This week in SparkBox: Sep 13 – Sep 19, 2026
Published Saturday, Sep 19, 2026
Every Monday we list what changed on every SparkBox in the last seven days, in plain language, with nothing left out. This week: 39 releases (1.6.686 to 1.6.725), 118 improvements, and 1 incident we owe you an explanation for. If your box is up to date, you already have all of it; if not, run sudo sparkbox update.
What broke, and what we did about it
Jellyfin sign-in broken after the last update? Update to 1.6.723
SparkBox 1.6.720 to 1.6.722 put Jellyfin back on version 10 while many boxes were already on 12, and a Jellyfin library that has been upgraded to 12 cannot be opened by 10 (sign-in fails with a database error). 1.6.723 restores Jellyfin 12.1. Run the update now; your library, users and settings are untouched. Do not delete or reset Jellyfin data.
Incidents get a banner on every affected dashboard the moment we know, and the fix is always an update away. We would rather tell you than have you find out.
What shipped
1.6.725 — Restarting or updating a single app can no longer downgrade it
- Yesterday's protection against an update reopening your data with an older app now also covers restarting or updating one app on its own (for example the Media Center from the dashboard, or with sparkbox restart media). If a release ever pins an older version than the one running on your box, that app is left running untouched and you are told why, instead of its database being opened by the older version.
- Tom AI now explains in plain language what three more earlier releases changed for you: the one that kept Portainer and the Minecraft panel working after a reset or a reboot, the one that made the VPN panel load on boxes set up from a second user account, and the one that let the Windows installer finish again.
1.6.724 — An update can no longer downgrade an app you are running
- sparkbox update now refuses to recreate a running app with an older image, exactly as sparkbox up already did. If a release ever pins an older version than the one on your box, the update leaves that app running untouched and tells you, instead of reopening its data with an older version. This is the check that would have stopped yesterday's Jellyfin sign-in failure.
- Support now raises an immediate alert to the team when a forum post or ticket says something broke or nothing is working, so a fix starts within minutes instead of waiting for the next scheduled pass.
1.6.723 — Jellyfin is back on 12.1 — fixes sign-in failing with a database error after the last update
- If Jellyfin stopped letting you sign in after updating to 1.6.720, 1.6.721 or 1.6.722, with an error like "SQLite Error 1: no such column: p.Permission_Permissions_Guid", this update fixes it. Those releases pinned Jellyfin back to 10.11.11 while your box had already moved to 12.1, and a Jellyfin database that has been upgraded to 12 cannot be opened by 10. This release puts Jellyfin 12.1 back; run the update and Jellyfin opens your existing library and users again. Do not delete or reset Jellyfin's data.
- The refuse-to-downgrade check inside sparkbox is being tightened so an older pin can never recreate a running app again, and the release rule that allowed this rollback has been withdrawn.
1.6.722 — An unhealthy database now says why, and Tom AI explains three more releases
- A database that goes unhealthy now tells you why. Nextcloud's and WordPress's databases check themselves by logging in the way the app does, but the check threw away its own error message, so the app sat there unable to reach its database while everything SparkBox could show you was a bare "unhealthy" with no reason. The reason — usually that the saved password and the database no longer agree — is now recorded where the dashboard, the doctor and support can all read it. Nothing about your password is written down.
- Tom AI now explains in plain language what three more earlier releases changed for you, instead of saying the details were not recorded: the one that fixed Windows installs picking up the wrong copy of Docker and leaving apps unable to look up internet addresses, the one that gathered up a batch of fixes so several unrelated annoyances went away together, and the one that made installing SparkBox as an app on a computer read as something for computers.
1.6.721 — Logging in after an update, and the Portainer password file
- You can sign in again right after a dashboard-only update. That quicker update ran as the system user and left the folder holding your sign-in sessions owned by it, so the dashboard could no longer write there and login failed with a permissions error on a box that had been working a minute earlier. The update now hands that folder back before it finishes.
