Dokploy v0.29.13

v0.29.13
Fixed 5
  • Validate API key name length to prevent opaque 500 errors
  • Preserve named-volume access mode when adding suffix in compose
  • Disambiguate repos with the same name in the repository selector
  • Allow clearing the server domain in settings
  • Fix UI typos
Security 15
  • Fix OS command injection in git clone across all providers
  • Fix git provider credential disclosure via cross-org IDOR (.one endpoints)
  • Fix SSH private key disclosure via server read endpoints
  • Fix cross-org IDOR and nodeId injection in swarm read endpoints
  • Fix git provider secret disclosure via application.one
  • Fix OS command injection in docker build/pull commands
What's Changed
New Contributors

Full Changelog: https://github.com/Dokploy/dokploy/compare/v0.29.12...v0.29.13

View original

Upgraded? How did it go?

Discussion