Stable-Releases vom 23. Juli 2026¶
Alle Änderungen, die am 23. Juli 2026 im Stable-Kanal erschienen sind — von v2.6.2 bis v2.6.6, neueste zuerst. Installiert wird v2.6.6; die Versionen darunter sind der Weg dorthin.
Stable v2.6.6¶
- fix(changelog): raise the stable changelog ceiling to the installed version
Stable v2.6.4¶
- fix(ssl): show aliases/subdomains as secured when covered by the primary cert's SAN
Stable v2.6.3¶
- fix(aliases): pre-fill www.
on domain select to prevent full-domain retyping - fix(ssl,domains): show actual resolved IP + bidirectional alias cleanup
- docs(plan): mark Phase 2/3 hardening + upstream repos done
- feat(agent): nginx.org upstream repo (opt-in) + own the vhost includes
- fix(sites): sites table fits narrower widths (progressive responsive columns)
- fix(changelog): keep full pre-stable history in the public changelog
- fix(docs): restore stable-version.json — panel fetches it to filter the stable changelog
- feat(changelog): separate stable and testing changelog lines
Stable v2.6.3¶
- feat(dashboard): security score badge in the admin header, linking to the advisor
- fix(cra): self-invalidate stale CVE cache + stable changelog shows full history
Stable v2.6.2¶
- feat(release): stable release rebuilds current code at the stable version
- feat(cron): optional e-mail notification per cron job (none/errors/always)
- fix(agent): correct PowerDNS repo key + self-heal changed vendor keys
- feat(agent): add PowerDNS, MariaDB, Dovecot to vendor upstream repos
- feat(agent): pin package families to vendor current-stable repos (rspamd pilot)
- feat(cra): evidence snapshots — audit trail of CRA readiness over time
- feat(cra): incident register (Art. 14 reporting evidence)
- fix(deps): bump golang.org/x/text to v0.39.0 (GO-2026-5970)
- fix(release): stable promotion advances sequentially, not to testing tip
Stable v2.6.2¶
- fix(agent): self-heal half-configured packages after the security catch-up
- feat(agent): apply pending security updates immediately after the fix + keep configs
- fix(security): apply Debian OS security updates on trixie + honest CVE feed
- feat(cra): CVE feed sourced from Debian Security Tracker (real open CVEs)
- fix(cra): CVE feed — readable severity + per-component grouping
- fix(cra): golangci-lint on CVE feed (errcheck + US spelling)
- feat(cra): live CVE feed — SBOM components matched against OSV.dev
- docs(plan): CRA cockpit stages 1-4 complete (SBOM, security.txt, incidents, snapshots)
- feat(cra): security.txt generator (RFC 9116) for coordinated disclosure