Compare commits

..
Author SHA1 Message Date
MickLesk 15117e56be Remove the PocketBase AI bot
It called GitHub Models, which GitHub retired on 2026-07-30. The endpoint now
answers every request with a plain-text "OK", so each mention ended in "Could
not parse the model response". The /pocketbase slash-command bot is unaffected.
2026-09-29 14:41:55 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 1a0323a963 Update CHANGELOG.md (#17588)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 12:22:31 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 36d6cb2c74 Update CHANGELOG.md (#17586)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 12:03:21 +00:00
Denislav DenevandMichel Roegl-Brunner 8a314a12be fix(romm): snapshot Redis hourly like the upstream image (#17562)
* fix(romm): snapshot Redis hourly like the upstream image

Redis' default save policy (3600 1 300 100 60 10000) rewrites the whole dump.rdb every 5 minutes on an idle RomM, because the RQ workers and scheduler change keys constantly. With the Switch TitleDB and PS2 serial caches the dump is ~50 MB, so an idle container writes ~14 GB/day. Upstream fixed this for the Docker image (rommapp/romm#3983, REDIS_SAVE_POLICY default "3600 1"), but that lives in docker/init_scripts/init, which the LXC install never runs. Apply the same policy on install and, for existing containers, on update unless a save policy is already set.

* Update ct/romm.sh

* Update install/romm-install.sh

---------

Co-authored-by: Michel Roegl-Brunner <73236783+michelroegl-brunner@users.noreply.github.com>
2026-09-29 14:02:51 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] d095b9020c Update CHANGELOG.md (#17584)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 11:49:13 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] f926f143cf Update CHANGELOG.md (#17580)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 11:13:56 +00:00
push-app-to-main[bot]andCanbiZ 098ce2dea0 Anki Sync Server (#17416)
* Add anki-sync-server (ct)

* Clean up comments in anki-sync-server.sh

Removed comments about local core checkout and credential storage.

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-09-29 13:13:28 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] ad4a5216a7 Update CHANGELOG.md (#17578)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 10:59:27 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 946294ad4a Update CHANGELOG.md (#17577)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-29 10:51:03 +00:00
github-actions[bot] 6dab490118 checkmate: bump Node.js from 22 to 24 (#17554)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-29 12:50:35 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 0c374bb482 Update CHANGELOG.md (#17570)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-28 21:11:41 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] aa4b4f43e1 Update CHANGELOG.md (#17569)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-28 21:11:19 +00:00
Bo Bartlett 02934b1fac fix(autocaliweb): wire .env into all service units, not just autocaliweb.service (#17561)
Only autocaliweb.service loaded $INSTALL_DIR/.env via EnvironmentFile.
The other three units never did, so any script they invoke falls back
to the Docker-oriented defaults baked into upstream (ACW_CONFIG_DIR=/config,
ACW_USER/ACW_GROUP=abc), none of which exist in this LXC install.

Confirmed via kindle_epub_fixer.py failing on both a missing /config
directory and a missing 'abc' system user during ingest.
2026-09-28 23:11:09 +02:00
Joren Guillaume 90827a0710 Change cp command (#17559)
Cover case where only dotfiles are inside the source directory.
2026-09-28 23:10:48 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] e5ce5acf9d Update CHANGELOG.md (#17568)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-28 21:10:19 +00:00
CanbiZ (MickLesk) 9a18b05026 Plane: install silo and mcli from pgsty instead of dl.min.io (#17347) 2026-09-28 23:09:51 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 4de0686850 Update CHANGELOG.md (#17567)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-28 21:09:35 +00:00
CanbiZ (MickLesk) 096da0dff6 Borg-UI: start through upstream's start.sh so migrations run (#17563) 2026-09-28 23:09:08 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] aadf3d94c1 Update CHANGELOG.md (#17566)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-28 19:55:39 +00:00
Chris cd7ac82058 Immich: Pin version to 3.2.4 (#17564)
- Upstream bugfixes
2026-09-28 21:55:12 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] a50fe45184 Update CHANGELOG.md (#17558)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-28 07:14:20 +00:00
CanbiZ (MickLesk) 9312a32495 Serve linkding's favicons and preview images (#17557)
linkding stores them in data/favicons and data/previews and upstream maps both
under /static next to the collected assets, with a sandbox CSP. The nginx site
only aliased the collected assets, so every downloaded image answered 404; the
update rewrites that block even without a new release.
2026-09-28 09:13:57 +02:00
CanbiZ (MickLesk) 2ee7d13367 Fill in the nginx resolver SparkyFitness 1.7.3 added (#17556)
Upstream's nginx.conf gained a resolver ${NGINX_RESOLVER} line that its Docker
entrypoint fills from /etc/resolv.conf; the script substitutes a fixed list of
placeholders, so the literal variable reached nginx and the config test failed.
Take the nameservers from resolv.conf the same way.
2026-09-28 09:13:47 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 9fb9a81cc2 Update CHANGELOG.md (#17552)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-27 21:39:04 +00:00
Jody VandClaude Sonnet 5 56886bb053 fix(aurral): bump to Node 26 and bypass strict engine pin (#17543)
* fix: bump aurral Node.js requirement from 22 to 26

Upstream aurral now requires Node 26.x (engines: "26.8.x" in v2.10.0),
causing npm ci to fail with EBADENGINE when the install script sets up
Node 22.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix: bypass npm engine-strict check for aurral build

aurral's .npmrc sets engine-strict=true and pins an exact node patch
(26.8.x), which NodeSource can never satisfy since it only ships the
latest patch per major (currently 26.10.0). Disable engine-strict for
the build, matching the ignore-engines workaround already used for
yarn-based apps in this repo (dashy, monica, excalidraw,
elementsynapse).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-27 23:38:40 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 5a9522b6b1 Update CHANGELOG.md (#17547)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-27 17:09:17 +00:00
durzo 989f064993 Tracearr: fetch map tiles on install/update (#17544) 2026-09-27 19:08:54 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] bc246308ab Update CHANGELOG.md (#17546)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-27 16:46:55 +00:00
Bo Bartlett 5ec6d35c8b fix(autocaliweb): define INSTALL_DIR before first use (#17545)
setup_uv was called with $INSTALL_DIR on the line before INSTALL_DIR
was ever assigned, causing every install to fail with:
  bash: line 58: INSTALL_DIR: unbound variable
2026-09-27 18:46:24 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] e2effe6510 Update CHANGELOG.md (#17538)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-27 00:05:34 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 712f7fe565 Archive old changelog entries (#17537)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-27 00:05:09 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 41ad683454 Update CHANGELOG.md (#17536)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 20:11:56 +00:00
sergstepanenko 44a22d77d3 Manyfold: chown /opt/manyfold_data to the manyfold user (#17534) 2026-09-26 22:11:31 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] ebe02e9c93 Update CHANGELOG.md (#17533)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 19:02:25 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 11e409f499 Update CHANGELOG.md (#17532)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 19:02:09 +00:00
CanbiZ (MickLesk) 42442ca968 Let steamcmd update itself before installing Satisfactory (#17526)
On the run in which steamcmd replaces itself, the app_update that follows fails
with 'Missing configuration', and the same command succeeds once it runs again.
A login-only run first takes that self-update out of the install and update.
2026-09-26 21:01:56 +02:00
CanbiZ (MickLesk) 0e28ea7fe1 Build the AudioMuse-AI noavx2 environment on Python 3.11 (#17528)
The noavx2 requirements pin numpy 1.23.5 and onnx 1.14.1, neither of which ships
a cp312 wheel, so on 3.12 uv built them from source: numpy fails without
distutils and onnx without cmake. Every noavx2 pin has a 3.11 wheel.
2026-09-26 21:01:46 +02:00
CanbiZ (MickLesk) 9db16c2073 Hold @lobehub/ui at 5.49 while LobeHub's stable release needs it (#17531)
@lobehub/ui 5.50.0 dropped NeuralNetworkLoading, and LobeHub 2.2.18 still imports
it through a ^5.47.0 range with lockfile: false, so every fresh build now fails.
Upstream moved off it on main; the pin only applies while package.json still asks
for a 5.4x range, so it stops on its own with the next stable release.
2026-09-26 21:01:28 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 8a3d372171 Update CHANGELOG.md (#17530)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 18:55:44 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 306eb3a54d Update CHANGELOG.md (#17529)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 18:55:15 +00:00
CanbiZ (MickLesk) 5127c85ca7 Keep Trilium updates on the server releases (#17525)
The repo also publishes web-clipper-v* releases, and whenever upstream marked one
of those as latest the update offered to replace the server with the browser
extension. A v prefix makes core pick the newest stable server release itself
instead of trusting that marking.
2026-09-26 20:54:46 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 4bca45dfc1 Update CHANGELOG.md (#17527)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 18:51:39 +00:00
CanbiZ (MickLesk) 83a4addccd Generate the NPM admin config and repair certbot's venv on update (#17523)
2.16.0 ships production.conf only as a template that its s6 prepare step renders,
so installs outside Docker never listened on 81; render it on install, on update
while keeping a custom admin port, and on update for containers already stuck on
2.16.0. Certbot's upgrade died on a dist-info without RECORD, which pip's own
--ignore-installed hint does not clear, so drop such records before upgrading.
2026-09-26 20:51:17 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 968cf0c155 Update CHANGELOG.md (#17524)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 18:49:30 +00:00
CanbiZ (MickLesk) dce092a0a4 Komodo: add KOMODO_HOST | fix broken spinner (#17481)
* Check Komodo actually started and point KOMODO_HOST at the container

* Stop Komodo hanging on an unclosed message block
2026-09-26 20:49:03 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 4bdb61cdf4 Update CHANGELOG.md (#17522)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 18:37:51 +00:00
David BarreraandClaude Opus 5.5 9489724d86 romm: run rq cron and a scans worker for RomM 5.3 (#17502)
RomM 5.3.0 dropped rq-scheduler (rommapp/romm@4e5921727), so
romm-scheduler.service fails with 203/EXEC on a missing
.venv/bin/rqscheduler. The same release moved scans to their own
"scans" queue (rommapp/romm@3593d2398), which the LXC worker never
listened on, so scans queued but never ran.

Match upstream's docker init: the scheduler service runs
`rq cron tasks.cron_config`, both workers run with --with-scheduler
so delayed jobs (watcher rescans) are released, and a new
romm-scan-worker.service consumes the scans queue.

The update script migrates existing units when romm-scheduler.service
still references rqscheduler. It runs before the release check, so
installs already on 5.3.x get repaired too.

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-26 20:37:22 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 76a09f5ad9 Update CHANGELOG.md (#17521)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-26 17:08:54 +00:00
CanbiZ (MickLesk)andpavlojs 91bccdacd3 Semaphore: fix BoltDB migration by pinning 2.18.30 (#17439)
* Fix Semaphore BoltDB migration

* Update ct/semaphore.sh

Co-authored-by: pavlojs <63199635+pavlojs@users.noreply.github.com>

---------

Co-authored-by: pavlojs <63199635+pavlojs@users.noreply.github.com>
2026-09-26 19:08:26 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 9e39761415 Update CHANGELOG.md (#17513)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-25 19:27:29 +00:00
community-scripts-pr-app[bot]andGitHub Actions d439341c7a Update .app files (#17509)
Co-authored-by: GitHub Actions <github-actions[bot]@users.noreply.github.com>
2026-09-25 21:26:18 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 432d56b887 Update CHANGELOG.md (#17511)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-25 19:09:49 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] ab02d929c3 Update CHANGELOG.md (#17510)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-25 19:09:29 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 8f0bcf9fe9 Update CHANGELOG.md (#17508)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-25 19:09:18 +00:00
CanbiZ (MickLesk) 89671ce007 Take the Obsidian version from the Ignis release tag (#17503)
Upstream renamed OBSIDIAN_VERSION in its Dockerfile to IGNIS_OBSIDIAN_PIN, so the
grep matched nothing - and under pipefail the assignment itself aborts, which is why
the fallback on the next line never ran. The tag already carries the pairing
(0.8.13+obsidian.1.13.7), so read it there and keep both Dockerfile keys as a
fallback.
2026-09-25 21:09:05 +02:00
CanbiZ (MickLesk) 28aa1bdbee Refactor: Umbrel OS VM (#17505)
Refactor Umbrel OS VM script to improve structure and readability. Update function calls and variable handling for better maintainability.
2026-09-25 21:08:49 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 0993068f56 Update CHANGELOG.md (#17504)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-25 16:25:09 +00:00
push-app-to-main[bot]andCanbiZ c7a9a32693 RustFS (#17499)
* Add rustfs (ct)

* update

* Aktualisieren von rustfs-install.sh

* Uncomment var_arm64 variable assignment

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
2026-09-25 18:24:39 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 01be93e721 Update CHANGELOG.md (#17494)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-25 09:10:26 +00:00
CanbiZ (MickLesk) d7a3386dab Docker-LXC: remove Portainer installation from install (#17493)
* Docker-LXC: remove Portainer installation from install

Removed Portainer installation prompts and related code.