- The media pipeline widget stops reporting a missing Portainer secret. If the saved admin password file was left empty — an update or a restore interrupted part way — SparkBox treated it as fine and started Portainer with a blank password, which Portainer refuses, so the error came back every time. An empty file is now filled in from the password SparkBox already recorded for you, before Portainer starts.
- The rule that keeps the dashboard's own pages from being compressed — the cause of the blank white dashboard fixed in v1.6.71 — is now covered by a test, so it cannot quietly come back.
1.6.720 — Jellyfin stays on the tested version, and Tom AI explains three more releases
- Jellyfin goes back to the version SparkBox tests and ships with, after an automatic update moved it two major versions ahead in one step, past the opt-in that exists for exactly that jump. If your box already moved to the newer Jellyfin it is left alone rather than rolled back. The updater now also recognises Jellyfin's shorter version numbers, so it steps one major version at a time like everything else.
- Tom AI now explains in plain language what three more earlier releases changed for you, instead of saying the details were not recorded: the one that stopped off-site backup erasing your bucket and keys when you switched it off and let libraries over 5 GB finish uploading, the one that fixed the welcome email's reply address and kept your request app working after a media app's key was regenerated, and the one that got detailed troubleshooting answers coming back instead of an empty reply.
1.6.719 — Tom AI answers three more "what changed in that release?" questions properly
- Tom AI now explains in plain language what three more earlier releases changed for you, instead of saying the details were not recorded: the one that made a terminal setup stick and warned that some VPN locations block file sharing, the one that stopped remote access showing green while signed out and stopped Roll Back claiming success when nothing was restored, and the one that got the certificate-expiry alert reading real certificates at last.
- Matrix: the one-time Synapse setup step now runs the same Synapse version as the server (an automatic version bump had moved only the server), so a new install's configuration matches what runs.
1.6.718 — A new spark for SparkBox
- SparkBox has a new logo across the website, all dashboard versions, sign-in and welcome screens, app launcher, and home-screen icons.
- The Legend constellation now features the new SparkBox artwork. Browser icons refresh with this update.
- The Windows installer and companion app brand assets use the same artwork.
1.6.717 — Your data-sharing choice is confirmed before the question closes
- The data-sharing question now waits until SparkBox confirms your answer is saved. Previously a failed save could silently close the question, causing it to appear again at the next login.
- Both Yes and Not now are remembered across logins and restarts. If a save cannot be confirmed, the question stays open with a clear retry message. This applies to Classic, the original Legend interface and Version 3.
1.6.716 — App refresh: 13 apps updated to their latest tested versions; Frigate starts on servers without a GPU
- Refreshed 13 apps to their latest stable versions in one update — each one was installed on the old version and upgraded on the test box before this shipped, and the fleet applies them on its normal update. Run `sudo sparkbox update` to take them now.
- Updated: actual-server 26.7.0 → 26.9.0, alpine 3.24.1 → 3.24.2, authelia 4.39.27 → 4.39.28, byparr 2.1.0 → 3.0.4, grafana 13.1.3 → 13.2.2, jellyfin 10.11.11 → 12.1, linkding 1.46.2 → 1.47.0, nextcloud 32.0.6 → 33.0.5, prometheus v3.13.2 → v3.14.0, speedtest-tracker 1.14.5 → 1.15.0, synapse v1.156.0 → v1.161.0, tailscale v1.102.3 → v1.102.4, wizarr v2026.7.1 → v2026.9.1.
- Jellyfin 12 and Nextcloud 33 are major versions: both migrated their existing libraries cleanly in the rehearsal and nothing was reset; expect Jellyfin's new-look interface after the update.
- Frigate: on a server without an Intel/AMD GPU (or in a VM that does not pass one through) Frigate could not start at all — Docker refused to create the container because the video device was hard-wired into its definition. The device is now only attached when the server actually has one, so Frigate starts everywhere and still uses hardware acceleration where it exists.
- Held back on purpose this time: n8n 2.x, Open WebUI 0.11 / Ollama 0.34 and Minecraft Bedrock — the test box could not prove them, so they stay on their current versions until it can.
