Zum Inhalt

Stable-Releases vom 27. Juli 2026

Alle Änderungen, die am 27. Juli 2026 im Stable-Kanal erschienen sind — von v2.6.25 bis v2.6.36, neueste zuerst. Installiert wird v2.6.36; die Versionen darunter sind der Weg dorthin.

Stable v2.6.36

  • fix(repair): don't flag uncoverable (NXDOMAIN) names as SAN drift

Stable v2.6.35

  • fix(repair): resolve SAN reachability via public DNS, not the local resolver

Stable v2.6.34

  • fix(repair): RepairSSL dropped www SANs on multi-IP servers

Stable v2.6.33

  • fix(repair): heal www of site-less redirect domains (RepairSSL + RepairNginxRedirects)

Stable v2.6.32

  • fix(ssl): also cover www of redirect domains that have no www domain row

Stable v2.6.31

  • fix(ssl): render redirect vhost before reissuing so www ACME challenge passes

Stable v2.6.30

  • fix(wordpress): CVE count over-counted + dashboard CVE links went nowhere

Stable v2.6.30

  • fix(ssl): www.* of a site-less redirect domain served the wrong certificate
  • fix(webstats): drop GoAccess '-' placeholder rows from category tables
  • fix(webstats): GoAccess JSON tables empty — --output-format is deprecated
  • fix(plesk-import): heal subdomains previously imported as standalone sites
  • feat(webstats): native stats page with time-range, replacing the GoAccess iframe
  • fix(plesk-import): subdomains, Obsidian schema, SSH-key DB, visible data loss
  • fix(i18n): portal snapped back to server default language after login

Stable v2.6.29

  • feat(wordpress): CVE exposure on dashboard + opt-in email alerts

Stable v2.6.29

  • fix(ssl): stop burning Let's Encrypt rate limit on domain re-create

Stable v2.6.28

  • fix(ssl): redirect-only domain served the wrong (first domain's) cert

Stable v2.6.27

  • chore(api): remove orphaned wp_vulnfeed_worker.go (deletion was never committed)
  • fix(wordpress): CVE feed stored nothing — tolerate array-shaped operator/impact

Stable v2.6.27

  • fix(agent): app ExecStart must be absolute for /opt runtimes + venvs (status=203)
  • fix(agent): app service was never created — drop unusable systemd-analyze verify

Stable v2.6.26

  • fix(wordpress): switch CVE source from removed Wordfence v2 to wpvulnerability.net

Stable v2.6.26

  • fix(agent): npm install with a selected Node version (runuser resets PATH)

Stable v2.6.25

  • feat(sites): reseller access to the Node/Python app manager
  • docs(sites): document selectable Node/Python runtime versions (phase 2)