Skip to content

FlowForge

v2.32.1 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

flow-based-programming low-code low-code-development low-code-development-platform no-code node-red
+1 more
visual-programming

Affected surfaces

auth deps

Summary

AI summary

Updates deps, deps-dev, and ci across a mixed release.

Full changelog

What's Changed

  • Device agent 4 related documentation update by @sumitshinde-84 in https://github.com/FlowFuse/flowfuse/pull/7658
  • Documentation Update For 2.32 by @sumitshinde-84 in https://github.com/FlowFuse/flowfuse/pull/7656
  • Upgrade echarts for XSS CVE by @hardillb in https://github.com/FlowFuse/flowfuse/pull/7657
  • fix(expert): dismiss pending tool-approval cards when a new message is sent by @andypalmi in https://github.com/FlowFuse/flowfuse/pull/7663
  • build(deps): bump nodemailer from 9.0.1 to 9.0.3 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7738
  • build(deps): bump @aws-sdk/credential-provider-node from 3.972.58 to 3.972.62 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7742
  • build(deps): bump @node-red/util from 5.0.0 to 5.0.1 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7753
  • build(deps): bump @redis/client from 6.0.1 to 6.1.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7746
  • build(deps-dev): bump @tailwindcss/postcss from 4.3.1 to 4.3.2 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7752
  • build(deps): bump @aws-sdk/client-sesv2 from 3.1075.0 to 3.1079.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7751
  • chore(expert): tool-permissions review follow-ups (comments + generic JsonViewer) by @andypalmi in https://github.com/FlowFuse/flowfuse/pull/7730
  • Add PAT scope foundation: request-context plugin, permission tagging, migrations, and models by @cstns in https://github.com/FlowFuse/flowfuse/pull/7580
  • ci: Replace custom scripts with slack_notification action in Tests workflow by @ppawlowski in https://github.com/FlowFuse/flowfuse/pull/7762
  • ci: Replace custom scripts with slack_notification action in Publish workflow by @ppawlowski in https://github.com/FlowFuse/flowfuse/pull/7764
  • ci: Replace custom scripts with slack_notification action in Install Test workflow by @ppawlowski in https://github.com/FlowFuse/flowfuse/pull/7763
  • ci: Replace manual scripts with slack_notification action in Create pre-staging environment by @ppawlowski in https://github.com/FlowFuse/flowfuse/pull/7761
  • Fix escaping in npm scripts in package.json by @Steve-Mcl in https://github.com/FlowFuse/flowfuse/pull/7771
  • chore: Upgrade eslint to v9 by @Steve-Mcl in https://github.com/FlowFuse/flowfuse/pull/7760
  • Remove @node-red/util dependency by @Steve-Mcl in https://github.com/FlowFuse/flowfuse/pull/7768
  • ci: Add slack notification to the release pipeline by @ppawlowski in https://github.com/FlowFuse/flowfuse/pull/7779
  • Enabled Expert Insights by default for self-hosted by @cstns in https://github.com/FlowFuse/flowfuse/pull/7773
  • fix: normalise Expert inbound origins to bare origin by @andypalmi in https://github.com/FlowFuse/flowfuse/pull/7783
  • [7446] Scoped PATs: API routes and controllers by @cstns in https://github.com/FlowFuse/flowfuse/pull/7766
  • Fix navigation for custom editor paths by @cstns in https://github.com/FlowFuse/flowfuse/pull/7784
  • fix: backfill adminOptIn for existing admin PATs by @cstns in https://github.com/FlowFuse/flowfuse/pull/7785
  • Scoped PATs: permission enforcement by @cstns in https://github.com/FlowFuse/flowfuse/pull/7777
  • build(deps): bump cypress-io/github-action from 7.4.0 to 7.4.1 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7739
  • build(deps): bump docker/setup-qemu-action from 4.1.0 to 4.2.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7737
  • build(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7744
  • build(deps): bump docker/login-action from 4.2.0 to 4.4.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7745
  • build(deps): bump docker/build-push-action from 7.2.0 to 7.3.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7741
  • Set admin flag on pre-staging setup token by @knolleary in https://github.com/FlowFuse/flowfuse/pull/7788
  • Add generic means for logging additional properties and add to acl routes by @knolleary in https://github.com/FlowFuse/flowfuse/pull/7819
  • build(deps): bump aws-actions/configure-aws-credentials from 6.2.1 to 6.2.2 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7792
  • fix: sanitise OpenMetrics metric names in admin stats endpoint by @ppawlowski in https://github.com/FlowFuse/flowfuse/pull/7787
  • docs: Introduce Kubernetes/FlowFuse observability documentation by @ppawlowski in https://github.com/FlowFuse/flowfuse/pull/7769
  • build(deps): bump @aws-sdk/credential-provider-node from 3.972.62 to 3.972.66 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7813
  • build(deps): bump dompurify from 3.4.11 to 3.4.12 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7812
