❌

Lees weergave

v2.10.2

Note

This release adds performance improvements across authentication, Docker calls, scheduled scans, project loading, and CVE serving. It also fixes container shell handling, scheduler overlap, image digest display, authentication flows, agent reconnection, and several UI and integration issues.

Fixes

  • Surface container shell close reasons and disable WebSocket compression β€” 30e1bb590a34d9aeded744a71d39e8709b3b7b33, b9b8c813f6d3735770f2bc1bf5c80b4967eb7e26 / #3814 (@kmendell)
  • Skip overlapping scheduled cron job runs β€” 51cf6bb6a1049a01596a5933ddb2508de6938dea, 5232b4d04bfb482ed9d3ec869f30ec2fee03ca30 / #3815 (@kmendell)
  • Refactor image digest inspection logic β€” d256fc2787efd18341d84e63e59e7cd38300e99d / #3826 (@jdrouhard)
  • Keep the first-login password dialog open and clear its flag after an admin password change β€” 6f90da73f3606e42e58a0f00c98208f5817c27c9 / #3831 (@kmendell)
  • Allow the frontend to recover from stale chunks after a redeploy β€” 8c294a7316f3616a704edfec366f4adccd91a577 (@kmendell)
  • Keep edge agents on gRPC after a manager restart β€” 4febf6d0dcf64997b53cba7743d082b4c7550979 (@kmendell)
  • Show digest-pinned image references β€” 5c0592994278ac9ab4600966dcdb460ecbef857b / #3836 (@kmendell)
  • Hide passkey login when no credentials are registered β€” b7b568e1a6911bf1b8369de129af792fb0f23e4e (@kmendell)
  • Honor SSH usernames in Git repository URLs β€” 837fe10c92ddbb2391d7b13475d475a68f7fca2c (@kmendell)
  • Support host memory accounting for Docker inside LXC β€” 416e93a4be282a5d26025f9fd00f3ae56c70bb71 / #3846 (@kmendell)
  • Load project digests automatically when entering the Updates page β€” 8d5eaeb9dda0072736eb67272de4d7d781d7472b (@kmendell)
  • Sort environments by name while placing the current selection first β€” 4e0f1dcfc074a4562b59ef03ee49dabbd68f40f5 (@kmendell)
  • Rate-limit webhook triggers by token instead of client IP β€” de1e978810a490fd7930a634bd4df765a50f65b2 / #3742 (@ohOgil)
  • Run backups in an activity instead of locking the UI β€” dd16fd942afaed4db4d63ad4fa787bce20251f8d / #3847 (@kmendell)

Performance

  • Serve cached authentication token state β€” 65fcfa637919992c81b373396265455a1f08ae3c, 5e8ecabd4f0c2aa3c3011baab6761dc13aabc96f / #3816 (@kmendell)
  • Route Docker daemon calls through singleflight callers β€” 64c2500b669f343451f2541a045b578e10ee172b / #3818 (@kmendell)
  • Share one stream producer across all clients β€” db9878d01dccfed0406cee7c5e573a7f2c8637fe / #3819 (@kmendell)
  • Look up Copa targets by digest instead of issuing database queries β€” ddcd50530759ed0b31d2f717e7d82a213bfd655d / #3821 (@kmendell)
  • Validate the projects metadata cache by file modification time and resolve entries in parallel β€” 0b44e8dd5e16131015e18c70601c79b1c2cad9a9 / #3823 (@kmendell)
  • Serve the CVE list from a normalized table β€” 31a9896dfb052ece34d7ba4c14d8347b9ad8a8b5 / #3825 (@kmendell)
  • Bound scheduled scans, skip unchanged images, and avoid remounting during navigation β€” 8299a56c5430f9a04ee132b15f58a9e46f810dc0 / #3829 (@kmendell)
  • Dispatch notification providers concurrently β€” 767992dc34a4b98d35fb220425bf51ea9b123961 / #3820 (@kmendell)

Improvements and refactoring

  • Allow selecting registries for Arcane Tools and Trivy databases β€” b85caceeef0ba5dd094ce1fcb82805acfd2a6445 / #3830 (@kmendell)
  • Clean up duplicate HTTP client logic β€” 8a74c1b729e6bd0b02e1bcf17a824cc445cb2eb3 (@kmendell)

