dependabot[bot]
276f613be1
chore(deps): bump sass from 1.101.7 to 1.102.0 in /tests/apps/multi
...
Bumps [sass](https://github.com/sass/dart-sass ) from 1.101.7 to 1.102.0.
- [Release notes](https://github.com/sass/dart-sass/releases )
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sass/dart-sass/compare/1.101.7...1.102.0 )
---
updated-dependencies:
- dependency-name: sass
dependency-version: 1.102.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-27 13:54:13 +00:00
dependabot[bot]
52a44467f9
chore(deps): bump sass from 1.101.6 to 1.101.7 in /tests/apps/multi
...
Bumps [sass](https://github.com/sass/dart-sass ) from 1.101.6 to 1.101.7.
- [Release notes](https://github.com/sass/dart-sass/releases )
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sass/dart-sass/compare/1.101.6...1.101.7 )
---
updated-dependencies:
- dependency-name: sass
dependency-version: 1.101.7
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-24 13:54:09 +00:00
dependabot[bot]
64785ca0ee
chore(deps): bump sass from 1.101.3 to 1.101.6 in /tests/apps/multi
...
Bumps [sass](https://github.com/sass/dart-sass ) from 1.101.3 to 1.101.6.
- [Release notes](https://github.com/sass/dart-sass/releases )
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sass/dart-sass/compare/1.101.3...1.101.6 )
---
updated-dependencies:
- dependency-name: sass
dependency-version: 1.101.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-23 13:54:09 +00:00
Jose Diaz-Gonzalez
e3687a62ed
Merge pull request #8856 from youdie006/feat/ports-parsed-mappings
...
Add pre-parsed port_mappings to ports:report json
2026-07-22 04:57:13 -04:00
Jose Diaz-Gonzalez
9c61031f3e
docs: add docs and tests for this feature
2026-07-22 03:45:32 -04:00
Jose Diaz-Gonzalez
e7df3a5fd6
Merge pull request #8860 from dokku/dependabot/pip/tests/apps/dockerfile-release/setuptools-83.0.0
...
chore(deps): bump setuptools from 78.1.1 to 83.0.0 in /tests/apps/dockerfile-release
2026-07-22 03:17:18 -04:00
Jose Diaz-Gonzalez
9e246e2114
Merge pull request #8859 from dokku/dependabot/npm_and_yarn/tests/apps/multi/immutable-5.1.9
...
chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
2026-07-22 03:16:52 -04:00
Jose Diaz-Gonzalez
f440c7794e
Merge pull request #8855 from dokku/dependabot/npm_and_yarn/tests/apps/multi/sass-1.101.3
...
chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
2026-07-22 03:16:38 -04:00
dependabot[bot]
3bf1079926
chore(deps): bump setuptools in /tests/apps/dockerfile-release
...
Bumps [setuptools](https://github.com/pypa/setuptools ) from 78.1.1 to 83.0.0.
- [Release notes](https://github.com/pypa/setuptools/releases )
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst )
- [Commits](https://github.com/pypa/setuptools/compare/v78.1.1...v83.0.0 )
---
updated-dependencies:
- dependency-name: setuptools
dependency-version: 83.0.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-22 07:13:34 +00:00
dependabot[bot]
878ca3c2f7
chore(deps): bump immutable from 5.1.5 to 5.1.9 in /tests/apps/multi
...
Bumps [immutable](https://github.com/immutable-js/immutable-js ) from 5.1.5 to 5.1.9.
- [Release notes](https://github.com/immutable-js/immutable-js/releases )
- [Changelog](https://github.com/immutable-js/immutable-js/blob/main/CHANGELOG.md )
- [Commits](https://github.com/immutable-js/immutable-js/compare/v5.1.5...v5.1.9 )
---
updated-dependencies:
- dependency-name: immutable
dependency-version: 5.1.9
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-22 07:13:25 +00:00
Jose Diaz-Gonzalez
d39064058b
Merge pull request #8857 from dokku/dependabot/npm_and_yarn/tests/apps/checks-root/body-parser-2.3.0
...
chore(deps): bump body-parser from 2.2.1 to 2.3.0 in /tests/apps/checks-root
2026-07-22 03:12:12 -04:00
dependabot[bot]
3542acc271
chore(deps): bump body-parser in /tests/apps/checks-root
...
Bumps [body-parser](https://github.com/expressjs/body-parser ) from 2.2.1 to 2.3.0.
