Compare commits

...
8 Commits
Author SHA1 Message Date
community-scripts-pr-app[bot]GitHubgithub-actions[bot] <github-actions[bot]@users.noreply.github.com>
9cc1a739a5 Update CHANGELOG.md (#16108)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-28 08:12:01 +00:00
0ce1cea6cd UmlautAdaptarr: use the Debian 13 Microsoft repo with its 2025 signing key (#16077)
* UmlautAdaptarr: use the Debian 13 Microsoft repo with its 2025 signing key

The container is Debian 13 (var_version 13) but the script configures the
Microsoft debian/12 prod repo with suite bookworm.

The move to debian/13 was reverted in #8392 because apt reported "OpenPGP
signature verification failed" (#8385), diagnosed at the time as Microsoft
not having populated the trixie repo. The actual cause was the signing key:
debian/13/prod is signed by EE4D7792F748182B (microsoft-2025.asc), while the
script kept microsoft.asc (EB3E94ADBE1229CF). The suite and URL were changed
but the key was not.

The trixie repo carries the required packages at current patch level
(dotnet-sdk-8.0 8.0.423-1, aspnetcore-runtime-8.0 8.0.29-1).

This makes the call identical to the six other scripts already on the
Debian 13 Microsoft repo (technitiumdns, igotify, mail-archiver, rdtclient,
fileflows, immichframe).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* UmlautAdaptarr: migrate existing containers to the Debian 13 repo on update

Per review feedback: the install-side fix only helps new containers.
Existing ones keep the Debian 12 repo indefinitely, because update_script
only fetches a GitHub release and never touches apt.

Repoints them when the stale Debian 12 repo is detected, mirroring the
conditional setup_deb822_repo calls in ct/technitiumdns.sh and
ct/fileflows.sh. The guard makes this a no-op once migrated.

setup_deb822_repo's microsoft* globs also clear the pre-#9839
microsoft-prod.sources layout; its key lived in /usr/share/keyrings,
which cleanup_old_repo_files does not cover, so it is removed explicitly
as ct/technitiumdns.sh does.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Tim Moore <tim.moore@ingenuity.com.au>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-07-28 18:11:29 +10:00
community-scripts-pr-app[bot]GitHubgithub-actions[bot] <github-actions[bot]@users.noreply.github.com>
e7eff1cf81 Update CHANGELOG.md (#16107)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-28 08:10:45 +00:00
Tim MooreandGitHub 03edfcef85 fix(bazarr): store data in /var/lib/bazarr instead of inside /opt/bazarr (#16098)
* fix(bazarr): store data in /var/lib/bazarr instead of inside /opt/bazarr

The installer creates /var/lib/bazarr and update_script() uses it as the
"is Bazarr installed" guard, but nothing pointed Bazarr at it. Bazarr
defaults its data directory to <install dir>/data, resolved from its own
source file rather than WorkingDirectory, so a stock container kept
config/ db/ backup/ cache/ log/ restore/ in /opt/bazarr/data - the
directory fetch_and_deploy_gh_release redeploys over - while
/var/lib/bazarr stayed empty.

Pass -c /var/lib/bazarr in the unit, matching the -data= flag the other
*arr scripts use. bazarr.py re-execs its child with sys.argv[1:], so the
flag survives the restart Bazarr performs while loading its config.

update_script() gains a one-time migration for existing installs. It runs
outside the release check so containers already on the latest version are
migrated too, is skipped when the unit already names a data directory,
refuses (before stopping the service) when both locations hold data, and
copies before removing so a failed migration leaves the original database
in place.

Fixes #16097

* fix(bazarr): drop explanatory comments per review
2026-07-28 18:10:12 +10:00
community-scripts-pr-app[bot]GitHubgithub-actions[bot] <github-actions[bot]@users.noreply.github.com>
bc488e467c Update CHANGELOG.md (#16106)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-28 08:09:09 +00:00
CanbiZ (MickLesk)andGitHub 303bb672e6 Bump GitHub Actions across workflows (#16091)
* Bump GitHub Actions across workflows

Update workflow dependencies to newer major versions in repository automation files. This upgrades `actions/checkout` to v7, `actions/github-script` to v9, `actions/create-github-app-token` to v3, and GitHub Pages actions (`upload-pages-artifact` and `deploy-pages`) to v5 to keep CI/CD and maintenance workflows current.

