Glances

Developer ToolsDesktop

A cross-platform system monitor that adapts what it shows to the terminal size.

Latest v4.5.6 · · Desktopby Nicolas HennionWebsitenicolargo/glances

Release activity

Release activity — 10 releases across 10 days since Oct 8, 2025. Each cell is one day; darker means more releases that day. Nothing is recorded before Oct 8, 2025. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026
MondayNo releases on Apr 27, 2026No releases on May 4, 2026No releases on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026
TuesdayNo releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 2026No releases on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026
WednesdayNo releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 2026No releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 20261 release on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 20261 release on Aug 1, 2026No releases on Aug 8, 2026

10 releases since Oct 8, 2025

Changelog

v4.5.6

Glances 4.5.6

Fixed 7
  • Alert level decided by dict ordering: a failing+slow URL is downgraded to WARNING, an unscanned URL reports CRITICAL
  • GPU plugin duplicates card name and omits N/A for unavailable metrics in multi-GPU
  • GPU plugin duplicates the utilisation value and paints it with the memory colour in multi-GPU
  • IP plugin displays wrong interface: outer loop in get_ip_address() never breaks
  • VideoCore (v3d) memory shows ~93% on Raspberry Pi 5 with gpu_mem=4M — misleading denominator from drm-total-memory
  • CSV export: --stdout-csv data rows desync from header when network interfaces change count at runtime
  • Glances Network plugin with mismatched schema not logging in TimescaleDB export
Security 5
  • Value-Level Bypass in as_dict_secure() leaks credentials in URL values via /api/4/config
  • --disable-config-exec does not cover on-alert action commands
  • Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction
  • Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values
  • REST API CORS Credentials Guard uses exact-match instead of membership test

Bugs corrected:

  • Alert level decided by dict ordering: a failing+slow URL is downgraded to WARNING, an unscanned URL reports CRITICAL #3632
  • GPU plugin duplicates card name and omits N/A for unavailable metrics in multi-GPU #3631
  • GPU plugin duplicates the utilisation value and paints it with the memory colour in multi-GPU #3630
  • IP plugin displays wrong interface: outer loop in get_ip_address() never breaks #3617
  • VideoCore (v3d) memory shows ~93% on Raspberry Pi 5 with gpu_mem=4M — misleading denominator from drm-total-memory #3611
  • CSV export: --stdout-csv data rows desync from header when network interfaces change count at runtime #3606
  • Glances Network plugin with mismatched schema not logging in TimescaleDB export #3592

Security patches:

  • as_dict_secure() Value-Level Bypass Leaks Credentials in URL Values via /api/4/config - CVE-2026-68520
  • --disable-config-exec does not cover on-alert action commands - CVE-2026-68519
  • Command injection bypass of action-template sanitizer via cross-field shell-operator reconstruction - CVE-2026-68518
  • Incomplete fix of CVE-2026-32608: action-template sanitizer is bypassed by nested stat values - CVE-2026-62982
  • REST API CORS Credentials Guard Uses Exact-Match Instead of Membership Test - CVE-2026-68517

Thanks to all the contributors for this version: yogendrarau, Gabriel Changamire, Sanjay Santhanam, William Wu, Martin Ďurana and Noa Levi.

View originalPermalink
How v4.5.6 went
v4.5.5

Glances 4.5.5

Added 4
  • Meter for CPU and MEM of GPU in the Quicklook plugin
  • CPU limit to docker, podman and lxd containers
  • GPU Monitoring for ARM / RaspberryPi
  • GPU plugin: display proc and temperature on NVIDIA Jetson (Tegra) integrated
Changed 2
  • Glances Alpine Docker images are now based on Alpine 3.24
  • Glances Ubuntu Docker images are now based on Ubuntu 26.04
Fixed 9
  • /api/4/containers performance issue with ~60 Docker containers
  • Crash when using --sparkline
  • VMs section does not show LOAD 1/5/15min values
  • AMD GPU detection for multi-digit DRM card numbers
  • Keep auto_unit within limits so columns stay aligned
  • Rest status check shouldn't require auth
Security 5
  • Fix arbitrary file write and command execution in AMP command configuration (CVE-2026-53925)
  • Fix XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack (CVE-2026-46611)
  • Fix XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (CVE-2026-46608)
  • Fix Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution (CVE-2026-46607)
  • Fix Command Injection via KVM/QEMU VM Domain Names in virsh.py (CVE-2026-46606)

