Zum Inhalt

Stable-Releases vom 4. September 2026

Alle Änderungen, die am 4. September 2026 im Stable-Kanal erschienen sind — von v2.9.34 bis v2.9.40, neueste zuerst. Installiert wird v2.9.40; die Versionen darunter sind der Weg dorthin.

Stable v2.9.40

  • fix(fail2ban): move wp-login jail placeholder out of the customers webroot
  • fix(fail2ban): wp-login jail's glob logpath killed the ENTIRE fail2ban service on a fresh install

Stable v2.9.39

  • fix(security): pass the fix-applied flag through to the frontend

Stable v2.9.39

  • Maintenance and stability improvements

Stable v2.9.38

  • feat(security): coordinate the firewall when the SSH port changes in the GUI

Stable v2.9.37

  • Maintenance and stability improvements

Stable v2.9.36

  • fix(import): remove Plesk "Backup Upload" mode — described a feature that was never implemented
  • fix(apparmor): watcher's denial filter required a substring that never occurs in real kernel output
  • fix(mail): bound doveadm sieve calls with a timeout, no more unbounded agent hang

Stable v2.9.35

  • feat(waf): surface exclusion recommendations in the Ausnahmeregeln table
  • fix(waf): allow HTTP/3 in ModSecurity protocol enforcement; add exclusion recommendations

Stable v2.9.34

  • fix(waf): re-verify logrotate self-heal on every agent start, not just first install
  • feat(stats): surface the accurate cookie-based demo visitor count
  • fix(stats): filter demo-visitor scanners that forge the demo Referer
  • fix(stats): stop leaking the Postgres password via docker exec argv
  • fix(stats): separate active vs. all-time counts on licensed/trial cards
  • fix(stats): scope Panel-Version/Update-Kanal to active installs only
  • feat(stats): add a Licenses tab with active-installation counts