Self-hosted Retool stable release 4.0
Release notes for the Self-hosted Retool 4.0 stable release.
Retool releases a version on the stable channel each quarter. A stable release is generally four versions behind the cloud-hosted version at the time.
Preparation and testing of a stable version occurs approximately four weeks prior to its release. Stable releases are rigorously tested before they are published. As the release cycle is less frequent, administrators can more easily maintain and upgrade deployments.
Retool supports each stable release for six months. During this time, Retool will release patch updates that contain bug fixes or security updates. Patch updates do not contain functionality changes and can be applied more quickly than performing a full version upgrade.
After six months, a stable release is considered deprecated. You can continue using a deprecated release but it will no longer receive updates. At this time, you should upgrade to the latest stable release.
Retool provides versioned product documentation for supported stable releases. When browsing Retool Docs, use the version dropdown menu in the navbar to switch to a relevant version.
Self-hosted Retool 4.0
Latest releaseCurrently supported
| Release | Released | Digest | |
|---|---|---|---|
| First | 4.0.0 | Jun 11, 2026 | sha256:673b37866382cf034fc4ea4b4e005b5f1405bd36107e6e905d81e30b1f781b68 |
| Latest | 4.0.7 | Jul 23, 2026 | sha256:2be4280bc16dc9a604a4fc597fb7bb47c9aa847da6ee1aad3a86042bee5bf05d |
Major changes in this release
New features, significant changes, and any actions required when upgrading.
| Type ↕ | Change ↑ |
|---|---|
| new | Analytics for Retool Workflows Monitor run counts, failure rates, latency, and resource usage across your workflows. |
| new | Build apps via MCP Build Retool apps using an MCP-connected AI coding agent. |
| new | Configurable memory limits for workflow code execution Configure memory limits for workflow code execution at the org or workflow level. |
| new | Hardened images in stable channel Security-hardened Docker images are now available for stable channel deployments. |
| new | MCP server for Retool MCP server for managing your Retool organization and users. |
| new | Python runtime version selector Select the Python runtime version for your workflow, with support for Python 3.14. |
| new | React app import Import existing React applications into the new Retool app builder. |
| new | Redesigned Workflows landing page The Workflows landing page has a new design, now available for all self-hosted deployments. |
| new | Retool 4.0 database migration Self-hosted Retool 4.0 runs an automatic database migration to prepare for Role-Based Access Control. |
| new | Retool 4.0 upgrade FAQ Common questions about upgrading to Retool 4.0. |
| new | Retool's new app builder Retool's new React-based app builder is now available on self-hosted. |
| new | Source control for apps Source control support for apps in the new app builder. |
| new | Update notifications for self-hosted admins Self-hosted admins now see a banner when a new Retool release or patch update is available. |
| new | View audit logs across spaces Organization admins can view audit logs across all spaces from a single page. |
| 14 changes | |
Patch release notes
Bug fixes, improvements, and other incremental updates across all patch releases in this release.
| Type | Description |
|---|---|
| 4.0.710 changes↑ | |
| added | Added environment variables to configure workflow loop timeouts on self-hosted deployments. [#80834] |
| fixed | Fixed intermittent workflow execution failures caused by nsjail remount races on Kubernetes. [#81457] |
| fixed | Fixed a foreign key error when deploying workflows through source control. [#81607] |
| fixed | Fixed excessive logging when large workflow runs exceeded the block result fetch cap. [#81571] |
| fixed | Fixed an infinite loop when calling utils.setUrlParameters() with unchanged values. [#81296] |
| fixed | Fixed REST API URL templates dropping mid-string colons in path expressions. [#81164] |
| fixed | Fixed detection of dropped Agent pubsub connections that caused silent failures. [#81182] |
| fixed | Fixed Vertex AI queries not working in workflows. [#80264] |
| fixed | Fixed module UUID validation before Source Control page saves. [#80506] |
| security fix | Fixed a host header injection vulnerability in the Google SSO OAuth redirect flow. [#81541] |
| 4.0.69 changes↑ | |
| added | Added accessible names and descriptions to Modal dialogs for screen reader support. [#79622] |
| fixed | Fixed Python runtime version not being preserved in workflow subflows and multi-step functions. [#80670] |
| fixed | Fixed raw Redis queries failing in workflows. [#77930] |
| fixed | Fixed classic apps created before version 4.0 rendering with a 1200px max width instead of fullscreen. [#80787] |
| fixed | Fixed the OpenAI handshake test attempting to validate response-only models with the Chat Completions endpoint. [#80718] |
| fixed | Fixed a WCAG accessibility violation by removing keyboard focus from the app canvas. [#79705] |
| improved | Improved Radio Group component accessibility with keyboard navigation and focus indicators. [#79929] |
| improved | Improved the agent in the app builder to show a specific error message when capacity is unavailable. [#80816] |
| security fix | Patched hono, js-yaml, aiohttp, nodemailer, tar, protobufjs, protobufjs-cli, launch-editor, webpack-dev-server, ws, dompurify, and tmp dependencies. Fixes CVE-2026-54286, CVE-2026-54287, CVE-2026-54288, CVE-2026-54289, CVE-2026-54290, CVE-2026-53550, CVE-2026-54273, CVE-2026-54274, CVE-2026-54275, CVE-2026-54276, CVE-2026-54277, CVE-2026-54278, CVE-2026-54279, CVE-2026-54280, GHSA-268h-hp4c-crq3, GHSA-r7g4-qg5f-qqm2, GHSA-wqvq-jvpq-h66f, CVE-2026-53655, CVE-2026-48712, CVE-2026-54269, CVE-2026-53632, CVE-2026-9595, CVE-2026-48779, CVE-2026-49458, CVE-2026-49459, CVE-2026-49978, GHSA-76mc-f452-cxcm, GHSA-cmwh-pvxp-8882, GHSA-gvmj-g25r-r7wr, GHSA-vxr8-fq34-vvx9, and CVE-2026-44705. [#80980] |
| 4.0.51 change↑ | |
| added | Added binary and form-data body support to the REST API resource's rawRequest method. [#79045] |
| 4.0.47 changes↑ | |
| added | Added keyless authentication for S3, GCS, and Azure blob storage using the deployment's workload identity. [#80546] |
| fixed | Fixed group membership updates removing claimed or expired user invites. [#80450] |
| fixed | Fixed copying published app links failing silently in Firefox. [#80200] |
| fixed | Fixed OAuth login redirecting to the wrong page for published apps. [#79972] |
| fixed | Fixed the new app builder failing to capture the latest commit in snapshots for protected apps. [#80189] |
| fixed | Fixed new app builder threads locking up when frontend hooks leaked into git commits. [#79904] |
| changed | Enabled theme packages for all self-hosted deployments. [#78670] |
| 4.0.38 changes↑ | |
| added | Added folder_id to the POST /api/v2/resources and PATCH /api/v2/resources/{id} endpoints for creating and moving resources between folders. [#80026] |
| fixed | Fixed published apps prompting reauthorization for OAuth resources that were never connected. [#79765] |
| fixed | Fixed app publishing failures in the new app builder caused by an incompatible gnutar version. [#80096] |
| fixed | Fixed agents incorrectly appearing in Workflow Analytics statistics and sidebar. [#80006] |
| fixed | Fixed the login redirect for published apps that use OAuth resources. [#79968] |
| security fix | Updated qs to 6.15.2 to patch a denial-of-service vulnerability. Fixes CVE-2026-8723. [#78615] |
| security fix | Hardened access controls on the source control git server. [#79818] |
