This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 5d
Developer Productivity
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
ci-cd
docker
feature-flag
feature-flaggers
feature-flagging
feature-flags
+9 more
feature-management
feature-toggles
flagsmith
multivariate-testing
python
react
remote-config
remote-control
self-hosted
Affected surfaces
deps
Summary
AI summaryUpdates CI, 2.255.0, and Dependency Updates across a mixed release.
Full changelog
2.255.0 (2026-07-21)
Features
- ClickHouse bring-your-own-warehouse connections (#8020) (10a36ab)
- experimentation: add per-organisation ingestion infrastructure service (#8035) (7266074)
- oauth: First-party CLI client and per-client scope policy (#8029) (4df9bfb)
- signup corporate-only experiment with exposure and new_signup events (#7979) (af83f8e)
- unify base URL config and add region dropdown with manual override (#7842) (11a02b6)
Bug Fixes
Dependency Updates
- API: Bump clickhouse-driver to 0.2.11 (#8049) (f388ee8)
- frontend: update dependency @babel/core to v7.29.6 [security] (#8050) (e072d63)
- frontend: update dependency body-parser to v2.3.0 [security] (#8051) (a0e79ea)
CI
- E2E: Collapse previous Playwright result entries in the sticky PR comment (#8012) (0838195)
- Fix documentation artefacts automatically (#8024) (ea9f723)
- pre-commit autoupdate (#7482) (552fd04)
- Renovate: Add force-update input to Renovate workflow (#8048) (b349c60)
Docs
Security Fixes
- dep: @babel/core upgraded to v7.29.6 – security fix
- dep: body-parser upgraded to v2.3.0 – security fix
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Flagsmith
Dashboard, API and SDKs for adding Feature Flags to your applications (alternative to LaunchDarkly).
Beta — feedback welcome: [email protected]