-
v0.13.0
StableAll checks were successfulCD / Smoke tests against Test (push) Successful in 1m25sCD / Promote to Int (push) Successful in 12sRelease / Build release images and notes (push) Successful in 3m31sRelease / Release-candidate operations QA (push) Successful in 46sCI / Build container images (push) Has been skippedProd deploy / Deploy the released images to Prod (push) Successful in 58sCI / Import/export fidelity gate (push) Successful in 59sCI / Lint, typecheck, test (push) Successful in 6m40sCI / Auth e2e pack (push) Successful in 8m21sRestore drill / Restore the latest backup into a scratch stack (push) Successful in 1m18sCI / Build container images (pull_request) Successful in 2m53sCI / Auth e2e pack (pull_request) Successful in 8m34sCI / Lint, typecheck, test (pull_request) Successful in 6m22sCI / Import/export fidelity gate (pull_request) Successful in 59sCD / Build and push images (push) Successful in 19sCD / Deploy to Test (push) Successful in 14sreleased this
2026-07-31 23:03:03 +02:00 | 37 commits to main since this releaseChanges since v0.12.0
- #296: remove the unsubscribe-token dual-verify window early
- #232: plugin allowlist with SHA-256 hash pinning
- ADRs 0019-0027: accepted after explicit operator review (2026-07-31)
- #246: mode enforced — reject profile-violating configuration writes
- #245: mode hidden — hide profile-violating options, mark the hiding
- #244: mode marked — flag profile-violating configuration in the UI
- #243: VS_NFD_MODE and the machine-readable hardening-profile catalog
- #221: offline update path incl. migrations, rehearsed with rollback
- #220: protocol of the isolated deployment run
- #288: reset schema before pg_restore — partitioned tables broke --clean
- #219: verified reproducible build without network access
- #218: mirror procedure into an internal registry
- #217: map IdP groups and roles onto the permission model
- #216: hard AUTH_LOCAL_ENABLED switch over every local credential flow
- #215: trusted reverse-proxy header / mTLS client-certificate path
- #214: OIDC Authorization Code with PKCE, Keycloak as reference IdP
- #225: read-trail master switch and written purpose limitation
- #224: read-trail storage — partitioning, retention, admin query path
- #223: dedup window for the read trail
- #222: read-access trail for classified pages
- #230: IT-Grundschutz mapping for APP.3.1 and CON.11.1
- #231: residual-risk list
- #227: hardening guide with the VS-NfD reference configuration
- #229: operations manual (install, update, backup/restore, deletion, roles)
- #228: security documentation (architecture, data flows, network plan)
- #213: warn on uploads to classified pages; instance policy can block
- #212: mark attachment downloads by filename prefix and companion file
- #211: classification through feeds, public API, search and the no-JS shell
- #210: mark the Markdown ZIP export with frontmatter, imprint and manifest
- #209: pandoc reference documents carry the VS-NfD marking for DOCX/ODT
- #208: VS-NfD marking in the Gotenberg per-page header and footer
- #207: print stylesheet with the classification on every printed sheet
- #206: show the VS-NfD marking in web view header and footer
- #205: classification inherits down the tree; lowering is a guarded, audited act
- #204: classification as first-class page metadata (ADR 0022)
- #203: pin all third-party deploy images by digest
- #201: stable audit event catalogue for syslog/SIEM export
- #200: hard instance-wide plugins.enabled kill switch
- #199: SHA-256 integrity hashes for attachments
- #202: SBOM and license report in CI
- #236: also pin the node helper images in workflows
- #236: pin the Node version
- #235: keep page_links rows pointing at purged pages — recorded decision
- #234: retention for mail_outbox
- #233: prune conversion job payloads for every job kind
- #198: CI fence — no tracked .env or secret material, example is authoritative
- #197: security response headers and an explicitly restrictive CORS policy
- #196: audit-trail retention job
- #195: trashed content leaves the search index itself
- adjust the maintenance-job count fence: 6 jobs with the orphan sweep
- #194: orphan-file sweep, drop the unused Attachment.deletedAt
- #193: pond purge — retention job and manual Site-Admin endpoint
- #192: deploy-level backup target allowlist
- #191: feeds.enabled instance switch, feed-token log masking
- #190: configurable session lifetime with a server-side idle timeout
- fix flaky tampered-token test: flip a significant signature character
- #189: make the CSRF origin check fail closed
- #188: purpose-bound token keys via HKDF, jose replaces the homegrown JWT
- #226: add the §52 VSA delimitation statement
- docs: VS-NfD readiness planning (ist-aufnahme, plan, ADRs 0019-0026, issue drafts)
⚠️ migration — this release applies database migrations automatically at api start. Downgrade window: one minor release (docs/self-hosting).
Downloads