# netbox-proxbox v0.0.29 v0.0.29 | Field |Value | | --- | --- | | Canonical URL | https://emersonfelipesp.com/netbox-proxbox/releases/v0.0.29 | | GitHub URL | https://github.com/emersonfelipesp/netbox-proxbox/releases/tag/v0.0.29 | | Tag | v0.0.29 | | State | latest | | Author | emersonfelipesp | | Created | 2026-10-05 12:49 UTC | | Published | 2026-10-05 12:54 UTC | | Target | main | | Synced | 2026-10-05 13:36 UTC | | Assets | 0 | ## Release notes ## netbox-proxbox 0.0.29 — security hardening Supports NetBox 4.5.8 through 4.7.0. Pairs with proxbox-api 0.0.23.post3, proxmox-sdk 0.0.15, and netbox-sdk 0.0.13. ### Security - **Sensitive data:** credential export, SSH credential secret reads, and the settings runtime key require an active superuser or an explicit per-user sensitive-data grant. Change-log snapshots of credential-bearing objects are redacted. - **Connection-target approval:** credentials are sent only to a Proxmox or NetBox endpoint whose exact connection target was approved; editing the target clears the approval. - **Scoped reads and actions:** plugin settings reads require view permission; HA data covers only endpoints the caller may view; HA arm/disarm requires the grantable `run_proxmox_action` action, skips endpoints with writes disabled, and reports per-cluster backend errors as failures. - **WebSocket sync:** the server-side sync route no longer starts work on GET; syncs require an authorized, CSRF-protected POST. - **Input validation:** Proxmox node, storage, guest type, VM ID, and firewall identifiers are validated before they reach backend request paths. - **Secure defaults:** new endpoints default to HTTPS and TLS verification, the process-wide certificate bundle override is removed, and new encryption keys must be canonical Fernet keys. System checks `netbox_proxbox.W100`–`W105` report insecure existing configuration. - **Dependencies:** raised security floors for Django, oauthlib, PyJWT, social-auth-core, urllib3, and virtualenv. ### Fixes - The Proxbox home page and the NetBox endpoint list no longer fail with a server error on NetBox 4.7. - Virtual-machine synchronization no longer stops with a duplicate node-device claim when paired with proxbox-api 0.0.23.post3. - Cluster virtual-machine bulk deletion is limited to the active cluster and reports missing or mismatched records. ### Upgrade notes - Apply the single migration `0104_security_hardening`. Existing endpoints keep their stored transport settings. - Approve each endpoint's connection target before synchronization resumes. - Grant `run_proxmox_action` to operators who use HA arm/disarm. - Automation that creates plain-HTTP backend endpoints must send `use_https: false`. - Rotate legacy raw encryption keys (`netbox_proxbox.W104`). ### Known limitation Node device identity is not yet scoped by Proxmox endpoint. If two Proxmox endpoints use the same cluster name and node name, give them distinct names until a later release adds endpoint scoping. ### Version note Version 0.0.28 is not used: its only published candidate predates this release's schema change, and each release ships exactly one migration. Full notes: [docs/release-notes/version-0.0.29.md](https://github.com/emersonfelipesp/netbox-proxbox/blob/main/docs/release-notes/version-0.0.29.md) ## Assets No binary assets attached. Source archives: | Format |URL | | --- | --- | | zip | https://api.github.com/repos/emersonfelipesp/netbox-proxbox/zipball/v0.0.29 | | tar.gz | https://api.github.com/repos/emersonfelipesp/netbox-proxbox/tarball/v0.0.29 |