Bugs corrected:

  • /api/4/containers stays ~4-5s with ~60 Docker containers #3559
  • Crash when using --sparkline #3547
  • VMs section does not show LOAD 1/5/15min values #3535
  • Fix AMD GPU detection for multi-digit DRM card numbers #3578
  • Keep auto_unit within limits, so columns stay aligned #3558
  • Rest status check shouldn't require auth #3544
  • Logging configuration to use boolean value #3536
  • Fix filesystem aliases for mixed-case mount points #3532
  • Regression in Disk I/O reporting #3546

Enhancements:

  • Add meter for CPU and MEM of GPU in the Quicklook plugin #1711
  • Add cpu limit to docker, podman and lxd containers #3557
  • GPU Monitoring (ARM / RaspberryPi) #1048
  • GPU plugin: display proc and temperature on NVIDIA Jetson (Tegra) integrated #3580

Security patches:

  • Arbitrary file write and command execution in AMP command configuration - Correct CVE-2026-53925
  • XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack - Correct CVE-2026-46611
  • XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard - Correct CVE-2026-46608
  • Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution - Correct CVE-2026-46607
  • Command Injection via KVM/QEMU VM Domain Names in virsh.py - Correct CVE-2026-46606

Continious integration, refactoring and documentation:

  • Add top 10 slowest plugins summary at end of --issue output #3572
  • Update documentation for hide/show #3546
  • Refactor: Improve load_additional_plugins Maintainability, Safety, and Plugin Discovery #3561
  • Refactor: Reduce Cyclomatic complexity of __display_top Issue #3549
  • Refactor: Reduce Cyclomatic complexity of display_popup() #3542
  • Refactor: Compute spacing
  • Refactor: handle quicklook required for display²
  • Refactor: Get plugin Width & get stats summary
  • Add unit test to containers/docker plugin

Packaging:

  • Glances Alpine Docker images are now based on Alpine 3.24
  • Glances Ubuntu Docker images are now based on Ubuntu 26.04

Thanks to all the contributors for this version: 20086080, cswaltzinger, Sergio LIVI, Adi, Ariel Eli, Gabriel St. Angel, Jack Harper, Tarrailt, William Wu, Yan and lawrence3699.

View originalPermalink
How v4.5.5 went
v4.5.4

Glances 4.5.4

Added 1
  • Add Rockchip MPP plugin for hardware encoder/decoder monitoring
Changed 2
  • Clamp memory used/percent to non-negative values for LXC containers
  • Support single-core Rockchip NPU load parsing and improve device naming
Fixed 4
  • Cannot set warning/critical temperature for a specific sensor
  • Memory percentage and used displayed as negative numbers
  • Incorrect Docker container count via Homeassistant Integration
  • Fix LXD filter excluding containers on standalone hosts
Security 3
  • Correct SSRF in Glances IP Plugin via public_api that leads to credential leakage (CVE-2026-35587)
  • Correct Cross-Origin Information Disclosure via Unauthenticated REST API /api/4 (CVE-2026-34839)
  • Validate keyspace/table/replication_factor in Cassandra plugin to prevent CQL injection (CVE-2026-35588)

Bug corrected:

  • Cannot set warning/critical temperature for a specific sensor #3525
  • Memory percentage and used displayed as negative numbers #3358
  • Incorrect Docker container count via Homeassistant Integration #3433
  • Fix LXD filter excluding containers on standalone hosts #3529