Dependency updates

  • Bump react-email from 6.9.2 to 6.9.3 β€” 0cbb2590792d935ff2c7a20468e91edc3b318304 (@dependabot[bot]); 8dd0210aec7303fa506cdf77e235804961107a7d / #3806 (@kmendell)
  • Update the tanstack-table group with two updates β€” f58bc47404cbc61ca0c2a62a4d48436e5b2b5688 (@dependabot[bot]); 0a7ea50401c95aff42f90b94172b0c2f42ece4cb / #3799 (@kmendell)
  • Bump ky from 2.0.2 to 2.1.0 β€” 5700fb7f52a95e3e21ab0fce8d5a7e453cb0201c (@dependabot[bot]); ab3eaae5751c0abe8ae326b35b565b43f2ed678f / #3802 (@kmendell)
  • Bump svelte from 5.56.10 to 5.57.0 β€” 3db4f4a591fd43aff54d5d9ca679780f6d9c5e35 (@dependabot[bot]); efb72f212b9795ecccfcf3b792a0e76dedebb1c6 / #3808 (@kmendell)
  • Bump @tanstack/svelte-query from 6.1.43 to 6.1.48 β€” 917e6c267748da315f93855dadbea3444466f12c (@dependabot[bot]); 242744189b8e1065be494d5cd25c8a97ecb511c0 / #3807 (@kmendell)
  • Bump pnpm to v12.2.1 β€” 7d33837fd5a2d8bfd9617dabe7347f1ea06ca1c2 (@kmendell)
  • Bump @xyflow/svelte from 1.6.3 to 1.6.5 β€” 1829e66194ca404bd8ff4b211e693a7d149ac184 / #3810 (@dependabot[bot])
  • Bump github.com/nicholas-fedor/shoutrrr from 0.18.0 to 0.19.0 in /backend β€” 343dc2020f10c610f81bb5834bcc5b858377afbe / #3840 (@dependabot[bot])
  • Bump golang.org/x/crypto from 0.55.0 to 0.56.0 in /backend β€” 37226ae35749563489551c840ca2b1620e07e3e6 / #3844 (@dependabot[bot])
  • Bump github.com/coreos/go-oidc/v3 from 3.20.0 to 3.21.0 in /backend β€” 504e5b6dda7ea16bdab84eb6b72c1da47e90414d / #3845 (@dependabot[bot])
  • Bump github.com/pressly/goose/v3 from 3.27.3 to 3.28.0 in /backend β€” d6271ea3045682a063b516ea0f1d71fc2f7e4a64 / #3841 (@dependabot[bot])
  • Bump github.com/klauspost/compress from 1.19.2 to 1.20.0 in /backend β€” 71d866fefdd79552afd4db123fd01cbd29199753 / #3843 (@dependabot[bot])
  • Bump github.com/mattn/go-runewidth from 0.0.28 to 0.0.29 in /cli β€” 5137b5dcb4efe2e6107adc7d316af4ec9132f01b / #3838 (@dependabot[bot])

  •  

v2.10.1

Note

This release fixes browser session cookie size issues and missing sidebar usernames.
It also updates the gopsutil and zod dependencies.

Fixes

  • Issue compact browser session cookies instead of the larger ML-DSA access JWT β€” df7c24c85e9d4fa9d380532db928ecc3aa13dc17 (@kmendell); e874390f6b4ca611a4b5f733868cca1e01138aca / #3813 (@kmendell).
  • Fall back to the username when the display name is unset in the sidebar user menu β€” 0c7174f1089079d79535563ac2d54b032ea6914a (@kmendell).

Dependencies

  • Bump github.com/shirou/gopsutil/v4, including 4.26.7 to 4.26.8 β€” c9ad2e6f9f9751764e5608128b7e55abf9349b88 (@dependabot[bot]); dd02c011c575c298dbd3f3167e4ba291edc06c59 / #3798 (@kmendell).
  • Bump zod from 4.4.3 to 4.5.4 β€” d95764cf15a2867e2ac573f8cf6f78654da597d7 / #3812 (@dependabot[bot]).

  •  

v2.10.0

Note

This release adds selective system restores, scheduled volume backups, Convert to Compose, direct image patching, Apple push notifications, and ML-DSA-87 signing for authentication and edge mTLS.
It also improves upgrade reliability, image update discovery, project logs, Swarm access, backup downloads, and UI performance.