* Remove Portainer installation instructions from docker.sh

Removed instructions for installing Portainer as an addon.
2026-09-25 11:09:54 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 8e51b22e8b Update CHANGELOG.md (#17492)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-25 06:19:05 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] f7b0e066a0 Update CHANGELOG.md (#17491)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-25 06:18:37 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] ac44688925 Update CHANGELOG.md (#17490)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-24 20:20:48 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] 25c9f5a142 Update CHANGELOG.md (#17489)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-24 20:20:36 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] d376f6a92e Update CHANGELOG.md (#17488)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-24 20:20:19 +00:00
CanbiZ (MickLesk) 037e55256c Journiv: Serve Node Frontend and add HTTP Auth .env (#17479)
* Let Journiv start over plain HTTP

* Build the Journiv frontend

* Return to the project root before alembic
2026-09-24 22:20:12 +02:00
CanbiZ (MickLesk) 26c3bb9325 Declare the RomM filesystem structure required since 5.3.0 (#17480) 2026-09-24 22:19:52 +02:00
MickLesk c69359d704 rm unneeded link 2026-09-24 12:23:17 +02:00
MickLesk 04fd8481f5 quickfix ln in immich update, Fixes #17482 2026-09-24 11:29:18 +02:00
community-scripts-pr-app[bot]andgithub-actions[bot] 03702ce31a Update CHANGELOG.md (#17475)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-24 06:44:33 +00:00
community-scripts-pr-app[bot]andgithub-actions[bot] e38cc1c631 Update CHANGELOG.md (#17474)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-24 06:07:14 +00:00
CanbiZ (MickLesk) b855a5782a Use apt_update_safe instead of aborting on a failed apt update (#17462) 2026-09-24 08:06:49 +02:00
197 changed files with 1050 additions and 1614 deletions
+146
View File
@@ -1,3 +1,149 @@
## 2026-09-26
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Manyfold: make /opt/manyfold_data writable for the manyfold user [@sergstepanenko](https://github.com/sergstepanenko) ([#17534](https://github.com/community-scripts/ProxmoxVE/pull/17534))
- steamcmd: update itself before installing Satisfactory [@MickLesk](https://github.com/MickLesk) ([#17526](https://github.com/community-scripts/ProxmoxVE/pull/17526))
- AudioMuse-AI: build noavx2 environment on Python 3.11 [@MickLesk](https://github.com/MickLesk) ([#17528](https://github.com/community-scripts/ProxmoxVE/pull/17528))
- LobeHub: pin lobehub/ui at 5.49 while LobeHub's stable release needs it [@MickLesk](https://github.com/MickLesk) ([#17531](https://github.com/community-scripts/ProxmoxVE/pull/17531))
- Keep Trilium updates on the server releases [@MickLesk](https://github.com/MickLesk) ([#17525](https://github.com/community-scripts/ProxmoxVE/pull/17525))
- NginxProxyManager: generate admin config and repair certbot's venv on update [@MickLesk](https://github.com/MickLesk) ([#17523](https://github.com/community-scripts/ProxmoxVE/pull/17523))
- Komodo: add KOMODO_HOST | fix broken spinner [@MickLesk](https://github.com/MickLesk) ([#17481](https://github.com/community-scripts/ProxmoxVE/pull/17481))
- romm: run rq cron and a scans worker for RomM 5.3 [@davidbb](https://github.com/davidbb) ([#17502](https://github.com/community-scripts/ProxmoxVE/pull/17502))
- #### 💥 Breaking Changes
- Semaphore: fix BoltDB migration by pinning 2.18.30 [@MickLesk](https://github.com/MickLesk) ([#17439](https://github.com/community-scripts/ProxmoxVE/pull/17439))
### 💾 Core
- Keep a dash-led bridge comment out of whiptail's options [@MickLesk](https://github.com/MickLesk) ([core#74](https://github.com/community-scripts/core/pull/74))
## 2026-09-25
### 🆕 New Scripts
- RustFS ([#17499](https://github.com/community-scripts/ProxmoxVE/pull/17499))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Ignis: take the Obsidian version from release tag [@MickLesk](https://github.com/MickLesk) ([#17503](https://github.com/community-scripts/ProxmoxVE/pull/17503))
- #### 🔧 Refactor
- Refactor: Umbrel OS VM [@MickLesk](https://github.com/MickLesk) ([#17505](https://github.com/community-scripts/ProxmoxVE/pull/17505))
- Docker-LXC: remove Portainer installation from install [@MickLesk](https://github.com/MickLesk) ([#17493](https://github.com/community-scripts/ProxmoxVE/pull/17493))
### 💾 Core
- Incus: make prompts visible for end-user [@MickLesk](https://github.com/MickLesk) ([core#73](https://github.com/community-scripts/core/pull/73))
- incus: do not let an install script block on an invisible prompt [@MickLesk](https://github.com/MickLesk) ([core#71](https://github.com/community-scripts/core/pull/71))
- tel: report progress from installs only, not updates [@MickLesk](https://github.com/MickLesk) ([core#72](https://github.com/community-scripts/core/pull/72))
## 2026-09-24
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Declare the RomM filesystem structure required since 5.3.0 [@MickLesk](https://github.com/MickLesk) ([#17480](https://github.com/community-scripts/ProxmoxVE/pull/17480))
- general: use apt_update_safe instead of aborting on a failed apt update [@MickLesk](https://github.com/MickLesk) ([#17462](https://github.com/community-scripts/ProxmoxVE/pull/17462))
- #### 🔧 Refactor
- Journiv: Serve Node Frontend and add HTTP Auth .env [@MickLesk](https://github.com/MickLesk) ([#17479](https://github.com/community-scripts/ProxmoxVE/pull/17479))
### 💾 Core
- core: accept an off-subnet gateway for /31 and /32 [@MickLesk](https://github.com/MickLesk) ([core#70](https://github.com/community-scripts/core/pull/70))
## 2026-09-23
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(signoz): install the histogramQuantile ClickHouse function [@maksimtech](https://github.com/maksimtech) ([#17386](https://github.com/community-scripts/ProxmoxVE/pull/17386))
- omniroute: bump to 4 GB for the npm install [@MickLesk](https://github.com/MickLesk) ([#17461](https://github.com/community-scripts/ProxmoxVE/pull/17461))
- Run Borg-UI with a single gunicorn worker [@MickLesk](https://github.com/MickLesk) ([#17445](https://github.com/community-scripts/ProxmoxVE/pull/17445))
- immich: keep geodata linked and the build deps present on update [@MickLesk](https://github.com/MickLesk) ([#17438](https://github.com/community-scripts/ProxmoxVE/pull/17438))
- #### 🔧 Refactor
- Refactor: Scanopy [@MickLesk](https://github.com/MickLesk) ([#16797](https://github.com/community-scripts/ProxmoxVE/pull/16797))
### 💾 Core
- stop a partial find from aborting the caller under pipefail [@MickLesk](https://github.com/MickLesk) ([core#68](https://github.com/community-scripts/core/pull/68))
- core: give RHEL-family containers an ostype PVE accepts [@MickLesk](https://github.com/MickLesk) ([core#67](https://github.com/community-scripts/core/pull/67))
- core: do not abort on a failed apt update [@MickLesk](https://github.com/MickLesk) ([core#66](https://github.com/community-scripts/core/pull/66))
- VM's: report a finished VM as done, not aborted [@MickLesk](https://github.com/MickLesk) ([core#65](https://github.com/community-scripts/core/pull/65))
- VM-Core: decide console autologin from the image, not USE_CLOUD_INIT [@MickLesk](https://github.com/MickLesk) ([core#63](https://github.com/community-scripts/core/pull/63))
- VM-Core: report failed image steps and restore tty1 autologin without cloud-init [@MickLesk](https://github.com/MickLesk) ([core#62](https://github.com/community-scripts/core/pull/62))
- tools: raise pnpm/yarn fetch timeout and lower network concurrency [@MickLesk](https://github.com/MickLesk) ([core#59](https://github.com/community-scripts/core/pull/59))
- VM-Core: stop discarding cloud-init error messages [@MickLesk](https://github.com/MickLesk) ([core#60](https://github.com/community-scripts/core/pull/60))
## 2026-09-22
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(invoiceshelf): re-link storage during update [@owenvoke](https://github.com/owenvoke) ([#17431](https://github.com/community-scripts/ProxmoxVE/pull/17431))
- fix(alpine-it-tools): write the version file after a successful update [@Houtek](https://github.com/Houtek) ([#17421](https://github.com/community-scripts/ProxmoxVE/pull/17421))
- Umami: Align pnpm with engines.pnpm on update [@ReneNulschDE](https://github.com/ReneNulschDE) ([#17404](https://github.com/community-scripts/ProxmoxVE/pull/17404))
- #### 🔧 Refactor
- several scripts: let uv see the project before syncing it | refactor some scripts that use uv [@MickLesk](https://github.com/MickLesk) ([#17436](https://github.com/community-scripts/ProxmoxVE/pull/17436))
### 💾 Core
- setup_uv: honour a project's required-version pin [@MickLesk](https://github.com/MickLesk) ([core#58](https://github.com/community-scripts/core/pull/58))
- fix(motd): repair legacy 00_lxc-details.sh header and dead color placeholders [@BadFlo](https://github.com/BadFlo) ([core#53](https://github.com/community-scripts/core/pull/53))
- meilisearch: take the raw binary, not the .deb [@MickLesk](https://github.com/MickLesk) ([core#57](https://github.com/community-scripts/core/pull/57))
### 📚 Documentation
- github: Stop generating header filenames with a newline in them [@MickLesk](https://github.com/MickLesk) ([#17435](https://github.com/community-scripts/ProxmoxVE/pull/17435))
### ❔ Uncategorized
- chore(ct): sync cloudflare-ddns defaults with PocketBase [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17446](https://github.com/community-scripts/ProxmoxVE/pull/17446))
## 2026-09-21
### 🆕 New Scripts
- AudioMuse-AI ([#17415](https://github.com/community-scripts/ProxmoxVE/pull/17415))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(portabase): meet the default admin password rules [@maksimtech](https://github.com/maksimtech) ([#17384](https://github.com/community-scripts/ProxmoxVE/pull/17384))
- truenas-vm: strip the G before the storage allocation [@MickLesk](https://github.com/MickLesk) ([#17407](https://github.com/community-scripts/ProxmoxVE/pull/17407))
- Librenms - Fix local snmpd community string setup [@dopch](https://github.com/dopch) ([#17363](https://github.com/community-scripts/ProxmoxVE/pull/17363))
- fix(iventoy): preserve release data and migrate legacy service launchers [@Msprg](https://github.com/Msprg) ([#17161](https://github.com/community-scripts/ProxmoxVE/pull/17161))
- xyops: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17398](https://github.com/community-scripts/ProxmoxVE/pull/17398))
### 💾 Core
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#56](https://github.com/community-scripts/core/pull/56))
- github-api: take the release the maintainer marked as latest [@MickLesk](https://github.com/MickLesk) ([core#55](https://github.com/community-scripts/core/pull/55))
- general: prune old Rust toolchains [@MickLesk](https://github.com/MickLesk) ([core#52](https://github.com/community-scripts/core/pull/52))
- Ask when the preselected storage cannot hold the content [@MickLesk](https://github.com/MickLesk) ([core#51](https://github.com/community-scripts/core/pull/51))
## 2026-09-20
### 🆕 New Scripts
- Your-Spotify ([#17376](https://github.com/community-scripts/ProxmoxVE/pull/17376))
## 2026-09-19
### 🆕 New Scripts
-626
View File
@@ -1,626 +0,0 @@
name: PocketBase AI Bot
# Natural-language companion to pocketbase-bot.yml.
# Mention the bot in plain English, e.g.:
# @pocketbase-bot change RAM to 4096 on zigbee2mqtt
# @pocketbase-bot disable script Nextcloud because upstream is broken
# The bot parses the request with GitHub Models, replies with the exact change(s)
# it understood, and only applies them after you reply "@pocketbase-bot confirm".
# The slash-command bot (/pocketbase ...) is unaffected; triggers do not overlap.
on:
issue_comment:
types: [created]
permissions:
models: read # lets the built-in GITHUB_TOKEN call GitHub Models inference
contents: write # built-in token opens the CT-defaults sync PR (like the slash bot)
pull-requests: write
jobs:
ai-bot:
runs-on: self-hosted
# Broad gate; the script does precise keyword + self-author checks.
if: contains(github.event.comment.body, '@pocketbase-bot')
steps:
- name: Mint GitHub App token (bot identity)
id: app-token
uses: actions/create-github-app-token@v3
with:
app-id: ${{ vars.GHAPP_PBBOT_ID }}
private-key: ${{ secrets.GHAPP_PBBOT_PRIVATE_KEY }}
- name: Run PocketBase AI bot
env:
# GitHub REST as the bot identity
GH_APP_TOKEN: ${{ steps.app-token.outputs.token }}
PB_BOT_APP_ID: ${{ vars.GHAPP_PBBOT_ID }}
# GitHub Models inference uses the built-in token (needs models: read)
MODELS_TOKEN: ${{ secrets.GITHUB_TOKEN }}
# Built-in token for git/PR ops (CT-defaults sync), mirroring the slash bot
GH_DEFAULT_TOKEN: ${{ secrets.GITHUB_TOKEN }}
AI_MODEL: openai/gpt-4o
# PocketBase
POCKETBASE_URL: ${{ vars.POCKETBASE_URL }}
POCKETBASE_COLLECTION: ${{ vars.POCKETBASE_COLLECTION }}
POCKETBASE_ADMIN_EMAIL: ${{ secrets.POCKETBASE_ADMIN_EMAIL }}
POCKETBASE_ADMIN_PASSWORD: ${{ secrets.POCKETBASE_ADMIN_PASSWORD }}
FRONTEND_URL: ${{ vars.FRONTEND_URL }}
REVALIDATE_SECRET: ${{ secrets.FRONTEND_INGEST_SECRET }}
# Event context
COMMENT_BODY: ${{ github.event.comment.body }}
COMMENT_ID: ${{ github.event.comment.id }}
COMMENT_AUTHOR_TYPE: ${{ github.event.comment.user.type }}
ISSUE_NUMBER: ${{ github.event.issue.number }}
REPO_OWNER: ${{ github.repository_owner }}
REPO_NAME: ${{ github.event.repository.name }}
ACTOR: ${{ github.event.comment.user.login }}
ACTOR_ASSOCIATION: ${{ github.event.comment.author_association }}
run: |
node << 'ENDSCRIPT'
(async function () {
const https = require('https');
const http = require('http');
const url = require('url');
// ── HTTP helper with redirect following ────────────────────────────
function request(fullUrl, opts, redirectCount) {
redirectCount = redirectCount || 0;
return new Promise(function (resolve, reject) {
const u = url.parse(fullUrl);
const isHttps = u.protocol === 'https:';
const body = opts.body;
const options = {
hostname: u.hostname,
port: u.port || (isHttps ? 443 : 80),
path: u.path,
method: opts.method || 'GET',
headers: opts.headers || {}
};
if (body) options.headers['Content-Length'] = Buffer.byteLength(body);
const lib = isHttps ? https : http;
const req = lib.request(options, function (res) {
if (res.statusCode >= 300 && res.statusCode < 400 && res.headers.location) {
if (redirectCount >= 5) return reject(new Error('Too many redirects from ' + fullUrl));
const redirectUrl = url.resolve(fullUrl, res.headers.location);
res.resume();
resolve(request(redirectUrl, opts, redirectCount + 1));
return;
}
let data = '';
res.on('data', function (chunk) { data += chunk; });
res.on('end', function () {
resolve({ ok: res.statusCode >= 200 && res.statusCode < 300, statusCode: res.statusCode, body: data });
});
});
req.on('error', reject);
if (body) req.write(body);
req.end();
});
}
// ── GitHub REST (as the bot app) ───────────────────────────────────
const owner = process.env.REPO_OWNER;
const repo = process.env.REPO_NAME;
const issueNumber = parseInt(process.env.ISSUE_NUMBER, 10);
const commentId = parseInt(process.env.COMMENT_ID, 10);
const actor = process.env.ACTOR;
function ghRequest(path, method, body) {
const headers = {
'Authorization': 'Bearer ' + process.env.GH_APP_TOKEN,
'Accept': 'application/vnd.github+json',
'X-GitHub-Api-Version': '2022-11-28',
'User-Agent': 'PocketBase-AI-Bot'
};
const bodyStr = body ? JSON.stringify(body) : undefined;
if (bodyStr) headers['Content-Type'] = 'application/json';
return request('https://api.github.com' + path, { method: method || 'GET', headers, body: bodyStr });
}
// Same as ghRequest but authenticated with the built-in GITHUB_TOKEN.
// Used for the CT-defaults sync branch/PR (the App token lacks contents:write).
function ghDefault(path, method, body) {
const headers = {
'Authorization': 'Bearer ' + process.env.GH_DEFAULT_TOKEN,
'Accept': 'application/vnd.github+json',
'X-GitHub-Api-Version': '2022-11-28',
'User-Agent': 'PocketBase-AI-Bot'
};
const bodyStr = body ? JSON.stringify(body) : undefined;
if (bodyStr) headers['Content-Type'] = 'application/json';
return request('https://api.github.com' + path, { method: method || 'GET', headers, body: bodyStr });
}
async function addReaction(content) {
try {
await ghRequest('/repos/' + owner + '/' + repo + '/issues/comments/' + commentId + '/reactions', 'POST', { content });
} catch (e) { console.warn('Could not add reaction:', e.message); }
}
async function postComment(text) {
const res = await ghRequest('/repos/' + owner + '/' + repo + '/issues/' + issueNumber + '/comments', 'POST', { body: text });
if (!res.ok) console.warn('Could not post comment:', res.body);
return res.ok ? JSON.parse(res.body) : null;
}
async function updateComment(id, text) {
const res = await ghRequest('/repos/' + owner + '/' + repo + '/issues/comments/' + id, 'PATCH', { body: text });
if (!res.ok) console.warn('Could not update comment:', res.body);
}
async function listIssueComments() {
const all = [];
let page = 1;
while (page <= 10) {
const res = await ghRequest('/repos/' + owner + '/' + repo + '/issues/' + issueNumber + '/comments?per_page=100&page=' + page);
if (!res.ok) break;
const batch = JSON.parse(res.body);
all.push.apply(all, batch);
if (batch.length < 100) break;
page++;
}
return all;
}
// ── 1. Self-trigger guard (App-token comments DO re-fire this event) ─
if (process.env.COMMENT_AUTHOR_TYPE === 'Bot') {
console.log('Comment authored by a bot — skipping to avoid loops.');
return;
}
// ── 2. Permission gate (mirrors the slash bot) ─────────────────────
const association = process.env.ACTOR_ASSOCIATION;
if (association !== 'OWNER' && association !== 'MEMBER') {
await addReaction('-1');
await postComment(
'❌ **PocketBase AI Bot**: @' + actor + ' is not authorized to use this command.\n' +
'Only org members (Contributors team) can use `@pocketbase-bot`.'
);
return;
}
// ── 3. Extract the instruction after the @pocketbase-bot handle ────
const commentBody = process.env.COMMENT_BODY || '';
const handleMatch = commentBody.match(/@pocketbase-bot(\[bot\])?/i);
if (!handleMatch) {
console.log('No @pocketbase-bot handle found — ignoring.');
return;
}
const instruction = commentBody.slice(handleMatch.index + handleMatch[0].length).trim();
if (!instruction) {
await addReaction('-1');
await postComment(
'ℹ️ **PocketBase AI Bot**: Tell me what to do, e.g.\n' +
'`@pocketbase-bot change RAM to 4096 on zigbee2mqtt` or `@pocketbase-bot disable script Nextcloud`.'
);
return;
}
// ── PocketBase auth + low-level helpers ────────────────────────────
const pbRaw = process.env.POCKETBASE_URL.replace(/\/$/, '');
const apiBase = /\/api$/i.test(pbRaw) ? pbRaw : pbRaw + '/api';
const coll = process.env.POCKETBASE_COLLECTION;
const recordsUrl = apiBase + '/collections/' + encodeURIComponent(coll) + '/records';
async function pbAuth() {
const res = await request(apiBase + '/collections/users/auth-with-password', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ identity: process.env.POCKETBASE_ADMIN_EMAIL, password: process.env.POCKETBASE_ADMIN_PASSWORD })
});
if (!res.ok) throw new Error('PocketBase auth failed: ' + res.body);
return JSON.parse(res.body).token;
}
async function pbFindRecord(token, slug) {
const filter = "(slug='" + String(slug).replace(/'/g, "''") + "')";
const res = await request(recordsUrl + '?filter=' + encodeURIComponent(filter) + '&perPage=1', { headers: { 'Authorization': token } });
const list = JSON.parse(res.body);
return list.items && list.items[0];
}
async function pbPatch(token, id, payload) {
return request(recordsUrl + '/' + id, {
method: 'PATCH',
headers: { 'Authorization': token, 'Content-Type': 'application/json' },
body: JSON.stringify(payload)
});
}
function readJsonBlob(val) {
if (Array.isArray(val)) return val;
try { return JSON.parse(val || '[]'); } catch (e) { return []; }
}
async function revalidate(s) {
const frontendUrl = process.env.FRONTEND_URL;
const secret = process.env.REVALIDATE_SECRET;
if (!frontendUrl || !secret) return;
try {
await request(frontendUrl.replace(/\/$/, '') + '/api/revalidate', {
method: 'POST',
headers: { 'Authorization': 'Bearer ' + secret, 'Content-Type': 'application/json' },
body: JSON.stringify({ tags: ['scripts', 'script-' + s] })
});
} catch (e) { console.warn('Revalidation skipped:', e.message); }
}
// ── CT-defaults sync PR (copied from slash bot) ────────────────────
function encodeContentPath(filePath) { return filePath.split('/').map(encodeURIComponent).join('/'); }
function decodeGitHubContent(content) { return Buffer.from((content || '').replace(/\n/g, ''), 'base64').toString('utf8'); }
function sanitizeBranchPart(value) {
return (value || '').toLowerCase().replace(/[^a-z0-9._/-]+/g, '-').replace(/\/+/g, '/').replace(/^-+|-+$/g, '');
}
function applyCtDefaultChanges(scriptText, varChanges) {
let nextText = scriptText;
const updatedVars = [], unchangedVars = [];
for (const [varName, rawValue] of Object.entries(varChanges)) {
const newValue = String(rawValue);
const pattern = new RegExp('(^\\s*' + varName + '="\\$\\{' + varName + ':-)([^"}]*)(\\}"\\s*$)', 'm');
const match = nextText.match(pattern);
if (!match) continue;
if (match[2] === newValue) { unchangedVars.push(varName); continue; }
nextText = nextText.replace(pattern, '$1' + newValue + '$3');
updatedVars.push(varName);
}
return { nextText, updatedVars, unchangedVars };
}
async function ensureBranch(defaultBranch, branchName) {
const ghRequest = ghDefault; // git ops run as the built-in token
const branchRefRes = await ghRequest('/repos/' + owner + '/' + repo + '/git/ref/heads/' + encodeURIComponent(branchName));
if (branchRefRes.ok) return;
const defaultRefRes = await ghRequest('/repos/' + owner + '/' + repo + '/git/ref/heads/' + encodeURIComponent(defaultBranch));
if (!defaultRefRes.ok) throw new Error('Could not read default branch ref: ' + defaultRefRes.body);
const defaultRef = JSON.parse(defaultRefRes.body);
const createBranchRes = await ghRequest('/repos/' + owner + '/' + repo + '/git/refs', 'POST', { ref: 'refs/heads/' + branchName, sha: defaultRef.object.sha });
if (!createBranchRes.ok) throw new Error('Could not create branch: ' + createBranchRes.body);
}
async function upsertCtDefaultsPr(slugValue, varChanges) {
const ghRequest = ghDefault; // contents/PR ops run as the built-in token
const wantedEntries = Object.entries(varChanges || {}).filter(function ([, v]) { return v !== undefined && v !== null && String(v) !== ''; });
if (wantedEntries.length === 0) return { status: 'skipped', reason: 'No mapped CT defaults changed.' };
const repoRes = await ghRequest('/repos/' + owner + '/' + repo);
if (!repoRes.ok) throw new Error('Could not read repository metadata: ' + repoRes.body);
const defaultBranch = JSON.parse(repoRes.body).default_branch;
const ctPath = 'ct/' + slugValue + '.sh';
const encodedCtPath = encodeContentPath(ctPath);
const defaultFileRes = await ghRequest('/repos/' + owner + '/' + repo + '/contents/' + encodedCtPath + '?ref=' + encodeURIComponent(defaultBranch));
if (defaultFileRes.statusCode === 404) return { status: 'skipped', reason: 'No matching CT file found at `' + ctPath + '`.' };
if (!defaultFileRes.ok) throw new Error('Could not read CT file from default branch: ' + defaultFileRes.body);
const branchName = 'pocketbase-sync/' + sanitizeBranchPart(slugValue || 'unknown');
await ensureBranch(defaultBranch, branchName);
