openhands
8486ac4053
feat(security): add darklist.de source and raise the blocklist cap to 1M
2026-09-24 23:22:27 +02:00
openhands
7f6febf906
fix(security): drop URLhaus feed, validate CIDR ranges, pass unknown client IPs
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 31s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m46s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m40s
2026-09-24 19:19:22 +02:00
openhands
7392b843ad
fix(security): LAPI-only engine boot, import via stdin, correct compose service
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 29s
CI / tests-integration (push) Successful in 1m46s
CI / tests-unit (push) Successful in 1m59s
CI / tests-ui (push) Successful in 2m53s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 1m54s
2026-09-24 18:59:13 +02:00
openhands
9562a75378
feat(security): external IP blocklist sync for the local CrowdSec engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m43s
CI / tests-ui (push) Successful in 2m35s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m3s
2026-09-24 18:39:38 +02:00
openhands
84d53139a9
feat(security): opt-in local CrowdSec LAPI bouncer on the Docker engine
Gitea Actions Runner Test / test-job (push) Successful in 0s
CI / check (push) Successful in 30s
CI / tests-unit (push) Successful in 1m37s
CI / tests-integration (push) Successful in 1m55s
CI / tests-ui (push) Successful in 2m23s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m38s
2026-09-24 18:08:18 +02:00
openhands
7707722f4c
fix(build): remove deprecated middleware to fix Next.js build and update ci-deploy script
CI / check (push) Successful in 4m24s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m58s
2026-09-21 20:58:34 +02:00
openhands
6c53f4680c
feat(studio): run nitro scans in the background with cancel-re-attach and nightly auto-clean
2026-09-19 13:41:14 +02:00
openhands
2c0439db6a
refactor(auth): remove obsolete CONVERT_PASSWORDS env var
...
CI / check (push) Successful in 4m25s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 2m26s
Legacy md5/argon2id hashes are now always upgraded to bcrypt on login, so
the CONVERT_PASSWORDS flag is no longer used. Drop it from env schema,
.env.example, the docker installer, and test mocks.
2026-09-17 15:01:23 +02:00
openhands
faa37e7c58
fix(ci): restore preflight image cleanup marker and remove obsolete publish-container tests
...
CI / check (push) Successful in 4m23s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 5m37s
- Restore build_attempted=1 in ci-preflight.sh so the exit trap
removes the temporary image tag
- Remove publish-container.test.ts and its harness (publication
workflow and script were removed in fff284aa )
- Update deploy-workflow-contract and docker-build-contract tests
to assert that publication has been removed
2026-09-15 11:29:20 +02:00
openhands
da90b90c97
fix(ci): guard browser context cleanup and export news e2e env before build
CI / check (push) Failing after 1m24s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-15 11:21:08 +02:00
Simo
fff284aaa0
ci: remove container publication workflows
CI / check (push) Failing after 1m26s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
2026-09-14 21:28:21 +02:00
openhands
6e0ffff94b
Restore docker-prune retention windows to match deploy contract
CI / check (push) Successful in 4m26s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 4m0s
CI / publish-container (push) Skipped
2026-09-14 17:55:28 +02:00
openhands
1a9e1e791a
Improve catalog studio UX and aggressive docker cleanup
...
CI / check (push) Failing after 1m25s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
Catalog Studio:
- Cross-parent drag & drop now uses optimistic updates with rollback
on failure (no more full tree reload / visible delay)
- Subpage creation adds the node optimistically then refreshes parent
only (was full tree reload)
- Single page deletion refreshes only the affected parent (was full
tree reload)
- Root page creation replaces native prompt() with an inline input
in the root tab bar
- Escape key no longer closes the dialog when an input field is focused
- TreeNodeUpdate type now supports parentId and orderNum for
optimistic structural changes
Docker:
- docker-prune.sh default mode now aggressively cleans all unreferenced
build cache, images >1h old, and stopped containers >1h old
(was 72h/7d/24h which let cache grow past 80% on every push)
2026-09-14 16:52:04 +02:00
Simo
349188af10
Merge remote-tracking branch 'origin/main' into codex/news-ci-preflight
CI / check (push) Successful in 4m18s
CI / preflight (push) Skipped
CI / deploy (push) Successful in 1m37s
CI / publish-container (push) Successful in 50s
2026-09-13 21:27:05 +02:00
openhands
d4e4711a77
feat: add gitlab-ci, logrotate setup and deploy alerts
CI / check (push) Successful in 4m8s
CI / deploy (push) Failing after 1m47s
CI / publish-container (push) Skipped