Enhancements:

  • Add Rockchip MPP plugin for hardware encoder/decoder monitoring #3514
  • Clamp memory used/percent to non-negative values for LXC containers #3505
  • Support single-core Rockchip NPU load parsing and improve device naming #3499

Security patches:

  • SSRF in Glances IP Plugin via public_api leads to credential leakage - Correct CVE-2026-35587
  • Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) - Correct CVE-2026-34839
  • fix(cassandra): validate keyspace/table/replication_factor to prevent CQL injection - Correct CVE-2026-35588 #3520

Continious integration and documentation:

  • pycache file is put in wheel #3516
  • Remove dead code #3507

Thanks to all the contributors for this version: csvke, Christian Rishøj, duriantaco, Julio César Suástegui, Paul and morimori-dev.

View originalPermalink
How v4.5.4 went
v4.5.3

Glances 4.5.3

Added 2
  • Support for LXC/LXD containers
  • Add export to ClickHouse
Fixed 3
  • Internal Server Error in Web Server Mode
  • Container plugin crashes with docker.errors.NullResource on Podman pod infra containers
  • ALERTS sometimes showing incorrect top process list
Security 2
  • Mitigate Command Injection via Dynamic Configuration Values (CVE-2026-33641)
  • Mitigate Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard (CVE-2026-33533)

Bug corrected:

  • Internal Server Error (Web Server Mode) #3502
  • Container plugin crashes with docker.errors.NullResource on Podman pod infra containers #3498
  • [ALERTS] Sometime the top process list is not the good one #3481

Enhancements:

  • Support for LXC/LXD containers #3480
  • Add export to ClickHouse #3320

Security patches:

  • Command Injection via Dynamic Configuration Values - Mitigate CVE-2026-33641
  • Cross-Origin System Information Disclosure via XML-RPC Server CORS Wildcard - Mitigate CVE-2026-33533

Continious integration and documentation:

  • Use sys.executable in the testsuite #3497
  • Add unit tests for LXD container engine #3487
  • Replace Py-Spy per Memray for FlameGraph generation
  • Make the WebUI build before the packages and Docker images build
  • Harden GitHub Actions workflows: minimal permissions, SHA pins, timeouts

Thanks to all the contributors for this version: Christian Rishøj, Jeongwoo Kim, Ofek Gabay, Steve Kowalik, Tanishq Shah, Mithun M.

View originalPermalink
How v4.5.3 went
v4.5.2

Glances 4.5.2

Fixed 1
  • System display error on little terminal
Security 8
  • Default CORS Configuration Allows Cross-Origin Credential Theft - Correct CVE-2026-32610
  • Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials - Correct CVE-2026-32609
  • REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding - Correct CVE-2026-32632
  • Unauthenticated API Exposure / Add warning message on startup - Correct CVE-2026-32596
  • SQL Injection in DuckDB Export via Unparameterized DDL Statements - Correct CVE-2026-32611
  • Command Injection via Process Names in Action Command Templates - Correct CVE-2026-32608
  • Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers - Correct CVE-2026-32634
  • Browser API Exposes Reusable Downstream Credentials - Correct CVE-2026-32633
Bug corrected
  • System display error on "little" terminal #3469
Security patches
  • Default CORS Configuration Allows Cross-Origin Credential Theft - Correct CVE-2026-32610
  • Incomplete Secrets Redaction: /api/v4/args Endpoint Leaks Password Hash and SNMP Credentials - Correct CVE-2026-32609
  • REST/WebUI Lacks Host Validation and Remains Exposed to DNS Rebinding - Correct CVE-2026-32632
  • Unauthenticated API Exposure / Add warning message on startup - Correct CVE-2026-32596
  • SQL Injection in DuckDB Export via Unparameterized DDL Statements - Correct CVE-2026-32611
  • Command Injection via Process Names in Action Command Templates - Correct CVE-2026-32608
  • Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed Servers - Correct CVE-2026-32634
  • Browser API Exposes Reusable Downstream Credentials via - Correct CVE-2026-32633
Breaking changes

This release addresses 8 security vulnerabilities (see below). Several of the mitigations change observable behaviour. Users who run Glances in web server or API mode (-w / --enable-webserver) should read the items below before upgrading.

