions were reattached forever — viewers
saw open websockets with no media and no newcamera.open_relayto the agent.
Pendingrequested/openingrows may still attach during the short open
window; stamped-but-expired leases always open a fresh pull. (PR #4787)
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Camera relay: core no longer reuses
-
v1.4.28
StableSome checks failedHelm Lint / Helm Lint (pull_request) Successful in 46sSecret Scan / gitleaks (pull_request) Successful in 57slint / lint (pull_request) Successful in 3m27sCI / build (pull_request) Failing after 3m31sSource Security Scan / source-security (push) Successful in 5m47sPublish Native Add-ons / publish (push) Successful in 6m18sPublish Wasm Plugins / publish (push) Successful in 7m18sPublish Release Artifacts / publish (push) Successful in 13m12sImage Security Scan / image-security (push) Successful in 14m42sPublish Release Artifacts / finalize (push) Successful in 1m0sreleased this
2026-08-02 02:58:34 +00:00 | 717 commits to staging since this releaseServiceRadar v1.4.28
Fixed agent-gateway camera relay tracker crashes that took down live camera
feeds after the v1.4.27 lease reaper landed, by making ingress liveness checks
safe for remote core PIDs.Whats New
1.4.28
- Camera relay: agent-gateway session tracker no longer calls
Process.alive?/1
on remote core ingress PIDs (that raisedArgumentError, crashed the tracker
GenServer, wiped gateway session state, and broke live feeds). Remote PIDs are
probed via:erpc; unreachable remotes leave the session until lease expiry.
(PR #4785)
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Camera relay: agent-gateway session tracker no longer calls
-
v1.4.27
StableSome checks failedNetprobe eBPF Verifier / Resolve verifier configuration (pull_request) Successful in 1m28sNetprobe eBPF Verifier / Verify eBPF programs on Linux 5.15 (pull_request) Successful in 12sNetprobe eBPF Verifier / Verify eBPF programs on Linux 5.8 (pull_request) Successful in 7sNetprobe eBPF Verifier / Verify eBPF programs on Linux 6.x (pull_request) Successful in 3sHelm Lint / Helm Lint (pull_request) Successful in 2m17sNetprobe eBPF Verifier / Verify eBPF refusal on Linux 5.4 (pull_request) Successful in 2sSecret Scan / gitleaks (pull_request) Successful in 1m50sGolang Tests / Golang Tests (pull_request) Successful in 3m24sweb-ng Precommit / web-ng precommit (pull_request) Successful in 3m7sRust Tests / Rust Integration Tests (pull_request) Successful in 3m24sRust Static musl / Static musl (netprobe) (pull_request) Successful in 3m48slint / lint (pull_request) Successful in 4m15sRust Integration Tests / test-integration-rust (pull_request) Successful in 4m17sRust Static musl / Static musl (netprobe)-1 (pull_request) Successful in 4m23sCI / build (pull_request) Successful in 5m52sPublish Wasm Plugins / publish (push) Failing after 3sSource Security Scan / source-security (push) Successful in 7m11sPublish Native Add-ons / publish (push) Successful in 8m33sPublish Release Artifacts / publish (push) Successful in 23m39sImage Security Scan / image-security (push) Successful in 26m5sPublish Release Artifacts / finalize (push) Successful in 52m44sreleased this
2026-08-02 00:18:34 +00:00 | 723 commits to staging since this releaseServiceRadar v1.4.27
Published the camera live-feed session fix that was cut as v1.4.26 but never
shipped (release publish failed on removed Debian security debs), and unblocked
container image builds by refreshing the postgis-layer curl/nghttp2 pins.Whats New
1.4.27
- Camera relay: agent-gateway reaps lease-expired relay sessions so orphaned
streams no longer permanently exhaust the per-agent limit of 16. Core reuses
a live edge session for the same camera source and stream profile (one
Membrane pull, many viewers) instead of opening a new agent relay on every
view. Soft viewer disconnects retain shared edge pulls while viewers remain;
idle-timeout still tears them down. (PR #4781) - Build: web-ng Bazel precommit stages shared Credo configs into the Mix
workdir somix credono longer fails with a missing.credo.ex_slop.exs.
