Commit Graph

2905 Commits

Author SHA1 Message Date
dependabot[bot]
276f613be1 chore(deps): bump sass from 1.101.7 to 1.102.0 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.101.7 to 1.102.0.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.101.7...1.102.0)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.102.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-27 13:54:13 +00:00
dependabot[bot]
52a44467f9 chore(deps): bump sass from 1.101.6 to 1.101.7 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.101.6 to 1.101.7.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.101.6...1.101.7)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.101.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-24 13:54:09 +00:00
dependabot[bot]
64785ca0ee chore(deps): bump sass from 1.101.3 to 1.101.6 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.101.3 to 1.101.6.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.101.3...1.101.6)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.101.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-23 13:54:09 +00:00
Jose Diaz-Gonzalez
e3687a62ed Merge pull request #8856 from youdie006/feat/ports-parsed-mappings
Add pre-parsed port_mappings to ports:report json
2026-07-22 04:57:13 -04:00
Jose Diaz-Gonzalez
9c61031f3e docs: add docs and tests for this feature 2026-07-22 03:45:32 -04:00
Jose Diaz-Gonzalez
e7df3a5fd6 Merge pull request #8860 from dokku/dependabot/pip/tests/apps/dockerfile-release/setuptools-83.0.0
chore(deps): bump setuptools from 78.1.1 to 83.0.0 in /tests/apps/dockerfile-release
2026-07-22 03:17:18 -04:00
Jose Diaz-Gonzalez
9e246e2114 Merge pull request #8859 from dokku/dependabot/npm_and_yarn/tests/apps/multi/immutable-5.1.9
chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
2026-07-22 03:16:52 -04:00
Jose Diaz-Gonzalez
f440c7794e Merge pull request #8855 from dokku/dependabot/npm_and_yarn/tests/apps/multi/sass-1.101.3
chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
2026-07-22 03:16:38 -04:00
dependabot[bot]
3bf1079926 chore(deps): bump setuptools in /tests/apps/dockerfile-release
Bumps [setuptools](https://github.com/pypa/setuptools) from 78.1.1 to 83.0.0.
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](https://github.com/pypa/setuptools/compare/v78.1.1...v83.0.0)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-version: 83.0.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 07:13:34 +00:00
dependabot[bot]
878ca3c2f7 chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
Bumps [immutable](https://github.com/immutable-js/immutable-js) from 5.1.5 to 5.1.9.
- [Release notes](https://github.com/immutable-js/immutable-js/releases)
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md)
- [Commits](https://github.com/immutable-js/immutable-js/compare/v5.1.5...v5.1.9)

---
updated-dependencies:
- dependency-name: immutable
  dependency-version: 5.1.9
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-22 07:13:25 +00:00
Jose Diaz-Gonzalez
d39064058b Merge pull request #8857 from dokku/dependabot/npm_and_yarn/tests/apps/checks-root/body-parser-2.3.0
chore(deps): bump body-parser from 2.2.1 to 2.3.0 in /tests/apps/checks-root
2026-07-22 03:12:12 -04:00
dependabot[bot]
3542acc271 chore(deps): bump body-parser in /tests/apps/checks-root
Bumps [body-parser](https://github.com/expressjs/body-parser) from 2.2.1 to 2.3.0.
- [Release notes](https://github.com/expressjs/body-parser/releases)
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md)
- [Commits](https://github.com/expressjs/body-parser/compare/v2.2.1...v2.3.0)

---
updated-dependencies:
- dependency-name: body-parser
  dependency-version: 2.3.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 19:58:27 +00:00
dependabot[bot]
64e7654453 chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
Bumps [sass](https://github.com/sass/dart-sass) from 1.101.0 to 1.101.3.
- [Release notes](https://github.com/sass/dart-sass/releases)
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sass/dart-sass/compare/1.101.0...1.101.3)

---
updated-dependencies:
- dependency-name: sass
  dependency-version: 1.101.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 13:54:12 +00:00
dependabot[bot]
e746ea98f8 chore(deps): bump python in /tests/apps/dockerfile-release
Bumps python from 3.15.0b3-bookworm to 3.15.0b4-bookworm.

