Compare commits

..

19 Commits

Author SHA1 Message Date
claude-ai-fix[bot]
16e2c6aac5 ci(triage): catch a malformed credential, not just a revoked one
The token was replaced at 08:25 and the runs at 08:26 still failed — with a
different error, which this gate did not recognise:

  "Invalid auth token · Fix external auth token · Invalid Authorization header
   value from CLAUDE_CODE_OAUTH_TOKEN: it contains a line break at character 62
   (110 characters on 2 lines)."

  "error": "invalid_request", "api_error_status": null

No "authentication_failed", no 401 — so the gate added a few hours earlier
reported this as a generic workflow fault, which is exactly the unhelpful
message it existed to replace. Two shapes of the same problem inside a week:
revoked (401) and malformed (invalid_request, reason only in the message text).

Detection now also matches the text marker, but only on an object the SDK
itself flagged with is_api_error_message — an issue body that merely mentions
the secret's name cannot fake one, and a false positive would change only the
message since this branch exits 1 regardless.

The SDK's own wording is more useful than anything inferred here ("a line break
at character 62" names the exact defect), so it is now quoted verbatim in the
annotation, and the remedy says to re-enter the secret as a SINGLE line.

Verified against both real execution-file shapes captured from production —
today's malformed failure and the 08-30 revoked one — plus regression that
max_turns still escalates, generic failures keep the generic message, and an
issue mentioning CLAUDE_CODE_OAUTH_TOKEN is not misreported as a credential
fault.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-31 10:29:49 +02:00
claude-ai-fix[bot]
3ac46b0cd5 ci(triage): name the real fault when the Claude credential is rejected
The AI pipeline has been down since ~2026-08-25. Every Claude-backed step fails
with:

  "result": "Failed to authenticate. API Error: 401 OAuth access token has been
             revoked."
  "error": "authentication_failed", "api_error_status": 401

The CLAUDE_CODE_OAUTH_TOKEN secret (last updated 2026-07-24) has been revoked.
That is not fixable in code — it needs regenerating — but the six days it went
unnoticed are, because nothing on the way out said so.

What a maintainer actually saw was the action reporting:

  "--json-schema was provided but Claude did not return structured_output.
   Result subtype: success"

which points at the schema, and then Apply verdict's generic "usually a
workflow-level fault ... left untouched for a retry". Neither mentions
credentials, and the failure presents per-issue while the real scope is every
tier at once: tier 1 cannot label, so tier 2's batch is empty and the sweep
reports success daily having done nothing.

GATE 1 now checks the execution file for authentication_failed / HTTP 401
before the max-turns branch and says what is wrong and what to do — regenerate
with `claude setup-token`, update the secret in the CR_PAT environment, and set
AI_DISABLED=true to silence the runs meanwhile. Same array guard and
fail-closed posture as hit_max_turns: an unrecognised shape is simply not an
auth failure and falls through to the generic branch.

Behaviour is otherwise unchanged — this branch already exited 1 without
touching labels, which was correct for a systemic fault.

Verified against the exact execution-file shape captured from the live 08-30
failure (both the issues and catch-up paths report the new error), and
regression-checked that max_turns still escalates on the automated retry, that
generic failures keep the generic message with and without an execution file,
and that the verdict paths are untouched.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-31 10:20:17 +02:00
Alexandre
c8ca11604e fix(calibre-web): document the optional features, drop the dead calibre install (#3032)
* feat(calibre-web): document the optional features and drop the dead calibre install

Issue #1143 asks how to add Calibre-Web's optional extras (metadata, kobo,
...) to the add-on. They are already there: the LinuxServer base image pip
installs optional-requirements.txt alongside requirements.txt into its
/lsiopy virtualenv, so every extra ships enabled. Listing the .dist-info
directories of the published image confirms scholarly, rarfile, py7zr,
mutagen, jsonschema, python-ldap, flask-dance, PyDrive2, comicapi and the
rest are present. Running pip install calibreweb[...] in the container just
fetches an unused second copy from PyPI and is thrown away when the
Supervisor recreates the container.

What actually hides the reporter's cover fields is Calibre-Web's own
gating: book_edit.html only renders 'Fetch Cover from URL' and 'Upload
Cover from Local Disk' when current_user.role_upload() and g.allow_upload
are both true, i.e. Enable Uploads plus the user's Upload permission. The
README now says so.

While checking where the Calibre binaries come from, the Dockerfile step
that claimed to install them turned out to be dead. The image has no wget,
only curl, so 'wget ... | sh /dev/stdin install_dir=/opt/calibre' loses
wget to exit 127, hands sh an empty script, and the pipeline still exits 0.
In the published amd64 image that RUN's layer decompresses to an empty tar
and no layer contains anything under /opt/calibre. Repairing it with curl
would not help: calibre's installer then hard-exits on the missing libEGL,
libOpenGL and libxcb-cursor that the universal-calibre mod apt-installs
itself, so the build would start failing and the image would grow by about
a gigabyte for binaries the mod already provides at start. The step is
removed and a comment records where the binaries really come from.

