## bunkerity/bunkerweb — v1.6.15-rc1…v1.6.15-rc2

_121 commits._

### Features
- **feat(crowdsec): add investigation and decision management** (80ff4d5)
- **feat(reverseproxy): per-URL max client size** (2bbdda9)
- **feat(core): match a request header as an ignore or list criterion** (f61c038)
- **Merge pull request #3859 from teguh02/feat/add-indonesian-translation** (2744dad)
- **feat: add Indonesian (id) translation** (230fb63)

### Fixes
- **fix(ui): stop losing the chosen theme on load and on navigation** (4fe2bea)
- **fix(ui): allow XSS rule patterns in config editor** (6d381f2)
- **fix(backup,scheduler): bound the db.lock wait** (aa468de)
- **fix(db): repair stable upgrades to 1.6.15-rc2 and migration generation** (d3f0244)
- **perf(redis,ui,cli): cut Redis round trips per request and per UI call** (c58b69e)
- **fix(metrics,ui): refill reports after a Redis wipe** (27a8aa1)
- **fix(deps): keep poll()'s timeout contract when skipping lost events** (783dd75)
- **fix(deps): apply the mlcache ipc patch to the vendored source** (ba2a2f9)
- **fix(metrics): METRICS_REDIS_TTL=0 now strips TTLs** (9520495)
- **fix(deps): step over lost ipc events instead of stalling every request** (cf7f998)
- **fix(healthcheck): report the loading state on /healthz** (3a66001)
- **Merge pull request #3840 from 1t1sCooL/fix-readme-dead-links** (1609559)
- **fix(docker): pin libuuid to 2.42.3-r1 in every image** (4bac888)
- **fix(installer): verify Docker upgrades by image, health and stability, last-wins .env** (0d3532e)
- **fix(metrics): rebuild request facets once, keep pane counts, restore counters lazily** (b5da733)
- **fix(crowdsec): SHA-256 cache namespaces, direct LAPI ping, per-service captcha, health report** (c54c49e)
- **fix(mtls,letsencrypt,reverseproxy): fail closed on bad CA/CRL, quoted locations, scoped ACME** (0af49ac)
- **fix(scheduler): back off failed publications, publish once and restore caches transactionally** (63a7f6a)
- **fix(db,ui,api): DB-backed TOTP counter, service_convert permission, explicit empty template** (71f6550)
- **[#3866] fix(api,ui): report a service's settings the way they are rendered** (b8f59c5)
- **fix: update curl packages to address CVEs** (7fa90c6)
- **fix(headers): sync hardcoded Permissions-Policy copies to the plugin default** (6412019)
- **fix(modsecurity): require a .log suffix for MODSECURITY_SEC_AUDIT_LOG** (70dde89)
- **fix(reverseproxy): reject spaces and directive-injection characters in REVERSE_PROXY_URL** (89d489a)
- **fix(autoconf): per-watch health markers and validate REVERSE_PROXY_URL before render** (dbd98e8)
- **fix(crowdsec): derive cache prefixes from a URL hash, not sorted index** (eda5fa2)
- **fix(installer): refuse a same-core Docker downgrade and read DATABASE_URI last-wins** (da85ff6)
- **fix(i18n): translate the missing filtered-action, certificate-validation and id-only UI keys** (61d0046)
- **fix(ui): set the document language attribute from the active UI locale** (3e8d64c)
- **fix(ui): carry the expired-session notice to /setup and sync the Permissions-Policy header** (05d3502)
- **fix(ui): make the TOTP replay counter monotonic and atomic across gunicorn workers** (19981d4)
- **fix(modsecurity): retry the CRS plugin download and keep the previous plugin set on failure** (a92cc31)
- **fix(db): stop save_config draining its caller's payload and mask credentials in database logs** (dfa3273)
- **fix(cli): resolve DATABASE_URI from scheduler.env the way the scheduler does** (25e6cfc)
- **fix(config): keep a wrapped base64 value and a bare declaration out of each other in a variables file** (41f4871)
- **fix(scheduler): repair the pre-job push, the loading state and the cache sweep** (abb60b1)
- **fix(api): reject plugin ids in the push swap's reserved prefix** (1a76b29)
- **fix(api): store the applied push digest outside the pushed tree and serialize the swap with reload** (32a2985)
- **fix(scheduler): fix the folder-push timeouts and retry a busy instance** (462c1e8)
- **fix(api): keep the client result tuple total and add a write timeout for the body** (7a6bf2c)
- **fix(api): keep the parked copy when a push-swap rollback fails** (a0a2bb4)
- **fix(metrics): retry the cold start counter restore after a Redis failure** (0142ef5)
- **fix(datastore): warn when a write evicts an unexpired entry** (eb892f4)
- **fix(whitelist): ignore a service whose whitelist is disabled** (b4cb64f)
- **fix(lua): fall back to the global value in has_variable** (357dde0)
- **fix(letsencrypt): refuse a wildcard group that cannot cover every configured hostname** (4b5e27c)
- **fix(mtls): keep client verification enforced until the CA bundle is distributed** (1deba69)
- **fix(api): keep the instance hostname when retrying over HTTP** (adaa0f3)
- **fix(gen,ui): refuse embedded newlines in setting values** (f6800cb)
- **fix(api): use the global_config vocabulary in the Biscuit authorizer** (ca81f07)
- **fix(ui): keep the startup error detail out of the temp UI response** (e5b977f)
- **fix(linux): assign variables.env values without eval** (195af46)
- **fix: remove retired free-trial promo flow** (894f318)
- **fix(cli): use the configured DATABASE_URI, not the loading render's default** (d97f698)
- **fix(lua): memoize uncompilable regexes and name the offending setting** (a369147)
- **[#3838] fix(logs): rotate on every pass, keep 14 generations** (5670948)

