Commit Graph

53 Commits

Author SHA1 Message Date
TrueCharts-Bot e0feb4afdb Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-04-20 00:25:55 +00:00
TrueCharts Bot ffc13416f5 feat(helm-deps): update chart common 29.0.15 → 29.1.0 (#47224)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://truecharts.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | minor | `29.0.15` →
`29.1.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-04-19 11:20:31 +02:00
TrueCharts-Bot 371d1817b4 Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-04-19 00:25:45 +00:00
TrueCharts Bot 4b163d1dc9 feat(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.22.1 → 0.23.0 (#47157)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/dispatcharr/dispatcharr](https://redirect.github.com/Dispatcharr/Dispatcharr)
| minor | `ccdfa7e` → `b731cda` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Dispatcharr/Dispatcharr
(docker.io/dispatcharr/dispatcharr)</summary>

###
[`v0.23.0`](https://redirect.github.com/Dispatcharr/Dispatcharr/blob/HEAD/CHANGELOG.md#0230---2026-04-17)

[Compare
Source](https://redirect.github.com/Dispatcharr/Dispatcharr/compare/v0.22.1...v0.23.0)

##### Security

- Set `DEFAULT_PERMISSION_CLASSES` to `IsAdmin` in the DRF
configuration. All viewsets and function-based views that require
non-admin or unauthenticated access were explicitly annotated: proxy
streaming endpoints (`stream_ts`, `stream_xc`, `stream_vod`, `head_vod`,
`stream_xc_movie`, `stream_xc_episode`) use
`@permission_classes([AllowAny])` (access is controlled by the
per-stream-type network allow-list inside the view body); the
`UserAgentViewSet`, `StreamProfileViewSet`, `CoreSettingsViewSet`, and
`ProxySettingsViewSet` gained `get_permissions()` methods mapping read
actions to `IsStandardUser` and write actions to `IsAdmin`; and
`AuthViewSet.logout` was updated to return `[Authenticated()]`.
- Fixed missing `network_access_allowed` checks in the VOD proxy.
`stream_vod`, `head_vod`, `stream_xc_movie`, and `stream_xc_episode`
were not checking the `STREAMS` network policy, unlike the equivalent TS
proxy endpoints.
- Explicitly marked the HDHomeRun discovery endpoints
(`DiscoverAPIView`, `LineupAPIView`, `LineupStatusAPIView`,
`HDHRDeviceXMLAPIView`) and the version endpoint with
`permission_classes = [AllowAny]` to document their intentionally public
access now that the global default is `IsAdmin`.
- Fixed path traversal vulnerability in file uploads. The M3U account
upload (`apps/m3u/api_views.py`), logo upload
(`apps/channels/api_views.py`), and backup upload
(`apps/backups/api_views.py`) all used the uploaded filename directly
without sanitization. `os.path.join()` discards all preceding components
when it encounters an absolute path segment, and `pathlib`'s `/`
operator behaves identically; a relative `../` sequence also escapes via
OS path resolution at `open()` time. All three upload paths now strip
directory components via `Path(name).name` and validate the resolved
path remains within the intended upload directory. Exploiting any of
these required admin credentials.
- Prevented users from setting `xc_password` (and other admin-managed
keys) on their own account via the `PATCH /api/accounts/users/me/`
endpoint.
- Hardened the HLS proxy `change_stream` endpoint by converting it from
a plain Django view to a DRF `@api_view` with
`@permission_classes([IsAdmin])`, ensuring the endpoint actually
enforces admin-only access. The previous decorator arrangement
(`@csrf_exempt` + `@permission_classes`) had no effect on a plain Django
view.
- Added rate limiting to the login endpoint (`POST
/api/accounts/token/`) using DRF's built-in throttling. A
`LoginRateThrottle` (3 requests/minute per IP, sliding window) is
applied to the `TokenObtainPairView`. Repeated failed attempts from the
same IP receive `429 Too Many Requests`.
- Extended rate limiting to the session-auth login alias (`POST
/api/accounts/auth/login/`). It now delegates entirely to
`TokenObtainPairView`, inheriting its throttle, network access check,
and audit logging, and returns JWT tokens instead of a session cookie
(the session-based response was unusable since `SessionAuthentication`
is not in `DEFAULT_AUTHENTICATION_CLASSES`). Both endpoints share the
same `"login"` throttle scope, so attempts across either path count
against the same per-IP limit.
- Removed `CORS_ALLOW_CREDENTIALS = True` from CORS configuration.
Dispatcharr authenticates via JWT `Authorization` headers and API keys —
not cookies — so credentials are never sent cross-origin by browsers.
The setting was also redundant: browsers reject
`Access-Control-Allow-Credentials: true` when
`Access-Control-Allow-Origin` is a wildcard (`*`), so it had no effect
in practice.
- Updated frontend npm dependencies to resolve 6 audit vulnerabilities
(6 high):
- Updated `@xmldom/xmldom` 0.8.11 → 0.8.12, resolving **high** XML
injection via unsafe CDATA serialization allowing attacker-controlled
markup insertion
([GHSA-wh4c-j3r5-mjhp](https://redirect.github.com/advisories/GHSA-wh4c-j3r5-mjhp))
- Updated `lodash` 4.17.23 → 4.18.1, resolving **high** Code Injection
via `_.template` imports key names
([GHSA-r5fr-rjxr-66jc](https://redirect.github.com/advisories/GHSA-r5fr-rjxr-66jc))
and **high** Prototype Pollution via array path bypass in `_.unset` and
`_.omit`
([GHSA-f23m-r3pf-42rh](https://redirect.github.com/advisories/GHSA-f23m-r3pf-42rh))
- Updated `vite` 7.3.1 → 7.3.2, resolving **high** Path Traversal in
optimized deps `.map` handling
([GHSA-4w7w-66w2-5vf9](https://redirect.github.com/advisories/GHSA-4w7w-66w2-5vf9)),
**high** `server.fs.deny` bypass with queries
([GHSA-v2wj-q39q-566r](https://redirect.github.com/advisories/GHSA-v2wj-q39q-566r)),
and **high** Arbitrary File Read via dev server WebSocket
([GHSA-p9ff-h696-f583](https://redirect.github.com/advisories/GHSA-p9ff-h696-f583))
- Updated `Django` 6.0.3 → 6.0.4, resolving the following CVEs:
- **CVE-2026-33033**: Potential DoS via `MultiPartParser` through
crafted multipart uploads.
- **CVE-2026-33034**: SGI requests with a missing or understated
`Content-Length` header could bypass the `DATA_UPLOAD_MAX_MEMORY_SIZE`
limit.
  - **CVE-2026-4292**: Privilege abuse in `ModelAdmin.list_editable`.
- **CVE-2026-3902**: ASGI header spoofing via underscore/hyphen
conflation.
  - **CVE-2026-4277**: Privilege abuse in `GenericInlineModelAdmin`.

##### Added

- **EPG historical data window**: the EPG XML output and XC EPG API now
support a `prev_days` URL parameter (e.g. `&prev_days=3`) to include
past programs in the EPG response. This allows third-party players that
request historical program schedules to receive the data they need. The
EPG URL builder in the Channels page exposes "Days forward" and "Days
back" controls. Per-user defaults for both values (`epg_days` /
`epg_prev_days`) can be configured in the User settings modal and are
applied automatically when no URL parameter is present. (Closes
[#&#8203;1154](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1154))
- **Plugin Hub**: administrators can now browse, install, and update
plugins directly from remote repositories via a new Plugin Hub page in
Settings. (Closes
[#&#8203;393](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/393))
— Thanks [@&#8203;sethwv](https://redirect.github.com/sethwv)
- Install plugins directly from the hub: the release zip is downloaded,
SHA256 integrity is verified, and the plugin is installed atomically.
- Update managed plugins when a newer version is available from their
source repo. Version compatibility constraints
(`min_dispatcharr_version` / `max_dispatcharr_version`) are enforced at
install time.
- Browse available plugins from all enabled repos with name,
description, version, author, and icon.
- Plugins installed from a repo are tracked as "managed": source repo,
slug, installed version, prerelease flag, and deprecated status are all
persisted and surfaced in the UI.
- Add plugin repositories by manifest URL. The official Dispatcharr
Plugins repository is pre-configured; third-party repos are supported by
supplying an optional GPG public key.
- Manifest signatures are verified via GPG; the official repo uses a
bundled public key. Signature status is displayed per-repo.
- Preview a repository URL before adding it - validates the manifest and
reports plugin count and signature status without saving anything.
- Configurable automatic manifest refresh interval (in hours; 0 to
disable) runs as a Celery background task.

##### Removed

- Removed dead `VODConnectionManager` class
(`apps/proxy/vod_proxy/connection_manager.py`) and its associated
helpers, which had been superseded by `MultiWorkerVODConnectionManager`.
All active code already used the multi-worker implementation. Removed
the unused `VODConnectionManager` import from `vod_proxy/views.py`, the
unscheduled `cleanup_vod_connections` task from `apps/proxy/tasks.py`,
and the unscheduled `cleanup_vod_persistent_connections` task from
`core/tasks.py`.
- Removed dead VOD URL routes: `VODPlaylistView` (playlist generation),
`VODPositionView` (position tracking), and the class-based
`VODStatsView` (replaced by the existing function-based `vod_stats`
view).
- Removed dead `updateVODPosition()` API method from
`frontend/src/api.js`, which called the now-removed position tracking
endpoint.

##### Fixed

- Fixed TV Guide "Record One" always scheduling the recording on the
first channel that matched the program's `tvg_id`, rather than the
channel the user actually selected. When multiple channels share the
same EPG source, the intended channel was silently ignored. The selected
channel object is now passed explicitly through the click handler chain
to `recordOne`, bypassing the `findChannelByTvgId` fallback lookup
entirely. (Fixes
[#&#8203;1140](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1140))
— Thanks [@&#8203;fezster](https://redirect.github.com/fezster)
- Graceful container shutdown: `docker stop` no longer results in exit
137 (SIGKILL). The entrypoint now explicitly stops all child processes —
including uWSGI workers, Celery, Daphne, and Redis, which are spawned as
uWSGI `attach-daemon` children and were previously invisible to the
signal handler. A polling loop replaces the old fixed `sleep`, exiting
as soon as all processes have stopped (up to an 8-second ceiling before
force-stopping). PostgreSQL is stopped using `pg_ctl stop -m immediate`
as a fallback rather than SIGKILL to avoid data corruption. Process
names are now recorded at startup and displayed correctly in crash
diagnostics. The unexpected-exit diagnostic block is now suppressed on
normal `docker stop` shutdowns. — Thanks
[@&#8203;Shokkstokk](https://redirect.github.com/Shokkstokk) for the
initial fix!
- Fixed two race conditions in the VOD proxy that caused the
`profile_connections` counter to go permanently negative, allowing
connections beyond the configured profile limit. (1)
`_decrement_profile_connections()` used a GET-before-DECR guard: two
concurrent decrements could both read the same positive value, both pass
the guard, and both fire, driving the counter below zero. Replaced with
an unconditional `DECR` followed by a clamp-to-zero if the result is
negative. (2) The `stream_generator` decremented `active_streams` and
then checked `has_active_streams()` in two separate Redis round-trips
without locking. A concurrent generator on another worker could read
`active_streams=0` in the window between those two calls and also
decrement the profile counter, producing a double-decrement. A new
`decrement_active_streams_and_check()` method performs both operations
under a single distributed lock, and a `profile_decremented` flag guards
all four call sites in the generator so the profile counter is only ever
decremented once per stream. (Closes
[#&#8203;1125](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1125))
— Thanks
[@&#8203;firestaerter3](https://redirect.github.com/firestaerter3)
- Fixed a provider TCP connection leak in the VOD proxy
`stream_generator`. When a stream ended via an unhandled exception path
that reached the `finally` block without any of the three exception
handlers having run (e.g. an error raised before the first `yield`), the
`finally` block decremented counters but never called
`redis_connection.cleanup()`. The upstream `requests.Response` and
`requests.Session` were left open until garbage collection. The
`finally` block now starts a `delayed_cleanup` daemon thread (matching
the 1-second delay used by the normal-completion and `GeneratorExit`
paths) so that seeking clients have time to reconnect and increment
`active_streams` before `cleanup()` checks whether it is safe to close
the connection.
- Fixed manual stream selection from the Stats page not enforcing M3U
profile connection limits in multi-worker deployments. When a non-owning
worker handled the `change_stream` request it correctly packaged
`stream_id` and `m3u_profile_id` into the Redis pubsub message, but the
owning worker's pubsub handler only consumed `url` and `user_agent`
silently dropping both IDs before calling `stream_manager.update_url()`.
Because `update_url` only calls `update_stream_profile()` when a
`stream_id` is provided, the `profile_connections` counter was never
updated after the switch, causing subsequent capacity checks to see
incorrect counts and bypass the full-profile guard. The handler now
extracts `stream_id` and `m3u_profile_id` from the event and forwards
them to `update_url()`. The bug did not affect single-worker / dev-mode
deployments because the owning worker handles those requests directly
without pubsub.
- Fixed the `next_stream` rotation endpoint applying the same class of
bug: `get_stream_info_for_switch()` was called and returned
`m3u_profile_id`, but the result was dropped when forwarding to
`ChannelService.change_stream_url()`, so `update_stream_profile()` was
never called and `profile_connections` counters were not updated after
an automatic stream rotation.
- Fixed stream switch metadata (`url`, `user_agent`, `stream_id`,
`m3u_profile`) being written to Redis before the switch was confirmed to
succeed. If the switch failed, URL unchanged or exception during
teardown, Redis described a URL not actually in use. Metadata is now
written only after `update_url()` returns `True`; on failure the owner
writes `stream_manager.url` back as the ground truth. The non-owner no
longer pre-writes metadata at all, all needed info is carried in the
pubsub payload and written by the owner after confirmation.
- Fixed the Stats page "Active Stream" dropdown not updating when a
stream switch occurs. The card was matching the active stream by
comparing the URL stored in Redis against stream URLs from the database,
which failed silently when the stored URL was a transformed/rewritten
value that didn't substring-match the original. The dropdown now matches
by `stream_id` (the authoritative value already present in the stats
payload) and re-runs only when `stream_id` changes, so the normal
polling interval drives updates with no extra renders.
- Fixed the XC Password field in the User modal being editable by
standard users despite the backend (`PATCH /api/accounts/users/me/`)
stripping `xc_password` from `custom_properties` for non-admin users,
causing the change to silently revert on save. The field and its
generate button are now disabled with an explanatory description when
the current user is not an administrator.
- Fixed live stream hiccups caused by nginx buffering TS proxy data to
disk. The `/proxy/` location block used `proxy_buffering off` and
`proxy_read/send_timeout` directives, which are silently ignored when
the upstream is `uwsgi_pass` (a different directive family). nginx was
therefore defaulting to `uwsgi_buffering on`, spooling stream data
through temp files on disk. Replaced with the correct `uwsgi_buffering
off`, `uwsgi_read_timeout 300s`, and `uwsgi_send_timeout 300s`
directives so stream data flows directly from uWSGI to the client socket
without intermediate disk I/O.
- Fixed the logo cache endpoint (`/api/channels/logos/{id}/cache/`)
holding a uWSGI greenlet indefinitely when fetching from a slow or
dripping remote server. The previous implementation used
`StreamingHttpResponse(iter_content())` with only a per-chunk read
timeout; a server that drips data just fast enough to reset the per-read
timer could hold the greenlet open forever. Replaced with an eager read
loop enforcing a hard total-download deadline (10 s) and a size cap (5
MB). Also fixed a race condition in the existing negative-cache logic:
the failure entry for a URL was cleared immediately upon receiving HTTP
200, before the body was read. A concurrent greenlet seeing no failure
entry during a slow download that ultimately timed out would also
attempt the fetch, defeating the cache. The entry is now cleared only
after the full body has been successfully received.
- Fixed uploading a local M3U file with no expiration date set sending
the string `"null"` as the `exp_date` field in the `FormData` request,
causing a 400 validation error from the API. Null/undefined values are
now skipped when building the `FormData` body, matching the behaviour
already present in the update path.
- Fixed `PATCH /api/channels/channels/edit/bulk/` returning a 500 error
when the request body included a `streams` list. The bulk edit handler
was iterating `validated_data` directly and calling `setattr(channel,
"streams", value)`, which Django prohibits on ManyToMany fields. Also
added an `@extend_schema` decorator so the Swagger UI correctly
documents the endpoint as accepting a JSON array and shows the `streams`
field. (Fixes
[#&#8203;883](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/883))
- Fixed several incorrect or incomplete OpenAPI (`@extend_schema`)
schemas across the API:
- `POST /api/epg/import/` — request body was undocumented; now correctly
shows the `id` field. Description updated from "import" to "refresh" to
match frontend and backend terminology.
- `DELETE /api/channels/logos/bulk-delete/` — `delete_files` boolean was
missing from the documented request body.
- `POST /api/channels/channels/batch-set-epg/` — `epg_data_id` inside
each association object was not marked `allow_null`/`required=False`,
even though passing `null` is the correct way to remove an EPG link.
- `PUT /api/connect/integrations/{id}/subscriptions/set/` — endpoint had
no `@extend_schema` at all; now documents that the request body is a
JSON array of subscription objects.

