Skip to content

kestra

v1.3.24 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

ai-agents automation control-plane data-engineering data-orchestration data-orchestrator
+13 more
devops etl high-availability infra-automation infra-ops iac java low-code orchestration pipeline pipeline-as-code scheduler workflow

Affected surfaces

auth

Summary

AI summary

Updates πŸ› Bug Fixes core, πŸš€ Features core, and πŸ›  Build release across a mixed release.

Full changelog

Changelog

πŸš€ Features

core

  • 198473d add full arg to the secret() pebble function
  • f130b91 add subflow() Pebble function (#16872), closes #16653 #16872

inputs

  • e6c95fb FORM input type with a Next/Back execution wizard (1.3 backport) (#16946), closes #16655 #16946

system

  • 13f5444 expose SSE follow-connection metrics in Prometheus (#16999), closes #16982 #16997 #16999

πŸ“˜ Subtasks

version

  • 660bdc3 update to version '1.3.24'

πŸ› Bug Fixes

core

  • e16ed65 fail fast on pebble function errors (#16881), closes #16881

execution

  • 3be7399 kiling a paused flow

executions

  • b0e2079 after execution killing
  • 7410375 close SSE streams on error to stop off-heap leak (#16985), closes #16982 #16984 #16985
  • 1f6c312 after execution killing

flows

  • dd4d592 apply query and namespace filters in findSourceCode

helm

  • 1b30ff0 delegate helm release to kestra-io/actions on releases/v1.3.x (#16879), closes #16294 #16761 #16879

repository

  • 7ce4ea5 return HTTP 422 on unknown sort field instead of NPE

security

  • 0100807 replace SHA-512 with bcrypt for BasicAuth password storage (1.3 backport)

storage

  • 50d3b31 retry transient temp-file deletion failures

triggers

  • d5ed2b7 make JDBC trigger create() idempotent

global

  • ee7b3fd propagate forced execution to flowable children
  • 6c8e6d0 render router-md as anchors using linkify (#16835), closes #16835

🏭 Tests

webserver

  • ea92c16 fix flowable after-execution case

πŸ›  Build

release

  • 28fcd94 use kestra base images when publishing docker

global

  • 64c5d39 make husky prepare script worktree-safe (#16877), closes #16877

  • 51fcc9e Revert "fix(executions): after execution killing"

Contributors

We'd like to thank the following people for their contributions:
BarthΓ©lΓ©my Ledoux, Florian Hussonnois, GitHub, LoΓ―c Mathieu, Malay Dewangan, Marco Sabatini, Nicolas K., Roman Acevedo, Steven Meek, brian-mulier-p, github-actions[bot], nKwiatkowski, zgxme

Security Fixes

  • Replace SHA‑512 with bcrypt for BasicAuth password storage (1.3 backport)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track kestra

Get notified when new releases ship.

Sign up free

About kestra

Event Driven Orchestration & Scheduling Platform for Mission Critical Applications

All releases β†’

Related context

Beta — feedback welcome: [email protected]