CVE-2026-32632 Host header validation is now enforced on the built-in web server. Requests whose Host header does not match localhost or 127.0.0.1 will be rejected with HTTP 400 by default. Users accessing Glances through a reverse proxy, a custom hostname, or a non-loopback IP address must declare the allowed values with the new allowed_hosts key in the [outputs] section of glances.conf (comma-separated list). This was already required for the MCP server since 4.5.1; it now also applies to the main REST/WebUI server.

CVE-2026-32610 The default CORS policy is now restrictive. Previously, the server replied with Access-Control-Allow-Origin: * which allowed any web page to issue credentialed cross-origin requests against the API. The wildcard is removed. Users running third-party web dashboards or custom front-ends on a different origin must explicitly list allowed origins with the cors_origins key in the [outputs] section of glances.conf.

CVE-2026-32609 Sensitive fields are now redacted on unauthenticated API responses. The /api/4/args and /api/4/config endpoints no longer return password hashes, SSL key paths, or SNMP community strings to callers that have not authenticated. Scripts and integrations that relied on reading these values from the API must now authenticate (token or password) to receive them.

CVE-2026-32633 and CVE-2026-32634 The Browser (multi-server mode) no longer forwards configured credentials to remote Glances servers, whether discovered via Zeroconf or listed in the [serverlist] section. Credentials are only sent after the user explicitly logs in to an individual server. Automated setups that relied on transparent credential propagation must switch to per-server authentication.

CVE-2026-32596 A WARNING is now printed to stdout at startup when the REST API is running without authentication (no --password and no API token configured). This is an informational message; the unauthenticated mode itself is unchanged and remains the default for private-network deployments. Startup scripts or monitoring pipelines that treat any stderr/stdout output as a failure may need to be updated.

CVE-2026-32611 The DuckDB export module now uses parameterized DDL statements. Table names derived from plugin or metric names are sanitized before use. Existing DuckDB databases whose table names contained characters that were previously interpolated verbatim may need to be recreated.

CVE-2026-32608 Process names used in [action] command templates are now shell-escaped before substitution. Templates that relied on unescaped special characters in process names to construct compound shell expressions will no longer behave as before.

Thanks to @psyberck for the UI patch and @DhiyaneshGeek / @restriction for CVEs reports.

View originalPermalink
How v4.5.2 went
v4.5.1

Glances 4.5.1

Added 4
  • Add Intel GPU monitoring support in the GPU plugin
  • Add Docker container health status and alert integration in containers plugin
  • Add libvirt-client toolchain to official Glances Docker image for VM plugin KVM/QEMU discovery
  • Add DeviceName key to SMART plugin device entries for unambiguous device identification in exports
Fixed 9
  • Fix DiskIO plugin crash on OpenBSD caused by unguarded attribute access in msg_curse()
  • Fix TypeError in DiskIO plugin when args is not populated in msg_curse()
  • Fix KeyError in Filesystem plugin when accessing bind-mounted or virtual paths like /etc/hostname
  • Fix sensor show/hide filtering by alias name in configuration file
  • Fix TypeError in SMART plugin with InfluxDB2 export caused by non-uniform key types
  • Fix Fahrenheit temperature display in WebUI

Release date: March 2026
Milestone: [#91](https://github.com/nicolargo/glances/milestone/91?closed=1)
21 issues & pull requests closed


Overview

Glances 4.5.1 is a stability and quality release that addresses regressions introduced in the 4.5.0.x series, fixes cross-platform compatibility issues (OpenBSD, macOS, Snap), and ships several community-driven enhancements — most notably Intel GPU monitoring, Docker container health alerting, and per-plugin min/max/mean statistics.