Backups and recovery

  • Add selective system restores and harden recovery β€” 874134cfedc2e8ae44e6f0cd7e957e87bc760988 (#3708) (@neurekadev)
  • Add system-managed volume backup scheduling β€” 53a959f93e26193c6c9ac4bb4053555f18e8b2ff (#3737) (@neurekadev)
  • Reduce S3 backup download amplification β€” 538350af6c72d0e6d80164f6aacb3b8dd02cd1bd (#3773) (@kmendell)

Containers, images, and projects

  • Add experimental Convert to Compose for running containers β€” 9aef34e4ea703cbee29d31a4338413018ce54f34 (#3746) (@kmendell)
  • Add direct Copacetic image patching β€” 3617720518f0bdfc4282a7b5844508f3b7da60ec (#3744) (@kmendell)
  • Restrict Copa patches to OS-level issues β€” e95c55326a59a615993113e0ee809df734a40b0a (@kmendell)
  • Store raw Trivy reports in the database and fix patch-target pagination β€” 53e7e82715bfebd9ed0d1a27dc0b777d0bbd68b0 (@kmendell)
  • Honor UI container exclusions during image update discovery β€” b9b2092c0e36d3eaba66335e003b7ecd5e858540 (#3763) (@kmendell)
  • Stop checking Arcane-built local images against registries β€” 8d10b7db2d34aefa44f0f9a684f3b84b2ae355d7 (@kmendell)
  • Query image update information directly instead of caching it per container listing β€” 509c6e81babef8c3ac0b4bf9c418c1d3115c50a8 (@kmendell)
  • Resolve upgrade target images for blank-target self-upgrades β€” 8bbd157a2963874998c481487d132f460cb15b1c (#3772) (@kmendell)
  • Honor COMPOSE_FILE and other predefined environment variables in projects β€” 6e1dbb2d22858014970f3b235b73acea0fc70ad5 (#3709) (@kmendell)
  • Forward registry authentication when deploying Swarm stacks from Git Sync or source edits β€” 1570a1da7a00e20012dcdf3d5496e2d9f39f732f (#3787) (@elfensky)

Reliability and operations

  • Return HTTP 200 from the environment health check β€” 6b46c36a237328fc0728ac8fd02e8bc79a149986 (@kmendell)
  • Write workspace files using the volume’s runtime identity instead of root β€” f4958ae8c8318bd921ef5be4ae9a6436309b0cd5 (#3745) (@kmendell)
  • Match Docker CLI memory accounting for cgroup v1 containers β€” 4c479f1c5b01ae6932e2de2ad91ca79aa6874edc (@kmendell)
  • Purge leftover Git clone scratch directories β€” d57d18f1136c1e518be656615f6e2df01d777e34 (#3771) (@kmendell)
  • Preserve stderr streams and Docker timestamps in project logs β€” cac8a9090baea3b44aa2868d195cd21c3dcf62f0 (#3770) (@kmendell)
  • Allow the Viewer role to browse Swarm resources β€” 3f205dea94fa6d40189cf80eec665e39c5131e60 (#3779) (@kmendell)
  • Trigger agent self-upgrades asynchronously and pass the manager’s resolved target version β€” d857910d9b08f96e7739c679415b18fd192a01b4 (#3786) (@kmendell)
  • Serialize explicit empty values in partial-update DTOs with omitzero β€” 24592561d9154da35d7fecd380e12c50e3c5783a (@kmendell)

Authentication and notifications

  • Add native Apple push notifications for the iOS app β€” 4b1abefec6b9b93ea331e1259e061c6862025a11 (#3783) (@kmendell)
  • Sign and verify sessions, OIDC, passkeys, and edge mTLS with ML-DSA-87 β€” 2993fd316d41fafc110476370870a49b9202969c (#3785) (@kmendell)
  • Accept display names in email notification From addresses β€” 034e7e7efd4e756f0c3145099f24f2afe0bc7596 (#3776) (@ohOgil)

User interface

  • Improve table-scrolling performance across all views β€” 1243d8e0bafdc110b8443ef710d999e5104ce632 (@kmendell)
  • Keep dialog widths within the content area β€” 5e7acb61d3bb6ef4bc60a80266c424f1d40d02c2 (@kmendell)
  • Move frontend files into a more maintainable structure β€” 938882a174322a1bbc6fe50fe926a4c61820797b (@kmendell)

