mirror of
https://github.com/alexbelgium/hassio-addons.git
synced 2026-10-11 18:51:35 +02:00
Compare commits
2 Commits
34bc539be3
...
docs/skill
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
833d0d3758 | ||
|
|
138e7d7c33 |
@@ -34,12 +34,6 @@ then generalising it to all hosts.**
|
|||||||
would have deleted a user's hand-written configuration.
|
would have deleted a user's hand-written configuration.
|
||||||
- A GPU probe created a hardware context — but that proved the driver worked, not that Chromium's
|
- A GPU probe created a hardware context — but that proved the driver worked, not that Chromium's
|
||||||
GPU path did.
|
GPU path did.
|
||||||
- SABnzbd's source was grepped to see which proxy headers it reads, and `X-Forwarded-For` was
|
|
||||||
forwarded because it reads that one — but `verify_xff_header` is on by default and makes it
|
|
||||||
*reject* every address in the chain that is not local, so ingress answered 403 for anyone
|
|
||||||
reaching Home Assistant from outside the LAN (#3019, fixed in #3023). Every check ran from
|
|
||||||
inside the container, where no such header exists. **That an app reads a header is not a reason
|
|
||||||
to send it — find out what it does with it, and exercise the path a remote user takes.**
|
|
||||||
|
|
||||||
The pattern is always *inference standing in for detection*. Before changing a default, ask what
|
The pattern is always *inference standing in for detection*. Before changing a default, ask what
|
||||||
this is like on a host unlike yours. Prefer detecting the condition at runtime over asserting it.
|
this is like on a host unlike yours. Prefer detecting the condition at runtime over asserting it.
|
||||||
|
|||||||
@@ -241,15 +241,17 @@ account. Note it and move on rather than guessing.
|
|||||||
**Resolving a review thread requires GraphQL** (`resolveReviewThread`); the REST API cannot do it.
|
**Resolving a review thread requires GraphQL** (`resolveReviewThread`); the REST API cannot do it.
|
||||||
`scripts/pr_review.sh` wraps fetch / reply / resolve.
|
`scripts/pr_review.sh` wraps fetch / reply / resolve.
|
||||||
|
|
||||||
**CHANGELOG heading dates are ISO, whatever the bots' defaults say.** Match the format already in
|
**Most CHANGELOG heading dates are ISO, whatever the bots' defaults say.** Match the format
|
||||||
the add-on's file. Repo-wide that is `## <version> (YYYY-MM-DD)`: 7705 dated headings against 363
|
already in the add-on's file — a `DD-MM-YYYY` file stays `DD-MM-YYYY`. Where you have no
|
||||||
in `DD-MM-YYYY`, and the newest entry is ISO in 125 of 135 add-ons. Copilot flags an ISO file that
|
precedent, ISO is the house style: as of 2026-08-25, `## <version> (YYYY-MM-DD)` accounts for
|
||||||
gets a `DD-MM-YYYY` entry (#3019). `DD-MM-YYYY` is not invented — it is what `onpush_builder.yaml`
|
7705 dated headings against 363 in `DD-MM-YYYY`, and the newest entry is ISO in 125 of 135
|
||||||
writes with `date '+%d-%m-%Y'` when it has to insert a heading you forgot, and what the
|
add-ons. Copilot flags an ISO file that gets a `DD-MM-YYYY` entry (#3019). `DD-MM-YYYY` is not
|
||||||
addons_updater bot writes when its `date_iso8601` option is off (`99-run.sh`; it is on in
|
invented — it is what `onpush_builder.yaml` writes with `date '+%d-%m-%Y'` when it has to insert
|
||||||
production here) — but neither is a reason to write it yourself. The builder's duplicate check is
|
a heading you forgot, and what the addons_updater bot writes when its `date_iso8601` option is
|
||||||
`grep -q "^## ${version} ("`, keyed on the exact `config.yaml` version and blind to the date, so
|
off (`99-run.sh`; it is on in production here) — but neither is a reason to write it yourself.