---
updated-dependencies:
- dependency-name: python
  dependency-version: 3.15.0b4-bookworm
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-21 13:53:08 +00:00
Jose Diaz-Gonzalez
dc802ddd19 feat: support per-app letsencrypt emails on k3s
The `letsencrypt-email-prod` and `letsencrypt-email-stag` properties can now be set per app in addition to globally, resolving app-level before the global value for the app's selected `letsencrypt-server`. An app that sets its own email renders a namespaced cert-manager `Issuer` using that email, while apps without an override continue to use the shared `ClusterIssuer` with the global email.
2026-07-19 03:31:55 -04:00
Jose Diaz-Gonzalez
1a376c3622 fix: prevent command injection via docker options eval
Values supplied through docker options, `--ttl-seconds`, and `-e` flowed into a Bash `eval` during build, deploy, and run, letting a low-privileged user execute arbitrary commands on the host as the dokku user. These arguments are now tokenized and passed through to the container verbatim, without shell expansion. A one-time migration repairs stored labels whose backticks were saved with a stray backslash so Traefik-style rules stay valid on the next deploy.
2026-07-19 01:42:12 -04:00
Jose Diaz-Gonzalez
f1f90233f6 Merge pull request #8841 from dokku/dependabot/docker/tests/apps/dockerfile-entrypoint/ruby-4.0.6
chore(deps): bump ruby from 4.0.5 to 4.0.6 in /tests/apps/dockerfile-entrypoint
2026-07-17 10:45:05 -04:00
dependabot[bot]
22718c10d7 chore(deps): bump google.golang.org/grpc in /tests/apps/gogrpc
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.82.0 to 1.82.1.
- [Release notes](https://github.com/grpc/grpc-go/releases)
- [Commits](https://github.com/grpc/grpc-go/compare/v1.82.0...v1.82.1)

---
updated-dependencies:
- dependency-name: google.golang.org/grpc
  dependency-version: 1.82.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-16 13:52:23 +00:00
dependabot[bot]
90d76060fe chore(deps): bump ruby in /tests/apps/dockerfile-entrypoint
Bumps ruby from 4.0.5 to 4.0.6.

---
updated-dependencies:
- dependency-name: ruby
  dependency-version: 4.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-15 13:52:31 +00:00
Jose Diaz-Gonzalez
5496029e07 fix: parse cert CN and subject on OpenSSL 3.x
The `certs` plugin extracted a certificate's Common Name and formatted its subject using string assumptions that only held for pre-3.x OpenSSL output, so a certificate with only a Common Name and no Subject Alternative Name reported no hostnames from `certs:report` and was not recognized during nginx config generation, while the subject report retained the `subject=` prefix and used the wrong separators. Normalizing the subject with `-nameopt` before parsing makes the extraction version independent across OpenSSL and LibreSSL.
2026-07-10 15:05:27 -04:00
Jose Diaz-Gonzalez
7bd866efee Merge pull request #8825 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-no-tini/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-no-tini
2026-07-09 21:14:44 -04:00
Jose Diaz-Gonzalez
4205871cec Merge pull request #8823 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-tini/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-tini
2026-07-09 21:14:36 -04:00
Jose Diaz-Gonzalez
16ba93f9e2 Merge pull request #8820 from dokku/dependabot/composer/tests/apps/php/heroku/heroku-buildpack-php-293
chore(deps-dev): bump heroku/heroku-buildpack-php from 292 to 293 in /tests/apps/php
2026-07-09 21:14:26 -04:00
Jose Diaz-Gonzalez
e2781c0553 Merge pull request #8821 from dokku/dependabot/docker/tests/apps/go-fail-predeploy/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/go-fail-predeploy
2026-07-09 21:14:17 -04:00
Jose Diaz-Gonzalez
91025ee23e Merge pull request #8822 from dokku/dependabot/docker/tests/apps/gogrpc/golang-1.26.5
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/gogrpc
2026-07-09 21:14:04 -04:00
dependabot[bot]
5ff86ec977 chore(deps): bump golang in /tests/apps/zombies-dockerfile-no-tini
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:53:12 +00:00
dependabot[bot]
7e05d6cca4 chore(deps): bump golang in /tests/apps/go-fail-postdeploy
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:53:05 +00:00
dependabot[bot]
58f509ed0c chore(deps): bump golang in /tests/apps/zombies-dockerfile-tini
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:52:57 +00:00
dependabot[bot]
5462744cf0 chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/gogrpc
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:52:57 +00:00
dependabot[bot]
ab14872c77 chore(deps): bump golang in /tests/apps/go-fail-predeploy
Bumps golang from 1.26.4 to 1.26.5.

