Mauricio Siu
98af5a2f07
fix(ci): create release tags on the pushed commit instead of default branch
...
(cherry picked from commit 472ebed06c )
[skip ci]
2026-08-06 00:43:52 -06:00
Mauricio Siu
5ed94954e6
Merge pull request #4972 from Dokploy/fix/domain-single-label-hostname
...
fix(domain): allow single-label hostnames without a TLD
(cherry picked from commit 75448f358e )
[skip ci]
2026-08-06 06:33:27 +00:00
Mauricio Siu
4e675d6f3f
Merge pull request #4978 from Dokploy/hotfix/v0.29.14
...
Hotfix v0.29.14: backport 20 bug fixes
2026-08-06 00:00:20 -06:00
Mauricio Siu
57fae73853
Update packages/server/src/utils/schedules/utils.ts
...
Co-authored-by: greptile-apps[bot] <165735046+greptile-apps[bot]@users.noreply.github.com>
2026-08-05 23:54:32 -06:00
Mauricio Siu
dd542994a4
chore: release v0.29.14
2026-08-05 23:49:59 -06:00
Narciso E. Núñez Arias
bcf97f92ab
Merge pull request #4772 from rifatdinc/fix-watch-paths-added-removed-files
...
fix(webhook): include added and removed files in watchPaths validation
(cherry picked from commit 3f98208f03 )
2026-08-05 23:48:13 -06:00
Mauricio Siu
e19d7bbf0e
Merge pull request #4971 from Dokploy/fix/restore-dialog-width
...
fix(ui): widen restore backup dialog to match other backup dialogs
(cherry picked from commit 3495fc89bf )
2026-08-05 23:48:12 -06:00
Mauricio Siu
3e4ed0c299
Merge pull request #4966 from Dokploy/fix/requests-hostname-filter-crash
...
fix(requests): guard RequestHost before filtering to avoid crash on malformed logs
(cherry picked from commit a0162ab566 )
2026-08-05 23:48:05 -06:00
Narciso E. Núñez Arias
112b2c8358
Merge pull request #4923 from dmtrTm/fix/rollback-environment-variables
...
fix: resolve environment variables on application rollback
(cherry picked from commit 46c87a22b0 )
2026-08-05 23:48:04 -06:00
Mauricio Siu
b7fdbd4704
Merge pull request #4557 from rnkp755/fix/env-update-issue
...
fix: invalidate railpack build cache when env changes
(cherry picked from commit a1230098c9 )
2026-08-05 23:48:04 -06:00
Mauricio Siu
13b897c01d
Merge pull request #4959 from Dokploy/fix/cleanup-preview-deployments-on-app-delete
...
fix(application): remove preview deployments when deleting an application
(cherry picked from commit 056b6983db )
2026-08-05 23:48:04 -06:00
Mauricio Siu
83008205b9
Merge pull request #4955 from Dokploy/fix/schedule-run-manually-deployment-metadata
...
fix(schedule): return deployment metadata from runManually and fail early on missing container
(cherry picked from commit 11e93dde38 )
2026-08-05 23:48:03 -06:00
Mauricio Siu
0f0102ff2d
Merge pull request #4933 from CyrilBIENNE/fix/preview-deployment-github-credentials
...
fix(preview-deployment): refetch github provider before authenticating
(cherry picked from commit a058d1f5c7 )
2026-08-05 23:48:03 -06:00
Mauricio Siu
cbe78950cc
Merge pull request #4954 from Dokploy/fix/error-page-status-code
...
fix(ui): show real status code on error page
(cherry picked from commit 3835a6fe68 )
2026-08-05 23:48:03 -06:00
Mauricio Siu
49ee74c89d
Merge pull request #4953 from Dokploy/fix/dropdown-dialog-window-blur
...
fix(ui): keep dropdown menus open on window blur
(cherry picked from commit 51cb7d2287 )
2026-08-05 23:48:02 -06:00
Mauricio Siu
e88d13f67b
Merge pull request #4947 from azizbecha/fix/4945-deployment-delete-loading
...
fix(ui): scope deployment delete loading
(cherry picked from commit 2be9e1e3df )
2026-08-05 23:48:02 -06:00
Mauricio Siu
2f89981597
Merge pull request #4948 from azizbecha/fix/collapsed-sidebar-avatar
...
