v2026.10.09.01 – v2026.10.09.02 — 2026-10-09
- fix(security): six net/http CVEs in the Go standard library, fixed by moving to go1.26.9
- feat(backup): carry the panel's own backup expectation into the snapshot as a manifest
- fix(backup): a customer's "backup now" and restore now cover every site, not just the first
- feat(backup): count mailboxes too, customer-wide like sites and databases
- fix(backup): tar_failed reaches the operator, and an incomplete run is never a pass
- feat(backup): name how much a customer-scoped scope covers
- fix(backup): panel-state tarDir failures no longer vanish into a false success
- fix(backup): a rolled-back config restore stops being followed by a reconfigure
- fix(backup): a restored mailbox whose panel record is gone is reported, not success
- fix(license): name the monthly self-service reset limit, not just the state
- fix(backup): a restore writes only into databases it may write into
- fix(a11y): the check id next to a warning policy stays readable in the light theme
- fix(backup): a run that is waiting for a free slot stops calling itself running
- fix(backup): ADR renumbered, restore-side dump clients joined, criterion 2 answered
- feat(backup): run backup and restore work in its own slice, rebuilt on today's main
- fix(sites): the per-site "Back up now" dialog names Databases' real scope