Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • N8N Security

    Discuss
    8
    2 Votes
    8 Posts
    415 Views
    J
    That’s a great point about the automated scrapes. Even if it's 'security by obscurity,' sometimes just not being an obvious target is half the battle! I’m really looking forward to the per-app IP whitelisting mentioned here - that seems like the most solid way to handle this without breaking the external webhooks. In the meantime, the OIDC workaround looks like a solid stopgap to at least add an extra layer.
  • Immich - Package Updates

    Pinned Immich
    225
    1 Votes
    225 Posts
    149k Views
    Package UpdatesP
    [1.98.0] Update immich to 2.6.1 Full Changelog Fixed a failed migration issue on the mobile app when the URL Switching feature is used fix(server): fallback to email when name is empty by @​jrasm91 in #​27016 fix: ignore errors deleting untitled album by @​jrasm91 in #​27020 fix(web): wrap long album title by @​jrasm91 in #​27012 fix(web): stop in-progress uploads on logout by @​jrasm91 in #​27021 fix: writing empty exif tags by @​danieldietzler in #​27025 fix(web): disable send button by @​jrasm91 in #​27051 fix(mobile): server url migration by @​mertalev in #​27050
  • 0 Votes
    9 Posts
    159 Views
    E
    Thank you, I just wanted to say that this worked!
  • Stirling-PDF - Package Updates

    Pinned Stirling-PDF
    158
    0 Votes
    158 Posts
    72k Views
    Package UpdatesP
    [3.8.1] Update Stirling-PDF to 2.7.3 Full Changelog New PDF read aloud feature in viewer mode to "speak" the PDF to you, will be improved more going forwards! Improved annotation handling in annotation UI Mac printing is finally working on desktop app! Several general bug fixes such as Fix non-ASCII characters in headers being rejected Fix bug for HTTP2 support
  • Baserow - Package Updates

    Pinned Baserow
    98
    2 Votes
    98 Posts
    35k Views
    Package UpdatesP
    [1.35.10] Update uv to 0.10.12 Full Changelog Add pypy 3.11.15 (#​18468) Add support for using Python 3.6 interpreters (#​18454) Include uv's target triple in version report (#​18520) Allow comma separated values in --no-emit-package (#​18565) Show uv audit in the CLI help (#​18540) Improve reporting of managed interpreter symlinks in uv python list (#​18459) Preserve end-of-line comments on previous entries when removing dependencies (#​18557) Treat abi3 wheel Python version as a lower bound (#​18536) Detect hard-float support on aarch64 kernels running armv7 userspace (#​18530)
  • NodeBB - Package Updates

    Pinned NodeBB
    172
    0 Votes
    172 Posts
    121k Views
    Package UpdatesP
    [2.26.0] Update NodeBB to 4.10.0 Full Changelog add /world as a potential home page route (58d3aa7) add category selector to /world quick composer (2f5021e) ability to show only local posts in /world (44e65b8) #​14094, notification drawer UX improvements (6c01a5d) allow 3 profile pics (#​14092) (533ae69) category group actor outbox, #​14083 (b317cdd) improve idempotency of ap test (8ca34e7) call syncfollowcounts on unfollow as well (ebe709d) sync follow counts on local and remote follows, #​14105 (44e78e4) cold load redirect should only affect guests (cc60667)
  • Formbricks - Package Updates

    Pinned Formbricks
    63
    0 Votes
    63 Posts
    8k Views
    Package UpdatesP
    [2.8.2] Update formbricks to 4.8.2 Full Changelog fix: [Backport] backports sentry improvement and loading page fix by @​pandeymangg in #​7534 fix: [Backport] backports the sdk initialization issues by @​pandeymangg in #​7536
  • Audiobookshelf - Package Updates

    Pinned Audiobookshelf
    81
    0 Votes
    81 Posts
    33k Views
    Package UpdatesP
    [1.97.1] Update audiobookshelf to 2.33.1 Full Changelog API Keys not respecting user enabled/disabled flag Podcast episode update endpoint sanitizes HTML for subtitle Playlist & collection create/update endpoints strip HTML tags from name More strings translated Belarusian by @​pavel-miniutka German by @​fabianjuelich Spanish by @​cyphra
  • Keycloak - Package Updates

    Pinned Keycloak
    37
    0 Votes
    37 Posts
    7k Views
    Package UpdatesP
    [1.5.6] Update keycloak to 26.5.6 Full Changelog CVE-2026-1180 - Blind Server-Side Request Forgery (SSRF) in Keycloak OIDC Dynamic Client Registration via jwks_uri oidc CVE-2026-1035 - Keycloak Refresh Token Reuse Bypass via TOCTOU Race Condition oidc CVE-2025-14777 - Keycloak IDOR in realm client creating/deleting CVE-2025-14082 keycloak-server: Keycloak Admin REST API: Improper Access Control leads to sensitive role metadata information disclosure CVE-2026-3121 - Keycloak: Privilege escalation via manage-clients permission CVE-2026-3190 - Information Disclosure via improper role enforcement in UMA 2.0 Protection API core CVE-2026-3911 Keycloak: Information disclosure of disabled user attributes via administrative endpoint user-profile CVE-2026-2366 Authorization Bypass: Unprivileged tokens can enumerate user organization memberships organizations Federated user disabled when external DB unavailable, never re-enabled storage AUTH_SESSION_ID cookie reuse causes cross-user session contamination on re-authentication authentication
  • Scaleway backup

