This release includes 2 security fixes for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
Summary
AI summaryUpdates constellation, π Bug Fixes, and π Features across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Low |
Support aggregate relationship order_by Support aggregate relationship order_by Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Feature | Low |
Reject bad distinct_on and negative limit/offset values Reject bad distinct_on and negative limit/offset values Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Feature | Low |
Cap GraphQL request body size Cap GraphQL request body size Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Feature | Low |
Expire JWT WebSocket sessions after inactivity Expire JWT WebSocket sessions after inactivity Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Feature | Low |
Emit enum types for mutationβonly inputs Emit enum types for mutationβonly inputs Source: granite4.1:30b@2026-06-03-audit Confidence: low |
β |
| Bugfix | Medium |
Treat null topβlevel `where` as no filter, matching Hasura behavior Treat null topβlevel `where` as no filter, matching Hasura behavior Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Bugfix | Medium |
Run insertβcheck after INSERT when payload omits referenced columns Run insertβcheck after INSERT when payload omits referenced columns Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Bugfix | Medium |
Partition multiβparent nested array inserts per parent CTE Partition multiβparent nested array inserts per parent CTE Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Bugfix | Medium |
Apply defaults in mixed multiβrow inserts Apply defaults in mixed multiβrow inserts Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Bugfix | Medium |
Partition objectβrel nested inserts per parent Partition objectβrel nested inserts per parent Source: llm_adapter@2026-06-03 Confidence: high |
β |
| Bugfix | Medium |
Harden JWT and adminβsecret authentication mechanisms Harden JWT and adminβsecret authentication mechanisms Source: llm_adapter@2026-06-03 Confidence: low |
β |
| Bugfix | Medium |
Enforce upsert update permissions Enforce upsert update permissions Source: granite4.1:30b@2026-06-03-audit Confidence: low |
β |
| Bugfix | Medium |
Harden stream cursors and introspection responses Harden stream cursors and introspection responses Source: granite4.1:30b@2026-06-03-audit Confidence: low |
β |
| Bugfix | Low |
Resolve where variables in queries Resolve where variables in queries Source: granite4.1:30b@2026-06-03-audit Confidence: low |
β |
| Bugfix | Low |
Preserve x-hasura literals in subscriptions Preserve x-hasura literals in subscriptions Source: granite4.1:30b@2026-06-03-audit Confidence: low |
β |
| Bugfix | Low |
Honor @skip/@include and root fragments/__typename directives Honor @skip/@include and root fragments/__typename directives Source: granite4.1:30b@2026-06-03-audit Confidence: low |
β |
Full changelog
[[email protected]] - 2026-06-03
π Features
- (constellation) Support aggregate relationship order_by (#4403)
- (constellation) Reject bad distinct_on & negative limit/offset (#4405)
- (constellation) Cap GraphQL request bodies (#4418)
- (constellation) Expire JWT WebSocket sessions (#4416)
π Bug Fixes
- (constellation) Treat null top-level
whereas no filter, matching Hasura (#4382) - (constellation) Run insert-check after INSERT when payload omits referenced cols (#4384)
- (constellation) Partition multi-parent nested array inserts per parent CTE (#4389)
- (constellation) Apply defaults in mixed multi-row inserts (#4388)
- (constellation) Partition multi-parent object-rel nested inserts per parent (#4392)
- (constellation) Resolve where variables (#4398)
- (constellation) Preserve x-hasura literals in subscriptions (#4399)
- (constellation) Harden JWT and admin-secret authentication (#4400)
- (constellation) Honor field aliases at every aggregate scope (#4407)
- (constellation) Support function default args (#4404)
- (constellation) Partition object-rel nested inserts per parent (#4401)
- (constellation) Resolve nested returning relationships from insert CTEs (#4414)
- (constellation) Apply remote-schema presets under non-default root types (#4415)
- (constellation) Preserve x-hasura literals in subscriptions (#4422)
- (constellation) Resolve where variables (#4423)
- (constellation) Enforce upsert update permissions (#4419)
- (constellation) Honor @skip/@include and root fragments/__typename (#4434)
- (constellation) Emit enum types for mutation-only inputs (#4438)
- (constellation) Harden stream cursors and introspection responses (#4439)
βοΈ Miscellaneous Tasks
- (nixops) Drop nix-filter input in favor of pkgs.lib.fileset (#4377)
- (nixops) Fix repo after bumping nixpkgs (#4394)
Security Fixes
- Harden JWT and admin-secret authentication in constellation (#4400)
- Harden stream cursors and introspection responses in constellation (#4439)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]