| security fix | Enforced per-app permission checks on source control git server endpoints. [#79681] |
| 4.0.24 changes↑ | |
| fixed | Fixed the Retool-managed Temporal enrollment flow for self-hosted Workflows deployments - the enrollment banner and update deployment wizard are now accessible again. [#79454] |
| fixed | Fixed intermittent preview loading failures in the Retool Apps builder caused by transient connection errors to the preview sandbox. [#79846] |
| fixed | Fixed a crash on the Commit and push button in the source control panel when the button was in a disabled state. [#79631] |
| security fix | Fixed a high severity security issue in Retool Forms. Blocked the $queryResponse system query from the public query endpoint, preventing anonymous callers from reading all prior form submissions. [#79546] |
| 4.0.17 changes↑ | |
| fixed | Fixed MCP app creation defaulting to the organization root folder, causing a 403 error for non-admin users without root folder write access. [#79525] |
| fixed | Fixed MCP app-generation websocket connections to route through the internal sandbox proxy, preventing connection failures when AGENT_EXECUTOR_PROXY_INGRESS_DOMAIN is configured on self-hosted deployments. [#79534] |
| fixed | Fixed an Agents crash when the agent received a tool call with an unrecognized tool name. [#79549] |
| fixed | Fixed MCP TypeScript resource execution failing because esbuild was not externalizing all required dependencies during bundling. [#79505] |
| fixed | Fixed an infinite retry loop in Agents where a failed tool call would be retried indefinitely instead of being surfaced as an error. [#79458] |
| fixed | Fixed null-origin links in published apps causing navigation failures on self-hosted deployments with a custom base URL. [#79393] |
| fixed | Fixed the MCP service using RETOOL_BACKEND_URL for internal API calls instead of the correct internal service address. [#79476] |
| 4.0.0447 changes↑ | |
| security fix | Fixed a security vulnerability where users with only Use permission on resources could execute self-defined queries by calling the /preview endpoint directly. [#71633] |
| security fix | Fixed an IDOR vulnerability in the Agents API that allowed mismatched agent and save IDs to return unauthorized data. [#71540] |
| added | Added OAuth 2.0 auto-refresh support for Retool AI resources using custom AI provider endpoints. [#70792] |
| added | Added support for custom headers on REST API OAuth 2.0 token exchange and refresh requests. [#71521] |
| added | Added DBCONNECTOR_POOL_CACHE_MAX_SIZE environment variable to configure the database connection pool cache size limit (default: 600). [#71573] |
| added | Added POST /api/library/folders endpoint to create Library folders via the API. [#71546] |
| added | Added PATCH /api/library/folders/{folderId} endpoint to rename Library folders via the API. [#71583] |
| added | Added DELETE /api/library/folders/{folderId} endpoint to delete Library folders via the API. [#71629] |
| added | Added PATCH /api/library/functions/{functionId}/move endpoint to move Backend Functions to a different Library folder via the API. [#71621] |
| added | Added PATCH /api/library/functions/{functionId} endpoint to rename Backend Functions and update their descriptions via the API. [#71844] |
| added | Added public REST API support for creating and configuring Kafka, MCP, SNS, and SQS resources. [#71658] |
| fixed | Fixed removing an NPM package from a workflow resetting the setup script and discarding all other imported libraries. [#70719] |
| fixed | Fixed a "subflow not found" error that occurred when running a Backend Function immediately after renaming it. [#71426] |
| fixed | Fixed a user.get is not a function error in audit trail middleware when the user object was a plain JavaScript object. [#71485] |
| fixed | Added AWS RDS Proxy CA certificates to the Retool image to enable TLS connections through RDS Proxy. [#71503] |
| fixed | Fixed deep-linked workflow run IDs being cleared before the run history was fully loaded. [#71520] |
| fixed | Fixed a page crash when searching the gRPC resource schema browser. [#71548] |
| fixed | Fixed the Query Playground not prompting users to confirm discarding unsaved changes when clicking New. [#71550] |
| fixed | Fixed the code editor hover tooltip showing unknown as the return type for setValue() and other async widget API methods. [#71560] |
| fixed | Fixed a 403 error on GET /api/roles when a user had the external scope but external apps were disabled. [#71571] |
| fixed | Fixed basic auth failures when using Azure DevOps repositories in Source Control in headless containers. [#71601] |
| fixed | Fixed audit trail logging failures caused by a user.get is not a function error. [#71608] |
| fixed | Fixed an empty tooltip appearing when hovering over transformers and variables in the app structure panel. [#71612] |
| fixed | Fixed the guided REST editor allowing resources to be saved after the spec URL was changed without reloading the spec. [#71628] |
| fixed | Fixed two bugs in the Amazon Knowledge Base update modal: Setup Required always appearing, and the modal opening for all knowledge bases instead of only the selected one. [#71645] |
| fixed | Fixed duplicate folders appearing in apps when multiplayer is enabled. [#71646] |
| fixed | Fixed a race condition in multipage apps that caused the app runtime to initialize twice on page load. [#71664] |
| fixed | Fixed an error when running a Retool AI vector context query using AWS Bedrock when no matching embeddings were found. [#71705] |
| fixed | Fixed Show on mobile and Show on desktop settings not persisting after a page refresh. [#71715] |
| fixed | Fixed enum values not appearing in module dropdown inputs. [#71724] |
| fixed | Fixed the guided REST editor freezing when switching back to a query backed by a large OpenAPI spec. [#71754] |
| fixed | Fixed the Last Published date not appearing in the Agents index page table view. [#71816] |
| fixed | Fixed dynamic template substitution in REST API form data key names, enabling {{expression}} syntax in form data key fields. [#71834] |
| fixed | Fixed components inside containers not rendering correctly for other collaborators when dragging components in or out of containers in multiplayer. [#71835] |
| fixed | Fixed misaligned tab underlines on the Settings > Groups details page. [#71919] |
| improved | Improved workflow block result display to show per-block truncation banners when results exceed the size limit, instead of a single run-level error that hid all block results. [#71014] |
| improved | Improved Assist to support building and editing Repeatable components such as lists, grids, and galleries. [#71130] |
| improved | Added Assist access scopes to the All Users role by default for new organizations. [#71552] |
| improved | Removed the assistMultipageEnabled feature flag, making multipage support in Assist available by default. [#71410] |
| improved | Updated the GET /api/library/functions API endpoint to return creator names instead of user IDs. [#71463] |
| changed | Restricted app editor access to users with the Builder seat type. [#71775] |
| added | Added bearer token authentication for Snowflake resources. [#72227] |
| added | Added Python 3.14 support for Python queries and transformers. [#72421] |
| added | Added filterBy support for Google Sheets read operations. [#72117] |
| added | Added describe and describeGlobal operations for Salesforce resources. [#72146] |
| added | Added static database role support for Vault secrets manager configuration. [#72264] |