* add dependabot for gh actions
2026-07-28 10:08:38 +02:00
community-scripts-pr-app[bot]GitHubgithub-actions[bot] <github-actions[bot]@users.noreply.github.com>
69854a4f74 Update CHANGELOG.md (#16103)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-07-28 07:40:00 +00:00
Tim MooreandGitHub dd74eef5f6 Cloudflare-DDNS: store API token in a 600 env file and build the binary at install time (#16100) 2026-07-28 09:39:30 +02:00
26 changed files with 166 additions and 49 deletions
+17
View File
@@ -0,0 +1,17 @@
# Keeps the GitHub Actions referenced in .github/workflows up to date.
# https://docs.github.com/code-security/dependabot/working-with-dependabot/dependabot-options-reference
version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "weekly"
day: "monday"
open-pull-requests-limit: 5
labels:
- "dependencies"
# One PR per week for all action bumps instead of one PR per action.
groups:
github-actions:
patterns:
- "*"
+3 -3
View File
@@ -20,21 +20,21 @@ jobs:
steps:
- name: Generate a token
id: generate-token
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ vars.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Generate a token for PR approval and merge
id: generate-token-merge
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.APP_ID_APPROVE_AND_MERGE }}
private-key: ${{ secrets.APP_KEY_APPROVE_AND_MERGE }}
# Step 1: Checkout repository
- name: Checkout repository
uses: actions/checkout@v2
uses: actions/checkout@v7
# Step 2: Disable file mode changes detection
- name: Disable file mode changes
+2 -2
View File
@@ -16,13 +16,13 @@ jobs:
CONFIG_PATH: .github/autolabeler-config.json
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Install dependencies
run: npm install minimatch
- name: Label PR based on file changes, title, and PR template
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const fs = require('fs').promises;
+4 -4
View File
@@ -19,25 +19,25 @@ jobs:
steps:
- name: Generate a token
id: generate-token
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ vars.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Generate a token for PR approval and merge
id: generate-token-merge
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.APP_ID_APPROVE_AND_MERGE }}
private-key: ${{ secrets.APP_KEY_APPROVE_AND_MERGE }}
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Archive old changelog entries
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const fs = require('fs').promises;
+5 -5
View File
@@ -19,20 +19,20 @@ jobs:
steps:
- name: Generate a token
id: generate-token
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ vars.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Generate a token for PR approval and merge
id: generate-token-merge
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.APP_ID_APPROVE_AND_MERGE }}
private-key: ${{ secrets.APP_KEY_APPROVE_AND_MERGE }}
- name: Checkout code
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
@@ -53,7 +53,7 @@ jobs:
- name: Get categorized pull requests
id: get-categorized-prs
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
async function main() {
@@ -213,7 +213,7 @@ jobs:
return await main();
- name: Update CHANGELOG.md
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const fs = require('fs').promises;
+1 -1
View File
@@ -17,7 +17,7 @@ jobs:
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
ref: main
+1 -1
View File
@@ -15,7 +15,7 @@ jobs:
contents: read
steps:
- name: Close PR if it does not follow the PR template
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const pr = context.payload.pull_request;
+1 -1
View File
@@ -14,7 +14,7 @@ jobs:
contents: read
steps:
- name: Close PR if unauthorized new script submission
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const pr = context.payload.pull_request;
+1 -1
View File
@@ -9,7 +9,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Auto-close if tteck script detected
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const issue = context.payload.issue;
+1 -1
View File
@@ -16,7 +16,7 @@ jobs:
steps:
- name: Checkout target repo (merge commit)
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
repository: community-scripts/ProxmoxVE
ref: ${{ github.event.pull_request.merge_commit_sha }}
+1 -1
View File
@@ -19,7 +19,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Delete branches of merged PRs