1.6.715 — Tom AI answers three more "what changed in that release?" questions properly
- Tom AI now explains in plain language what three earlier releases changed for you, instead of saying the details were not recorded: the twenty-two-fix batch, the release that repaired empty "what's new" notes and a failed update deleting a saved settings file, and the one that brought the refund and billing form back to a real mailbox.
1.6.714 — Version 3: your preview becomes your workspace
- Version 3 now follows the new workspace design throughout: a constellation hero, quieter sidebar, compact favorites dock, and coordinated widgets and controls.
- Choose your favorite apps for the dock, find apps and settings with Ctrl/Cmd K, and jump straight from a health warning to its details.
- Server pulse now shows real CPU and memory readings with 1-hour, 24-hour and 7-day views. History builds as your dashboard collects readings; missing periods stay blank.
- A prominent update notice appears across dashboard pages when a SparkBox update is available. Review the release before updating, on Free, Legend, Classic or the original Legend interface.
- Existing app management, settings, Vault and older dashboard choices remain available.
1.6.712 — Version 3: a new workspace for SparkBox Free and Legend
- Meet the Version 3 interface: a clean workspace for SparkBox Free and a distinct Legend home with an app dock, Tom AI panel, atmosphere choices and saved layouts.
- Choose your dashboard from the sidebar: Version 3, Version 1 (Classic), or Version 2 (Original Legend) for supporters. Your apps, data and existing dashboard choice stay in place.
- V3 uses the existing app, container, update, backup, security and account controls. Its Vault opens and manages entries directly in the new interface.
- The home screen distinguishes app availability from system status. Disk warnings and unavailable metrics stay visible instead of being presented as a healthy server.
- Daylight and Nightfall themes, responsive layouts, and separate saved widget preferences for V3.
1.6.711 — Actual Budget, Open WebUI and n8n stop restarting on their own; Home layout holes closed
- Actual Budget: if only half of its HTTPS certificate was ever written — an interrupted first install, a partial restore — nothing repaired it, and the app exited on the missing half and restarted forever. `sparkbox up` now checks both halves before starting it and regenerates them if either is missing or empty. A working certificate is left alone, so you are not asked to accept a new one for no reason.
- Open WebUI: its first start downloads and sets up its embedding model, and only answers as healthy once that is done. On a slower box that took longer than it was given, so it was declared unhealthy and restarted — throwing away the partial download and beginning the same wait again. It now gets the time it needs; a fast box is still ready as soon as it answers.
- n8n: it was only claiming about half of the memory its app is allowed, which was enough for ordinary use but not for the database upgrade that runs after a version change — so it could run out of memory part-way through while memory was still free. It now asks for what it needs up front.
- Home (customised layouts): cards no longer leave a hole beside or under themselves. A card that had once grown tall kept that height forever, so a short launcher next to a tall system column left up to 700px of empty wallpaper, a hidden My Ship card still held its rows, and a section header could end up under its own cards. Rows now match the tallest card, hidden cards give their rows back, sections stay in order, and the settled layout is saved so the page does not jump on the next load.
- Classic dashboard: one set of corner radii (8 / 12 / 16px) across buttons, cards and panels instead of nineteen different ones; light mode keeps the wallpaper readable; links are styled everywhere; the low-disk banner stays visible while you scroll.
- Privacy & Terms (website): the AI providers behind Tom AI and support are named, the two add-ons that renew are stated with how to cancel, the sub-processor list and Ultimate-app data notes are published, and stored Tom AI transcripts are redacted the same way the live chat is.
1.6.713 — Hardware transcoding starts on more servers, and a warning before a mount disappears
- Hardware transcoding now starts on servers whose graphics card reports one group for both of its devices. Jellyfin, Tdarr and ErsatzTV previously refused to start with GPU transcoding turned on, and the only sign was the app failing to come up.
- If you added a folder to a container outside SparkBox — in Portainer, for example — SparkBox now tells you before an update that the folder is about to be dropped, and hands you the exact lines to keep it permanently.
