This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+7 more
Summary
AI summarySSO domain DNS verification (admin‑only) adds security hardening.
Full changelog
🔌 Pieces
- fix(gmail): default Find Email to latest emails when no filters set (#13124) @sanket-a11y
- chore(savvycal): bump version to 0.1.0 (#13114) @onyedikachi-david
- feat(savvycal): add i18n, consolidate triggers, correct event types, and add team/link filters (#12233) @bst1n
- feat(piece): add Chess.com community piece (#13018) @FionnHughes
- feat(parallel): add Parallel piece with web research actions (#13098) @sanket-a11y
- feat(descript): add Descript integration with actions and triggers (#13030) @hugh-codes
- feat(deftform): add Deftform piece with 7 actions and 1 polling trigger (#13037) @cumonvip1
- feat(pieces): add Proxycurl piece (#12149) @Harmatta
- fix(snowflake): drop invalid session:role-any scope from OAuth flow (#13061) @AhmadTash
- fix(microsoft-teams): make dropdown loaders resilient to throttling a… (#13060) @AhmadTash
- feat: add Avian as AI provider (#11447) @avianion
- feat(baserow): add Upsert Row and Upload File actions (#12982) @bst1n
- feat(baserow): restore JWT auth + Row Event trigger + auto-create select options (#12964) @bst1n
- feat(mistral): add ocr action and support for cloudflare AI gateway (#13028) @AdamSelene
- feat(service-now): expand actions and triggers, add knowledge/email/c… (#13043) @AhmadTash
- chore(qawafel): update logo URL (#13054) @sanket-a11y
- feat(Qawafel): add Qawafel piece with order, product, invoice and mer… (#12923) @sanket-a11y
- fix(microsoft-outlook): update logo URL (#13053) @kishanprmr
- fix(slack): use user token for usergroups.users.update (#13011) @sanket-a11y
- feat(pieces): add ko-fi piece (#12795) @WilliamZero9
- fix(attio): normalize record values and add Get Record action (#13026) @kishanprmr
- feat(ninjapipe): add NinjaPipe CRM piece (#12981) @cumonvip1
- feat(aiprise): add environment switch sandbox/production) to auth (#13025) @sanket-a11y
- fix(drupal): remove redundant peerDependencies causing publish pipeline failure (#13021) @kishanprmr
- fix(drupal): remove unused imports, fix URL typo, and bump version to 1.1.5 (#13012) @kishanprmr
- feat(microsoft-teams): get recording and transcript actions (#12637) @kishanprmr
- feat(slack): add find user group by handle and update user group actions (#12777) @bertrandong
- fix(baserow): revert triggers to manual webhook setup (#12912) @onyedikachi-david
- feat(piece): greenhouse integration (#12697) @onyedikachi-david
- feat(mixmax): add Mixmax email productivity piece (#12191) (#12673) @tarai-dl
- feat(amazon-s3): add Generate Signed Upload URL action (#12322) @hugh-codes
- feat(aiprise): add get-by-id and business-search actions (#12853) @sanket-a11y
- chore(piece-google-vertexai): pin peers to 0.26.2 / 0.57.2 / 0.12.1 and bump to 0.1.3 (#12847) @kishanprmr
- feat(Wafeq): add Wafeq accounting integration (#12782) @sanket-a11y
✨ Exciting New Features
- feat: sso domain verification (#13072) @MrChaker
- feat: make platform creation manual for new users (#13000) @MrChaker
- feat: add runs stats visual (#12804) @MrChaker
- feat(ai): add input images support for generate image action (#13032) @AhmadTash
- feat: Think + Work — AI chat experience (#12509) @hazemadelkhalel
- feat(chat): move chat feature from CE to EE (#13127) @hazemadelkhalel
- feat(chat): add server-side tool approval for destructive actions (#13104) @hazemadelkhalel
- feat(chat): make chat platform-wide with project context selector (#13075) @hazemadelkhalel
- feat(mcp): add platform-wide MCP server (#13089) @hazemadelkhalel
- feat: add SSO domain DNS verification (admin-only) (#13071) @MrChaker
- feat(chat): add conversation compaction to prevent context window overflow (#13059) @hazemadelkhalel
- feat: upgrade chat model lists to latest versions (#13044) @hazemadelkhalel
- feat(chat): replace E2B sandbox with Vercel AI SDK for multi-provider chat (#13041) @hazemadelkhalel
- feat(mcp): add ap_run_action tool for one-shot piece execution (#12767) @utopianguide
🐞 Bug Fixes