##### Changed

- **Output bitrate DB persistence**: the `ffmpeg_output_bitrate` stat is
no longer written to the database on every FFmpeg stats tick
(\~2/second). Instead, a local exponential moving average (EMA, α=0.1)
accumulates readings continuously. The first 10 samples (\~5 seconds)
are discarded as warmup to avoid polluting the average with FFmpeg's
unstable ramp-up values. After warmup, the smoothed value is flushed to
the database at most once every 30 seconds, and a final flush occurs
when the stream stops but only if the EMA has been seeded (i.e. the
stream ran past warmup). Streams that stop during warmup leave the
existing database value untouched, preserving previously accurate
measurements when channel-hopping.
- Performance: `generate_m3u`, `generate_epg`, and `xc_get_live_streams`
now use `select_related('channel_group', 'logo')` (or
`select_related('logo')` for EPG) on every Channel queryset in
`apps/output/views.py`. Previously each channel in the loop triggered a
separate database query for its `logo` and `channel_group` foreign keys;
with the JOIN-based prefetch this is reduced to a single query per
request. On deployments with \~2 000 channels, `xc_get_live_streams`
response time drops from \~2.5–4 s to \~250–450 ms. (Closes
[#&#8203;1127](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1127))
— Thanks [@&#8203;xBOBxSAGETx](https://redirect.github.com/xBOBxSAGETx)
- Performance: `generate_epg` now uses
`select_related('epg_data__epg_source')` on all EPG channel querysets,
eliminating N+1 database queries for `EPGSource` traversal per channel
(\~15 s improvement on \~2000-channel deployments; total EPG generation
time dropped from \~87 s to \~72 s in benchmarks).
- Performance: `xc_get_epg` now uses
`select_related('epg_data__epg_source')` on all three channel fetch
paths. Previously each request triggered 2 additional queries to resolve
`channel.epg_data` and `channel.epg_data.epg_source`.
- Performance: `generate_m3u` now uses `prefetch_related` for streams
when `?direct=true` is requested, eliminating N+1 stream queries (one
per channel) on that code path.
- Performance: `EPGGridAPIView` (`apps/epg/api_views.py`) now uses
`select_related('epg_data__epg_source')` on the
`channels_with_custom_dummy` queryset, eliminating 2 extra queries per
channel (for `epg_data` and `epg_source`) in the dummy EPG generation
loop.
- Performance: `generate_epg` now issues a single cross-channel
`ProgramData` bulk query. `.values()` returns plain dicts, bypassing
per-row Django model instantiation. Results are consumed in independent
5000-row keyset-paginated chunks. Combined with the `select_related`
improvements above, EPG generation time on large deployments is
significantly reduced.
- Performance: `xc_get_live_streams` no longer calls
`ChannelGroup.objects.get_or_create(name="Default Group")` once per
null-group channel; replaced with a lazy-initialised closure that
executes at most one query regardless of how many ungrouped channels are
present.
- AIO containers now connect to the internal PostgreSQL instance via a
Unix domain socket instead of TCP loopback. Users who have
`POSTGRES_HOST` explicitly set to `localhost` or `127.0.0.1` in their
compose file are automatically migrated to the socket path; any other
explicit value (external host/IP) is left untouched. — Thanks
[@&#8203;JCBird1012](https://redirect.github.com/JCBird1012)
- Improved the EPG response cache key. Previously it was based on the
raw query string and username, meaning a user default of `epg_days=7`
and an explicit `&days=7` URL parameter produced different cache entries
for identical output. The key is now built from all resolved effective
parameter values (`days`, `prev_days`, `cachedlogos`, `tvg_id_source`)
so semantically equivalent requests always share the same cache entry.
- Improved the HDHR, M3U, and EPG URL builder popovers in the Channels
table: each popover now opens with a brief intro sentence describing its
purpose. Toggle switches were refactored to use Mantine's native `label`
and `description` props (replacing the previous manual
`Group`/`Stack`/`Text` layout), giving each switch a properly styled
description line beneath its label. Switch alignment was also corrected.
Toggles now appear on the left with the label and description stacked to
the right, consistent with standard Mantine form layout.
- Redesigned the User settings modal with a tabbed layout: **Account**
(username, email, name, password), **Permissions** (user level, stream
limit, channel profiles, mature content filter - admin only), **EPG
Defaults** (days forward/back), and **API & XC** (XC password, API key
management). Fields are now logically grouped rather than split across
two ad-hoc columns.
- EPG channel scanning now automatically removes stale `EPGData`
entries. tvg-ids that were present in a previous scan but are no longer
found in the upstream source, provided they are not mapped to any
channel. This prevents unbounded database bloat over time. Entries
mapped to at least one channel are always preserved.
- Rewrote the M3U line parser as an `iter_m3u_entries` generator that
owns the full per-entry state machine. Intermediate directive lines
between `#EXTINF` and the stream URL are now handled correctly rather
than corrupting the pending entry or being silently misassigned. A
`#EXTINF` with no following URL is discarded with a warning instead of
carrying over a `url`-less entry into batch processing. Attribute keys
are normalised to lowercase during parsing (provider attribute names
remain case-insensitive end-to-end). The `#EXTINF` attribute regex is
pre-compiled at module load, and attribute lookups use O(1) `dict.get()`
instead of linear scans — approximately 10% faster parsing on large M3U
files.
- Added support for the `#EXTGRP` directive in M3U files. When a
`group-title` attribute is absent from the `#EXTINF` line, the value
from a following `#EXTGRP:` line is used as the group. An explicit
`group-title` attribute always takes priority. (Closes
[#&#8203;1088](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1088))
- Added accumulation of `#EXTVLCOPT` directives per entry. Options are
stored as a list under `vlc_opts` inside the stream's
`custom_properties`, available for downstream use (e.g. passing
VLC-specific options to the player). This is for a planned future
enhancement and can also be utlized with the API.
- M3U stream name parsing now uses the comma text (the canonical display
title per the base `#EXTINF` spec) as the primary stream name, falling
back to `tvc-guide-title`, then `tvg-name`, rather than preferring
`tvg-name` first. Providers that use `tvg-name` as an EPG key and put
the human-readable title after the comma will now display the correct
name. Providers that duplicate the same value in both fields are
unaffected. (Fixes
[#&#8203;1081](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1081))
- FloatingVideo player: the native video controls (timeline, play/pause,
volume) are now hidden by default when a live stream starts and only
appear when the user hovers over the player.
- Enhanced Swagger UI authorization dialog: registered a custom
`OpenApiAuthenticationExtension` for `ApiKeyAuthentication` so
drf-spectacular now generates an `ApiKeyAuth (apiKey)` entry alongside
`jwtAuth`. Both entries include descriptive text linking to the relevant
endpoints (`/api/accounts/token/`, `/api/accounts/api-keys/generate/`,
`/api/accounts/api-keys/revoke/`).
- Refactored frontend form components (`AccountInfoModal`,
`AssignChannelNumbers`, `Channel`, `ChannelBatch`, `ChannelGroup`,
`Connection`, `CronBuilder`, `DummyEPG`, and `EPG`) to extract business
logic into dedicated utility modules under `src/utils/forms/`. Each
extracted module is covered by unit tests. Mantine compound component
references (`Table.Tbody`, `Popover.Target`, `Accordion.Item`, etc.)
have been updated to use flat named imports. — Thanks
[@&#8203;nick4810](https://redirect.github.com/nick4810)
- Improved the EPG BOM fix from v0.22.1: replaced the
`lstrip(b'\xef\xbb\xbf')` / `startswith` approach with
`start.find(b'<?xml')`, which locates the XML declaration regardless of
any leading bytes BOM, whitespace, or other encoding markers without
needing to know what those bytes are.
- Dependency updates:
  - `Django` 6.0.3 → 6.0.4 (security patch; see Security section)
  - `djangorestframework` 3.16.1 → 3.17.1
  - `requests` 2.33.0 → 2.33.1
  - `gevent` 25.9.1 → 26.4.0
  - `rapidfuzz` 3.14.3 → 3.14.5
  - `sentence-transformers` 5.3.0 → 5.4.0
  - `lxml` 6.0.2 → 6.0.3
- Added `python-gnupg` for GPG signature verification of official and
third-party plugin repository manifests.

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvZGlzcGF0Y2hhcnIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-04-18 18:29:11 +00:00
TrueCharts Bot 9f06caf48c chore(dispatcharr): update image alpine digest to 5b10f43 (#47051) 2026-04-18 18:32:48 +02:00
TrueCharts-Bot 91642136a2 Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-04-18 00:24:44 +00:00
Kjeld Schouten fcbe54ccf4 more fixes 2026-04-17 22:06:12 +02:00
TrueCharts-Bot ce6c266331 Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-04-17 18:06:06 +00:00
TrueCharts Bot 509cd59e0a fix(helm-deps): update chart common 29.0.10 → 29.0.15 (#47022)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `29.0.10` →
`29.0.15` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-04-15 13:43:44 +02:00
TrueCharts Bot 827a6dd178 fix(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.22.0 → 0.22.1 (#46845)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/dispatcharr/dispatcharr](https://redirect.github.com/Dispatcharr/Dispatcharr)
| patch | `06189b5` → `ccdfa7e` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Dispatcharr/Dispatcharr
(docker.io/dispatcharr/dispatcharr)</summary>

###
[`v0.22.1`](https://redirect.github.com/Dispatcharr/Dispatcharr/blob/HEAD/CHANGELOG.md#0221---2026-04-05)

[Compare
Source](https://redirect.github.com/Dispatcharr/Dispatcharr/compare/v0.22.0...v0.22.1)

##### Fixed

- Fixed EPG sources that emit a UTF-8 BOM (e.g. ErsatzTV, EPGShare,
WebGrab+Plus) parsing 0 channels and 0 programmes after the HTML entity
fix introduced in v0.22.0. `bytes.lstrip()` only strips ASCII
whitespace, leaving the three BOM bytes (`EF BB BF`) in place, so
`stripped.startswith(b'<?xml')` returned `False`. The function fell
through to the no-declaration branch and prepended the HTML entity
DOCTYPE block *before* the BOM and XML declaration, producing invalid
XML that lxml silently discarded under `recover=True`. Fixed by
stripping the BOM explicitly before the whitespace strip:
`start.lstrip(b'\xef\xbb\xbf').lstrip()`. BOM-free files are unaffected.
(Closes
[#&#8203;1173](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1173))
— Thanks [@&#8203;dwot](https://redirect.github.com/dwot) for the fix!