Refs https://github.com/alexbelgium/hassio-addons/issues/1143

* docs(calibre-web): tighten the optional-features wording after review

Say pip install calibreweb[...] is unsupported and can disturb the pinned
dependencies rather than calling the result unused, scope the extra-package
advice to compatible packages, list the calibre binaries as examples rather
than as a set all three operations need, and mark the docker mod as the
default rather than a certainty since DOCKER_MODS can be overridden.
2026-08-31 07:18:40 +02:00
github-actions
0f5b646078 Github bot : image compressed 2026-08-30 23:12:32 +00:00
Alexandre
408eef8a0f fix(lint): make the Unicode-space regex actually match Unicode spaces (#3027)
The `Lint workflows` autofix job has failed on every scheduled run since at
least 2026-08-16, with `shfmt` reporting parse errors ("LitWord cannot be
followed by a word", "${ stmts;} is a mksh feature", ...) in ~70 shell scripts
that parse cleanly on a pristine checkout.

Root cause is the preceding "Fix non-printable Unicode spaces" step. Its regex
was written as `$'[\\u00A0\\u2002...]'`: the doubled backslash makes bash's
ANSI-C quoting emit the literal text ` `, and Perl has no `\u` codepoint
escape — `\u` is the titlecase-next-character operator, so the character class
degrades to the plain characters `0 2 3 5 7 8 9 A B F`. The step therefore
replaced those digits and letters with spaces in every text file in the repo,
which is what left the shell scripts unparseable. `shfmt` then exited 1 and the
job stopped before opening its autofix PR — the only reason the corruption was
never committed.

Switch to Perl's own `\x{...}` escape in a plain single-quoted string, so the
class holds the ten intended code points and nothing else.

Verified locally against the exact step body extracted from the workflow: on a
sample of the repo it now rewrites only the real U+202F occurrences (e.g.
`postgres_15/.../99-run.sh`, `birdnet-pi/DOCS.md`) and leaves all other text
untouched, and `shfmt v3.12.0 -w -i 4 -ci -bn -sr` over the whole repo exits 0
with no parse errors.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-30 09:50:12 +02:00
Alexandre
0997c302ae fix(filebrowser_quantum): make Download save the file in the iOS companion app (#3030)
* fix(filebrowser_quantum): make Download save the file in the iOS companion app

FileBrowser downloads by clicking an <a> that carries no download attribute
and letting the attachment response do the rest. The Home Assistant iOS
companion app is a WKWebView, where a download only happens when WebKit turns
a navigation action into a WKDownload -- which is what the download attribute
does, and the app hands the result to its own download manager
(WebViewController+WebKitDelegates.swift, navigationAction:didBecome
download:). Its response policy delegate returns .allow for every sub-frame
and never returns .download, so inside the ingress panel a plain attachment
navigation is simply rendered: a text file opens and shows its content with no
way to save it.

The ingress filter now adds the attribute, matched on the two exact download
endpoints so nothing else in the app is touched. Desktop browsers already
downloaded these and are unaffected, and an empty value keeps the filename the
server sends in Content-Disposition.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(filebrowser_quantum): keep Open file a navigation, and narrow the claims

Review of #3030 found that the 'no preview available' fallback renders an
'Open file' link on the same download endpoint with inline=true
(views/files/Preview.vue), so a pathname-only match would have turned opening
a file into downloading it. Exclude inline=true.

Also narrows two overstated claims: the app's download manager is gated on
iOS 17, and the public-share sidebar downloads with window.open() rather than
an anchor, so it is not covered.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-30 09:49:09 +02:00
Alexandre
331af4bcc9 fix(filebrowser_quantum): navigate in place instead of opening a new tab under ingress (#3026)
The tool views (Tools -> File Size Analyzer, Duplicate Finder, the file list
panel) always pass showLimitedOptions to the context menu, and the context
menu's openParentFolder() hands that same flag to goToItem() as its newTab
argument. The parent folder is therefore opened with
window.open(<absolute url>, '_blank'). Behind Home Assistant ingress that
popup lands on the raw /api/hassio_ingress/<token>/ URL with no Home
Assistant frontend around it to keep the ingress session alive, so the new
tab answers 401 instead of showing the folder.

The ingress vhost now injects the same window.open shim the komga add-on
uses, scoped to the two SPA route prefixes goToItem() builds ('files/' and
'public/share/'), so download and preview popups keep their own tab.

