The keyed platform renderer preserves row owners, but the disk table captured mount-time presentation. Derive current health, readings, placement and target bindings reactively without discarding focus or expanded detail. Cover snapshot replacement, in-place updates, missing evidence and attention-filter recovery; record desktop and phone browser acceptance.
Change-source: pulse-maintainer
Suppress raw CLI targets/output, HTTP response bodies and credential-bearing endpoint paths across firing, recovery, tests, queue audits and settings logs. Preserve exact delivery inputs, typed causes and retry classification; retain structured status, counts and safe validation reasons.
Contract-Neutral: Shared agent-lifecycle and storage-recovery references are unchanged; this diagnostic repair alters no agent or storage behaviour, API schema, destination admission or delivery policy.
Change-source: pulse-maintainer
Finish the connected #2077 outcome: persist an observed TrueNAS host temperature through the existing canonical writer, so local chart coverage cannot suppress the Thermals panel. Extend the pinned REST-to-chart control to cover the write, persistent readback and full local-window fast path; preserve source and absence gates.
Change-source: pulse-maintainer
Contract-Neutral: Restores existing TrueNAS Thermals history through its canonical writer; no agent lifecycle, schema, route, resource identity or alert-policy delta.
Complete the native CORE #2077 repair after its whole-suite adverse result: retain ARC without inventing free RAM, enforce live-window freshness even with coarse RRD steps, and assert bounded graph splitting including CPU temperature. Keep empty/zero, aligned ARC and transport boundaries intact.
Change-source: pulse-maintainer
Exercise the unique-device selection ceiling separately from deduplication, and keep the graph-isolation account aligned with catalogue-selected requests. No runtime logic or public contract shape is changed.
Change-source: pulse-maintainer
Bind the anonymised JSON regression input to the existing TrueNAS runtime proof policy. The repair restores existing canonical behavior and has no public contract shape change; its source, tests and substantive monitoring account remain in the preceding commit.
Change-source: pulse-maintainer
Use external RRD timing, native legends, scoped device graphs and measured CPU temperature for issue #2077. Keep absent, empty and zero buckets distinct, normalize CORE CPU states and preserve ARC alignment, safe transport failures and canonical projection. Add native-shape and end-to-end monitoring controls without changing release selection.
Change-source: pulse-maintainer
Contract-Neutral: Restores existing canonical metrics and temperature behaviour for CORE input formats; no public schema, route, resource identity or alert-policy delta.
Move the quiet-hours startup regression beside the other monitor proof files without changing any runtime, test or contract content. This corrects the registry audit's lexical ordering error.
Change-source: pulse-maintainer
Keep continuous and late replay held without spending a provider attempt. Split mixed batches atomically so eligible alerts retain admitted destinations, occurrence links and retry budgets, and bind saved monitor policy before activating persisted work. Add local receipt, cancellation, rollback, reconstruction and race regression coverage with the owning contracts and verification routes.
Change-source: pulse-maintainer
Repair the deterministic registry audit rejection by moving the dedicated quiet-hours test into its lexicographic position and matching the existing indentation. Preserve all verification entries, path policies and runtime bytes.
Change-source: pulse-maintainer
Compare scheduled civil minutes on each selected day so repeated or missing DST minutes cannot shift suppression. Calculate non-full-day replay from real clock boundaries and keep location fallback read-only for concurrent policy consumers. Retain category controls and the existing full-day replay boundary; pin the civil-time contract and dedicated regression proof.
Change-source: pulse-maintainer
Preserve exact Core candidate identity for issue #2369, its required-member provenance and genuine-deficit controls. Retain source proof limitations and the owned compatible patch route; no frontend content changes.
Change-source: pulse-maintainer
Retain configured RAID members separately from source-native totals through collection, reports and canonical read views. Correct the healthy legacy mdadm tuple from #2369 without subtracting spares from mdstat requirements or suppressing real deficits, failures and recovery warnings. Preserve observed zero-active counts through fallback, and verify collector, wire, ingestion, health and canonical activation/resolution boundaries.
Change-source: pulse-maintainer
Extract the Windows-independent Docs repair from candidate 136d039de4a1f8f7debfb1f82d4fffd8bf610083. Add trusted scope after sanitization without expanding document-controlled attributes. Preserve table-local scrolling and verify the current eight-header plans table in desktop Chromium and phone WebKit; native Windows work remains separate.
Change-source: pulse-maintainer
Failed setup now yields local-only, topology-free diagnostics. Require recognised Running state and successful tailnet ping before TCP, retain probe exits without raw private output or fallback probes, and exercise twenty synthetic readiness/privacy cases. Parent controls expose false success and private output on both channels. Keep workflow identities, secrets, action pins, mutation gates and release scope unchanged.