- [Release notes](https://github.com/expressjs/body-parser/releases )
- [Changelog](https://github.com/expressjs/body-parser/blob/master/HISTORY.md )
- [Commits](https://github.com/expressjs/body-parser/compare/v2.2.1...v2.3.0 )
---
updated-dependencies:
- dependency-name: body-parser
dependency-version: 2.3.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-21 19:58:27 +00:00
dependabot[bot]
64e7654453
chore(deps): bump sass from 1.101.0 to 1.101.3 in /tests/apps/multi
...
Bumps [sass](https://github.com/sass/dart-sass ) from 1.101.0 to 1.101.3.
- [Release notes](https://github.com/sass/dart-sass/releases )
- [Changelog](https://github.com/sass/dart-sass/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sass/dart-sass/compare/1.101.0...1.101.3 )
---
updated-dependencies:
- dependency-name: sass
dependency-version: 1.101.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-21 13:54:12 +00:00
dependabot[bot]
e746ea98f8
chore(deps): bump python in /tests/apps/dockerfile-release
...
Bumps python from 3.15.0b3-bookworm to 3.15.0b4-bookworm.
---
updated-dependencies:
- dependency-name: python
dependency-version: 3.15.0b4-bookworm
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-21 13:53:08 +00:00
Jose Diaz-Gonzalez
dc802ddd19
feat: support per-app letsencrypt emails on k3s
...
The `letsencrypt-email-prod` and `letsencrypt-email-stag` properties can now be set per app in addition to globally, resolving app-level before the global value for the app's selected `letsencrypt-server`. An app that sets its own email renders a namespaced cert-manager `Issuer` using that email, while apps without an override continue to use the shared `ClusterIssuer` with the global email.
2026-07-19 03:31:55 -04:00
Jose Diaz-Gonzalez
1a376c3622
fix: prevent command injection via docker options eval
...
Values supplied through docker options, `--ttl-seconds`, and `-e` flowed into a Bash `eval` during build, deploy, and run, letting a low-privileged user execute arbitrary commands on the host as the dokku user. These arguments are now tokenized and passed through to the container verbatim, without shell expansion. A one-time migration repairs stored labels whose backticks were saved with a stray backslash so Traefik-style rules stay valid on the next deploy.
2026-07-19 01:42:12 -04:00
Jose Diaz-Gonzalez
f1f90233f6
Merge pull request #8841 from dokku/dependabot/docker/tests/apps/dockerfile-entrypoint/ruby-4.0.6
...
chore(deps): bump ruby from 4.0.5 to 4.0.6 in /tests/apps/dockerfile-entrypoint
2026-07-17 10:45:05 -04:00
dependabot[bot]
22718c10d7
chore(deps): bump google.golang.org/grpc in /tests/apps/gogrpc
...
Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go ) from 1.82.0 to 1.82.1.
- [Release notes](https://github.com/grpc/grpc-go/releases )
- [Commits](https://github.com/grpc/grpc-go/compare/v1.82.0...v1.82.1 )
---
updated-dependencies:
- dependency-name: google.golang.org/grpc
dependency-version: 1.82.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-16 13:52:23 +00:00
dependabot[bot]
90d76060fe
chore(deps): bump ruby in /tests/apps/dockerfile-entrypoint
...
Bumps ruby from 4.0.5 to 4.0.6.
---
updated-dependencies:
- dependency-name: ruby
dependency-version: 4.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-15 13:52:31 +00:00
Jose Diaz-Gonzalez
5496029e07
fix: parse cert CN and subject on OpenSSL 3.x
...
The `certs` plugin extracted a certificate's Common Name and formatted its subject using string assumptions that only held for pre-3.x OpenSSL output, so a certificate with only a Common Name and no Subject Alternative Name reported no hostnames from `certs:report` and was not recognized during nginx config generation, while the subject report retained the `subject=` prefix and used the wrong separators. Normalizing the subject with `-nameopt` before parsing makes the extraction version independent across OpenSSL and LibreSSL.
2026-07-10 15:05:27 -04:00
Jose Diaz-Gonzalez
7bd866efee
Merge pull request #8825 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-no-tini/golang-1.26.5
...
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-no-tini
2026-07-09 21:14:44 -04:00
Jose Diaz-Gonzalez
4205871cec
Merge pull request #8823 from dokku/dependabot/docker/tests/apps/zombies-dockerfile-tini/golang-1.26.5
...