1.6.710 — App refresh: 18 app(s) updated to their latest tested versions
- Refreshed 18 app(s) to their latest stable versions, all in one update — each was installed and tested end-to-end by the nightly auto-bump rehearsal before this shipped. Run `sudo sparkbox update`.
- Updated: changedetection.io 0.55.8 → 0.60.7, chaptarr 0.9.936 → 0.9.958, crafty-4 4.10.8 → 4.11.0, duplicati 2.3.0 → 2.4.0, flaresolverr v3.5.0 → v3.5.2, freshrss 1.29.1 → 1.30.0, ghost 6.57.1-alpine → 6.64.0-alpine, homarr v1.71.0 → v1.77.1, homepage v2.2.0 → v2.4.0, mealie v3.25.1 → v3.27.0, navidrome 0.63.2 → 0.64.0, nextcloud 31.0.9 → 32.0.6, prowlarr 2.5.2 → 2.6.5, radarr 6.3.0 → 6.4.4, sabnzbd 4.4.1 → 5.1.3, server 2.9.1 → 3.1.1, shelfarr 2026.08.31.1 → 2026.09.10.1, sonarr 4.0.19 → 4.0.20.
1.6.709 — Sharing an AI answer no longer publishes anything you pasted into the chat, and reset-password really lets you back in
- Share to demox no longer publishes secrets. If you pasted an .env excerpt, a licence key, a Plex claim token, an API key or a password into the chat while asking your question, the pre-filled public post carried it word for word into the forum, the address bar and your browser history. Both your question and the AI reply are now filtered before the post is prepared, and each removed value is labelled so you can see which credential it was. If you shared a chat before this update, treat anything you pasted into it as public and rotate it.
- sparkbox reset-password now really gets you back in. On a box updated from an older version the reset could report success and the new password be accepted, and the dashboard would still bounce you straight back to the login form, because the folder it keeps your session in was left owned by root and it could not write a session file. Resetting the password now repairs that folder before it restarts the dashboard.
- The built-in assistant now gives the right details for connecting Sonarr, Radarr or Prowlarr to SABnzbd by hand. It used to leave people chasing DNS and Docker networks after "Unable to connect to SABnzbd"; it now tells you the host and port those apps actually need (localhost, port 8081) and warns that 8186 is the browser port only.
1.6.708 — Stay signed in after an update, and a clear answer when the media setup has to finish on the server
- The dashboard no longer signs you out and says it cannot load your services after sparkbox update or sparkbox restart. The folder it keeps your session in was only prepared during sparkbox up, so any other restart could leave it owned by root and unwritable; it is now prepared on every path that recreates the containers.
- Finish media setup: when the button is pressed from inside the dashboard container it now says plainly that the step has to run on the server and gives you the exact command (sudo /opt/sparkbox/sparkbox media-finish), instead of failing with "/app is not writable as the current user" or quietly creating folders nobody can see. The Moonfin toggle shows the same reason.
- Tom AI: more of its help articles now explain, in plain language, what a past fix actually changed for you, instead of ending with a note that the resolution was not recorded.
1.6.707 — Cloudflare Tunnel 2026.9.1, CoolerControl 5.0, and Tom AI that finds a third more answers
- Cloudflare Tunnel connector updated to 2026.9.1 (September security and stability fixes). No settings change; your tunnel reconnects on its own.
- CoolerControl updated to 5.0: new interface, calibration wizard, security hardening. Fan curves, profiles and sensors carry over. If you used the "EMA" smoothing function type, it becomes plain Identity after the update; re-add smoothing as an EMA custom sensor.
- Tom AI finds noticeably more of its own help articles, because it now matches the way customers actually phrase a problem, and seven new articles cover SABnzbd "name does not resolve", File Browser vs root-owned music folders, the orange "starting" icon, and more.
- Tom AI outcome reporting: the dashboard now reports how a repair session ended on every step, not only when a fix ran, so our cost and success numbers are honest.