🐛 Bug Fixes
Plugins
  • DiskIO — crash on OpenBSD ([#3452](https://github.com/nicolargo/glances/issues/3452))
    A regression introduced in 4.5.0.5 caused Glances to crash on OpenBSD when the DiskIO plugin was active. The root cause was an unguarded attribute access in msg_curse(). Fixed and covered by an additional test case.

  • DiskIO — empty args not handled in msg_curse() ([#3429](https://github.com/nicolargo/glances/issues/3429))
    A TypeError would be raised in specific runtime configurations where args was not yet populated when msg_curse() was called. A safe default is now enforced.

  • Filesystem — KeyError: '/etc/hostname' on get_view ([#3470](https://github.com/nicolargo/glances/issues/3470))
    Certain bind-mounted or virtual paths (e.g. /etc/hostname inside containers) could trigger a KeyError in the FS plugin's view logic. The lookup is now guarded with a safe fallback.

  • Sensors — show/hide by alias name broken ([#3439](https://github.com/nicolargo/glances/issues/3439))
    Filtering sensors by alias name via the configuration file had no effect in some configurations. Sensor aliasing and the associated hide/show logic are now correctly applied together.

  • SMART — non-uniform key types cause TypeError with InfluxDB2 export ([#3449](https://github.com/nicolargo/glances/issues/3449))
    Mixed integer/string key types in the SMART plugin's device stats dict were causing a TypeError when exporting to InfluxDB2. Key types are now normalized before export.

Web UI
  • Fahrenheit display incorrect in WebUI ([#3450](https://github.com/nicolargo/glances/issues/3450))
    Temperature values were not properly converted to Fahrenheit in the Web UI when the --fahrenheit option was set. The unit conversion is now applied consistently on the frontend side.
Snap Packaging
  • AMD GPU plugin: PermissionError on /usr/share/libdrm/amdgpu.ids ([#3456](https://github.com/nicolargo/glances/issues/3456))
    Glances packaged as a Snap would refuse to start on systems with an AMD GPU because the GPU plugin attempted to open a file outside the Snap sandbox. The exception is now caught at the correct level (open() rather than f.read()), preventing the crash at startup.

  • NVIDIA GPU not detected under Snap ([#3292](https://github.com/nicolargo/glances/issues/3292))
    The Snap package was missing the opengl interface declaration in snapcraft.yaml, preventing the NVIDIA GPU plugin from accessing the required device nodes under strict confinement. The interface is now correctly declared.

MCP Server
  • DNS rebinding protection blocks external MCP clients ([#3467](https://github.com/nicolargo/glances/issues/3467))
    The MCP server was rejecting connections from external hosts because the underlying SSE transport's DNS rebinding protection only allowed localhost by default. A new mcp_allowed_hosts configuration key (parsed in GlancesRestfulApi.load_config() and forwarded via TransportSecuritySettings) lets operators explicitly whitelist external hostnames, following the same pattern as cors_origins.

✨ Enhancements
Intel GPU Monitoring ([#994](https://github.com/nicolargo/glances/issues/994))

Intel GPU metrics are now supported in the GPU plugin, closing a long-standing feature request. The implementation follows the multi-vendor reader architecture, joining the existing NVIDIA and AMD backends.

Docker Container Health Status & Alerts ([#3402](https://github.com/nicolargo/glances/issues/3402))

The containers plugin now surfaces Docker's native health check status (healthy, unhealthy, starting) and integrates it with Glances' alert system so that unhealthy containers trigger visible warnings in the TUI and API.

VM Plugin — libvirt Support in Docker Image ([#3427](https://github.com/nicolargo/glances/issues/3427) / [#3436](https://github.com/nicolargo/glances/issues/3436))

The official Glances Docker image now includes the libvirt-client toolchain, enabling the VMs plugin to discover and monitor KVM/QEMU virtual machines when the host's libvirt socket is bind-mounted into the container.