const branchFileRes = await ghRequest('/repos/' + owner + '/' + repo + '/contents/' + encodedCtPath + '?ref=' + encodeURIComponent(branchName));
if (!branchFileRes.ok) throw new Error('Could not read CT file from sync branch: ' + branchFileRes.body);
const branchFile = JSON.parse(branchFileRes.body);
const currentBranchText = decodeGitHubContent(branchFile.content);
const updateResult = applyCtDefaultChanges(currentBranchText, Object.fromEntries(wantedEntries));
if (updateResult.updatedVars.length === 0) return { status: 'skipped', reason: 'CT defaults already up to date.' };
const putRes = await ghRequest('/repos/' + owner + '/' + repo + '/contents/' + encodedCtPath, 'PUT', {
message: 'chore(ct): sync ' + slugValue + ' defaults from PocketBase',
content: Buffer.from(updateResult.nextText, 'utf8').toString('base64'),
sha: branchFile.sha,
branch: branchName
});
if (!putRes.ok) throw new Error('Could not update CT file: ' + putRes.body);
const openPrRes = await ghRequest('/repos/' + owner + '/' + repo + '/pulls?state=open&head=' + encodeURIComponent(owner + ':' + branchName) + '&base=' + encodeURIComponent(defaultBranch));
if (!openPrRes.ok) throw new Error('Could not query existing PRs: ' + openPrRes.body);
const openPrs = JSON.parse(openPrRes.body);
if (openPrs.length > 0) return { status: 'updated', prUrl: openPrs[0].html_url, updatedVars: updateResult.updatedVars };
const createPrRes = await ghRequest('/repos/' + owner + '/' + repo + '/pulls', 'POST', {
title: 'chore(ct): sync ' + slugValue + ' defaults with PocketBase',
body: '## Summary\n- Sync default CT variables for `' + slugValue + '` after an `@pocketbase-bot` update.\n- Updated vars: `' + updateResult.updatedVars.join('`, `') + '`.\n\n## Source\n- Triggered by @' + actor + ' via PocketBase AI bot.\n',
head: branchName,
base: defaultBranch
});
if (!createPrRes.ok) throw new Error('Could not create PR: ' + createPrRes.body);
return { status: 'created', prUrl: JSON.parse(createPrRes.body).html_url, updatedVars: updateResult.updatedVars };
}
// ── Allow-lists (mirror the slash bot) ─────────────────────────────
const ALLOWED_FIELDS = {
name: 'string', description: 'string', logo: 'string', documentation: 'string',
website: 'string', project_url: 'string', repository: 'string', config_path: 'string',
tags: 'string', port: 'number', default_user: 'nullable_string', default_passwd: 'nullable_string',
unprivileged: 'number', updateable: 'boolean', privileged: 'boolean',
architectures: 'select_list', platforms: 'select_list',
is_dev: 'boolean', is_disabled: 'boolean', disable_message: 'string',
is_deleted: 'boolean', deleted_message: 'string'
};
const SELECT_VALUES = {
architectures: ['amd64', 'arm64'],
platforms: ['pve', 'incus'],
};
const FIELD_TO_CT_VAR = { tags: 'var_tags', unprivileged: 'var_unprivileged' };
const RESOURCE_KEYS = { cpu: 'number', ram: 'number', hdd: 'number', os: 'string', version: 'string' };
const METHOD_KEYS = { config_path: 'string', script: 'string' };
const ALL_METHOD_KEYS = Object.assign({}, RESOURCE_KEYS, METHOD_KEYS);
const RESOURCE_TO_CT_VAR = { cpu: 'var_cpu', ram: 'var_ram', hdd: 'var_disk', os: 'var_os', version: 'var_version' };
function castFieldValue(key, rawVal) {
const type = ALLOWED_FIELDS[key];
if (!type) return { error: 'Unknown field `' + key + '`' };
if (type === 'boolean') {
if (rawVal === true || rawVal === 'true') return { value: true };
if (rawVal === false || rawVal === 'false') return { value: false };
return { error: '`' + key + '` must be true/false' };
}
if (type === 'number') {
const n = parseInt(rawVal, 10);
if (isNaN(n)) return { error: '`' + key + '` must be a number' };
return { value: n };
}
if (type === 'select_list') {
// architectures/platforms are multi-selects over a closed set,
// so an unknown value is rejected rather than stored. The model
// may hand back an array or a comma-separated string.
const allowed = SELECT_VALUES[key] || [];
const raw = Array.isArray(rawVal) ? rawVal : String(rawVal == null ? '' : rawVal).split(',');
const values = raw.map(function (v) { return String(v).trim(); }).filter(Boolean);
const bad = values.filter(function (v) { return allowed.indexOf(v) === -1; });
if (bad.length > 0) return { error: '`' + key + '` accepts ' + allowed.join(', ') + ' — got: ' + bad.join(', ') };
return { value: values };
}
if (type === 'nullable_string') return { value: rawVal === '' || rawVal == null ? null : String(rawVal) };
return { value: String(rawVal) };
}
// ── Operation validation (used at propose AND confirm time) ────────
// Never trust raw operations: enforce the field/op allow-lists and
// re-cast values. Returns only well-formed, allowed operations.
function sanitizeOperations(ops) {
const validOps = [], problems = [];
for (const op of (Array.isArray(ops) ? ops : [])) {
if (op && op.kind === 'field') {
const cast = castFieldValue(op.field, op.value);
if (cast.error) { problems.push(cast.error); continue; }
validOps.push({ kind: 'field', field: op.field, value: cast.value });
} else if (op && op.kind === 'note' && ['add', 'edit', 'remove'].includes(op.action)) {
validOps.push({ kind: 'note', action: op.action, type: String(op.type || ''), text: op.text, newText: op.newText });
} else if (op && op.kind === 'method' && ['add', 'edit', 'remove'].includes(op.action)) {
const changes = {};
for (const [k, v] of Object.entries(op.changes || {})) { if (ALL_METHOD_KEYS[k]) changes[k] = v; }
validOps.push({ kind: 'method', action: op.action, type: String(op.type || 'default'), changes });
} else {
problems.push('Unsupported operation: `' + JSON.stringify(op) + '`');
}
}
return { validOps, problems };
}
// ── Executor: apply a validated {slug, operations} set ─────────────
async function applyOperations(action) {
const token = await pbAuth();
const record = await pbFindRecord(token, action.slug);
if (!record) return { ok: false, summary: '❌ No PocketBase record for slug `' + action.slug + '`.' };
const fieldPayload = {};
let notesArr = readJsonBlob(record.notes);
let methodsArr = readJsonBlob(record.install_methods);
let notesChanged = false, methodsChanged = false;
const ctChanges = {};
const lines = [];
for (const op of action.operations) {
if (op.kind === 'field') {
const cast = castFieldValue(op.field, op.value);
if (cast.error) { lines.push('- ⚠️ skipped field: ' + cast.error); continue; }
fieldPayload[op.field] = cast.value;
if (FIELD_TO_CT_VAR[op.field]) ctChanges[FIELD_TO_CT_VAR[op.field]] = cast.value;
lines.push('- `' + op.field + '` → `' + JSON.stringify(cast.value) + '`');
} else if (op.kind === 'note') {
const type = String(op.type || '').toLowerCase();
if (op.action === 'add') {
notesArr.push({ type, text: String(op.text || '') });
notesChanged = true; lines.push('- note add `' + type + '`: ' + op.text);
} else if (op.action === 'remove') {
const before = notesArr.length;
notesArr = notesArr.filter(function (n) { return !(String(n.type).toLowerCase() === type && n.text === op.text); });
if (notesArr.length !== before) { notesChanged = true; lines.push('- note remove `' + type + '`: ' + op.text); }
else lines.push('- ⚠️ note remove: no `' + type + '` note matched');
} else if (op.action === 'edit') {
const idx = notesArr.findIndex(function (n) { return String(n.type).toLowerCase() === type && n.text === op.text; });
if (idx !== -1) { notesArr[idx].text = String(op.newText || ''); notesChanged = true; lines.push('- note edit `' + type + '`'); }
else lines.push('- ⚠️ note edit: no `' + type + '` note matched');
}
} else if (op.kind === 'method') {
const type = String(op.type || '').toLowerCase();
const changes = op.changes || {};
if (op.action === 'remove') {
const before = methodsArr.length;
methodsArr = methodsArr.filter(function (im) { return String(im.type || '').toLowerCase() !== type; });
if (methodsArr.length !== before) { methodsChanged = true; lines.push('- method remove `' + type + '`'); }
else lines.push('- ⚠️ method remove: `' + type + '` not found');
} else {
let method = methodsArr.find(function (im) { return String(im.type || '').toLowerCase() === type; });
if (!method && op.action === 'add') { method = { type, resources: { cpu: 1, ram: 512, hdd: 4, os: 'debian', version: '13' } }; methodsArr.push(method); }
if (!method) { lines.push('- ⚠️ method edit: `' + type + '` not found'); continue; }
if (!method.resources) method.resources = {};
for (const [k, v] of Object.entries(changes)) {
if (RESOURCE_KEYS[k]) {
method.resources[k] = RESOURCE_KEYS[k] === 'number' ? parseInt(v, 10) : String(v);
if (RESOURCE_TO_CT_VAR[k]) ctChanges[RESOURCE_TO_CT_VAR[k]] = method.resources[k];
} else if (METHOD_KEYS[k]) {
method[k] = v === '' ? null : String(v);
}
}
methodsChanged = true;
lines.push('- method `' + (op.action === 'add' ? 'add' : 'edit') + '` `' + type + '`: ' + JSON.stringify(changes));
}
}
}
if (Object.keys(fieldPayload).length) {
const r = await pbPatch(token, record.id, fieldPayload);
if (!r.ok) return { ok: false, summary: '❌ Field update failed:\n```\n' + r.body + '\n```' };
}
if (notesChanged) {
const r = await pbPatch(token, record.id, { notes: notesArr });
if (!r.ok) return { ok: false, summary: '❌ Notes update failed:\n```\n' + r.body + '\n```' };
}
if (methodsChanged) {
const r = await pbPatch(token, record.id, { install_methods: methodsArr });
if (!r.ok) return { ok: false, summary: '❌ Install-method update failed:\n```\n' + r.body + '\n```' };
}
await revalidate(action.slug);
let ctNote = '';
if (Object.keys(ctChanges).length) {
try {
const sync = await upsertCtDefaultsPr(action.slug, ctChanges);
if (sync.status === 'created') ctNote = '\n\n**CT sync PR:** ' + sync.prUrl;
else if (sync.status === 'updated') ctNote = '\n\n**CT sync PR updated:** ' + sync.prUrl;
else if (sync.status === 'skipped') ctNote = '\n\n**CT sync skipped:** ' + sync.reason;
} catch (e) { ctNote = '\n\n**CT sync failed:** ' + e.message; }
}
return { ok: true, summary: lines.join('\n') + ctNote };
}
// ── 4. Confirm branch ──────────────────────────────────────────────
const PENDING_RE = /<!--\s*pocketbase-pending:\s*([A-Za-z0-9+/=]+)\s*-->/;
const isConfirm = /^(confirm|yes|apply|do it|y)\b/i.test(instruction);
if (isConfirm) {
const comments = await listIssueComments();
const appId = String(process.env.PB_BOT_APP_ID || '');
let pending = null, pendingComment = null;
for (let i = comments.length - 1; i >= 0; i--) {
const c = comments[i];
// Only trust a marker in a comment THIS bot app authored — otherwise a
// user could hand-craft a forged pocketbase-pending marker and confirm it.
const byBotApp = c.user && c.user.type === 'Bot' &&
c.performed_via_github_app && String(c.performed_via_github_app.id) === appId;
if (!byBotApp) continue;
const m = c.body && c.body.match(PENDING_RE);
if (m) { pending = m[1]; pendingComment = c; break; }
}
if (!pending) {
await addReaction('confused');
await postComment('🤔 **PocketBase AI Bot**: I have no pending change to confirm in this thread.');
return;
}
let action;
try { action = JSON.parse(Buffer.from(pending, 'base64').toString('utf8')); }
catch (e) { await postComment('❌ **PocketBase AI Bot**: Could not decode the pending change.'); return; }
// Re-validate the decoded operations before applying (defense-in-depth).
const recheck = sanitizeOperations(action.operations);
if (!action.slug || recheck.validOps.length === 0) {
await addReaction('-1');
await postComment('❌ **PocketBase AI Bot**: The pending change is no longer valid. Please restate the request.');
return;
}
action.operations = recheck.validOps;
let result;
try { result = await applyOperations(action); }
catch (e) { await addReaction('-1'); await postComment('❌ **PocketBase AI Bot**: ' + e.message); return; }
if (!result.ok) { await addReaction('-1'); await postComment(result.summary); return; }
await updateComment(pendingComment.id, pendingComment.body.replace(PENDING_RE, '<!-- pocketbase-applied -->'));
