github rcourtman/Pulse v6.3.1
Pulse v6.3.1

latest release: helm-chart-6.3.1
4 hours ago

✅ Release Asset Validation: PASSED

All release assets have been validated successfully!

Status: Ready for publication ✅
Validated: 2026-08-23 12:54:50 UTC
Workflow: Pulse Release Pipeline #370

Validation Summary

  • All required assets present ✓
  • Checksums verified ✓
  • Version strings correct ✓
  • Binary architectures validated ✓

Pulse v6.3.1 Release Notes

v6.3.1 is a stable patch release for the Pulse v6 line. It follows stable
v6.3.0 and contains focused corrections for alert delivery, Unified Agent
control, local subscription providers, and Docker monitoring overhead.

Highlights

  • Recover or dismiss terminal notification failures without losing delivery
    history, while disabled PBS offline alerts remain silent.
  • Docker commands recover safely after token rotation, and Synology hosts avoid
    repeated full-daemon storage scans on every report.
  • Local subscription providers now resolve and diagnose their CLIs as the
    actual Pulse service account.

Improved

  • Notification delivery history now exposes confirmed retry and dismiss
    operations for terminal failures. Retried items receive a fresh bounded
    attempt budget while their prior audit history remains available.
  • Refused governed actions record the resource, capability, stable refusal
    code, and the specific Docker command-agent lookup that missed.
  • Standard systemd installs give the Pulse service account a private CLI home
    and a deterministic executable search path. Explicit provider CLI path
    overrides remain available for non-standard layouts.
  • Docker host storage totals are refreshed on a bounded 15-minute cadence and
    retain the last good aggregate when a refresh fails. Live host and container
    metrics continue on the configured reporting interval.

Fixed

  • Disabled PBS offline alerts no longer enter the notification dispatch path;
    enabled alerts and recovery notifications retain their existing lifecycle.
  • Docker start, stop, restart, remove, and update commands recover after an
    agent reporting-token rotation by proving the exact tenant, agent ID, and
    canonical hostname rather than weakening identity matching.
  • Docker update preflight once again routes through the Unified Agent, and
    terminal digest-drift refusals no longer strand later update attempts.
  • Local subscription setup failures now distinguish a CLI that is missing or
    not logged in for the Pulse service account from provider network
    reachability failures.
  • Synology DSM Docker monitoring no longer launches a verbose daemon-wide disk
    usage inventory every 30 seconds or immediately retries a slow failed scan.

Release Qualification

  • The release uses the emergency stable-patch path because the fixes address
    active customer harm across alert delivery, infrastructure control, local AI
    setup, and Docker host load without introducing a same-version RC.
  • The exact pushed release SHA must pass the no-publication Release Dry Run and
    its integrated exact-SHA candidate checks before that same SHA is submitted
    to the single-build publication workflow.
  • The release owner approved a v6.3.1-only exception because SignPath's
    production certificate remains CSR pending. Windows Unified Agent binaries
    are not Authenticode-signed and may display an Unknown Publisher warning;
    exact-SHA checksums, detached signatures, immutable-manifest verification,
    and published-digest verification remain mandatory.
  • No mobile-facing path changed between v6.3.0 and this release, so the mobile
    decision is no-mobile-impact; no companion build or store rollout is
    required.

Upgrade Notes

Use the normal v6 install or update flow for v6.3.1. Existing configurations
remain valid and no manual data migration is required.

The rollback target is v6.3.0. The exact rollback reinstall command is:

./scripts/install.sh --version v6.3.0

Paid Pulse Pro, Relay, and eligible legacy customers should continue to use the
private download page and private runtime image for paid runtime features.

Installation

Docker (recommended):

docker pull rcourtman/pulse:6.3.1

Docker Compose:
Update your docker-compose.yml to use rcourtman/pulse:6.3.1

See the Installation Guide for complete setup instructions.

Review the Code signing policy for release provenance, approval roles, and signing scope.

Paid Pulse Pro, Relay, and eligible legacy customers: public GitHub release assets and the public rcourtman/pulse Docker image are community builds. They do not include the private Pulse Pro runtime hooks. Use https://pulserelay.pro/download.html with your activation key to get the private Pulse Pro Docker image or Linux/LXC archive.

Promotion Metadata

  • Promotion channel: stable
  • Candidate stable tag: v6.3.1
  • Promoted prerelease tag: n/a
  • Rollback target: v6.3.0
  • Rollback command: ./scripts/install.sh --version v6.3.0
  • Hotfix exception: true
  • Hotfix reason: Active customer harm across notification delivery recovery, Docker command continuity, local subscription setup, and Synology Docker host load.
  • Windows Authenticode required: false
  • Unsigned Windows exception: true
  • Unsigned Windows reason: SignPath production certificate remains CSR PENDING and the release-signing policy is invalid; the release owner accepts unsigned Windows Unified Agent artifacts for v6.3.1 with public Unknown Publisher disclosure and unchanged exact-SHA integrity controls.

Don't miss a new Pulse release

NewReleases is sending notifications on new releases.