Skip to content

Stable releases of July 23, 2026

Everything that shipped on the stable channel on July 23, 2026 — v2.6.2 through v2.6.6, newest first. v2.6.6 is what you install; the versions below it are how you get there.

Stable v2.6.6

  • fix(changelog): raise the stable changelog ceiling to the installed version

Stable v2.6.4

  • fix(ssl): show aliases/subdomains as secured when covered by the primary cert's SAN

Stable v2.6.3

  • fix(aliases): pre-fill www. on domain select to prevent full-domain retyping
  • fix(ssl,domains): show actual resolved IP + bidirectional alias cleanup
  • docs(plan): mark Phase 2/3 hardening + upstream repos done
  • feat(agent): nginx.org upstream repo (opt-in) + own the vhost includes
  • fix(sites): sites table fits narrower widths (progressive responsive columns)
  • fix(changelog): keep full pre-stable history in the public changelog
  • fix(docs): restore stable-version.json — panel fetches it to filter the stable changelog
  • feat(changelog): separate stable and testing changelog lines

Stable v2.6.3

  • feat(dashboard): security score badge in the admin header, linking to the advisor
  • fix(cra): self-invalidate stale CVE cache + stable changelog shows full history

Stable v2.6.2

  • fix(agent): self-heal half-configured packages after the security catch-up
  • feat(agent): apply pending security updates immediately after the fix + keep configs
  • fix(security): apply Debian OS security updates on trixie + honest CVE feed
  • feat(cra): CVE feed sourced from Debian Security Tracker (real open CVEs)
  • fix(cra): CVE feed — readable severity + per-component grouping
  • fix(cra): golangci-lint on CVE feed (errcheck + US spelling)
  • feat(cra): live CVE feed — SBOM components matched against OSV.dev
  • docs(plan): CRA cockpit stages 1-4 complete (SBOM, security.txt, incidents, snapshots)
  • feat(cra): security.txt generator (RFC 9116) for coordinated disclosure

Stable v2.6.2

  • feat(release): stable release rebuilds current code at the stable version
  • feat(cron): optional e-mail notification per cron job (none/errors/always)
  • fix(agent): correct PowerDNS repo key + self-heal changed vendor keys
  • feat(agent): add PowerDNS, MariaDB, Dovecot to vendor upstream repos
  • feat(agent): pin package families to vendor current-stable repos (rspamd pilot)
  • feat(cra): evidence snapshots — audit trail of CRA readiness over time
  • feat(cra): incident register (Art. 14 reporting evidence)
  • fix(deps): bump golang.org/x/text to v0.39.0 (GO-2026-5970)
  • fix(release): stable promotion advances sequentially, not to testing tip