₺ Logo TCMB Rates Documentation

Release history

Release notes

The releases that have been published and what each one brought. From 1.3.0 onwards updates are automatic: the installation checks a signed release announcement every day, verifies the package, installs it, and rolls back to the previous version if the health check does not pass. Details: Updates.

1.5.31 current

30.09.2026

  • One-click Logo connection. The Read from Logo settings (LOGODB.CFG) button on the wizard's connection step reads Logo's own SQL settings through the Logo Objects registered on the machine and fills in the server, database and authentication type. The SQL password never goes to the browser; it stays on the server.

1.5.24 current

23.09.2026

  • Sturdier offline licence screen. On air-gapped installations the licence file upload screen now opens independently of the product’s licence gate: even if the licence server is unreachable or setup is incomplete, the device information file is produced and a licence file can be uploaded.
  • Licensing components updated. The product moved to version 0.8.10 of the licensing library; nothing changes on screen.
  • Groundwork: learning Logo table IDs. A helper screen that learns the Logo table IDs needed for change-log entries ships in the package but is off by default; it is switched on only under guidance from support.

1.5.23 leaner e-mail

19.09.2026

  • The daily rate e-mail is now plain. Technical lines about the product’s internals (audit columns of Logo tables, change-log identifiers) are no longer printed above the rates. They were accurate, but they did not change anything on your side — and sitting at the top every morning, they overshadowed the warnings that do matter.
  • What stays in the e-mail: what concerns you. Which bulletin date was used (weekend / public holiday carry-over), an approaching licence expiry, and rows that could not be written or were skipped. The rate check report e-mail follows the same rule.
  • Nothing is lost, only moved. Those warnings remain in full on the product’s screen, in its log files and in the run record — everything installation and support need is still there.

1.5.22 audit trail signature

19.09.2026

  • Rates written by the product no longer look unowned in an audit. Because Logo does not stamp the rows of its common rate table, rates written by the product could not answer “who changed this rate?” — while Logo’s own download could. The product now records every write in Logo’s own change log, on behalf of the Logo user selected in the settings, and the entry states what was done. Our row is therefore shown in the same place and the same form as one written by Logo.
  • The trail of earlier writes can be filled in. The Complete audit trail button on the rate check screen fills in rows the product wrote earlier without leaving a trail, using its own write log. The button first states how many entries will be written and asks for confirmation; it does not touch rate values — only audit entries are added; pressing it a second time does not duplicate anything. Entries carry the real time of the work and state plainly that they were filled in later: the log never shows a moment that did not happen.
  • If it cannot be done, the reason is on screen. No Logo user selected in the settings (there would be no one to record the entry on behalf of), nothing to fill in, or a table that cannot be signed this way — each is reported separately. For now only the common rate table is signed; no entry is written for company rate tables, and the screen says so.
  • The audit entry never puts the rate write at risk. It is written after the rates reach Logo, separately; if it fails, your rates still count as written and the problem is reported as a warning. Existing entries are never touched and nothing is deleted.

1.5.21 reading the change log

19.09.2026

  • “Who changed this rate?” is now answered for the common rate table too. Logo does not stamp the rows of its common rate table, so the product used to report “no audit trail” for them. Logo does, however, record who changed such a row and when in its own change log. The row detail now reads that log as well — and because the log also records what was done, the description of each change (such as “downloaded from the TCMB … new values”) is shown entry by entry.
  • The screen says where the information came from. A badge in the detail window states the source — row stamp or change log — and the rate check list gained a filterable Audit source column. When the log holds a single entry, the product states that this entry is the last change and that it does not reveal who created the row: what it does not know, it does not guess.
  • Change times are no longer lost. The time of a log entry (16:18, say) could previously appear as 00:00 in some cases; this is fixed.

1.5.20 row detail + default scope

19.09.2026

  • The rate check screen now opens on the “common table”. On some installations it cannot be read whether Logo’s common rate table applies to the companies; the product then stayed on the safe side and listed both the common table and the company tables. The result: the same rate appeared twice and the “written / missing” counters were doubled. The screen now opens on the common table alone; to see company tables, pick a company or “all companies” in the selector. While the common table is selected, the common-table dropdown stays disabled together with the reason — which selection is in force can be read off the screen.
  • Clicking a row opens the full story of that rate. Click any row in the rate check list: the window shows the identity of the rate (rate date ↔ bulletin date, company, table, rate code), a side-by-side comparison of the expected values and the ones in Logo (the differing column highlighted), and Logo’s own audit stamp — who added it and when, who changed it and when. If the row does not exist in Logo at all, or exists without a stamp, that is stated plainly instead of being hidden behind a dash.