| added | Added web grounding configuration support for Google Gemini resources. [#72060] |
| added | Added support for GPT-5.4 model with 1,050,000 token context window for AI resource queries. [#72480] |
| fixed | Fixed REST API URL parameter parsing truncating values containing = characters. [#72626] |
| fixed | Fixed SAML SSO login failures for identity providers whose X.509 certificates contain large OID arc values. [#72515] |
| fixed | Fixed utils.copyToClipboard failing in Safari browser. [#72128] |
| fixed | Fixed Slack resource markdown mode toggle not bypassing HTML conversion. [#72040] |
| fixed | Fixed Edit Resource Modal stacking issues in workflows. [#72510] |
| fixed | Fixed passwordless magic link URLs to use custom domain when configured. [#72228] |
| fixed | Fixed Vault database engine to correctly handle 404 errors. [#72435] |
| changed | Updated Kimi K2 model to automatically use Kimi K2.5. [#72594] |
| changed | Changed audit log behavior to omit query content for improved security. [#72207] |
| improved | Improved REST API guided configuration to handle deepObject parameter style. [#72053] |
| improved | Improved REST API configuration to validate OpenAPI specification URLs. [#72103] |
| deprecated | Deprecated Deepseek 3.2 and Kimi 0905 AI models. [#72299] |
| security fix | Updated fast-xml-parser to address CVE-2026-25896 XSS vulnerability and CVE-2026-26278 DoS vulnerability. [#71952] |
| security fix | Updated tar dependency to address CVE-2026-26960 and CVE-2026-29786 path traversal vulnerabilities. [#72733] |
| security fix | Updated path-to-regexp dependency to address CVE-2024-45296 ReDoS vulnerability. [#72730] |
| security fix | Updated underscore dependency to address CVE-2026-27601 DoS vulnerability. [#72736] |
| security fix | Updated semver dependency to address CVE-2022-25883 ReDoS vulnerability. [#72735] |
| security fix | Updated nodemailer dependency to address CVE-2025-14874 DoS vulnerability. [#72734] |
| security fix | Updated basic-ftp dependency to address CVE-2026-27699 vulnerability. [#72616] |
| security fix | Updated jspdf dependency to address CVE-2026-25535 vulnerability. [#72315] |
| security fix | Updated minimatch dependency to address CVE-2026-26996 ReDoS vulnerability. [#72335] |
| security fix | Updated serialize-javascript to address GHSA-5c6j-r48x-rmvq code injection vulnerability. [#72537] |
| added | Added OpenAPI spec change detection to the guided REST API editor, automatically applying non-breaking changes and displaying a warning banner for breaking changes. [#73131] |
| added | Added Python version configuration to workflow language settings. [#72290] |
| improved | Improved the Agents page to show inline error banners instead of replacing the page when the agents API fails. [#73072] |
| improved | Improved Assist in Ask mode to include database schema tools. [#73032] |
| fixed | Fixed Assist's REST API query tool to correctly handle existing key-value pair body formats. [#73164] |
| fixed | Fixed Assist always using the fallback model instead of the user-configured model. [#73154] |
| fixed | Fixed frame resolution incorrectly dropping when a folder node is selected in the component tree. [#73143] |
| fixed | Removed empty description column from the workflows table on the workflows index page. [#73137] |
| fixed | Fixed OAuth nonce handler firing twice in some authentication flows. [#73132] |
| fixed | Fixed /api/verifyEmail endpoint crashing on malformed input. [#73081] |
| fixed | Fixed agents metadata API timeouts that caused the Agents page to load slowly. [#73068] |
| fixed | Fixed image upload to enforce LLM provider size limits and compress oversized images automatically. [#73066] |
| fixed | Fixed Date Picker component failing to parse date-fns format tokens PP, PPP, PPPP, and G. [#73040] |
| fixed | Fixed periodic query checkbox unchecking when the interval input is cleared by backspacing. [#73030] |
| fixed | Fixed loop blocks incorrectly showing 'No Resource Selected' when a function runner is selected. [#73025] |
| fixed | Fixed collaborative editing errors when applying document updates. [#72970] |
| fixed | Fixed Snowflake OAuth infinite reauth loop caused by stale refresh token expiration not persisting after token refresh. [#72838] |
| fixed | Fixed workflow memory limit error message to show the configured WORKFLOW_MEMORY_LIMIT_MBS value instead of a hardcoded number. [#72837] |
| fixed | Fixed OAuth consent page showing generic icons for Databricks and Slack resource types. [#72719] |
| fixed | Fixed guided REST API editor to prevent adding duplicate Server Variable keys. [#72600] |
| fixed | Fixed workflow blocks to validate payload size against RETOOL_CLIENT_MAX_BODY_SIZE and return a descriptive error for oversized payloads. [#72041] |
| security fix | Upgraded flatted to patch a DoS vulnerability in JSON parsing. Fixes CVE-2026-32141. [#73168] |
| security fix | Upgraded langchain from 0.0.106 to 0.3.37 to address a prompt injection vulnerability in the workflow executor. Fixes GHSA-r399-636x-v7f6. [#72894] |
| security fix | Upgraded hono to 4.10.2 to address a JWT audience claim validation bypass. Fixes CVE-2025-62610. [#72892] |
| security fix | Upgraded markdown-it to 14.1.1 to address a ReDoS vulnerability via crafted markdown input. Fixes GHSA-38c4-r59v-3vqw. [#72889] |
| security fix | Upgraded bn.js to 5.2.3 to patch a timing side-channel vulnerability in Snowflake SDK cryptographic operations. Fixes GHSA-378v-28hj-76wf. [#72885] |
| security fix | Upgraded ip to 1.1.9 to patch a ReDoS vulnerability via crafted IP strings. Fixes GHSA-78xj-cgh5-2h22. [#72884] |
| security fix | Patched immutable from 3.7.6 to 3.8.3 to fix Prototype Pollution in draft-js and rc-editor transitive dependencies. Fixes CVE-2026-29063. [#72874] |
| security fix | Fixed SAML error response to no longer reflect request body or headers, preventing PII disclosure. [#71873] |
| security fix | Fixed approval workflow API to enforce organization ownership checks on execution updates, preventing unauthorized cross-org modifications. [#71781] |
| added | Added public API support for Azure Identity authentication in REST API resources. [#73540] |
| added | Added pinch-to-zoom support for Camera component in mobile apps. [#73271] |
| added | Added Python 3.14 custom library support for queries and workflows. [#73159] |
| fixed | Fixed Assist code validation failing when accessing properties on unknown types. [#73497] |
| fixed | Fixed non-builder users being able to clone pages into published folders. [#73448] |
| fixed | Fixed periodic query interval defaulting to 5000ms when the checkbox is unchecked. [#73420] |
| fixed | Fixed OAuth callback configuration failures raising 500 errors instead of 400 errors. [#73414] |
| fixed | Fixed Stack component width serialization using percentage-based widths instead of pixel-based widths. [#73408] |
| fixed | Fixed app loading errors when using invalid _historyOffset query parameter values. [#73281] |
| fixed | Fixed page name duplication on creation to prevent unique constraint errors. [#73264] |
| fixed | Fixed autocomplete suggestions closing the function editor dialog when clicked. [#73250] |
| fixed | Fixed List View Container component auto height failing to render after page refresh. [#73209] |
| fixed | Fixed unnecessary tooltip displaying on Publish button. [#73450] |
| changed | Breaking Change: Changed delete group member API endpoint parameter name from userSid to userId. [#73512] |
| improved | Improved Assist wireframe matching to ignore coordinates when component heights change dynamically. [#73526] |
| improved | Improved Settings navigation to land users on the Requests tab when accessing /settings/users#requests. [#73463] |