await addReaction('+1');
await postComment(
'✅ **PocketBase AI Bot**: Applied to **`' + action.slug + '`**\n\n' + result.summary +
'\n\n*Confirmed by @' + actor + '*'
);
return;
}
// ── 5. New request: acknowledge, fetch script list, call the model ─
await addReaction('eyes');
const token0 = await pbAuth();
const scripts = [];
let page = 1;
while (page <= 5) {
const res = await request(recordsUrl + '?fields=slug,name&perPage=500&page=' + page, { headers: { 'Authorization': token0 } });
if (!res.ok) break;
const data = JSON.parse(res.body);
(data.items || []).forEach(function (it) { if (it.slug) scripts.push({ slug: it.slug, name: it.name || it.slug }); });
if (!data.items || data.items.length < 500) break;
page++;
}
const SYSTEM_PROMPT =
'You translate a maintainer\'s natural-language request into a STRICT JSON change-set for a ' +
'script catalog (PocketBase). Respond with a SINGLE JSON object and nothing else.\n\n' +
'Schema:\n' +
'{\n' +
' "slug": string|null, // MUST be one of the known slugs below, chosen from the request\n' +
' "operations": [ ... ], // [] if you cannot determine concrete changes\n' +
' "human_summary": string, // short plain-English description\n' +
' "clarification": string|null // a question to ask if ambiguous/unsupported; else null\n' +
'}\n\n' +
'Operation kinds:\n' +
'- {"kind":"field","field":<one of: ' + Object.keys(ALLOWED_FIELDS).join(', ') + '>,"value":<bool|number|string>}\n' +
' (booleans true/false; "is_disabled"/"is_deleted"/"is_dev" are booleans; "port"/"unprivileged" are numbers; rest strings.)\n' +
'- {"kind":"note","action":"add"|"edit"|"remove","type":string,"text":string,"newText":string?}\n' +
'- {"kind":"method","action":"add"|"edit"|"remove","type":string,"changes":{cpu?:number,ram?:number,hdd?:number,os?:string,version?:string,config_path?:string,script?:string}}\n' +
' (RAM/HDD are in MB/GB; method "type" defaults to "default" if the user does not name one.)\n\n' +
'Rules:\n' +
'- Only use fields/operations listed above. If the request needs something else, set clarification and operations=[].\n' +
'- "disable"/"enable" map to is_disabled true/false. If disabling and the user gave a reason, also set disable_message.\n' +
'- Resolve the target script to a slug from the list. If you cannot confidently match exactly one, set slug=null and ask via clarification.\n\n' +
'Known scripts (slug — name):\n' +
scripts.map(function (s) { return s.slug + ' — ' + s.name; }).join('\n');
const modelRes = await request('https://models.github.ai/inference/chat/completions', {
method: 'POST',
headers: { 'Authorization': 'Bearer ' + process.env.MODELS_TOKEN, 'Content-Type': 'application/json', 'Accept': 'application/json' },
body: JSON.stringify({
model: process.env.AI_MODEL || 'openai/gpt-4o',
temperature: 0.1,
response_format: { type: 'json_object' },
messages: [{ role: 'system', content: SYSTEM_PROMPT }, { role: 'user', content: instruction }]
})
});
if (!modelRes.ok) {
await addReaction('-1');
await postComment('❌ **PocketBase AI Bot**: Model request failed (' + modelRes.statusCode + ').\n```\n' + modelRes.body.slice(0, 500) + '\n```');
return;
}
let parsed;
try {
const content = JSON.parse(modelRes.body).choices[0].message.content;
const cleaned = content.replace(/^```(?:json)?\s*/i, '').replace(/```\s*$/i, '').trim();
parsed = JSON.parse(cleaned);
} catch (e) {
await addReaction('-1');
await postComment('❌ **PocketBase AI Bot**: Could not parse the model response. Please rephrase.');
return;
}
// ── 6. Validate ────────────────────────────────────────────────────
const knownSlugs = new Set(scripts.map(function (s) { return s.slug; }));
const problems = [];
if (parsed.clarification) problems.push(parsed.clarification);
if (!parsed.slug || !knownSlugs.has(parsed.slug)) problems.push('I could not match the request to a known script.');
const sanitized = sanitizeOperations(parsed.operations);
const validOps = sanitized.validOps;
problems.push.apply(problems, sanitized.problems);
if (validOps.length === 0) problems.push('No concrete, supported change was found.');
if (problems.length) {
await addReaction('confused');
await postComment(
'🤔 **PocketBase AI Bot**: I need a bit more to act on that.\n\n- ' + problems.join('\n- ') +
'\n\nTry naming the script and the exact change, e.g. `@pocketbase-bot set RAM to 4096 on zigbee2mqtt`.'
);
return;
}
// ── 7. Propose (do NOT apply yet) ──────────────────────────────────
const action = { slug: parsed.slug, operations: validOps };
const bullets = validOps.map(function (op) {
if (op.kind === 'field') return '- `' + op.field + '` → `' + JSON.stringify(op.value) + '`';
if (op.kind === 'note') return '- note ' + op.action + ' `' + op.type + '`' + (op.text ? ': ' + op.text : '');
return '- method ' + op.action + ' `' + op.type + '`: ' + JSON.stringify(op.changes);
}).join('\n');
const marker = '<!-- pocketbase-pending: ' + Buffer.from(JSON.stringify(action), 'utf8').toString('base64') + ' -->';
await addReaction('+1');
await postComment(
'🤖 **PocketBase AI Bot** — please confirm\n\n' +
(parsed.human_summary ? '> ' + parsed.human_summary + '\n\n' : '') +
'**Target:** `' + action.slug + '`\n**Proposed changes:**\n' + bullets + '\n\n' +
'Reply **`@pocketbase-bot confirm`** to apply, or restate the request to adjust.\n' + marker
);
})().catch(function (e) {
console.error('Fatal error:', e && (e.message || e));
process.exit(1);
});
ENDSCRIPT
+115 -137
View File
@@ -107,6 +107,9 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
@@ -120,7 +123,7 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
<details>
<summary><h4>September (19 entries)</h4></summary>
<summary><h4>September (26 entries)</h4></summary>
[View September 2026 Changelog](.github/changelogs/2026/09.md)
@@ -546,6 +549,116 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-09-29
### 🆕 New Scripts
- Anki Sync Server ([#17416](https://github.com/community-scripts/ProxmoxVE/pull/17416))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(romm): snapshot Redis hourly like the upstream image [@DenislavDenev](https://github.com/DenislavDenev) ([#17562](https://github.com/community-scripts/ProxmoxVE/pull/17562))
- checkmate: bump Node.js from 22 to 24 [@github-actions[bot]](https://github.com/github-actions[bot]) ([#17554](https://github.com/community-scripts/ProxmoxVE/pull/17554))
### 💾 Core
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#77](https://github.com/community-scripts/core/pull/77))
- Default the scripts base to ProxmoxVE [@MickLesk](https://github.com/MickLesk) ([core#76](https://github.com/community-scripts/core/pull/76))
- Generate app headers [@github-actions[bot]](https://github.com/github-actions[bot]) ([core#75](https://github.com/community-scripts/core/pull/75))
## 2026-09-28
### 🚀 Updated Scripts
- Immich: Pin version to 3.2.4 [@vhsdream](https://github.com/vhsdream) ([#17564](https://github.com/community-scripts/ProxmoxVE/pull/17564))
- #### 🐞 Bug Fixes
- fix(autocaliweb): wire .env into all service units, not just autocali… [@bobartlett](https://github.com/bobartlett) ([#17561](https://github.com/community-scripts/ProxmoxVE/pull/17561))
- Zipline: Change cp command [@Mraedis](https://github.com/Mraedis) ([#17559](https://github.com/community-scripts/ProxmoxVE/pull/17559))
- Borg-UI: start through upstream's start.sh so migrations run [@MickLesk](https://github.com/MickLesk) ([#17563](https://github.com/community-scripts/ProxmoxVE/pull/17563))
- linkding: serve favicons and preview images [@MickLesk](https://github.com/MickLesk) ([#17557](https://github.com/community-scripts/ProxmoxVE/pull/17557))
- SparkyFitness: Fill in the nginx resolver 1.7.3 added [@MickLesk](https://github.com/MickLesk) ([#17556](https://github.com/community-scripts/ProxmoxVE/pull/17556))
- #### 🔧 Refactor
- Plane: Replace MinIO installation with Silo [@MickLesk](https://github.com/MickLesk) ([#17347](https://github.com/community-scripts/ProxmoxVE/pull/17347))
## 2026-09-27
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(aurral): bump to Node 26 and bypass strict engine pin [@JodyVanden](https://github.com/JodyVanden) ([#17543](https://github.com/community-scripts/ProxmoxVE/pull/17543))
- Tracearr: fetch map tiles on install/update [@durzo](https://github.com/durzo) ([#17544](https://github.com/community-scripts/ProxmoxVE/pull/17544))
- fix(autocaliweb): define INSTALL_DIR before first use [@bobartlett](https://github.com/bobartlett) ([#17545](https://github.com/community-scripts/ProxmoxVE/pull/17545))
## 2026-09-26
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Manyfold: make /opt/manyfold_data writable for the manyfold user [@sergstepanenko](https://github.com/sergstepanenko) ([#17534](https://github.com/community-scripts/ProxmoxVE/pull/17534))
- steamcmd: update itself before installing Satisfactory [@MickLesk](https://github.com/MickLesk) ([#17526](https://github.com/community-scripts/ProxmoxVE/pull/17526))
- AudioMuse-AI: build noavx2 environment on Python 3.11 [@MickLesk](https://github.com/MickLesk) ([#17528](https://github.com/community-scripts/ProxmoxVE/pull/17528))
- LobeHub: pin lobehub/ui at 5.49 while LobeHub's stable release needs it [@MickLesk](https://github.com/MickLesk) ([#17531](https://github.com/community-scripts/ProxmoxVE/pull/17531))
- Keep Trilium updates on the server releases [@MickLesk](https://github.com/MickLesk) ([#17525](https://github.com/community-scripts/ProxmoxVE/pull/17525))
- NginxProxyManager: generate admin config and repair certbot's venv on update [@MickLesk](https://github.com/MickLesk) ([#17523](https://github.com/community-scripts/ProxmoxVE/pull/17523))
- Komodo: add KOMODO_HOST | fix broken spinner [@MickLesk](https://github.com/MickLesk) ([#17481](https://github.com/community-scripts/ProxmoxVE/pull/17481))
- romm: run rq cron and a scans worker for RomM 5.3 [@davidbb](https://github.com/davidbb) ([#17502](https://github.com/community-scripts/ProxmoxVE/pull/17502))
- #### 💥 Breaking Changes
- Semaphore: fix BoltDB migration by pinning 2.18.30 [@MickLesk](https://github.com/MickLesk) ([#17439](https://github.com/community-scripts/ProxmoxVE/pull/17439))
### 💾 Core
- Keep a dash-led bridge comment out of whiptail's options [@MickLesk](https://github.com/MickLesk) ([core#74](https://github.com/community-scripts/core/pull/74))
## 2026-09-25
### 🆕 New Scripts
- RustFS ([#17499](https://github.com/community-scripts/ProxmoxVE/pull/17499))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Ignis: take the Obsidian version from release tag [@MickLesk](https://github.com/MickLesk) ([#17503](https://github.com/community-scripts/ProxmoxVE/pull/17503))
- #### 🔧 Refactor
- Refactor: Umbrel OS VM [@MickLesk](https://github.com/MickLesk) ([#17505](https://github.com/community-scripts/ProxmoxVE/pull/17505))
- Docker-LXC: remove Portainer installation from install [@MickLesk](https://github.com/MickLesk) ([#17493](https://github.com/community-scripts/ProxmoxVE/pull/17493))
### 💾 Core
- Incus: make prompts visible for end-user [@MickLesk](https://github.com/MickLesk) ([core#73](https://github.com/community-scripts/core/pull/73))
- incus: do not let an install script block on an invisible prompt [@MickLesk](https://github.com/MickLesk) ([core#71](https://github.com/community-scripts/core/pull/71))
- tel: report progress from installs only, not updates [@MickLesk](https://github.com/MickLesk) ([core#72](https://github.com/community-scripts/core/pull/72))
## 2026-09-24
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Declare the RomM filesystem structure required since 5.3.0 [@MickLesk](https://github.com/MickLesk) ([#17480](https://github.com/community-scripts/ProxmoxVE/pull/17480))