1.5.19 who wrote it + half rows

19.09.2026

  • Half-written rate rows are now completed. A rate row in Logo can have some columns filled and others left at 0 (for example buying/selling written, the effective columns empty). With update existing rows switched off the product used to skip such a row entirely; now only the empty columns are filled and the ones that already hold a value are left untouched. Your “do not overwrite” decision therefore still stands: filling a gap is not overwriting. If the central bank publishes no value for that rate (some currencies have no effective rate), nothing is written.
  • “Completed” is counted separately. The run summary and the Runs list show a completed counter next to added and updated, and the rate check screen marks rows in three colours. So when updating is switched off, it is immediately clear why a row changed. Earlier runs are classified correctly too.
  • “Who added this rate, who changed it?” is answered on screen. The Logo rate check screen gained filterable Added by and Changed by columns plus optional Added / Changed timestamp columns. The values come from Logo’s own audit stamp and user list; older rows without a stamp stay blank.
  • Screens fill the window. The wide gap under some lists and the page itself scrolling (pushing the toolbar off screen) are fixed: the table scrolls inside its own area, the version footer always stays at the bottom, and table text is slightly tighter — more rows fit on one screen. Lists of thousands of rows stay fast.
  • The setup screen opens in a modern browser. Setup no longer hands the address to the machine’s default browser; it launches whichever of Edge, Chrome or Firefox is installed. On servers whose default is Internet Explorer, “the setup screen never appears” is gone.
  • Update status is visible on screen. The new Update screen shows when an update was last requested, what the answer was, and whether the updater is installed. The updater can now also use the proxy server configured in the product — on networks that reach the internet only through a proxy, automatic updates no longer stall silently.

1.5.18 e-mail over SMTP only

18.09.2026

  • E-mail is sent over one path only: SMTP. Sending through SQL Server’s Database Mail (sp_send_dbmail) has been removed. An installation that used that path does not go quiet without saying so: the e-mail step shows a notice explaining what happened and what to do, and the notice disappears once you save your SMTP details.
  • Encryption is now a choice, not a guess. The old “use SSL/TLS” checkbox is replaced by a Security field with four options: STARTTLS (port 587) · direct SSL/TLS (port 465) · automatic · no encryption (internal network only). If the mode and the port do not match, the screen says so before a connection is attempted and fills in the common port with one click.
  • A failed test e-mail tells you what to do. Instead of a raw .NET sentence you get an actionable suggestion. If the server’s certificate was not issued for the name you connect to, the names on the certificate are listed (“enter one of these, reachable from here, as the SMTP server”); rejected credentials, relay permission, name resolution (DNS) and a closed port are each recognised separately — including the command to check the port.
  • The last resort is stated plainly: if you cannot reach an internal server by the name on its certificate, you may turn on Skip certificate validation. The connection stays encrypted, only the server’s identity is not verified; the correct fix is still to use the name on the certificate.

1.5.17 diffs and logs

18.09.2026

  • The rate check screen now says WHAT differs. It used to print only “Diff 1,2,3,4”; every difference is now named with its values: R2 Forex selling · expected 41.2345 · Logo 41.5 (+0.2655). The real fix was not the wording but the comparison itself: the rate day in Logo and the bulletin day that produced it are not the same day — a TCMB bulletin applies on the next business day, and further ahead across holidays. Because the two were not matched, almost every row looked “different” in all four columns. The two dates are now separate columns (Rate date (Logo) and Bulletin date), holiday carry-over matches the correct bulletin, and the first day of the selected range no longer looks “not written” for no reason. Value column headers also state which TCMB rate they carry.
  • Writing to Logo now leaves a trail. For doubts such as “it does not write to the shared rate table” there is no more guesswork: the executed INSERT/UPDATE scripts — in a form you can paste into SSMS — and the reason for every skip (setting off · currency undefined in Logo · values already identical) are written to the log, with a per-table summary of “N inserted, N updated, N skipped”. Logo writing has its own log file: logs\logo-yazim-<day>.log (30 days).
  • Log files can be read on screen. The new Log files screen lets you pick and search the Logo write, application and setup logs and view the last 100–5000 lines; the full file path is shown on screen. A screenshot is enough for support — nobody has to hunt for files on the server.
  • Logo’s own audit stamp is filled in. When rates are written, the CAPIBLOCK fields (creating/modifying user and timestamp) are written too; the user is picked from Logo’s own user list in Settings → Logo. If no user is picked, the write stays byte-for-byte what it is today.