| improved | Improved Phone Number Input component to use image-based flag icons on Windows instead of emoji for cross-platform consistency. [#73285] |
| improved | Improved Assist layout guidance for repeatable components and updated tool chip to show before/after property changes. [#73160] |
| improved | Improved PostgreSQL query performance by implementing custom streaming without server-side cursors. [#70600] |
| security fix | Hardened runtime sandbox. [#73311] |
| security fix | Fixed Set Default Theme endpoint missing an authorization check. [#73208] |
| security fix | Fixed email webhook handler to validate DKIM/SPF against actual email content instead of the unvalidated request body. [#72806] |
| security fix | Fixed a security vulnerability in the Source Control branch merging implementation. [#73174] |
| security fix | Updated sequelize from 6.31.0 to 6.37.8 to patch CVE-2026-30951. [#73179] |
| security fix | Updated axios and jsPDF to patch CVE-2026-25639 and CVE-2026-31938. [#73165] |
| security fix | Updated npm dependencies to patch vulnerabilities in sha.js, dompurify, nanoid, react-router, and diff. [#73207] |
| security fix | Updated npm dependencies to patch vulnerabilities in hono, undici, jpeg-js, and minimist. [#73293] |
| security fix | Updated npm dependencies in the workflows environment to patch security vulnerabilities. [#73422] |
| security fix | Updated npm dependencies in the sandbox environment to patch security vulnerabilities. [#73419] |
| security fix | Updated Python dependencies in the sandbox environment to patch security vulnerabilities. [#73421] |
| added | Added audit logging for failed query executions. [#73892] |
| added | Added name_contains filter to the GET /api/v2/apps endpoint for filtering apps by name. [#74154] |
| added | Added POST /api/v2/users/{userId}/logout endpoint to terminate user sessions and return OIDC RP-initiated logout URL. [#73524] |
| added | Added No filtering or sorting search mode to Select, Multiselect, Listbox, and Multiselect Listbox components to preserve server-side ordering. [#73758] |
| added | Added {{ current_user }} as a supported template string in the resource editor. [#73822] |
| added | Added Azure Blob Storage resource to the public API. [#73889] |
| added | Added support for multiple deployments in Azure AI queries. [#73592] |
| added | Added ability to create a new app from app version history. [#73613] |
| fixed | Fixed JDBC schema introspection for IBM DB2 and Hive databases. [#73520] |
| fixed | Fixed workflow source control deployment failures caused by createdBy metadata in protected trigger data. [#73990] |
| fixed | Fixed PDF Viewer component infinite loop when cancelling the password prompt for password-protected PDFs. [#73866] |
| fixed | Fixed Number Input form validation for minimum and maximum constraints, and re-triggers validation when min/max properties change. [#73624] |
| fixed | Fixed Stack component widths being incorrectly converted to percentages on app reload. [#74077] |
| fixed | Fixed agent execution errors when using Claude Opus 4.6+ models. [#74066] |
| fixed | Fixed component drag-and-drop positioning when moving components from canvas into Stack components. [#73878] |
| fixed | Fixed race condition causing JavaScript errors when navigating between apps with the openApp event handler. [#74087] |
| fixed | Fixed AI query streaming errors not displaying in the UI. [#73612] |
| fixed | Fixed OAuth2 flow to allow cursor:// protocol redirect URIs for Cursor IDE connections. [#74151] |
| fixed | Fixed a bug where components could not be moved from the Stack component to the canvas. [#73828] |
| changed | Marked the guided REST API as generally available and added a deprecation notice to the OpenAPI connector. [#73694] |
| changed | Updated OpenAI GPT-4 model replacement from gpt-4-turbo to gpt-4.1. [#74065] |
| security fix | Fixed SSRF bypass vulnerability in image proxy endpoint. Fixes CVE-2025-57814. [#73530] |
| security fix | Updated webpack to 5.104.1 to address security vulnerabilities. Fixes CVE-2025-68157 and CVE-2025-68458. [#74019] |
| security fix | Updated CPython standalone to 3.10.20+20260310 in the Python sandbox. Fixes CVE-2025-8869, CVE-2026-1703, and CVE-2025-47273. [#74005] |
| security fix | Updated ajv, markdown-it, and flatted in the workflow code executor. Fixes CVE-2025-69873, CVE-2026-2327, and CVE-2026-33228. [#74004] |
| security fix | Updated Python packages in sandbox environments to address security vulnerabilities. [#73824] |
| security fix | Updated JavaScript packages in sandbox and workflow environments to address security vulnerabilities. [#73823] |
| security fix | Removed deprecated request package. Fixes CVE-2023-28155. [#73513] |
| security fix | Updated backend npm packages to address security vulnerabilities. Fixes CVE-2025-25288. [#73503] |
| security fix | Updated @smithy/config-resolver to address GHSA-6475-r3vj-m8vf. [#73496] |
| security fix | Removed Cargo.lock from the backend Docker image to address security vulnerabilities. [#73994] |
| security fix | Removed dead hoek dependency and updated coveralls. Fixes CVE-2020-36604 and CVE-2018-3728. [#74024] |
| security fix | Upgraded samlify to v2.12.0 with XPath injection protection and XXE-safe XML parsing. [#74359] |
| security fix | Fixed a vulnerability allowing a user's TOTP secret to be overwritten or 2FA disabled without verifying the existing 2FA code. [#73915] |
| security fix | Fixed an IDOR vulnerability allowing authenticated users to access image blobs belonging to a different organization. [#73441] |
| security fix | Fixed a cross-organization IDOR vulnerability allowing authenticated users to send tool approval, auth approval, and terminate signals to agent runs belonging to other organizations. [#71878] |
| security fix | Fixed personal access tokens being restored without re-validating scopes against current user permissions, and added audit logging for token revocation and deletion. [#73537] |
| security fix | Upgraded fast-xml-parser to v5.5.6 in code-executor sandbox environments. Fixes CVE-2026-33036. [#73785] |
| security fix | Upgraded serialize-javascript to v7.0.5. Fixes CVE-2026-34043. [#74161] |
| security fix | Upgraded node-forge from v1.3.3 to v1.4.0. Fixes CVE-2026-33891, CVE-2026-33894, and CVE-2026-33895. [#74162] |
| security fix | Upgraded brace-expansion to address a zero-step DoS vulnerability. Fixes CVE-2026-33750. [#74166] |
| security fix | Added picomatch overrides to address a ReDoS vulnerability. Fixes CVE-2026-33671. [#74164] |
| security fix | Upgraded handlebars to v4.7.9 in sandbox environments. Fixes CVE-2026-33937. [#74253] |
| added | Added audit logging for workflow events including renames, trigger configuration changes, releases, protection toggles, and custom URL path changes. [#74149] |
| added | Added a DELETE /api/v2/workflows/:workflowId endpoint to the public REST API for deleting workflows programmatically. [#73879] |
| added | Added a link in the help menu to navigate to the local per-instance API reference. [#74393] |
| added | Added plan-tier badges and a plan filter to the per-instance /reference API documentation page. [#73628] |
| fixed | Fixed OAuth authentication failures being silently swallowed when the DBCS pipe was enabled, causing errors to go unreported. [#74584] |
| fixed | Fixed XML query responses returning undefined for rawXml and parsedXml properties when the DBCS pipe was enabled. [#74329] |
| fixed | Fixed Query Library showing raw error data as a successful result instead of displaying the error when the DBCS pipe was enabled. [#74298] |
