Is your SegAudit up to date?
Enter the version you run (the app shows it in Version and updates) to see what is newer and whether any of it fixes a security issue.
Releases
| Version | Released | Kind | Notes |
|---|
Follow new releases in any feed reader: releases feed. Security advisories have their own page and feed.
Update a connected host
One command pulls the newest release on your major version, checks it and restarts. Your license stays where it is.
cd segaudit # the folder with docker-compose.yml and licence/
./segaudit-update --pullIt runs docker compose pull and docker compose up -d with the Compose file from the release, which follows tag 1. To stay on one version, set SEGAUDIT_TAG=1.0.0 in .env.
Update an air-gapped host
Download on a connected machine
Take the bundle for your jump host's CPU with its SHA-256, signature and trust root files.
Carry the four files across
Use your approved transfer process. Keep them in one folder.
Run segaudit-update
It checks the SHA-256 and CPU type, checks the signature when Cosign is installed, loads the image and restarts. First time? Extract it once with
tar -xzf <bundle> ./segaudit-update.
# on the jump host, in the folder with docker-compose.yml and licence/
./segaudit-update segaudit-1.0.0-linux-amd64.tar.gzLinux, x86-64 (Intel, AMD)
linux/amd64 offline bundle: the image, docker-compose.yml and segaudit-update.
SHA-256Signature (.sigstore.json)trusted_root.jsonSBOM (SPDX)
Linux, Arm 64-bit (Apple silicon VMs, Graviton, Ampere)
linux/arm64 offline bundle: the image, docker-compose.yml and segaudit-update.
SHA-256Signature (.sigstore.json)trusted_root.jsonSBOM (SPDX)
Fix releases and feature releases
Fix release
For example 1.4.1, 1.4.2
Security and bug fixes only. Free for every edition, whatever your license says.
Feature release
For example 1.5.0
New features. Paid features run with any license that is current on the day the release came out; everything else keeps working.
Questions
Does the app check for updates by itself?
No. SegAudit makes no network requests of its own. After 90 days on the same version it shows a quiet note with a link to this page, and nothing happens unless you click it.
Will an update reset my license?
No. The license file lives in the licence folder next to docker-compose.yml, outside the image, and segaudit-update never touches it.
Can updates install themselves?
Not by default: you choose when an update reaches the plant. On a connected host you can schedule ./segaudit-update --pull with cron or a systemd timer if you want it automatic.
How do I go back to the previous version?
Run segaudit-update with the older bundle, or set SEGAUDIT_TAG to the older version on a connected host. Every release stays downloadable for at least 10 years.
How do I check a download?
segaudit-update checks the SHA-256, and the signature too when Cosign is installed. The verification guide has the commands to run yourself.