1.5.16 health identity

17.09.2026

  • The health endpoint now says which product it is. The /healthz response carries a fixed app: "TcmbKur" field (also while the setup wizard is open). The install script and the automated tests first ask “is this address really running TcmbKur?” and only then compare versions — if another product happens to sit on the same port, “reachable + version matches” can no longer mislead. The response also carries the release date (releasedAt).
  • The install script's health gate got stricter. Post-install verification no longer settles for “running + 200”; it expects product identity, status, database and version all at once, and a wrong product stops it with an explicit “DIFFERENT PRODUCT” message.

1.5.15 token gate

17.09.2026

  • Sign-in, sign-out and change-password forms now give an explicit answer when the security token is missing. If the form's anti-forgery token is missing or stale (a tab left open for a long time, a browser that dropped the cookie), the product no longer silently bounces you to the sign-in page as if the credentials were wrong; it rejects the request with 400 – token missing or invalid. Reload the page and submit again. The check is a single gate on the endpoints themselves — not repeated (and forgotten) form by form.
  • The administrator recovery endpoint is invisible from outside. The recovery path can only be called from the server itself; a remote request gets 404 before the token is even looked at, so not even “there is such an endpoint here” leaks. Behaviour is unchanged; the order is now guaranteed and pinned by a test.

1.5.14 company discovery

14.09.2026

  • When you pick a company, the shared rate table now follows that company. The Logo rates screen used to show the shared rate table (L_DAILYEXCHANGES) unconditionally, even though Logo records on L_CAPIFIRM which company actually uses it. The product now discovers that flag at run time — the column name differs between Logo versions, so it is never hard-coded — and the badge states which column the decision came from: Decision source: L_CAPIFIRM.<column>. Pick a company that keeps its own table and the shared row no longer appears.
  • If the flag cannot be read, the product says “unknown” instead of guessing. When no column can be discovered the screen shows both tables and explains why — showing more and saying so beats silently showing less. You can also decide manually from the selector: Automatic · Show shared table · Hide. Nothing about writing to Logo changed; this only affects what the control screen reads.
  • “Fetch now” no longer stops at today. The TCMB bulletin is published at 15:30 on each business day and is valid for the next business day, but a manual fetch only ran for a single target day — so operators saw tomorrow empty and assumed the product was broken. A manual fetch now runs a range, from the configured target day up to the furthest day the published bulletin is valid for. Each day is a separate run in the log, so one failure does not stop the others.
  • The runs screen has a cleanup button too. It is available to administrators, the boundary is the start of the date range shown on screen (visible records stay, older ones go), and you are told how many records will be deleted before confirming. A run still in progress is neither deleted nor counted — deleting it would destroy the rollback snapshot of the rows already written to Logo; the number of protected records is stated separately.
  • The proxy (HTTP 407) advice now points at a setting that actually exists. The text described proxy user name and password fields that had been removed from the product. It now points at Settings → Proxy server → “Authenticate with Windows identity” and, if that is not enough, at the bypass rule to request from your network team. We do not store a password that your organisation rotates.