SMART Plugin — DeviceName Key Added ([#3457](https://github.com/nicolargo/glances/pull/3457))

Each SMART device entry now carries an explicit DeviceName field, making device identification unambiguous in exports (InfluxDB, CSV, etc.) and the REST API.

Per-Plugin Min / Max / Mean Statistics ([#3462](https://github.com/nicolargo/glances/pull/3462))

All plugins now compute and expose min, max, and mean values accumulated since Glances startup. These aggregate metrics are available via the REST API and can be used for lightweight trend analysis without requiring a full time-series export stack.

CPU Plugin — Improved Display on macOS ([#3464](https://github.com/nicolargo/glances/issues/3464))

The CPU plugin's TUI and WebUI rendering has been improved for macOS, where certain fields (e.g. steal, guest) are not available. The layout now adapts gracefully to the subset of metrics exposed by the platform rather than showing empty or misleading columns.

History — --enable-history Flag Restored ([#3416](https://github.com/nicolargo/glances/issues/3416))

The --enable-history CLI flag was silently ignored in recent releases. It is now correctly wired to the graph export backend, restoring the ability to write per-plugin time-series data to disk from the command line.


🔧 Code Quality & Refactoring
  • JSON serializer hardened ([#3454](https://github.com/nicolargo/glances/pull/3454))
    The internal JSON serializer now performs comprehensive type normalization (e.g. numpy scalars, Decimal, non-serializable objects) before encoding, preventing silent data corruption or export failures. Covered by a new test suite.

  • split_esc cyclomatic complexity reduced ([#3461](https://github.com/nicolargo/glances/pull/3461))
    The split_esc() utility function in glances_globals was refactored to lower its cyclomatic complexity, improving readability and reducing the risk of regressions in escape-sequence parsing.

  • Plugin tests added to Makefile ([#3446](https://github.com/nicolargo/glances/pull/3446))
    Individual plugin test targets are now available via make test-plugins, making it easier for contributors and CI pipelines to run focused plugin-level regression checks.


📖 Documentation

Upgrade Notes

This is a drop-in replacement for 4.5.0.x. No configuration file changes are required unless you want to take advantage of the new mcp_allowed_hosts option.

Snap users are strongly encouraged to upgrade: the AMD GPU startup crash and the NVIDIA GPU detection fix are both included and require no manual intervention beyond refreshing the snap package.


Contributors

Many thanks to all the contributors who reported issues and submitted pull requests for this release:

[@YamiYukiSenpai](https://github.com/YamiYukiSenpai), [@amzon-ex](https://github.com/amzon-ex), [@axodentally](https://github.com/axodentally), [@fpusan](https://github.com/fpusan), [@janusn](https://github.com/janusn), [@kleinmatic](https://github.com/kleinmatic), [@lcheylus](https://github.com/lcheylus), [@lubomir-moric](https://github.com/lubomir-moric), [@mark-rahal](https://github.com/mark-rahal), [@mikemhenry](https://github.com/mikemhenry), [@Ambika-Patidar](https://github.com/Ambika-Patidar), [@AbdelhamidKhald](https://github.com/AbdelhamidKhald), [@Julietmgbole](https://github.com/Julietmgbole), [@sdoshi2061](https://github.com/sdoshi2061), [@cjlindem](https://github.com/cjlindem)


Full changelog: https://github.com/nicolargo/glances/milestone/91?closed=1

View originalPermalink
How v4.5.1 went
v4.5.0

Glances 4.5.0

Added 8
  • Add native support for ZFS filesystem monitoring
  • Add Neural Processing Unit (NPU) performance monitoring
  • Add enhanced monitoring for NVMe drives
  • Add DuckDB export option
  • Add CPU core assignment display in process list to show which CPU core each process is running on
  • Add API token authentication to secure RestfulAPI server
  • Add comprehensive unit tests for core plugins
  • Add Jupyter notebook documentation for the Glances API
Changed 2
  • Improve GPU name detection from amdgpu.ids
  • Update license to SPDX format
Fixed 10
  • Fix CPU speed and max speed display issues in WebUI
  • Fix TIME+ column showing incorrect large values in WebUI
  • Fix KeyError: 'used' exception in ASGI application
  • Fix InfluxDB export type mismatches for AMPs
  • Fix Quicklook behavior when psutil.cpu_freq().max equals 0.0
  • Fix SNMP discovery with -c parameter

Warning: Glances 4.5.0 has been removed and replaced by Glances 4.5.0.1.