2026-09-13 21:17:04 +02:00
openhands
b688760309
feat: add documentation, alerts, cron setup and update dashboard
CI / check (push) Successful in 4m6s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m15s
2026-09-13 21:16:08 +02:00
openhands
bd977da3a5
feat: add db-restore, maintenance, doctor scripts and update dashboard
CI / check (push) Successful in 4m7s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m19s
2026-09-13 21:15:14 +02:00
openhands
a605807c69
feat: add perf-report, setup-dev, check-updates and update dashboard
CI / check (push) Successful in 4m9s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m14s
2026-09-13 21:14:26 +02:00
openhands
636fde523f
feat: add dashboard, security-scan, and monitor scripts
CI / check (push) Successful in 4m12s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m17s
2026-09-13 21:13:36 +02:00
openhands
f2b64bc83a
feat: add verify-deploy, check-env, and db-optimize helper scripts
CI / check (push) Successful in 4m13s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m19s
2026-09-13 21:12:50 +02:00
openhands
7840f44e5e
feat: add logs.sh and backup.sh helper scripts
CI / check (push) Successful in 4m9s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m22s
2026-09-13 21:11:05 +02:00
Simo
33a760ab6b
ci: verify isolated Docker news journeys before merging to main
CI / check (push) Successful in 4m23s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
CI / preflight (push) Successful in 1m36s
2026-09-13 21:05:02 +02:00
Simo
46f7ad6571
feat(ops): add integrity-checked backups and isolated restore drills
CI / check (push) Successful in 4m12s
CI / deploy (push) Failing after 2m8s
CI / publish-container (push) Skipped
2026-09-13 20:29:18 +02:00
Simo
7867bf6b72
test(news): gate deployment on an isolated real browser publication journey
CI / check (push) Successful in 3m28s
CI / deploy (push) Successful in 18s
CI / publish-container (push) Successful in 2m47s
2026-09-13 20:27:04 +02:00
Simo
9a2d73a6f6
feat(docker): provide verified-header proxy profiles for self-hosted clones
CI / check (push) Failing after 1m45s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-13 20:15:10 +02:00
Simo
52f6d1491f
fix(news): persist publication requests and retry cache delivery
CI / check (push) Successful in 3m12s
CI / deploy (push) Successful in 1m13s
CI / publish-container (push) Successful in 42s
2026-09-13 18:33:45 +02:00
Simo
13665e0c3c
feat(catalog): persist idempotent bulk operations and retryable deliveries
CI / check (push) Successful in 3m7s
CI / deploy (push) Successful in 1m37s
CI / publish-container (push) Successful in 44s
2026-09-13 18:05:03 +02:00
Simo
76e46d295c
fix(test): register Docker import check with Vitest
CI / check (push) Successful in 3m7s
CI / deploy (push) Successful in 19s
CI / publish-container (push) Successful in 1m25s
2026-09-13 18:02:00 +02:00
Simo
8f55ff2d17
feat(docker): guide clone installation and validate paired update artifacts
CI / check (push) Failing after 1m18s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-13 17:57:14 +02:00
openhands
1caef76f82
feat(ops): self-heal disk pressure instead of only alerting
...
CI / check (push) Successful in 2m36s
CI / deploy (push) Successful in 1m28s
CI / publish-container (push) Successful in 46s
The 5-minute disk probe now reclaims storage automatically: from 85% it runs the gentle age-windowed Docker prune, from 90% it drops the age windows (docker-prune.sh --force: all unused build cache and unreferenced images, all stopped containers) so a mount can never silently max out. Alerts still fire at 85/90/95% and their hint now points at non-Docker growth when reclaiming is not enough. Force mode is reserved for the worker; deploys keep the gentle mode. Volumes are off-limits in every path.
2026-09-13 13:18:00 +02:00
openhands
fe26ca3ff3
feat(ops): alert on filesystem fill levels from the host worker
...
CI / check (push) Successful in 2m30s
CI / deploy (push) Successful in 1m25s
CI / publish-container (push) Successful in 1m5s
Add a pure df parser (disk-usage.ts) with 85/90/95% threshold classification, a diskPressure() alert (Discord/email/alert_logs, severity escalates with fill), and a 5-minute host-side probe in jobs-worker.ts that raises one alert per crossing mount, cooldown-gated per mount+level. Real mounts only: overlay/tmpfs pseudo filesystems are ignored.
2026-09-13 13:12:37 +02:00
openhands
47917bb63b
ops(docker): prune unused cache on deploys and nightly
...
CI / check (push) Failing after 23s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
Add scripts/docker-prune.sh (build cache >72h capped at 4g, unreferenced images >7d, stopped containers >24h; never volumes), run it after every CI deploy and compose update, and schedule a nightly prune from the host-side jobs-worker. Tighten the deployment contract tests to assert the scoped-prune boundaries.