Change-source: pulse-maintainer
A restored image-update incident must not wait another whole delay before positive reports refresh it. Recover pending age from the same resource's active occurrence, retaining acknowledgement and delivery identity while preserving explicit recovery and a new update's normal delay. Exercise both checkpoint authorities, both cleanup paths, cached and unknown evidence, 24/48-hour delays and isolated hosts through the public checker.
Change-source: pulse-maintainer
Replace literal credential bootstraps with the exercised bounded Core private-entry pattern, preserve a checked local private-file route for non-terminal FreeBSD command fields, and consolidate Unix repair, upgrade and removal transport without changing token issuance, TLS choice or host identity. Removal does not depend on a new binary preflight. Windows credential transport remains the next rework step. Add executable PTY/file/lifecycle proofs and the missing DOMPurify after-attributes detached-subtree regression, with parent-bound browser evidence.
Change-source: pulse-maintainer
Adapt PR2351 to current main without losing bounded probe deadlines, retries, explicit binds or confidentiality. Inspect IPv6 wildcard socket mode so unrelated servers sharing the port cannot determine Pulse health. Apply the telemetry callback only after a persisted explicit boolean transition, including stale-disk and null-input boundaries.
Retain real HTTP/HTTPS wildcard and same-port isolation regressions, callback persistence-order tests, and the owning subsystem contracts. No dependency manifests, frontend source or telemetry payload schema change. Exact runtime proof remains dependent on the unavailable root graph; it is not represented as passed.
Change-source: pulse-maintainer
Original-source: https://github.com/rcourtman/Pulse/pull/2351
Original-commit: f50c4d6e3b
Co-authored-by: rcourtman <8825017+rcourtman@users.noreply.github.com>
Preserve exact Core candidate c0525852f8 and its differential, affected-race and benchmark evidence. Compose with the fixed initial main frontier; installed CPU and release follow-through remain separately owned.
Change-source: pulse-maintainer
The residual whole-broadcast profile attributes about 80 percent of synthetic allocation to connected-infrastructure grouping. Request only its unchanged 0.90 identity floor, and discard equal or worse-priority fallback peers before allocating and sorting them. Keep general matching and all group identity, ambiguity, explanation and review semantics against independent pre-repair oracles. Update the obsolete broadcast-wrapper source assertion to the prepared single-pass path.
Change-source: pulse-maintainer
On 30 Sep and 1 Oct two new advisories (brace-expansion
GHSA-q2hr-2g5m-vwhr, DOMPurify GHSA-p98j-92pf-mc4p) failed the required
frontend audit on every PR across main, release/v6.4 and release/v6.5,
holding the v6.5 RC for days and blocking the v6.4.6 preparation. The
existing scheduled npm-audit is informational and only sees main. This
adds a daily workflow that runs the same complete frontend audit as
Build and Test on main and every active release line, fails on any
finding, and names the branch, advisories and fix. The maintainer's
release-path health check raises it to Delivery immediately.
The first exact candidate proof compiled and passed frontend snapshot tests, but rejected two monitoring fixture fields that only exist on frontend projections. Use the canonical resource name and tags to test the same sort/freshness boundaries. Preserve that failed aggregate result; no production code or expectation is relaxed.
Change-source: pulse-maintainer
An update, rollback or reinstall must not silently enable unattended updates. Share the existing-install opt-in prompt and retain affirmative CLI and interactive choices without changing helper refresh or fresh-install defaults.
Exercise all five existing main flows and add bounded configuration/timer intent observations to the signed published lifecycle rehearsal, including changed and unavailable negative controls.
Change-source: pulse-maintainer
On 30 Sep-1 Oct 2026 GHSA-q2hr-2g5m-vwhr (brace-expansion) and
GHSA-p98j-92pf-mc4p (DOMPurify) failed the required "Audit complete
frontend dependency graph" step on every pull request to main,
release/v6.4 and release/v6.5. That held the v6.4.6 preparation PR and
the v6.5 RC for days with no owner. The scheduled audit in
security-scan.yml only informs and runs on the default branch, so
release lines were never checked.
dependency-advisory-watch.yml runs daily and on dispatch. It lists main
plus every release/v<major>.<minor> line at or newer than the latest
stable's line (all lines if that lookup fails), then audits each in a
fail-fast-free matrix. Each job fetches only that line's
frontend-modern/package.json and package-lock.json with git and runs
scripts/npm-audit-retry.sh all on them under the same Node.js pin that
build-and-test requires. npm audit reads the lockfile, so nothing is
installed. The job never checks out or runs the audited branch's code,
because a scheduled run holds the default branch's cache scope and
CodeQL flagged running npm ci there as cache poisoning.
A job fails when the audit fails, and its step summary and annotation
name the branch, the GHSA ids and the fix (npm audit fix
--package-lock-only plus raised floors in dependencySecurity.test.ts).