    Solved Support backup scaleway
    26
    1 Votes
    26 Posts
    488 Views
    C
    In the end I used S3 compatible option to set this up successfully. IDK why I could not get the Scaleway option to work. Thanks all for your help & input
  • Unusable application

    Docker Registry
    1
    1 Votes
    1 Posts
    36 Views
    No one has replied
  • Cloudron and Swap File Use

    Moved Discuss
    9
    0 Votes
    9 Posts
    439 Views
    robiR
    @Jamie_Casper can you give us an example that's more specific?
  • Forgejo built-in SSH server not authenticating public keys

    Forgejo
    4
    2 Votes
    4 Posts
    60 Views
    robiR
    Is cloudron@ the admin or default user?
  • Excalidraw

    Community Apps
    1
    3 Votes
    1 Posts
    35 Views
    No one has replied
  • 1 Votes
    13 Posts
    343 Views
    F
    @LoudLemur i'm working a lot with strapi, developed plugins and more So yeah, it def. has its limitations or "weird edges", but in general i'm happy with it as backend for my apps. And like you said, strapi is more for serious business depending logic (with more effort in CI/CD) while directus is more for non-technical and quick-deploy setups.
  • 13 Votes
    35 Posts
    28k Views
    timconsidineT
    In https://forum.cloudron.io/post/118908 @girish rightly questioned how private bundling stock Excalidraw is, and as a result whether it is not just easier to use the hosted version. But I like Excalidraw ! And I want it on my Cloudron ! And I want it to be as private as possible (completely private maybe not possible). And I liked @chmod777 suggestion in https://forum.cloudron.io/post/120436. So I have made package changes and pushed 1.1.2. There is now a file /app/data/user/json where you can set 2 options. {"privacyBundle":true,"useCSP":true} the first removes some stuff from the image (actually technically, builds a stock repo bundle, and a bundle with stuff removed) the second injects headers in your browser to stop the browser calling certain remote sites. Restart container after editing, of course. There is then also a new script in container /app/code/verify-runtime.sh which outputs diagnosis, with a summary at the end : == summary == settings: privacyBundle=true, useCSP=true servedIndex: /app/data/www/index.html bundleMatch: privacy cspMeta: YES cspConnectSrc: 'self' blob: privacyEndpoints: YES externalStringsInBundle: firebasestorage.googleapis.com, libraries.excalidraw.com, scripts.simpleanalyticscdn.com, excalidraw.nyc3.cdn.digitaloceanspaces.com externalStringsMeaning: present in static files, not proof of requests Is it private? I think so, as much as it can be. The glaring violations have been dealt with. If you're in paranoia mode, use browser Dev Tools to check network activity. So, now, it's def worth having this modified Excalidraw on Cloudron EDIT : surprisingly having 2 app versions in the same app does not increase dockermimage size much. I guess because of sharing of layers. But nonetheless
  • DKIM when external relay is configured

    Unsolved Support mail dkim mail relay
    6
    2 Votes
    6 Posts
    92 Views
    P
    Could you please check whether this applies to the PTR4 record as well? As I hadn’t configured it on the Cloudron – since I was using a relay – I experienced issues with incoming email delivery until I configured it. I then configured the PTR4 record and everything was solved. I know that PTR4 record is related only to outbound, but I want to figure out if there is some relationship on what happened. Thanks a lot
  • GitLab - Package Updates

    Pinned GitLab
    229
    1 Votes
    229 Posts
    213k Views
    Package UpdatesP
    [1.114.0] Update gitlab-foss to 18.10.0 Add #find_by_id_through_partition to Ci::Pipeline (merge request) Prevent use of REST lifecycle terms in free text fields (merge request) Reduce GraphQL query complexity for security inventory query (merge request) GitLab Enterprise Edition Add separate queue for backfilling (merge request) GitLab Enterprise Edition Adds work_item_type_ids filter to GraphQL (merge request) Create offline transfer route and controller (merge request) Enable bso_minimal_access_fallback feature flag by default (merge request) GitLab Enterprise Edition Show custom WI types within Custom Fields config (merge request) GitLab Enterprise Edition Add Vulnerabilities Over Time chart to PDF export (merge request) GitLab Enterprise Edition Add override action display to policy drawer (merge request) GitLab Enterprise Edition
  • Dockerfile flexibility

    App Packaging & Development
    6
    0 Votes
    6 Posts
    61 Views
    nebulonN
    I have pushed a new cli version now which supports showing more help info for cloudron build --help now
  • Metabase - Package Updates

    Pinned Metabase
    527
    1 Votes
    527 Posts
    419k Views
    Package UpdatesP
    [3.2.1] Update metabase to 0.59.3.2 Full Changelog