github basnijholt/compose-farm v1.22.1

3 hours ago

Security fixes

  • Make the web UI safe by default: bind to loopback and reject remote HTTP and WebSocket clients unless authentication or an explicit opt-out is configured.
  • Verify SSH host keys for native and AsyncSSH connections, with fingerprint confirmation and trust-only setup support.
  • Update vulnerable dependencies and audit the locked production dependency set with uv audit in CI.
  • Pin and checksum remotely vendored frontend assets and verify them during wheel builds.
  • Keep the container password database read-only while supporting arbitrary runtime user IDs.
  • Constrain registry update requests by validating request bodies, batch sizes, image inventory, and registry destinations.
  • Shell-quote compose stack paths used in remote commands.

Maintenance

  • Upgrade and pin GitHub Actions to current stable releases.
  • Update the Traefik example to 3.7 and the Paperless Redis example to 8.

Full changelog: v1.22.0...v1.22.1

Don't miss a new compose-farm release

NewReleases is sending notifications on new releases.