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-30 07:59:04 +02:00
github-actions[bot]
141ffe9075 Update stargazer map & cache 2026-08-30 00:53:58 +00:00
github-actions
bb6dee8f91 GitHub bot: changelog [nobuild] 2026-08-29 09:52:23 +00:00
Alexandre
4611326a69 Update config.yaml 2026-08-29 11:46:12 +02:00
github-actions
8dd38fe5cc GitHub bot: changelog [nobuild] 2026-08-29 07:16:33 +00:00
Alexandre
7b3ec3fdbe Update version to 20260829.1 in config.yaml 2026-08-29 09:11:04 +02:00
alexbelgium
0e7a3946d4 Updater bot : zoraxy updated to 3.3.4 (upstream 3.3.4) 2026-08-29 09:06:31 +02:00
alexbelgium
ce29e6be12 Updater bot : prowlarr updated to 2.6.2.5583.12 (upstream nightly-2.6.2.5583-ls12) 2026-08-29 09:04:14 +02:00
alexbelgium
a0499ace1a Updater bot : flexget updated to 3.20.8 (upstream 3.20.8) 2026-08-29 09:02:03 +02:00
alexbelgium
a1d2de14c0 Updater bot : epicgamesfree updated to 2026.08.29 (upstream debian-2026-08-29) 2026-08-29 09:01:41 +02:00
alexbelgium
23cb9d9fed Updater bot : emby_beta updated to 4.10.0.29 (upstream 4.10.0.29) 2026-08-29 09:01:28 +02:00
github-actions
cebd18627e GitHub bot: changelog [nobuild] 2026-08-29 06:22:10 +00:00
Alexandre
b68d5335b2 Update config.yaml 2026-08-29 08:15:52 +02:00
159 changed files with 206 additions and 25 deletions