| fixed | Fixed a crash in the DBCS XML response transformer by replacing xml2js with fast-xml-parser. [#74500] |
| fixed | Fixed a 500 error on the PATCH /api/resources/names/:resourceName endpoint caused by a foreign key constraint violation when creating a new environment-specific resource. [#74655] |
| fixed | Fixed a 500 error in the save query endpoint when the data parameter was missing, null, or not a valid JSON object. [#74646] |
| fixed | Fixed queries in modules failing to execute on page load due to a race condition between model lookup and eager query trigger. [#74482] |
| fixed | Fixed current_user.groups returning a literal string instead of a group array in apps using custom auth flows. [#74239] |
| fixed | Fixed an issue where setting Table row height to dynamic programmatically did not properly enable dynamic row heights. [#74062] |
| fixed | Fixed the Table component's Regenerate Columns feature only detecting columns from the first 10 rows of data. [#72039] |
| fixed | Fixed an error with mobile apps that caused screens to stop rendering. [#74635] |
| fixed | Fixed parent workflows showing a generic failure message instead of the actual error when a child workflow fails. [#74173] |
| fixed | Fixed the branch reset modal accepting unknown branch names that could not be matched to a real remote branch. [#74180] |
| fixed | Fixed the legacy Retool AI resource becoming uneditable when version control was locked. [#73771] |
| fixed | Fixed saving changes to a Retool Database resource configuration throwing a badData error due to incorrect deep equality comparison for nested option objects. [#73381] |
| fixed | Fixed a memory leak in the self-hosted proxy by automatically cleaning up aborted upstream socket connections. [#72210] |
| fixed | Fixed a false-positive "Workflow Backend Egress" health check appearing on the Code Executor card in the Services Debugging page. [#74185] |
| fixed | Fixed the Secrets Manager test connection endpoint to require admin permissions, and updated the UI to use the correct current API endpoint. [#74375] |
| fixed | Fixed system-scoped roles that are required for direct sharing from being deleted. [#74388] |
| fixed | Fixed the permission assignment modal displaying a resource's internal name instead of its display name on the Roles and Permissions settings page. [#74454] |
| fixed | Fixed multiplayer showing a persistent loading state when a WebSocket upgrade fails due to a permanent authentication error, now immediately displaying the error. [#74273] |
| fixed | Fixed mobile app query failures clearing rawData when the raw query payload was available. [#74437] |
| fixed | Fixed blank screens, missing version info in settings, and JSON parsing errors on Android. [#74364] |
| improved | Improved app availability when multiplayer fails to connect. Apps now fall back to single-user editing instead of showing a blocking overlay. [#74481] |
| improved | Improved error messaging when an app edit session fails due to authorization, now showing the specific error instead of a generic message. [#74280] |
| improved | Improved the Resources page to show a toast notification when a user attempts to access a resource they do not have permission to view. [#73987] |
| improved | Extended time duration parsing to support compound strings such as '2m10s' or '1m30s500ms' in addition to single-unit values. [#74277] |
| improved | Increased the multiplayer sync message batch size from 10 to 50 to reduce message overhead during collaborative editing. [#74344] |
| improved | Clarified the wording of the truncated block results banner in the workflow Run history log viewer. [#74439] |
| added | Added ServiceNow resource type for self-hosted deployments. [#74983] |
| added | Added commit signing support for GitLab source control integrations. [#74969] |
| added | Enabled ProtoJSON format for gRPC resource queries on self-hosted deployments. [#74945] |
| added | Added support for the resource indicator parameter (RFC 8707) in OAuth 2.0 resource connections. [#74286] |
| added | Added image generation support for Google Gemini resources using gemini-3.1-flash-image-preview and gemini-3-pro-image-preview models. [#74383] |
| added | Added CockroachDB resource type with connection string autofill support. [#74003] |
| added | Added Jump to Today button to the Timeline component toolbar. [#74938] |
| added | Added query redaction setting to the audit log configuration in organization settings. [#74974] |
| added | Added GCS support for workflow block result storage via WORKFLOW_BLOCK_STORAGE_LOCATION=gcs. [#74079] |
| added | Added SNOWFLAKE_VALIDATION_DISABLE_HEARTBEAT environment variable for Snowflake connection management on self-hosted deployments. [#75033] |
| fixed | Fixed app loading issue that prevented clicking on apps from the home page. [#75096] |
| fixed | Fixed OAuth2 resources to require re-authentication when not already in an authenticated state. [#74926] |
| fixed | Fixed an issue with components that had dynamic heights. [#74792] |
| fixed | Fixed race condition in the OpenAPI query editor that could overwrite user-edited parameter values. [#74770] |
| fixed | Fixed multipage app navigation for page URL slugs that included leading slashes. [#74875] |
| fixed | Fixed app saves being dropped when multiplayer mode falls back to single-user mode. [#74905] |
| improved | Improved MongoDB resource to surface value too long errors as user-visible errors. [#74628] |
| improved | Improved Table component column width tooltip to accurately describe proportional distribution behavior. [#74991] |
| security fix | Upgraded scikit-learn from 1.2.1 to 1.5.0 in the code executor sandbox environment. Fixes CVE-2024-5206. [#75118] |
| security fix | Upgraded yaml package to address a denial-of-service vulnerability. Fixes CVE-2026-33532. [#75114] |
| security fix | Upgraded http-proxy-middleware in frontend to address a cross-site scripting vulnerability. Fixes CVE-2024-21536. [#75107] |
| security fix | Upgraded Node.js from 22.22.0 to 22.22.2 in Docker images. Fixes CVE-2026-21637. [#74262] |
| security fix | Upgraded esbuild in code executor and workflow code executor to address Go standard library vulnerabilities. [#74984] |
| security fix | Applied security patches for node-forge, minimatch, and brace-expansion dependencies. [#74880] |
| security fix | Removed unauthenticated /workflows/sendTestEmail endpoint to prevent potential abuse. [#74915] |
| added | Added a Clear action to the Google Sheets integration to clear a range of cells. [#75335] |
| added | Added a timescale selector to the Timeline component for Week, Month, Quarter, and Year views. [#74940] |
| added | Added audit log events for app theme creation, updates, deletion, and branding setting changes. [#75129] |
| added | Added an authentication prompt when opening an agent chat with no messages. [#75035] |
| added | Added the offline assets tab and Offline Asset PDF source option to all mobile app settings. [#75230] |
| fixed | Fixed AWS SigV4 signing to derive host from request URL, resolving AccessDenied errors. [#75354] |
| fixed | Fixed S3 query Max Keys validation incorrectly rejecting numeric values. [#75323] |
| fixed | Fixed Snowflake connection test to correctly validate connections and preserve failure details. [#75349] |
| fixed | Fixed MongoDB SCRAM-SHA-256 authentication failures with the upgraded MongoDB 4.17 driver. [#75405] |
| fixed | Fixed 'Failed to Open App' error after navigating to a new app via a custom login page. [#74871] |
| fixed | Fixed query reordering failures in apps with modules during simultaneous multiplayer editing. [#75417] |