1.5.12 Logo rate check

13.09.2026

  • You can check the rates in Logo from inside the product. The new Logo rates screen puts the rates in the product's own archive side by side with the values that actually sit in the Logo tables — the shared rate table L_DAILYEXCHANGES and the per-company tables LG_EXCHANGE_XXX — for the date range you pick. Every row carries exactly one state: written · value differs · not written · not in the archive · not defined in Logo. The “only problems” switch leaves just the rows that need you. Until now the product only showed what it had written; seeing what stands in Logo meant running a database query.
  • “No rate today” and “TCMB could not be reached” are no longer the same line. The runs list and the dashboard now show the kind of result: No bulletin (TCMB published none that day — the product did its job, and the row is not red), TCMB unreachable (network, proxy or firewall), Licence, Configuration, Error. When someone says “no rates came in today”, the screen now says where to look.
  • The internet access test no longer appears to hang. When a connection is dropped silently, Windows keeps retrying for a long time, so the test could run past a minute and the operator assumed the product had frozen. Every step now has its own deadline (~25 seconds in the worst case) and, when it expires, the screen prints that step's own diagnosis rather than “cancelled”. The example address in the proxy field no longer looks like a real IP either (vekil.firma.local:8080) — typing the example verbatim was the wrong answer.
  • The network access choice survives updates. Even with “Local network” chosen during installation, the next update could close the service back down to this server only; and when the wizard changed the choice on an installed service, the firewall rule was opened but the service kept listening on the old address. Access scope is now a setting: an update does not overwrite it, and the wizard really does change the listening address of the installed service.
  • Logs clean themselves up, and lists open on a date range. Settings has a Log retention (days) field (0 = off); the product deletes old log records in the background. The Rates, Runs and Logs screens open with Today · This week · This month · This year · All chips (default: this month), the choice is remembered, and the filtering happens in the database — a growing archive does not slow the screen down. “Clear” on the Logs screen first says how many records will be deleted, then asks for confirmation.

1.5.11 install folder

13.09.2026

  • Setup now remembers the folder the product is actually installed in. Until now the installer offered C:\ERP\TcmbKur every single time. If the product lived somewhere else, pressing Enter created a second copy and pointed the service at it; because the settings, the licence and the logs stayed behind in the old folder, the product came up after the update as if it had never been configured. Setup now finds the folder from three sources in order — the running service's registration, its own installation record, and the auto-updater's settings — and offers what it found, naming the source it came from.
  • Moving the folder tells the operator what will happen first. When a folder other than the existing installation is typed in, setup warns that the settings (connection details), the licence and the logs are not moved, and asks for confirmation. Silent installs (--sessiz) skip the question and apply the choice.
  • The installation record lives outside the application folder. The folder is recorded under %ProgramData%\ERP\Kurulum\TCMBKUR in a file only administrators and SYSTEM can write, so an update that refreshes the application folder does not erase it. If the record cannot be written the installation still succeeds — it only warns.
  • The installer's Properties window now reads 1.5.11 as well. The first 1.5.11 package of the day still carried File version 1.5.10.0; the package was corrected and re-published the same day. A 1.5.11 file downloaded before 12:45 on 13.09.2026 carries the older digest; moving to 1.5.12 settles that too.

1.5.10 network access

12.09.2026

  • Network access is now a single choice during setup. The access step of the setup wizard offers two options: This server only (the default) and Local network. Choosing “Local network” makes the product do both jobs — it opens the address the service listens on and adds the Windows firewall rule itself; switching back to “This server only” removes that rule again. The addresses other machines should use (http://<server-IP>:5230) are listed on screen as clickable links.
  • “I opened the firewall rule and still cannot connect” is over. Network access has two legs: the rule being open and the service listening on a network address. Until now the product listened only on 127.0.0.1, so even a hand-made rule left remote browsers timing out. Both legs are now set up by the product and shown on the same screen.
  • The firewall rule is opened for the Domain/Private profiles only. No port is opened on a public network profile — a service that carries passwords over plain HTTP does not belong on a guest network. While open to the network, the warning that sign-in passwords travel unencrypted is shown on screen as well; the lasting fix is to put the product behind a TLS-terminating reverse proxy.
  • Setup steps still run only from the server itself, even when the product is open to the network. The endpoints that ask for SQL credentials, set the administrator password and install the service are refused when called from the network (and the attempt is logged). Sign in on the server and use http://127.0.0.1:5230/setup/index.html.

1.5.9 network & activation

12.09.2026

  • A warning e-mail now arrives before the term expires. Starting one week before the end date, a reminder is sent once a day to the sender address in your e-mail settings: which server, which date, how many days are left and what to do. Once the term lapses, rates are not written to Logo. The reminder stops by itself once the term is renewed.
  • Log noise cleaned up. On installations with no internet access the product stopped writing an hourly "cannot be reached" record; when access really is required, the reason is written as a single warning line that says what to do.
  • Internet access to the TCMB can be tested from the screen. The Test internet access button on Settings → Fetch tries https://www.tcmb.gov.tr with the product's own network stack and reports the result with its duration — so the reason behind "it opens in Edge but the application cannot fetch" becomes visible on screen (a browser uses the system proxy, a service does not).
  • The proxy setting lives inside the product. Address, user name and password are entered on Settings → Fetch; the password is stored encrypted and never returns to the screen. The setting takes effect the moment it is saved — no service restart — and the test button uses the same setting.
  • Signing in from other machines on the network works. Users connecting with the server's local IP address got stuck on the sign-in screen; the session cookie is now carried over plain HTTP as well. Recovery and first-time setup steps still open only from the server itself, by design.

