Andras Bacsai
13172849e1
Merge remote-tracking branch 'origin/next' into api-sensitive-data-scrubber
2026-07-02 15:57:43 +02:00
Andras Bacsai
6871160623
fix(api): gate sensitive storage and GitHub fields
...
Expose GitHub app secrets and file storage content only when the request has sensitive read access. Hide LocalFileVolume content by default and resolve application UUIDs from route parameters.
2026-07-02 15:50:43 +02:00
Andras Bacsai and GitHub
438eeefa73
feat(api): add REST endpoints for destinations ( #10405 )
2026-07-02 15:34:30 +02:00
Andras Bacsai
70021c8d5e
fix(api): handle destination create races as conflicts
2026-07-02 15:33:01 +02:00
Andras Bacsai and GitHub
ae839198d6
feat(mcp): add per-team server toggle ( #10771 )
2026-07-02 15:19:07 +02:00
Andras Bacsai
88d5aff018
Merge remote-tracking branch 'origin/next' into team-level-mcp-enablement
2026-07-02 15:15:11 +02:00
Andras Bacsai
4ef884e1ac
Merge remote-tracking branch 'origin/next' into feat/api-destinations
2026-07-02 15:14:13 +02:00
Andras Bacsai and GitHub
5b1ac432c7
Improve S3 storage handling ( #10832 )
2026-07-02 15:07:00 +02:00
Andras Bacsai
20b5b90cf9
Merge remote-tracking branch 'origin/next' into improve-s3-storage-handling
2026-07-02 15:06:11 +02:00
Andras Bacsai
78d9244caa
fix: improve s3 storage handling
2026-07-02 15:05:05 +02:00
Andras Bacsai and GitHub
bed058b826
Improve outbound URL validation ( #10833 )
2026-07-02 15:02:37 +02:00
Andras Bacsai and GitHub
558520ce75
Improve storage mount path handling ( #10831 )
2026-07-02 15:01:33 +02:00
Andras Bacsai
a06c1a7bf5
Improve storage mount path handling
2026-07-02 14:54:38 +02:00
Andras Bacsai
c7f014017b
Improve outbound URL validation
2026-07-02 14:46:46 +02:00
Andras Bacsai and GitHub
39ae16de42
Improve team resource route handling ( #10829 )
2026-07-02 14:34:27 +02:00
Andras Bacsai
a121386ab4
Merge branch 'next' into improve-resource-route-handling
2026-07-02 13:25:47 +02:00
Andras Bacsai
fb2d477e48
fix: improve team resource route handling
2026-07-02 13:05:27 +02:00
Andras Bacsai
74f4d04f53
fix(backups): default S3 storage for backup schedules
...
Show the S3 storage selector even when S3 backups are disabled, save
storage changes immediately, and improve responsive confirmation buttons.
2026-07-02 12:47:54 +02:00
Andras Bacsai
76d429fb74
fix(sidebar): center unread badge in settings menu
2026-07-02 12:35:28 +02:00
Andras Bacsai
22b31f5671
fix(backups): require valid S3 storage selection
...
Preserve S3 backups when a single valid storage is available, require
explicit selection when multiple storages exist, and disable S3 when none
are available.
Make backup action controls responsive on narrow screens.
2026-07-01 11:14:20 +02:00
Andras Bacsai
b93a91cc00
docs(security): document deployment command trust boundary
2026-06-30 15:48:22 +02:00
Andras Bacsai
78374b566a
fix members smtp pw update
2026-06-30 15:29:19 +02:00
Andras Bacsai and GitHub
63d6d835a9
Align resource creation permissions ( #10799 )
2026-06-29 15:59:46 +02:00
Andras Bacsai
29445bf177
fix: align resource creation permissions
2026-06-29 15:57:17 +02:00
Andras Bacsai and GitHub
f2d11d9300
fix(railpack): interpolate build-time env variables by sourcing build… ( #10768 )
2026-06-29 11:08:19 +02:00
Andras Bacsai and GitHub
9f36a8df31
Harden database backup imports ( #10796 )
2026-06-29 10:36:31 +02:00
Andras Bacsai
7d65a4b496
Merge remote-tracking branch 'origin/next' into harden-database-import-files
2026-06-29 10:35:35 +02:00
Andras Bacsai and GitHub
f4c863bc34
fix(service): correct Convex origin env vars and expose HTTP actions port ( #10646 )
2026-06-29 10:27:55 +02:00
Andras Bacsai and GitHub
0194a6f104
feat(service): add Inngest one-click service template ( #10612 )
