Self-hosted Retool Edge release 4.70
Release notes for the Self-hosted Retool 4.70 edge release.
Releases on the Edge channel occur weekly. Each release occurs one week after the equivalent release for cloud-hosted Retool.
Edge releases are available for organizations that want the latest features or to use private beta functionality. Retool recommends most organizations use Stable releases unless you have a specific need for Edge releases and can keep your deployment up-to-date.
Retool supports only the most recent release on the Edge channel. As Edge releases are weekly, bug fixes and improvements are included in the next release. All previous releases are then considered deprecated.
Retool's main documentation site reflects the latest Edge release. Since Edge updates weekly and only the most recent release is supported, the docs you're already browsing apply to this release — there's no separate version to switch to.
Self-hosted Retool 4.70
Latest releaseCurrently supported
Edge release notes
Bug fixes, improvements, and changes in this release.
| Type ↑ | Description ↕ |
|---|---|
| 4.70.040 changes↑ | |
| added | Added support for using legacy OpenAPI resources in the new app builder. [#84723] |
| added | Added GPT 6 Sol, GPT 6 Luna, and GPT Image 2.5 models for AI queries. [#85232] |
| added | Added Claude Opus 5.5 model for AI queries and the new app builder. [#85763] |
| added | Added a confirmation prompt before discarding unsaved access policy changes on a resource. [#85435] |
| added | Added Amazon SQS as a supported resource for backend functions in the new app builder. [#86176] |
| added | Added Apache Kafka as a supported resource for backend functions in the new app builder. [#86180] |
| added | Added Elasticsearch as a supported resource for backend functions in the new app builder. [#86182] |
| added | Added support for chrome-extension:// origins in custom Content Security Policy settings. [#86893] |
| added | Added backend function output and error logs to the debug console in the new app builder. [#86933] |
| fixed | Fixed source control dropping default AI model selections from apps and Query Library entries. [#85563] |
| fixed | Fixed workflow libraries reappearing after deletion and remaining installed in runs. [#85851] |
| fixed | Fixed false 'is not defined' warnings for existing components and queries in the JavaScript code editor in classic apps. [#86319] |
| fixed | Fixed JavaScript executor proxy requests continuing after the sandbox disconnects, which could rerun queries. [#86429] |
| fixed | Fixed source control deployments failing when a protected resource declared a suffixed symbol. [#86557] |
| fixed | Fixed the permissions migration leaving admin groups without folder access scopes. [#86598] |
| fixed | Fixed the new app builder ignoring OpenAPI operations that have no operationId. [#86664] |
| fixed | Fixed the new app builder caching non-spec responses from OpenAPI spec URLs and never fetching them again. [#86632] |
| fixed | Fixed email auto-join assigning the wrong seat type when External Apps is turned on. [#86910] |
| fixed | Fixed DELETE /appTheme/:id returning 500 instead of 400 for a non-numeric theme ID. [#85757] |
| fixed | Fixed POST /api/validate-nonce returning 500 instead of 400 for a non-string nonce. [#86194] |
| fixed | Fixed workflow release endpoints returning 500 instead of 400 for a malformed release ID. [#86235] |
| fixed | Fixed POST /api/grid/retooldb/runMigration returning 500 instead of 404 when the environment has no Retool DB resource. [#86250] |
| fixed | Fixed table preview in access policies returning 500 instead of 404 when the queried table does not exist. [#86258] |
| fixed | Fixed the new app builder thread messages endpoints returning 500 instead of 400 for invalid message content. [#86265] |
| fixed | Fixed POST /api/requestAccessToOrg returning 500 instead of 4xx for a malformed email or orgId. [#86647] |
| fixed | Fixed creating a branch from a missing Azure Repos branch returning 500 instead of 404. [#86899] |
| fixed | Fixed function-approval-status returning 500 instead of 404 for a commit that is not in the app repository. [#86900] |
| fixed | Fixed requests hanging when the backend cannot lease a database connection from the pool. [#87013] |
| fixed | Fixed workflow blocks being reported as successful when their query fails, so retry policies now run. [#86921] |
| improved | Improved job queue shutdown and cancellation handling when the new app builder uses pg-boss. [#86452] |
| improved | Improved S3 storage resilience to DNS outages by caching DNS results for up to one hour. [#86538] |
| improved | Improved reliability by retrying user permission queries after transient database connection resets. [#86773] |
| improved | Improved backend memory use by canceling in-flight query work when a client disconnects. [#87051] |
| changed | Changed access policy rows to use a status switch instead of Activate and Deactivate buttons. [#85433] |
| changed | Changed MongoDB find, aggregate, and listCollections queries to stream results by default. [#86926] |
| security fix | Fixed Athena resource credentials being shared with other AWS resources in the same worker. [#86202] |
| security fix | Enforced current_user spoofing checks on cached query results to stop cross-user cache hits. [#86349] |
| security fix | Fixed a row-level security bypass caused by template expressions split across query clauses. [#86398] |
| security fix | Limited non-admin embed tokens to adding external users to groups the token owner is in. [#86439] |
| security fix | Fixed the Code Executor reading sandbox configurations that package build code could modify. [#86542] |
| 40 changes | |