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/zombies-dockerfile-tini
2026-07-09 21:14:36 -04:00
Jose Diaz-Gonzalez
16ba93f9e2
Merge pull request #8820 from dokku/dependabot/composer/tests/apps/php/heroku/heroku-buildpack-php-293
...
chore(deps-dev): bump heroku/heroku-buildpack-php from 292 to 293 in /tests/apps/php
2026-07-09 21:14:26 -04:00
Jose Diaz-Gonzalez
e2781c0553
Merge pull request #8821 from dokku/dependabot/docker/tests/apps/go-fail-predeploy/golang-1.26.5
...
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/go-fail-predeploy
2026-07-09 21:14:17 -04:00
Jose Diaz-Gonzalez
91025ee23e
Merge pull request #8822 from dokku/dependabot/docker/tests/apps/gogrpc/golang-1.26.5
...
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/gogrpc
2026-07-09 21:14:04 -04:00
dependabot[bot]
5ff86ec977
chore(deps): bump golang in /tests/apps/zombies-dockerfile-no-tini
...
Bumps golang from 1.26.4 to 1.26.5.
---
updated-dependencies:
- dependency-name: golang
dependency-version: 1.26.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 13:53:12 +00:00
dependabot[bot]
7e05d6cca4
chore(deps): bump golang in /tests/apps/go-fail-postdeploy
...
Bumps golang from 1.26.4 to 1.26.5.
---
updated-dependencies:
- dependency-name: golang
dependency-version: 1.26.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 13:53:05 +00:00
dependabot[bot]
58f509ed0c
chore(deps): bump golang in /tests/apps/zombies-dockerfile-tini
...
Bumps golang from 1.26.4 to 1.26.5.
---
updated-dependencies:
- dependency-name: golang
dependency-version: 1.26.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 13:52:57 +00:00
dependabot[bot]
5462744cf0
chore(deps): bump golang from 1.26.4 to 1.26.5 in /tests/apps/gogrpc
...
Bumps golang from 1.26.4 to 1.26.5.
---
updated-dependencies:
- dependency-name: golang
dependency-version: 1.26.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 13:52:57 +00:00
dependabot[bot]
ab14872c77
chore(deps): bump golang in /tests/apps/go-fail-predeploy
...
Bumps golang from 1.26.4 to 1.26.5.
---
updated-dependencies:
- dependency-name: golang
dependency-version: 1.26.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 13:52:38 +00:00
dependabot[bot]
01f3280746
chore(deps-dev): bump heroku/heroku-buildpack-php in /tests/apps/php
...
Bumps [heroku/heroku-buildpack-php](https://github.com/heroku/heroku-buildpack-php ) from 292 to 293.
- [Release notes](https://github.com/heroku/heroku-buildpack-php/releases )
- [Changelog](https://github.com/heroku/heroku-buildpack-php/blob/main/CHANGELOG.md )
- [Commits](https://github.com/heroku/heroku-buildpack-php/compare/v292...v293 )
---
updated-dependencies:
- dependency-name: heroku/heroku-buildpack-php
dependency-version: '293'
dependency-type: direct:development
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-09 13:52:36 +00:00
Jose Diaz-Gonzalez
611cb89711
Merge pull request #8805 from RichardDorian/master
...
Allow custom values for chown
2026-07-08 18:09:31 -04:00
Jose Diaz-Gonzalez
c37ba0f255
Merge pull request #8810 from dokku/8797-network-list-expose-whether-a-network-was-created-by-dokku
...
Expose whether a network was created by dokku
2026-07-08 14:52:32 -04:00
RichardDorian
513b200f5c
test(storage): add out-of-bounds chown coverage for go code and script
2026-07-08 19:38:08 +02:00
Jose Diaz-Gonzalez
ac4b86fd8e
feat: expose whether a network was created by dokku
...
`network:list` and `network:info` now expose a `DokkuManaged` boolean derived from the `com.dokku.network-name` label that `network:create` applies, and `network:list` gains a `--dokku-managed` flag to restrict output to dokku-created networks. This lets tooling distinguish networks dokku created from Docker built-ins and networks created by other tooling such as compose.
2026-07-08 00:03:29 -04:00
Jose Diaz-Gonzalez
1ee462dc3c
docs: document nginx validate-config load_module override
...
The nginx deploy-time pre-validation runs `nginx -t` against a minimal wrapper that omits the global `load_module` directives, so a custom `nginx.conf.sigil` using a directive from a dynamically loaded module fails validation even though it is valid against the running server. Document overriding the `validate-config` template through the `nginx-app-template-source` trigger as the supported workaround.
2026-07-07 23:33:59 -04:00
Jose Diaz-Gonzalez
24e3809a34
Merge pull request #8807 from dokku/8802-buildpacks-allow-setting-the-entire-ordered-buildpack-list-in-one-command
...