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const owner = context.repo.owner;
+1 -1
View File
@@ -17,7 +17,7 @@ jobs:
runs-on: self-hosted
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
+1 -1
View File
@@ -13,7 +13,7 @@ jobs:
contents: write
steps:
- name: Checkout repository
uses: actions/checkout@v4
uses: actions/checkout@v7
- name: Clean CHANGELOG (remove HTML header)
run: sed -n '/^## /,$p' CHANGELOG.md > changelog_cleaned.md
+1 -1
View File
@@ -14,7 +14,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- name: Lock old issues and PRs
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const daysBeforeLock = 7;
+1 -1
View File
@@ -26,7 +26,7 @@ jobs:
steps:
- name: Mint GitHub App token (bot identity)
id: app-token
uses: actions/create-github-app-token@v1
uses: actions/create-github-app-token@v3
with:
app-id: ${{ secrets.PB_BOT_APP_ID }}
private-key: ${{ secrets.PB_BOT_APP_PRIVATE_KEY }}
+1 -1
View File
@@ -12,7 +12,7 @@ jobs:
runs-on: self-hosted
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
+1 -1
View File
@@ -16,7 +16,7 @@ jobs:
contents: read
steps:
- name: Handle stale PRs
uses: actions/github-script@v7
uses: actions/github-script@v9
with:
script: |
const now = new Date();
+3 -3
View File
@@ -13,7 +13,7 @@ jobs:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7
- name: Create redirect page
run: |
@@ -33,9 +33,9 @@ jobs:
</html>
EOF
- uses: actions/upload-pages-artifact@v3
- uses: actions/upload-pages-artifact@v5
with:
path: site
- name: Deploy
uses: actions/deploy-pages@v4
uses: actions/deploy-pages@v5
+1 -1
View File
@@ -16,7 +16,7 @@ jobs:
runs-on: self-hosted
steps:
- name: Checkout Repository
uses: actions/checkout@v4
uses: actions/checkout@v7
with:
fetch-depth: 0
+14
View File
@@ -508,6 +508,20 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-07-28
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- UmlautAdaptarr: use the Debian 13 Microsoft repo with its 2025 signing key [@angusmaul](https://github.com/angusmaul) ([#16077](https://github.com/community-scripts/ProxmoxVE/pull/16077))
- fix(bazarr): store data in /var/lib/bazarr instead of inside /opt/bazarr [@angusmaul](https://github.com/angusmaul) ([#16098](https://github.com/community-scripts/ProxmoxVE/pull/16098))
- Cloudflare-DDNS: store API token in a 600 env file and build the binary at install time [@angusmaul](https://github.com/angusmaul) ([#16100](https://github.com/community-scripts/ProxmoxVE/pull/16100))
### 📂 Github
- Bump GitHub Actions across workflows [@MickLesk](https://github.com/MickLesk) ([#16091](https://github.com/community-scripts/ProxmoxVE/pull/16091))
## 2026-07-27
### 🆕 New Scripts
+25
View File
@@ -28,6 +28,31 @@ function update_script() {
msg_error "No ${APP} Installation Found!"
exit
fi
if ! grep -qE -- "bazarr\.py.*[[:space:]](-c|--config)([[:space:]]|=)" /etc/systemd/system/bazarr.service 2>/dev/null; then
if [[ -d /opt/bazarr/data && ! -L /opt/bazarr/data && -n "$(ls -A /var/lib/bazarr/ 2>/dev/null)" ]]; then
msg_error "/opt/bazarr/data and /var/lib/bazarr both contain data - refusing to merge them. Keep the copy you want in /var/lib/bazarr, remove /opt/bazarr/data, then run the update again."
exit 1
fi
msg_info "Moving Bazarr data to /var/lib/bazarr"
systemctl stop bazarr
if [[ -L /opt/bazarr/data ]]; then
rm -f /opt/bazarr/data
elif [[ -d /opt/bazarr/data ]]; then
if ! cp -a /opt/bazarr/data/. /var/lib/bazarr/; then
systemctl start bazarr
msg_error "Could not copy /opt/bazarr/data to /var/lib/bazarr - nothing was removed."
exit 1
fi
rm -rf /opt/bazarr/data
fi
sed -i -E "s|^(ExecStart=.*bazarr\.py.*)$|\1 -c /var/lib/bazarr|" /etc/systemd/system/bazarr.service
systemctl daemon-reload
systemctl start bazarr
msg_ok "Moved Bazarr data to /var/lib/bazarr"
fi
if check_for_gh_release "bazarr" "morpheus65535/bazarr"; then
msg_info "Stopping Service"
systemctl stop bazarr
+27 -3
View File
@@ -11,7 +11,7 @@ var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-1024}"
var_disk="${var_disk:-3}"
var_os="${var_os:-debian}"
var_version="${var_version:-12}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
@@ -24,11 +24,35 @@ function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /etc/systemd/system/cloudflare-ddns.service ]]; then