- Moonfin (Jellyfin request button): the installer now picks the Jellyfin build of the plugin, not the Emby one, so Jellyfin 12 loads it; the toggle is marked experimental until Moonfin can show its button on Jellyfin 12 (use Seerr to request in the meantime).
- UGOS and other boxes that moved the dashboard off port 443: sparkbox up no longer rebinds Nginx Proxy Manager to 443 when an old value is left in the shell; the .env setting wins.
- Checkup (sparkbox doctor): the out-of-memory report now reads the same on the server and in the dashboard. Kills that are not SparkBox apps are reported on their own line on the server, and the dashboard says plainly that it cannot see them instead of quietly showing a shorter list.
1.6.706 — Doctor sees five more faults, MariaDB password repair, Stable Diffusion sizes itself, no daily message limit for founding Legend
- sparkbox doctor now reports five faults it could not see before: a VPN country change that never reached the VPN container, a Tailscale node that is not on your tailnet, finished downloads stuck before your library (in the app's own words), several apps that stopped in the same minute, and a Jellyfin folder it cannot watch with no recent scan. Each comes with the exact fix.
- Windows: doctor reads the port blocks Windows reserves for itself and, if one covers a SparkBox app port, names the ports and prints the documented fix.
- BookStack and Nextcloud: sudo sparkbox repair-db-auth bookstack (or cloud) repairs a database password mismatch after a restore or .env regeneration. It saves a copy first, resets only the existing logins, and never wipes your data.
- Stable Diffusion sizes its memory limit from your box's RAM each time it starts, tells you plainly if the box has under 8 GB instead of crash-looping, and doctor says whether the app's own limit or the whole box ran out of memory.
- Tom AI: if you bought Legend while the card said "no practical limit for normal use Tom AI chat" (before 26 July), the daily message limit does not apply to your key. No action needed.
- sparkbox logs now hides passwords, keys and tokens in the live log stream, like doctor already did.
1.6.705 — Sixteen fixes from the support queue: WSL first-run freeze, seeded app logins, VPN forwarded port, Home Assistant 2026.9
- Windows: opening the SparkBox distro from the Start menu could freeze every SparkBox command behind the Linux first-run wizard. The installer, sparkbox up and doctor now disarm it.
- Windows: a media drive mounted from a WSL terminal is now visible to Docker, so the media apps see your files.
- Portainer and qBittorrent are now opened in the firewall like every other app, so LAN access no longer times out.
- The admin login SparkBox creates for Sonarr, Radarr and Prowlarr now appears under Settings → Service Passwords and in the first-login popup, so turning "Trust my LAN" off never locks you out.
- Doctor now recognises an Immich database that is up but rejecting Immich's password and points you at the one-command repair instead of calling it a crash-loop.
- The OnlyOffice secret key is shown with your other passwords, and the Cloud guide covers the two Nextcloud settings that stop "Error while downloading the document file".
- sudo sparkbox bootstrap-token no longer exits silently on a box that lost its token; it explains the state and names sudo sparkbox reset-password. The login screen gives the same recovery.
- Installing an app from the dashboard no longer warns about a broken network or a missing media drive when both are fine.
- The Moonfin plugin installs on any NAS without needing extra tools on the system.
- When Sonarr or Radarr cannot tell which show or movie a finished download belongs to, the Media pipeline card sends you straight to Manual Import instead of suggesting a restart.
- When an update is cut short because the box ran out of memory, the update screen says exactly that.
- A box that cannot write its own history file no longer reports a phantom crash every ten minutes.
- When your VPN hands SparkBox a forwarded port (ProtonVPN, PIA), qBittorrent now listens on that port automatically instead of staying firewalled.
- Choosing Private Internet Access, Perfect Privacy or VPN No practical limit for normal use now connects instead of the VPN container looping on "provider name not active".
- Home Assistant now ships the current 2026.9 release and upgrades existing installs in place, keeping your users, devices and history. If you maintain Home Assistant YAML by hand, check Home Assistant's breaking-change notes between 2024.12 and 2026.9.
