Skip to main content

Changelog

Updates, changes, and improvements at Retool.

Refer to the stable and edge release notes for detailed information about self-hosted releases.

3 posts tagged with "Hardened images"

Updates related to the rollout of hardened self-hosted images.

View All Tags

Deprecation of preinstalled libraries in custom authentication JavaScript steps

As part of our continued efforts to keep Retool secure and reduce vulnerabilities, Retool is deprecating several preinstalled third-party libraries, such as jsonwebtoken, crypto-js, moment, and uuid, currently available in custom authentication JavaScript steps. Retool plans to remove these libraries from cloud and self-hosted instances in Q2 2027.

If your custom authentication steps use any of these libraries, you can migrate to Node.js built-in equivalents, such as crypto and Buffer, well ahead of the removal date. Migrating before then avoids any disruption to your authentication flows.

Only REST API, GraphQL, OpenAPI, and gRPC resources that use Custom Auth with a JavaScript step that loads a preinstalled library are affected. JavaScript steps that use Node.js built-in modules, such as crypto, continue to work without changes.

Who is affected​

Any customers who have resources that use Custom Auth as its authentication method and one of its JavaScript steps loads a preinstalled library. Custom authentication steps that only use Form (modal), API Request, or Define a variable steps aren't affected, and neither are JavaScript steps that don't call require().

Deprecation of Windows Authentication for Microsoft SQL Server resources

As part of our continued efforts to keep Retool secure and reduce vulnerabilities, hardened images become the default for self-hosted images starting in Q2 2027. As a result, Retool is deprecating Windows Authentication for Microsoft SQL Server resources. This deprecation also applies to Kerberos authentication for Microsoft SQL Server, which relies on Windows Authentication.

Hardened images are intentionally minimal and don't include the additional third-party libraries and utilities that Windows Authentication relies on. Microsoft SQL Server resources with Connect using Windows Auth enabled will eventually stop working, so plan to migrate before your resources are affected.

Who is affected​

This change only affects self-hosted organizations with Microsoft SQL Server resources that have Connect using Windows Auth enabled.

Continued hardening of Retool's infrastructure

Retool previously announced the adoption of hardened deployment images, starting with the backend service. A hardened code-executor image is now available, built in the same manner as the backend image.

These images are used by Retool for its cloud-hosted platform and are available for self-hosted organizations to adopt. Eventually, all images used by Retool will be hardened.

Hardened images are built on a minimal, tightly controlled base to improve supply-chain security and reduce the attack surface. They also benefit from a smaller, more tightly curated set of included software, which reduces the risk of security vulnerabilities.

Retool is continuing to work on new and existing hardened images. Over time, this means some existing features and bundled libraries will no longer be supported in their current form. If a feature or library will no longer be available, or if a change requires updates to your current configuration, Retool will share this information in a changelog post with specific information and any relevant migration guidance.

Each changelog post will provide as much advance notice as possible so that you have time to review and implement any changes that may be needed.