• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Question Is there any way to get notified about important security updates?

Azurel

Silver Pleskian
Server operating system version
AlmaLinux 9.8
Plesk version and microupdate number
18.0.80#4
Is there any way to get notified about important security updates (via e-mail)?

P.S. In my Plesk, click on "Check for updates" didn't find any new updates. I then went to "Add or Remove Components" to see the update #4 for Plesk. After the upgrade, I see the notification "Plesk Obsidian 18.0.80 Update 4 has been installed," but Plesk itself still shows "Update #3". After few minutes its refreshed to "Update #4".
 
Here’s something else the Plesk team might want to consider, if they’d like?

The home screen has a “What's New” box with some rather useless information and missing important details. I have installed version 18.0.80#4 and see:

1. A prominent link to version 18.0.80#0 at the very top. Why?
2. Why am I seeing additional older releases for 18.0.79 even though I have version 18.0.80+ installed?
3. Why doesn’t 18.0.80#4 display a label such as “IMPORTANT” or “URGENT,” since it’s a “critical security issue” update?

In the worst-case scenario, I don’t even see updates available to me in the overview because older versions are taking up the space or upates for extension I have not installed.

I’d really like to have a link here in the box that lets me set up email notifications for updates to my Plesk version and my installed extensions.

1787643261248.png
 
@Azurel , our team already sends security notifications via email (couple of days later after the release) to all Plesk partners and customer (licenses purchased directly from plesk.com).
The security team is also working on an upcoming WebPros Trust Center, which will provide a public vulnerability catalog with options to subscribe for updates via email or RSS.

The "What's New' widget highlights the current major release and lists the latest updates in chronological orders as they are show in the changelog.
 
The security team is also working on an upcoming WebPros Trust Center, which will provide a public vulnerability catalog with options to subscribe for updates via email or RSS.
That's great. Because my license is from Hetzner and never get a email for this kind of issues :)
 
Is there any way to get notified about important security updates (via e-mail)?
~~~
Not exactly what you want, but this may / may not be something you could consider:

a) Setup a daily check process for the Plesk Changelog URL: https://docs.plesk.com/release-notes/obsidian/change-log/ by way of either a hosted service e.g. create an account at Website change detection, monitoring, alerts, notifications, restock alerts | changedetection.io to check the aforementioned url, set the watch for 24 hours, add any other desired customization eg. word or category specifics. OR make a a self-hosted version. This would be using Docker, if you already maintain an always-on Ubuntu/Plesk server (don't know if that's applicable with AlmaLinux, but pretty sure that you will) Then, as part of the config of either, you can ensure that you receive your daily notifications of any Plesk changes. If you want to set this up for OS changes/updates as well, you would need two, separate configurations within either setup, for obvious reasons.

b) Switch from auto to manual updates for Plesk. This, together with the proceeding, would give you more control and better options for timing, plus, you can delay adding the latest Plesk updates as you see fit. Some prefer this, as they can see IF there are any issues with the latest Plesk updates BEFORE invoking them.

FWIW We have used b) for a very long time now, but we manually check the Plesk Changelog ourselves at set intervals, as we don't have a desire for lots of system emails and, we get Plesk GUI - Plesk Update prompts anyway, as well as the default Plesk generated update emails, which cover 'some' of the OS updates.
 
I just stumbled across a hidden “feature” by accident. ;)
Your approach of scraping the change-log website daily might not be necessary after all. Check out this update: https://docs.plesk.com/release-notes/obsidian/change-log/#plesk-18060
You’ll find this entry there:
The latest 30 entries from the Plesk Obsidian changelog are now available in an RSS feed. You can find the feed here.
And it links directly to a RSS feed:
https://docs.plesk.com/release-notes/obsidian/change-log/rss.xml
Which makes me wonder: why isn’t the RSS feed linked somewhere prominently at the top of the changelog page?
 
Back
Top