This release includes 1 security fix for security teams reviewing exposed deployments.
Published 1mo
Dashboards & Home Pages
✓ No known CVEs patched
This release patches 1 known CVE
Topics
asset-management
building
web
dataplatform
device-management
edge-computing
+14 more
energy
energy-management
energy-monitor
fleet-management
fleet-telematics
iot
iot-application
iot-platform
modbus
mqtt
mqtt-broker
ota-update
rules-engine
smartcity
Affected surfaces
auth
rbac
Summary
AI summaryUpdates Other changes, 🐞 Bug fixes, and 🔒 Security updates across a mixed release.
Full changelog
What's Changed
🔒 Security updates
- (CVE pending) on Insecure Direct Object Reference (IDOR) in the bulk alarm deletion endpoint
🎉 New features
- New Vaadin UI integration by @MartinaeyNL in https://github.com/openremote/openremote/pull/2377
⭐ Enhancements
- Update Flyway to current version by @ebariaux in https://github.com/openremote/openremote/pull/2886
🐞 Bug fixes
- Disable SandboxTransformer (that's not doing anything anyway) for Groovy rules by @ebariaux in https://github.com/openremote/openremote/pull/2849
- Improved asset datapoints export access control by @ebariaux in https://github.com/openremote/openremote/pull/2869
- Improve access control on asset import / discovery for agents by @ebariaux in https://github.com/openremote/openremote/pull/2871
Other changes
- Fix setup project sourceset resolution for manager run task by @Ekhorn in https://github.com/openremote/openremote/pull/2836
- Fix incorrect processing of docker tags by @Ekhorn in https://github.com/openremote/openremote/pull/2845
- Add missing UI artifacts in npm dry run job by @Ekhorn in https://github.com/openremote/openremote/pull/2846
- Exclude npm and include gradle in dependabot config by @ebariaux in https://github.com/openremote/openremote/pull/2815
- Bump docker/build-push-action from 7.1.0 to 7.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2860
- Bump aws-actions/configure-aws-credentials from 6.1.0 to 6.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2857
- Bump github/codeql-action from 4.35.0 to 4.36.2 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2854
- Bump aws-actions/amazon-ecr-login from 2.1.3 to 2.1.5 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2856
- Bump tspascoal/get-user-teams-membership from 3.0.0 to 4.0.2 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2859
- Add ignore rule for openremote/openremote actions by @Ekhorn in https://github.com/openremote/openremote/pull/2862
- Bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2863
- Comment NPM ecosystem in dependabot.yml by @wborn in https://github.com/openremote/openremote/pull/2867
- Bump docker/login-action from 4.1.0 to 4.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2864
- Bump docker/setup-qemu-action from 4.0.0 to 4.1.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2865
- Bump docker/setup-buildx-action from 4.0.0 to 4.1.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2866
- Minor DB compose and metrics settings by @richturner in https://github.com/openremote/openremote/pull/2834
- Bump bouncyCastle from 1.83 to 1.84 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2858
- Bump byteBuddy from 1.16.1 to 1.18.10 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2855
- Bump org.xerial:sqlite-jdbc from 3.53.0.0 to 3.53.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2870
- Bump grpc from 1.80.0 to 1.82.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2861
- Hide realm picker for non-admin users by @Ekhorn in https://github.com/openremote/openremote/pull/2872
- UI bugfix for asset pagination in Rules UI not working anymore by @MartinaeyNL in https://github.com/openremote/openremote/pull/2875
- Bump aws-actions/amazon-ecr-login from 2.1.5 to 2.1.6 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2876
- Bump actions/setup-java from 5.2.0 to 5.3.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2883
- Detect changes of UI files outside UI dir by @Ekhorn in https://github.com/openremote/openremote/pull/2891
- Bump js-yaml from 4.1.0 to 4.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2887
- Bump ws from 7.5.10 to 7.5.11 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2889
- Align dependabot with yarnrc npmMinimalAgeGate setting by @Ekhorn in https://github.com/openremote/openremote/pull/2892
- Group and ignore some npm dependencies by @Ekhorn in https://github.com/openremote/openremote/pull/2899
- Bump vaadin from 25.1.3 to 25.1.4 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2902
- Remove or-vaadin-icon component by @Ekhorn in https://github.com/openremote/openremote/pull/2904
Full Changelog: https://github.com/openremote/openremote/compare/1.24.2...1.25.0
Breaking Changes
- Removed `or-vaadin-icon` component
Security Fixes
- (CVE pending) Fixed Insecure Direct Object Reference (IDOR) in the bulk alarm deletion endpoint
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About OpenRemote
IoT Asset management, Flow Rules and WHEN-THEN rules, Data visualization, Edge Gateway.
Related context
Related tools
Earlier breaking changes
- v1.24.0 Requires PostgreSQL versions 15.14+ or 17.9+; older versions will fail to boot.
- v1.24.0 PostgreSQL TimescaleDB now uses HyperCore compression by default.
- v1.24.0 Upgraded to Groovy version 5.0, impacting Groovy rules and tests.
- v1.24.0 Replace obsolete Keycloak adapter with Nimbus based JWT token verifier.
Beta — feedback welcome: [email protected]