- general: use apt_update_safe instead of aborting on a failed apt update [@MickLesk](https://github.com/MickLesk) ([#17462](https://github.com/community-scripts/ProxmoxVE/pull/17462))
- #### 🔧 Refactor
- Journiv: Serve Node Frontend and add HTTP Auth .env [@MickLesk](https://github.com/MickLesk) ([#17479](https://github.com/community-scripts/ProxmoxVE/pull/17479))
### 💾 Core
- core: accept an off-subnet gateway for /31 and /32 [@MickLesk](https://github.com/MickLesk) ([core#70](https://github.com/community-scripts/core/pull/70))
## 2026-09-23
### 🚀 Updated Scripts
@@ -1148,139 +1261,4 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
- #### 🔧 Refactor
- Refactor: Calibre-Web database creation [@MickLesk](https://github.com/MickLesk) ([#16842](https://github.com/community-scripts/ProxmoxVE/pull/16842))
- mastodon: read .ruby-version dynamically instead of hardcoding 4.0.5 [@MickLesk](https://github.com/MickLesk) ([#16829](https://github.com/community-scripts/ProxmoxVE/pull/16829))
## 2026-08-27
### 🆕 New Scripts
- Seanime ([#16777](https://github.com/community-scripts/ProxmoxVE/pull/16777))
- Yopass ([#16778](https://github.com/community-scripts/ProxmoxVE/pull/16778))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- excalidash: Add a sed to switch to the correct DB Provider [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#16814](https://github.com/community-scripts/ProxmoxVE/pull/16814))
- fix(stirling-pdf): remove broken ExecStop using %n [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#16813](https://github.com/community-scripts/ProxmoxVE/pull/16813))
### 🧰 Tools
- #### 🐞 Bug Fixes
- Fix: Incorporate the new update functions to prevent a empty grep on … [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#16809](https://github.com/community-scripts/ProxmoxVE/pull/16809))
## 2026-08-26
### 🆕 New Scripts
- CentOS ([#16772](https://github.com/community-scripts/ProxmoxVE/pull/16772))
- AlmaLinux ([#16771](https://github.com/community-scripts/ProxmoxVE/pull/16771))
- Fedora ([#16770](https://github.com/community-scripts/ProxmoxVE/pull/16770))
- Devuan ([#16773](https://github.com/community-scripts/ProxmoxVE/pull/16773))
- OpenEuler ([#16774](https://github.com/community-scripts/ProxmoxVE/pull/16774))
- Gentoo ([#16775](https://github.com/community-scripts/ProxmoxVE/pull/16775))
- openSUSE ([#16776](https://github.com/community-scripts/ProxmoxVE/pull/16776))
- Directus ([#16779](https://github.com/community-scripts/ProxmoxVE/pull/16779))
- HAProxy ([#16760](https://github.com/community-scripts/ProxmoxVE/pull/16760))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- [Fix]: LimeSurvey - enable Apache mod_rewrite [@jonathan8devs](https://github.com/jonathan8devs) ([#16767](https://github.com/community-scripts/ProxmoxVE/pull/16767))
- endurain: migrate legacy FRONTEND_DIR path on update [@MickLesk](https://github.com/MickLesk) ([#16794](https://github.com/community-scripts/ProxmoxVE/pull/16794))
### 💾 Core
- #### 🐞 Bug Fixes
- tools.func: recognize bare XZ-compressed tarballs in fetch_and_deploy* [@MickLesk](https://github.com/MickLesk) ([#16796](https://github.com/community-scripts/ProxmoxVE/pull/16796))
- tools.func: fix mongodb version comparison, guard apt purge against removing dependents [@MickLesk](https://github.com/MickLesk) ([#16795](https://github.com/community-scripts/ProxmoxVE/pull/16795))
### 📂 Github
- github: teach the PocketBase bot every field [@MickLesk](https://github.com/MickLesk) ([#16781](https://github.com/community-scripts/ProxmoxVE/pull/16781))
## 2026-08-25
### 🆕 New Scripts
- Budget-Board ([#16714](https://github.com/community-scripts/ProxmoxVE/pull/16714))
- Maintainerr ([#16716](https://github.com/community-scripts/ProxmoxVE/pull/16716))
- pyLoad ([#16717](https://github.com/community-scripts/ProxmoxVE/pull/16717))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- fix(apache-tika): handle upstream's switch from jar to zip distribution [@Munza2020](https://github.com/Munza2020) ([#16726](https://github.com/community-scripts/ProxmoxVE/pull/16726))
- Fix Firecrawl install: add ccache dependency for koffi native build [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#16746](https://github.com/community-scripts/ProxmoxVE/pull/16746))
- excalidash: Fix broken Update [@michelroegl-brunner](https://github.com/michelroegl-brunner) ([#16747](https://github.com/community-scripts/ProxmoxVE/pull/16747))
- #### 💥 Breaking Changes
- Migrate the (remaining) Top 25 scripts to the new core engine [@MickLesk](https://github.com/MickLesk) ([#16749](https://github.com/community-scripts/ProxmoxVE/pull/16749))
## 2026-08-24
### 🆕 New Scripts
- ArchLinux ([#16715](https://github.com/community-scripts/ProxmoxVE/pull/16715))
- AirTrail ([#16713](https://github.com/community-scripts/ProxmoxVE/pull/16713))
- RockyLinux ([#16718](https://github.com/community-scripts/ProxmoxVE/pull/16718))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Add setup_mongodb back in Omada [@lucacome](https://github.com/lucacome) ([#16736](https://github.com/community-scripts/ProxmoxVE/pull/16736))
- fireshare: source fireshare.env during update [@MickLesk](https://github.com/MickLesk) ([#16706](https://github.com/community-scripts/ProxmoxVE/pull/16706))
- netbox: serve on plain HTTP too, port 80 forced HTTPS redirect broke reverse proxies [@MickLesk](https://github.com/MickLesk) ([#16707](https://github.com/community-scripts/ProxmoxVE/pull/16707))
- FileFlows: Fix Download URL [@MickLesk](https://github.com/MickLesk) ([#16708](https://github.com/community-scripts/ProxmoxVE/pull/16708))
- Gitea: fix git-over-SSH auth, group-writable home dir tripped sshd StrictModes [@MickLesk](https://github.com/MickLesk) ([#16710](https://github.com/community-scripts/ProxmoxVE/pull/16710))
### 🧰 Tools
- #### 🐞 Bug Fixes
- post-pve/pbs-install: fix component_exists_in_sources matching substrings of hyphenated tokens [@MickLesk](https://github.com/MickLesk) ([#16709](https://github.com/community-scripts/ProxmoxVE/pull/16709))
## 2026-08-23
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Set default ProxmoxVE raw URL in PVE-UPS & fix var_cpu sorting [@MickLesk](https://github.com/MickLesk) ([#16689](https://github.com/community-scripts/ProxmoxVE/pull/16689))
## 2026-08-22
### 🆕 New Scripts
- pve-ups ([#16670](https://github.com/community-scripts/ProxmoxVE/pull/16670))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- docuseal: use DocuSeal's patched PDFium build to fix service start [@MickLesk](https://github.com/MickLesk) ([#16673](https://github.com/community-scripts/ProxmoxVE/pull/16673))
- #### ✨ New Features
- update authentik to 2026.8.0 [@thieneret](https://github.com/thieneret) ([#16674](https://github.com/community-scripts/ProxmoxVE/pull/16674))
## 2026-08-21
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- wallos: fix: migrations [@CrazyWolf13](https://github.com/CrazyWolf13) ([#16666](https://github.com/community-scripts/ProxmoxVE/pull/16666))
- barassistant: fix: compatibility with v6 [@CrazyWolf13](https://github.com/CrazyWolf13) ([#16665](https://github.com/community-scripts/ProxmoxVE/pull/16665))
- Immichframe: remove settings.yaml UUID placeholder [@MickLesk](https://github.com/MickLesk) ([#16660](https://github.com/community-scripts/ProxmoxVE/pull/16660))
- openziti-controller: redirect stdin from /dev/null to skip postinst's interactive bootstrap prompt [@MickLesk](https://github.com/MickLesk) ([#16650](https://github.com/community-scripts/ProxmoxVE/pull/16650))
- bookorbit: bump default RAM to prevent tsc OOM segfault during nest build [@MickLesk](https://github.com/MickLesk) ([#16649](https://github.com/community-scripts/ProxmoxVE/pull/16649))
- immich: split jpegli into its own build step, resolve library revisions dynamically [@MickLesk](https://github.com/MickLesk) ([#16656](https://github.com/community-scripts/ProxmoxVE/pull/16656))
- tdarr: make unzip non-interactive to prevent hang [@MickLesk](https://github.com/MickLesk) ([#16648](https://github.com/community-scripts/ProxmoxVE/pull/16648))
- immich: fix jpegli patch path after upstream base-images split jpegli from libjxl [@MickLesk](https://github.com/MickLesk) ([#16647](https://github.com/community-scripts/ProxmoxVE/pull/16647))
- mastodon: read .ruby-version dynamically instead of hardcoding 4.0.5 [@MickLesk](https://github.com/MickLesk) ([#16829](https://github.com/community-scripts/ProxmoxVE/pull/16829))
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
setup_mariadb
if check_for_gh_release "2fauth" "Bubka/2FAuth"; then
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_info "Creating Backup"
+66
View File
@@ -0,0 +1,66 @@
#!/usr/bin/env bash
_CS_DEFAULT_URL="https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main"
_cs_boot="${COMMUNITY_SCRIPTS_CORE_DIR:-$(dirname "${BASH_SOURCE[0]}")/../../core}/core/build.func"
source "$_cs_boot" 2>/dev/null || source <(curl -fsSL "${COMMUNITY_SCRIPTS_CORE_URL:-https://raw.githubusercontent.com/community-scripts/core/main}/core/build.func")
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://docs.ankiweb.net/sync-server.html
APP="Anki-Sync-Server"
var_tags="${var_tags:-anki;flashcards;sync}"
var_cpu="${var_cpu:-1}"
var_ram="${var_ram:-512}"
var_disk="${var_disk:-4}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /opt/anki-sync-server/.env ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "anki-sync-server" "ankitects/anki"; then
msg_info "Stopping Service"
systemctl stop anki-sync-server
msg_ok "Stopped Service"
create_backup /opt/anki-sync-server/.env /opt/anki-sync-server/data
msg_info "Updating Anki Sync Server"
$STD uv pip install --python /opt/anki-sync-server/venv/bin/python "anki==$(get_latest_github_release "ankitects/anki")"
cat <<EOF >~/.anki-sync-server
$(get_latest_github_release "ankitects/anki")
EOF
msg_ok "Updated Anki Sync Server"
restore_backup
msg_info "Starting Service"
systemctl start anki-sync-server
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:8080${CL}"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating Apache Cassandra"
$STD apt update
apt_update_safe
$STD apt install -y --only-upgrade cassandra cassandra-tools
msg_ok "Updated Apache Cassandra"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating Apache CouchDB"
$STD apt-get update
apt_update_safe
$STD apt-get install -y --only-upgrade couchdb
msg_ok "Updated Apache CouchDB"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating Apt-Cacher-NG"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated Apt-Cacher-NG"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating Aria2"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated Aria2"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
msg_info "Updating AudiobookShelf"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated AudiobookShelf"
msg_ok "Updated successfully!"
+3 -1
View File
@@ -41,6 +41,7 @@ function update_script() {
AUDIOMUSE_BACKEND="$(cat /opt/audiomuse-ai_data/.backend 2>/dev/null || echo cpu)"
REQ_COMMON="common.txt"
PY_VERSION="3.12"
case "$AUDIOMUSE_BACKEND" in
gpu)
REQ_ACCEL="gpu.txt"
@@ -49,6 +50,7 @@ function update_script() {
cpu-noavx2)
REQ_COMMON="common-noavx2.txt"
REQ_ACCEL="cpu-noavx2.txt"
PY_VERSION="3.11"
;;
*)
REQ_ACCEL="cpu.txt"
@@ -57,7 +59,7 @@ function update_script() {
msg_info "Updating Python Environment (${AUDIOMUSE_BACKEND})"
cd /opt/audiomuse-ai
$STD uv venv --seed --python 3.12 /opt/audiomuse-ai/.venv
$STD uv venv --seed --python "$PY_VERSION" /opt/audiomuse-ai/.venv
$STD uv pip install --python /opt/audiomuse-ai/.venv \
-r "/opt/audiomuse-ai/requirements/${REQ_COMMON}" \
-r "/opt/audiomuse-ai/requirements/${REQ_ACCEL}"
+4 -1
View File
@@ -38,13 +38,16 @@ function update_script() {
msg_ok "Stopped Service"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "aurral" "lklynet/aurral" "tarball"
