601
[ ~/netbox-proxbox/releases/v0.0.29 ]tty0

emerson@netdevops:~/netbox-proxbox$ gh release view v0.0.29 --repo emersonfelipesp/netbox-proxbox

back to releases / back to project

v0.0.29

[open on GitHub]
tag=v0.0.29state=latestpublished=2026-10-05synced=2026-10-05 13:36 UTC
author
emersonfelipesp
created
2026-10-05 12:49 UTC
target
main
downloads
0

emerson@netdevops:~/netbox-proxbox$ cat RELEASE_NOTES.md

netbox-proxbox 0.0.29 — security hardening

Supports NetBox 4.5.8 through 4.7.0. Pairs with proxbox-api 0.0.23.post3, proxmox-sdk 0.0.15, and netbox-sdk 0.0.13.

Security

  • Sensitive data: credential export, SSH credential secret reads, and the settings runtime key require an active superuser or an explicit per-user sensitive-data grant. Change-log snapshots of credential-bearing objects are redacted.
  • Connection-target approval: credentials are sent only to a Proxmox or NetBox endpoint whose exact connection target was approved; editing the target clears the approval.
  • Scoped reads and actions: plugin settings reads require view permission; HA data covers only endpoints the caller may view; HA arm/disarm requires the grantable run_proxmox_action action, skips endpoints with writes disabled, and reports per-cluster backend errors as failures.
  • WebSocket sync: the server-side sync route no longer starts work on GET; syncs require an authorized, CSRF-protected POST.
  • Input validation: Proxmox node, storage, guest type, VM ID, and firewall identifiers are validated before they reach backend request paths.
  • Secure defaults: new endpoints default to HTTPS and TLS verification, the process-wide certificate bundle override is removed, and new encryption keys must be canonical Fernet keys. System checks netbox_proxbox.W100–W105 report insecure existing configuration.
  • Dependencies: raised security floors for Django, oauthlib, PyJWT, social-auth-core, urllib3, and virtualenv.

Fixes

  • The Proxbox home page and the NetBox endpoint list no longer fail with a server error on NetBox 4.7.
  • Virtual-machine synchronization no longer stops with a duplicate node-device claim when paired with proxbox-api 0.0.23.post3.
  • Cluster virtual-machine bulk deletion is limited to the active cluster and reports missing or mismatched records.

Upgrade notes

  • Apply the single migration 0104_security_hardening. Existing endpoints keep their stored transport settings.
  • Approve each endpoint's connection target before synchronization resumes.
  • Grant run_proxmox_action to operators who use HA arm/disarm.
  • Automation that creates plain-HTTP backend endpoints must send use_https: false.
  • Rotate legacy raw encryption keys (netbox_proxbox.W104).

Known limitation

Node device identity is not yet scoped by Proxmox endpoint. If two Proxmox endpoints use the same cluster name and node name, give them distinct names until a later release adds endpoint scoping.

Version note

Version 0.0.28 is not used: its only published candidate predates this release's schema change, and each release ships exactly one migration.

Full notes: docs/release-notes/version-0.0.29.md

emerson@netdevops:~/netbox-proxbox$ gh release download --pattern '*'

assets

no binary assets attached

source code