### Backend
- **Merge pull request #3904 from bunkerity/dev** (6096544)
- **Merge pull request #3903 from bunkerity/dev** (112c0a8)
- **Merge pull request #3902 from bunkerity/dev** (c9f0910)
- **Merge pull request #3898 from bunkerity/dev** (6f03f37)
- **Merge pull request #3897 from bunkerity/dev** (61889c5)
- **Merge pull request #3890 from Ayushsinha322/docs/modsecurity-audit-log-parts-default** (dbf2797)
- **Merge pull request #3884 from bunkerity/dependabot/github_actions/dev/docker/setup-qemu-action-4.3.0** (ac7f95e)
- **Merge pull request #3883 from bunkerity/dependabot/github_actions/dev/pullfrog/pullfrog-0.1.68** (4337bce)
- **Merge pull request #3882 from bunkerity/dependabot/github_actions/dev/getplumber/plumber-0.4.52** (4960d83)
- **Merge pull request #3863 from bunkerity/dependabot/github_actions/dev/softprops/action-gh-release-3.0.3** (63f217a)
- **Merge branch 'dev' of https://github.com/bunkerity/bunkerweb into dev** (96ef7f8)
- **deps/gha: bump docker/setup-qemu-action from 3.7.0 to 4.3.0** (77208fe)
- **deps/gha: bump pullfrog/pullfrog from 0.1.67 to 0.1.68** (6c23000)
- **deps/gha: bump getplumber/plumber from 0.4.48 to 0.4.52** (c1c8329)
- **deps/gha: bump softprops/action-gh-release from 3.0.2 to 3.0.3** (99ed569)
- **Merge branch 'dev' of https://github.com/bunkerity/bunkerweb into dev** (bac6410)
- **Monthly mmdb update** (e38d566)
- **Release preparation for version 1.6.14** — This is a comprehensive development merge preparing the codebase for version 1.6.14, including workflow optimizations, documentation updates across multiple languages, dependency management improvements, and bug fixes. Changes span CI/CD pipelines, Docker configurations, API documentation, and infrastructure setup files. (6a90674)

### Docs
- **docs(plugins): update official plugins to 1.12** (eadfb72)
- **docs(changelog): update release notes** (0e61523)
- **docs(pro): add maintenance docs** (5daa37f)
- **docs(changelog): thank docs contributor** (c23710d)
- **docs: resolve audit log merge conflicts** (36595b9)
- **docs: correct documented default for MODSECURITY_SEC_AUDIT_LOG_PARTS** (fc9e116)
- **docs(readme): pin the Linux docs link** (5f3511d)
- **docs(changelog): v1.6.15~rc2 entries** (f1d753f)
- **docs(features): sync the mTLS, reverse proxy, ModSecurity, metrics and CrowdSec rows** (394a4d9)
- **docs(metrics,crowdsec): sync locale READMEs with the English source** (3c34dc5)
- **docs(integrations): document KEEP_CONFIG_ON_RESTART and correct two overstated settings** (52d47d2)
- **docs(ci): fix plumber README's stale master workflow reference** (c4b7df1)
- **docs(kubernetes): port the API_TOKEN guidance to all locales** (6ca4209)
- **docs(kubernetes): require API_TOKEN and narrow the API whitelist** (dffaad7)
- **docs: document Grafana and Zabbix integrations** (1426b83)
- **docs: document Grafana and Zabbix integrations** (e4a1bc2)
- **docs(readme): fix dead links (versioned docs, Cloud page)** (75ac5cb)

### Chore
- **ci(release): build candidates Docker Hub can actually accept** (2c14c46)
- **ci(release): stop a single flake from costing a whole rebuild** (1a901a2)
- **ci(release): rename candidate validation job** (3cc9d29)
- **ci(arm): fail the ARM node job when Docker install fails** (6be10db)
- **ci(staging): move image smoke checks upstream** (28d2f0f)
- **chore(deps): Refresh Python dependency pins and lockfile hashes** (40afc1b)
- **chore(docker): Update pinned Docker base image digests** (b12780f)
- **ci(release): assert every version pin matches src/VERSION** (7a36ddc)
- **chore(release): propagate the 1.6.15~rc2 bump** (39f87c7)
- **chore(tests): Update Kubernetes DNS resolver for Scaleway Kapsule** (41c48e5)
- **ci(release): accept self-review from the release owners** (6e1de37)
- **chore(release): bump to 1.6.15~rc2, update the changelog and upgrade notes** (6671364)
- **ci(release): build candidates once, test the exact artifacts per platform, promote by digest** (a3394b4)
- **ci: add restricted Pullfrog workflow** (02d2702)
- **ci: mirror dev and testing images to GitLab** (c860001)
- **ci: publish release images directly to the GitLab mirror** (5cc901e)
- **build: pin a nodejs/npm floor in the Alpine minify builders and the AIO OpenSSL CVE floor** (451aae9)
- **ci: stop persisting checkout credentials** (d8a8350)
- **build: patch expat CVEs in container images** (b6dc6c7)
- **chore(i18n): Improve Indonesian UI translations** (f0f5b41)
- **chore(crowdsec): update CrowdSec to v1.8.0** (5c65de1)
- **chore(ui): move Indonesian to its place in the language picker order** (0900499)
- **chore: Improve issue templates with affected area and duplicate checks** (61f7cdd)
- **chore: Update pinned Docker base image digests** (bd1d018)
- **ci(release): require a verifiable signature on release tags** (a18a93a)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/bunkerity/bunkerweb?utm_source=github-action)._