1.5.8 Database Mail

12.09.2026

  • SQL Server itself can now send the e-mail. If a Database Mail profile is already running on your server, the Fetch the profiles on SQL Server button on the e-mail step lists them; pick one and that profile sends the notifications — the SMTP password is never asked for, because it already lives on the server and stays there. You can also import the profile's server, port and sender details into the SMTP fields and continue the classic way; on that path you have to type the password yourself. The one permission needed: membership of DatabaseMailUserRole in msdb for the SQL user the product connects with. If you will send e-mails with attachments, also give a folder SQL Server can read.
  • A fresh installation no longer produces "errors". On an installation that had not been configured yet, the Logs screen filled up with red records nobody had caused: the service tried to fetch rates as soon as it started and failed because the Logo mapping was not in place. The automatic fetch now waits until setup is complete, and failures coming from the network, the bulletin or activation are written as a warning that says what to do, not as an error. If the operator presses Run now, the result — errors included — is still shown to them.
  • The activation screen goes through a single decision point. It is no longer possible for the screen to show a red state above and a green one below; when the operation is accepted, the screen refreshes itself.

1.5.7 setup wizard

12.09.2026

  • The setup wizard no longer stalls on the activation step. On a customer machine that step could not open, and while failing it silently took the whole wizard down — so the operator believed the e-mail step was the one blocking them, when the defect was in fact on the next step. The step now opens even with no configuration at all.
  • The e-mail settings step says on screen that it is optional. The step carries an Optional badge, and when no field is filled in the forward button reads Skip and continue. E-mail settings can also be entered after installation from the Settings screen.
  • If a screen fails, the application stays up. An unexpected error no longer leaves a dead page: the menu, top bar and version footer stay in place, and the screen shows a short explanation, a Retry button and an error id. The same id appears on the matching record in the Logs screen — one code is enough when you contact support.

1.5.6 setup checks

12.09.2026

  • Setup now checks the connection explicitly. The wizard has a Test connection button, and the answer on screen is one of three: Not tested, Connection verified (with the time and how long it took) or Could not connect. Changing the server, the database or the user resets that mark — a stale green never misleads you. You move on only with a verified connection.
  • The error tells you what to do. Instead of the raw SQL Server sentence you get the action: "Windows authentication was refused, switch to a SQL user", "the server could not be reached, is TCP/IP and port 1433 open", "the database name is wrong or the user has no permission".
  • Setup keeps its own log. Every attempt, discovery and step is written to logs\kurulum-<day>.log, and the wizard's "Setup log" panel shows the latest lines on screen. One file is enough when support asks. Passwords are never written to it.
  • The downloaded file states its version. The installer arrives with its own icon and carries the version number in its name and in the file properties; no more "TcmbKurKurulum (1).exe, (2).exe…" in the Downloads folder.

1.5.5 sign-in recovery

11.09.2026

  • There is now a way out if you cannot sign in. The I cannot sign in link on the login screen creates the administrator account, or resets its password, from the server console. The security boundary is explicit: it only works from the server itself (127.0.0.1), a remote request does not even learn that the screen exists, and every reset is written to the log.
  • The first password is now printed on screen. The last wizard step asks for the administrator password; left empty, the account opens with admin / admin and must be changed at first sign-in. The completion screen states the credentials and opens the management panel.
  • The setup screen no longer raises false alarms on an installed system. Opening that address after installation shows an "Installation complete" card instead of the wizard; the red Unexpected token '<' lines and the bogus failure list are gone.
  • The product always starts in Turkish. Even when the browser is configured for English, the interface opens in Turkish; the language changes only by your own choice.