2026-09-13 13:04:03 +02:00
openhands
0af8d8a398
fix(lint): resolve biome formatting and unused variables across codebase
CI / check (push) Failing after 1m5s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-12 19:45:29 +02:00
openhands
91008d84fe
feat(i18n): synchronize all translation keys across all supported locales (25 languages)
CI / check (push) Failing after 1m10s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-12 19:30:16 +02:00
Simo
410a1e466c
fix(ci): keep optional report extraction non-blocking
CI / check (push) Successful in 58s
CI / deploy (push) Successful in 1m24s
CI / publish-container (push) Successful in 48s
2026-09-11 08:42:33 +02:00
Simo
cc714b427a
ci: report per-route JavaScript budgets from Docker build
CI / check (push) Failing after 54s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-11 08:41:31 +02:00
Simo
76f0420d64
feat(import): run catalog synchronizations as durable jobs
CI / check (push) Successful in 57s
CI / deploy (push) Successful in 18s
CI / publish-container (push) Successful in 1m18s
2026-09-11 00:36:22 +02:00
Simo
fec8dd3c5d
fix(docker): enforce Node version alignment across build stages
CI / check (push) Failing after 53s
CI / deploy (push) Skipped
CI / publish-container (push) Skipped
2026-09-11 00:11:18 +02:00
openhands
cea88eaa57
feat(catalog): repair page hierarchy cycles and duplicate sibling page order
...
CI / check (push) Successful in 1m3s
CI / deploy (push) Successful in 1m23s
CI / publish-container (push) Successful in 47s
The Arcturus errors "page hierarchy contains a cycle page 354 and 357" and
"sibling order 1 is used more than once (111 problems)" come from
catalog_pages, not catalog_items: pages 354/357 point at themselves, and
many parents have child pages sharing the same order_num. Extend the
emulator catalog scan + fix to detect both: pages whose parent chain loops
back get detached (parent_id = 0 on the highest cycle member) and every
affected parent's children are renumbered sequentially, preserving their
current relative order.
Add scripts/diag-emulator.ts to inspect the live catalog state.
2026-09-10 11:50:27 +02:00
Simo
27447ce029
feat(docker): add guided install and saved one-command updates
CI / check (push) Successful in 53s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Successful in 46s
2026-09-09 20:49:05 +02:00
Simo
8dc187483c
fix(ci): verify registry upload against exported OCI config
CI / check (push) Successful in 51s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Successful in 54s
2026-09-09 20:33:14 +02:00
Simo
e617ed176a
fix(ci): resolve OCI platform before verifying published config
CI / check (push) Successful in 50s
CI / deploy (push) Successful in 1m7s
CI / publish-container (push) Failing after 43s
2026-09-09 20:27:03 +02:00
Simo
2af244b634
fix(ci): publish registry blobs in bounded chunks
CI / check (push) Successful in 52s
CI / deploy (push) Successful in 1m6s
CI / publish-container (push) Failing after 1m2s
2026-09-09 20:22:07 +02:00
Simo
867113d5d4
fix(ci): publish container under token account namespace
CI / check (push) Successful in 56s
CI / deploy (push) Successful in 1m9s
CI / publish-container (push) Failing after 30s
2026-09-09 19:53:16 +02:00
Simo
c389c3893d
feat(cms): improve catalog, editorial recovery and operations
CI / check (push) Successful in 52s
CI / deploy (push) Successful in 2m10s
CI / publish-container (push) Failing after 1m18s
2026-09-09 19:36:15 +02:00
openhands
ecadef904d
chore: remove knip, husky and lint-staged
...
CI / check (push) Successful in 1m11s
CI / deploy (push) Successful in 1m19s
Drop the unused knip dead-code check and the husky+lint-staged pre-commit hook pipeline. All checks remain covered by the CI workflow (lint, typecheck, i18n, tests).
2026-09-08 16:56:55 +02:00
openhands
2a1aef1c1b
fix: complete Playwright removal in CI deploy workflow
...
CI / check (push) Successful in 1m13s
CI / deploy (push) Successful in 2m9s
Drop the leftover Playwright browser install and e2e smoke test from the deployment script, and update the deployment contract tests to cover the verify-deployed-release smoke check instead.
2026-09-08 16:47:39 +02:00
openhands
25f4d74209
feat(ci): switch Cloudflare bypass from FlareSolverr to Byparr
CI / check (push) Successful in 3m59s
CI / deploy (push) Successful in 2m13s
2026-09-08 16:02:12 +02:00
openhands
fabd160250
fix(ci): bound Docker build cache with BuildKit cache mounts
...
CI / check (push) Failing after 2m48s
CI / deploy (push) Skipped
- Move the pnpm store, apk and .next caches into --mount=type=cache so
dependencies are shared across builds instead of duplicated in fresh
image layers (was the source of unbounded disk growth).
- Replace the deprecated --keep-storage prune flag in ci-deploy.sh with
the working --max-used-space=4g (buildx v0.37 renamed the flag). The
deprecated flag silently did nothing, so the BuildKit cache kept
growing unbounded (was 15.86GB); it is now capped at 4GB after every
deploy.
2026-09-08 15:39:13 +02:00
Simo
c4496e710b
feat(docker): prepare portable images with runtime hotel configuration
CI / check (push) Successful in 1m6s
CI / deploy (push) Successful in 1m23s
2026-09-07 22:37:53 +02:00