This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 1mo
Containers & Orchestration
✓ No known CVEs patched
This release patches 3 known CVEs
Affected surfaces
auth
Summary
AI summaryChange default listen port from 3000 to 1852 and add per-stack auto‑update toggle.
Full changelog
0.64.0 (2026-04-27)
Added
- app-store: sort grid by stars and rotate featured weekly (#787) (dcf8794)
- auto-update: per-stack auto-update enable/disable toggle (#771) (af9cb0a)
- auto-update: show pending image updates fleet-wide on the Auto-Updates page (#770) (58df1a5)
- change default listen port from 3000 to 1852 (#756) (ed553f1)
- cloud-backup: mirror fleet snapshots to S3-compatible storage (#782) (03f91cd)
- dashboard: replace 24h charts with Configuration Status and Recent Activity (#785) (d7d8f9b)
- deploy-logs: opt-in deploy progress modal with structured log rows (#779) (dd9d338)
- events: broadcast state-invalidate on docker events so dashboard updates live (#768) (5c50218)
- files: per-stack file explorer (#780) (801a098)
- license: replace local auto-trial with Lemon Squeezy hosted trial flow (#755) (d6b744e)
- notifications: add structured category enum to dispatcher and history (#774) (44dba59)
- notifications: match routing rules by labels and categories (#776) (e003413)
- scheduler: add auto_backup, auto_stop, auto_down, auto_start and delete_after_run one-shot mode (#777) (abee078)
- scheduler: support fleet-wide auto-update schedules per node (#773) (a74564f)
- security: add SBOM attestations, VEX document, and retire .trivyignore (#790) (3668c71)
- security: rebuild Docker CLI/Compose from source, pin base image digests (#789) (7e4ea71)
- sidebar: keyboard shortcuts for stack menu actions (#729) (1ef9658)
- sso: split SSO providers by delivery model across tiers (#754) (a502da5)
- stacks: add optional volume prune to delete confirmation (#788) (38a9f27)
- stacks: add Schedule task shortcut to stack context and kebab menus (#772) (819d2a6)
- stacks: per-service start/stop/restart lifecycle actions (#778) (6986b92)
Fixed
- auto-update: label same-tag rebuilds as 'Rebuild available' instead of '10.11 -> 10.11' (#766) (584cda7)
- backend: restore remote proxy mount order before local routers (#747) (43a5959)
- env: return empty body for missing .env files; surface non-OK responses cleanly (#767) (a962654)
- frontend: clear sidebar update dot after toolbar Update click (#763) (5746104)
- frontend: make copy buttons work over plain HTTP (#757) (4c35226)
- frontend: stream log lines on next paint and show ms-precision timestamps (#764) (c9657b1)
- login: remove branding duplication, add shimmer and ping dot (#727) (d47f6b4)
- logs: drop millisecond suffix from log timestamp display (#769) (c7cdcd0)
- monitor: include node name in janitor alert and stop firing on near-empty hosts (#765) (9e0f521)
- notifications: scope routing rules to nodes via node_id column (#775) (fcbdd59)
- security: clear cached policy evaluations when a scan policy is deleted (#758) (24c0a28)
- sidebar: remove 1-hour staleness filter from activity ticker (#786) (f94b2ce)
Breaking Changes
- Change default listen port from 3000 to 1852 (requires updating any reverse‑proxy rules, firewall exceptions, or client code that assumes port 3000).
- Add per-stack auto‑update enable/disable toggle (introduces new configuration key `auto_update.enabled` for each stack).
Security Fixes
- **security:** clear cached policy evaluations when a scan policy is deleted
- **security:** rebuild Docker CLI/Compose from source and pin base image digests (mitigates supply‑chain risks)
- **security:** add SBOM attestations and VEX document; retire .trivyignore
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Sencho
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]