Dependencies

  • Bump github.com/aquasecurity/trivy from 0.69.3 to 0.72.0 in /backend β€” 29784fead298d740fb07db2754d53ff55e3bb9c4 (#3748) (@dependabot[bot])
  • Bump github.com/sirupsen/logrus from 1.10.0 to 1.10.1 in /backend β€” be4220fa2cc44c348177de5c39354b716a517413 (#3753) (@dependabot[bot])
  • Bump github.com/quay/claircore from 1.5.52 to 1.5.53 in /backend β€” 611b5d7ff298ccd51b0675874354282aa117356c (#3747) (@dependabot[bot])
  • Bump github.com/samber/hot from 0.13.0 to 0.13.1 in /backend β€” cecdb777ec0f3487ab442f2bd1a45dc1120f0564 (#3754) (@dependabot[bot])
  • Bump charm.land/bubbles/v2 from 2.2.0 to 2.2.1 in /cli β€” b631dd67c34ef642c3bb177ad3d9df09c0974b0d (#3752) (@dependabot[bot])
  • Bump @tanstack/svelte-query from 6.1.39 to 6.1.43 β€” 55762896904d9453f2c2cbeb26645b6e0f6818a2 (#3761) (@dependabot[bot])
  • Bump github.com/google/go-containerregistry from 0.21.9 to 0.22.0 in /backend β€” 3c0aac7c557ace8a15ffbd60dd6dc4448ec43a93 (#3755) (@dependabot[bot])
  • Bump marked from 18.0.10 to 18.0.11 β€” 201a3ff183a0f07e342398d0b1b12ca3847777a5 (#3759) (@dependabot[bot])

Refactoring

  • Use generics to eliminate redundant logic β€” 671ebef57234c40acba287925c5ee6ac9efdd399 (#3683) (@kmendell)
  • Migrate JWT and JWKS handling to jwx v4 β€” 45b063a074f521f45591f58c7b1d89b4395dc267 (#3790) (@kmendell)

  •  

v2.9.0

Note

This release adds automated S3 backups, standalone container editing, batched container-update notifications, and GitOps redeployment for stopped projects.
It also expands the CLI with commands for vulnerabilities, activities, and webhooks while improving project handling, OIDC support, and API behavior.

Features

  • Add automated S3 backups β€” 555c5dfbac478e7bbe336fff29cfe4d6277b2d6d (#3459) (@affeldt28)
  • Batch container-update notifications β€” 0239f62b45c7b2d485285a54fc54e44b6a0721e8 (#3650) (@wyx1818)
  • Add the ability to edit standalone containers β€” 24894fc7310b747e95d2b5d59e0a5100bb8bf12f (#3646) (@kmendell)
  • Add renaming for unused volumes β€” 1e413ada2f2413fa2a7c97798288b73ddb9d6b6c (#3704) (@neurekadev)
  • Pull and redeploy images after GitOps sync for stopped projects β€” f17e84412ae41dac1945f5b6896bafce8c244bb9 (#3698) (@ohOgil)
  • Add CLI commands for the latest server features and adopt hyphen-free command naming β€” d84511b8d67bef5fe3117832c9173ecc987e38da (@kmendell)
  • Add CLI commands for vulnerabilities, activities, and webhooks with end-to-end coverage β€” f4f9df0e8f1373a9e7fcba145383fcda8b4b3fc2 (@kmendell)

Fixes

  • Ensure stable ordering for page walks without an explicit sort β€” bf783a828ef816acf789851dffb2b8b8ed249450 (#3648) (@kmendell)
  • Percent-decode API path parameters before use β€” c469305cdacf49b80f7f5639f00eef597c1ca102 (#3682) (@kmendell)
  • Show Git-synced project files as read-only instead of hiding them or crashing β€” da21e2694754434d9b6b936834aed44173378ef1 (#3690) (@kmendell)
  • Send the build directive for projects from the backend β€” 53017c67cf91656965d667bf23e80dc0b46bd482 (#3691) (@kmendell)
  • Allow assigning roles to OIDC users and handle username collisions during OIDC login β€” c38c2580fb14f8a8f15f74ef9203bfdb9896c466 (#3692) (@kmendell)
  • Make the update-all dialog scroll correctly with large fleets β€” b7a619b2c7f8f08f05cc78f3db51ac6aa63e9ef4 (@kmendell)
  • Validate cgroup-derived container IDs during self-detection with network_mode: service β€” c24013107eff0adba0813b66b50350a03a487895 (#3710) (@kmendell)
  • Handle updates to discovered Compose projects β€” 275aface140f0d41e67adef402859f8a2a6ba207 (#3711) (@kmendell)