if [[ ! -f /usr/local/bin/ddns ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
msg_error "There is no update function for ${APP}."
if check_for_gh_release "cloudflare-ddns" "favonia/cloudflare-ddns"; then
msg_info "Stopping Service"
systemctl stop cloudflare-ddns
msg_ok "Stopped Service"
setup_go
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "cloudflare-ddns" "favonia/cloudflare-ddns" "tarball"
msg_info "Updating ${APP}"
cd /opt/cloudflare-ddns
export CGO_ENABLED=0 GOOS=linux
$STD go build -trimpath -ldflags="-s -w" -o /usr/local/bin/ddns ./cmd/ddns
msg_ok "Updated ${APP}"
msg_info "Removing Build Dependencies"
rm -rf /usr/local/go /usr/local/bin/go /usr/local/bin/gofmt /root/go /root/.cache/go-build /opt/cloudflare-ddns
msg_ok "Removed Build Dependencies"
msg_info "Starting Service"
systemctl start cloudflare-ddns
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
+12
View File
@@ -29,6 +29,18 @@ function update_script() {
exit
fi
if grep -qs "packages.microsoft.com/debian/12" /etc/apt/sources.list.d/microsoft*.sources; then
msg_info "Migrating Microsoft Repository to Debian 13"
setup_deb822_repo \
"microsoft" \
"https://packages.microsoft.com/keys/microsoft-2025.asc" \
"https://packages.microsoft.com/debian/13/prod/" \
"trixie" \
"main"
rm -f /usr/share/keyrings/microsoft-prod.gpg
msg_ok "Migrated Microsoft Repository to Debian 13"
fi
if check_for_gh_release "UmlautAdaptarr" "PCJones/Umlautadaptarr"; then
msg_info "Stopping Service"
systemctl stop umlautadaptarr
+1 -1
View File
@@ -36,7 +36,7 @@ UMask=0002
Restart=on-failure
RestartSec=5
Type=simple
ExecStart=/opt/bazarr/venv/bin/python3 /opt/bazarr/bazarr.py
ExecStart=/opt/bazarr/venv/bin/python3 /opt/bazarr/bazarr.py -c /var/lib/bazarr
KillSignal=SIGINT
TimeoutStopSec=20
SyslogIdentifier=bazarr
+37 -12
View File
@@ -13,8 +13,6 @@ setting_up_container
network_check
update_os
setup_go
var_cf_api_token="default"
read -rp "${TAB3}Enter the Cloudflare API token: " var_cf_api_token
@@ -53,23 +51,50 @@ while true; do
done
msg_ok "Configured Application"
setup_go
fetch_and_deploy_gh_release "cloudflare-ddns" "favonia/cloudflare-ddns" "tarball"
msg_info "Building ${APPLICATION}"
cd /opt/cloudflare-ddns
export CGO_ENABLED=0 GOOS=linux
$STD go build -trimpath -ldflags="-s -w" -o /usr/local/bin/ddns ./cmd/ddns
msg_ok "Built ${APPLICATION}"
# The binary is statically linked (CGO_ENABLED=0), so Go is only a build-time
# dependency. Removing it keeps the container small; update_script reinstalls it
# via setup_go when a rebuild is needed.
msg_info "Removing Build Dependencies"
rm -rf /usr/local/go /usr/local/bin/go /usr/local/bin/gofmt /root/go /root/.cache/go-build /opt/cloudflare-ddns
msg_ok "Removed Build Dependencies"
msg_info "Setting up service"
mkdir -p /root/go
useradd --system --no-create-home --shell /usr/sbin/nologin cloudflare-ddns 2>/dev/null || true
cat <<EOF >/etc/cloudflare-ddns.env
CLOUDFLARE_API_TOKEN=${var_cf_api_token}
DOMAINS=${var_cf_domains}
PROXIED=${var_cf_proxied}
IP6_PROVIDER=${var_cf_ip6_provider}
EOF
chown root:root /etc/cloudflare-ddns.env
chmod 600 /etc/cloudflare-ddns.env
cat <<EOF >/etc/systemd/system/cloudflare-ddns.service
[Unit]
Description=Cloudflare DDNS Service (Go run)
After=network.target
Description=Cloudflare DDNS Service
After=network-online.target
Wants=network-online.target
[Service]
Environment="CLOUDFLARE_API_TOKEN=${var_cf_api_token}"
Environment="DOMAINS=${var_cf_domains}"
Environment="PROXIED=${var_cf_proxied}"
Environment="IP6_PROVIDER=${var_cf_ip6_provider}"
Environment="GOPATH=/root/go"
Environment="GOCACHE=/tmp/go-build"
ExecStart=/usr/local/bin/go run github.com/favonia/cloudflare-ddns/cmd/ddns@latest
Type=simple
User=cloudflare-ddns
Group=cloudflare-ddns
EnvironmentFile=/etc/cloudflare-ddns.env
ExecStart=/usr/local/bin/ddns
Restart=always
RestartSec=300
NoNewPrivileges=true
ProtectSystem=strict
ProtectHome=true
PrivateTmp=true
[Install]
WantedBy=multi-user.target
+3 -3
View File
@@ -16,9 +16,9 @@ update_os
msg_info "Installing Dependencies"
setup_deb822_repo \
"microsoft" \
"https://packages.microsoft.com/keys/microsoft.asc" \
"https://packages.microsoft.com/debian/12/prod/" \
"bookworm" \
"https://packages.microsoft.com/keys/microsoft-2025.asc" \
"https://packages.microsoft.com/debian/13/prod/" \
"trixie" \
"main"
$STD apt install -y \
dotnet-sdk-8.0 \