| fixed | Fixed the app editor remaining in multiplayer mode when previewing a previous app version. [#75018] |
| fixed | Fixed UI issues for agents with view-only permissions, including false error banners. [#75265] |
| fixed | Fixed Android mobile app rendering issues including clipped modals and invisible text in alerts. [#75023] |
| fixed | Fixed iOS camera and barcode scanner not remounting correctly after navigation. [#75022] |
| fixed | Fixed Camera and Image Input preview UIs in the mobile app to respect device safe areas. [#75198] |
| fixed | Fixed JavaScript query timeouts being incorrectly reported as out-of-memory errors. [#75452] |
| fixed | Fixed the resource usage count for AI resources to include Assist, Ask AI, and Vector instances. [#75345] |
| improved | Introduced a warning when reconfiguring a Retool Database that existing app and query references will break. [#75453] |
| improved | Introduced a warning when deleting an AI resource that is configured for Assist or Ask AI. [#75325] |
| improved | Enabled gRPC connection pooling by default, improving performance for gRPC resource queries. [#75357] |
| improved | Enabled structured REST API query mode by default for resources with an OpenAPI spec configured. [#75295] |
| improved | Improved SQL query streaming performance by batching model updates until the stream completes. [#71114] |
| security fix | Blocked JNDI injection in JDBC connection strings to prevent remote code execution via DB2 driver. [#75194] |
| security fix | Upgraded axios to 1.15.0 to fix a SSRF vulnerability in NO_PROXY handling. Fixes CVE-2025-62718. [#75188] |
| security fix | Upgraded protobufjs to fix a gRPC schema code injection vulnerability. Fixes CVE-2026-41242. [#75528] |
| security fix | Upgraded d3-color to 3.1.0 to fix a ReDoS vulnerability in color parsing functions. [#75430] |
| security fix | Upgraded hono and nodemailer to fix SSE injection and static file security vulnerabilities. [#75347] |
| security fix | Disabled JavaScript evaluation in the PDF Viewer component to prevent script execution. Fixes CVE-2024-4367. [#75098] |
| security fix | Upgraded webpack-dev-server to 5.2.3 to fix host header bypass vulnerabilities. Fixes CVE-2025-30359 and CVE-2025-30360. [#75113] |
| security fix | Upgraded path-to-regexp to fix multiple ReDoS vulnerabilities. [#75106] |
| security fix | Upgraded lodash to 4.18.1 to fix a prototype pollution vulnerability. Fixes CVE-2026-4800. [#75138] |
| security fix | Upgraded the tar package in workflow code execution to fix a path traversal vulnerability. Fixes CVE-2026-23745. [#75237] |
| security fix | Applied SSRF protection to vector URL crawling to prevent DNS rebinding attacks. [#75286] |
| security fix | Upgraded Java backend dependencies to address multiple security vulnerabilities. [#74790] |
| security fix | Upgraded Tomcat in the Java database connector to 10.1.54 to fix security vulnerabilities. [#75346] |
| added | Added ClickHouse resource integration for connecting to ClickHouse databases. [#74103] |
| added | Added gpt-image-2 model support for OpenAI image generation. [#75653] |
| added | Added Claude Opus 4.7 model to the AI resource model registry. [#75413] |
| improved | Improved the organization of beta resource integrations. [#75520] |
| changed | Changed default OpenAI image generation model to gpt-image-1-mini. [#75656] |
| fixed | Fixed Google Sheets resource memory usage and added abort signal support. [#75309] |
| fixed | Fixed Google Sheets resource intermittent 'Premature close' errors under concurrent load. [#75809] |
| fixed | Fixed OAuth token refresh to sanitize blank custom header rows. [#75741] |
| fixed | Fixed memory leak in database connector stream consumer on premature client close. [#75738] |
| added | Added gpt-5.5 model support for Assist and Agents. [#75824] |
| added | Added retoolContext.secrets support for workflow non-resource blocks in self-hosted deployments. [#75141] |
| improved | Improved wrapped integration connectors to use mini OpenAPI specs for reduced latency and fresher operation metadata. [#75501] |
| improved | Improved AI resource performance by skipping unnecessary schema fetch calls. [#75880] |
| fixed | Fixed document parsing action visibility in AI resource query dropdowns. [#75834] |
| fixed | Fixed AI credit balance returning zero allocation for self-hosted instances with valid license features. [#75900] |
| fixed | Fixed Invoke Agent workflow block to use published release instead of draft when executing full workflow runs. [#75807] |
| fixed | Fixed permission assignment object picker to display module icon for module pages instead of generic app icon. [#75788] |
| fixed | Fixed Claude Haiku 4.5 model resolution by updating to versioned name claude-haiku-4-5-20251001. [#75906] |
| security fix | Fixed DOM-based XSS vulnerability in legacy custom component iframe endpoints. [#75885] |
| fixed | Fixed query execution for newly created Google Drive resources. [#76257] |
| fixed | Fixed Google Drive query editor crash when accessing documentation links. [#76266] |
| fixed | Fixed duplicate Re-auth buttons in Agents backend functions for OAuth resources. [#76331] |
| fixed | Fixed Loop block batch settings carrying over between queries. [#74907] |
| fixed | Fixed schema viewer for Google Drive and other wrapped integrations to display endpoints from the mini-spec manifest. [#75926] |
| fixed | Fixed bug where editorSidebarOpen was undefined in app editor. [#75577] |
| fixed | Fixed /settings/retool-ai page to tolerate stale or malformed AI provider resources without crashing. [#76211] |
| fixed | Fixed Assist handshake to use the AI provider resources selected in AI settings for managed-key detection. [#76248] |
| fixed | Fixed Sprig survey iframe blocking clicks outside the survey region. [#76182] |
| fixed | Fixed RetoolAI OAuth gating to work independently of the provider resource refactor. [#76212] |
| fixed | Fixed Java database connector process isolation issues, including file descriptor limits and a null pointer exception in logging. [#76189] |
| fixed | Fixed Java database connector Unix domain socket failures by removing rlimit_as from nsjail process isolation. [#76280] |
| fixed | Fixed parent widget ID resolution in Layout Compiler to correctly migrate global header components. [#76150] |
| fixed | Fixed mobile app RetoolDB template to require write access to retool_db. [#76223] |
| fixed | Fixed inverted Save and Next button labels in the RBAC Add group modal. [#76166] |
| changed | Changed default for Share credentials between users to false for Salesforce, Google Analytics, Google Search Console, Slack (OpenAPI), HubSpot, Front, and legacy Google Sheets OAuth resources. [#76326] |
| improved | Improved Make protected workflow branch banner to be larger and use a warning color. [#76285] |
| improved | Improved OAuth error handling in Assist and Agents to surface authentication prompts instead of generic errors. [#75768] |
| improved | Upgraded MongoDB driver to 4.17.2, resolving saslprep warning spam in dbconnector logs. [#76209] |
| improved | Improved new agent creation to automatically select the first available AI provider resource instead of defaulting to OpenAI. [#75860] |
| improved | Improved List View scrolling behavior by making scroll-thrashing prevention the default. [#76052] |
| improved | Improved Chart v2 (Plotly) component stability by making the dimension-stabilizer wrapper the default. [#76049] |
| improved | Improved OpenAPI integration manifests to display operation descriptions in the query editor and schema viewer. [#76183] |
