github PegaProx/project-pegaprox v1.0.1
PegaProx 1.0.1

4 hours ago

A maintenance + feature release on top of 1.0.

🌏 Languages

  • Simplified Chinese (įŽ€äŊ“中文) — the web UI is now available in Simplified Chinese. Thanks @ranydb.

đŸ–Ĩī¸ Console

  • SPICE is offered in every VM console entry point — a downloadable virt-viewer .vv for audio / USB / multi-monitor sessions, alongside the built-in noVNC.

🔒 Security

  • Another Aikido penetration-test pass closed a set of authorization / IDOR gaps: power- and cost-rate reads are now scoped to the caller's clusters (a scoped API token can no longer enumerate every cluster's rates); the client portal's reboot action is gated on vm.restart instead of vm.start; and further authz / validation / SSRF invariants from batches 1–2 are enforced.
  • The CIS SSH-hardening control no longer disables TCP forwarding — the built-in VNC console tunnels through it — and applied hardening controls are now selectable for rollback.

🐛 Fixes

  • Container disks — adding a disk to a container now targets a container mountpoint (mpN) instead of a QEMU disk key, and never overwrites an occupied slot.
  • Unlock — a locked VM/CT can be unlocked even on token-authenticated clusters (falls back to qm / pct unlock over SSH).
  • OIDC keeps the full preferred_username instead of truncating at @ (#486).
  • RBAC — the storage / snapshot / backup / update action bars follow their backend permissions (#644).
  • Scheduled rolling + maintenance updates evacuate local disks by default (#630 / #629).
  • Node temperature parsing falls back to plain sensors text when JSON is unavailable (#601).
  • In-band BMC reads fall back key → agent → password, so password-only nodes still report hardware health (#609).
  • ESXi / cross-hypervisor migration lists route to their own handlers (#654).

đŸ“Ļ Platform

  • ARM64 / aarch64 build artifacts are now published (#674). Thanks @gyptazy.
  • cryptography is pinned to 50 and pyOpenSSL to 26.4 to keep the vulnerable 49 line out (#650).

✅ Quality

438 automated tests (authorization, integration, SSL-bootstrap, hardware, i18n) run on every PR, and the whole branch was re-audited before release.

Thank you to everyone who filed, fixed, translated and sponsored along the way. 💚

💛 Sponsors

PegaProx is AGPL-3.0 and built in the open. Huge thanks to our Platinum sponsors who keep it moving:

💎 Platinum

Don't miss a new project-pegaprox release

NewReleases is sending notifications on new releases.