Read-only, hosted-only, no secrets, no uploads.
List the continuity-aware registry once, decorate one owned host projection, and sort final frontend rows rather than a second estate-sized conversion array. Encode concrete frontend resources directly into immutable snapshot buffers, decoding every authoritative ID from those bytes; leave generic marshalers and all other fields on the existing path. Keep live freshness, alert and lifecycle semantics without a cache.
Change-source: pulse-maintainer
Preserve the complete reviewed maintenance tip and published upstream source unchanged. Combine their installability contract and subsystem registry entries without changing runtime behaviour.
Change-source: pulse-maintainer
Reuse the complete-download and preflight private-token entry boundary for both monitoring modes. Keep issued credentials separate and no-store, use the installer-owned token path in the diagnostic service reference, and reject structural unit injection before minting. Add executable root/sudo, history, transport, failure cleanup and systemd grammar regressions alongside the subsystem contracts.
Change-source: pulse-maintainer
Install a published release (latest stable by default) with its signed
install.sh, seed auth, a webhook and a PVE node through the API, upgrade with
the installed /bin/update --version helper, then roll back with the documented
/bin/update --version command. Each step checks /api/version and the binary
version, /api/health, unit state, the seeded settings against fixed
expectations and the pre-upgrade read-back, and data-dir survival, then
reports a phase table in the step summary.
The workflow is read-only, hosted-only, uploads nothing and no release job
depends on it.
Merge Core candidate cf12c37e63 unchanged onto 22380a3546. Resolve only the shared browser receipt to the candidate receipt; changed frontend source exactly matches its non-merge proof-bearing commit. Preserve newer safe API recipes and sparse History source.
Retained focused configapi, hostagent, mock, monitoring and installtests race suites, affected API cases, frontend suite and type-check, builds and PVE/PBS desktop and phone-emulated browser checks cover the changed behaviour. Broad API timeout and output-limit attempts remain unresolved, not passes. No installed recovery, release qualification, publication or deployment is claimed.
Change-source: pulse-maintainer
Preserve exact Delivery candidate 90c80acb49, including bounded grouped notes, operator safety checks and complete qualification source closure. No product or published release changes.
Change-source: pulse-maintainer
Exact-source validation found two unbound compiled packages after composing the retained notes repair with current main. Include both in the source manifest and report the whole dependency closure without weakening the check.
Change-source: pulse-maintainer
Compose the exact earlier source repair on the current reviewed base for final validation. No published release or source routing is changed.
Change-source: pulse-maintainer
Render lone stored observations at their actual time instead of blank collecting panels. Label live legend fallbacks as current and describe empty windows without claiming collection is active. Preserve source/range isolation and failed-refresh recovery.
Add sparse-observation regressions and scoped browser evidence, and align both canonical contracts with the shared renderer's verification boundary.
Change-source: pulse-maintainer
Bind the new compiled notes helper and authored fixture in the rootful source manifest. Repair the visual rollback fixture's missing version and align the internal control-plane page with the active release-reliability target, without changing source routing or published packets.
Change-source: pulse-maintainer
Bind stable notes to version and operator disclosures rather than obsolete prose. Support bounded grouped customer sections for v6.4.6 and later, align generation and rendering, and preserve published history and all qualification gates.
Change-source: pulse-maintainer
Separate PVE/PBS setup and telemetry credentials from shell source and download URLs. Use silent root/sudo input, private-file handoff, complete downloads and the agent preflight; preserve scope, TLS defaults, single-line paste and coherent rolling-upgrade metadata. Reveal tokens through the existing dialog and discard late issuance after close. Pin executable shell, history, TLS/registration and browser contracts without using real credentials.
Change-source: pulse-maintainer
Preserve the exact Web candidate, parent-bound browser receipt and lint correction. Restore first-touch disclosure while retaining delegated nested controls and keyboard behaviour.
Change-source: pulse-maintainer
Mark clickable table rows as native WebKit touch targets without moving their actions out of Solid's delegated event ordering. Preserve keyboard disclosure, embedded controls, dynamic action removal and explicit native handlers; cover the shared table and data grid, and record production PBS drawer browser proof.
Change-source: pulse-maintainer
Carry per-metric presence through REST and realtime snapshots, canonical host rows and shared History writes. Do not interpret arbitrary numeric object fields as reporting values. Preserve bounded telemetry failure diagnostics without blocking inventory or exposing provider text.
Change-source: pulse-maintainer
The exact no-mutation watchdog failed at published 6.4.5 because the release line has pending repairs but still declares its stable VERSION. Observe that governed source and its preceding stable reference without inventing a new promotion, while keeping candidate resolver gates unchanged and watchdog artifacts out of promotion-readiness records.
Change-source: pulse-maintainer