1.5.4 setup screen

11.09.2026

  • The setup screen no longer fails silently in old browsers. If the server's default browser is Internet Explorer, the page explains what to do instead of appearing blank and unresponsive: it preselects the address and shows the command that opens it in a modern browser.
  • The stored SQL password is preserved. The password box is empty when the wizard is reopened; leaving it empty keeps the stored password (the password is never sent to the browser). If the server or the user name is changed, the stored password is not reused.
  • Misleading "Error" badges on a successful installation are gone. The setup screen served by the service now hides the service-management actions it does not offer instead of raising errors.

1.5.3 single-file installer

11.09.2026

  • Installation is a single file. Download TcmbKurKurulum.exe and double-click it — no unzipping, no PowerShell, no "unblock file" step. The zip and script route remains for support.
  • Download links are stable: /dl/kurulum always serves the latest version, /dl/kurulum/<version> the archive.
  • The settings file inside the package is now born unconfigured, so a fresh installation always opens the setup wizard.

1.5.2 installation never stalls

11.09.2026

  • Installation no longer stops halfway. If the Logo database cannot be determined, the files are copied and the setup wizard opens instead of the installer failing.
  • SQL Server authentication is supported end to end (user name + password); the password never appears on the command line and is written to the settings file with machine-scoped protection.
  • The wizard suggests the Logo folder from the registry. LOGODB.CFG is encrypted, so the server and database cannot be read from it — they are scanned or asked for, and the screen says so.

1.5.1 choices during setup

11.09.2026

  • The installer now asks instead of guessing: the target folder, the SQL server and the Logo database are picked from a list.
  • Local SQL Server instances are discovered automatically; the selected database is validated before it is used, so a wrong name surfaces where it is typed.
  • -Sessiz option for unattended installation.

1.5.0 one database

10.09.2026

  • The separate TcmbKur database is gone. Application tables live in the customer's own Logo database as dbo.TCMBKUR_*; backup, migration and permissions follow that single database.
  • Servers without internet access: activation can be completed on these installations too; the steps are explained on screen.
  • The user guide gained a screenshot gallery with a lightbox.

1.4.1

10.09.2026

  • The product and documentation site went live at tcmbkur.erp.tr; the package and the installation guide download from stable links.
  • Quote and contact addresses updated.
  • The installation guide was expanded: all six wizard steps are now documented with screenshots.

1.4.0 activation

10.09.2026

  • Activation happens by itself. The customer is not asked to type a key or a code; the step is completed by following the guidance on screen.
  • Activation concerns only the step that writes to Logo; fetching rates, the panel and updates work independently of it.
  • The customer installation package was simplified; installation is a single script.

1.3.0 automatic updates

09.09.2026

  • Automatic updates are live. The updater lives outside the application under %ProgramData%\ErpUpdate\TCMBKUR and is triggered by a task that runs daily at 03:20 with SYSTEM rights.
  • A package is announced with a signed manifest; no file changes before its size and SHA-256 are verified.
  • After installation there is a health gate: is the service running, does /healthz return 200, does the reported version match the target. If it fails, the previous version is restored and the bad package is quarantined.
  • The database, appsettings.Production.json, keys, logs and listen-url.txt are preserved across updates.
  • Activation and the device identity moved outside the application folder — an update no longer drops the identity.

1.2.1

09.09.2026

  • The contact address became configurable.
  • The wording on the status screen was clarified.

1.2.0 activation

09.09.2026

  • Connection to the ERP online services (lisans.erp.tr). The decision arrives signed and is cached.
  • A network outage does not lock the application; it keeps working on the last valid cached decision.
  • Activation state became visible in the panel.

Before 1.2.0

The core capabilities of the product were built in these releases:

AreaWhat it brought
TCMB bulletin calendarFinding the correct bulletin for a target day, walking back when there is none, and early-fetch protection (no writing of incomplete data before 15:30).
Logo mappingMapping RATES1..4 to foreign-exchange and banknote buying/selling, target-day selection, and the 16:00 check report.
Local installation modelThe application runs as a Windows service on the customer's own machine; rate data never leaves it.
Setup wizardSix-step installation: database, Logo connection, fetching rates, e-mail, activation and summary.

Release policy

  • Security patches are independent of activation state. Every installation receives the patch.
  • The schema only grows. A new version can read old data; a destructive change is spread across three releases.
  • There is no downgrade. The only way back is the automatic rollback of a failed update.
  • Every release's number and date appear in the footer of the panel and in the /healthz response, from the same source.