Skip to content

xyops

Automation & Workflows

A unified, open‑source platform that combines job scheduling, workflow automation, server monitoring, alerting, and incident response into a single extensible system.

JavaScript Latest v1.0.45 · 1mo ago Security brief →

Features

  • Job scheduling beyond cron with advanced triggers
  • Visual workflow editor for connecting events, actions, and monitors
  • Real‑time server monitoring with customizable alerts
  • Integrated incident response that links jobs, metrics, and tickets
  • Simple self‑hosted setup suitable for any fleet size

Recent releases

View all 32 releases →
v1.0.45 Mixed
Security fixes
  • dep: lodash vulnerability fix in async sub-dependency (v4.18.1)
Notable features
  • Postgres storage engine support with pixl-server-storage v4.1.0
  • Redis storage engine support with ioredis module
  • Custom sub-job labels now visible on workflow job detail screens
Full changelog
  • 041c000: Version 1.0.45
    • Bump pixl-server-storage to v4.1.0 for new Postgres storage engine.
    • Add pg module for Postgres storage engine.
    • Add ioredis module for Redis storage engine.
    • Bump lodash (sub-dep of async) to v4.18.1 for another vuln fix.
  • 715a640: Bug Fix: Custom sub-job labels were not visible on workflow job detail screen. Fixes #242.
  • f946407: Sample Config: Add new default Postgres storage engine configuration.
  • 6f863ba: Docs: Add new storage setup doc, and link it from existing docs.
  • 46fc0be: UI Strings: Tweak limit and action table captions to be more clear about category and universal inheritance.
  • 7f962c8: UI Tweak: Fix "Copy to Clipboard" button in code viewer dialog.
  • dd937e6: Bug Fix: Upon job recovery after restart, unset job.remote flag in case job is dead (so it can abort after going stale). Fixes #240.
  • 58be32f: Meta: Add local bin/release.sh script for automating releases.

Full Diff: https://github.com/pixlcore/xyops/compare/v1.0.44...v1.0.45

v1.0.44 Bug fix
Notable features
  • Webhook headers array enforcement
  • Bulk delete page refresh
  • Workflow event target expressions
Full changelog
  • bc2a0ea: Version 1.0.44
  • ea357ff: Meta: Add release.yml to automatically generate release notes and a GH release via GH actions.
  • e379951: Servers Doc: Fix tabs that snuck into docker-compose sample.
  • e07bea5: UI Tweak: Job Details: When user content contains markdown, increase its body font size slightly.
  • a97589d: Bug Fix: Ensure web hook headers are an array at the API level, and add extra safeguards. Fixes #238.
  • 74d5778: Servers Doc: Updated automated docker workers section with new xysat configuration setup.
  • 3124d5c: Security Overview Doc: Made a few minor corrections and wording adjustments.
  • f4ba4f7: Multi/Satelite Release List APIs: Add optional verbose parameter, to include full response from GitHub.
  • 018e43b: Add SECURITY_OVERVIEW.md document, to complement THREAT_MODEL.md.
  • e8cf67b: Bulk Deletes: When internal deletion jobs complete, refresh applicable search results pages in case users are waiting. Fixes #236
  • 4c0bf02: Admin Upgrade Conductors API: Default single server pre-delay time to 5 seconds to allow for job to complete before starting upgrade.
  • 0ff5230: Workflows: Support event/job target expression in the multiplex controller, and do not abort the workflow if no servers match. Fixes #233
  • 68972b9: Docs: Remove NFS as a recommended storage configuration.
  • 888d1bf: System Diag Report: Small tweaks, trim load avg for display, add message for zero servers.

Full Diff: https://github.com/pixlcore/xyops/compare/v1.0.43...v1.0.44

v1.0.43 New feature
Breaking changes
  • API endpoints with v1 suffix return HTTP 404 on failure instead of other codes
Security fixes
  • Patched lodash vulnerability via dependency override
Notable features
  • Magic link form customization with button text and icons
  • Version upgrade indicators for conductors and satellite servers
  • Diagnostic report generation for GitHub issues
v1.0.41 Security relevant
Security fixes
  • Patched picomatch vulnerability in pixl-tools
  • Patched nodemailer vulnerability in pixl-mail
Notable features
  • Global sidebar section hiding configuration
  • Secret vault management for plugins
v1.0.40 New feature
Breaking changes
  • Sub-job queuing now uses per-job namespace instead of shared queue
Security fixes
  • Improved secret scrubbing from webhook diagnostic output
Notable features
  • Custom SSO plugin command for validation and transformation
  • Per-job-namespace queuing for workflows

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
4,290
Forks
433
Languages
JavaScript CSS HTML

Beta — feedback welcome: [email protected]