I'm excited to announce the release of Glances 4.5.0, featuring 40 completed issues and pull requests! This release brings significant new features, important bug fixes, and major improvements to stability and security.

🆕 New Features

Advanced Monitoring Capabilities:

  • ZFS Monitoring - Native support for ZFS filesystem monitoring
  • NPU Monitoring - Track Neural Processing Unit performance
  • NVMe Support - Enhanced monitoring for NVMe drives
  • DuckDB Export - New export option to DuckDB database
  • CPU Core Assignment - See which CPU core each process is running on in the process list

Security & API:

  • API Token Authentication - Secure your RestfulAPI server with token-based authentication
  • Security Hardening - Fixed Jinja2 and timeout vulnerabilities (B701, B113)
  • Clear-text logging fix - Improved handling of sensitive information in logs
🐛 Major Bug Fixes
  • Fixed CPU speed/max speed display issues in WebUI
  • Corrected TIME+ showing incorrect large values in WebUI
  • Resolved KeyError: 'used' exception in ASGI application
  • Fixed InfluxDB export type mismatches for AMPs
  • Corrected Quicklook behavior when psutil.cpu_freq().max=0.0
  • Fixed SNMP discovery with -c parameter
  • Resolved fetch option incompatibility with client/server mode
✨ Improvements
  • Code Quality - Significant code complexity reduction and refactoring
  • AMD GPU Support - Better GPU name detection from amdgpu.ids
  • Docker - Improved build pipeline
  • UI/UX - Removed empty space issues with Quicklook plugin
  • Testing - Added comprehensive unit tests for core plugins
  • Documentation - New Jupyter notebook for the Glances API
  • Packaging - Updated license to SPDX format
📦 Get It Now
pip install --upgrade glances

Or pull the latest Docker image:

docker pull nicolargo/glances:latest

Full changelog available on the [GitHub milestone page](https://github.com/nicolargo/glances/milestone/88?closed=1).

Special thanks to all contributors who made this release possible! 🙏

As always, feedback and bug reports are welcome on our [GitHub issues page](https://github.com/nicolargo/glances/issues).


Note: If you find Glances useful, consider [sponsoring the project](https://github.com/sponsors/nicolargo) to support its continued development!

View originalPermalink
How v4.5.0 went
v4.4.0

Glances 4.4.0

Added 5
  • New Python API available to use Glances as a Python library in your own development
  • Add a new --fetch option to display a snapshot of the current system status
  • Show used port in container section
  • Add Disk I/O Latency stats
  • Add experimental export to DuckDB database
Changed 8
  • Process list long command line is now truncated by default, use arrow keys to show the full command line
  • SHIFT + arrow keys are used to switch between column sorts in TUI
  • Prometheus export format is now more user friendly
  • Sensors plugin refresh by default every 10 seconds
  • Do not call update if a call is done to a specific plugin through the API
  • Process virtual memory display can be disabled by configuration
  • Choose between used or available in the mem plugin
  • Filter fields to export
Fixed 7
  • Glances not showing processes on macOS
  • Last dev build broke Homepage API calls
  • Cloud plugin always generating communication with 169.254.169.254 even if the plugin is disabled
  • API response delay when VMs are running
  • Glances does not display CPU stats correctly on Windows
  • Glances hangs if network device is not available
  • Glances crashes when trying to filter on macOS
What's Changed