  • build(deps): bump lru-cache from 11.5.1 to 11.5.2 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7797
  • build(deps): bump mqtt from 5.15.1 to 5.15.2 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7801
  • Use shared subscription group for Expert platform requests by @Steve-Mcl in https://github.com/FlowFuse/flowfuse/pull/7823
  • Introduce status field to Device model for better representation of state by @Steve-Mcl in https://github.com/FlowFuse/flowfuse/pull/7828
  • Skip offline devices in Expert API to avoid unnecessary timeouts by @Steve-Mcl in https://github.com/FlowFuse/flowfuse/pull/7831
  • [7833] Flaky HA unit test + update cypress config by @n-lark in https://github.com/FlowFuse/flowfuse/pull/7834
  • build(deps-dev): bump systeminformation from 5.31.6 to 5.31.17 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7835
  • build(deps): bump websocket-driver from 0.7.4 to 0.7.5 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7836
  • build(deps): bump @aws-sdk/client-sesv2 from 3.1079.0 to 3.1085.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7793
  • [7653] New instance creation fails to load immersive editor/FlowFuse Expert by @n-lark in https://github.com/FlowFuse/flowfuse/pull/7661
  • build(deps-dev): bump webpack from 5.108.1 to 5.108.4 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7756
  • build(deps): bump @sentry/node from 10.62.0 to 10.65.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7791
  • build(deps): bump @fastify/helmet from 13.0.2 to 13.1.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7794
  • build(deps-dev): bump vue-tsc from 3.3.5 to 3.3.7 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7795
  • build(deps): bump @fastify/websocket from 11.2.0 to 11.3.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7796
  • build(deps): bump @fastify/cookie from 11.0.2 to 11.1.1 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7798
  • build(deps): bump @fastify/static from 9.1.3 to 10.1.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7799
  • build(deps-dev): bump cypress from 15.18.0 to 15.18.1 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7803
  • build(deps): bump @fastify/swagger-ui from 6.0.0 to 6.1.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7805
  • build(deps-dev): bump @typescript-eslint/parser from 8.62.1 to 8.63.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7816
  • build(deps): bump fastify from 5.9.0 to 5.10.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7748
  • build(deps-dev): bump webpack-cli from 7.1.0 to 7.2.1 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7740
  • build(deps): bump marked from 18.0.5 to 18.0.6 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7802
  • build(deps-dev): bump postcss from 8.5.16 to 8.5.17 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7806
  • build(deps): bump @fastify/multipart from 10.0.0 to 10.1.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7807
  • build(deps): bump @fastify/swagger from 9.7.0 to 9.8.1 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7800
  • build(deps): bump posthog-node from 5.38.6 to 5.41.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7808
  • build(deps): bump @sentry/vue from 10.62.0 to 10.65.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7809
  • Fix MCP feature enumeration with with cap, deadline and per instance fault containement by @Steve-Mcl in https://github.com/FlowFuse/flowfuse/pull/7841
  • Add source column to AuditLog with request context propagation by @cstns in https://github.com/FlowFuse/flowfuse/pull/7825
  • Validate resource ownership in broker api by @knolleary in https://github.com/FlowFuse/flowfuse/pull/7845
  • Inject source context headers in MCP tool calls by @cstns in https://github.com/FlowFuse/flowfuse/pull/7830
  • build(deps-dev): bump @typescript-eslint/eslint-plugin from 8.62.1 to 8.64.0 by @dependabot[bot] in https://github.com/FlowFuse/flowfuse/pull/7804
  • Add granular RBAC SSO support by @hardillb in https://github.com/FlowFuse/flowfuse/pull/7733
  • Fix pipeline stage validations by @knolleary in https://github.com/FlowFuse/flowfuse/pull/7850
  • fix: enable default maintenance schedule for opt-out tiers on instance creation by @robmarcer in https://github.com/FlowFuse/flowfuse/pull/7822
  • Release 2.32.1 by @hardillb in https://github.com/FlowFuse/flowfuse/pull/7851

Full Changelog: https://github.com/FlowFuse/flowfuse/compare/v2.32.0...v2.32.1

Security Fixes

  • Upgrade echarts to mitigate XSS CVE (CVE not explicitly listed)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track FlowForge

Get notified when new releases ship.

Sign up free

About FlowForge

Deploy Node-RED applications in a reliable, scalable and secure manner. The FlowForge platform provides DevOps capabilities for Node-RED development teams.

All releases →

Related context

Beta — feedback welcome: [email protected]