This release adds 1 notable feature for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+7 more
ReleasePort's take
Moderate signalSlack bot invocations now gated by respond_member_group_list allowlist. Includes bugfixes for tool name mismatches and per-user header handling.
Why it matters: Allowlist restricts Slack bot access to authorized group members. Bugfixes address tool naming and header issues in MCP integration. Test configuration in dev.
Summary
AI summarySlack bot invocations are now gated by a respond_member_group_list allowlist.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Slack bot invocation gated by respond_member_group_list allowlist Slack bot invocation gated by respond_member_group_list allowlist Source: llm_adapter@2026-05-21 Confidence: low |
— |
| Bugfix | Medium |
Tool Name mismatch issue fixed Tool Name mismatch issue fixed Source: llm_adapter@2026-05-21 Confidence: high |
— |
| Bugfix | Medium |
Per user multiple header issue fixed Per user multiple header issue fixed Source: llm_adapter@2026-05-21 Confidence: high |
— |
Full changelog
What's Changed
- fix(tools): Tool Name mismatch issue (#10981) to release v3.3 by @github-actions[bot] in https://github.com/onyx-dot-app/onyx/pull/10986
- fix(mcp): per user multiple header (#10995) to release v3.3 by @evan-onyx in https://github.com/onyx-dot-app/onyx/pull/11000
- feat(slack-bot): gate invocation by respond_member_group_list allowlist (#10992) to release v3.3 by @nmgarza5 in https://github.com/onyx-dot-app/onyx/pull/11012
Full Changelog: https://github.com/onyx-dot-app/onyx/compare/v3.3.2...v3.3.3
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Onyx Community Edition
Chat UI that works with any LLM. It comes loaded with advanced features like agents, web search, RAG, MCP, deep research, Connectors to 40+ knowledge sources, and more.
Related context
Related tools
Earlier breaking changes
- v4.0.2 Requires running the OpenSearch document index migration before upgrading to v4.0.
- v3.3.7 Environment variable DANSWER_RUNNING_IN_DOCKER renamed to ONYX_RUNNING_IN_DOCKER.
- v3.0.13 OpenSearch enabled as default search backend replacing Vespa
- v3.0.13 License enforcement enabled by default in EE mode
Beta — feedback welcome: [email protected]