SegAudit
Updates

Is your SegAudit up to date?

Enter the version you run (the app shows it in Version and updates) to see what is newer and whether any of it fixes a security issue.

Releases

No public release yet. The first one will be listed here with its date, kind and security fixes.

Follow new releases in any feed reader: releases feed. Security advisories have their own page and feed.

Update a connected host

One command pulls the newest release on your major version, checks it and restarts. Your license stays where it is.

cd segaudit            # the folder with docker-compose.yml and licence/
./segaudit-update --pull

It runs docker compose pull and docker compose up -d with the Compose file from the release, which follows tag 1. To stay on one version, set SEGAUDIT_TAG=1.0.0 in .env.

Update an air-gapped host

  1. Download on a connected machine

    Take the bundle for your jump host's CPU with its SHA-256, signature and trust root files.

  2. Carry the four files across

    Use your approved transfer process. Keep them in one folder.

  3. Run segaudit-update

    It checks the SHA-256 and CPU type, checks the signature when Cosign is installed, loads the image and restarts. First time? Extract it once with tar -xzf <bundle> ./segaudit-update.

# on the jump host, in the folder with docker-compose.yml and licence/
./segaudit-update segaudit-1.0.0-linux-amd64.tar.gz
The first public release is being prepared. Its bundles, checksums and signatures appear here the moment it is published. Follow the updates feed to hear when.

Fix releases and feature releases

Fix release

For example 1.4.1, 1.4.2

Security and bug fixes only. Free for every edition, whatever your license says.

Feature release

For example 1.5.0

New features. Paid features run with any license that is current on the day the release came out; everything else keeps working.

Questions

Does the app check for updates by itself?

No. SegAudit makes no network requests of its own. After 90 days on the same version it shows a quiet note with a link to this page, and nothing happens unless you click it.

Will an update reset my license?

No. The license file lives in the licence folder next to docker-compose.yml, outside the image, and segaudit-update never touches it.

Can updates install themselves?

Not by default: you choose when an update reaches the plant. On a connected host you can schedule ./segaudit-update --pull with cron or a systemd timer if you want it automatic.

How do I go back to the previous version?

Run segaudit-update with the older bundle, or set SEGAUDIT_TAG to the older version on a connected host. Every release stays downloadable for at least 10 years.

How do I check a download?

segaudit-update checks the SHA-256, and the signature too when Cosign is installed. The verification guide has the commands to run yourself.