Refactoring

  • Upgrade to Go 1.27.0 β€” b22edb6909c5497f3e72e27d4570551c7fb2fe91 (#3680) (@kmendell)
  • Use native Temporal for time and date parsing β€” 60c2dee13cd9405175b6e0a5d65053724bb005cd (#3714) (@kmendell)
  • Use AI generation for GitHub release notes β€” 2240e8f0c7a49331f3ba7e385d7b793b844fbcaa (#3739) (@kmendell)

Dependency updates

  • Bump @sveltejs/kit from 3.0.0-next.21 to 3.0.0-next.23, then to 3.0.0-next.25 β€” cd8c48b36c926a5342a5b83f373269e4ec4093a1 (#3672), 70475a2cf7ca52f2d017422551ce645e4507aaa4 (#3727) (@dependabot[bot])
  • Bump svelte from 5.56.8 to 5.56.9, then to 5.56.10 β€” d4d83941e2685a2273a6437670d17b71816d5620 (#3666), 1478dd7df710c42161b16f7cb07be79193e7570b (#3724) (@dependabot[bot])
  • Bump svelte-sonner from 1.1.1 to 1.2.1 β€” 39ce639ebe506fb4b825fd08335a98bc55a7efd1 (#3670) (@dependabot[bot])
  • Bump @xyflow/svelte from 1.6.2 to 1.6.3 β€” a59e1e8cdc38513921dc01c4e686581e208fd10d (#3668) (@dependabot[bot])
  • Bump charm.land/lipgloss/v2 from 2.0.5 to 2.0.6 in the CLI β€” 98f5cac2359a4b5dd42355b9c4da24ebc1a1739d (#3662) (@dependabot[bot])
  • Bump @codemirror/view from 6.43.8 to 6.43.9 β€” f2f34fac879a920afa772c0a6f0b509b7a74c478 (#3664) (@dependabot[bot])
  • Bump the AWS SDK for Go v2 dependency group with five updates in the backend β€” ffc1f128f487d1942f56c636c1daeba757649e57 (#3731) (@dependabot[bot])
  • Bump github.com/samber/slog-echo/v2 from 2.0.0 to 2.1.0 in the backend β€” 6c3f58f2b29acfb341d2071857e089b68f69529d (#3735) (@dependabot[bot])
  • Bump go.getarcane.app/acfs from 0.4.1 to 0.4.2 in the CLI and backend β€” 65b97153f05e20107ca04c70c60f3c1210409ac3 (#3722), 8087a444b343b9e8099df3a40d3a6fbb67c85441 (#3732) (@dependabot[bot])
  • Bump github.com/mattn/go-runewidth from 0.0.27 to 0.0.28 in the CLI β€” 3f43202a9c7550d087f60077a53ae59616b925f7 (#3719) (@dependabot[bot])
  • Bump go.getarcane.app/updater from 0.7.2 to 0.7.3 in the backend β€” d9b58268878a9a3de48013a6aa6d1f2b1681112b (#3733) (@dependabot[bot])
  • Bump go.getarcane.app/docker/convert from 0.1.0 to 0.2.0 in the backend β€” 8d52e7a704f675fcc01a31a72b29b9a8e5799011 (#3734) (@dependabot[bot])
  • Bump charm.land/bubbletea/v2 from 2.0.8 to 2.0.9 in the CLI β€” f012dbf16a2473a78fa9c44e6b2e7c384e522679 (#3720) (@dependabot[bot])
  • Bump charm.land/bubbles/v2 from 2.1.1 to 2.2.0 in the CLI β€” 29c5dc6afd682d08a26185ec5aa07a88e17ac6f9 (#3721) (@dependabot[bot])
  • Bump @tanstack/svelte-query from 6.1.38 to 6.1.39 β€” d200e9f73555d23b26a7e80270283fa3a9302213 (#3725) (@dependabot[bot])
  • Bump bits-ui from 2.18.1 to 2.19.0 β€” 3646524258861b2f6d67f7bd67be4b96a830e0c0 (#3728) (@dependabot[bot])
  • Bump marked from 18.0.9 to 18.0.10 β€” 82a2771040785fd68d44d1c66d8691543b3c4d7a (#3729) (@dependabot[bot])
  • Bump vite-plus to 0.3.0 β€” f3002cbd30db67f0bd4e05feaf9dec830b1b35a3 (@kmendell)
  • Bump @tanstack/virtual-core from 3.17.7 to 3.17.8 β€” ea1ab4b086e857166bdff9f43fabb92f7cdb7360 (#3723) (@dependabot[bot])