fix(ui): prevent collapsed avatar clipping
(cherry picked from commit 3b0bdd8f74 )
2026-08-05 23:48:02 -06:00
Mauricio Siu
c7a96ed82c
Merge pull request #4782 from imrja8/fix/watchpath-badge-removal
...
fix(ui): resolve unclickable watch path removal button
(cherry picked from commit 018e56a7b4 )
2026-08-05 23:48:01 -06:00
Mauricio Siu
d4e087e128
Merge pull request #4937 from Dokploy/fix/persist-trigger-type-provider-forms
...
fix(ui): persist trigger type selection in GitHub provider forms
(cherry picked from commit bb73c6e6dd )
2026-08-05 23:48:01 -06:00
Mauricio Siu
7f41b098f9
Merge pull request #4911 from AbiRaditya/fix/cloudflare-badge-tooltip-error-title
...
fix(domains): don't render CDN info message as an error in DNS tooltip
(cherry picked from commit 5df820a740 )
2026-08-05 23:48:01 -06:00
Mauricio Siu
43229c89da
Merge pull request #4931 from Dokploy/fix/postgres-100-arg-limit-finders
...
fix: avoid postgres 100-argument limit in schedule, volume backup and port queries
(cherry picked from commit deebf0f107 )
2026-08-05 23:48:00 -06:00
Mauricio Siu
c6607f3a19
Merge pull request #4924 from dmtrTm/fix/rollback-query-arg-limit
...
fix: avoid postgres 100-argument limit in findRollbackById
(cherry picked from commit 069939e8f9 )
2026-08-05 23:48:00 -06:00
Mauricio Siu
6e84f39a9f
Merge pull request #4929 from Dokploy/fix/remove-buttons-not-persisting
...
fix(ui): make interactive icons inside badges clickable again
(cherry picked from commit 425d478a0b )
2026-08-05 23:47:59 -06:00
Mauricio Siu
b024c9c2fd
Merge pull request #4626 from veksen/veksen/textarea-resets-while-editing
...
fix: prevent environment form from resetting while editing
(cherry picked from commit 73e4fdd757 )
2026-08-05 23:47:59 -06:00
Mauricio Siu
982f4d70f7
Merge pull request #4890 from SteadEXE/canary
...
fix(ui): add cursor pointer style for buttons
(cherry picked from commit 0fc75840d2 )
2026-08-05 23:47:59 -06:00
Mauricio Siu
a49615038f
Merge pull request #4883 from Dokploy/canary
...
Build Docker images / build-and-push-cloud-image (push) Has been cancelled
Build Docker images / build-and-push-schedule-image (push) Has been cancelled
Build Docker images / build-and-push-server-image (push) Has been cancelled
Dokploy Docker Build / docker-amd (push) Has been cancelled
Dokploy Docker Build / docker-arm (push) Has been cancelled
Dokploy Monitoring Build / docker-amd (push) Has been cancelled
Dokploy Monitoring Build / docker-arm (push) Has been cancelled
Generate and Sync OpenAPI / Generate OpenAPI and commit to Dokploy repo (push) Has been cancelled
Dokploy Docker Build / combine-manifests (push) Has been cancelled
Dokploy Docker Build / generate-release (push) Has been cancelled
Dokploy Docker Build / sync-version (push) Has been cancelled
Dokploy Monitoring Build / combine-manifests (push) Has been cancelled
🚀 Release v0.29.13
2026-07-21 10:00:57 -06:00
Mauricio Siu
8b868c66d6
Merge pull request #4882 from Dokploy/feat/custom-ai-providers
...
Auto PR to main when version changes / create-pr (push) Waiting to run
Build Docker images / build-and-push-cloud-image (push) Waiting to run
Build Docker images / build-and-push-schedule-image (push) Waiting to run
Build Docker images / build-and-push-server-image (push) Waiting to run
Dokploy Docker Build / docker-amd (push) Waiting to run
Dokploy Docker Build / docker-arm (push) Waiting to run
Dokploy Docker Build / combine-manifests (push) Blocked by required conditions
Dokploy Docker Build / generate-release (push) Blocked by required conditions
Dokploy Docker Build / sync-version (push) Blocked by required conditions
autofix.ci / format (push) Waiting to run
Dokploy Monitoring Build / docker-amd (push) Waiting to run
Dokploy Monitoring Build / docker-arm (push) Waiting to run
Dokploy Monitoring Build / combine-manifests (push) Blocked by required conditions
Generate and Sync OpenAPI / Generate OpenAPI and commit to Dokploy repo (push) Has been cancelled
feat(ai): allow organizations to define custom AI provider presets
2026-07-21 03:23:32 -06:00
Mauricio Siu
366e44b75a
fix(ai): only show Custom Presets button to owner/admin roles
2026-07-21 03:22:48 -06:00
Mauricio Siu
cb2db0d30a
Bump version from v0.29.12 to v0.29.13
2026-07-21 03:22:19 -06:00
Mauricio Siu
7ba3853bab
feat(ai): allow organizations to define custom AI provider presets
...