(PR #4781) - Build: refresh MODULE.bazel Debian
http_filepins for libcurl3-gnutls
(deb12u15) and libnghttp2-14 (deb12u3) so the postgis extension layer can
fetch during release publish after upstream removed the prior security
updates. (unblocks v1.4.26 publish failure) - Dgraph client: first-party Rust client with hermetic E2E integration tests
and Bazel-generated gRPC bindings for dgraph protos. (PR #4738) - Packaging / release: tagged Forgejo deb/rpm assets are limited to edge
installers (agent, nats, cli, log-collector, flow-collector, bmp-collector,
trapd, rperf, rperf-checker). Control-plane services remain container/Helm
only. Finalize prunes fat Forgejo releases to the newest 10 to control
attachment growth. (PR #4773) - CI and build graph: Bazel-native Go short tests, parallel Rust musl/lint
legs, hermetic web-ng precommit cache layers, and several cache-key and
registry-auth fixes that stop false invalidations and unauthenticated pulls.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Camera relay: agent-gateway reaps lease-expired relay sessions so orphaned
-
v1.4.25
StableSome checks failedSecret Scan / gitleaks (pull_request) Successful in 1m35sSource Security Scan / source-security (push) Successful in 2m3slint / lint (pull_request) Successful in 5m18sPublish Wasm Plugins / publish (push) Successful in 11m47sPublish Native Add-ons / publish (push) Successful in 16m58sImage Security Scan / image-security (push) Successful in 37m48sCI / build (pull_request) Failing after 41m36sPublish Release Artifacts / publish (push) Successful in 48m27sPublish Release Artifacts / finalize (push) Successful in 48sreleased this
2026-07-27 09:23:51 +00:00 | 838 commits to staging since this releaseServiceRadar v1.4.25
Delivered a brand-aligned observability console, operator-facing ad-hoc network
scans, AWX live launch preflight, prefix-tag flow enrichment with NetBox
import, and package-owned credential profiles — plus MTR sweep foundations and
fleet-health surfaces for native add-ons.Whats New
1.4.25
- Observability console: web-ng drops daisyUI in favor of ServiceRadar brand
tokens, redesigns log/event/alert detail viewers, path-based observability
tabs with shareable intent URLs, session-held SRQL pagination, and dialog
top-layer modals that sit above the ops chrome with outside-click dismiss.
(web-ng UI track after v1.4.24) - Ad-hoc network scans: operators can launch scans from web-ng with REST and
LiveView surfaces; core dispatches work and ingests results over JetStream.
(PR #4673) - AWX live launch preflight: controller-bound checks, immutable evidence
snapshots, survey-default review gates, and drift categories surface before
a launch proceeds. (PR #4617) - Prefix tagging and inventory: LPM trie enrichment for flows, NetBox-driven
prefix import, and a first-party NetBox inventory-sync Wasm plugin.
(PRs #4642, #4643) - Package-owned credentials: external packages declare and own credential
profile rules; the UI restyles those rules onto design-system chrome.
(PR #4711) - MTR foundations: HostResult carries MTRStatus for first-class sweep mode
work, and fresh installs retain MTR policy correctly. (PRs #4678, #4663) - Native add-on fleet: rollout health is queryable via API and SRQL; failed
rollouts can retry; zero-touch release reconciliation selects the right
extension package. (PRs #4670, #4667, #4649) - Runtime hardening: agent-gateway buffers stream forward failures; password-
only tenants no longer report SSO; event severity stats include current
events; web-ng liveness stays up during migrations; synthetic liveness
alerts are suppressed; continuous-aggregate privileges for seasonal
disposition are repaired; topology attachment metadata is retained.
(PRs #4664, #4662, #4661, #4660, #4659, #4658, #4672, #4651) - Armis identity: generic identity bridges are removed; hermetic DIRE E2E
coverage and integration NATS fixtures land in CI. (PRs #4707, #4712, #4719) - Docs and build: ServiceRadar Cloud quickstart runbook; product docs aligned
to the design system; Bazel-generated Rust gRPC bindings for dgraph protos.
(docs track, PR #4737)
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Observability console: web-ng drops daisyUI in favor of ServiceRadar brand
-
v1.4.24
StableAll checks were successfulHelm Lint / Helm Lint (pull_request) Successful in 42sSecret Scan / gitleaks (pull_request) Successful in 2m6slint / lint (pull_request) Successful in 4m38sGolang Tests / test-go (pull_request) Successful in 11m1sCI / build (pull_request) Successful in 39m1sSource Security Scan / source-security (push) Successful in 12m59sPublish Native Add-ons / publish (push) Successful in 14m55sPublish Wasm Plugins / publish (push) Successful in 14m52sImage Security Scan / image-security (push) Successful in 39m45sPublish Release Artifacts / publish (push) Successful in 42m18sPublish Release Artifacts / finalize (push) Successful in 44sreleased this
2026-07-19 03:01:08 +00:00 | 1050 commits to staging since this releaseServiceRadar v1.4.24
Made verified releases and trusted extension maintenance zero-touch, added
health-gated add-on fleet updates, stabilized recurring reconciliation, and
improved cross-subnet topology discovery.Whats New
1.4.24
- Zero-touch releases: cached publication retries now recover immutable OCI
digests and sign the verified registry artifact. Complete signed releases
advance the guardeddemo/prod-releasebranch, where conservative ArgoCD
auto-sync deploys them without prune or self-heal. (PRs #4627, #4629, #4631) - Native add-ons: the catalog converges on the latest verified first-party
release, safely auto-approves trusted packages, and advances compatible
fleet assignments through canaries, bounded batches, health gates, soak
windows, and rollback. Legacy policy backfill runs asynchronously so startup
is never blocked. The anomaly add-on advances to 0.3.1. (PRs #4633, #4636) - Wasm plugins: canonical signed packages import automatically, trusted legacy
assignments recover from current mTLS and authoritative policy evidence, and
the UI reports the actual deployed release instead of stale catalog data.
