feat: reflect netOrk v0.12.0–v0.28.0 release notes
Seventeen releases since the site was last brought up to date, checked against the changelog and the code at the v0.28.0 tag. - New feature sections: Security Assessment (TLS/SSH grades, CVE and container-image matching, exposure, deep scans; Knowledge Base licence), Vulnerability Management (triage queue, decisions with reasons, deferrals that come back, verified fixes), DHCP, Managed Services, Notifications (Signal). - Existing sections gain per-user SSH keys and session windows, multi-role devices, one device per address per site, LAN Scan, MAC-table topology, service checks, site reachability, per-site firewall profiles with diff, honoured drift auto-correct, 16 Ansible roles, 18 dashboard widgets. - Corrections: Docker status is Linux/OMV/QNAP, not Proxmox. - Roadmap: CVE tracking shipped and is gone from "Planned"; a "Next release" group lists what is on main but unreleased (CrowdSec across sites, Windows driver, single-use console tickets, reboots refused instead of faked). - NIS2: Art. 21 (2e) now describes the vulnerability handling that exists, (2i) adds attributable terminal sessions; CVE tracking left "coming". - Persona pages: two new items each, counts updated. Glossary: Kea, WinRM, LAPI. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
04c5c00280
commit
4cba6e156c
+44
-10
@@ -7,13 +7,30 @@ type Group = { label: string; items: Item[] }
|
||||
const GROUPS: Record<'en' | 'de', Group[]> = {
|
||||
en: [
|
||||
{
|
||||
label: 'Planned',
|
||||
label: 'Next release',
|
||||
items: [
|
||||
{
|
||||
title: 'CVE tracking per device',
|
||||
detail: 'Cross-reference installed packages and OS versions against NVD / OSV. Surfaces "this device has 3 unpatched CVEs (CVSS ≥ 7)" without leaving netOrk.',
|
||||
title: 'CrowdSec across sites',
|
||||
detail: 'The CrowdSec plugin grows into its own section: every LAPI instance, decisions and alerts across sites, how many sites one address reached, bans inside your own subnets counted separately, and which internet-facing hosts nobody watches yet.',
|
||||
},
|
||||
{
|
||||
title: 'Windows driver',
|
||||
detail: 'Windows hosts over WinRM: facts, interfaces, ARP, routes and services, including service control.',
|
||||
},
|
||||
{
|
||||
title: 'Single-use console tickets',
|
||||
detail: 'The browser terminal opens with a one-time ticket instead of passing the session token in the WebSocket URL.',
|
||||
nis2: true,
|
||||
},
|
||||
{
|
||||
title: 'Honest reboots',
|
||||
detail: 'A reboot request for a device whose driver cannot restart it is refused with a reason instead of being reported as done.',
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
label: 'Planned',
|
||||
items: [
|
||||
{
|
||||
title: 'Compliance dashboard',
|
||||
detail: 'Per-site Art. 21 checklist: asset coverage, patch status, security agent deployment, config drift, syslog forwarding, audit activity — aggregated into a single view.',
|
||||
@@ -37,8 +54,8 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
|
||||
nis2: true,
|
||||
},
|
||||
{
|
||||
title: 'Firewall profile management — rework',
|
||||
detail: 'Push reusable firewall rule templates to OPNsense and OpenWRT devices. The existing implementation is being re-scoped from scratch — profile types, rule sets, and the push mechanism are all under review before further work lands.',
|
||||
title: 'Firewall profile management — next steps',
|
||||
detail: 'Per-site profiles with a diff against a live OPNsense and step-by-step apply shipped in 0.12. Profile types, OpenWrt as a target, and the push mechanism beyond that are still under review.',
|
||||
},
|
||||
],
|
||||
},
|
||||
@@ -71,13 +88,30 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
|
||||
],
|
||||
de: [
|
||||
{
|
||||
label: 'Geplant',
|
||||
label: 'Nächstes Release',
|
||||
items: [
|
||||
{
|
||||
title: 'CVE-Tracking pro Gerät',
|
||||
detail: 'CVE-Abgleich mit installierten Paketen und OS-Versionen über NVD / OSV. Zeigt „Dieses Gerät hat 3 ungepatchte CVEs (CVSS ≥ 7)" direkt in netOrk an.',
|
||||
title: 'CrowdSec über alle Standorte',
|
||||
detail: 'Das CrowdSec-Plugin wird ein eigener Bereich: jede LAPI-Instanz, Entscheidungen und Alerts über alle Standorte, wie viele Standorte eine Adresse erreicht hat, Sperren im eigenen Netz getrennt gezählt, und welche vom Internet erreichbaren Hosts noch niemand überwacht.',
|
||||
},
|
||||
{
|
||||
title: 'Windows-Treiber',
|
||||
detail: 'Windows-Hosts über WinRM: Fakten, Interfaces, ARP, Routen und Dienste, inklusive Dienststeuerung.',
|
||||
},
|
||||
{
|
||||
title: 'Einmal-Tickets für die Konsole',
|
||||
detail: 'Das Browser-Terminal öffnet mit einem einmal gültigen Ticket, statt das Sitzungstoken in der WebSocket-URL mitzugeben.',
|
||||
nis2: true,
|
||||
},
|
||||
{
|
||||
title: 'Ehrliche Neustarts',
|
||||
detail: 'Eine Neustart-Anfrage für ein Gerät, dessen Treiber es nicht neu starten kann, wird mit Begründung abgelehnt, statt als erledigt gemeldet zu werden.',
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
label: 'Geplant',
|
||||
items: [
|
||||
{
|
||||
title: 'Compliance-Dashboard',
|
||||
detail: 'Art. 21-Checkliste pro Standort: Asset-Abdeckung, Patch-Status, Security-Agent-Deployment, Config-Drift, Syslog-Weiterleitung, Audit-Aktivität — zusammengefasst in einer Ansicht.',
|
||||
@@ -101,8 +135,8 @@ const GROUPS: Record<'en' | 'de', Group[]> = {
|
||||
nis2: true,
|
||||
},
|
||||
{
|
||||
title: 'Firewall-Profile — Überarbeitung',
|
||||
detail: 'Wiederverwendbare Firewall-Regel-Templates auf OPNsense- und OpenWRT-Geräte pushen. Die bestehende Implementierung wird von Grund auf neu bewertet — Profiltypen, Regelsätze und der Push-Mechanismus stehen vor der Weiterentwicklung auf dem Prüfstand.',
|
||||
title: 'Firewall-Profile — nächste Schritte',
|
||||
detail: 'Profile pro Standort mit Diff gegen eine echte OPNsense und schrittweisem Anwenden kamen mit 0.12. Profiltypen, OpenWrt als Ziel und der Push-Mechanismus darüber hinaus stehen noch auf dem Prüfstand.',
|
||||
},
|
||||
],
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user