|
||||||
an ISO heading you wrote yourself still suppresses the bot's insertion.
|
The builder's duplicate check is `grep -q "^## ${version} ("` — an unescaped BRE, so the dots in
|
||||||
|
a version match any character, and it does not look at the date at all. Either way an ISO heading
|
||||||
|
you wrote yourself still suppresses the bot's insertion.
|
||||||
|
|
||||||
**The repo's `.markdownlint.yaml` does not disable MD022/MD032**, so a CHANGELOG will show
|
**The repo's `.markdownlint.yaml` does not disable MD022/MD032**, so a CHANGELOG will show
|
||||||
dozens of pre-existing heading/list findings. They are noise because lint is `continue-on-error`,
|
dozens of pre-existing heading/list findings. They are noise because lint is `continue-on-error`,
|
||||||
|
|||||||
@@ -934,7 +934,6 @@ If you want to do add the repository manually, please follow the procedure highl
|
|||||||

|

|
||||||
![aarch64][aarch64-badge]
|
![aarch64][aarch64-badge]
|
||||||
![amd64][amd64-badge]
|
![amd64][amd64-badge]
|
||||||
![ingress][ingress-badge]
|
|
||||||
![smb][smb-badge]
|
![smb][smb-badge]
|
||||||
![localdisks][localdisks-badge]
|
![localdisks][localdisks-badge]
|
||||||
|
|
||||||
|
|||||||
@@ -1,9 +1,3 @@
|
|||||||
## 20260828 (28-08-2026)
|
|
||||||
- Minor bugs fixed
|
|
||||||
## 20260826.1 (26-08-2026)
|
|
||||||
- Synced with upstream birdnet-go; new/updated PRs pending in fork
|
|
||||||
## 20260826 (26-08-2026)
|
|
||||||
- Minor bugs fixed
|
|
||||||
## 20260729.1 (2026-08-01)
|
## 20260729.1 (2026-08-01)
|
||||||
|
|
||||||
- Version renamed from `source-20260729.1`, which Home Assistant could not order and therefore could not reliably offer as an update: every number of the previous version is kept, as a section of its own. The addon itself and the upstream version it tracks are unchanged
|
- Version renamed from `source-20260729.1`, which Home Assistant could not order and therefore could not reliably offer as an update: every number of the previous version is kept, as a section of its own. The addon itself and the upstream version it tracks are unchanged
|
||||||
|
|||||||
@@ -127,5 +127,5 @@ slug: birdnet-go-dev
|
|||||||
udev: true
|
udev: true
|
||||||
url: https://github.com/alexbelgium/hassio-addons
|
url: https://github.com/alexbelgium/hassio-addons
|
||||||
usb: true
|
usb: true
|
||||||
version: "20260828"
|
version: "20260729.1"
|
||||||
video: true
|
video: true
|
||||||
|
|||||||
@@ -1,11 +1,4 @@
|
|||||||
## 20260826 (26-08-2026)
|
|
||||||
- Minor bugs fixed
|
|
||||||
## 20260716.1 (26-08-2026)
|
|
||||||
- Minor bugs fixed
|
|
||||||
|
|
||||||
## 20260716.1 (2026-08-26)
|
|
||||||
- Rebuild after syncing the alexbelgium/birdnet-go fork with upstream tphakala/birdnet-go and resolving conflicts on all open pull requests
|
|
||||||
|
|
||||||
## 20260716 (2026-07-16)
|
## 20260716 (2026-07-16)
|
||||||
- Update to latest version from tphakala/birdnet-go (changelog : https://github.com/tphakala/birdnet-go/releases)
|
- Update to latest version from tphakala/birdnet-go (changelog : https://github.com/tphakala/birdnet-go/releases)
|
||||||
|
|
||||||
|
|||||||
@@ -128,4 +128,4 @@ slug: birdnet-go
|
|||||||
udev: true
|
udev: true
|
||||||
url: https://github.com/alexbelgium/hassio-addons/tree/master/birdnet-go
|
url: https://github.com/alexbelgium/hassio-addons/tree/master/birdnet-go
|
||||||
usb: true
|
usb: true
|
||||||
version: "20260826"
|
version: "20260716"
|
||||||
|
|||||||
@@ -1,7 +1,4 @@
|
|||||||
|
|
||||||
## 5.1.1.3 (2026-08-25)
|
|
||||||
- Fixed ingress returning `403 External internet access denied` when Home Assistant is reached from outside the local network. SABnzbd's `verify_xff_header` option, which is on by default, refuses any request whose `X-Forwarded-For` chain contains a non-local address, so the proxy no longer forwards that header.