  •  

v2.8.1

Bug fixes

  • report never-pulled image refs as a distinct 'not pulled' state instead of failing the update check (#3631 by @kmendell)
  • localize category cards (#3596 by @InfinityPacer)
  • coalesce concurrent Docker image/container list calls to cut duplicate decodes (#3635 by @kmendell)
  • gate project archiving on live Docker state instead of stale persisted status(c487936 by @kmendell)
  • use stored credentials for non-Docker Hub registries (#3639 by @BobzTH)
  • add missing options to project redeploy dropdown(f7cb885 by @kmendell)
  • go1.26.6 h2c ReadHeaderTimeout regression(6d4f222 by @kmendell)
  • use errors.Is(err, fs.ErrNotExist) for acfs error checks (#3647 by @rohitkumbhar)
  • unblock git sync workspaces and pre-deploy hooks on permission edges (#3637 by @kmendell)

Dependencies

Other

Full Changelog: v2.8.0...v2.8.1

  •  

v2.8.0

New features

Bug fixes

  • move ios app passkey logic to backend(3b0fc6a by @kmendell)
  • return actual passkey identity(1ef7cc5 by @kmendell)
  • keep detecting passkeys with old ids(bfc35fb by @kmendell)
  • serialize concurrent per-container updates to prevent stranded recreate (#3541 by @JoeJoeflyn)
  • put arcane binary on $PATH in container images (#3547 by @JoeJoeflyn)
  • editor line highlight and selection rendering fully opaque on default accent color (#3554 by @kmendell)
  • git sync no longer fails on sockets or unreadable files outside the repo (#3561 by @kmendell)
  • allow saving compose files with includes outside the project directory (#3556 by @kmendell)
  • make compose up wait timeout configurable so long depends_on conditions don't abort deploys (#3557 by @kmendell)
  • webhook trigger endpoint responds 202 immediately instead of blocking until action completes (#3558 by @kmendell)
  • redeploy swarm stack when saving edited stack source (#3559 by @kmendell)
  • allow logging in with email address (#3555 by @kmendell)
  • actionable error when the projects directory is unreadable by the runtime user(802ab89 by @kmendell)
  • only log environment connect/disconnect events on real state transitions (#3564 by @kmendell)
  • resolve docker.sock host path for self-upgrade when using network_mode service (#3565 by @kmendell)
  • pick a DOCKER_HOST-reachable network for the self-update upgrader (#3566 by @kmendell)
  • dispatch agent notifications over the edge tunnel so remote environments send notifications (#3567 by @kmendell)
  • report CPU count from scheduler affinity so LXC core limits are respected (#3568 by @kmendell)
  • surface container shell websocket close codes for disconnect diagnostics (#3569 by @kmendell)
  • serve named pprof profiles instead of the index page (#3563 by @rknightion)
  • false 409 workspace conflict when saving files in imported projects (#3560 by @kmendell)
  • prevent white flash on page load and refreshes(a680185 by @kmendell)
  • stop loading every scan blob to serve one list page (#3610 by @kmendell)
  • show the real v2.x.x-next.xx upgrade target for next builds(5321b2a by @kmendell)

Performance improvements

  • cache validated API keys and debounce last_used_at writes (#3603 by @kmendell)
  • omit the output column from the build history list query (#3604 by @kmendell)
  • filter unhealthy containers at the daemon in auto-heal (#3605 by @kmendell)
  • stop building a new Docker CLI per compose call (#3607 by @kmendell)
  • share snapshot production and cheapen badge queries (#3608 by @kmendell)
  • cache GPU stats and pace the system-stats sampler to subscribers (#3609 by @kmendell)
  • batch message appends and drop the per-line re-SELECT (#3611 by @kmendell)
  • materialize the effective config once per refresh (#3619 by @kmendell)

