Skip to main content

Changelog

Follow new updates and improvements to Anaphora.

Anaphora 0.18: safer sign-in and security updates

Anaphora 0.18 is a security update for the sign-in. It locks the settings that come from your environment, limits the first-time setup page to user accounts, and updates components in the image. It carries no database migration, so you can go back to 0.17 the same way. Most installations need no action. If you sign in with single sign-on only, read "Before you upgrade" before you install it.

Locked settings

Settings that come from your environment variables, such as the OIDC client, are now locked. The settings page cannot change them.

Anaphora also does not save the OIDC client secret from your environment in its database any more, and the settings page does not show it. The secret stays in the memory of the running server only.

The first-time setup page

When an installation has no administrator yet, Anaphora shows a setup page to create the first one. This page now creates local user accounts and nothing else. It cannot change any other setting. It also keeps the sign-in methods that are already set. Before, it switched OIDC off.

While the page is open, the start log warns you, and the upgrade script shows it as a problem, with the address of the page. Create the first administrator there before you make the installation reachable.

If OIDC_SYSTEM_GROUPS names your administrators, they sign in with single sign-on from the first start, and the setup page does not open.

Sign-in and security

  • Connections that stay open (WebSockets) get the same sign-in checks as normal page loads, and they close when the user signs out. Anaphora itself does not use them.

  • The image gets security fixes: perl-base 5.36.0-7+deb12u4 (CVE-2026-13221 and six more), handlebars 4.7.10 (CVE-2026-106445, CVE-2026-106446), shell-quote 1.12.0 (CVE-2026-102422), sharp 0.35.5 (GHSA-wq5f-xc86-pv6w) and source-map-js 1.2.2 (CVE-2026-93749).

  • The sign-in service is now Authfish 1.0.190.

Fixes

  • If the first start of a new installation fails, Anaphora keeps no half-saved settings. The next start begins clean.

Before you upgrade

Single sign-on only

  • If your users sign in only with single sign-on and you have no local administrator, create one in Settings before you upgrade. It is your way in when single sign-on is off, for example after a mistake in an OIDC_* variable or a change of licence. Without it, the setup page opens again while single sign-on is off.

Administrator from the environment

  • ADMIN_USERNAME and ADMIN_PASSWORD apply only to the first start of an empty installation. If the start log says that no one can administer Anaphora yet, open the address it shows and create the first administrator there. Setting the variables later does not close the page.

The full list of changes is in the changelog.

Improved

0.8.0

Added

  • Kibana Connector waits for Dashboard to be fully loaded

  • New action: wait an arbitrary amount of time before continue

  • Templates: Logo upload, color theme and default font

Fixed

  • When testing, capture will output the correct error message on wrong credentials

  • Cron job not triggering correctly

ImprovedFixed