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvZGlzcGF0Y2hhcnIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2026-04-13 18:27:35 +02:00
TrueCharts Bot d53ffcaf79 fix(helm-deps): update chart common 29.0.0 → 29.0.10 (#46661)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `29.0.0` →
`29.0.10` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-04-02 02:00:45 +02:00
TrueCharts Bot 9fb3507e24 feat(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.21.1 → 0.22.0 (#46628)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/dispatcharr/dispatcharr](https://redirect.github.com/Dispatcharr/Dispatcharr)
| minor | `3fe4da0` → `06189b5` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Dispatcharr/Dispatcharr
(docker.io/dispatcharr/dispatcharr)</summary>

###
[`v0.22.0`](https://redirect.github.com/Dispatcharr/Dispatcharr/blob/HEAD/CHANGELOG.md#0220---2026-04-01)

[Compare
Source](https://redirect.github.com/Dispatcharr/Dispatcharr/compare/v0.21.1...v0.22.0)

##### Security

- Updated `requests` 2.32.5 → 2.33.0, resolving the following CVE:
- **CVE-2026-25645** (moderate): Insecure temp file reuse in
`extract_zipped_paths()` utility function.
- Updated frontend npm dependencies to resolve 4 audit vulnerabilities
(2 moderate, 2 high):
- Updated `brace-expansion` 5.0.2 → 5.0.5, resolving **moderate**
zero-step sequence causing process hang and memory exhaustion
([GHSA-f886-m6hf-6m8v](https://redirect.github.com/advisories/GHSA-f886-m6hf-6m8v))
- Updated `flatted` 3.4.1 → 3.4.2, resolving **high** Prototype
Pollution via `parse()` in NodeJS flatted
([GHSA-rf6f-7fwh-wjgh](https://redirect.github.com/advisories/GHSA-rf6f-7fwh-wjgh))
- Updated `picomatch` 4.0.3 → 4.0.4, resolving **high** method injection
in POSIX character classes causing incorrect glob matching
([GHSA-3v7f-55p6-f55p](https://redirect.github.com/advisories/GHSA-3v7f-55p6-f55p))
and a ReDoS vulnerability via extglob quantifiers
([GHSA-c2c7-rcm5-vvqj](https://redirect.github.com/advisories/GHSA-c2c7-rcm5-vvqj))
- Updated `yaml` 1.10.2 → 1.10.3, resolving **moderate** stack overflow
via deeply nested YAML collections
([GHSA-48c2-rrv3-qjmp](https://redirect.github.com/advisories/GHSA-48c2-rrv3-qjmp))

##### Added

- Connection cards on the Stats page now show the **username** of the
connected user. For live channel connections a new User column appears
between IP Address and Connected; for VOD connections the username is
shown inline next to the IP address in the Client summary row. The
username is resolved from the user store using the `user_id` stored in
Redis client metadata. (Closes
[#&#8203;766](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/766),
Closes
[#&#8203;586](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/586))
- `ip_address` and `user_id` were not included in the client info
returned by `get_detailed_channel_info()` despite being available in the
Redis hash. Both fields are now extracted and returned. `user_id` is now
also included in the VOD stats response.
- Web UI stream preview now sends an `Authorization: Bearer` header with
each mpegts.js request, identifying the logged-in user. Live channel
previews initiated from the web UI now appear on the Stats page with the
correct username rather than as unknown user.
- `client_connect` and `client_disconnect` system events now include the
**username** of the connected user. The username is stored alongside the
client metadata in Redis and included in the event payload for
`log_system_event` calls (making it available to webhook and script
integrations).
- Donate button added to the sidebar footer. A heart icon links to the
project's Open Collective page, visible in both expanded and collapsed
states. Hovering shows a "Support Dispatcharr" tooltip. The version
string is also now clickable to copy it to the clipboard.
- User stream limits: administrators can now set a maximum number of
concurrent streams per user account. When a user reaches their limit,
the system can automatically terminate an existing stream to free a slot
based on configurable rules. Limit enforcement applies to both live
channels and VOD. (Closes
[#&#8203;544](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/544))
- Each user account has a new **Stream Limit** field (0 = unlimited)
configurable from the user edit form in Settings → Users.
- Global enforcement behaviour is configurable in Settings → User
Limits:
- **Terminate on Limit Exceeded**: automatically stop an existing stream
when the user's limit is reached (vs. rejecting the new connection).
- **Terminate Oldest**: prefer terminating the oldest stream when
freeing a slot; disable to prefer the newest.
- **Prioritize Single-Client Channels**: prefer terminating streams on
channels that only this user is watching.
- **Ignore Same-Channel Connections**: count multiple connections to the
same live channel as one stream toward the limit. Same-channel
reconnects are always allowed through. When this is enabled and a
channel must be freed, all connections to the chosen channel are
terminated together so that the unique-channel count actually decreases.
VOD is explicitly excluded from this bypass since VOD connections are
not shared upstream.
- TLS and mutual TLS (mTLS) support for Redis and PostgreSQL connections
in modular deployments. Supports encrypted connections, server
certificate verification (Redis: on/off; PostgreSQL: verify-full,
verify-ca, require), CA certificate configuration, and client
certificate authentication. Configured via environment variables in the
docker compose file. Includes startup validation for certificate paths
and TLS/URL scheme conflicts, and a read-only Connection Security panel
in System Settings. (Closes
[#&#8203;950](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/950))
— Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Status filter for M3U group and VOD category filter modals: A new
**All / Enabled / Disabled** segmented control is now shown alongside
the text search input in the Live, VOD - Movies, and VOD - Series tabs
of the M3U Group Filter modal. The status filter works in combination
with the text search and also scopes the "Select Visible" / "Deselect
Visible" buttons so they only act on the currently visible subset.
(Closes
[#&#8203;312](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/312))

##### Changed

- M3U Profile form (XC accounts): added a **Simple / Advanced** mode
toggle for credential-based URL rewriting. In Simple mode users enter
just a new username and password; the search and replace patterns are
built automatically from the account's current credentials. In Advanced
mode the full regex fields are shown as before. The selected mode is
saved to `custom_properties.xcMode` and auto-detected on existing
profiles (a profile whose search pattern matches the account's current
`username/password` is recognised as Simple automatically). The Live
Regex Demonstration panel is hidden in Simple mode.
- XtreamCodes VOD endpoints (`/movie/` and `/series/`) no longer
redirect clients to a UUID-based proxy URL. Requests are now handled
directly in the proxy layer via `stream_xc_movie` and
`stream_xc_episode`, which call `stream_vod()` internally. The original
XC path is preserved for the client throughout the stream.
- `CustomTable` column layout now supports flexible (`grow`) columns
alongside fixed-width ones:
- Column definitions accept a `grow` property (boolean or number) to opt
into flex layout. A numeric value sets the flex-grow weight, allowing
relative sizing between grow columns (e.g. `grow: 2` gives a column
twice the share of spare space as `grow: 1`).
- `maxSize` is now respected on grow columns, capping how wide they
expand via `maxWidth`.
- The wrapper's `minWidth` calculation now uses `minSize` (not
TanStack's 150px default) for grow columns, preventing the table from
overflowing its container when columns would otherwise be sized larger
than available space.
- Dependency updates:
  - `requests` 2.32.5 → 2.33.0 (security patch; see Security section)
  - `celery` 5.6.2 → 5.6.3
  - `torch` 2.10.0+cpu → 2.11.0+cpu
  - `sentence-transformers` 5.2.3 → 5.3.0
  - `yt-dlp` 2026.3.13 → 2026.3.17
- Docker base image cleanup: removed `python-is-python3`, `python3-pip`,
and `streamlink` from the apt package list in `DispatcharrBase`.
`python3-pip` and `streamlink` were pulling outdated system Python
packages (e.g. `requests 2.31.0`, `cryptography 41.0.7`, `lxml 5.2.1`)
into the system Python's site-packages despite the app running entirely
in the uv-managed venv at `/dispatcharrpy`. `streamlink` is already
installed in the venv via `pyproject.toml`. `python-is-python3` is
unnecessary as `PATH` resolves bare `python` to the venv binary.
- M3U table **Max Streams** column now reflects the combined limit
across all active profiles. When a playlist has multiple active
profiles, the column displays their summed total (or ∞ if any profile is
unlimited) and a hover tooltip lists each profile's individual limit by
name. (Closes
[#&#8203;816](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/816))
- Toggling an M3U profile's active state now immediately updates the
playlist store (including the `playlists` array), so the **Max Streams**
total in the M3U table reflects the change without a page reload.
- M3U account form: **Max Streams** field changed from a plain text
input to a number input with increment/decrement controls, consistent
with other integer fields.
- M3U account form: removed unused `useMantineTheme` import and `theme`
variable.
- Moved `guideUtils.js` from `frontend/src/pages/` to
`frontend/src/utils/` to be consistent with other utility modules (e.g.
`networkUtils.js`). Updated all imports across `GuideRow.jsx`,
`HourTimeline.jsx`, `ProgramDetailModal.jsx`, `RecordingCardUtils.js`,
`Guide.jsx`, and related test files.
- Frontend cleanup: removed unused imports from `M3UGroupFilter`,
`LiveGroupFilter`, and `VODCategoryFilter` (`Yup`, `M3UProfiles`,
several unused Mantine components, dead `OptionWithTooltip` component,
duplicate lucide-react imports, and `Divider` in `VODCategoryFilter`).
No behaviour changes.
- Network Access settings: leaving a field blank no longer shows a
validation error. The default CIDR range for that field is saved
automatically and a "Defaults Restored" warning is displayed listing
which fields were reset. (Closes
[#&#8203;726](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/726))

##### Fixed

- M3U profile URL rewriting now uses the `regex` module instead of `re`
across all URL transform code paths (`url_utils.transform_url`,
`core/views.py`, `vod_proxy/_transform_url`,
`tasks.get_transformed_credentials`, and the WebSocket live-preview
handler in `consumers.py`). The `regex` module natively accepts
JavaScript/PCRE-style named capture groups (`(?<name>...)`) without any
conversion, eliminating the root cause of patterns that matched in the
frontend live preview but failed on the backend with a `re.error`. As a
further improvement, `regex` also supports variable-length lookbehind
assertions (e.g. `(?<=a+)`), which `re` rejects with an error; patterns
using these will now work correctly on the backend as well.
Replace-pattern JS tokens are still normalised before calling
`regex.sub`: `$<name>` → `\g<name>` and `$1`/`$2`/… → `\1`/`\2`/…
(Python replacement syntax). Also fixed a bug in the WebSocket preview
handler where a pattern error was incorrectly returning the search
pattern string as the preview output instead of the original URL. (Fixes
[#&#8203;1005](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1005))
- Web UI stream preview (`FloatingVideo`) was calling
`mpegts.createPlayer()` with all `Config` options (e.g. `enableWorker`,
`liveSync`, `headers`) merged into the first `MediaDataSource` argument.
mpegts.js only reads `Config` from the optional second argument;
unrecognised fields in the first are silently ignored. As a result all
player configuration was effectively the library defaults — worker
offloading was disabled, latency management had no effect, and the
`Authorization: Bearer` header (required for user identification) was
never sent. Fixed by splitting into the correct two-argument call. Both
`liveBufferLatencyChasing` and `liveSync` have been disabled,
eliminating playback-rate fluctuations that caused audible stuttering on
live streams. SourceBuffer cleanup thresholds were also relaxed from
10s/5s to 120s/60s to prevent frequent SourceBuffer pauses.
- HTML named entities in XMLTV EPG files are now correctly preserved
during lxml parsing. Some EPG providers (particularly French and other
European sources) use HTML named entities like `&eacute;`, `&icirc;`,
`&uuml;` in channel names, program titles, and metadata. These are not
valid XML entities — lxml 6.0.2 with `recover=True` silently drops them,
causing characters to go missing (e.g., "Chaîne Télé" becomes "Chane
Tl"). This is now fixed by injecting an XML `<!DOCTYPE tv [...]>`
internal subset declaring all 252 HTML 4 named entities directly into
the byte stream that lxml reads, using a lightweight in-memory wrapper
(`_PrependStream`) with zero disk I/O. libxml2 resolves the entities
during its normal C-level parse pass — no Python-level preprocessing or
temporary files are involved. The DOCTYPE block (\~8 KB) is built once
at module load from Python's stdlib `html.entities.name2codepoint` and
reused for every parse. Files that already declare their own
`<!DOCTYPE>` are passed through unchanged. (Closes
[#&#8203;1095](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1095))
— Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
for helping with this!
- Duplicate recordings created when EPG sources refresh and re-evaluate
series rules (Fixes
[#&#8203;940](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/940))
— Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen):
- **Program ID instability**: `parse_programs_for_source()` deletes and
recreates all `ProgramData` rows with new auto-increment IDs on every
EPG refresh. The dedup set used these IDs, so it never matched after a
refresh. Deduplication now uses a stable `(tvg_id, start_time,
end_time)` composite key sourced from
`Recording.custom_properties.program`.
- **Secondary guard using wrong times**: The DB guard compared
unadjusted program times against offset-adjusted
`Recording.start_time`/`end_time`, so it never matched when any DVR
pre/post offset was configured. It now queries
`custom_properties__program__start_time/end_time` (the original,
unadjusted program times stored at recording creation).
- **No concurrency guard**: Each EPG source refresh fired
`evaluate_series_rules.delay()` independently. Concurrent tasks loaded
the dedup set before others committed, allowing races. Evaluation is now
serialized with `acquire_task_lock` (reusing the existing EPG task
pattern). Gracefully degrades if Redis is unavailable — the primary and
secondary dedup guards still protect.
- EPG refresh tasks (`refresh_epg_data`) were being killed
mid-transaction on large EPG sources. The `soft_time_limit=1700s`
introduced in v0.21.0 raised `SoftTimeLimitExceeded`, a subclass of
`Exception`, which was swallowed by the existing `except Exception`
handler in `parse_programs_for_source`, leaving the database in a
partial state with no logged error. `soft_time_limit` has been removed
from `refresh_epg_data` and `time_limit` raised to 14400s (4 hours) as a
true last-resort ceiling; the existing `TaskLockRenewer` daemon thread
continues to renew the Redis lock every 120s for legitimately
long-running tasks.

