Skip to content

Releases: ITSEC-Research/bron-vault

Release Version 1.4.0

Choose a tag to compare

@mastomii mastomii released this 18 Jun 09:13
6bfdcc0

feat: add exact email monitoring as a monitor target type

Release Version 1.3.9

Choose a tag to compare

@mastomii mastomii released this 02 Jun 03:01
19cf8c9

Summary:

  • feat: add domain monitoring API with webhook alerts and documentation

Release Version 1.3.8

Choose a tag to compare

@yokokho yokokho released this 16 Apr 01:04
c41de9e

Summary:

  • feat: add category slug validation and trigger 404 for invalid routes
  • feat: implement SSRF protection and strict content validation in image proxy and migrate to Next.js Image component
  • feat: render placeholder container when typing effect is hidden to prevent layout shift
  • feat: implement device report generation system with HTML templates and API endpoints
  • style: standardize page header icons with consistent styling and primary color accents
  • style: improve responsive layout for documentation page and sidebar container
  • style: improve table layout and add text truncation to report templates

Contributors:

YoKo Kho (@YoKoAcc)
Tomi Ashari (@mastomii)


Migration note: JWT-based cookies

Bron Vault now uses JWT-based cookies for authentication. If you are upgrading from a version prior to February 11, you must add a JWT_SECRET variable to your .env file. For example:

JWT_SECRET=super_secret_random_string_at_least_32_chars_long

Make sure the secret is at least 32 characters long. This key is used by the server to sign and verify JWTs.

Release Version 1.3.7

Choose a tag to compare

@yokokho yokokho released this 02 Apr 01:22
def8d94

Summary:

  • feat: add category editing functionality and force page reloads after category mutations
  • feat: add edit functionality for feed sources and implement forced page reloads after data mutations
  • feat: implement advanced search builder with boolean logic support for article filtering
  • feat: implement drag-and-drop reordering for feed sources and add user preference support for custom feed layouts
  • feat: add SourceIcon component to display source favicons in news feed list
  • feat: implement per-source pagination for grouped article view
  • style: adjust sidebar menu item padding and height for improved layout consistency
  • chore: update category page description text

Contributors:

YoKo Kho (@YoKoAcc)
Tomi Ashari (@mastomii)


Migration note: JWT-based cookies

Bron Vault now uses JWT-based cookies for authentication. If you are upgrading from a version prior to February 11, you must add a JWT_SECRET variable to your .env file. For example:

JWT_SECRET=super_secret_random_string_at_least_32_chars_long

Make sure the secret is at least 32 characters long. This key is used by the server to sign and verify JWTs.

Release Version 1.3.6

Choose a tag to compare

@yokokho yokokho released this 31 Mar 23:54
939ac8c

Summary:

  • feat(api): implement GET /api/feeds/articles with advanced search, pagination, and date range filtering
  • feat(api): implement complete CRUD operations for feed categories and sources at /api/feeds/categories and /api/feeds/sources
  • feat(api): add manual sync trigger via POST /api/feeds/sync and background processing utility using rss-parser
  • feat(ui): implement news feed aggregator page with dynamic category routing and interactive article previews
  • feat(ui): build centralized feed configuration interface for admin-level management of sources and categories
  • feat(ui): integrate dynamic feed categories directly into the application sidebar navigation
  • feat(db): extend database schema definition to support multi-source feed aggregation and storage
  • feat(api): implement GET /api/v1/device/:deviceId to retrieve device summary, system information, and optional credentials, software, and files
  • feat(api): implement GET /api/v1/summary to provide overall statistics (devices, credentials, files, domains, URLs)
  • feat(api): introduce pagination for credentials retrieval
  • feat(api): add date filtering and top TLDs aggregation support
  • feat(api): include country statistics with heatmap-ready aggregation data
  • refactor: update authentication routes and sidebar layout components
  • refactor: standardize global page container widths to max-w-7xl and stabilize session logout redirect mechanism
  • chore(api): add error handling and request logging for device endpoint
  • chore(api): enhance error handling and logging for summary endpoint
  • chore(api): include developer debug routes for feed data inspection and serialization testing
  • chore: update package.json and project dependencies for RSS feed parsing support

Contributors:

YoKo Kho (@YoKoAcc)
Tomi Ashari (@mastomii)


Migration note: JWT-based cookies

Bron Vault now uses JWT-based cookies for authentication. If you are upgrading from a version prior to February 11, you must add a JWT_SECRET variable to your .env file. For example:

JWT_SECRET=super_secret_random_string_at_least_32_chars_long

Make sure the secret is at least 32 characters long. This key is used by the server to sign and verify JWTs.