2026-06-29 10:27:37 +02:00
Andras Bacsai and GitHub
84bf96ce76
chore(service): gitea-runner patch version bump ( #10566 )
2026-06-29 10:27:20 +02:00
Andras Bacsai
2d63d51237
fix: harden database backup imports
2026-06-29 10:27:01 +02:00
Andras Bacsai
9a64b2ea0a
Merge remote-tracking branch 'origin/next' into fix/railpack-buildtime-env-interpolation
2026-06-29 10:20:07 +02:00
Andras Bacsai
2dc34f61ff
fix(railpack): create empty build-time env file
2026-06-29 10:19:22 +02:00
Andras Bacsai and GitHub
fe9b43be7c
fix(deploy): preserve private key command metadata ( #10795 )
2026-06-29 10:17:57 +02:00
Andras Bacsai
a630532308
fix(deploy): preserve deploy key command metadata
2026-06-29 10:17:09 +02:00
Andras Bacsai
3729b5c074
improve github webhook
2026-06-28 15:25:58 +02:00
Andras Bacsai
1a5b8d3612
fix(deploy): skip logging deploy key commands
2026-06-28 13:15:18 +02:00
Andras Bacsai and GitHub
dcb235f831
Validate environment variable keys ( #10773 )
2026-06-25 18:34:59 +02:00
Andras Bacsai
87d4744390
Validate environment variable keys
2026-06-25 18:19:58 +02:00
Andras Bacsai
bef94a9ce2
feat(mcp): add per-team server toggle
2026-06-25 11:42:19 +02:00
Aditya Tripathi
623bf89543
fix(railpack): interpolate build-time env variables by sourcing build-time .env
...
Railpack builds forwarded build-time variables inline as `env 'KEY=VALUE'`,
which single-quotes each value and prevents shell interpolation. References
like BETTER_AUTH_URL=$COOLIFY_URL reached the build as the literal string
"$COOLIFY_URL" instead of the resolved URL, breaking builds that validate
their env (e.g. SvelteKit/better-auth).
Wrap the railpack `docker buildx build` invocation with the same
wrap_build_command_with_env_export() helper used by the Dockerfile and
Nixpacks build paths, sourcing the build-time .env file (which writes
COOLIFY_* first and double-quotes normal vars to allow $VAR expansion).
Only buildpack control variables (NIXPACKS_/RAILPACK_), excluded from that
file and never needing interpolation, remain inline. Secret flags are
unchanged and read the interpolated values from the exported environment.
Fixes #10736
2026-06-24 20:11:46 +00:00
Andras Bacsai and GitHub
3f0a0f7a0d
chore(ci): gate docs reminder comments on "Waiting for Docs PR" label ( #10659 )
2026-06-23 17:24:09 +02:00
Andras Bacsai and GitHub
f87cacc3f0
chore(deps): bump esbuild, laravel-vite-plugin and vite ( #10665 )
2026-06-23 17:23:25 +02:00
Andras Bacsai and GitHub
75791339d0
chore(deps): bump symfony/routing from 7.4.12 to 7.4.13 ( #10680 )
2026-06-23 17:23:00 +02:00
Andras Bacsai and GitHub
f9b16b4158
chore(deps): bump symfony/http-foundation from 7.4.8 to 7.4.13 ( #10683 )
2026-06-23 17:22:40 +02:00
Andras Bacsai and GitHub
9b6a9c6007
chore(deps): bump phpseclib/phpseclib from 3.0.52 to 3.0.54 ( #10710 )
2026-06-23 17:22:16 +02:00
Andras Bacsai and GitHub
fd9293887e
chore(deps): bump laravel/framework from 12.60.2 to 12.61.1 ( #10711 )
2026-06-23 17:21:52 +02:00
Andras Bacsai and GitHub
ae817a53fa
chore(deps): bump guzzlehttp/guzzle from 7.10.3 to 7.12.1 ( #10738 )
2026-06-23 17:21:27 +02:00
Andras Bacsai and GitHub
376d9ae86b
chore(deps): bump guzzlehttp/psr7 from 2.10.1 to 2.12.1 ( #10739 )
2026-06-23 17:21:06 +02:00
dependabot[bot] and GitHub
b3d4446d44
chore(deps): bump guzzlehttp/psr7 from 2.10.1 to 2.12.1
...
Bumps [guzzlehttp/psr7](https://github.com/guzzle/psr7 ) from 2.10.1 to 2.12.1.
- [Release notes](https://github.com/guzzle/psr7/releases )
- [Changelog](https://github.com/guzzle/psr7/blob/2.12/CHANGELOG.md )
- [Commits](https://github.com/guzzle/psr7/compare/2.10.1...2.12.1 )
---
updated-dependencies:
- dependency-name: guzzlehttp/psr7
dependency-version: 2.12.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-22 17:48:00 +00:00