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvZGlzcGF0Y2hhcnIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2026-04-01 05:54:35 +02:00
TrueCharts Bot d2925c98de BREAKING CHANGE(helm-deps): Update chart common 28.33.4 → 29.0.0 (#46224)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | major | `28.33.4` →
`29.0.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9tYWpvciJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-03-19 17:38:03 +01:00
TrueCharts Bot 29f02f9831 feat(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.20.2 → 0.21.1 (#46164)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/dispatcharr/dispatcharr](https://redirect.github.com/Dispatcharr/Dispatcharr)
| minor | `116f7f4` → `3fe4da0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Dispatcharr/Dispatcharr
(docker.io/dispatcharr/dispatcharr)</summary>

###
[`v0.21.1`](https://redirect.github.com/Dispatcharr/Dispatcharr/blob/HEAD/CHANGELOG.md#0211---2026-03-18)

[Compare
Source](https://redirect.github.com/Dispatcharr/Dispatcharr/compare/v0.21.0...v0.21.1)

##### Fixed

- Docker container initialization fixes for PUID/PGID handling — Thanks
[@&#8203;CodeBormen](https://redirect.github.com/CodeBormen):
- Backups failing on previous installations where `/data/backups`
already existed: `/data/backups` was missing from the `DATA_DIRS` list
in the init script, causing the PUID/PGID ownership migration to skip
the directory and leave it with incorrect permissions.
- Container startup failure on upgrade when data directories reside on
external mounts (NFS, SMB/CIFS, FUSE): `chown` failures under `set -e`
were crashing the container, breaking setups that worked fine on the
previous image. Failures are now collected per-directory and reported as
a consolidated warning; the container continues to start and Django
reports at runtime if it cannot write a specific directory.
- Upgrading users running as UID 102 (the internal PostgreSQL system
user) instead of the expected UID 1000: the PUID/PGID auto-detect
introduced in v0.21.0 read ownership from `/data/db`, which was UID 102
in pre-PUID images, causing Django, file creation, and comskip to all
run as the wrong user. PUID/PGID now default to 1000 (matching the
original Django UID) rather than auto-detecting from data directory
ownership.

###
[`v0.21.0`](https://redirect.github.com/Dispatcharr/Dispatcharr/blob/HEAD/CHANGELOG.md#0210---2026-03-17)

[Compare
Source](https://redirect.github.com/Dispatcharr/Dispatcharr/compare/v0.20.2...v0.21.0)

##### Security

- Updated frontend npm dependencies to resolve 1 high-severity
vulnerability:
- Updated `flatted` to 3.4.1, resolving **high** unbounded recursion DoS
in the `parse()` revive phase
([GHSA-25h7-pfq9-p65f](https://redirect.github.com/advisories/GHSA-25h7-pfq9-p65f))
- Updated `Django` to 6.0.3 and `django-celery-beat` to 2.9.0, resolving
new security vulnerabilities:
- [CVE-2026-25673](https://www.cve.org/CVERecord?id=CVE-2026-25673):
Potential denial-of-service vulnerability in URLField via Unicode
normalization on Windows (March 3, 2026)
- [CVE-2026-25674](https://www.cve.org/CVERecord?id=CVE-2026-25674):
Potential incorrect permissions on newly created file system objects
(March 3, 2026)

##### Added

- Configurable sidebar navigation ordering and visibility — Thanks
[@&#8203;jcasimir](https://redirect.github.com/jcasimir)
- Sidebar nav items can be reordered via drag-and-drop in Settings → UI
Settings → Navigation.
- Individual nav items can be hidden from the sidebar using the eye
toggle. Hiding an item preserves its position in the order.
- A "Reset to Default" button restores the role-appropriate default
order and clears all hidden items.
- Order and visibility are saved per-user with optimistic updates and
automatic rollback on failure. Changes appear in the sidebar immediately
without a page reload.
- Admin users see a grouped navigation: flat items (`Channels`, `VODs`,
`M3U & EPG Manager`, `TV Guide`, `DVR`, `Stats`, `Plugins`) plus
collapsible `Integrations` (Connections, Logs) and `System` (Users, Logo
Manager, Settings) groups. The `System` group cannot be hidden.
- Non-admin users see `Channels`, `TV Guide`, and `Settings`, with the
`Settings` item not hideable.
- Unit tests for `NotificationCenter`, `NotificationCenterUtils`, and
`M3URefreshNotification` components, and for settings form components
`DvrSettingsForm`, `NetworkAccessForm`, `ProxySettingsForm`,
`StreamSettingsForm`, `SystemSettingsForm`, `UiSettingsForm`. — Thanks
[@&#8203;nick4810](https://redirect.github.com/nick4810)
- Unit tests for DVR port resolution (`build_dvr_candidates`) and
selective Redis flush behavior in modular mode. — Thanks
[@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Floating video player improvements
- **Title display**: The channel, stream, or VOD title is now shown in
the player header bar. Title is passed through from all preview entry
points: channel table, stream table, stream connection card, guide, DVR,
recording cards, recording details modal, VOD modal, and series modal.
- **Persistent state**: Size, position, volume level, and mute state are
now saved across sessions using a single `dispatcharr-player-prefs`
localStorage key. Size and position are restored on next open (clamped
to the current viewport); volume and mute are restored when the player
initialises.
- New Client Buffer proxy setting: new clients joining an active channel
are now positioned a configurable number of seconds behind live rather
than a fixed chunk count. The start position is determined by wall-clock
chunk receive time (stored as a Redis sorted set alongside the buffer),
so the buffer depth is consistent in seconds regardless of stream
bitrate. Setting the value to `0` starts clients at live with no buffer.
Defaults to 5 seconds. Existing chunk-count gating for the first client
connecting to a channel is unchanged. The setting is exposed in Settings
→ Proxy as "New Client Buffer (seconds)".
- Channel table filter for channels that have stale streams: A new "Has
Stale Streams" filter option in the channel table header menu highlights
and filters channels containing at least one stale stream. Channels with
stale streams are visually distinguished with an orange tint. The filter
is mutually exclusive with "Only Empty Channels". - Thanks
[@&#8203;JCBird1012](https://redirect.github.com/JCBird1012)
- "Next Highest Channel" numbering mode when creating channels from
streams: A new `Next Highest` option is available alongside `Provider`,
`Auto`, and `Custom` when creating channels from the Streams table.
Selecting it assigns channel numbers starting one above the current
highest channel number; the next available number is fetched from the
backend at selection time. (Closes
[#&#8203;1000](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1000))
— Thanks [@&#8203;JCBird1012](https://redirect.github.com/JCBird1012)
- TV Guide program cards now display richer metadata — Thanks
[@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- **Season/episode badges** (e.g. `S12E06`) extracted from EPG
`<episode-num>` elements, `onscreen` episode strings (e.g. `S12 E6`,
`S3E21`, `S8 E8 P2/2`), and as a last-resort fallback from description
text patterns at parse time (3-tier pipeline). (Closes
[#&#8203;1065](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1065))
- **Episode subtitle** shown below the program title on guide cards;
falls back to the short description when no subtitle is available.
- **Status badges**: `LIVE`, `NEW`, `PREMIERE`, and `FINALE` surfaced
from EPG flags on both compact cards and the detail modal.
- **Program detail modal**: Clicking any guide program opens a modal
with full program details — poster/icon image, season/episode, subtitle,
duration, categories, cast/director/writer credits, content rating, star
ratings, production date, original air date, video quality, and external
links to IMDb and TMDB where available. Detail data is fetched from a
new `GET /api/epg/programs/{id}/` endpoint backed by the new
`ProgramDetailSerializer`. Dummy/placeholder programs skip the fetch.
- **Real-time progress bars**: Currently-airing programs show a green
progress bar on their guide card that updates every second via direct
DOM manipulation (no React re-renders).
- **Channel name tooltip**: Hovering the channel logo column shows the
channel name.
- Sort icons added to the Group and EPG column headers in the Channels
table, and to the Group column header in the Streams table. Clicking a
sort icon cycles through ascending/descending/unsorted states. EPG
sorting required a backend change (`epg_data__name` added to
`ChannelViewSet.ordering_fields`); Group sorting was already supported
by the API in both tables. (Closes
[#&#8203;854](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/854))
— Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- DVR enhancements — Thanks
[@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- **Stop Recording**: A new Stop button (distinct from Cancel) cleanly
ends an in-progress recording early and keeps the partial file available
for playback. The API returns immediately; stream teardown and task
revocation happen in a background thread to prevent 504 timeouts. When
multiple recordings run simultaneously, stopping one only terminates
that recording's proxy client by ID, leaving all others unaffected.
(Closes
[#&#8203;454](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/454))
- **Extend Recording**: In-progress recordings can be extended by 15,
30, or 60 minutes without interrupting the stream.
- **Inline metadata editing**: Title and description can now be edited
directly in the recording details modal.
- **Refresh artwork button**: Manually re-run poster resolution on
demand from the recording card.
- **Multi-source poster resolution**: Added pipeline querying EPG, VOD,
TMDB, OMDb, TVMaze, and iTunes for richer recording artwork.
- **Series rules for currently-airing episodes**: Series rules now
capture currently-airing episodes in addition to future scheduled ones.
(Closes
[#&#8203;473](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/473))
- **Search and filter controls**: Added search and filter controls to
the recordings list.
- **Stream generator throttling**: Cached the `ProxyServer` singleton
reference per client and throttled Redis resource checks (1 s) and
non-owner health checks (2 s), eliminating 3+ Redis round-trips per
stream loop iteration.
- **Automatic crash recovery on worker restart**: A `worker_ready`
Celery signal now fires `recover_recordings_on_startup` automatically
when the worker starts, so recordings stuck in "recording" status are
recovered without manual intervention.
- Account expiration tracking and notifications for M3U profiles
- A new `exp_date` field on `M3UAccountProfile` stores the account
expiration date as a proper `DateTimeField`. For Xtream Codes accounts
the field is auto-synced from `custom_properties.user_info.exp_date` on
every save (supports both Unix timestamps and ISO date strings). For
non-XC M3U accounts the date can be entered manually via the account or
profile form.
- The M3U accounts table now shows an **Expiration** column displaying
the earliest expiration date across all profiles for that account
(color-coded: red = expired, orange = expiring soon, green = OK).
Hovering the cell shows a tooltip with per-profile expiration details
including inactive-profile labels.
- A daily Celery Beat task (`check_xc_account_expirations`) checks all
active profiles with an expiration date and manages system
notifications: a normal-priority warning is raised for profiles expiring
within 7 days; a high-priority alert is raised once the profile has
already expired. Warning and expired notifications use separate keys so
dismissing the 7-day warning does not suppress the expiration alert.
- Notifications are also updated immediately when a profile is saved: if
the expiration date is cleared or pushed beyond the 7-day window, any
existing warning/expired notifications are deleted; if the date falls
within the window or is already past, the matching notification is
updated in place.
- Non-XC accounts expose a `DateTimePicker` on both the M3U account form
and the profile form.