Organization admins can define their own AI providers (name + API URL)
from the AI settings section. When at least one custom provider is
defined, it replaces the built-in provider list in the Add AI form,
the API URL is auto-filled and locked, and the backend rejects any
configuration whose URL is not in the allowed list.
2026-07-21 03:19:06 -06:00
Mauricio Siu
8def9e933e
Merge pull request #4880 from Dokploy/fix/sso-initial-credentials-linking
...
fix(auth): enable email verification for SSO and user creation
2026-07-21 02:50:51 -06:00
Mauricio Siu
e9b51667e2
fix(auth): enable email verification for SSO and user creation
...
Updated the SSO configuration to trust verified emails and modified user creation to set emailVerified to true by default. This enhances security and ensures that user email verification is properly handled.
2026-07-21 02:50:22 -06:00
Mauricio Siu
25370cac30
Merge pull request #4847 from ANSUJKMEHER/fix-4666-action-terminology
...
fix: rename compose "Reload" action to "Rebuild"
2026-07-21 00:52:29 -06:00
Mauricio Siu
52c7db1f66
Merge pull request #4877 from Dokploy/fix/2fa-invalid-code-error-message
...
fix(2fa): show correct error message for invalid TOTP code
2026-07-21 00:52:04 -06:00
Mauricio Siu
6d65a36aac
fix(2fa): show correct error for invalid TOTP code
...
The verify-totp handler checked for the error code
INVALID_TWO_FACTOR_AUTHENTICATION, which no longer exists in
better-auth 1.6.23 (the two-factor plugin now returns INVALID_CODE).
As a result, entering a wrong TOTP code fell through to the generic
catch and showed "Error verifying 2FA code / Unknown error" instead of
a clear "Invalid verification code" message.
Match the current better-auth error code so the specific, actionable
message is shown.
2026-07-20 18:20:56 -06:00
Mauricio Siu
cbec72ed80
Merge pull request #4876 from Dokploy/fix/collapsed-sidebar-org-menu-width
...
Auto PR to main when version changes / create-pr (push) Waiting to run
Build Docker images / build-and-push-cloud-image (push) Waiting to run
Build Docker images / build-and-push-schedule-image (push) Waiting to run
Build Docker images / build-and-push-server-image (push) Waiting to run
Dokploy Docker Build / docker-amd (push) Waiting to run
Dokploy Docker Build / docker-arm (push) Waiting to run
Dokploy Docker Build / combine-manifests (push) Blocked by required conditions
Dokploy Docker Build / generate-release (push) Blocked by required conditions
Dokploy Docker Build / sync-version (push) Blocked by required conditions
autofix.ci / format (push) Waiting to run
Dokploy Monitoring Build / docker-amd (push) Waiting to run
Dokploy Monitoring Build / docker-arm (push) Waiting to run
Dokploy Monitoring Build / combine-manifests (push) Blocked by required conditions
Generate and Sync OpenAPI / Generate OpenAPI and commit to Dokploy repo (push) Waiting to run
fix(ui): organization menu clipped when sidebar is collapsed
2026-07-20 18:04:24 -06:00
Mauricio Siu
3b102fac56
fix(ui): organization menu clipped when sidebar is collapsed
...
The organization switcher's DropdownMenuContent inherited its width from
the collapsed trigger (~40px) via the base primitive's
w-(--radix-dropdown-menu-trigger-width), clamping the menu to the
min-w-32 (128px) floor. This cut off the org name and action buttons in
icon mode.
Set an explicit w-64 so the menu fits its content regardless of the
trigger width, matching the pattern already used by the notification
dropdown in the same file.