NODE_VERSION="22" setup_nodejs
NODE_VERSION="26" setup_nodejs
msg_info "Updating Aurral"
cd /opt/aurral
export VITE_APP_VERSION="$(cat ~/.aurral)"
export VITE_GITHUB_REPO="lklynet/aurral"
export VITE_RELEASE_CHANNEL="stable"
# aurral's .npmrc sets engine-strict=true and pins an exact node patch (e.g. 26.8.x),
# which NodeSource can't match since it only ships the latest patch per major.
export npm_config_engine_strict=false
$STD npm ci --workspace frontend --include-workspace-root=false
$STD npm run build --workspace frontend
$STD npm ci --workspace backend --omit=dev --include=optional --include-workspace-root=false
+1 -1
View File
@@ -34,7 +34,7 @@ function update_script() {
fi
if check_for_gh_release "authelia" "authelia/authelia"; then
$STD apt update
apt_update_safe
$STD apt -y upgrade
fetch_and_deploy_gh_release "authelia" "authelia/authelia" "binary"
msg_ok "Updated successfully!"
+31 -9
View File
@@ -32,15 +32,9 @@ function update_script() {
exit
fi
if grep -q -- '--workers 2' /etc/systemd/system/borg-ui.service 2>/dev/null; then
msg_info "Reducing Service to a single worker"
sed -i 's/--workers 2/--workers 1/' /etc/systemd/system/borg-ui.service
systemctl daemon-reload
systemctl try-restart borg-ui
msg_ok "Reduced Service to a single worker"
fi
local changed=0
if check_for_gh_release "borg-ui" "karanhudia/borg-ui"; then
changed=1
msg_info "Stopping Service"
systemctl stop borg-ui
msg_ok "Stopped Service"
@@ -110,9 +104,37 @@ function update_script() {
$STD uv venv --python "$BORG_PYTHON" /opt/borg-ui/.venv
$STD uv pip install --python /opt/borg-ui/.venv -r requirements.txt
msg_ok "Updated Python Environment"
fi
if [[ -f /opt/borg-ui/packaging/native/start.sh ]] && ! grep -q 'packaging/native/start.sh' /etc/systemd/system/borg-ui.service; then
msg_info "Switching Service to the upstream start script"
cat <<EOF >/etc/systemd/system/borg-ui.service
[Unit]
Description=Borg-UI
Wants=network-online.target
After=network-online.target
[Service]
Type=simple
User=root
WorkingDirectory=/opt/borg-ui
EnvironmentFile=/opt/borg-ui/.env
Environment=BORG_UI_VENV=/opt/borg-ui/.venv
ExecStart=/bin/bash /opt/borg-ui/packaging/native/start.sh
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl daemon-reload
msg_ok "Switched Service to the upstream start script"
changed=1
fi
if [[ "$changed" == 1 ]]; then
msg_info "Starting Service"
systemctl start borg-ui
systemctl restart borg-ui
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
+1 -1
View File
@@ -39,7 +39,7 @@ Package: bunkerweb
Pin: version ${RELEASE}
Pin-Priority: 1001
EOF
$STD apt update
apt_update_safe
$STD apt-mark unhold bunkerweb nginx
$STD apt install -y --allow-downgrades bunkerweb="${RELEASE}"
msg_ok "Updated BunkerWeb"
+1 -1
View File
@@ -40,7 +40,7 @@ update_deb_based() {
fi
msg_info "Updating Caddy LXC"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Caddy LXC"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt-get update
apt_update_safe
$STD apt-get -y upgrade
msg_ok "Updated ${APP} LXC"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated $APP LXC"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated ${APP} LXC"
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating ddclient"
$STD apt update
apt_update_safe
$STD apt install --only-upgrade -y ddclient
$STD systemctl restart ddclient
msg_ok "Updated ddclient"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated $APP LXC"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating deCONZ"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated deCONZ"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating Defguard"
$STD apt update
apt_update_safe
$STD apt install -y defguard defguard-proxy
msg_ok "Updated Defguard"
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
msg_info "Updating Deluge"
ensure_dependencies python3-setuptools
$STD apt update
apt_update_safe
$STD pip3 install deluge[all] "pyopenssl<25" --upgrade
msg_ok "Updated Deluge"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
exit
fi
msg_info "Updating Devuan LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated Devuan LXC"
exit
+1 -3
View File
@@ -36,7 +36,7 @@ catch_errors
update_deb_based() {
msg_info "Updating base system"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Base system updated"
@@ -73,5 +73,3 @@ description
msg_ok "Completed successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW} Portainer is available as a separate addon. Install it with:${CL}"
echo -e "${GATEWAY}${BGN}bash -c \"\$(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/tools/addon/portainer.sh)\"${CL}"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt-get update
apt_update_safe
$STD apt-get -y upgrade
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -37,7 +37,7 @@ function update_script() {
msg_ok "Service stopped"
msg_info "Updating Debian LXC"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Debian LXC"
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating ${APP}"
$STD apt update
apt_update_safe
$STD apt install -y elasticsearch
msg_ok "Updated ${APP}"
+1 -1
View File
@@ -34,7 +34,7 @@ function update_script() {
NODE_VERSION="22" NODE_MODULE="yarn" setup_nodejs
msg_info "Updating LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated LXC"
+1 -1
View File
@@ -40,7 +40,7 @@ function update_script() {
"main"
fi
msg_info "Updating evcc LXC"
$STD apt update
apt_update_safe
$STD apt --only-upgrade install -y evcc
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
msg_info "Updating FHEM"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated FHEM"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating GitLab (Patience)"
$STD apt update
apt_update_safe
$STD apt install -y gitlab-ce
msg_ok "Updated GitLab"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
fi
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated $APP LXC"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -49,7 +49,7 @@ update_deb_based() {
fi
msg_info "Updating Grafana LXC"
$STD apt update
apt_update_safe
$STD apt --only-upgrade install -y grafana
msg_ok "Updated successfully!"
}
+3 -3
View File
@@ -43,17 +43,17 @@ function update_script() {
MONGO_VERSION="8.2" setup_mongodb
msg_info "Updating Graylog"
$STD apt update
apt_update_safe
$STD apt upgrade -y
curl -fsSL "https://packages.graylog2.org/repo/packages/graylog-7.0-repository_latest.deb" -o "graylog-7.0-repository_latest.deb"
$STD dpkg -i graylog-7.0-repository_latest.deb
$STD apt update
apt_update_safe
ensure_dependencies graylog-server graylog-datanode
rm -f graylog-7.0-repository_latest.deb
msg_ok "Updated Graylog"
elif dpkg --compare-versions "$CURRENT_VERSION" ge "7.0"; then
msg_info "Updating Graylog"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Graylog"
fi
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating ${APP}"
$STD apt update
apt_update_safe
$STD apt install -y haproxy
msg_ok "Updated ${APP}"
+6
View File
@@ -0,0 +1,6 @@
___ __ _ _____ _____
/ | ____ / /__(_) / ___/__ ______ _____ / ___/___ ______ _____ _____
/ /| | / __ \/ //_/ /_____\__ \/ / / / __ \/ ___/_____\__ \/ _ \/ ___/ | / / _ \/ ___/
/ ___ |/ / / / ,< / /_____/__/ / /_/ / / / / /__/_____/__/ / __/ / | |/ / __/ /
/_/ |_/_/ /_/_/|_/_/ /____/\__, /_/ /_/\___/ /____/\___/_/ |___/\___/_/
/____/
+6
View File
@@ -0,0 +1,6 @@
____ __ ___________
/ __ \__ _______/ /_/ ____/ ___/
/ /_/ / / / / ___/ __/ /_ \__ \
/ _, _/ /_/ (__ ) /_/ __/ ___/ /
/_/ |_|\__,_/____/\__/_/ /____/
+1 -1
View File
@@ -63,7 +63,7 @@ EOF
fi
msg_info "Updating Nodejs"
$STD apt update
apt_update_safe
$STD apt upgrade nodejs -y
msg_ok "Updated Nodejs"
+1 -1
View File
@@ -63,7 +63,7 @@ function update_script() {
fi
if [ "$UPD" == "3" ]; then
msg_info "Installing Home Assistant Community Store (HACS)"
$STD apt update
apt_update_safe
cd /var/lib/docker/volumes/hass_config/_data
$STD bash <(curl -fsSL https://get.hacs.xyz)
msg_ok "Installed Home Assistant Community Store (HACS)"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt install -y homebridge
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
exit
fi
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated $APP LXC"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt install -y hyperion
msg_ok "Updated successfully!"
exit
+8 -3
View File
@@ -49,9 +49,14 @@ function update_script() {
msg_ok "Built Ignis"
msg_info "Checking Obsidian Web Assets"
OBSIDIAN_VERSION=$(grep -oP 'OBSIDIAN_VERSION=\K[0-9.]+' /opt/ignis/apps/ignis-server/Dockerfile | head -n1)
[[ -z "$OBSIDIAN_VERSION" ]] && OBSIDIAN_VERSION="$(cat /opt/ignis_data/obsidian.version 2>/dev/null)"
if [[ -n "$OBSIDIAN_VERSION" && "$OBSIDIAN_VERSION" != "$(cat /opt/ignis_data/obsidian.version 2>/dev/null)" ]]; then
# From the release tag (0.8.13+obsidian.1.13.7): upstream renamed the Dockerfile variable.
OBSIDIAN_VERSION=""
[[ "${IGNIS_BUILD:-}" == *obsidian.* ]] && OBSIDIAN_VERSION="${IGNIS_BUILD##*obsidian.}"
if [[ ! "$OBSIDIAN_VERSION" =~ ^[0-9]+(\.[0-9]+)+$ ]]; then
OBSIDIAN_VERSION="$(grep -ohP '(OBSIDIAN_VERSION|IGNIS_OBSIDIAN_PIN)=\K[0-9.]+' /opt/ignis/apps/ignis-server/Dockerfile 2>/dev/null | head -n1 || true)"
fi
[[ "$OBSIDIAN_VERSION" =~ ^[0-9]+(\.[0-9]+)+$ ]] || msg_warn "Could not determine the paired Obsidian version - keeping the installed assets"
if [[ "$OBSIDIAN_VERSION" =~ ^[0-9]+(\.[0-9]+)+$ && "$OBSIDIAN_VERSION" != "$(cat /opt/ignis_data/obsidian.version 2>/dev/null)" ]]; then
rm -rf /opt/ignis_data/obsidian-app
mkdir -p /opt/ignis_data/obsidian-app
curl -fsSL -o /tmp/obsidian.asar.gz "https://github.com/obsidianmd/obsidian-releases/releases/download/v${OBSIDIAN_VERSION}/obsidian-${OBSIDIAN_VERSION}.asar.gz"
+3 -5
View File
@@ -56,7 +56,7 @@ Pin:release a=testing
Pin-Priority: 450
EOF
[[ -f /etc/apt/preferences.d/immich ]] && rm /etc/apt/preferences.d/immich
$STD apt update
apt_update_safe
msg_ok "Added Debian Testing repo"
fi
@@ -113,7 +113,7 @@ EOF
msg_ok "Image-processing libraries up to date"
fi
RELEASE="v3.2.2"
RELEASE="v3.2.4"
if check_for_gh_release "Immich" "immich-app/immich" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
if [[ $(cat ~/.immich) > "2.5.1" ]]; then
msg_info "Enabling Maintenance Mode"
@@ -193,8 +193,6 @@ EOF
export SHARP_FORCE_GLOBAL_LIBVIPS=true
$STD pnpm --dir "$APP_DIR/node_modules/sharp" exec npm run build
ln -sfn "$GEO_DIR" "$APP_DIR/geodata"
# Patch helmet.json: disable upgrade-insecure-requests for HTTP access
if [[ -f "$APP_DIR/helmet.json" ]]; then
jq '.contentSecurityPolicy.directives["upgrade-insecure-requests"] = null' "$APP_DIR/helmet.json" >"$APP_DIR/helmet.json.tmp" && mv "$APP_DIR/helmet.json.tmp" "$APP_DIR/helmet.json"
@@ -325,7 +323,7 @@ EOF
[[ ! -f "$GEO_DIR/countryInfo.txt" ]] && curl_with_retry "https://download.geonames.org/export/dump/countryInfo.txt" "countryInfo.txt"
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$APP_DIR"/upload
ln -s "${UPLOAD_DIR:-/opt/immich/upload}" "$ML_DIR"/upload
ln -s "$GEO_DIR" "$APP_DIR"
ln -sfn "$GEO_DIR" "$APP_DIR/geodata"
[[ ! -f /usr/bin/immich ]] && ln -sf "$APP_DIR"/cli/bin/immich /usr/bin/immich
[[ ! -f /usr/bin/immich-admin ]] && ln -sf "$APP_DIR"/bin/immich-admin /usr/bin/immich-admin
+1 -1
View File
@@ -42,7 +42,7 @@ function update_script() {
msg_ok "Created backup"
msg_info "Updating Infisical"
$STD apt update
apt_update_safe
$STD apt install -y infisical-core
$STD infisical-ctl reconfigure
msg_ok "Updated Infisical"
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
msg_info "Updating InfluxDB"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated InfluxDB"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -38,7 +38,7 @@ function update_script() {
fi
msg_info "Updating InvenTree"
$STD apt update
apt_update_safe
$STD apt install --only-upgrade inventree -y