##### Changed

- Dependency updates:
- `Django` 5.2.11 → 6.0.3 (security patch + major version upgrade; see
Security section)
- `django-celery-beat` ≥2.8.1 → ≥2.9.0 (adds explicit Django 6.0
support)
- When selecting an EPG source for a channel, the EPG source dropdown
now only lists enabled (active) EPGs, sorted alphabetically.
- Channels page default splitter ratio changed from 50/50 to 60/40
(channels/streams) so all channel action buttons are visible without
scrolling on 1080p displays.
- Frontend component refactoring and cleanup — Thanks
[@&#8203;nick4810](https://redirect.github.com/nick4810)
- `FloatingVideo`, `SeriesModal`, `VODModal`, `SystemEvents`,
`M3URefreshNotification`, and `NotificationCenter` significantly reduced
in size by separating business logic into dedicated utility modules
under `utils/components/` (`FloatingVideoUtils.js`,
`SeriesModalUtils.js`, `VODModalUtils.js`,
`NotificationCenterUtils.js`).
- `FloatingVideo` resize handle elements extracted into a standalone
`ResizeHandles` sub-component.
- `YouTubeTrailerModal` extracted into a standalone component
(`components/modals/YouTubeTrailerModal.jsx`).
- `NotificationCenter` and `Sidebar` updated from Mantine dot-notation
sub-components (`Popover.Target`, `Popover.Dropdown`,
`ScrollArea.Autosize`, `AppShell.Navbar`) to Mantine v7 named imports
(`PopoverTarget`, `PopoverDropdown`, `ScrollAreaAutosize`,
`AppShellNavbar`).
- `M3URefreshNotification` now uses the centralized `showNotification()`
utility (from `notificationUtils.js`) instead of calling
`notifications.show()` directly, bringing it in line with the rest of
the app. State updates also converted to functional updater form (`prev
=> ...`) to eliminate potential stale-closure bugs.
- `SystemEvents` now imports `format` from `dateTimeUtils` for
consistent date/time formatting.
- Removed a dead `onLogout` handler in `Sidebar` that called `logout()`
and `window.location.reload()` but was never wired to any UI element.
- EPG output when no `days` parameter is specified now excludes
already-ended programs instead of returning all historical data.