Breaking changes:

  • A new Python API is now available to use Glances as a Python lib in your hown development #3237
  • In the process list, the long command line is now truncated by default. Use the arrow keys to show the full command line. SHIFT + arrow keys are used to switch between column sorts (TUI).
  • Prometheus export format is now more user friendly (see detail in #3283)

Enhancements:

  • Make a Glances API in order to use Glances as a Python lib #3237
  • Add a new --fetch (neofetch like) option to display a snapshot of the current system status #3281
  • Show used port in container section #2054
  • Show long command line with arrow key #1553
  • Sensors plugin refresh by default every 10 seconds
  • Do not call update if a call is done to a specific plugin through the API #3033
  • [UI] Process virtual memory display can be disable by configuration #3299
  • Choose between used or available in the mem plugin #3288
  • [Experimental] Add export to DuckDB database #3205
  • Add Disk I/O Latency stats #1070
  • Filter fields to export #3258
  • Remove .keys() from loops over dicts #3253
  • Remove iterator helpers #3252

Bug corrected:

  • [MACOS] Glances not showing Processes on MacOS #3100
  • Last dev build broke Homepage API calls ? only 1 widget still working #3322
  • Cloud plugin always generate communication with 169.254.169.254, even if the plugin is disabled #3316
  • API response delay (3+ minutes) when VMs are running #3317
  • [WINDOWS] Glances do not display CPU stat correctly #3155
  • Glances hangs if network device (NFS) is no available #3290
  • Fix prometheus export format #3283
  • Issue #3279 zfs cache and memory math issues #3289
  • [MACOS] Glances crashes when I try to filter #3266
  • Glances hang when killing process with muliple CTRL-C #3264
  • Issues after disabling system and processcount plugins #3248
  • Headers missing from predefined fields in TUI browser machine list #3250
  • Add another check for the famous Netifaces issue - Related to #3219
  • Key error 'type' in server_list_static.py (load_server_list) #3247

Continuous integration and documentation:

  • Glances now use uv for the dev environment #3025
  • Glances is compatible with Python 3.14 #3319
  • Glances provides requirements files with specific versions for each release
  • Requirements files are now generated dynamically with the make requirements or requirements-upgrade target
  • Add duplicate line check in pre-commit (strange behavor with some VScode extension)
  • Solve issue with multiprocessing exception with Snap package
  • Add a test script for identify CPU consumption of sensor plugin
  • Refactor port to take into account netifaces2
  • Correct issue with Chrome driver in WebUI unit test
  • Upgrade export test with InfluxDB 1.12
  • Fix typo of --export-process-filter help message #3314
  • In the outdated feature, catch error message if Pypi server not reachable
  • Add unit test for auto_unit
  • Label error in docs #3286
  • Put WebUI conf generator in a dedicated script
  • Refactor the Makefile to generate WebUI config file for all webui targets
  • Update sensors documentation #3275
  • Update docker compose env quote #3273
  • Update docker-compose.yml #3249
  • Update API doc generation
  • Update README with nice icons #3236
  • Add documentation for WebUI test
New Contributors

Full Changelog: https://github.com/nicolargo/glances/compare/v4.3.3...v4.4.0

View originalPermalink
How v4.4.0 went
v4.3.3

Glances 4.3.3

Changed 2
  • Change 'Pinned thread' to 'Pinned task' and 'Upin' to 'Unpin'
  • Update plugin containers display and order
Fixed 4
  • Ignore unsupported line endings in password file
  • Fix matching problem when fs config has 'show' value
  • Fix the sorting of containers
  • Fix a race condition in namedtuple_to_dict
Security 2
  • Security upgrade h11 from 0.14.0 to 0.16.0
  • Fix for 8 vulnerabilities
What's Changed
New Contributors

Full Changelog: https://github.com/nicolargo/glances/compare/v4.3.2...v4.3.3

View originalPermalink
How v4.3.3 went
View all

Discussion