Dependencies

  • bump github.com/google/go-containerregistry from 0.21.7 to 0.21.8 in /backend (#3529 by @dependabot[bot])
  • bump github.com/shirou/gopsutil/v4 from 4.26.6 to 4.26.7 in /backend (#3530 by @dependabot[bot])
  • bump gorm.io/driver/postgres from 1.6.1 to 1.6.2 in /backend (#3528 by @dependabot[bot])
  • bump the aws-sdk-go-v2 group across 1 directory with 3 updates (#3527 by @dependabot[bot])
  • bump @internationalized/date from 3.12.2 to 3.12.3 (#3521 by @dependabot[bot])
  • bump the tanstack-table group across 1 directory with 2 updates (#3514 by @dependabot[bot])
  • bump tailwind-variants from 3.3.0 to 3.3.1 (#3523 by @dependabot[bot])
  • bump pnpm to v11.21.0(9e2fe2f by @kmendell)
  • bump github.com/docker/cli from 29.7.1+incompatible to 29.7.2+incompatible in /backend (#3590 by @dependabot[bot])
  • bump the tanstack-table group across 1 directory with 2 updates (#3575 by @dependabot[bot])
  • bump github.com/moby/buildkit from 0.32.1 to 0.32.2 in /backend (#3587 by @dependabot[bot])
  • bump github.com/nicholas-fedor/shoutrrr from 0.16.3 to 0.17.0 in /backend (#3585 by @dependabot[bot])
  • bump github.com/libtnb/sqlite from 1.2.1 to 1.2.2 in /backend (#3592 by @dependabot[bot])
  • bump the aws-sdk-go-v2 group in /backend with 3 updates (#3584 by @dependabot[bot])
  • bump github.com/google/go-containerregistry from 0.21.8 to 0.21.9 in /backend (#3593 by @dependabot[bot])
  • bump github.com/klauspost/compress from 1.19.1 to 1.19.2 in /backend (#3588 by @dependabot[bot])
  • bump the codemirror group across 1 directory with 2 updates (#3576 by @dependabot[bot])
  • bump react-email from 6.9.1 to 6.9.2 (#3583 by @dependabot[bot])
  • bump marked from 18.0.7 to 18.0.9 (#3591 by @dependabot[bot])
  • bump go.getarcane.app/builds to v0.3.1(6d2ec79 by @kmendell)
  • bump @sveltejs/kit from 3.0.0-next.13 to 3.0.0-next.21 (#3579 by @dependabot[bot])
  • bump google.golang.org/protobuf from 1.36.12-0.20260120151049-f2248ac996af to 1.36.12 in /backend (#3617 by @dependabot[bot])

Other

Full Changelog: v2.7.0...v2.8.0

  •  

v2.7.0

Important

Project variable resolution now matches the Docker Compose CLI

Previously, environment variables set on Arcane's own container (such as PORT) could be picked up when resolving ${VARIABLE} references in your projects' compose files. This could cause surprising results β€” for example, a project using ${PORT:-8191} could end up binding to Arcane's own port instead of its default (#3499).

Starting with this release, variable references in a project's compose file resolve only from:

  • your global Variables (.env.global)
  • the project's own .env file
  • defaults in the compose file itself (${VAR:-default})
  • timezone and locale from Arcane's environment (TZ, LANG, LANGUAGE, LC_ALL)

This means a project deployed through Arcane now resolves its variables the same way as running docker compose up in the project directory, and projects can no longer accidentally pick up Arcane's own configuration.

If a project referenced a variable that was only defined on Arcane's container, add it under Customization β†’ Variables to share it with all projects, or to that project's .env file. No other action is needed.

New features

  • simplify build registry image references (#3243 by @traeli)
  • add gated admin password reset to interal CLI (#3470 by @kmendell)
  • per user passkey mfa / passwordless login support (#3493 by @kmendell)
  • custom payload generic webhooks and google chat notifications (#3417 by @khanhx)
  • bump docker/compose to v5.4.0, gate diverged-volume recreation behind deploy option, pull pre_start hook and image-volume images (#3502 by @kmendell)

Bug fixes

  • synchronize structured log toggle state (#3418 by @Kstateag)
  • project log timestamps (#3456 by @Kstateag)
  • improve lifecycle permission diagnostics (#3404 by @Kstateag)
  • gate image event watcher to prevent registry rate limits (#3467 by @kmendell)
  • serialize bulk deletes and refresh image data (#3466 by @kmendell)
  • refresh image labels during self-upgrade (#3479 by @kmendell)
  • forward icon catalog setting over tunnel endpoints (#3495 by @kmendell)
  • update overridden env keys in place in effective .env instead of appending duplicates (#3496 by @kmendell)
  • bulk remove doing nothing on non-HTTPS deployments (#3498 by @kmendell)
  • stale environment bootstrap API keys accumulating and being undeletable (#3501 by @kmendell)
  • sheet panel animation restarting on hover during open (#3503 by @kmendell)
  • only grant default admin role during bootstrap or zero-admin recovery, not to any account named arcane (#3504 by @kmendell)
  • enforce configured password policy on all password creation and reset paths (#3505 by @kmendell)
  • stop leaking Arcane's own process environment into compose variable interpolation (#3508 by @kmendell)