##### Fixed

- Single-stream channel creation modal not opening correctly when
clicking the channel-creation button on an individual stream row in the
Streams table. — Thanks
[@&#8203;JCBird1012](https://redirect.github.com/JCBird1012)
- DVR series rule creation failing with a 500 error when the stored
`series_rules` data contained corrupted (non-dict) entries. Added type
guards on the getter, setter, and generic settings serializer to filter
invalid entries on read and write. Hardened the EPG ignore list getters
(`prefixes`, `suffixes`, `custom`) with the same pattern. Frontend
settings parse and save now validate `series_rules` with
`Array.isArray()`, matching the existing EPG field pattern, preventing
corrupted data from being round-tripped back to the database. (Fixes
[#&#8203;1059](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1059))
— Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- TS proxy clients stuck indefinitely in keepalive mode when a stream
fails and never recovers (Fixes
[#&#8203;1102](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1102),
[#&#8203;1103](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1103))
— Thanks
[@&#8203;cmcpherson274](https://redirect.github.com/cmcpherson274) &
[@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- **Keepalive duration cap**: Non-owner worker clients sending keepalive
packets to hold a connection open during failover can now be held at
most `MAX_KEEPALIVE_DURATION` seconds (default 300 s). If no real stream
data has been received within that window, the client is disconnected
with a warning log. The timer resets each time real data resumes, so
independent stalls do not accumulate.
- **`last_active` tracking**: `last_active` is now updated on every
keepalive packet and on every real data chunk, so clients actively
waiting during a failover are not incorrectly evicted as ghost clients
by the heartbeat thread. The heartbeat thread now only refreshes the
Redis TTL rather than updating `last_active`, ensuring the
ghost-detection check reflects true client activity rather than
heartbeat activity.
- **Buffer reset on stream transition**: A new `reset_buffer_position()`
method on `StreamBuffer` clears the in-memory write buffer and
partial-packet accumulator when switching between FFmpeg processes.
Without this, a partial 188-byte TS packet from the dying FFmpeg process
was being prepended to the first bytes from the new FFmpeg process,
producing a corrupted TS packet boundary that broke audio decoder sync
on the client side. Redis-stored chunks already consumed by clients are
unaffected.
- **`add_chunk()` locking hardened**: The lock scope in `add_chunk()`
was expanded to cover the entire partial-packet merge and write-buffer
accumulation phase, preventing a race condition between `add_chunk()`
and the new `reset_buffer_position()` call.
- uWSGI segfaults caused by mixing threading and gevent concurrency
models. The dev and debug uWSGI configs had `threads` and
`enable-threads = true` set alongside gevent, which triggers
segmentation faults particularly on ARM64/Python 3.13. Removed those
options to match the already-correct production config. — Thanks
[@&#8203;jcasimir](https://redirect.github.com/jcasimir)
- `Stream.last_seen` and `ChannelGroupM3UAccount.last_seen` model
defaults now use `django.utils.timezone.now` instead of
`datetime.datetime.now`, eliminating spurious `RuntimeWarning:
DateTimeField received a naive datetime` warnings emitted during test
database creation and on new record creation when `USE_TZ=True`.
- EPG programme parsing crash when an XMLTV source contains programme
titles exceeding 255 characters. Previously, a single oversized title
would cause the entire `bulk_create` batch to fail with a database
truncation error, silently dropping all programmes in that batch. Titles
are now truncated to 255 characters before being saved. (Fixes
[#&#8203;1039](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1039))
- Container startup failure when `PUID`/`PGID` is set, caused by
`/data/db` ownership conflicts between the `postgres` system user (UID
102) and the configured PUID/PGID. PostgreSQL now runs as the PUID/PGID
user in AIO mode, eliminating all `chown`-to-UID-102 operations and
unifying `/data` ownership. (Fixes
[#&#8203;1078](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1078))
— Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Existing installations where PUID/PGID differs from the current
`/data/db` owner are migrated automatically on first startup; a sentinel
file prevents redundant recursive `chown` on subsequent boots.
- PUID/PGID auto-detected from existing data ownership when not
explicitly set, avoiding cross-UID `chown` failures on restricted
filesystems (NFS `root_squash`, CIFS).
- PUID/PGID validated as positive non-zero integers before any
user/group operations.
- UID collisions with the `postgres` system user (e.g. PUID=102) are now
handled gracefully.
- Ensured proper variable quoting in the /docker/ directory to guard
from inappropriate input
- Floating video player bug fixes
- **Resize stuck after releasing mouse outside window**: The `mouseup`
event is not delivered when the pointer leaves the viewport, leaving the
`mousemove` listener active indefinitely. Fixed by checking
`event.buttons === 0` at the top of `handleResizeMove`; when no button
is held the resize session is torn down immediately.
- **Drag stuck after releasing mouse outside window**: Same root cause
as the resize bug. Fixed by detecting `event.buttons === 0` in the
`onDrag` handler and dispatching a synthetic `mouseup` event so
react-draggable cleanly ends the drag session.
- **Player draggable off screen**: The player could be dragged off any
edge, making the header (and drag handle) unreachable. The player is now
fully bounded: left and top edges are clamped to `x ≥ 0` / `y ≥ 0` so
the header is always reachable, and right/bottom edges are clamped to
the viewport. Size and position are also re-clamped automatically when
the browser window is resized, with proportional scale-down if the saved
size exceeds the new viewport.
- Double error notification when saving user preferences: `API.updateMe`
was catching errors internally and displaying a notification before
re-throwing, causing callers to display a second notification for the
same failure.
- Navigation preference saves from concurrent sessions could overwrite
each other due to a double-merge race: the frontend was pre-merging
`custom_properties` before sending, then the backend merged again
against the DB value, causing the second session's write to silently
drop keys set by the first. The frontend now sends only the delta; the
backend merges authoritatively against the stored value.
- Stale nav item IDs (e.g. from a previous nav structure) are now
scrubbed from `navOrder` and `hiddenNav` on the next preference save,
preventing unbounded growth of the `custom_properties` JSON field.
- Version update notification persisting after upgrading to the notified
version (e.g. "v0.20.2 available" shown while already running v0.20.2).
Root cause: `check_for_version_update.delay()` was called from
`AppConfig.ready()`, which fires inside Celery prefork pool subprocesses
before the broker connection is established, causing the dispatch to
fail silently with no log output. Fixed by moving the startup dispatch
to the `worker_ready` signal in `celery.py` (consistent with the
existing `recover_recordings_on_startup` pattern), and deleting the
stale `version-{current_version}` notification at the top of the
production check path so it is cleared even when GitHub is unreachable.
A WebSocket update is sent immediately on deletion so the frontend badge
clears without waiting for the API response.
- VOD orphan cleanup crashing with a `ForeignKeyViolation`
(`IntegrityError`) when a concurrent refresh task created a new
`M3UMovieRelation` or `M3USeriesRelation` for a movie/series between the
orphan-detection query and the `DELETE` SQL. Both
`orphaned_movies.delete()` and `orphaned_series.delete()` are now
wrapped in `try/except IntegrityError`; affected records are skipped
with a warning and will be cleaned up on the next scheduled run.
- XC stream refresh crashing with a `null value in column "name"`
database error when a provider returns streams with a null or empty
name. Affected streams are now assigned a generated fallback name in the
format `<account name> - <stream_id>` so the refresh completes
successfully and the stream remains accessible. A warning is logged for
each affected stream.
- 504 Gateway Timeout when saving M3U group settings on slower hardware
(e.g. Synology NAS). Replaced per-row `update_or_create()` loops with
`bulk_create(update_conflicts=True)` wrapped in `transaction.atomic()`
for both `ChannelGroupM3UAccount` and `M3UVODCategoryRelation`, reducing
hundreds of individual DB round-trips to a single query per model.
(Fixes
[#&#8203;745](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/745))
— Thanks [@&#8203;nickgerrer](https://redirect.github.com/nickgerrer)
- Improved frontend table stability during M3U imports: Fixed incorrect
default `state` initialization (`[]` → `{}`) in `CustomTable` to match
TanStack Table v8's expected state object shape. Added
`autoResetPageIndex: false` and `autoResetExpanded: false` to prevent
TanStack Table from issuing internal state resets on data updates.
Memoized `processedData` in `M3UsTable` to avoid redundant sort/filter
recomputation on re-renders. - Thanks
[@&#8203;marcinolek](https://redirect.github.com/marcinolek)
- `debian_install.sh` hardened for non-UTF8 environments (common in
minimal LXC containers) - Thanks
[@&#8203;marcinolek](https://redirect.github.com/marcinolek)
- Added `setup_locales` step that installs the `locales` package,
enables `en_US.UTF-8`, regenerates locales, and exports `LANG`/`LC_ALL`
before any other work runs, preventing PostgreSQL from defaulting to
`SQL_ASCII` encoding.
- PostgreSQL database creation now explicitly passes `-E UTF8` to
`createdb`.
- `PATH` in the Celery worker, Celery Beat, and Daphne systemd service
files extended to include
`/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin`, fixing failures
where background tasks could not locate `ffmpeg` or `ffprobe`.
- `is_adult` field parsing now guards against invalid values (e.g. the
string `"None"`) that providers may send instead of a valid integer,
preventing a `ValueError` crash during M3U/XC stream refresh. A new
`parse_is_adult()` helper wraps the cast in a `try/except`, returning
`False` for anything that cannot be interpreted as `1`. (Fixes
[#&#8203;1061](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1061))
— Thanks [@&#8203;JCBird1012](https://redirect.github.com/JCBird1012)
- M3U EXTINF attribute parsing for values containing `=` or `==` (e.g.
base64-padded `tvg-logo` URLs, catchup tokens with query strings). The
previous regex used `[^\s]+` for the key pattern, allowing `=` signs
inside a quoted value to be greedily absorbed into the next attribute's
key name, causing that attribute and all subsequent ones on the line to
be silently dropped. Changed to `[^\s=]+` so the key match always stops
at the first `=`. (Fixes
[#&#8203;1055](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1055))
- Thanks [@&#8203;JCBird1012](https://redirect.github.com/JCBird1012)
- Celery worker memory leak during M3U/XC refresh causing 20–80 MB
growth per cycle with no reclamation (Fixes
[#&#8203;1012](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1012),
[#&#8203;1053](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1053))
- Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Restructured `refresh_single_m3u_account()` with a `try/finally` that
guarantees `del` of large data structures runs before Celery's
`gc.collect()`, and lock release on all exit paths (success, exception,
early return)
- Re-enabled batch data cleanup in `process_m3u_batch_direct()` (was
commented out)
- Added `CELERY_WORKER_MAX_MEMORY_PER_CHILD = 512 MB` as a safety net
against pymalloc arena fragmentation
- EPG output was filtering programs using `start_time__gte=now` when the
`days` parameter was specified, which caused currently-airing programs
(started before the request time but not yet ended) to be omitted from
the XML output. This produced a gap in clients' guides immediately after
an EPG refresh, lasting until the next program started. Fixed by
changing the filter to `end_time__gte=now` so any program that has not
yet finished is included.
- TS proxy connection slot leaks and TOCTOU races in stream
initialization (Fixes
[#&#8203;947](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/947))
- Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- **TOCTOU race in slot reservation**: `get_stream()` previously used a
`GET`→check→`INCR` sequence, allowing concurrent requests to both read
the same count below the limit and both reserve a slot, silently
exceeding `max_streams`. Replaced with an atomic `INCR`-first pattern:
increment unconditionally, check the result, roll back with `DECR` if
over capacity. — Thanks
[@&#8203;patchy8736](https://redirect.github.com/patchy8736)
- **Leak on URL generation failure**: `generate_stream_url()` called
`get_stream()` (which `INCR`s the counter) but had no cleanup path if
subsequent DB lookups or URL construction failed. The
post-`get_stream()` block is now wrapped in a `try/except` that calls
`release_stream()` on any error.
- **Leak on retry-loop timeout**: the retry loop in `stream_ts()` called
a bare `get_stream()` on the first failure to classify the error reason.
If a slot was available, this `INCR`'d the counter and set Redis keys
that were never released when the loop timed out. A `release_stream()`
call is now issued before returning 503.
- **Leak on `initialize_channel()` failure**: when
`initialize_channel()` returned `False`, the connection slot allocated
by the preceding `get_stream()` was never released. A
`connection_allocated` flag now tracks whether this request performed
the `INCR` (fresh initialization vs. joining an existing channel), and
`release_stream()` is called guarded by that flag to prevent incorrect
decrements when attaching to an already-running channel.
- **Safety net for unexpected exceptions**: the outer `except` in
`stream_ts()` now checks `connection_allocated` and calls
`release_stream()` as a last-resort cleanup for any unhandled exception
that escapes before the channel is handed off to the stream lifecycle.
- **`release_stream()` now returns `bool`** and adds a metadata-hash
fallback: if the primary `channel_stream` / `stream_profile` Redis keys
have already been cleaned up by the proxy, it recovers `stream_id` and
`profile_id` from the channel's metadata hash and clears those fields
atomically to prevent duplicate `DECR`s on repeated calls. — Thanks
[@&#8203;patchy8736](https://redirect.github.com/patchy8736)
- **`update_stream_profile()` uses a Redis pipeline** for the
old-profile DECR + key update + new-profile INCR sequence, preventing
counter drift if the process crashes between operations.
- **`stream_generator._cleanup()`** now falls back to
`Stream.objects.get()` when the channel UUID resolves to a preview flow
rather than a normal channel, rather than silently skipping the slot
release.
- **VOD `cleanup_persistent_connection()`** fallback DECR is now
conditional: it only decrements the profile counter when the connection
tracking key had already expired by TTL (i.e., `remove_connection()`
would have skipped the DECR), preventing double-decrements when the key
is still present.
- Ghost clients and channels stuck in `INITIALIZING` state in the TS
proxy (Fixes
[#&#8203;695](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/695),
[#&#8203;669](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/669))
— Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- **`INITIALIZING` added to cleanup grace period monitoring**: channels
stuck in `INITIALIZING` are now surfaced by the cleanup task and torn
down, preventing indefinite hangs when stream startup fails.
- **Orphaned channel cleanup validates client SET entries**: the cleanup
task now cross-checks client SET members against actual metadata hashes;
ghost SET entries are removed and the channel is torn down cleanly when
no real clients remain.
- **Stats page self-heals**: ghost client SET entries are detected and
removed when reading channel stats, preventing stale entries from
inflating the active-client count.
- **`remove_ghost_clients()` extracted to `ClientManager`**:
ghost-detection logic is now a single authoritative helper, callable
with an optional pre-fetched `client_ids` set to eliminate a redundant
Redis `SMEMBERS` round-trip when the caller already holds the set.
- **Ownership TTL fallback**: the error-state writer now triggers via
ownership check *or* state guard fallback, so a channel stuck in a
pre-active state is correctly marked `ERROR` even when the ownership TTL
expired during retries.
- **Missing `SOURCE_BITRATE` / `FFMPEG_BITRATE` metadata constants**
added to `ChannelMetadataField`, preventing `AttributeError` on detailed
channel stats reads.
- TS proxy client stream lag recovery now only bumps clients forward
when their next required chunk has genuinely expired from Redis (TTL),
rather than unconditionally jumping if they fell more than 50 chunks
behind. Clients are repositioned to the oldest available chunk (minimum
data loss) using an atomic server-side Lua binary search, falling back
to near the buffer head if nothing is available.
- TS proxy streams dying after 30–200 seconds in multi-worker
uWSGI/Celery deployments, caused by three interrelated bugs. (Fixes
[#&#8203;992](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/992),
[#&#8203;980](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/980))
- Thanks [@&#8203;PFalko](https://redirect.github.com/PFalko)
- **Double ProxyServer instantiation**: `ProxyConfig.ready()` called
`TSProxyServer()` directly while `TSProxyConfig.ready()` also called
`TSProxyServer.get_instance()`, creating two instances per worker — each
with its own cleanup thread. The orphaned thread could not extend
ownership because it had no entries in `stream_managers`. Fixed by using
`TSProxyServer.get_instance()` in `ProxyConfig.ready()`.
- **`flushdb()` on every Redis client init**: `RedisClient.get_client()`
called `client.flushdb()` whenever `_client` was `None`. Celery
autoscale (`--autoscale=6,1`) spawning new workers mid-stream triggered
this path, nuking all Redis keys including active ownership keys, client
records, and channel metadata. Removed the `flushdb()` call entirely.
- **No recovery from expired ownership**: `get_channel_owner()` called
`redis.get()` twice inside a lambda (TOCTOU race — key could expire
between calls); `extend_ownership()` silently returned `False` on expiry
with no re-acquisition; and the non-owner cleanup path unconditionally
killed streams even when the worker held the `stream_manager`. Fixed
with a single `GET` in `get_channel_owner()`, re-acquisition via atomic
`SET NX EX` in `extend_ownership()`, and a re-acquisition attempt with
client-aware cleanup deferral in the cleanup thread.
- `get_instance()` deadlock: if `ProxyServer()` raised an exception
during singleton construction, `_instance` was left permanently as the
`_INITIALIZING` sentinel, causing all subsequent `get_instance()`
callers to spin in an infinite `gevent.sleep()` loop. Construction is
now wrapped in `try/except`; on failure `_instance` resets to `None` so
the next call can retry.
- Non-atomic ownership acquisition in `try_acquire_ownership()`:
replaced the separate `setnx()` + `expire()` calls with a single atomic
`SET NX EX`, eliminating the race window where a process crash between
the two calls could leave an ownership key with no TTL (permanent
ownership lock).
- DVR bug fixes — Thanks
[@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- **Duplicate recording execution**:
`run_recording.apply_async(countdown=...)` exceeded Redis' default
`visibility_timeout` (3600 s) for recordings scheduled more than one
hour out, causing Redis to redeliver the task to multiple workers
simultaneously and producing corrupted output files. Replaced
`apply_async` with `ClockedSchedule` + `PeriodicTask` for
database-backed one-shot scheduling that survives restarts and upgrades
without the redelivery race. `run_recording` also now exits immediately
if the recording is already in progress, completed, or stopped.
`revoke_task()` cleans up both the `PeriodicTask` and its orphaned
`ClockedSchedule` on execution. (Fixes
[#&#8203;940](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/940),
[#&#8203;641](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/641))
- **Stream reconnection resilience**: Recordings now survive transient
network drops with automatic reconnection retrying up to 5 times and
appending to the existing file. DB operations use exponential-backoff
retry for transient database errors throughout the recording lifecycle.
- **Crash recovery pipeline**: On worker restart, recordings stuck in
"recording" status have their segments concatenated and remuxed. Remux
sanity checks reject MKV output that is less than 50% the size of a
previous MKV (duplicate-task overwrite) or less than 10% of the source
TS (corrupt first attempt); the source `.ts` is preserved for manual
recovery on all failure paths. (Fixes
[#&#8203;619](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/619),
[#&#8203;624](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/624))
- **Output file collision**: Fixed collision when multiple tasks
targeted the same filename.
- **WebSocket deadlock**: `send_websocket_update()` was deadlocking the
gevent event loop, causing one recording's WebSocket events to block all
other simultaneous recordings.
- **DVR client isolation**: Stop and Cancel operations now identify the
target client by recording ID (via `User-Agent:
Dispatcharr-DVR/recording-{id}`), ensuring only the correct proxy client
is torn down and never affecting other recordings on the same channel.
- **Accidental stream termination on delete**: `destroy()` now only
calls `_stop_dvr_clients()` for in-progress recordings, preventing
stream termination when deleting a completed recording.
- **Recording card logos**: Logos were not displaying due to a channel
summary API shape mismatch.
- **Logo fetch negative cache**: Added negative cache for failed remote
logo fetches so dead CDNs no longer block Daphne workers on repeated
requests.
- **Artwork fuzzy-match sanitisation**: Poster artwork fuzzy-matching
against external APIs (TMDB, OMDb, etc.) was producing incorrect results
for channels with names like "USA A\&E SD\*"; channel-name strings are
now sanitised before querying external sources.
- **Series modal "No upcoming episodes"**: Fixed due to a missing
`_group_count` merge and an incorrect time filter.
- **Series rule cleanup**: Deleting a series rule left orphaned
recordings and stale Guide indicators; rule deletion now cleans up all
associated recordings. Orphaned recordings with no parent rule are also
cleaned up automatically. (Fixes
[#&#8203;1041](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1041))
- **Series rule timezone calculation**: Recurring rules silently dropped
scheduled recordings for users in UTC-negative timezones after 4 pm
local time. (Fixes
[#&#8203;1042](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1042))
- **Recording modal TDZ crash**: Modal crashed on load in production
bundles due to a Temporal Dead Zone error — editing state was referenced
before its declaration in the minified bundle.
- **Description textarea focus loss**: The description textarea lost
focus immediately when opened because the inline editing component was
remounting on every render.
- **WebSocket-driven refresh**: Replaced all manual `fetchRecordings()`
polling calls with debounced WebSocket-driven refresh so the recordings
list stays up to date without redundant API requests.
- **comskip exit code handling**: comskip treated exit code 1 ("no
commercials found") as a fatal error, causing post-processing to fail on
clean recordings. Exit code 1 is now recognised as a successful no-op.
- **Differentiated WebSocket notification events**: `recording_stopped`,
`recording_cancelled` (in-progress cancel), and `recording_deleted` with
a `was_in_progress` flag now allow the frontend to display distinct
"Recording stopped", "Recording cancelled", and "Recording deleted"
toasts.
- **Duplicate series rule evaluation race**: Creating a series rule
fired `evaluate_series_rules.delay()` in the API view while the frontend
immediately called the synchronous evaluate endpoint, racing to create
duplicate recordings for the same program. Removed the redundant async
call from the API; the frontend's explicit evaluate call is now the sole
evaluation path.
- **Recording card S/E badge overlap**: Season/episode badges were
overlapping and metadata was hidden on the recording card.
- **Orphaned recording fallback in series modal**: When a series rule no
longer exists, the recurring rule modal now shows a "Delete Recording"
button for the orphaned recording instead of failing silently.
- Modular mode deployment hardening — Thanks
[@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- **Postgres version check with restricted DB users**: The version check
was connecting to the hardcoded `postgres` database, which fails when
the configured user lacks access to it. Changed to use `$POSTGRES_DB` so
the check works with least-privilege database users. (Fixes
[#&#8203;1045](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1045))
- **DVR recording broken in modular mode**: Internal TS stream URL
candidates hardcoded port `9191`, so recordings failed when
`DISPATCHARR_PORT` was set to any other value. URL construction now
reads `DISPATCHARR_PORT` from the environment via the new
`build_dvr_candidates()` helper. `DISPATCHARR_PORT` is also now
explicitly passed to the Celery container in `docker-compose.yml`.
- **Selective Redis flush in modular mode**: `wait_for_redis.py` now
performs a targeted flush in modular mode — clearing stale stream locks,
proxy metadata, and server-state keys — while preserving Celery broker
and result-backend keys. Previously either a full `flushdb()` (which
wiped Celery queues) or no flush at all was performed.
- **Redis wait stripping environment variables**: The modular-mode Redis
readiness check ran as a uWSGI `exec-pre` hook, which executes under `su
-` and strips Docker environment variables, making `DISPATCHARR_ENV` and
`REDIS_HOST` unavailable. Moved to the container entrypoint so all env
vars are present.
- **Stale environment variables after container restart**:
`/etc/profile.d/dispatcharr.sh` was only written on the first container
run; restarts with changed env vars (e.g. a rotated `POSTGRES_PASSWORD`)
retained stale values. The file is now truncated and rewritten on every
startup. `/etc/environment` entries are likewise updated rather than
skipped when a key already exists. All exported values are now quoted to
prevent breakage from special characters.
- **Celery entrypoint startup timeouts**: The JWT key wait and migration
wait loops had no timeout, leaving the Celery worker hanging
indefinitely if the web container was stuck. Each loop now times out
(120 s for JWT, 300 s for migrations) and exits with a clear diagnostic
message. The migration readiness check is also replaced from a fragile
`showmigrations | grep` pattern to `migrate --check`, which exits
cleanly on both unapplied migrations and connection errors.
- **Service startup ordering**: `depends_on` entries for `db` and
`redis` in `docker-compose.yml` upgraded from plain name-link ordering
to `condition: service_healthy`, ensuring containers wait for actual
readiness signals before starting.
- **`host.docker.internal` resolution on Linux**: Added `extra_hosts:
host.docker.internal:host-gateway` to the web service in
`docker-compose.yml` so Linux hosts resolve `host.docker.internal` the
same way Docker Desktop does on macOS/Windows.

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvZGlzcGF0Y2hhcnIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL21pbm9yIl19-->
2026-03-18 04:39:40 +01:00
TrueCharts-Bot 6c96fb9c0f Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-03-18 00:20:43 +00:00
Alfred Göppel ec199707c1 fix(charts): fix chart.yaml annotations for all charts (#46134)
**Description**
<!--
Please include a summary of the change and which issue is fixed. Please
also include relevant motivation and context. List any dependencies that
are required for this change.
-->
⚒️ Fixes  # <!--(issue)-->

**⚙️ Type of change**

- [ ] ⚙️ Feature/App addition
- [ ] 🪛 Bugfix
- [ ] ⚠️ Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [x] 🔃 Refactor of current code
- [ ] 📜 Documentation Changes

**🧪 How Has This Been Tested?**
<!--
Please describe the tests that you ran to verify your changes. Provide
instructions so we can reproduce. Please also list any relevant details
for your test configuration
-->

**📃 Notes:**
<!-- Please enter any other relevant information here -->

**✔️ Checklist:**

- [x] ⚖️ My code follows the style guidelines of this project
- [x] 👀 I have performed a self-review of my own code
- [ ] #️⃣ I have commented my code, particularly in hard-to-understand
areas
- [ ] 📄 I have made changes to the documentation
- [ ] 🧪 I have added tests to this description that prove my fix is
effective or that my feature works
- [ ] ⬆️ I increased versions for any altered app according to semantic
versioning
- [x] I made sure the title starts with `feat(chart-name):`,
`fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or
`fix(docs):`

** App addition**

If this PR is an app addition please make sure you have done the
following.