- Turning an app off with sudo sparkbox disable no longer hides the enabled-app list from the dashboard: afterwards Tom AI's built-in doctor used to stop halfway with no summary, and the ad-block stats read as nothing enabled. Existing installs are repaired on the next sudo sparkbox up.
1.6.704 — A failed install no longer leaves your DNS changed
- If an install fails before SparkBox starts, the installer now puts the host's DNS back the way it was: it turns the systemd-resolved stub listener back on and restores /etc/resolv.conf. Previously a failed install left the DNS change made for Pi-hole in place on a box that never got SparkBox.
- A finished install, an upgrade on a box that already runs Pi-hole, and anything else already holding port 53 are left exactly as they are.
1.6.703 — Tom AI checks repair compatibility before selecting its model
- Tom AI identifies the installed dashboard before selecting the new repair model. Older dashboards keep their existing repair provider until they have the current verification safeguards.
- The corrected qBittorrent login repair can be offered after an older implementation failed, but only when fresh checks confirm the login problem. Failures of the corrected repair still stop repeat attempts. The direct repair also recognizes Prowlarr connections.
1.6.702 — Media login repairs clear temporary bans and use current checks
- The qBittorrent login repair now saves corrected download-client credentials before restarting qBittorrent to clear a temporary login ban, then checks that the apps can actually log in.
- Tom AI media diagnostics check current authentication instead of treating old log warnings as a current failure. The new repair model path uses current tool results for its diagnostic summaries.
- An unrelated app that was already unhealthy no longer prevents a successful qBittorrent login repair from being verified. New health regressions still fail verification.
1.6.701 — Repair summaries stay accurate during AI handoffs
- Extended the local verification safeguards used by the upcoming Tom AI repair update: a handoff to another AI model cannot turn a failed, unverified, or declined action into a claim that it was fixed. The new repair routing remains under evaluation.
1.6.700 — Finished setup helpers, an honest doctor write check, and steadier Tom AI actions
- A one-time setup helper that has finished its job (for example the antivirus module's clamav-init) no longer shows as exited with a Resume button. The Running list now says “Setup done” with Logs only, and the V2 container table labels it done with no Start button, so a finished helper is not mistaken for a crashed service.
- sudo sparkbox doctor now tests whether your apps (the user id they run as) can actually write to your media folder, instead of reporting that root can. A box where downloads and imports fail with “Permission denied” no longer gets a green “MEDIA_ROOT is writable”; it gets the warning and the fix command.
- Tom AI’s action turns now ride out a momentary DNS lookup hiccup the same way its chat turns already did, instead of failing at once with an EAI_AGAIN error while the box’s network is fine.
1.6.699 — Tom AI prepares safer repair summaries
- Added safeguards for the upcoming Tom AI update: repair summaries use the checks performed by your box, so a failed or unverified repair cannot be reported as fixed. Declined actions are reported as skipped. This new path remains disabled during testing.
1.6.698 — Tom AI avoids repeated repairs and checks what actually worked
- Tom AI stops repeating a failed action when the relevant checks have not changed, including after another message in the same conversation. After two failed attempts, it stops that action and investigates another cause.
- When you ask to fix a qBittorrent login problem, Tom can now use fresh Sonarr and Radarr login checks to offer the existing credential repair directly. You still approve it first, and Tom checks the login again before reporting success. This direct path is available on paid boxes; unclear cases use the usual investigation.
- Your “fixed” feedback now applies to the conversation as a whole. It no longer marks every repair attempted in that conversation as successful. Stuck-download guidance also asks Tom to investigate the import reason before proposing another scan.
1.6.697 — Matrix chat survives scheduled updates and reboots
- Matrix chat: Synapse no longer dies after a scheduled update or a reboot. Every update run re-owns the app folders to your box user, and Synapse — which runs as its own user — was then locked out of its own signing key and database at the next start: sb-synapse-init sat at "Exited (1)", sb-synapse never left "Created", and the only way back was a manual chown of the Matrix folder. The Matrix setup step now hands that folder back to Synapse before it starts, every time, so a scheduled update or a restart brings your chat straight back.