View File

@@ -273,6 +273,7 @@ Gajalshankar,India,
Gangol,,2026-08-10
Garak1980,,2026-08-10
GaryOG,,2026-08-10
GentryChe,,2026-08-30
Germaenace,,2026-08-10
Getrio,Italy,
Ghost-Sam1222,,2026-08-10
@@ -385,6 +386,7 @@ JosephBlock,United States,
Julian1701,,2026-08-10
JulienFloris,Netherlands,
JuraLadanov,,2026-08-10
Jutsch,,2026-08-30
K0stIa,,2026-08-10
KRC604,,2026-08-10
KairuByte,,2026-08-10
@@ -441,6 +443,7 @@ Lizzardis,,2026-08-10
LoginByCall,,2026-08-10
Lolekpolek,,2026-08-10
LonelySoul7X,,2026-08-10
Loong-He,China,2026-08-30
Lorsel,Italy,
Luca2165801154,,2026-08-10
Lucius-Waverly,,2026-08-16
@@ -990,6 +993,7 @@ berkovich98,,2026-08-10
bertrand-f,,2026-08-10
bes-r,Netherlands,
bestnub,Germany,
betechyou,,2026-08-30
beyercenter,,2026-08-10
bezigebever,,2026-08-10
bggsolar,Germany,
@@ -1225,6 +1229,7 @@ denisgolius,Ukraine,
dennisjonda,Germany,
dennisvandalen,Netherlands,
denvernbd,Russian Federation,2026-08-10
der-berni,Germany,2026-08-30
derailius,,2026-08-10
dethpickle,United States,
dev4jam,Australia,
@@ -1522,6 +1527,7 @@ hreikin,United Kingdom,
hsiguy,,2026-08-10
huangyixinv,,2026-08-10
hubikj,,2026-08-10
hufforguk,,2026-08-30
hugobloem,United Kingdom,
hujiayi0126,,2026-08-10
hunterlong,United States,
@@ -1661,6 +1667,7 @@ joshcliffejones,United Kingdom,
joshmeads,Canada,
josiah-eichelman,,2026-08-10
jpaulomt,,
jpeisach,United States,2026-08-30
jpmaldonado,,2026-08-10
jpoll962,,2026-08-10
jpombas,Portugal,
@@ -1831,6 +1838,7 @@ mProwler,United States,
mStrangers,,2026-08-10
mabt,,2026-08-10
macedobernardo,,2026-08-10
machineGnu,,2026-08-30
madjetey,,2026-08-10
maggle-swim,,2026-08-10
malachitgruen,Germany,
@@ -1840,6 +1848,7 @@ manu7691,United States,
manugratx,,2026-08-10
mapeje,Sweden,
maphouse,Canada,
marat-365,,2026-08-30
maratbakirov,,2026-08-10
marcetad,,2026-08-10
marcjay,United Kingdom,
@@ -1849,6 +1858,7 @@ marcschraepler,Austria,
marcusrbrown,,2026-08-10
mareklab,,2026-08-10
marevers,Germany,
marialaranjo,,2026-08-30
marian-paun,Romania,
mariusvslprts,Germany,
mark-219,United States,2026-08-16
@@ -2173,6 +2183,7 @@ pwitte,,2026-08-10
pxshh,,2026-08-10
pynbbz,,2026-08-10
pyrech,France,
pysj,,2026-08-30
pziezio,Poland,
pzkpfw6,,2026-08-10
qadk,,2026-08-10
@@ -2196,6 +2207,7 @@ rascasseuk,,2026-08-10
raul811,,2026-08-10
raulpetruta,Romania,
rawpie2,,2026-08-10
raymand211092,Cuba,2026-08-30
raytedjaja,,2026-08-10
rbalaev,,2026-08-10
rbaron,,2026-08-10
@@ -2211,6 +2223,7 @@ reggiano,,2026-08-10
reid,United States,
reinvanhaaren,Netherlands,
remb0,Netherlands,
renatoptr,,2026-08-30
renejr63,,2026-08-10
resomi,,2026-08-10
retpolanne,Brazil,
1 username country last_checked
273 Gangol 2026-08-10
274 Garak1980 2026-08-10
275 GaryOG 2026-08-10
276 GentryChe 2026-08-30
277 Germaenace 2026-08-10
278 Getrio Italy
279 Ghost-Sam1222 2026-08-10
386 Julian1701 2026-08-10
387 JulienFloris Netherlands
388 JuraLadanov 2026-08-10
389 Jutsch 2026-08-30
390 K0stIa 2026-08-10
391 KRC604 2026-08-10
392 KairuByte 2026-08-10
443 LoginByCall 2026-08-10
444 Lolekpolek 2026-08-10
445 LonelySoul7X 2026-08-10
446 Loong-He China 2026-08-30
447 Lorsel Italy
448 Luca2165801154 2026-08-10
449 Lucius-Waverly 2026-08-16
993 bertrand-f 2026-08-10
994 bes-r Netherlands
995 bestnub Germany
996 betechyou 2026-08-30
997 beyercenter 2026-08-10
998 bezigebever 2026-08-10
999 bggsolar Germany
1229 dennisjonda Germany
1230 dennisvandalen Netherlands
1231 denvernbd Russian Federation 2026-08-10
1232 der-berni Germany 2026-08-30
1233 derailius 2026-08-10
1234 dethpickle United States
1235 dev4jam Australia
1527 hsiguy 2026-08-10
1528 huangyixinv 2026-08-10
1529 hubikj 2026-08-10
1530 hufforguk 2026-08-30
1531 hugobloem United Kingdom
1532 hujiayi0126 2026-08-10
1533 hunterlong United States
1667 joshmeads Canada
1668 josiah-eichelman 2026-08-10
1669 jpaulomt
1670 jpeisach United States 2026-08-30
1671 jpmaldonado 2026-08-10
1672 jpoll962 2026-08-10
1673 jpombas Portugal
1838 mStrangers 2026-08-10
1839 mabt 2026-08-10
1840 macedobernardo 2026-08-10
1841 machineGnu 2026-08-30
1842 madjetey 2026-08-10
1843 maggle-swim 2026-08-10
1844 malachitgruen Germany
1848 manugratx 2026-08-10
1849 mapeje Sweden
1850 maphouse Canada
1851 marat-365 2026-08-30
1852 maratbakirov 2026-08-10
1853 marcetad 2026-08-10
1854 marcjay United Kingdom
1858 marcusrbrown 2026-08-10
1859 mareklab 2026-08-10
1860 marevers Germany
1861 marialaranjo 2026-08-30
1862 marian-paun Romania
1863 mariusvslprts Germany
1864 mark-219 United States 2026-08-16
2183 pxshh 2026-08-10
2184 pynbbz 2026-08-10
2185 pyrech France
2186 pysj 2026-08-30
2187 pziezio Poland
2188 pzkpfw6 2026-08-10
2189 qadk 2026-08-10
2207 raul811 2026-08-10
2208 raulpetruta Romania
2209 rawpie2 2026-08-10
2210 raymand211092 Cuba 2026-08-30
2211 raytedjaja 2026-08-10
2212 rbalaev 2026-08-10
2213 rbaron 2026-08-10
2223 reid United States
2224 reinvanhaaren Netherlands
2225 remb0 Netherlands
2226 renatoptr 2026-08-30
2227 renejr63 2026-08-10
2228 resomi 2026-08-10
2229 retpolanne Brazil

Binary file not shown.

Before

Width:  |  Height:  |  Size: 68 KiB

After

Width:  |  Height:  |  Size: 64 KiB

BIN
.github/stats.png vendored

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.9 KiB

After

Width:  |  Height:  |  Size: 1.9 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 9.9 KiB

