Update ghcr.io/ancsemi/haven Docker tag in stack haven from 4.12.0 to v4.13.0 #531

Merged
renovate-bot merged 1 commit from renovate/ghcr.io-ancsemi-haven-4.x into main 2026-09-25 08:26:06 -04:00
Collaborator

This PR contains the following updates:

Package Update Change
ghcr.io/ancsemi/haven minor 4.12.0 → 4.13.0

Release Notes

ancsemi/Haven (ghcr.io/ancsemi/haven)

v4.13.0

Compare Source

A second security release, following up the review in 4.12.0. DMs no longer
go out unencrypted without asking, a contact's changed encryption key is
flagged, and the backup of your DM key can be locked with a passphrase the
server never sees (Settings > Encryption). Private channel codes change when
someone is removed, and forged proxy addresses are ignored. If your server
sits behind Cloudflare's proxy (not the tunnel), set TRUST_PROXY=1
or every
visitor looks like the same person to the login limits. Also: a too-long
thread reply is no longer lost. Run npm install (Start Haven.bat and start.sh
do it for you): the Flash games player is a new dependency.

Security
  • DMs ask before anything goes out unencrypted. A DM went out readable
    by the server, without asking, whenever encryption was locked on the
    device or the other person had never set it up, and pictures and files
    went up the same way. Now nothing is sent until you choose: send it
    unencrypted, unlock encryption, or cancel, which puts the message back in
    the box. The lock in a DM's header shows when messages there are not
    encrypted, and a message that fails to encrypt is no longer sent anyway.
  • A contact's changed encryption key is flagged. Haven remembers each
    contact's key on your device. If it changes, because they reset their
    keys or because someone in between swapped it, the DM says so, the lock
    turns into a warning, and nothing is encrypted to the new key until you
    trust it. Show verification code opens the code to compare with them.
  • Encryption passphrase, in Settings > Encryption. The backup of your
    encrypted-DM key is locked with your login password, which the server
    receives every time you sign in. You can lock it with a separate
    passphrase instead, one the server never sees. Sign-in then asks for it
    once on each new device, and changing your password no longer touches the
    backup. Nobody can reset the passphrase for you, including the server
    admin.
  • Forged proxy headers are ignored. TRUST_PROXY now believes a proxy only
    on the same machine or the local network (nginx, Caddy, Docker, the
    built-in tunnel), so a server exposed straight to the internet ignores a
    forged X-Forwarded-For and nobody can pick their own address to get past
    login limits or IP bans. If your proxy runs on another machine, such as
    Cloudflare's proxy, set TRUST_PROXY=1
    , or every visitor will look like
    the proxy.
  • Removing or kicking someone from a private channel changes its join
    code
    , and its private sub-channels' codes, so the code they already know
    no longer lets them back in.
  • Moving a top-level channel under another needs the delete-channel
    permission on it
    , since the move lets that parent's sub-channel managers
    delete it.
  • Flash games load their player from Haven itself. The Ruffle player came
    from unpkg, whichever version was newest that day, fetched from a third
    party by every player, and the games pages allowed scripts from all of
    unpkg. It is a pinned dependency now, and no page allows unpkg.
Fixed
  • A too-long reply in a thread was still lost (#​5691). The 4.12.0 fix
    covered the main message box and DMs. A thread reply comes back into the
    thread box now too, and the thread and pop-out DM boxes stop at the length
    limit like the main box does.
  • start.sh installs new dependencies after an update, not only the first
    time it runs.

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [ghcr.io/ancsemi/haven](https://github.com/ancsemi/Haven) | minor | `4.12.0` → `4.13.0` | --- ### Release Notes <details> <summary>ancsemi/Haven (ghcr.io/ancsemi/haven)</summary> ### [`v4.13.0`](https://github.com/ancsemi/Haven/blob/HEAD/CHANGELOG.md#4130---2026-09-24) [Compare Source](https://github.com/ancsemi/Haven/compare/v4.12.0...v4.13.0) A second security release, following up the review in 4.12.0. DMs no longer go out unencrypted without asking, a contact's changed encryption key is flagged, and the backup of your DM key can be locked with a passphrase the server never sees (Settings > Encryption). Private channel codes change when someone is removed, and forged proxy addresses are ignored. **If your server sits behind Cloudflare's proxy (not the tunnel), set TRUST\_PROXY=1** or every visitor looks like the same person to the login limits. Also: a too-long thread reply is no longer lost. Run npm install (Start Haven.bat and start.sh do it for you): the Flash games player is a new dependency. ##### Security - **DMs ask before anything goes out unencrypted.** A DM went out readable by the server, without asking, whenever encryption was locked on the device or the other person had never set it up, and pictures and files went up the same way. Now nothing is sent until you choose: send it unencrypted, unlock encryption, or cancel, which puts the message back in the box. The lock in a DM's header shows when messages there are not encrypted, and a message that fails to encrypt is no longer sent anyway. - **A contact's changed encryption key is flagged.** Haven remembers each contact's key on your device. If it changes, because they reset their keys or because someone in between swapped it, the DM says so, the lock turns into a warning, and nothing is encrypted to the new key until you trust it. Show verification code opens the code to compare with them. - **Encryption passphrase, in Settings > Encryption.** The backup of your encrypted-DM key is locked with your login password, which the server receives every time you sign in. You can lock it with a separate passphrase instead, one the server never sees. Sign-in then asks for it once on each new device, and changing your password no longer touches the backup. Nobody can reset the passphrase for you, including the server admin. - **Forged proxy headers are ignored.** TRUST\_PROXY now believes a proxy only on the same machine or the local network (nginx, Caddy, Docker, the built-in tunnel), so a server exposed straight to the internet ignores a forged X-Forwarded-For and nobody can pick their own address to get past login limits or IP bans. **If your proxy runs on another machine, such as Cloudflare's proxy, set TRUST\_PROXY=1**, or every visitor will look like the proxy. - **Removing or kicking someone from a private channel changes its join code**, and its private sub-channels' codes, so the code they already know no longer lets them back in. - **Moving a top-level channel under another needs the delete-channel permission on it**, since the move lets that parent's sub-channel managers delete it. - **Flash games load their player from Haven itself.** The Ruffle player came from unpkg, whichever version was newest that day, fetched from a third party by every player, and the games pages allowed scripts from all of unpkg. It is a pinned dependency now, and no page allows unpkg. ##### Fixed - **A too-long reply in a thread was still lost ([#&#8203;5691](https://github.com/ancsemi/Haven/issues/5691)).** The 4.12.0 fix covered the main message box and DMs. A thread reply comes back into the thread box now too, and the thread and pop-out DM boxes stop at the length limit like the main box does. - **start.sh installs new dependencies after an update**, not only the first time it runs. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMjMuMSIsInVwZGF0ZWRJblZlciI6IjQzLjEyMy4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJtaW5vciIsInJlbm92YXRlIl19-->
renovate-bot scheduled this pull request to auto merge when all checks succeed 2026-09-25 01:02:29 -04:00
renovate-bot deleted branch renovate/ghcr.io-ancsemi-haven-4.x 2026-09-25 08:26:07 -04:00
Sign in to join this conversation.
No reviewers
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
Kevin/docker-l2!531
No description provided.