1.6.696 — `sparkbox up <app>` no longer starts an app you never enabled
- Command line: `sparkbox up <app>` on an app that is not enabled now stops with "Module <app> is not enabled — enable it first with 'sparkbox enable <app>'" instead of quietly starting a second copy of it. Restart has refused this for months; up now matches. On a box running the Media bundle, `sparkbox up jellyfin` also tells you your Jellyfin lives inside the bundle (sb-jellyfin-media) and that `sudo sparkbox restart media` is the command that reaches it — so you never end up with a plain "Jellyfin" tile next to "Jellyfin (media bundle)".
- Tom AI: now knows that deleting Jellyfin's database while the rest of its folder stays behind leaves Jellyfin unable to start (the "no such table: __EFMigrationsHistory" crash that no restart, ownership change or fresh image can clear), that doubled episodes come from a duplicate library you remove inside Jellyfin rather than by deleting the database, and how to tell an accidental second Jellyfin from the bundle's own. It also picks up the real fix for the v1.6.441 Settings change instead of a placeholder.
1.6.695 — Migration import accepts a full-size export bundle
- Migration: importing your sparkbox-migration.json on a new box no longer fails with "Invalid JSON body." once the export carries your app settings. The import now accepts a bundle as large as the export can produce, so a finished export (which correctly ends with three closing braces) imports as-is; never re-export or edit it.
- Tom AI: now knows the migration file is complete and the import size limit was the cause, so it no longer tells you to re-export a good file.
1.6.694 — Refer a friend card for Legend owners; plural-aware guide search
- Legend owners: a Refer a friend card on Home. Earn $10 for every Legend sale you refer and your friend gets $10 off the one-time $49; free to join, tracked automatically through the purchase. Dismiss it and it stays away for a month.
- Help links: asking about "no indexers found" now lands on the add-a-search-source guide instead of a troubleshooting article, because the guide search treats plurals and singulars the same.
1.6.693 — Tom AI free taste for free keys; Legend offers where features are locked; antivirus quarantine is yours
- Free keys get a small taste of Tom AI. Every free personal-use key now includes 2 agent fixes and 20 chat messages of Tom AI, right in the dashboard — it reads your box, explains what is wrong and fixes it on your tap. When the taste is used up, the dashboard shows what it did and what Legend keeps.
- Locked features now say what Legend is instead of dead-ending. Where a free box used to see "this is a supporter feature", it now sees what Legend adds, that it is $49 once with no subscription, and a link — plus an Activate a key button if you already own one.
- Free boxes see what the doctor found. Home shows the issues the doctor found this week with a Fix with Tom AI button that explains Legend; nothing is shown when the box is clean.
- Antivirus: the quarantine folder is created at install and owned by you, so restoring or deleting a quarantined file no longer needs sudo.
- Vaultwarden updated to 1.37.3.
1.6.692 — `sparkbox logs` works for an app bundle's name; Tom AI knows the Nginx Proxy Manager login
- Running `sudo sparkbox logs matrix` (or any app bundle whose containers are not named after it) used to stop with "No such container" — exactly when you were chasing a crash after an update. It now follows every container in that bundle, with each line labelled by container name, and says plainly when the bundle is not started yet. `sparkbox logs sonarr` and the other single-app names work exactly as before.
- Tom AI now knows how signing in to Nginx Proxy Manager works on a SparkBox: the sign-in details from the upstream project's own documentation do not apply on a SparkBox, the email and password SparkBox created are under Settings → Service Passwords, there is no `reset-password npm` command (asking for one only printed an error), and if you changed the account inside Nginx Proxy Manager the current login is the one that counts. It now gives the real way to bring SparkBox back in sync instead of pointing at a command that does not exist.
- Also carries customer-readable solutions for three older patch-log articles (v1.6.427, v1.6.428, v1.6.430) — help-text only.