After

Width:  |  Height:  |  Size: 4.5 KiB

View File

@@ -38,7 +38,7 @@ jobs:
run: |
set -euo pipefail
CHANGED_FILES=$(git diff --name-only "$DIFF_RANGE")
UNICODE_SPACES_REGEX=$'[\\u00A0\\u2002\\u2003\\u2007\\u2008\\u2009\\u202F\\u205F\\u3000\\u200B]'
UNICODE_SPACES_REGEX='[\x{00A0}\x{2002}\x{2003}\x{2007}\x{2008}\x{2009}\x{202F}\x{205F}\x{3000}\x{200B}]'
for file in $CHANGED_FILES; do
if [ -f "$file" ]; then
MIME_TYPE=$(file --mime-type -b "$file")
@@ -89,7 +89,7 @@ jobs:
- name: Fix non-printable Unicode spaces in all text files
run: |
set -euo pipefail
UNICODE_SPACES_REGEX=$'[\\u00A0\\u2002\\u2003\\u2007\\u2008\\u2009\\u202F\\u205F\\u3000\\u200B]'
UNICODE_SPACES_REGEX='[\x{00A0}\x{2002}\x{2003}\x{2007}\x{2008}\x{2009}\x{202F}\x{205F}\x{3000}\x{200B}]'
find . -type f ! -path "./.git/*" | while read -r file; do
MIME_TYPE=$(file --mime-type -b "$file")
if [[ "$MIME_TYPE" == text/* ]]; then

View File

@@ -362,6 +362,50 @@ jobs:
"$EXECUTION_FILE" >/dev/null 2>&1
}
# Did the run die because the Claude credential is bad? The action
# reports this uselessly — the failure surfaces as "--json-schema was
# provided but Claude did not return structured_output", which points
# at the schema and not at auth. The execution file carries the truth.
#
# A bad credential shows up in more than one shape, and both have been
# seen in production within a week:
# * revoked token -> error "authentication_failed", HTTP 401
# * malformed token -> error "invalid_request", api_error_status
# null, and the reason only in the SDK's message text ("Invalid
# Authorization header value from CLAUDE_CODE_OAUTH_TOKEN: it
# contains a line break at character 62").
# Matching only the first shape reported the second as a generic
# workflow fault, so the text marker is checked too — but only on an
# object the SDK itself flagged as an API error, so an issue body that
# merely mentions the secret's name cannot fake one. A false positive
# would change only the message: this branch exits 1 either way.
hit_auth_failure() {
[ -n "${EXECUTION_FILE:-}" ] && [ -s "${EXECUTION_FILE:-}" ] || return 1
jq -e '(type == "array") and
any(.[]?;
(type == "object") and
(((.error? // "") == "authentication_failed") or
((.error_status? // 0) == 401) or
((.api_error_status? // 0) == 401) or
(((.is_api_error_message? // false) == true) and
(tostring | test("CLAUDE_CODE_OAUTH_TOKEN|Invalid auth token")))))' \
"$EXECUTION_FILE" >/dev/null 2>&1
}
# The SDK's own words are far more useful than anything this script
# can infer — "it contains a line break at character 62" names the
# exact defect. Surface it verbatim when present.
auth_failure_detail() {
[ -n "${EXECUTION_FILE:-}" ] && [ -s "${EXECUTION_FILE:-}" ] || return 0
jq -r 'if type == "array" then
[ .[]? | select(type == "object")
| select((.is_api_error_message? // false) == true)
| tostring
| capture("(?<m>Invalid Authorization header value[^\"]*|Invalid auth token[^\"]*)")
| .m ] | first // ""
else "" end' "$EXECUTION_FILE" 2> /dev/null || true
}
# GATE 1 — did the action itself run? This is checked BEFORE looking
# at the payload, because the action can fail *after* having written
# a valid structured output: the object would sail through the shape
@@ -380,6 +424,17 @@ jobs:
if [ "${CLASSIFY_OUTCOME:-}" = "failure" ]; then
restore_needs_info
# Checked before anything else, because it is the one failure with
# a specific remedy and it takes down every tier at once — tier 1
# cannot label, so tier 2's batch is empty and the whole pipeline
# goes quiet while each run still fails in a way that reads like a
# per-issue problem. Say plainly what is wrong and what to do.
if hit_auth_failure; then
DETAIL=$(auth_failure_detail)
echo "::error::CLAUDE_CODE_OAUTH_TOKEN is being rejected${DETAIL:+ — $DETAIL}. This is NOT a problem with issue #$ISSUE: every AI workflow is down until the credential is fixed. Regenerate with 'claude setup-token' and re-enter the secret in the CR_PAT environment as a SINGLE line with no line break or trailing newline. Set the AI_DISABLED repo variable to 'true' to silence these runs meanwhile."
exit 1
fi
# ...with one exception. Exhausting the turn budget is NOT a
# workflow fault: the action ran fine and this particular issue was
# just too tangled to finish inside the turn budget. Treating it as systemic

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.7 KiB

After

Width:  |  Height:  |  Size: 1.7 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.7 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.1 KiB

After

Width:  |  Height:  |  Size: 1.8 KiB

View File

@@ -1,3 +1,9 @@
## 20260829.2 (29-08-2026)
- Minor bugs fixed
## 20260829.1 (29-08-2026)
- Minor bugs fixed
## 20260829 (29-08-2026)
- Minor bugs fixed
## 20260828.2 (28-08-2026)
- Synced with upstream birdnet-go; fork PR #57 updated
## 20260828.1 (28-08-2026)