Release Version 1.3.5

Choose a tag to compare

@yokokho yokokho released this 26 Feb 00:06

Summary:

  • refactor(import-logs): Update log creation flow to support progress tracking during file processing.
  • feat(import-logs-ui): Implement real-time polling on Import Logs page for immediate upload status feedback.
  • feat(import-logs-ui): Add auto-refresh trigger after import process completion to sync final state.
  • fix(mysql): ensure default values for SQL query parameters in LazyPool methods

Contributors:

YoKo Kho (@YoKoAcc)
Tomi Ashari (@mastomii)


Migration note: JWT-based cookies

Bron Vault now uses JWT-based cookies for authentication. If you are upgrading from a version prior to February 11, you must add a JWT_SECRET variable to your .env file. For example:

JWT_SECRET=super_secret_random_string_at_least_32_chars_long

Make sure the secret is at least 32 characters long. This key is used by the server to sign and verify JWTs.

Release Version 1.3.4

Choose a tag to compare

@yokokho yokokho released this 23 Feb 06:36

Summary:

  • feat(upload-settings): Add apiConcurrency, tempCleanupHours, and apiMaxDurationSeconds for better upload control.
  • refactor(upload-api): Improve file handling by saving uploads to temporary path before processing.
  • refactor(upload-api): Implement concurrency control using p-limit for safer parallel API uploads.
  • chore(deps): Add p-limit dependency and update package-lock.json.
  • chore(gitignore): Exclude TypeScript build info files from version control.
  • refactor(next-config): Disable webpack build worker to reduce memory usage during build.

Contributors:

YoKo Kho (@YoKoAcc)
Tomi Ashari (@mastomii)


Migration note: JWT-based cookies

Bron Vault now uses JWT-based cookies for authentication. If you are upgrading from a version prior to February 11, you must add a JWT_SECRET variable to your .env file. For example:

JWT_SECRET=super_secret_random_string_at_least_32_chars_long

Make sure the secret is at least 32 characters long. This key is used by the server to sign and verify JWTs.

Release Version 1.3.3

Choose a tag to compare

@yokokho yokokho released this 17 Feb 11:07
2fe38d5

Summary:

  • refactor(docker): Fully migrate from docker-compose (v1) to docker compose (v2).
  • refactor(docker): Update all scripts and documentation to use Docker Compose v2 syntax.
  • refactor(docker): Improve docker-start.sh with smarter Docker detection and Ubuntu auto-install guidance.
  • refactor(docker): Simplify Dockerfile by removing UID/GID build args and host-side permission adjustments.
  • refactor(docker): Align setup-docker.sh with updated compose conventions and service naming.
  • chore: Update README.md to reflect new Docker flow and requirements.
  • refactor(audit-logs): Improve detail dialog layout and structured content rendering.
  • refactor(audit-logs): Ensure DialogContent uses full width and prevents overflow.
  • refactor(audit-logs): Render log details in code-block format for better readability and flexible data structures.

Contributors:

YoKo Kho (@YoKoAcc)
Tomi Ashari (@mastomii)


Migration note: JWT-based cookies

Bron Vault now uses JWT-based cookies for authentication. If you are upgrading from a version prior to February 11, you must add a JWT_SECRET variable to your .env file. For example:

JWT_SECRET=super_secret_random_string_at_least_32_chars_long

Make sure the secret is at least 32 characters long. This key is used by the server to sign and verify JWTs.

Release Version 1.3.2

Choose a tag to compare

@yokokho yokokho released this 12 Feb 09:12
e0404cd

Summary:

  • fix(domain-recon): Fix summary 500 by using "credentials c" so query builder conditions resolve.
  • style(search): Improve query mode toggle button styling and accessibility
  • chore: Updated README.md to include advanced search query options, domain monitoring features, S3-compatible storage details, roles for access control, and API v1 specifications.

Contributors:

Tomi Ashari (@mastomii)
YoKo Kho (@YoKoAcc)


Migration note: JWT-based cookies

Bron Vault now uses JWT-based cookies for authentication. If you are upgrading from a version prior to February 11, you must add a JWT_SECRET variable to your .env file. For example:

JWT_SECRET=super_secret_random_string_at_least_32_chars_long

Make sure the secret is at least 32 characters long. This key is used by the server to sign and verify JWTs.

Release Version v1.3.1

Choose a tag to compare

@yokokho yokokho released this 12 Feb 09:11
5055553

Summary:

  • fix(auth): Fix login session lost after redirect when using app over HTTP (e.g. Docker) by deriving cookie Secure from request.

Contributors:

Tomi Ashari (@mastomii)
YoKo Kho (@YoKoAcc)


Migration note: JWT-based cookies

Bron Vault now uses JWT-based cookies for authentication. If you are upgrading from a version prior to February 11, you must add a JWT_SECRET variable to your .env file. For example:

JWT_SECRET=super_secret_random_string_at_least_32_chars_long

Make sure the secret is at least 32 characters long. This key is used by the server to sign and verify JWTs.