You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: CHANGELOG.md
+16-9Lines changed: 16 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,23 +4,30 @@ Updater-facing software changes only — documentation, site, repository, and co
4
4
5
5
## [Unreleased]
6
6
7
-
### Added
7
+
##[0.18.0] - 2026-08-17
8
8
9
-
- Actual Budget is available in the app catalog. It is envelope budgeting on your own server: you hand out the money that is actually in your accounts across categories at the start of each month and watch what is left in each one come down as you spend, with schedules for the bills you already know about and reports built from your own history. It runs as a single service with one data volume, sets its own password the first time you open it, and connects to no bank unless you add bank-sync credentials yourself.
9
+
### Added
10
10
11
-
- Paperless-ngx is available in the app catalog. Scan or photograph letters, invoices and contracts and it reads the text so you can search for any word inside them, suggesting the sender and tags for each new document. Text recognition runs on your own server in English, Dutch, German, French, Italian or Spanish, chosen during install; its optional cloud AI and remote OCR features stay off, and its own update check is switched off because MOS handles app updates. Its privacy assessment is rated "Private by default": watched on the wire through a full session of uploading, text recognition, searching and browsing its settings, neither of its containers contacted anything outside your server.
11
+
- A home-server install now has two ways in, and the screen shown when the install finishes offers both: `http://home.mos.home`, which needs a `*.mos.home` rule in your own router or Pi-hole, and `http://home.<your-lan-ip-with-dashes>.local.myownsuite.org` — for example `home.192-168-123-45.local.myownsuite.org` — which needs nothing set up on any device. Installed apps answer under whichever you use, neither address is a setting, and dashboard tiles now open the app through the address you arrived on instead of the one that installed it. **The second address sends DNS lookups for your app subdomains to MOS-operated nameservers, which do not log queries; the first never involves MOS infrastructure.** It contains your server's LAN address, so set a DHCP reservation — both addresses need one, and if it changes, saved links and app addresses break until each app is applied again. Applying your own domain with HTTPS stops the second address being served, and cloud/VPS installs are unaffected.
12
+
- App packages can declare what each of their services needs to run — memory and CPU at rest, and at peak where a service has heavy work to do — and the Resources view shows the figures beside the existing light/medium/heavy band. Radicale and Stirling PDF declare them first; apps without figures read as before. **Compatibility:**`resources.services.<id>.requires` is an optional addition to manifest generation 1 that older releases ignore, so packages using it require this release.
13
+
-**Actual Budget**: envelope budgeting, one service and one volume. Sets its own password on first open; connects to no bank unless you add sync credentials.
14
+
-**Paperless-ngx**: searchable scanned documents, OCR on your own server in the language chosen at install (EN/NL/DE/FR/IT/ES). Cloud AI, remote OCR and its own update check are off. Rated "Private by default" — no outbound traffic observed.
12
15
13
16
### Changed
14
17
15
-
- Vaultwarden and Stirling PDF now show screens in the catalog before you install them: the vault, an entry with its two-factor code, the password generator and a shared Send for Vaultwarden; the toolbox, merging statements, redacting a payslip and reading a scan for Stirling PDF. Both ship a patch package update that carries the images and changes nothing about how either app runs.
16
-
- Every catalog package now names the full set of commercial products it stands in for instead of two or three, ranked by how widely known each one is. Suite Manager's app search matches those names, so searching "onedrive", "lastpass" or "ynab" finds the app that takes their place; screens with limited room still show only the two best-known.
17
-
- Immich's privacy assessment was redone against observed behaviour rather than documentation, using a network capture of the running package and a capture of the browser client. Its posture moves from "Privacy configured" to "External dependency". The map is enabled and, because MOS pins Immich's configuration to a file, no owner or administrator can turn it off; opening it requests map imagery from Immich's tile service, which its privacy policy says logs the requested tile, the IP address and timing. MOS accepted that trade because the map is part of what makes Immich worth running, and your photo coordinates are never sent — markers come from your own server and are drawn in your browser. The assessment now names every external host reached, corrects the version check's destination from GitHub to version.immich.cloud, and records that turning photo GPS into place names runs locally from data shipped inside the image.