| improved | Improved error handling to capture Anthropic reliability errors mid-stream. [#76294] |
| improved | Improved workflow aggregate usage performance by setting lock and idle transaction timeouts and capping retries. [#76210] |
| improved | Improved AI number generation to discourage thousands separators for identifier numbers. [#73248] |
| improved | Improved page navigation synchronization between iframe and browser for published apps. [#75913] |
| removed | Removed per-workflow CPU limits from the Code Executor resource limits system. Memory limits remain unchanged. [#76231] |
| security fix | Updated seccomp security profile to block the AF_ALG socket family. Fixes CVE-2026-31431. [#76235] |
| security fix | Fixed cross-tenant data leak in MotherDuck connector by embedding authentication token in JDBC URL. [#76977] |
| security fix | Fixed JDBC resource caching to prevent connection pool reuse across unsaved resources. [#76834] |
| security fix | Applied SSRF-safe DNS lookup compatibility with undici's autoSelectFamily. [#76842] |
| security fix | Applied SSRF validation for AI provider base URLs. [#76042] |
| security fix | Replaced timing-vulnerable string comparisons with constant-time comparisons in authentication paths. [#75920] |
| security fix | Patched CSV formula injection vulnerability in user export functionality. [#75905] |
| security fix | Updated axios to 1.15.2, patching multiple authentication bypass, SSRF, prototype pollution, and CRLF injection vulnerabilities. Fixes CVE-2026-42033, CVE-2026-42034, CVE-2026-42035, CVE-2026-42036, CVE-2026-42037, CVE-2026-42038, CVE-2026-42039, CVE-2026-42040, CVE-2026-42041, CVE-2026-42042, CVE-2026-42043, CVE-2026-42044, and CVE-2026-42264. [#76715] |
| security fix | Updated Java database connector dependencies for security improvements in Netty, Spring Boot, Spring Framework, and PostgreSQL driver. [#76722] |
| security fix | Patched postcss XSS via unescaped style tags in CSS stringify output. Fixes CVE-2026-41305. [#76719] |
| security fix | Patched hono bodyLimit bypass and JSX HTML injection vulnerabilities. Fixes CVE-2026-44455 and CVE-2026-44456. [#76717] |
| security fix | Patched uuid buffer bounds check in v3/v5/v6. Fixes CVE-2026-41907. [#76712] |
| security fix | Updated @anthropic-ai/sdk to patch insecure default file permissions in local filesystem memory tool. Fixes CVE-2026-41686. [#76713] |
| security fix | Patched simple-git remote code execution vulnerability. Fixes CVE-2026-6951. [#76718] |
| security fix | Patched smol-toml denial of service via documents with thousands of commented lines. Fixes GHSA-v3rj-xjv7-4jmq. [#76616] |
| security fix | Patched basic-ftp client-side DoS vulnerabilities. Fixes CVE-2026-41324 and CVE-2026-44240. [#76716] |
| security fix | Updated ws library to patch DoS via excessive HTTP headers. Fixes CVE-2024-37890. [#75553] |
| security fix | Updated markdown-it for security improvements in rendering. [#75554] |
| fixed | Fixed Secrets Manager error handling to display toast notifications instead of clearing all configurations on update or delete failures. [#76783] |
| fixed | Fixed 404 errors when using forward slashes in Secrets Manager configuration names by properly URL-encoding path components. [#76785] |
| fixed | Fixed REST API query editor retaining stale OpenAPI state when switching between resources, modes, or operations. [#76474] |
| fixed | Corrected Claude 4.6 and 4.7 token limits to reflect 1 million context window for Anthropic and Bedrock AI resources. [#76589] |
| fixed | Fixed validation schema mismatch for Google AI resource service account authentication. [#76674] |
| fixed | Fixed MongoDB resource authentication errors by updating the mongodb510 driver. [#76559] |
| added | Added environment variable to override default maximum SSH connection limit for PostgreSQL resources. [#73976] |
| changed | Migrated Retool-managed DeepSeek AI model from deprecated V3 to V3.1 endpoint. [#76453] |
| changed | Changed serverless function query execution timeout to match workflow query timeout. [#76800] |
| improved | Updated Snowflake SDK to version 2.4.0 to reduce socket hang-up errors. [#76628] |
| improved | Migrated REST API connector to native fetch implementation for improved performance. [#76470] |
| improved | Improved Workflow Analytics page performance by using pre-aggregated hourly statistics. [#75465] |
| security fix | Patched pnpm from 10.16.1 to 10.28.2 to address multiple path traversal, command injection, and lockfile integrity vulnerabilities. Fixes CVE-2025-69262, CVE-2025-69263, CVE-2025-69264, CVE-2026-23888, CVE-2026-23889, CVE-2026-23890, CVE-2026-24056, and CVE-2026-24131. [#76615] |
| security fix | Patched fast-uri to 3.1.2 to address path traversal and host confusion. Fixes CVE-2026-6321 and CVE-2026-6322. [#76911] |
| security fix | Patched fast-xml-parser to 5.7.3 in mobile Lambdas. [#76912] |
| security fix | Patched hono to 4.12.18 to address CSS declaration injection, JWT date validation, and cache poisoning issues. Fixes CVE-2026-44457, CVE-2026-44458, and CVE-2026-44459. [#76913] |
| security fix | Sanitized internal API resource metadata from public MCP resources info responses. [#76928] |
| security fix | Restricted sandbox require to ce-libraries only to prevent escape via Node modules. [#76954] |
| security fix | Blocked dynamic import() in code sandbox via ESM loader hook. [#76989] |
| security fix | Validated and rate-limited unauthenticated public app abuse reports. [#77022] |
| security fix | Patched protobufjs to 7.5.6 and @protobufjs/utf8 to 1.1.1 to address code injection and DoS vulnerabilities. Fixes CVE-2026-44288, CVE-2026-44289, CVE-2026-44290, CVE-2026-44291, CVE-2026-44292, CVE-2026-44293, and CVE-2026-44294. [#77139] |
| security fix | Patched protobufjs-cli to 1.2.1 to fix OS command injection and code injection from crafted schema names. Fixes CVE-2026-42290 and CVE-2026-44295. [#77141] |
| security fix | Added canUserChangeGridAccess check to grid ACL endpoints to prevent unauthorized enumeration. [#77148] |
| security fix | Restricted grid ACL endpoints to groups only when userListAccess is disabled, preventing user enumeration. [#77164] |
| security fix | Excluded vulnerable pac4j from hive-jdbc and hive-service. [#77259] |
| security fix | Patched io.opentelemetry to 1.62.0. Fixes CVE-2026-45292. [#77314] |
| added | Added an extended thinking toggle for OpenAI models in Agents advanced configuration. [#74662] |
| added | Added rawAuthorizationScheme, Google serviceAccount, and session auth types to REST API resources via the Retool API. [#76858] |
| added | Added HOST_RESERVED_MEMORY and related environment variables to fine-tune js_executor Memory Budget Manager. [#76930] |
| added | Added Google Drive API documentation link to the query editor. [#77048] |
| added | Added space-specific usage charts for AI credits and workflow runs. [#77151] |
| added | Added cross-space audit log explorer for root org admins. [#77207] |
| fixed | Hid the Create folder button for users without edit access to the root workflow folder. [#75893] |
| fixed | Updated query caching so resources with user-specific parameters do not share results across users. [#76037] |
| fixed | Supported the Tab key when adding invite emails in the share modal. [#76504] |
| fixed | Added missing agent models to the analytics registry. [#76551] |
| fixed | Fixed initial prompt suggestions briefly persisting between tabs in Assist. [#76631] |
| fixed | Disposed gRPC inner cache entries on eviction to release pooled clients. [#76684] |
| fixed | Passed experimentsId to dbconnector process isolation flag checks for deterministic evaluation. [#76781] |