- [ ] 🖼️ I have added an icon in the Chart's root directory called
`icon.png`

---

_Please don't blindly check all the boxes. Read them and only check
those that apply.
Those checkboxes are there for the reviewer to see what is this all
about and
the status of this PR with a quick glance._
2026-03-17 11:40:04 +01:00
TrueCharts Bot 465db91ac6 fix(helm-deps): update chart common 28.33.3 → 28.33.4 (#45987)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.33.3` →
`28.33.4` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->
2026-03-12 21:15:56 +01:00
TrueCharts Bot 77276072da fix(helm-deps): update chart common 28.33.0 → 28.33.3 (#45974)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.33.0` →
`28.33.3` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-03-12 15:06:57 +01:00
TrueCharts-Bot 35a06650d9 Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-03-06 00:23:07 +00:00
TrueCharts Bot 5e7adcd624 fix(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.20.1 → 0.20.2 (#45753)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/dispatcharr/dispatcharr](https://redirect.github.com/Dispatcharr/Dispatcharr)
| patch | `db8a9d3` → `116f7f4` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Dispatcharr/Dispatcharr
(docker.io/dispatcharr/dispatcharr)</summary>

###
[`v0.20.2`](https://redirect.github.com/Dispatcharr/Dispatcharr/blob/HEAD/CHANGELOG.md#0202---2026-03-03)

[Compare
Source](https://redirect.github.com/Dispatcharr/Dispatcharr/compare/v0.20.1...v0.20.2)

##### Security

- Updated frontend npm dependencies to resolve 2 high-severity
vulnerabilities:
- Updated `minimatch` to ≥10.2.3, resolving **high** ReDoS via
matchOne() combinatorial backtracking with multiple non-adjacent
GLOBSTAR segments
([GHSA-7r86-cg39-jmmj](https://redirect.github.com/advisories/GHSA-7r86-cg39-jmmj))
- Updated `rollup` to ≥4.58.1, resolving **high** Arbitrary File Write
via Path Traversal
([GHSA-mw96-cpmx-2vgc](https://redirect.github.com/advisories/GHSA-mw96-cpmx-2vgc))

##### Fixed

- EPG filter regression in channel table (introduced in 0.20.0 channel
store refactor): The EPG filter dropdown was showing all EPG sources
regardless of whether they had any channels assigned, and the "No EPG"
option was never displayed. Fixed by annotating EPGSource records with a
`has_channels` flag (via a lightweight `EXISTS` subquery) so only active
EPG sources with at least one channel assigned appear as filter options.
"No EPG" now appears only when at least one channel globally has no EPG
assigned; this is determined by a second `EXISTS` query embedded
directly in the paginated channel response
(`has_unassigned_epg_channels`), avoiding any additional network
requests.
- Stale stream rows missing hover effect: Stale streams in the streams
table had no hover color change, unlike channels with no streams
assigned. Converted the inline `backgroundColor` style to a CSS class
(`stale-stream-row`) so the `:hover` rule can apply correctly. Applied
the same fix to the channel-streams sub-table, where the teal
expanded-row background caused the semi-transparent red tint to visually
mismatch; the sub-table now uses a pre-blended solid color via
`color-mix()` to match the appearance of stale rows in the main streams
table.
- Channel table onboarding shown when filter returns zero results: The
channel store refactor changed to loading only channel IDs instead of
full channel objects, leaving `Object.keys(channels).length` always `0`
and incorrectly triggering the onboarding state on any empty filter.
Fixed by checking `channelIds.length` instead.
- TV Guide scrolls to position 0 when a filter yields no results:
Applying any filter that temporarily empties the channel list (e.g.
switching directly between two channel groups, or typing a search query
that matches nothing) caused the guide to show a blank/empty view with
no programs visible. The `VariableSizeList` unmounts when
`filteredChannels` becomes empty, destroying its DOM node and resetting
`scrollLeft` to 0. On remount the scroll position was never restored
because `initialScrollComplete` was still `true`. Fixed by saving the
user's current scroll position when the channel list empties
mid-transition, then restoring it once new channels have loaded. On
first load the guide still scrolls to the current time as before.
- `debian_install.sh` regressions after `uv` migration on clean/minimal
Debian installs: fixed pip-less venv (`ensurepip`), missing `gunicorn`
for the systemd unit, and inconsistent `DJANGO_SECRET_KEY` availability
(now persisted to `.env` via `EnvironmentFile`). Docker unaffected. -
Thanks [@&#8203;marcinolek](https://redirect.github.com/marcinolek)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvZGlzcGF0Y2hhcnIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2026-03-03 05:21:52 +01:00
TrueCharts Bot c685ddd8cf feat(helm-deps): update chart common 28.32.5 → 28.33.0 (#45682)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | minor | `28.32.5` →
`28.33.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-03-01 11:04:58 +01:00
TrueCharts Bot b5bbdbc7bf fix(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.20.0 → 0.20.1 (#45599)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/dispatcharr/dispatcharr](https://redirect.github.com/Dispatcharr/Dispatcharr)
| patch | `f3583e5` → `db8a9d3` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Dispatcharr/Dispatcharr
(docker.io/dispatcharr/dispatcharr)</summary>

###
[`v0.20.1`](https://redirect.github.com/Dispatcharr/Dispatcharr/blob/HEAD/CHANGELOG.md#0201---2026-02-26)

[Compare
Source](https://redirect.github.com/Dispatcharr/Dispatcharr/compare/v0.20.0...v0.20.1)

##### Fixed

- Login form disabled after token expiry: The login button was
permanently rendered as disabled ("Logging you in...") on page load
after a session expired, preventing users from logging back in. A
regression in v0.20.0 caused `LoginForm` to check `if (user)` to detect
an already-authenticated reload, but the Zustand auth store initializes
`user` as a truthy empty object `{ username: '', email: '', user_level:
'' }`, so the loading state was set immediately on every mount. Reverted
to pre-regression behavior. (Fixes
[#&#8203;1029](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/1029))

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvZGlzcGF0Y2hhcnIiLCJhdXRvbWVyZ2UiLCJyZW5vdmF0ZS9jb250YWluZXIiLCJ0eXBlL3BhdGNoIl19-->
2026-02-27 03:49:55 +01:00
TrueCharts Bot ac53c949e5 feat(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.19.0 → 0.20.0 (#45593) 2026-02-26 21:42:57 +01:00
TrueCharts Bot 772ec1b1b4 fix(helm-deps): update chart common 28.32.2 → 28.32.5 (#45514)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.32.2` →
`28.32.5` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-02-24 21:16:35 +01:00
TrueCharts Bot d828cf193b feat(helm-deps): update chart common 28.31.19 → 28.32.2 (#45462)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | minor | `28.31.19`
→ `28.32.2` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-02-24 05:37:48 +01:00
TrueCharts Bot 71711148d4 feat(helm-deps): update chart common 28.30.2 → 28.31.19 (#45418)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | minor | `28.30.2` →
`28.31.19` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the [Dependency
Dashboard](../issues/18710) for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yOS4yIiwidXBkYXRlZEluVmVyIjoiNDMuMjkuMiIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-02-23 05:37:11 +01:00
TrueCharts Bot 02dac97d45 fix(helm-deps): update chart common 28.30.0 → 28.30.2 (#45040)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.30.0` →
`28.30.2` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My44LjUiLCJ1cGRhdGVkSW5WZXIiOiI0My44LjUiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOlsiYXBwL3p3YXZlanMybXF0dCIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-02-16 13:13:23 +01:00
TrueCharts Bot 507412860e feat(helm-deps): update chart common 28.29.59 → 28.30.0 (#45031)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | minor | `28.29.59`
→ `28.30.0` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My44LjUiLCJ1cGRhdGVkSW5WZXIiOiI0My44LjUiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOlsiYXBwL3p3YXZlanMybXF0dCIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvbWlub3IiXX0=-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-02-15 23:04:15 +01:00
TrueCharts-Bot fe6ee7ee60 Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-02-15 11:30:36 +00:00
TrueCharts Bot 3d99f5804a fix(helm-deps): update chart common 28.29.49 → 28.29.59 (#44970)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.49`
→ `28.29.59` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My44LjUiLCJ1cGRhdGVkSW5WZXIiOiI0My44LjUiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOlsiYXBwL3p3YXZlanMybXF0dCIsImF1dG9tZXJnZSIsInJlbm92YXRlL2NvbnRhaW5lciIsInR5cGUvcGF0Y2giXX0=-->

Signed-off-by: Kjeld Schouten <info@kjeldschouten.nl>
Co-authored-by: Kjeld Schouten <info@kjeldschouten.nl>
2026-02-15 11:33:44 +01:00
Kjeld Schouten d05c0a6e71 port yaml-language-server logic from common2026 2026-02-14 22:35:03 +01:00
TrueCharts Bot 597c66afa6 feat(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.18.1 → 0.19.0 (#44756)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[docker.io/dispatcharr/dispatcharr](https://redirect.github.com/Dispatcharr/Dispatcharr)
| minor | `425be85` → `8b53fbe` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

Add the preset `:preserveSemverRanges` to your config if you don't want
to pin your dependencies.

---

### Release Notes

<details>
<summary>Dispatcharr/Dispatcharr
(docker.io/dispatcharr/dispatcharr)</summary>

###
[`v0.19.0`](https://redirect.github.com/Dispatcharr/Dispatcharr/blob/HEAD/CHANGELOG.md#0190---2026-02-10)

[Compare
Source](https://redirect.github.com/Dispatcharr/Dispatcharr/compare/v0.18.1...v0.19.0)

##### Added

- Add system notifications and update checks
  -Real-time notifications for system events and alerts
  -Per-user notification management and dismissal
-Update check on startup and every 24 hours to notify users of available
versions
  -Notification center UI component
  -Automatic cleanup of expired notifications
- Network Access "Reset to Defaults" button: Added a "Reset to Defaults"
button to the Network Access settings form, matching the functionality
in Proxy Settings. Users can now quickly restore recommended network
access settings with one click.
- Streams table column visibility toggle: Added column menu to Streams
table header allowing users to show/hide optional columns (TVG-ID,
Stats) based on preference, with optional columns hidden by default for
cleaner default view.
- Streams table TVG-ID column with search filter and sort: Added TVG-ID
column to streams table with search filtering and sort capability for
better stream organization. (Closes
[#&#8203;866](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/866))
- Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Frontend now automatically refreshes streams and channels after a
stream rehash completes, ensuring the UI is always up-to-date following
backend merge operations.
- Frontend Unit Tests: Added comprehensive unit tests for React hooks
and Zustand stores, including:
- `useLocalStorage` hook tests with localStorage mocking and error
handling
  - `useSmartLogos` hook tests for logo loading and management
  - `useTablePreferences` hook tests for table settings persistence
  - `useAuthStore` tests for authentication flow and token management
  - `useChannelsStore` tests for channel data management
  - `useUserAgentsStore` tests for user agent CRUD operations
  - `useUsersStore` tests for user management functionality
  - `useVODLogosStore` tests for VOD logo operations
  - `useVideoStore` tests for video player state management
  - `useWarningsStore` tests for warning suppression functionality
- Code refactoring for improved readability and maintainability - Thanks
[@&#8203;nick4810](https://redirect.github.com/nick4810)
- EPG auto-matching: Added advanced options to strip prefixes, suffixes,
and custom text from channel names to assist matching; default matching
behavior and settings remain unchanged (Closes
[#&#8203;771](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/771))
- Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Redis authentication support for modular deployments: Added support
for authentication when connecting to external Redis instances using
either password-only authentication (Redis <6) or username + password
authentication (Redis 6+ ACL). REDIS\_PASSWORD and REDIS\_USER
environment variables with URL encoding for special characters. (Closes
[#&#8203;937](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/937))
- Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Plugin logos: if a plugin ZIP includes `logo.png`, it is surfaced in
the Plugins UI and shown next to the plugin name.
- Plugin manifests (`plugin.json`) for safe metadata discovery, plus
legacy warnings and folder-name fallbacks when a manifest is missing.
- Plugin stop hooks: Dispatcharr now calls a plugin's optional `stop()`
method (or `run("stop")` action) when disabling, deleting, or reloading
plugins to allow graceful shutdown.
- Plugin action buttons can define `button_label`, `button_variant`, and
`button_color` (e.g., Stop in red), falling back to “Run” for older
plugins.
- Plugin card metadata: plugins can specify `author` and `help_url` in
`plugin.json` to show author and docs link in the UI.
- Plugin cards can now be expanded/collapsed by clicking the header or
chevron to hide settings and actions.