1.6.691 — Dashboard audit batch: honest backup coverage, visible retry, keyboard navigation, local archives; Enter respects Cancel
- Two dashboard fixes from this weekend's audit. Pressing Enter while the Cancel button was highlighted in a confirmation dialog used to run the action anyway; Enter now does what the highlighted button says, and Escape still cancels. And installing Hearth or TomSparkCal could end with "installed but not running yet" even though the app was healthy, because those apps are reached through the proxy rather than a LAN port and the installer was only looking at LAN ports; it now watches the container itself, so a healthy install finishes as Running.
- Dashboard fixes from this weekend's audit, second batch. The Backup Center now says what an archive really covers: "Configuration + app data" normally, "Partial backup" with the excluded items listed when the media library is left out, and Help no longer promises that a dead drive never loses your photos. Panes that failed to load used to sit blank forever; they now show "Couldn't load — Retry", the update-schedule switch shows an unknown state instead of Off when its read fails, and a failed backup shows the real reason (disk space, permissions). The sidebar is keyboard-navigable: real links you can Tab to, Enter and Space work, the current page is announced, app and settings switches have names for screen readers, plus a skip-to-content link and a visible focus ring. The Backblaze links in backup setup are readable on the dark theme. "Access from anywhere" now opens the guided setup instead of a Network panel with no wizard. The Backup pane lists your local archives with Download and Restore. Help no longer says "all without the cloud"; the licence pane can show an Ultimate badge. Under the hood, two dashboard functions shared a name so the Overview's network-exposure fields never filled in; that is fixed and a test now rejects duplicate names.
1.6.689 — TomSparkCal joins SparkBox Apps
- Install TomSparkCal from Apps for a private calendar hosted on your own SparkBox. Paste or dictate plans, review their dates, and share Together events with family through encrypted sync.
- Use the Access picker for a private Tailscale address or HTTPS domain. Calendar data survives updates and removal of the running container. Personal and Work plans remain local in this self-hosted mode.
1.6.688 — The media pipeline strip names the real fix for a permission failure instead of telling you to restart
- When a finished download couldn't be moved into your library and Sonarr or Radarr described the failure in the wording their Linux runtime actually uses — "Operation not permitted", or an access error code rather than the words "permission denied" — the media pipeline strip on your home page told you to restart the Media apps, which cannot give the app ownership of a folder it never had. The strip now recognises those wordings as the folder-permissions problem they are and points you at the same repair it already recommends for a plain permission denied (sudo sparkbox check-media-perms), so the fix you see matches the one that works.
1.6.687 — The media pipeline no longer says Radarr is missing search sources it already has
- If you had renamed one of the search sources Prowlarr passes into Radarr or Sonarr, the media pipeline strip on your home page could say Radarr wasn't using any of your search sources, even though every one of them was there and searches worked. SparkBox connects Prowlarr to Radarr and Sonarr over the box's own local address, and the strip only recognised a passed-in source by its original name, so a renamed one dropped out of the count. The strip now recognises those sources by the address SparkBox itself set up, so a rename no longer produces a false alarm.
1.6.686 — Tom AI stops inventing how things work when it does not know
- Tom AI no longer states how SparkBox works internally unless it has a SparkBox knowledge article for it, and it no longer calls something a SparkBox bug or sends you to rebuild a stack to test a theory. When it cannot find the cause it now says what it observed and what it ruled out, then hands you to the forum. One user was told that a Prowlarr indexer type was missing from Radarr and rebuilt their media stack for nothing; no such type exists, Prowlarr pushes its indexers into Radarr through its own Apps page. The same bar now applies to what Tom AI says about Radarr, Sonarr, Prowlarr, Jellyfin and the other apps: a setting or menu is named only when it is certain to exist.
How to get all of this
One command on your box, whenever suits you. Nothing here changes your data or your settings.
sudo sparkbox updateLegend members get every future update and every app we ever ship for a one-time $49. See what Legend includes.