(PR #4632) - Runtime reconciliation: invalid Proxmox credential rules become stable,
fail-closed skips instead of repeated grant failures, while stale Oban
execution recovery uses row locking and enum-safe schema updates. (PR #4638) - Automation packaging: AWX launch sanitization accepts pending controller
evidence, and TinyGo argument allowlists remain reproducible in CI. (PR #4628) - Topology mapping: cross-subnet attachment evidence, Q-BRIDGE forwarding
discovery, UniFi management identity, and identifier-aware binding improve
device placement across routed networks. (PR #4640)
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
- Zero-touch releases: cached publication retries now recover immutable OCI
-
v1.4.23
StableSome checks failedHelm Lint / Helm Lint (pull_request) Successful in 39sSecret Scan / gitleaks (pull_request) Successful in 1m22slint / lint (pull_request) Successful in 2m55sGolang Tests / test-go (pull_request) Successful in 8m10sCI / build (pull_request) Successful in 24m5sSource Security Scan / source-security (push) Successful in 5m41sPublish Native Add-ons / publish (push) Successful in 6m35sPublish Wasm Plugins / publish (push) Successful in 6m20sPublish Release Artifacts / publish (push) Failing after 35m21sPublish Release Artifacts / finalize (push) Has been skippedImage Security Scan / image-security (push) Successful in 38m13sreleased this
2026-07-18 08:49:47 +00:00 | 1080 commits to staging since this releaseServiceRadar v1.4.23
Restored first-party add-on and plugin imports, removed impossible legacy
recovery actions, and stabilized recurring background work and release
validation.Whats New
1.4.23
- Native add-ons: verified immutable bundles can be reused across release
envelopes when an add-on version is unchanged. Corrected first-party package
versions and OCI identity checks prevent false source conflicts during
release catalog synchronization. (PR #4613) - Wasm plugins and assignment recovery: signed bundles with empty optional
manifest arrays now import correctly. The Plugins Manager no longer offers
recovery actions that cannot succeed for unbound historical assignments and
keeps supported assignment workflows available. (PRs #4609, #4610) - Background scheduling: self-scheduling Oban workers reliably retain their
successor jobs under uniqueness constraints. OUI refreshes now run weekly
and provider metadata refreshes daily instead of repeatedly contacting the
upstream services. (PRs #4614, #4623) - Anomaly verification: committed scorecard and regression coverage lock in
spike coalescing, duplicate suppression, and seasonal-delivery behavior
without introducing a second anomaly implementation. (PR #4607) - Release integrity: Git tags, product metadata, Helm charts, Argo release
sources, native add-on catalogs, and published OCI artifacts are checked for
consistent immutable versions. Local release operators can run the same OCI
chart occupancy guard with an installed Helm client. (PRs #4608, #4624) - Gateway availability: Helm now exposes replica, disruption-budget, and
topology-spread controls for highly available Envoy Gateway deployments.
(PR #4606)
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
1 download
- Native add-ons: verified immutable bundles can be reused across release
-
v1.4.22
StableSome checks failedHelm Lint / Helm Lint (push) Successful in 1m50sSecret Scan / gitleaks (push) Successful in 1m42slint / lint (push) Successful in 3m51sGolang Tests / test-go (push) Successful in 9m22sElixir Quality / Elixir Quality (push) Has been cancelledCI / build (push) Has been cancelledHelm Lint / Helm Lint (pull_request) Successful in 1m50sSecret Scan / gitleaks (pull_request) Successful in 2m5slint / lint (pull_request) Successful in 4m21sGolang Tests / test-go (pull_request) Successful in 9m29sCI / build (pull_request) Successful in 31m2sElixir Quality / Elixir Quality (pull_request) Successful in 38m23sPublish Native Add-ons / publish (push) Successful in 5m59sSource Security Scan / source-security (push) Successful in 5m57sPublish Wasm Plugins / publish (push) Successful in 6m17sImage Security Scan / image-security (push) Successful in 28m47sPublish Release Artifacts / publish (push) Successful in 30m0sPublish Release Artifacts / finalize (push) Successful in 48sreleased this
2026-07-17 15:24:07 +00:00 | 1119 commits to staging since this releaseServiceRadar v1.4.22
Restored hosted core startup for tenant environments that use the private
first-sign-in mail flow.Whats New
1.4.22
- Hosted first sign-in: core now uses Swoosh's supported Req API client, which
is already included in the production image. This prevents startup from
aborting when local mail delivery is enabled and Hackney is intentionally
absent. - Release configuration coverage verifies that the local-mailer production
overlay retains Req and that the conflicting Hackney client is not loaded.
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
1 download
- Hosted first sign-in: core now uses Swoosh's supported Req API client, which