18
-
- Privacy labels now answer two plain questions instead of five overlapping ones: installed the way MOS ships it, does anything leave your server, and if it does, who decided that. A new label, "Your choice", covers apps where something leaves and the app itself has a setting that stops it — MOS picks the default it thinks is right for most people and tells you where the switch is. "External dependency" is reserved for cases where nothing in the app can stop it, and now states that MOS reviewed and accepted the trade rather than leaving you a bare warning. A reviewed app can no longer be labelled "Not yet reviewed"; that is now only ever the state of an app whose review has not been done. Two labels changed as a result and no letter grade moved: Seafile is now "Private by default", because every external integration it offers is off unless you connect one; Vaultwarden is now "Your choice", because it fetches website icons for the sites you save passwords for, which tells those sites that someone at your server's address has an account there. That was previously labelled as though MOS had turned it off, which MOS had not. Vaultwarden's own Settings screen has a "Show website icons" preference that stops it. The label also now links to the full assessment, published on each app's page: every piece of evidence with its source, what the review covered and deliberately did not, the policies read, how it was produced — and the open questions it does not settle. **Compatibility:** the assessment format changed, and an older MOS cannot read it, so all eight catalog packages ship a patch update requiring this release or newer. Update MOS before updating apps; an older installation is not offered these package versions at all rather than failing partway.
19
-
- Immich package 0.5.0 updates Immich to v3.1.0. Its health check now targets the endpoint Immich actually serves, so a server whose API is failing is reported as unhealthy instead of passing on a 404. Immich's database migrations are forward-only: once the update has applied, going back to the previous Immich version is not supported. Live Photos uploaded in the background on the previous version may have missing thumbnails; running Immich's "missing" thumbnail job clears them, as does the nightly job.
18
+
- Installing on your own hardware now uses a prebuilt disk image (`.img.xz`, ~2 GB) instead of an ISO installer: the machine is installed and boot-tested in the release pipeline and you flash the finished result, so first boot downloads nothing and takes minutes instead of 15–30. **Compatibility:** the target machine must boot in UEFI mode and have a single internal disk — it names the disk it found and asks you to type `YES` rather than erasing anything on its own. Existing servers are unaffected and the ISO is no longer published.
19
+
- Servers installed from the image now show a My Own Suite login message instead of Ubuntu's. Canonical's version advertised Ubuntu Pro, printed a package-update count that contradicted the Updates screen, and fetched news from `motd.ubuntu.com` on a timer — an outbound call no owner asked for. The image still states plainly that it is built from Ubuntu and is not a Canonical product.
20
+
- Privacy labels reworked around one question: does anything leave your server, and who decided. New "Your choice" label where an in-app setting stops it; "External dependency" now means nothing can, and that MOS accepted the trade. Labels link to the full published assessment. Seafile → "Private by default"; Vaultwarden → "Your choice" (fetches website icons; Settings → "Show website icons" stops it). No grade moved. **Compatibility:** the assessment format changed, so all eight packages ship patch updates requiring this release. Update MOS before apps — older installs are not offered these versions rather than failing partway.
21
+
- Immich's privacy assessment redone from network captures: "Privacy configured" → "External dependency". The map requests tiles from Immich's tile service, which logs tile, IP and timing, and MOS pins the config so it cannot be disabled; photo coordinates are never sent. Version check goes to version.immich.cloud, not GitHub.
22
+
- Immich package 0.5.0 updates Immich to v3.1.0; its health check now targets an endpoint Immich serves. **Migrations are forward-only — no downgrade after this applies.** Live Photos uploaded in the background on the previous version may lack thumbnails until Immich's "missing" job runs.
23
+
- Catalog packages name the full set of products they replace, and app search matches them: "onedrive", "lastpass" and "ynab" find the right app.
24
+
- Vaultwarden and Stirling PDF show screenshots before install. Patch update; no runtime change.
25
+
- The app list shows each app's one-line summary instead of the opening paragraph of its full description, which had turned the catalog into a wall of text; the full description still opens with the app. Radicale, Seafile, Stirling PDF, ONLYOFFICE and Vaultwarden ship plainer summaries to match, and Stirling PDF moves from "Light" to "Medium" resources, which its declared figures now back up.
20
26
21
27
### Fixed
22
28
23
-
- Backing up to an exFAT or NTFS drive no longer fails with "EPERM: operation not permitted, chmod ...". MOS built the state snapshot on the destination drive itself, which required that drive to store Linux file permissions; external drives are normally formatted exFAT or NTFS and cannot. The snapshot is now built on the system disk and only the finished archive is written to the drive, so the permissions the drive cannot hold are preserved inside the backup and restored correctly. Any MOS installation with installed apps was affected, and the backup failed rather than producing an incomplete bundle.
29
+
- The Apps screen now reliably picks up new apps and versions. Its background catalog fetch rejected itself as "too soon" if Apps had been opened in the last 30 seconds, and never retried after a failure, so the list could sit stale for hours.
30
+
- Backing up to an exFAT or NTFS drive no longer fails with "EPERM: operation not permitted, chmod ...". The snapshot is now built on the system disk and only the finished archive written to the drive. Affected every installation with apps; the backup failed rather than producing an incomplete bundle.
0 commit comments