CLI - Bug fixes

Dependencies

Other

  • move to coder/websocket library as it is actively maintained (#3431 by @kmendell)
  • move automation logic to use actors (#3458 by @kmendell)

Full Changelog: v2.6.0...v2.7.0

  •  

v2.6.0

New features

  • raw docker CLI output for all operations + interactive watch mode (#3376 by @kmendell)
  • clickable dashboard tiles, volumes tile, and default landing page (#3383 by @kmendell)
  • add row, bulk, and Update All actions to the updates page (#3398 by @kmendell)

Bug fixes

  • harden gRPC tunnel reliability and request lifecycle (#3325 by @kmendell)
  • prevent image update checks from getting stuck in a running state (#3327 by @kmendell)
  • preserve IPAM fields in network inspect responses (#3335 by @kmendell)
  • remove full stack trace from logging(1bed071 by @kmendell)
  • correct swarm resource scoping and stack deploy conformance (#3385 by @kmendell)
  • tear down abandoned dashboard and activity streams promptly (#3388 by @kmendell)
  • skip unreadable directories instead of discarding the project file tree (#3393 by @kmendell)
  • preserve duplicate diagnostic log entries (#3390 by @Kstateag)
  • resolve relative compose paths that escape the projects mount (#3401 by @kmendell)
  • harden credential targets and browse paths (#3403 by @kmendell)
  • resolve nil dereferences and a database pool leak(c89ac52 by @kmendell)
  • handle unchecked error returns across backend and CLI(e4a5420 by @kmendell)
  • honor updater opt-out labels during image scans (#3405 by @Kstateag)
  • stream environment liveness over a multiplexed client stream (#3406 by @kmendell)
  • crashes, goroutine leaks, and hot-path performance in the backend (#3425 by @kmendell)
  • enforce actor privilege checks in user service (#3426 by @kmendell)

CLI - Bug fixes

Dependencies

  • bump actions/setup-go from 6 to 7 (#3342 by @dependabot[bot])
  • bump pnpm to v11.16.0(d0339d4 by @kmendell)
  • bump @tanstack/svelte-query from 6.1.36 to 6.1.37 (#3363 by @dependabot[bot])
  • bump @fontsource-variable/montserrat from 5.2.8 to 5.3.0 (#3360 by @dependabot[bot])
  • bump react-email from 6.8.1 to 6.9.0 (#3352 by @dependabot[bot])
  • bump svelte from 5.56.4 to 5.56.7 (#3351 by @dependabot[bot])
  • bump github.com/docker/cli from 29.6.1+incompatible to 29.6.2+incompatible in /backend (#3340 by @dependabot[bot])
  • bump @fontsource-variable/geist-mono from 5.2.8 to 5.3.0 (#3364 by @dependabot[bot])
  • bump github.com/klauspost/compress from 1.19.0 to 1.19.1 in /backend (#3339 by @dependabot[bot])
  • bump google.golang.org/grpc from 1.82.0 to 1.82.1 in /backend (#3337 by @dependabot[bot])
  • bump github.com/moby/buildkit from 0.31.1 to 0.31.2 in /backend (#3336 by @dependabot[bot])
  • bump the tanstack-table group across 1 directory with 2 updates (#3341 by @dependabot[bot])
  • bump @tanstack/virtual-core from 3.17.4 to 3.17.5 (#3355 by @dependabot[bot])
  • bump @sveltejs/kit from 3.0.0-next.8 to 3.0.0-next.11 (#3362 by @dependabot[bot])
  • bump @codemirror/lang-markdown from 6.5.0 to 6.5.1 in the codemirror group across 1 directory (#3344 by @dependabot[bot])
  • bump github.com/nicholas-fedor/shoutrrr from 0.16.1 to 0.16.2 in /backend (#3396 by @dependabot[bot])
  • bump the aws-sdk-go-v2 group in /backend with 3 updates (#3394 by @dependabot[bot])
  • bump github.com/libtnb/sqlite from 1.2.0 to 1.2.1 in /backend (#3395 by @dependabot[bot])
  • bump github.com/pressly/goose/v3 from 3.27.2 to 3.27.3 in /backend (#3397 by @dependabot[bot])

Other

Full Changelog: v2.5.0...v2.6.0

  •  
❌