---
updated-dependencies:
- dependency-name: golang
  dependency-version: 1.26.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:52:38 +00:00
dependabot[bot]
01f3280746 chore(deps-dev): bump heroku/heroku-buildpack-php in /tests/apps/php
Bumps [heroku/heroku-buildpack-php](https://github.com/heroku/heroku-buildpack-php) from 292 to 293.
- [Release notes](https://github.com/heroku/heroku-buildpack-php/releases)
- [Changelog](https://github.com/heroku/heroku-buildpack-php/blob/main/CHANGELOG.md)
- [Commits](https://github.com/heroku/heroku-buildpack-php/compare/v292...v293)

---
updated-dependencies:
- dependency-name: heroku/heroku-buildpack-php
  dependency-version: '293'
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-09 13:52:36 +00:00
Jose Diaz-Gonzalez
611cb89711 Merge pull request #8805 from RichardDorian/master
Allow custom values for chown
2026-07-08 18:09:31 -04:00
Jose Diaz-Gonzalez
c37ba0f255 Merge pull request #8810 from dokku/8797-network-list-expose-whether-a-network-was-created-by-dokku
Expose whether a network was created by dokku
2026-07-08 14:52:32 -04:00
RichardDorian
513b200f5c test(storage): add out-of-bounds chown coverage for go code and script 2026-07-08 19:38:08 +02:00
Jose Diaz-Gonzalez
ac4b86fd8e feat: expose whether a network was created by dokku
`network:list` and `network:info` now expose a `DokkuManaged` boolean derived from the `com.dokku.network-name` label that `network:create` applies, and `network:list` gains a `--dokku-managed` flag to restrict output to dokku-created networks. This lets tooling distinguish networks dokku created from Docker built-ins and networks created by other tooling such as compose.
2026-07-08 00:03:29 -04:00
Jose Diaz-Gonzalez
1ee462dc3c docs: document nginx validate-config load_module override
The nginx deploy-time pre-validation runs `nginx -t` against a minimal wrapper that omits the global `load_module` directives, so a custom `nginx.conf.sigil` using a directive from a dynamically loaded module fails validation even though it is valid against the running server. Document overriding the `validate-config` template through the `nginx-app-template-source` trigger as the supported workaround.
2026-07-07 23:33:59 -04:00
Jose Diaz-Gonzalez
24e3809a34 Merge pull request #8807 from dokku/8802-buildpacks-allow-setting-the-entire-ordered-buildpack-list-in-one-command
Allow replacing buildpack list atomically
2026-07-07 22:13:59 -04:00
Jose Diaz-Gonzalez
62164181e0 Merge pull request #8808 from dokku/8799-docker-options-report-expose-options-as-a-structured-list
Expose docker-options as structured lists in JSON report
2026-07-07 21:29:56 -04:00
Jose Diaz-Gonzalez
4652749b5b feat: expose docker-options as structured lists in JSON report
Add parallel -list keys to docker-options:report --format json so export
tools can round-trip options without splitting space-joined strings.

