A status page for the people who use your services: a read-only page behind a secret link, set up under Config → Status page. Around it, Config gets tabs for Unraid and a "new" mark in the section list, Bookmarks and the category titles draw faster with many bookmarks and containers, two theme fixes, and the build now checks for known vulnerabilities before anything is released.
Status page
- new — a page at
/s/<token>for the people who use your services, with its data at/s/<token>/data.json. It shows an overall line, a banner for planned maintenance, and groups of services, each with its state, since when it is down, 30 day bars, response time and uptime. The visitor's device picks the language and light or dark; the page refreshes every minute and pauses while the tab is hidden. It never shows error details, container images or internal addresses unless Link is switched on for a service. Config and token live in the store; every wrong address answers the same 404,/s/*allows 60 requests a minute per visitor (counted by the real client address behind a proxy), "Only from the home network" lets in private addresses the install can identify, and the token is kept out of the request log. The owner API sits behind the write token. Specs:tests/status-page-visitor.spec.jsand thestatus_page_*_test.gofiles. - new — Config → Status page. Five tabs, All and then one per card: Link and access (turn it on, Copy, Open, a QR code, New link… which retires the old link at once), Top of the page, Groups and services (a picker offers a linked bookmark and container as one service) and Maintenance (windows per group). Sub-tabs and ℹ modals as on the other sections. Spec:
tests/config-status-page.spec.js. - fix — editing a maintenance window under Behavior no longer drops the groups it is linked to. The window was saved from the form's fields alone, and the link to the status page's groups is not one of them.
- new — the status page and Config → Status page speak all six languages. The visitor page picked the language from
Accept-Language, but its 32 strings (statusPageStringsinstatus_page_view.go) had nostatusPage.*keys inlocales/, so every visitor read English; Config → Status page's 78 strings and the four Unraid tab names existed only as English fallbacks too. All of them are inlocales/{en,nl,de,fr,es,zh}.jsonnow. - fix — the command palette offers Config → Status page.
_CONFIG_SECTIONSinsearch-commands.jshad no row for it, so typing config status found nothing.commands.configStatusPageis its label in six languages;tests/dashboard-command-palette-config.spec.jscompares the palette againstDashboardConfig.SECTIONSand failed without it.
Config
- new — Unraid has tabs. All, Connection, How it works and What you get, as on the other sections; a tab hides cards instead of redrawing them, so the page no longer jumps when you move between sections.
tests/config-unraid.spec.jscovers it. - new — a small "new" behind Structure, Containers, Unraid and Status page in the section list.
DashboardConfig.NEW_SECTIONSnames them, and the mark is drawn from an attribute with empty alt text so the tabs keep their accessible names. Clear the list once the release is no longer recent.
Performance
- fix — containers are matched to bookmarks once, not once per row.
containersForranbookmarkForfor every container on every row, so the work grew as rows × containers × bookmarks, and each call parsed addresses withnew URL.docker-search-index.jsnow keeps the answer for every container until the container list, the bookmarks, the links set by hand or the host address change, and parses each address once.tests/docker-bookmark-link.spec.jsfails without it. - fix — category titles are fitted together, not one at a time. Each title was reset, measured and resized in turn, and every measurement forced a layout.
dashboard-category-title-fit.jsnow fits all of them in a fixed number of layouts, however many there are.tests/category-title-fit-batched.spec.jscounts the layouts. - fix — the Bookmarks list looks up its URL keys and its rows once when health lands. The canonical key of an address is cached by the address as given (it depends on the string alone, so it cannot go stale), and the health repaint builds one lookup for all rows instead of walking the library for each.
tests/bookmarks-health-repaint-cost.spec.jscovers it.
Themes
- fix — the newest theme stylesheet wins, and older ones go. Two refreshes in a row (Use theme runs one inside
applyThemeChoiceand one after it) left two/api/theme.csslinks loading, and the second was put after the first only by position, so the older copy could come last, win the cascade and never be removed.visual-settings.jsnow replaces the last link and removes every link before the new one.tests/theme-css-reload.spec.jscovers it. - fix — with several custom themes, the theme stylesheet has the same bytes every time. Custom themes came out in map order, so with two or more of them every render after any data write hashed differently and the browser fetched the 600 KB file again. They are sorted now, as the built-in themes are.
TestThemeCSSSameThemesSameBytesfails without it.
Inbox
- fix — pasting a link the Inbox already holds opens a styled Inbox. The answer to a duplicate is to open the view on the existing item, and that went straight to
DashboardInbox.openInboxView, past the loader's, which was the only one to fetch the views stylesheet bundle. On a fresh dashboard the list then drew as bare markup. The module'sopenInboxViewnow awaitsViewStyles.ensureViewStylesitself, which also covers triage started from the dashboard.tests/dashboard-paste-choice-style.spec.jspastes a duplicate and checks the Inbox's rules have arrived.
Build and security
- new — Go 1.26 and a current
golang.org/x/net.govulncheckon Go 1.24 reported 29 advisories in the standard library, which this moves past. The Dockerfile builds withgolang:1.26-alpineand runs on Alpine 3.24, and CI takes its Go version fromgo.mod. - new — CI runs
govulncheckon every push, pinned to v1.1.4 so a new release of the tool cannot change what passes. - new — the release image is scanned with Trivy before it is pushed, in
docker-publish.yml, which dev now tracks too. - new —
release-to-main.shruns the same two checks first, throughscripts/release-preflight.sh:govulncheck, and a Trivy scan of an image built on this machine. It needs Docker running, and--skip-scanskips it for an emergency. A finding indocker-publish.ymlwould leave a release with no image and no way out but a new patch version; this finds it before anything is merged, tagged or pushed. - fix — the browser extension's copy of
bookmark-url-utils.jscarries the URL key cache too. The cache went intostatic/js/bookmark-form/only, and CI'scheck-extension-bookmark-form.shfailed on the drift;sync-extension-bookmark-form.shbrought the copy level.
Tests
- tests —
tests/config-help-health.spec.jscounts nine panels on Help → Monitoring, with the two for the status page.tests/whats-new-hidden-release.spec.jsnames v1.19.0 as the release the modal leads with.
Help and docs
- docs — Help → Config lists Unraid and Status page among the sections and explains the "new" mark and the tabs they share with Inbox and Containers.
config.sectionStatusPagewas missing, so its label fell back to English in every language; it exists in all six now. - docs — MANUAL §12.8 and §23.10 and Help → Monitoring describe the status page, how to share it over the internet (proxy only
/s/and/static/status/,NEXTDASH_TRUSTED_PROXIES) and what to restore. The README lists it under Health and monitoring. - docs — Help → Monitoring's two status page panels open with a drawing and read in six languages. Every Help article opens with one (
tests/config-setting-art.spec.js): a working and a down service for The status page, and the two paths a proxy should pass for Sharing the status page safely (HELP_PANEL_ART). Their bodies were English fallbacks in the code;config.helpStatusPage*now has them in every language, and the "new" mark in the section list (config.sectionNewBadge) is translated too. - docs — Config → Overview and About → News & features carry the status page, dated
v1.19.0, in six languages.
Docs
- docs —
static/data/whats-new/v1.19.0.jsonand its index entry;whats-new-stub.jsmovedDASHBOARD_RELEASEto2026.10-dashboard-release-v1.19.0andNEXTDASH_WHATS_NEW_DATA_VERSIONone step. The Inbox fix above was listed under v1.18.4.1 after that release went out; it ships here, so it moved.go generaterefreshedasset_hashes_gen.go.