This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+10 more
Affected surfaces
ReleasePort's take
Moderate signalReleasePort Layer 1 v1.19.2 fixes several SSH‑related bugs and adds a breaking change that requires migrating host resources to the new SSH resource mode for configuration management.
Why it matters: Severity 70 breaking change mandates migration of all host→SSH configurations before upgrade; bugfixes resolve role‑based access, edge cases, and blueprint errors affecting SREs and developers.
Summary
AI summaryUpdates https://pangolin.net/news/1-19-release, https://github.com/fosrl/pangolin/releases/tag/1.19.0, and https://docs.pangolin.net/self-host/how-to-update across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Breaking | High |
Requires migration of host resources to new SSH resource mode for config management Requires migration of host resources to new SSH resource mode for config management Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Dependency | Medium |
Requires Badger Traefik plugin update to v1.4.1 and manual Traefik restart Requires Badger Traefik plugin update to v1.4.1 and manual Traefik restart Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Dependency | Medium |
Requires Newt version 1.13.0 or greater for browser‑based RDP, SSH, and VNC Requires Newt version 1.13.0 or greater for browser‑based RDP, SSH, and VNC Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes SSH public resource support for non-admin roles Fixes SSH public resource support for non-admin roles Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes SSH public resource respecting ssh action restrictions on roles Fixes SSH public resource respecting ssh action restrictions on roles Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes private SSH resource edge case with missing host Fixes private SSH resource edge case with missing host Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes blueprint server‑side error caused by bad containers Fixes blueprint server‑side error caused by bad containers Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes missing translations in UI/localization Fixes missing translations in UI/localization Source: llm_adapter@2026-06-13 Confidence: high |
— |
| Bugfix | Medium |
Fixes mode missing in possible migration edge case Fixes mode missing in possible migration edge case Source: llm_adapter@2026-06-13 Confidence: high |
— |
Full changelog
Read the 1.19 Announcement
Read the full announcement with discussion of new features: Pangolin 1.19: Browser Remote Access — SSH, RDP, VNC & More
What's Changed
Refer to the original 1.19 notes for a complete list of what changed since 1.18.
- Fix mode missing in possible migration edge case
- Fix SSH public resource not working with roles other than admin
- Fix SSH public resource not respecting ssh action restriction on roles
- Fix missing translations
- Fix private SSH resource edge case with missing host
- Fix blueprint server side error with bad containers
How to Update
[!WARNING]
This version includes a new mode of private resource: SSH. If you had previously used host resources and configured the SSH access tab, you will now need to switch these to SSH resources in order to manage the SSH config. If you do not switch they will continue to function as before but you will be unable to adjust settings.
[!IMPORTANT]
1.19 browser-based SSH requires the Badger Traefik plugin to be on the latest versionv1.4.1. The migration will automatically do this if it can find the Traefik config in the standard location BUT YOU WILL NEED TO RESTART TRAEFIK TO PULL THE NEW PLUGIN. Otherwise, please ensure your Badger is up to date.
[!IMPORTANT]
Browser-based RDP, SSH, and VNC as well as the new Pangolin SSH mode requires Newt version1.13.0or greater.
[!IMPORTANT]
Always back up your config app-data before updating. This will allow you to easily roll back if the update breaks your configuration. You will not be able to easily downgrade otherwise.
Breaking Changes
- SSH private resource mode introduced; existing host resources must be converted to SSH resources to manage SSH config.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]