msg_ok "Updated InvenTree"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -34,7 +34,7 @@ function update_script() {
NODE_VERSION="24" NPM_VERSION="11" setup_nodejs
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -34,7 +34,7 @@ function update_script() {
setup_mariadb
msg_info "Updating ITSM-NG"
$STD apt update
apt_update_safe
$STD apt -y upgrade
chown -R www-data:www-data /var/lib/itsm-ng
mkdir -p /usr/share/itsm-ng/css/palettes
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating Container OS"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated Container OS"
+1 -1
View File
@@ -34,7 +34,7 @@ function update_script() {
JAVA_VERSION="21" setup_java
msg_info "Updating Jenkins"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Jenkins"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -41,7 +41,7 @@ function update_script() {
fi
msg_info "Updating Jitsi Meet"
$STD apt update
apt_update_safe
$STD apt install -y --only-upgrade \
jitsi-meet \
jicofo \
+11
View File
@@ -45,6 +45,17 @@ function update_script() {
$STD uv sync --locked --no-editable --no-install-project
msg_ok "Updated Python Environment"
NODE_VERSION="24" setup_nodejs
msg_info "Building Frontend"
cd /opt/journiv/frontend
$STD npm ci
$STD npm run build
cd /opt/journiv
msg_ok "Built Frontend"
grep -q '^ALLOW_INSECURE_COOKIE_AUTH_OVER_HTTP=' /opt/journiv.env ||
echo 'ALLOW_INSECURE_COOKIE_AUTH_OVER_HTTP=true' >>/opt/journiv.env
msg_info "Running Database Migrations"
set -a
source /opt/journiv.env
+1 -1
View File
@@ -44,7 +44,7 @@ function update_script() {
msg_ok "Stopped Service"
msg_info "Updating packages"
$STD apt-get update
apt_update_safe
$STD apt-get -y upgrade
msg_ok "Updated packages"
+1 -1
View File
@@ -35,7 +35,7 @@ function update_script() {
CURRENT=$(dpkg-query -W -f='${Version}' kiwix-tools 2>/dev/null)
msg_info "Updating Package Index"
$STD apt update
apt_update_safe
msg_ok "Updated Package Index"
CANDIDATE=$(apt-cache policy kiwix-tools | awk '/Candidate:/{print $2}')
+1 -1
View File
@@ -36,7 +36,7 @@ function update_script() {
msg_warn "⚠️ ${APP} has been migrated to an addon script."
echo ""
msg_info "This is a one-time migration. After this, you can update ${APP} anytime with:"
msg_custom "ℹ️" "${YW}" "This is a one-time migration. After this, you can update ${APP} anytime with:"
echo -e "${TAB}${TAB}${GN}update_komodo${CL} or ${GN}bash <(curl -fsSL ${ADDON_SCRIPT})${CL}"
echo ""
read -r -p "${TAB}Migrate update function now? [y/N]: " CONFIRM
+10
View File
@@ -32,6 +32,16 @@ function update_script() {
exit
fi
if grep -q 'alias /opt/linkding/static/;' /etc/nginx/sites-available/linkding 2>/dev/null; then
msg_info "Serving Favicons and Preview Images"
sed -i \
-e 's|location /static/ {|location ~ ^/static/(.*)$ {|' \
-e 's|alias /opt/linkding/static/;|root /opt/linkding;\n try_files /static/$1 /data/favicons/$1 /data/previews/$1 =404;\n add_header Content-Security-Policy "sandbox";|' \
/etc/nginx/sites-available/linkding
$STD systemctl reload nginx
msg_ok "Serving Favicons and Preview Images"
fi
if check_for_gh_release "linkding" "sissbruecker/linkding"; then
msg_info "Stopping Services"
systemctl stop nginx linkding linkding-tasks
+1 -1
View File
@@ -38,7 +38,7 @@ function update_script() {
msg_info "Stopped Service"
msg_info "Updating Container"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Container"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating lldap"
$STD apt update
apt_update_safe
$STD apt upgrade -y lldap
msg_ok "Updated lldap"
msg_ok "Updated successfully!"
+3
View File
@@ -46,6 +46,9 @@ function update_script() {
msg_info "Building Application"
cd /opt/lobehub
export NODE_OPTIONS="--max-old-space-size=8192"
if grep -qE '"@lobehub/ui": "\^5\.4[0-9]\.' package.json; then
sed -i "/^overrides:/a\ '@lobehub/ui': ~5.49.1" pnpm-workspace.yaml
fi
$STD pnpm install
$STD pnpm run build:docker
unset NODE_OPTIONS
+1 -1
View File
@@ -51,7 +51,7 @@ update_deb_based() {
msg_ok "Stopped Loki"
msg_info "Updating Loki"
$STD apt update
apt_update_safe
$STD apt install -y --only-upgrade loki
msg_ok "Updated Loki"
+1 -1
View File
@@ -40,7 +40,7 @@ update_deb_based() {
fi
setup_mariadb
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
}
+1 -1
View File
@@ -30,7 +30,7 @@ function update_script() {
msg_error "No ${APP} Installation Found!"
exit
fi
$STD apt update
apt_update_safe
$STD apt upgrade -y
NODE_VERSION="24" NODE_MODULE="matterbridge" setup_nodejs
msg_ok "Updated successfully!"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -37,7 +37,7 @@ function update_script() {
msg_ok "Stopped Service"
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated ${APP} LXC"
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
msg_info "Updating MongoDB LXC"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -41,7 +41,7 @@ function update_script() {
fi
msg_info "Updating MQTT"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -40,7 +40,7 @@ function update_script() {
create_backup /etc/mumble/mumble-server.ini /var/lib/mumble-server/mumble-server.sqlite
msg_info "Updating Mumble"
$STD apt update
apt_update_safe
$STD apt install -y mumble-server
cat <<EOF >~/.mumble
$(get_latest_github_release "mumble-voip/mumble")
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
JAVA_VERSION="21" setup_java
msg_info "Updating ${APP}"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -34,7 +34,7 @@ function update_script() {
fi
msg_info "Updating Netbird"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -37,7 +37,7 @@ function update_script() {
msg_ok "Stopped Service"
msg_info "Updating LXC packages"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated LXC packages"
+12
View File
@@ -118,10 +118,18 @@ EOF
$STD "$CERTBOT_PYTHON" -m ensurepip --upgrade
fi
$STD "$CERTBOT_PYTHON" -m pip install --upgrade pip setuptools wheel
find /opt/certbot/lib/python3*/site-packages -maxdepth 1 -name '*.dist-info' -type d ! -exec test -e '{}/RECORD' ';' -exec rm -rf '{}' + 2>/dev/null || true
$STD "$CERTBOT_PYTHON" -m pip install --upgrade certbot certbot-dns-cloudflare
msg_ok "Updated Certbot"
fi
if [[ -f /etc/nginx/conf.d/production.conf.template && ! -f /etc/nginx/conf.d/production.conf ]]; then
msg_info "Restoring Admin Interface"
sed 's/{{NPM_ADMIN_PORT}}/81/g' /etc/nginx/conf.d/production.conf.template >/etc/nginx/conf.d/production.conf
systemctl restart openresty
msg_ok "Restored Admin Interface"
fi
if check_for_gh_release "nginxproxymanager" "NginxProxyManager/nginx-proxy-manager"; then
msg_info "Stopping Services"
systemctl stop openresty
@@ -159,6 +167,10 @@ EOF
cp /opt/nginxproxymanager/docker/rootfs/etc/logrotate.d/nginx-proxy-manager /etc/logrotate.d/nginx-proxy-manager
ln -sf /etc/nginx/nginx.conf /etc/nginx/conf/nginx.conf
rm -f /etc/nginx/conf.d/dev.conf
if [[ -f /etc/nginx/conf.d/production.conf.template ]]; then
ADMIN_PORT=$(grep -oP '^\s*listen\s+\K[0-9]+(?=\s+default)' /etc/nginx/conf.d/production.conf 2>/dev/null | head -n1 || true)
sed "s/{{NPM_ADMIN_PORT}}/${ADMIN_PORT:-81}/g" /etc/nginx/conf.d/production.conf.template >/etc/nginx/conf.d/production.conf
fi
mkdir -p /tmp/nginx/body \
/run/nginx \
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating Notifiarr"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Notifiarr"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -54,7 +54,7 @@ update_deb_based() {
fi
msg_info "Updating ntfy"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated ntfy"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating ntopng"
$STD apt update
apt_update_safe
$STD apt install -y ntopng
msg_ok "Updated ntopng"
+1 -1
View File
@@ -41,7 +41,7 @@ function update_script() {
fi
msg_info "Updating NZBGet"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated NZBGet"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -39,7 +39,7 @@ function update_script() {
create_backup /var/lib/couchdb /opt/couchdb/etc/local.d/obsidian-livesync.ini /opt/obsidian-livesync/.env
msg_info "Updating Container OS"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated Container OS"
+1 -1
View File
@@ -39,7 +39,7 @@ function update_script() {
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating OnlyOffice Document Server"
$STD apt update
apt_update_safe
$STD apt -y --only-upgrade install onlyoffice-documentserver
msg_ok "Updated OnlyOffice Document Server"
+1 -1
View File
@@ -39,7 +39,7 @@ function update_script() {
msg_ok "Stopped services"
msg_info "Updating packages"
$STD apt-get update
apt_update_safe
$STD apt-get dist-upgrade -y
ensure_dependencies "inotify-tools"
msg_ok "Updated packages"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
msg_info "Updating OpenProject"
$STD apt update
apt_update_safe
$STD apt install --only-upgrade -y openproject
msg_ok "Updated OpenProject"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated $APP LXC"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated $APP LXC"
msg_ok "Updated successfully!"
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating Orb"
$STD apt update
apt_update_safe
$STD apt install -y --only-upgrade orb
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -33,7 +33,7 @@ function update_script() {
fi
msg_info "Updating ${APP}"
$STD apt update
apt_update_safe
$STD apt install -y ot-recorder
msg_ok "Updated ${APP}"
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
setup_mariadb
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated $APP LXC"
exit
+1 -1
View File
@@ -32,7 +32,7 @@ function update_script() {
fi
msg_info "Updating PiHole"
set +e
$STD apt update
apt_update_safe
$STD apt upgrade -y
/usr/local/bin/pihole -up
msg_ok "Updated PiHole"
+1 -1
View File
@@ -79,7 +79,7 @@ function update_script() {
fi
msg_info "Updating Plex Media Server"
$STD apt update
apt_update_safe
$STD apt install -y plexmediaserver
msg_ok "Updated Plex Media Server"
+2 -2
View File
@@ -38,7 +38,7 @@ function update_script() {
if [ "$UPD" == "1" ]; then
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated successfully!"
@@ -59,7 +59,7 @@ function update_script() {
fi
if [ "$UPD" == "2" ]; then
msg_info "Installing Home Assistant Community Store (HACS)"
$STD apt update
apt_update_safe
cd /var/lib/containers/storage/volumes/hass_config/_data
$STD bash <(curl -fsSL https://get.hacs.xyz)
msg_ok "Installed Home Assistant Community Store (HACS)"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt upgrade -y
msg_ok "Updated successfully!"
exit
+1 -1
View File
@@ -39,7 +39,7 @@ update_deb_based() {
exit
fi
msg_info "Updating ${APP} LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated successfully!"
}
+1 -1
View File
@@ -46,7 +46,7 @@ function update_script() {
fi
msg_info "Updating PowerDNS"
$STD apt update
apt_update_safe
$STD apt install -y --only-upgrade pdns-server pdns-backend-sqlite3
msg_ok "Updated PowerDNS"
+1 -1
View File
@@ -31,7 +31,7 @@ function update_script() {
exit
fi
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated $APP LXC"
msg_ok "Updated successfully!"
+2 -2
View File
@@ -36,7 +36,7 @@ function update_script() {
echo "deb [signed-by=/usr/share/keyrings/proxmox-archive-keyring.gpg] http://download.proxmox.com/debian/pdm bookworm pdm-test" >/etc/apt/sources.list.d/pdm-test.list
curl -fsSL https://enterprise.proxmox.com/debian/proxmox-archive-keyring-trixie.gpg -o /usr/share/keyrings/proxmox-archive-keyring.gpg
rm -f /etc/apt/keyrings/proxmox-release-bookworm.gpg /etc/apt/sources.list.d/proxmox-release-bookworm.list
$STD apt update
apt_update_safe
msg_ok "Updated old sources"
fi
@@ -55,7 +55,7 @@ function update_script() {
fi
msg_info "Updating $APP LXC"
$STD apt update
apt_update_safe
$STD apt -y upgrade
msg_ok "Updated $APP LXC"
msg_ok "Updated successfully!"

Some files were not shown because too many files have changed in this diff Show More