| fixed | Resolved deprecated AI models in handleAIQueryExecution for accurate billing. [#76784] |
| fixed | Fixed workflow import for users with individual resource permissions. [#76854] |
| fixed | Validated missing JDBC connection strings to return a controlled error instead of crashing. [#76883] |
| fixed | Raised waitForPort timeout for embedded test servers. [#76899] |
| fixed | Stabilized MultiplayerContext waitForSynced test flake. [#76901] |
| fixed | Allowed non-admin users with manage_source_control permission to set release manifests. [#76922] |
| fixed | Handled empty usage service license keys. [#76923] |
| fixed | Auto-completed secrets in the Query Library resource form. [#76947] |
| fixed | Used per-request timeout for undici TCP connect in REST API queries. [#76951] |
| fixed | Fixed test setup race condition for bastion. [#76953] |
| fixed | Ensured audit trails queries route to the audit trails database instead of the application database. [#76956] |
| fixed | Sent usage analytics requests as POST instead of GET. [#76967] |
| fixed | Adjusted Assist chat scrollbar position. [#76999] |
| fixed | Fixed REST API queries using native fetch by aligning undici Content-Type inference and decompression. [#77003] |
| fixed | Displayed external users without an email correctly in groups settings. [#77011] |
| fixed | Gated billing usage tab on the NamedSeats plan feature. [#77013] |
| fixed | Rounded AI credits usage metrics to the nearest integer. [#77014] |
| fixed | Scoped billing metrics to the manage billing permission. [#77017] |
| fixed | Raised billing chart tooltip above the selector to fix overlap. [#77020] |
| fixed | Used the plugin-aware resource registry for editor-type lookups. [#77029] |
| fixed | Forwarded child process stdio to logger after WarmProcPool checkout. [#77036] |
| fixed | Used the manifest's serverUrl to build URLs for unlisted REST operations. [#77046] |
| fixed | Fixed seatUsage to count external users and exclude pending invites. [#77062] |
| fixed | Hid usage chart over time when filtering on a space. [#77074] |
| fixed | Added line-buffering and structured log parsing to HttpProxyCache stdio handlers. [#77085] |
| fixed | Soft-failed the permissions endpoint on orphaned role grants to avoid 500 errors. [#77091] |
| fixed | Fixed the Agent Chat component displaying "Agent" instead of the agent name for users with use-only access. [#77098] |
| fixed | Fixed a workflow editor crash for non-editor users on protected workflows. [#77110] |
| fixed | Added missing model pricing families for GPT-3.5-turbo, GPT-4-turbo, Claude 3.5 Sonnet/Haiku, and GPT-5. [#77114] |
| fixed | Gated personal folder ID load check behind the personalAppFoldersEnabledForOrg experiment. [#77117] |
| fixed | Capped pagination limit at 100 in MCP list tools. [#77121] |
| fixed | Propagated NODE_EXTRA_CA_CERTS to process-isolated dbconnector children. [#77133] |
| fixed | Fixed empty config variables in retoolContext when changing environments. [#77153] |
| fixed | Fixed V2 resource permissions for Retool AI resource on org creation. [#77177] |
| fixed | Added landing page to V2 RBAC group settings. [#77211] |
| fixed | Scoped child-space billing usage metrics to the correct space. [#77241] |
| fixed | Added all Google Drive scopes from OAS to the resource settings. [#77243] |
| fixed | Stopped DBCONNECTOR_BODY_PARAMS_TYPE_ERROR warning spam on Google Drive queries. [#77268] |
| fixed | Fixed Retool AI resource permissions at org creation. [#77304] |
| improved | Auto-wired htmlFor, id, aria-describedby, aria-invalid, and aria-required on Field components for improved accessibility. [#76639] |
| improved | Centralized MCP pagination LIMIT_SCHEMA with a token-conscious default of 10. [#76734] |
| improved | Fixed universal access enumeration and removed precompute overhead in V2 permissions path. [#76836] |
| improved | Broadened REST API getaddrinfo ENOTFOUND error classification to user errors. [#77008] |
| improved | Parallelized sequential async calls in the permissions module. [#77026] |
| improved | Dropped redundant RESOURCE_TYPE_KEYWORDS precompute in the resource catalog. [#77032] |
| improved | Eagerly spawned replacement processes in WarmProcPool to keep the pool filled. [#77033] |
| improved | Dropped includeChildObjects in getGroupPagesV2, getGroupWorkflowsV2, and getGroupScreensV2 for faster permission checks. [#77059] |
| improved | Parallelized folder fetches in the getPermissions V2 path for better permissions performance. [#77118] |
| improved | Omitted empty value parameters from OAuth URLs. [#77143] |
| improved | Surfaced JS Executor out-of-capacity errors with clearer messaging. [#77226] |
| improved | Reduced code editor latency by replacing createAnalysisProject with a singleton scope. [#77262] |
| improved | Improved performance of /api/organization/permissions by consolidating queries in PermissionsBundleDao. [#77264] |
| changed | Updated the Sentry Frontend SDK to v8. [#77158] |
| removed | Removed the secretsManagerMultiConfig flag and the legacy secrets UI. [#76609] |
| removed | Removed the sanitizeCustomAuthScope feature flag after rollout. [#76714] |
| removed | Removed the Python upgrade feature flag for workflows after rollout. [#76924] |
| removed | Removed the dbConnLambdaV3 feature flag, making the V3 Lambda integration the only path. [#76983] |
| removed | Removed the useJsExecutor feature flag and code_executor routing branches after JS Executor migration. [#76990] |
| removed | Removed the /executeServerlessFunctionV2 endpoint and evalServerExecutor from code_executor. [#76991] |
| removed | Removed unlaunched resource credentials endpoints. [#77131] |
| added | Added AGENT_SANDBOX_* environment variable aliases for AGENT_EXECUTOR_* on self-hosted instances. [#77836] |
| added | Added auto-refresh support for Retool AI OAuth client-credentials tokens. [#77946] |
| added | Added support for the Gemini 3.5 Flash model in Google Gemini and Vertex AI resources. [#77972] |
| fixed | Fixed OpenAPI v3 spec imports defaulting to an incorrect base URL when the servers array is missing. [#74266] |
| fixed | Fixed FIDO2 passkey authentication failing with ECDSA signature parsing errors after the 3.393 dependency update. [#77851] |
| fixed | Fixed Amazon S3 workflow block result cleanup failing with malformed XML errors. [#77922] |
| fixed | Fixed vector crawl workflow failures caused by missing database access objects in automated requests. [#77925] |
| fixed | Fixed vector crawl URL queue not clearing after reaching the visited URL limit. [#77927] |
| fixed | Fixed Retool AI authentication banner incorrectly appearing for client-credentials OAuth failures. [#77976] |
| fixed | Fixed managed AI provider proxy authentication on self-hosted instances by adding a placeholder key. [#78002] |
| changed | Changed the app share modal to no longer require external domain setup. [#77942] |
| security fix | Updated ws to patch an uninitialized memory disclosure vulnerability. Fixes CVE-2026-45736. [#77570] |
| security fix | Updated brace-expansion to patch a denial-of-service vulnerability where large numeric ranges bypass the max protection. Fixes CVE-2026-45149. [#77571] |
| security fix | Updated protobufjs to patch a denial-of-service vulnerability via unbounded recursive JSON descriptor expansion. Fixes CVE-2026-45740. [#77732] |
| security fix | Updated idna to patch an internationalized domain name vulnerability. Fixes CVE-2026-45409. [#77733] |
| security fix | Updated commons-configuration2 to patch an XML external entity vulnerability. Fixes CVE-2026-45205. [#77830] |
| 493 changes | |