This release includes 3 security fixes for security teams reviewing exposed deployments.
Published 16h
Containers & Orchestration
✓ No known CVEs patched
This release patches 3 known CVEs
Topics
docker
docker-deployment
docker-stack
docker-stack-deploy
docker-ui
self-hosted
+1 more
websocket
Affected surfaces
deps
Summary
AI summaryUpdates 0.96.0, 2026-07-26, and https://github.com/Studio-Saelix/sencho/issues/1677 across a mixed release.
Full changelog
0.96.0 (2026-07-26)
Added
- add Admiral Hardened Build channel and business assurance surfaces (#1629) (381ed2a)
- add Apprise as a fourth notification channel (#1644) (83b3d93)
- add configurable notification dispatch retries (#1655) (090a0d7)
- add developer-mode startup and stack hydration timing (#1619) (b70a529)
- add service-scoped Compose update and restore (#1648) (63213c0)
- add service-scoped stack alert rules (#1681) (85842cc)
- blueprints: require confirmed rollout preview before reconcile (#1649) (d94e586)
- graduate Host Console to Community admins (#1669) (dd54a2e)
- guide missing external network creation during deploy (#1645) (35bb744)
- node-scoped Networking operator page (#1603) (8980910)
- stack glob patterns and route severity levels (#1651) (972f2b9)
- surface stack Monitor from header and service cards (#1693) (524cc56)
- ui: add Classic, Smart, and Compact desktop navigation styles (#1642) (25586fc)
- weekly UTC maintenance windows for mute rules (#1661) (a3edee5)
Fixed
- assorted UI/UX polish fixes (#1670) (cfb42af)
- blueprints: fail closed on marker ownership for apply and withdraw (#1694) (17a8dc8)
- blueprints: gate confirmed apply on live intent fingerprint (#1663) (155db30)
- blueprints: write compose.yaml so first-time apply is not shadowed (#1668) (e15b9d1)
- bump brace-expansion override to 5.0.8 to clear high-severity audit (#1702) (d0a4f1e)
- dedupe healthcheck alerts and share crash rate limits (#1690) (ec0f59a)
- docs: remove duplicate license url key in openapi.yaml (#1628) (8ca8eba)
- fleet: expose Community cordon on NodeCard (#1646) (674220b)
- fleet: isolate corrupt snapshot file decrypt failures (#1650) (3b02795)
- fleet: refresh prune reclaimable estimate after successful run (#1675) (ed5ca9c)
- fleet: verify update status before removing readiness cards (#1697) (719180f)
- image-updates: match any local RepoDigest against the remote tag (#1695) (6688da9)
- image-updates: normalize docker.io host aliases to the registry API host (#1706) (bb7c76b)
- image-updates: treat multi-arch child digests as up to date (#1641) (66ec4eb)
- keep running containers until stack pull/build succeeds (#1657) (3f1f15a)
- leave editor after deleting the open stack (#1665) (55fa29f)
- notifications: align Sencho update alerts with Fleet cache (#1620) (4079cb9)
- notifications: neutralize satellite-local node names in alert bodies (#1640) (d8e4ede)
- notifications: stop embedding Local in janitor alerts (#1631) (678c198)
- notifications: version mute replica retractions for soft-cleanup restore (#1703) (9859ce6)
- pin brace-expansion to a patched version in both packages (#1658) (8598390)
- pin postcss override to clear backend audit vulnerability (#1701) (e33eda3)
- prevent false empty states during stack hydration (#1659) (b06dfd7)
- purge deleted-stack notifications from panel and ticker (#1674) (698b7d0)
- rate-limit: verify node_proxy JWT before skipping limiters (#1647) (31d4e46)
- rbac: cover stack assignment cleanup on blueprint withdraw (#1664) (6484c79)
- recognize clean one-shot completions in health gate and drift (#1691) (79914fe)
- reconcile sticky update indicators with Anatomy preview (#1698) (0daddfd)
- security: bump grpc to 1.82.1 in docker CLI and compose builds (#1678) (ce4eeb6)
- settings: toast and block save when node settings fail to load (#1654) (ad00517)
- sso: correct settings description to drop unsupported SAML claim (#1662) (a4d9fa7)
- stacks: fail closed when compose ps errors during update orphan classify (#1708) (6887670)
- ui: default Reduced Motion on Calm and quiet decorative rails (#1622) (c170c3f)
- ui: hide log service chips on single-service stacks (#1689) (a89498a)
- ui: lower-overhead Reduced effects for constrained GPUs (#1616) (c01f247)
- ui: use Docker health status terms on container cards (#1696) (4d2270a), closes #1677
- unlock Community deploy policy hard-blocking (#1643) (b91025d)
Breaking Changes
- **blueprints:** require confirmed rollout preview before reconcile
Security Fixes
- Bump brace‑expansion override to 5.0.8 to clear high‑severity audit
- Pin postcss override to clear backend audit vulnerability
- **security:** bump grpc to 1.82.1 in docker CLI and compose builds
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Sencho
All releases →Beta — feedback welcome: [email protected]