View File

@@ -127,5 +127,5 @@ slug: birdnet-go-dev
udev: true
url: https://github.com/alexbelgium/hassio-addons
usb: true
version: "20260828.2"
version: "20260829.2"
video: true

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.6 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.5 KiB

After

Width:  |  Height:  |  Size: 1.8 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.7 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

View File

@@ -1,4 +1,8 @@
## 0.6.27.3 (2026-08-30)
- Doc: explain in the README that Calibre-Web's optional extras (metadata, kobo, gdrive, gmail, goodreads, ldap, oauth, comics) are already installed by the LinuxServer base image, that `pip install calibreweb[...]` inside the container is useless and not persistent, and that the cover fields on the Edit Metadata page are gated on `Enable Uploads` plus the user's `Upload` permission (https://github.com/alexbelgium/hassio-addons/issues/1143)
- Fix: remove the Dockerfile step that claimed to install the Calibre binaries into `/opt/calibre`. There is no `wget` in the image, so the command failed silently and left the layer empty; the binaries are and were provided at start by the default `linuxserver/mods:universal-calibre` docker mod
## 0.6.27.2 (2026-08-23)
- Fix: trust the whole supervisor network range for the ingress auth header instead of the addon's own address, which changes across restarts. The list is only written when that range is missing, so an entry added in the calibre-web admin page is no longer erased on every start (https://github.com/alexbelgium/hassio-addons/pull/3010)

View File

@@ -35,11 +35,9 @@ RUN \
&& echo '#!/bin/sh' > /usr/bin/xdg-desktop-menu && chmod +x /usr/bin/xdg-desktop-menu \
&& echo '#!/bin/sh' > /usr/bin/xdg-mime && chmod +x /usr/bin/xdg-mime
# Install calibre binaries (provides calibredb required for book downloads)
# hadolint ignore=DL4006
RUN \
wget -nv -O- https://download.calibre-ebook.com/linux-installer.sh | sh /dev/stdin install_dir=/opt/calibre
ENV PATH="/opt/calibre:${PATH}"
# By default the calibre binaries (calibredb, ebook-convert, ebook-meta) are installed at start by
# the linuxserver/mods:universal-calibre docker mod, set as the default DOCKER_MODS in config.yaml.
# The xdg-* stubs above keep its calibre_postinstall step quiet.
# Global LSIO modifications
COPY ha_lsio.sh /ha_lsio.sh

View File

@@ -97,6 +97,18 @@ This addon supports mounting both local drives and remote SMB shares:
- **Local drives**: See [Mounting Local Drives in Addons](https://github.com/alexbelgium/hassio-addons/wiki/Mounting-Local-Drives-in-Addons)
- **Remote shares**: See [Mounting Remote Shares in Addons](https://github.com/alexbelgium/hassio-addons/wiki/Mounting-remote-shares-in-Addons)
### Optional Calibre-Web features
Calibre-Web documents optional extras that a manual installation adds with `pip install calibreweb[metadata]` and similar. **You do not need to install anything here**: the LinuxServer base image this add-on builds on installs Calibre-Web's `requirements.txt` *and* its full `optional-requirements.txt` into the application's virtualenv, so the gdrive, gmail, goodreads, ldap, oauth, metadata, comics and kobo dependencies are all present already. Running `pip install calibreweb[...]` inside the container is not a supported way to enable them: it installs the PyPI distribution of Calibre-Web over an installation that already has those dependencies, and it can disturb the versions the base image pinned. It is also thrown away, because the Supervisor recreates the add-on container on restart.
Optional features are switched on in the Calibre-Web web interface, not in the add-on options, under `Admin` -> `Basic Configuration` -> `Feature Configuration` (for example `Enable Uploads`, `Enable Kobo sync`, `Use Goodreads`).
**Book covers.** The `Fetch Cover from URL` and `Upload Cover from Local Disk` fields only appear on a book's `Edit Metadata` page when `Enable Uploads` is ticked in `Feature Configuration` **and** the logged-in user has the `Upload` permission (`Admin` -> the user -> `Upload`). A missing Python package is not what hides them.
**Conversion, metadata embedding and the other Calibre integrations** use command-line binaries such as `ebook-convert`, `ebook-meta` and `calibredb`. Those are installed at start by the `linuxserver/mods:universal-calibre` docker mod, which is the shipped default of the `DOCKER_MODS` option. If you set `DOCKER_MODS` yourself, keep `linuxserver/mods:universal-calibre` in the list (mods are separated by `|`) or those binaries disappear.
**Other compatible Python packages** can be installed from the add-on's custom script (see the section below); `pip` there points at Calibre-Web's own virtualenv. Such a script runs on every start, and it has to, since the container's writable layer does not persist.
### Custom Scripts and Environment Variables
This addon supports custom scripts and environment variables:

View File

@@ -116,5 +116,5 @@ schema:
slug: calibre-web
udev: true
url: https://github.com/alexbelgium/hassio-addons/tree/master/calibre_web
version: "0.6.27.2"
version: "0.6.27.3"
video: true

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.6 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.7 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.7 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

View File

@@ -1,4 +1,7 @@
## 4.10.0.29 (2026-08-29)
- Update to latest version from linuxserver/docker-emby (changelog : https://github.com/linuxserver/docker-emby/releases)
## 4.10.0.28 (2026-08-29)
- Update to latest version from linuxserver/docker-emby (changelog : https://github.com/linuxserver/docker-emby/releases)

View File

@@ -16,7 +16,7 @@
ARG BUILD_FROM
ARG BUILD_VERSION
ARG BUILD_UPSTREAM="4.10.0.28"
ARG BUILD_UPSTREAM="4.10.0.29"
FROM ${BUILD_FROM}
##################

View File

@@ -122,5 +122,5 @@ schema:
slug: emby_nas
udev: true
url: https://github.com/alexbelgium/hassio-addons/tree/master/emby
version: "4.10.0.28"
version: "4.10.0.29"
video: true

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

View File

@@ -5,5 +5,5 @@
"slug": "emby",
"source": "github",
"upstream_repo": "linuxserver/docker-emby",
"upstream_version": "4.10.0.28"
"upstream_version": "4.10.0.29"
}

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.7 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

View File

@@ -1,4 +1,8 @@
## 2026.08.29 (2026-08-29)
- Update to latest version from charlocharlie/epicgames-freegames
- Upstream tag : debian-2026-08-29
## 2026.08.13 (2026-08-13)
- Update to latest version from charlocharlie/epicgames-freegames
- Upstream tag : debian-2026-08-13

View File

@@ -88,5 +88,5 @@ schema:
slug: epicgamesfree
udev: true
url: https://github.com/alexbelgium/hassio-addons
version: "2026.08.13"
version: "2026.08.29"
webui: "[PROTO:ssl]://[HOST]:[PORT:3000]"

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

View File

@@ -2,10 +2,10 @@
"dockerhub_by_date": true,
"dockerhub_list_size": 2,
"github_exclude": "-",
"last_update": "2026-08-13",
"last_update": "2026-08-29",
"repository": "alexbelgium/hassio-addons",
"slug": "epicgamesfree",
"source": "dockerhub",
"upstream_repo": "charlocharlie/epicgames-freegames",
"upstream_version": "debian-2026-08-13"
"upstream_version": "debian-2026-08-29"
}

View File

@@ -1,4 +1,26 @@
## 1.5.3.2 (2026-08-30)
- Fix Download in the Home Assistant iOS companion app (iOS 17 and later),
where a file opened and showed its content with no way to save it.
FileBrowser downloads by clicking a link that carries no `download`
attribute, and the app's WKWebView only turns a click into a real download
when that attribute is present, so inside the ingress panel the file was
simply rendered. The ingress filter now adds the attribute to FileBrowser's
own download link. "Open file" still opens, and the public-share sidebar's
own download button is not covered. Desktop browsers already downloaded
these and are unchanged, as is direct access on port 8071.
## 1.5.3.1 (2026-08-29)
- Fix "open parent directory" in Tools -> File Size Analyzer under Home
Assistant ingress. FileBrowser opened the parent folder in a new tab, which
lands on the raw ingress URL with no Home Assistant frontend around it to
keep the ingress session alive, so the new tab answered 401 instead of
showing the folder. The ingress vhost now turns that popup into a navigation
of the panel itself. The same fix covers the other tool views and the "go to
item" action on search results, which open a new tab the same way. Download
and preview popups, links pointing out of the add-on, and direct access on
port 8071 are unchanged.
## 1.5.3 (2026-08-29)
- Update to latest version from gtsteffaniak/filebrowser (changelog : https://github.com/gtsteffaniak/filebrowser/releases)

View File

@@ -118,4 +118,4 @@ schema:
slug: filebrowser_quantum
udev: true
url: https://github.com/alexbelgium/hassio-addons
version: "1.5.3"
version: "1.5.3.2"

