Skip to content

kestra

v1.0.50 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

ai-agents automation control-plane data-engineering data-orchestration data-orchestrator
+13 more
devops etl high-availability infra-automation infra-ops iac java low-code orchestration pipeline pipeline-as-code scheduler workflow

Affected surfaces

crypto_tls

Summary

AI summary

Updates πŸ› Bug Fixes core, πŸš€ Features core, and πŸ“˜ Subtasks version across a mixed release.

Full changelog

Changelog

πŸš€ Features

core

  • 95ca778 add 'sys purge-queue' CLI command and fix queue purge lock timeout (#17268), closes #17268

πŸ“˜ Subtasks

version

  • 08c025c update to version '1.0.50'

πŸ› Bug Fixes

core

  • 6e272ea keep task runner job names within the 63-char limit

design-system

  • a0c8a8f remeasure Monaco fonts on fonts.ready to prevent caret drift

webserver

  • a0c9d3a use constant-time comparison for webhook trigger key

Contributors

We'd like to thank the following people for their contributions:
Anas Khan, GitHub, LoΓ―c Mathieu, Nicolas K., Steven Meek, github-actions[bot], nKwiatkowski

Security Fixes

  • Webhook trigger key comparison now uses constant‑time algorithm

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kestra

Get notified when new releases ship.

Sign up free

About kestra

Event Driven Orchestration & Scheduling Platform for Mission Critical Applications

All releases β†’

Related context

Beta — feedback welcome: [email protected]