github marcpope/borgbackupserver v2.98.5

2 hours ago

We've spent a good part of the past week hardening and locking down BBS: code audits, outside security reports, and an automated scanner that now checks every change. The goal is for BBS to be the most secure platform for running Borg backups. This release finishes the current round.

Security

  • Docker: the default admin account could come back after a restart. Each container start re-applied every database migration, including the one that created admin with the password admin. On an install where the default admin had been given a new username and a new email, the next restart created a second admin account with that password. Docker now applies each migration once. The update locks any account still on that password, as long as another admin exists, and logs a warning. If your Users list shows an admin account you didn't create, delete it.
  • The default admin no longer uses a borgbackupserver.com email address. Docker installs that kept admin@borgbackupserver.com are moved to admin@localhost.invalid, an address that can't receive mail. Password reset no longer sends links to placeholder addresses. Set a real address in your profile so password resets and notifications reach you.
  • Server host is validated. The server host and per-client host override must be a hostname or IP address. The value is written into the server's configuration file, and it wasn't checked before.
  • Every finding from the new code scanner has been reviewed.

Fixes

  • Docker installs now run every migration, including the ones written in PHP. Before, upgraded Docker installs skipped those, so the 2.98.4 change that encrypts plugin passwords saved in plain text only took effect on fresh Docker installs.

No agent change; agent stays 2.98.4.

Don't miss a new borgbackupserver release

NewReleases is sending notifications on new releases.