Allow replacing buildpack list atomically
2026-07-07 22:13:59 -04:00
Jose Diaz-Gonzalez
62164181e0
Merge pull request #8808 from dokku/8799-docker-options-report-expose-options-as-a-structured-list
...
Expose docker-options as structured lists in JSON report
2026-07-07 21:29:56 -04:00
Jose Diaz-Gonzalez
4652749b5b
feat: expose docker-options as structured lists in JSON report
...
Add parallel -list keys to docker-options:report --format json so export
tools can round-trip options without splitting space-joined strings.
Closes #8799
2026-07-07 19:49:17 -04:00
Jose Diaz-Gonzalez
16f8b25bda
feat: allow replacing buildpack list atomically
...
Add buildpacks:set --replace so callers can replace an app's complete ordered buildpack list in one command while preserving existing single-buildpack and --index behavior.
Closes #8802
2026-07-07 18:37:38 -04:00
Jose Diaz-Gonzalez
b2c4f61387
feat: expose scheduler-k3s autoscaling-auth state for read-back
...
Align autoscaling-auth:report with annotations and labels reporting so export tools can recover configured trigger auth via flat JSON keys and info flags, while stdout stays secret-safe unless --include-metadata is used.
Closes #8800
2026-07-07 18:07:39 -04:00
RichardDorian
a0361d59c1
test(storage): add unit test for custom chown values
2026-07-07 20:48:34 +02:00
Jose Diaz-Gonzalez
25b1356435
Merge pull request #8803 from dokku/dependabot/pip/tests/apps/dockerfile-release/django-5.2.16
...
chore(deps): bump django from 5.2.15 to 5.2.16 in /tests/apps/dockerfile-release
2026-07-07 12:18:52 -04:00
Jose Diaz-Gonzalez
cf15fb139e
Merge remote-tracking branch 'origin/master' into parallel-bash-reports
...
# Conflicts:
# go.work
2026-07-07 10:38:57 -04:00
dependabot[bot]
8a35ed337e
chore(deps): bump django in /tests/apps/dockerfile-release
...
Bumps [django](https://github.com/django/django ) from 5.2.15 to 5.2.16.
- [Commits](https://github.com/django/django/commits )
---
updated-dependencies:
- dependency-name: django
dependency-version: 5.2.16
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-07 13:54:29 +00:00
Jose Diaz-Gonzalez
8d0c36bad6
feat: port checks and domains :report subcommands to golang
...
The bash :report implementations for the checks and domains plugins are replaced with a compiled golang binary that collects report keys in parallel and marshals json directly. The domains global report header now matches the shared renderer used by every other golang report, and its bats assertion is updated accordingly.
2026-07-07 06:43:31 -04:00
Jose Diaz-Gonzalez
5faabea3d4
feat: port vhost proxy :report subcommands to golang
...
The bash :report implementations for the caddy, haproxy, openresty, and traefik proxy plugins are replaced with a compiled golang binary that collects report keys in parallel and marshals json directly. The traefik dns-provider values keep their masking behaviour, remaining hidden in the default stdout report while surfacing for --format json or an explicit flag query. These four plugins previously had no unit tests, so a bats suite covering the report matrix is added for each.
2026-07-07 06:29:01 -04:00
Jose Diaz-Gonzalez
9c819cfebc
feat: add --format json support to plugin:list
...
Adds a `--format json` flag to `plugin:list` whose output includes each plugin's install source - for git-based third-party plugins, the git remote URL, the checked-out commit, and the followed branch - so the set of installed plugins can be reconstructed elsewhere.
Closes #8798 .
2026-07-07 05:17:40 -04:00
Jose Diaz-Gonzalez
857d115fdd
feat: add --format json support to ps:scale
...
The `ps:scale` command now accepts a `--format` flag that defaults to `stdout` and can be set to `json` to emit the current formation as a JSON array of process type and quantity objects, matching the JSON output the `:report` subcommands already provide. The flag only applies when displaying the current formation; it is ignored when process types are supplied for scaling. When no scale has been set for the app, the JSON output is an empty array.
2026-07-06 13:57:19 -04:00
Jose Diaz-Gonzalez
21c27e99cc
feat: add --format json support to apps:list
...
The `apps:list` command now accepts a `--format` flag that defaults to `stdout` and can be set to `json` to emit the app names as a JSON array, matching the JSON output the `:report` subcommands already provide. When no apps exist, the JSON output is an empty array.
2026-07-06 11:50:56 -04:00