- fix: federated signup redirection (#13093) @MrChaker
- fix: add invitation check (#13066) @MrChaker
- fix: remove dangerouslySetInnerHTML XSS risk in code block (#13056) @hazemadelkhalel
- fix(workers): drain BullMQ deferredFailure jobs to terminal failed state (#13120) @abuaboud
- fix(chat): fix markdown table rendering when header contains # (#13126) @hazemadelkhalel
- fix(workers): backfill streamStepProgress in v7→v8 migration and reject poisoned jobs (#13125) @abuaboud
- fix(workers): honor BullMQ deferredFailure to drain zombie jobs (#13110) @abuaboud
- fix(chat): default to personal project and show Personal Project label (#13109) @hazemadelkhalel
- fix(chat): persist user message before streaming to survive page refresh (#13107) @hazemadelkhalel
- fix(chat): replace hardcoded Anthropic with generic AI provider in setup UI (#13101) @hazemadelkhalel
- fix(engine): defer flow payload resolution to engine subprocess (#13087) @abuaboud
- fix: trigger sample data was getting lost when editing a published flow (#13022) @AbdulTheActivePiecer
- fix(saml): support Microsoft Entra schema-qualified claims and harden SAML response parsing (#13057) @abuaboud
- fix(worker): retain failed jobs per queue default for non-event-destination jobs (#13046) @amrdb
- fix(sso): accept SAML IdP metadata URL and auto-fetch the XML (#13010) @abuaboud
- fix(pieces): guard against crash when installing .tgz piece (#13027) @kishanprmr
- fix(chat): improve streaming stability with diagnostics and recovery (#13020) @hazemadelkhalel
- fix(chat): invalidate connections query after creating connection in chat (#13019) @hazemadelkhalel
- fix(server): always revalidate index.html to avoid stale assets behind Cloudflare (#13015) @abuaboud
- fix(chat): wait for in-flight events before closing stream (#13013) @hazemadelkhalel
- fix(worker): accept /api/v1/health on worker health server (#13008) @abuaboud
- fix(chat): stop killing active streams on tab visibility change (#13007) @hazemadelkhalel
- fix(chat): resolve system prompt path from project root (#12990) @hazemadelkhalel
🎨 Enhancements & Polish
- feat(chat): enhance AI chat build experience (#13133) @hazemadelkhalel
- feat(chat): show connection status and reconnect in picker (#13123) @hazemadelkhalel
- fix(chat): default to Sonnet instead of Opus for chat model (#13122) @hazemadelkhalel
- perf(engine): shrink engine bundle from 1.9 MB to 1.3 MB (#12733) @abuaboud
- feat(chat): add conversation header and fix connection picker state (#13116) @hazemadelkhalel
- feat(chat): enhance system prompt and add cross-project tools (#13115) @hazemadelkhalel
- feat(chat): redesign AI chat UI with progressive proposals and connection picker (#13079) @yazeed-prog
- fix(mcp): resolve platformId so private (CUSTOM) pieces are discoverable (#12769) @utopianguide
- fix(web): limit error dialog to table-related queries (#13033) @AbdulTheActivePiecer
- fix(builder): resizing sample data section in the builder wasn't working on first try (#13009) @AhmadTash
- feat(chat): UI design pass for AI chat experience (#13002) @yazeed-prog
- fix(chat): improve streaming reliability and error recovery (#13001) @hazemadelkhalel
- feat(chat): multi-question form, session recovery, and UX improvements (#12999) @hazemadelkhalel
- fix(chat): per-user sandbox with SDK caching and optimized lifecycle (#12997) @hazemadelkhalel
- fix(mcp): handle expired step data and unblock status-only run filters (#12994) @utopianguide
- fix(mcp): tighten router branch condition validation to prevent silent step.valid=false (#12822) @utopianguide
Thanks ❤️
@AbdulTheActivePiecer, @AdamSelene, @AhmadTash, @FionnHughes, @Harmatta, @MrChaker, @WilliamZero9, @abuaboud, @amrdb, @avianion, @bertrandong, @bst1n, @cumonvip1, @hazemadelkhalel, @hugh-codes, @kishanprmr, @onyedikachi-david, @sanket-a11y, @tarai-dl, @utopianguide and @yazeed-prog
Security Fixes
- feat: add SSO domain DNS verification (admin‑only) — hardens SAML/SSO configuration (#13071)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
Related context
Related tools
Beta — feedback welcome: [email protected]