##### Changed

- XtreamCodes Authentication Optimization: Reduced API calls during XC
refresh by 50% by eliminating redundant authentication step. This should
help reduce rate-limiting errors.
- App initialization efficiency: Refactored app initialization to
prevent redundant execution across multiple worker processes. Created
`dispatcharr.app_initialization` utility module with
`should_skip_initialization()` function that prevents custom
initialization tasks (backup scheduler sync, developer notifications
sync) from running during management commands, in worker processes, or
in development servers. This significantly reduces startup overhead in
multi-worker deployments (e.g., uWSGI with 10 workers now syncs the
scheduler once instead of 10 times). Applied to both `CoreConfig` and
`BackupsConfig` apps.
- M3U/EPG Network Access Defaults: Updated default network access
settings for M3U and EPG endpoints to only allow local/private networks
by default (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16,
::1/128, fc00::/7, fe80::/10). This improves security by preventing
public internet access to these endpoints unless explicitly configured.
Other endpoints (Streams, XC API, UI) remain open by default.
- Modular deployments: Bumped modular Postgres image to 17 and added
compatibility checks (PostgreSQL version and UTF-8 database encoding)
when using external databases to prevent migration/encoding issues.
- Stream Identity Stability: Added `stream_id` (provider stream
identifier) and `stream_chno` (provider channel number) fields to Stream
model. For XC accounts, the stream hash now uses the stable `stream_id`
instead of the URL when hashing, ensuring XC streams maintain their
identity and channel associations even when account credentials or
server URLs change. Supports both XC `num` and M3U
`tvg-chno`/`channel-number` attributes.
- Swagger/OpenAPI Migration: Migrated from `drf-yasg` (OpenAPI 2.0) to
`drf-spectacular` (OpenAPI 3.0) for API documentation. This provides:
- Native Bearer token authentication support in Swagger UI - users can
now enter just the JWT token and the "Bearer " prefix is automatically
added
  - Modern OpenAPI 3.0 specification compliance
  - Better auto-generation of request/response schemas
  - Improved documentation accuracy with serializer introspection
- Switched to uv for package management: Migrated from pip to uv
(Astral's fast Python package installer) for improved dependency
resolution speed and reliability. This includes updates to Docker build
processes, installation scripts (debian\_install.sh), and project
configuration (pyproject.toml) to leverage uv's features like virtual
environment management and lockfile generation. - Thanks
[@&#8203;tobimichael96](https://redirect.github.com/tobimichael96) for
getting it started!
- Copy to Clipboard: Refactored `copyToClipboard` utility function to
include notification handling internally, eliminating duplicate
notification code across the frontend. The function now accepts optional
parameters for customizing success/failure messages while providing
consistent behavior across all copy operations.

##### Fixed

- XC EPG Logic: Fixed EPG filtering issues where short EPG requests had
no time-based filtering (returning expired programs) and regular EPG
requests used `start_time__gte` (missing the currently playing program).
Both now correctly use `end_time__gt` to show programs that haven't
ended yet, with short EPG additionally limiting results. (Fixes
[#&#8203;915](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/915))
- Automatic backups not enabled by default on new installations: Added
backups app to `INSTALLED_APPS` and implemented automatic scheduler
initialization in `BackupsConfig.ready()`. The backup scheduler now
properly syncs the periodic task on startup, ensuring automatic daily
backups are enabled and scheduled immediately on fresh database creation
without requiring manual user intervention.
- Fixed modular Docker Compose deployment and entrypoint/init scripts to
properly support `DISPATCHARR_ENV=modular`, use external
PostgreSQL/Redis services, and handle port, version, and encoding
validation (Closes
[#&#8203;324](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/324),
Fixes
[#&#8203;61](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/61),
[#&#8203;445](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/445),
[#&#8203;731](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/731))
- Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Stream rehash/merge logic now guarantees unique stream\_hash and
always preserves the stream with the best channel ordering and
relationships. This prevents duplicate key errors and ensures the
correct stream is retained when merging. (Fixes
[#&#8203;892](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/892))
- Admin URL Conflict with XC Streams: Updated nginx configuration to
only redirect exact `/admin` and `/admin/` paths to login in production,
preventing interference with stream URLs that use "admin" as a username
(e.g., `/admin/password/stream_id` now properly routes to stream
handling instead of being redirected).
- EPG Channel ID XML Escaping: Fixed XML parsing errors in EPG output
when channel IDs contain special characters (&, <, >, ") by properly
escaping them in XML attributes. (Fixes
[#&#8203;765](https://redirect.github.com/Dispatcharr/Dispatcharr/issues/765))
- Thanks [@&#8203;CodeBormen](https://redirect.github.com/CodeBormen)
- Fixed NumPy baseline detection in Docker entrypoint. Now properly
detects when NumPy crashes on import due to CPU baseline incompatibility
and installs legacy NumPy version. Previously, if NumPy failed to
import, the script would skip legacy installation assuming it was
already compatible.
- Backup Scheduler Test: Fixed test to correctly validate that automatic
backups are enabled by default with a retention count of 3, matching the
actual scheduler defaults. - Thanks
[@&#8203;jcasimir](https://redirect.github.com/jcasimir)
- Hardened plugin loading to avoid executing plugin code unless the
plugin is enabled.
- Prevented plugin package names from shadowing standard library or
installed modules by namespacing plugin imports with safe aliases.
- Added safety limits to plugin ZIP imports (file count and size caps)
and sanitized plugin keys derived from uploads.
- Enforced strict boolean parsing for plugin enable/disable requests to
avoid accidental enables from truthy strings.
- Applied plugin field defaults server-side when running actions so
plugins receive expected settings even before a user saves.
- Plugin settings UI improvements: render `info`/`text` fields, support
`input_type: password`, show descriptions/placeholders, surface save
failures, and keep settings in sync after refresh.
- Disabled plugins now collapse settings/actions to match the closed
state before first enable.
- Plugin card header controls (delete/version/toggle) now stay
right-aligned even with long descriptions.
- Improved plugin logo resolution (case-insensitive paths + absolute
URLs), fixing dev UI logo loading without a Vite proxy.
- Plugin reload now hits the backend, clears module caches across
workers, and refreshes the UI so code changes apply without a full
backend restart.
- Plugin loader now supports `plugin.py` without `__init__.py`,
including folders with non-identifier names, by loading modules directly
from file paths.
- Plugin action handling stabilized: avoids registry race conditions and
only shows loading on the active action.
- Plugin enable/disable toggles now update immediately without requiring
a full page refresh.

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My40LjIiLCJ1cGRhdGVkSW5WZXIiOiI0My40LjIiLCJ0YXJnZXRCcmFuY2giOiJtYXN0ZXIiLCJsYWJlbHMiOlsiYXBwL2Rpc3BhdGNoYXJyIiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->
2026-02-11 00:30:46 +00:00
TrueCharts-Bot bafc468832 Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-02-03 00:19:06 +00:00
TrueCharts Bot 32a5df0fda feat(helm-deps): update chart common to v28.29.49 (#44431)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.40`
-> `28.29.49` |
|
[common](https://trueforge.org/truetech/truecharts/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | minor | `28.26.4`
-> `28.29.49` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciIsInR5cGUvcGF0Y2giXX0=-->

Signed-off-by: Kjeld Schouten <info@kjeldschouten.nl>
Co-authored-by: Kjeld Schouten <info@kjeldschouten.nl>
2026-02-02 22:19:33 +01:00
TrueCharts-Bot bf152c8e74 Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-02-01 15:24:18 +00:00
TrueCharts-Bot f8c1ee7bdf Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-01-31 19:20:09 +00:00
Alfred Göppel a802ce64e9 fix(all-charts): Fix chart.yaml & add missing icons (#44393)
**Description**
<!--
Please include a summary of the change and which issue is fixed. Please
also include relevant motivation and context. List any dependencies that
are required for this change.
-->
⚒️ Fixes  # <!--(issue)-->

**⚙️ Type of change**

- [ ] ⚙️ Feature/App addition
- [ ] 🪛 Bugfix
- [ ] ⚠️ Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] 🔃 Refactor of current code
- [ ] 📜 Documentation Changes

**🧪 How Has This Been Tested?**
<!--
Please describe the tests that you ran to verify your changes. Provide
instructions so we can reproduce. Please also list any relevant details
for your test configuration
-->

**📃 Notes:**
<!-- Please enter any other relevant information here -->

**✔️ Checklist:**

- [ ] ⚖️ My code follows the style guidelines of this project
- [ ] 👀 I have performed a self-review of my own code
- [ ] #️⃣ I have commented my code, particularly in hard-to-understand
areas
- [ ] 📄 I have made changes to the documentation
- [ ] 🧪 I have added tests to this description that prove my fix is
effective or that my feature works
- [ ] ⬆️ I increased versions for any altered app according to semantic
versioning
- [ ] I made sure the title starts with `feat(chart-name):`,
`fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or
`fix(docs):`

** App addition**

If this PR is an app addition please make sure you have done the
following.

- [ ] 🖼️ I have added an icon in the Chart's root directory called
`icon.png`

---

_Please don't blindly check all the boxes. Read them and only check
those that apply.
Those checkboxes are there for the reviewer to see what is this all
about and
the status of this PR with a quick glance._
2026-01-31 20:18:46 +01:00
TrueCharts-Bot 5aef95e6ad Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-01-31 18:06:18 +00:00
Alfred Göppel a855dd67f7 fix(charts): remove old annotations & add proper category (#44376)
**Description**
<!--
Please include a summary of the change and which issue is fixed. Please
also include relevant motivation and context. List any dependencies that
are required for this change.
-->
⚒️ Fixes  # <!--(issue)-->

**⚙️ Type of change**

- [ ] ⚙️ Feature/App addition
- [ ] 🪛 Bugfix
- [ ] ⚠️ Breaking change (fix or feature that would cause existing
functionality to not work as expected)
- [ ] 🔃 Refactor of current code
- [ ] 📜 Documentation Changes

**🧪 How Has This Been Tested?**
<!--
Please describe the tests that you ran to verify your changes. Provide
instructions so we can reproduce. Please also list any relevant details
for your test configuration
-->

**📃 Notes:**
<!-- Please enter any other relevant information here -->

**✔️ Checklist:**

- [ ] ⚖️ My code follows the style guidelines of this project
- [ ] 👀 I have performed a self-review of my own code
- [ ] #️⃣ I have commented my code, particularly in hard-to-understand
areas
- [ ] 📄 I have made changes to the documentation
- [ ] 🧪 I have added tests to this description that prove my fix is
effective or that my feature works
- [ ] ⬆️ I increased versions for any altered app according to semantic
versioning
- [ ] I made sure the title starts with `feat(chart-name):`,
`fix(chart-name):`, `chore(chart-name):`, `docs(chart-name):` or
`fix(docs):`

** App addition**

If this PR is an app addition please make sure you have done the
following.

- [ ] 🖼️ I have added an icon in the Chart's root directory called
`icon.png`

---

_Please don't blindly check all the boxes. Read them and only check
those that apply.
Those checkboxes are there for the reviewer to see what is this all
about and
the status of this PR with a quick glance._

---------

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-01-31 14:45:57 +01:00
TrueCharts Bot 53112a7ff0 chore(dispatcharr): update image alpine digest to 2510918 (#44358) 2026-01-31 04:58:56 +01:00
TrueCharts-Bot d2de50f17e Commit daily changes
Signed-off-by: TrueCharts-Bot <bot@truecharts.org>
2026-01-31 00:17:02 +00:00
TrueCharts Bot 4c9a7d4d6c feat(dispatcharr): update image docker.io/dispatcharr/dispatcharr 0.17.0 → 0.18.1 (#44216) 2026-01-27 21:36:56 +01:00
TrueCharts Bot 09e7d81949 fix(helm-deps): update chart common 28.29.37 → 28.29.40 (#44167)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.37`
-> `28.29.40` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->
2026-01-27 11:38:33 +01:00
TrueCharts Bot 6fef4f5378 fix(helm-deps): update chart common 28.29.36 → 28.29.37 (#44120)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.36`
-> `28.29.37` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->
2026-01-26 20:43:14 +01:00
TrueCharts Bot e5dbc41f1d fix(helm-deps): update chart common 28.29.35 → 28.29.36 (#44059)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.35`
-> `28.29.36` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-01-24 11:39:54 +01:00
TrueCharts Bot b2f0b22973 fix(helm-deps): update chart common 28.29.30 → 28.29.35 (#43970)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.30`
-> `28.29.35` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-01-23 16:34:04 +01:00
TrueCharts Bot 2bda3b6dbd fix(helm-deps): update chart common to v28.29.30 (#43902)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.27`
-> `28.29.30` |
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.18`
-> `28.29.30` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->
2026-01-22 08:53:40 +01:00
TrueCharts Bot 01774c784b fix(helm-deps): update chart common 28.29.24 → 28.29.27 (#43825)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.24`
-> `28.29.27` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-01-20 07:42:53 +01:00
TrueCharts Bot d70fdda029 fix(helm-deps): update chart common 28.29.23 → 28.29.24 (#43809)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.23`
-> `28.29.24` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-01-19 16:43:24 +01:00
TrueCharts Bot e2e09b4f87 fix(helm-deps): update chart common 28.29.20 → 28.29.23 (#43775)
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [common](https://truecharts.org/charts/library/common)
([source](https://ghcr.io/cloudnative-pg/postgis)) | patch | `28.29.20`
-> `28.29.23` |

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://redirect.github.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi4xNy4wIiwidXBkYXRlZEluVmVyIjoiNDIuMTcuMCIsInRhcmdldEJyYW5jaCI6Im1hc3RlciIsImxhYmVscyI6WyJhcHAvendhdmVqczJtcXR0IiwiYXV0b21lcmdlIiwicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9wYXRjaCJdfQ==-->

Signed-off-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
Co-authored-by: Alfred Göppel <43101280+alfi0812@users.noreply.github.com>
2026-01-19 06:51:12 +01:00