Stable-Releases vom 7. Oktober 2026¶
Alle Änderungen, die am 7. Oktober 2026 im Stable-Kanal erschienen sind — von v2.10.9 bis v2.10.10, neueste zuerst. Installiert wird v2.10.10; die Versionen darunter sind der Weg dorthin.
Stable v2.10.10¶
- Merge: the backup fixes from the audit — locks, hanging runs, room on disk, panel state
- fix(backup): PostgreSQL dumps reach psql through stdin, a key that does not fit an existing repository is named, a failed panel-state run shows as a failure, an unknown database name is reported
- fix(backup): the panel state holds roles and the platform's own databases, not the customers' data
- fix(backup): panel state, node state and the recovery flows work on disk too, and reserve their room first
- fix(backup): the lock inspection calls get the same wait bound as the other restic calls
- fix(backup): a locked-repository error tells the operator what to do, and a reworded restic retry message is reported instead of silently disabling the stall rule
- fix(backup): database dumps go to disk instead of RAM, the room is reserved before the first dump for every target, and a prune keeps a reserve
- fix(backup): a run retrying a failing backend is stopped within minutes, the short restic calls are bounded and the agent caps parallel runs
- fix(backup): a repository lock is removed only when no process can still hold it
- feat(backup): the panel-state backup is created by itself and the Security Advisor reports its state
- docs: say where the password hashes in the panel-state backup actually live
- feat(backup): a restore brings back every database dump of the snapshot, restores PostgreSQL, and reports what it could not
- docs: the restore note gets its own section on cross-customer dump import
- fix(backup): a full restore imports only its own snapshot's database dumps and leaves no dump folders behind
- docs: backup system audit, code path findings with questions for measurement
- feat(i18n): fail the release on new hard-coded UI text
- fix(security-advisor): show the CVE and PHP hints, the scope note and the RFC line in the viewer's language
Stable v2.10.9¶
- fix(sites): sites without a wish are brought to their package's worker limit at start instead of keeping a stale stored value
- fix(sites): the backfill no longer reads the old default as a wish, new sites' pools get the package limit, a wish of 1 is shown as the 2 the pool runs
- fix(ui): a failed or waiting preview capture shows a symbol with the reason, one hook for all four thumbnails
- fix(i18n): add the texts for a failed and a busy site preview in all 15 languages
- fix(sites): a customer's worker wish is kept apart from the effective count, so a downgrade and upgrade give it back and new sites show what their pool gets
- fix(screenshots): a failed capture answers 502 instead of 404 and a failing site is retried with a back-off, not on every page view
- fix(quota): limits and permissions follow the subscription they belong to, forwarders, catch-alls and error pages are stored under their own subscription
- docs: record the test box's new load recording and keep the watcher in the repo
- fix(subscriptions): worker changes by a package change are audited, a new site takes the slice of its own subscription
- fix(subscriptions): a package change moves the PHP worker pools and DB governor limits along, and package edits stop rebuilding other subscriptions' pools
- fix(screenshots): a second refresh run skips captures already in progress, hung-capture slot release under test
- Merge: the Security Advisor says its findings in the reader's language
- fix(advisor): the PHP end-of-life check follows installed packages, not leftover config directories
- fix(screenshots): one shared limit on concurrent Chromium captures so previews cannot drive a server into OOM
- docs: clear the demo's remaining findings and record how, with the measured memory figures
- feat(security-advisor): translate the fix explanations via message keys
- feat(security-advisor): translate the finding texts via message keys and parameters