Fixes #4840
2026-07-20 18:03:28 -06:00
Mauricio Siu
b2ade17487
Merge pull request #4874 from Dokploy/fix/idor-server-remove
...
fix(security): cross-org authorization bypass in server.remove
2026-07-20 17:40:18 -06:00
Mauricio Siu
ffe62bca0e
Merge pull request #4875 from Dokploy/fix/cmdi-registry-test-login
...
fix(security): command injection in registry.testRegistry / testRegistryById
2026-07-20 17:40:00 -06:00
Mauricio Siu
d3f522b7a6
fix(security): command injection in registry.testRegistry/testRegistryById remote path
...
The remote (execAsyncRemote) path built `echo ${password} | docker ${args.join(" ")}`
with the password, registryUrl and username interpolated unescaped, so a password
like `pw; whoami` ran arbitrary commands as root on the target server. Reuse
safeDockerLoginCommand (already used by create/update), which shell-escapes each
field and feeds the password via --password-stdin. The local argv+stdin path was
already safe.
2026-07-20 17:17:45 -06:00
Mauricio Siu
4aee66b2d1
fix(security): enforce organization ownership on server.remove
...
server.remove deleted a server (and its deployment rows) by caller-supplied
serverId without checking it belongs to the active organization, unlike server.one
and server.update. An owner/admin of org A could delete org B's server registration.
Resolve and compare the server's organizationId before the active-services guard,
so cross-org callers are rejected without leaking existence.
2026-07-20 17:14:35 -06:00
Mauricio Siu
d02f34f9d4
Merge pull request #4873 from Dokploy/fix/cmdi-quote-sweep
...
fix(security): escape user-controlled values across command-injection sinks (quote sweep)
2026-07-20 17:05:16 -06:00
Mauricio Siu
92310ddb14
fix(security): base64-encode remote traefik YAML and escape config paths
...
writeTraefikConfigRemote piped the stringified YAML through echo '...' where a
single quote in any label/host/serviceName broke out (GHSA-478p). Encode it as
base64 like the other writers, and quote() every configPath used in remote
rm/cat/redirect commands (including the input.path-derived ones).
2026-07-20 16:49:48 -06:00
Mauricio Siu
16b5b7293f
fix(security): escape file paths and remote schedule command in shell invocations
...
quote() the user-derived paths that reach the shell in file mounts
(mount.ts, docker getCreateFileCommand), patch repo read (repoPath/filePath),
certificate create/remove (certificatePath), and the remote scheduled command
(containerId/shellType/command/logPath), so $(), backticks and traversal in
these fields can no longer inject commands.
2026-07-20 16:48:43 -06:00
Mauricio Siu
d629faebc6
fix(security): validate volumeName and escape volume-backup file names
...
Add VOLUME_NAME_REGEX (Docker volume-name format) and enforce it on volumeName in
create/update/runManually — a legit volume name never contains shell metacharacters,
so this blocks injection across every docker run/rm/rclone sink at once. Escape the
user-supplied backupFileName and the mount volumeName in database rebuild with quote().
2026-07-20 16:45:55 -06:00
Mauricio Siu
eeb6e7b8ea
fix(security): escape S3/rclone args and restore paths to prevent command injection
...
Wrap S3 credential flags (getS3Credentials + destination.testConnection), the
listBackupFiles search path, and every restore backupPath/backupFile with
shell-quote's quote() so $(), backticks, quotes and spaces in destination
fields or backupFile can no longer break out of the rclone shell commands.
2026-07-20 16:11:16 -06:00
Mauricio Siu
9b078e0b4c
Merge pull request #4871 from Dokploy/refactor/inline-quote-git-providers
...
refactor(providers): inline quote() in git clone commands, drop shellWord helper
2026-07-20 16:00:15 -06:00
Mauricio Siu
ce4be79b3d
refactor(providers): inline quote() in git clone commands, drop shellWord helper
...
Use shell-quote's quote([...]) directly at each git-provider clone call site
instead of the one-line shellWord wrapper, and remove the now-unused helper.
Behavior is identical (quote([String(v ?? '')])).
2026-07-20 15:58:16 -06:00
Mauricio Siu
8c2e91a5e6
Merge pull request #4870 from Dokploy/fix/github-setup-callback-authz
...
fix(security): missing authorization on GitHub App setup callback (unauth cross-org write)
2026-07-20 15:40:46 -06:00
Mauricio Siu
0514363062
chore: drop explanatory comments in github setup handler
2026-07-20 15:37:17 -06:00