|
|
||||||
|
|
||||||
## 5.1.1.2 (2026-08-25)
|
## 5.1.1.2 (2026-08-25)
|
||||||
- Ingress is now enabled: the WebUI opens directly in the Home Assistant sidebar, and the "Open Web UI" button now goes there. Access by ip:port is unchanged, but has to be typed rather than clicked, as Home Assistant does not allow an add-on to offer both.
|
- Ingress is now enabled: the WebUI opens directly in the Home Assistant sidebar, and the "Open Web UI" button now goes there. Access by ip:port is unchanged, but has to be typed rather than clicked, as Home Assistant does not allow an add-on to offer both.
|
||||||
- Note for users who set a "Host verification" whitelist in SABnzbd: ingress sends `Host: 127.0.0.1:8080` upstream, because SABnzbd rejects any Host that is not an IP literal. That whitelist therefore no longer filters the ingress route, which is gated by Home Assistant authentication instead. Direct ip:port access is unchanged and still filtered.
|
- Note for users who set a "Host verification" whitelist in SABnzbd: ingress sends `Host: 127.0.0.1:8080` upstream, because SABnzbd rejects any Host that is not an IP literal. That whitelist therefore no longer filters the ingress route, which is gated by Home Assistant authentication instead. Direct ip:port access is unchanged and still filtered.
|
||||||
|
|||||||
@@ -106,4 +106,4 @@ schema:
|
|||||||
slug: sabnzbd
|
slug: sabnzbd
|
||||||
udev: true
|
udev: true
|
||||||
url: https://github.com/alexbelgium/hassio-addons
|
url: https://github.com/alexbelgium/hassio-addons
|
||||||
version: "5.1.1.3"
|
version: "5.1.1.2"
|
||||||
|
|||||||
@@ -10,17 +10,10 @@ server {
|
|||||||
|
|
||||||
# SABnzbd refuses any request whose Host is not an IP literal
|
# SABnzbd refuses any request whose Host is not an IP literal
|
||||||
# ("Access denied - Hostname verification failed"), so send the
|
# ("Access denied - Hostname verification failed"), so send the
|
||||||
# upstream socket rather than the browser's host.
|
# upstream socket rather than the browser's host. X-Forwarded-For is
|
||||||
|
# the only other header it reads (for its verify_xff_header option).
|
||||||
proxy_set_header Host $proxy_host;
|
proxy_set_header Host $proxy_host;
|
||||||
|
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||||
# X-Forwarded-For must NOT be forwarded. verify_xff_header defaults to
|
|
||||||
# on, and check_access() then requires every address in the header to
|
|
||||||
# be local, so Supervisor's copy of the browser's public address makes
|
|
||||||
# SABnzbd answer 403 "External internet access denied" for anyone
|
|
||||||
# reaching Home Assistant from outside the LAN. Clearing it leaves
|
|
||||||
# SABnzbd looking at nginx's own loopback address. Access is gated by
|
|
||||||
# Home Assistant authentication before it ever reaches this proxy.
|
|
||||||
proxy_set_header X-Forwarded-For "";
|
|
||||||
|
|
||||||
# The interface itself only emits relative links, so no body
|
# The interface itself only emits relative links, so no body
|
||||||
# rewriting is needed. Redirects are the exception: Raiser() emits
|
# rewriting is needed. Redirects are the exception: Raiser() emits
|
||||||
|
|||||||
Reference in New Issue
Block a user