Closes #8799
2026-07-07 19:49:17 -04:00
Jose Diaz-Gonzalez
16f8b25bda feat: allow replacing buildpack list atomically
Add buildpacks:set --replace so callers can replace an app's complete ordered buildpack list in one command while preserving existing single-buildpack and --index behavior.

Closes #8802
2026-07-07 18:37:38 -04:00
Jose Diaz-Gonzalez
b2c4f61387 feat: expose scheduler-k3s autoscaling-auth state for read-back
Align autoscaling-auth:report with annotations and labels reporting so export tools can recover configured trigger auth via flat JSON keys and info flags, while stdout stays secret-safe unless --include-metadata is used.

Closes #8800
2026-07-07 18:07:39 -04:00
RichardDorian
a0361d59c1 test(storage): add unit test for custom chown values 2026-07-07 20:48:34 +02:00
Jose Diaz-Gonzalez
25b1356435 Merge pull request #8803 from dokku/dependabot/pip/tests/apps/dockerfile-release/django-5.2.16
chore(deps): bump django from 5.2.15 to 5.2.16 in /tests/apps/dockerfile-release
2026-07-07 12:18:52 -04:00
Jose Diaz-Gonzalez
cf15fb139e Merge remote-tracking branch 'origin/master' into parallel-bash-reports
# Conflicts:
#	go.work
2026-07-07 10:38:57 -04:00
dependabot[bot]
8a35ed337e chore(deps): bump django in /tests/apps/dockerfile-release
Bumps [django](https://github.com/django/django) from 5.2.15 to 5.2.16.
- [Commits](https://github.com/django/django/commits)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 5.2.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-07 13:54:29 +00:00
Jose Diaz-Gonzalez
8d0c36bad6 feat: port checks and domains :report subcommands to golang
The bash :report implementations for the checks and domains plugins are replaced with a compiled golang binary that collects report keys in parallel and marshals json directly. The domains global report header now matches the shared renderer used by every other golang report, and its bats assertion is updated accordingly.
2026-07-07 06:43:31 -04:00
Jose Diaz-Gonzalez
5faabea3d4 feat: port vhost proxy :report subcommands to golang
The bash :report implementations for the caddy, haproxy, openresty, and traefik proxy plugins are replaced with a compiled golang binary that collects report keys in parallel and marshals json directly. The traefik dns-provider values keep their masking behaviour, remaining hidden in the default stdout report while surfacing for --format json or an explicit flag query. These four plugins previously had no unit tests, so a bats suite covering the report matrix is added for each.
2026-07-07 06:29:01 -04:00
Jose Diaz-Gonzalez
9c819cfebc feat: add --format json support to plugin:list
Adds a `--format json` flag to `plugin:list` whose output includes each plugin's install source - for git-based third-party plugins, the git remote URL, the checked-out commit, and the followed branch - so the set of installed plugins can be reconstructed elsewhere.

Closes #8798.
2026-07-07 05:17:40 -04:00
Jose Diaz-Gonzalez
857d115fdd feat: add --format json support to ps:scale
The `ps:scale` command now accepts a `--format` flag that defaults to `stdout` and can be set to `json` to emit the current formation as a JSON array of process type and quantity objects, matching the JSON output the `:report` subcommands already provide. The flag only applies when displaying the current formation; it is ignored when process types are supplied for scaling. When no scale has been set for the app, the JSON output is an empty array.
2026-07-06 13:57:19 -04:00
Jose Diaz-Gonzalez
21c27e99cc feat: add --format json support to apps:list
The `apps:list` command now accepts a `--format` flag that defaults to `stdout` and can be set to `json` to emit the app names as a JSON array, matching the JSON output the `:report` subcommands already provide. When no apps exist, the JSON output is an empty array.
2026-07-06 11:50:56 -04:00