github carverauto/serviceradar v1.4.52

10 hours ago

ServiceRadar v1.4.52

An unenrolled SSH host key is a reviewable trust decision at the
console instead of a dead session. Packet capture runs end to
end from netprobe through the agent gateway. NetBox and Proxmox
credentials come from the unified database model, the CLI is
srctl with device-code sign-in, and Kubernetes node readiness
raises alerts. Also: Proxmox console and identity fixes, RBAC
reaches SRQL detail queries, and vulnerability matching is
distribution aware.

Whats New

1.4.52

  • Remote access: an unenrolled target host key ends the session
    with a reviewable trust decision naming the dialed address,
    key algorithm, and SHA256 fingerprint, instead of an opaque
    knownhosts: key is unknown close. Accepting reopens the
    session bound to that exact target and fingerprint. A key that
    changed under an already-trusted host stays a hard close.
    (PR #4371)
  • Remote access: SSH close reasons survive broker shutdown, so a
    failed open reports why instead of a generic disconnect.
    (PR #4353)
  • Remote access: SSH and Proxmox host shells prefer inventory
    IPs, certificate connect is refused up front when target
    policy grants no accounts, and RDP setup keeps its fetch
    receiver. (PR #4337, #4344, #4356)
  • Proxmox: the guest console no longer crashes on mount, an
    omitted console assignment resolver is handled, certificate
    pins are honored, and identities no longer fuse across
    clusters. Name-keyed identifiers are archived.
    (PR #4374, #4355, #4329, #4351)
  • Capture: netprobe capture runs end to end -- session caps and
    pre-open, the capture session RPC, agent routing, and the
    agent-gateway bridge. A filter string can no longer kill the
    process or resolve to the wrong port.
    (PR #4284, #4291, #4295, #4296, #4298, #4302, #4304, #4312,
    #4315)
  • Credentials: NetBox and Proxmox integrations take their
    credentials from the unified database model, and the TLS
    policy control is reachable for every transport provider.
    (PR #4134, #4136)
  • CLI: the binary is srctl and supports device-code
    authentication. Plugin configuration has APIs and CLI
    playbooks. (PR #4330, #4333)
  • Kubernetes: node readiness raises alerts, with notification
    setup and current/snapshot node tables. (PR #4338)
  • Authorization: the RBAC policy editor covers group access, and
    LiveView detail queries enforce SRQL RBAC. (PR #4308, #4328)
  • Vulnerabilities: package matching is distribution aware, so a
    backported fix stops reporting as vulnerable. (PR #4279)
  • Sweep: attempted port coverage and attribution are durable,
    device_sweep_overlap reports declared-vs-observed, and a
    group with execution history can be deleted.
    (PR #4276, #4314, #4335)
  • Inventory: device IP conflicts surface as validation errors and
    inferred device types are corrected across integrations.
    (PR #4370, #4336)
  • Web UI: observability pages have live controls, anomaly alerts
    are named by metric and identity, log detail shows the
    collector target and error, and the event anomaly summary
    respects the viewer timezone.
    (PR #4331, #4311, #4309, #4300)
  • Core: netflow provider CIDR index bloat is reclaimed by
    concurrent reindex, admission-lane histograms get Prometheus
    buckets, outbound auth timeouts fail fast instead of retrying,
    and anomaly drift modes normalize booleans.
    (PR #4322, #4299, #4343, #4326)
  • Schema: 20260904120000 (device sweep overlap view),
    20260904174656 (role profile on user groups),
    20260906110000 / 20260906120000 (Kubernetes node tables),
    20260906140000 (cascade sweep group deletes),
    20260906150000 (archive Proxmox name-keyed identifiers).
    migrations.expectedVersion is 20260906150000.

Don't miss a new serviceradar release

NewReleases is sending notifications on new releases.