View File

@@ -3,7 +3,7 @@ server {
include /etc/nginx/includes/server_params.conf;
include /etc/nginx/includes/proxy_params.conf;
client_max_body_size 0;
location / {
@@ -12,6 +12,60 @@ server {
proxy_send_timeout 30m;
proxy_read_timeout 30m;
proxy_pass %%protocol%%://backend%%subpath%%;
# Two things the ingress panel needs that a plain browser tab does not.
# Both are injected into the page's existing nonce-carrying inline script
# rather than next to <div id="app">: FileBrowser sends
# script-src 'self' 'nonce-<random>', so a standalone inline <script>
# would be blocked. If upstream ever drops that
# window.__pwaDeferredPrompt line the filter stops matching and both
# behaviours revert, which is the state before either fix.
#
# 1. Opening a folder. The tool views (Tools -> File Size Analyzer and
# the others) always set the context menu's showLimitedOptions flag, and
# openParentFolder() hands that same flag to goToItem() as its newTab
# argument, so the folder is opened with window.open(<url>, '_blank').
# Behind ingress that popup lands on the raw /api/hassio_ingress/<token>/
# url with no Home Assistant frontend around it to keep the ingress
# session alive, so the new tab answers 401 instead of showing the
# folder. Turn it into a navigation of the panel itself. The context
# menu's "go to item" action, offered by search results and the tool
# views, hardcodes the same new tab and is fixed with it.
#
# Scoped to the two prefixes goToItem() builds, "files/" and
# "public/share/", so the window.open calls that download or preview a
# file (they go to api/resources/download) keep their own tab: sending
# an inline raw file to location.assign would replace the whole app. A
# link out of the add-on keeps its own tab as well, unless a user points
# a sidebar link -- or a link inside a file open in the editor -- at this
# same instance's files/ or public/share/ route. Same shape as the komga
# add-on's ingress filter.
#
# 2. Download. FileBrowser downloads a file by building an <a> with no
# download attribute, clicking it, and letting the attachment response do
# the rest. The Home Assistant iOS companion app is a WKWebView, and a
# download happens there only when WebKit turns a navigation *action*
# into a WKDownload, which is what the download attribute does -- the app
# hands that to its own download manager
# (WebViewController+WebKitDelegates.swift, navigationAction:didBecome
# download:). Its response policy delegate returns .allow for every
# sub-frame and never returns .download, so a plain attachment navigation
# inside the ingress panel is just rendered: a text file opens and shows
# its content with no way to save it. Adding the attribute makes the same
# click a real download. Desktop browsers already downloaded these and
# are unaffected, and an empty value keeps the filename the server sends
# in Content-Disposition. Matched on the two exact download endpoints,
# minus inline=true: the "no preview available" fallback renders an
# "Open file" link on the same endpoint with that parameter
# (views/files/Preview.vue), and it is meant to open, not save. Only
# programmatic clicks pass through here -- a person clicking a link never
# calls HTMLAnchorElement.prototype.click -- so this reaches
# FileBrowser's own hidden download anchor and nothing a user clicks.
#
# Not covered: the public-share sidebar downloads with window.open()
# rather than an anchor, and the app's download manager is gated on
# iOS 17 (WebViewController+WebKitDelegates.swift).
sub_filter "window.__pwaDeferredPrompt = null;" "window.__pwaDeferredPrompt = null;(function(){var o=window.open;window.open=function(u,n,f){try{var b=(window.globalVars||{}).baseURL;if(u&&n==='_blank'&&!f&&b){if(b.slice(-1)!=='/')b+='/';var t=new URL(u,location.href);if((t.protocol==='http:'||t.protocol==='https:')&&t.origin===location.origin&&(t.pathname.indexOf(b+'files/')===0||t.pathname.indexOf(b+'public/share/')===0)){location.assign(t.href);return window}}}catch(e){}return o.apply(window,arguments)};var c=HTMLAnchorElement.prototype.click;HTMLAnchorElement.prototype.click=function(){try{var b=(window.globalVars||{}).baseURL;if(b&&this.href&&!this.hasAttribute('download')){if(b.slice(-1)!=='/')b+='/';var t=new URL(this.href,location.href);if(t.origin===location.origin&&t.searchParams.get('inline')!=='true'&&(t.pathname===b+'api/resources/download'||t.pathname===b+'public/api/resources/download')){this.download=''}}}catch(e){}return c.apply(this,arguments)}})();";
}
}

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.7 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.1 KiB

After

Width:  |  Height:  |  Size: 1.8 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.6 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

View File

@@ -1,4 +1,7 @@
## 3.20.8 (2026-08-29)
- Update to latest version from wiserain/flexget
## 3.20.6 (2026-08-22)
- Update to latest version from wiserain/flexget

View File

@@ -95,5 +95,5 @@ schema:
slug: flexget
udev: true
url: https://github.com/alexbelgium/hassio-addons
version: "3.20.6"
version: "3.20.8"
webui: "[PROTO:ssl]://[HOST]:[PORT:5050]"

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

View File

@@ -1,9 +1,9 @@
{
"dockerhub_list_size": "10",
"last_update": "2026-08-22",
"last_update": "2026-08-29",
"repository": "alexbelgium/hassio-addons",
"slug": "flexget",
"source": "dockerhub",
"upstream_repo": "wiserain/flexget",
"upstream_version": "3.20.6"
"upstream_version": "3.20.8"
}

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.2 KiB

After

Width:  |  Height:  |  Size: 1.8 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.7 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.2 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.6 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.7 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.4 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Some files were not shown because too many files have changed in this diff Show More