]> ### 2026.09.25 - Replace the opaque inline encoded tarball with a public, checksummed Slackware .txz release asset for Community Applications reviewability. - Keep install/update lifecycle commands readable in the .plg and install package files with upgradepkg --install-new. - Package only SecretGuard-owned files, without archive entries for stock parent directories. - Document that the always-on watcher stops Vault-protected containers after reboot until the Vault is unlocked. ### 2026.09.18.6 - Add generic adoption of eligible legacy plain env files without rewriting secrets, templates or Docker settings. - Store only container, env path, variable names and adoption state under the SecretGuard plugin configuration. - Keep rollback unavailable for adopted env files that do not contain original XML metadata. ### 2026.09.18.5 - Validate the public Unraid plugin update channel from 2026.09.18.4. - Version and changelog only; no runtime, UI or security behavior changed. ### 2026.09.18.4 - Enable Unraid plugin update checks through the public GitHub main-branch manifest. - pluginURL: https://raw.githubusercontent.com/mr1beast/unraid-secretguard/main/unraid-secretguard.plg - No SecretGuard migration, Vault, rollback, storage, Docker recreation or UI behavior changed. ### 2026.09.18.3 - Make Overview the default landing tab. - Move Protection overview and Docker template audit onto the Overview tab. - Group Secret storage, Dedicated SecretGuard share and Encrypted Vault together on one Settings tab. - UI-only change; SecretGuard backend behavior is unchanged. ### 2026.09.18.1 - Split Secret storage, Dedicated SecretGuard share and Encrypted Vault into separate tabs. - Keep Protection overview and Docker template audit visible below the tabbed settings area. - Remember the selected settings tab in the browser. - UI-only change; no migration, Vault, storage, rollback or container recreation logic changed. ### 2026.09.18 - Collapse Docker audit containers by default using an expandable accordion layout. - Show per-container variable count and HIGH/MEDIUM finding summary in the collapsed row. - Keep the existing migration form and variable table unchanged inside each expanded container. - UI-only change; no migration, Vault, storage, rollback or container recreation logic changed. ### 2026.09.13.6 - Add optional one-click creation of a dedicated Unraid share named secretguard. - Pin the share to the selected physical disk/pool and disable SMB/NFS export. - SecretGuard uses the direct physical path instead of /mnt/user/secretguard. - Refuse to overwrite an existing non-SecretGuard share or non-empty directory. ### 2026.09.13.5 - Discover mounted persistent Unraid storage instead of assuming a cache pool exists. - Always show cache as the conventional option; mark it NOT MOUNTED / NOT PERSISTENT when absent. - Prefer mounted encrypted storage and block Plain env migration on rootfs/tmpfs/RAM or unmounted pool paths. - Add safe Delete / Reset Vault. - Improve Plugins-page title and description. ### 0.5.0 - Harden Vault lock/unlock and reboot lifecycle. - Add staged and verified master-password change. - Add unlock rate limiting, logging and notifications. - Wrong passwords never automatically delete Vault data. ### 0.4.0 - First GitHub-ready public beta. - Scan installed Docker templates and migrate likely credentials to managed env files or encrypted Vault storage. - Add automatic recreation, protection overview and variable-level rollback. https://github.com/mr1beast/unraid-secretguard/releases/download/v2026.09.25/unraid-secretguard-2026.09.25-noarch-1.txz a8e9db8c6ad81100e1780dfaed618a3912182df2c4a085a70d080bf18f223648 /dev/null || true /usr/local/emhttp/plugins/unraid-secretguard/scripts/restart-watcher.sh >/dev/null 2>&1 || true if [ -f /boot/config/plugins/unraid-secretguard/vault.json ]; then /usr/local/emhttp/webGui/scripts/notify -e "Unraid SecretGuard" -s "SecretGuard vault locked" -d "Encrypted Vault is locked after plugin install/reboot. Vault-protected containers are stopped by SecretGuard until you unlock the Vault in Settings > User Utilities > Unraid SecretGuard." -i warning >/dev/null 2>&1 || true fi echo "Unraid SecretGuard installed. Open Settings -> User Utilities -> Unraid SecretGuard." ]]> /dev/null || true; fi rm -rf /run/unraid-secretguard for pkg in /var/log/packages/unraid-secretguard-*; do [ -f "$pkg" ] || continue removepkg "$(basename "$pkg")" >/dev/null 2>&1 || true done rm -rf /usr/local/emhttp/plugins/unraid-secretguard # Preserve persistent settings/vault metadata; encrypted/plain secret files live in the user-selected secret directory. echo "Unraid SecretGuard removed. Persistent settings and vault metadata were preserved in /boot/config/plugins/unraid-secretguard." ]]>