Skip to content

OpenRemote

v1.25.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

asset-management building web dataplatform device-management edge-computing
+14 more
energy energy-management energy-monitor fleet-management fleet-telematics iot iot-application iot-platform modbus mqtt mqtt-broker ota-update rules-engine smartcity

Affected surfaces

auth rbac

Summary

AI summary

Updates Other changes, 🐞 Bug fixes, and 🔒 Security updates across a mixed release.

Full changelog

What's Changed

🔒 Security updates

  • (CVE pending) on Insecure Direct Object Reference (IDOR) in the bulk alarm deletion endpoint

🎉 New features

  • New Vaadin UI integration by @MartinaeyNL in https://github.com/openremote/openremote/pull/2377

⭐ Enhancements

  • Update Flyway to current version by @ebariaux in https://github.com/openremote/openremote/pull/2886

🐞 Bug fixes

  • Disable SandboxTransformer (that's not doing anything anyway) for Groovy rules by @ebariaux in https://github.com/openremote/openremote/pull/2849
  • Improved asset datapoints export access control by @ebariaux in https://github.com/openremote/openremote/pull/2869
  • Improve access control on asset import / discovery for agents by @ebariaux in https://github.com/openremote/openremote/pull/2871

Other changes

  • Fix setup project sourceset resolution for manager run task by @Ekhorn in https://github.com/openremote/openremote/pull/2836
  • Fix incorrect processing of docker tags by @Ekhorn in https://github.com/openremote/openremote/pull/2845
  • Add missing UI artifacts in npm dry run job by @Ekhorn in https://github.com/openremote/openremote/pull/2846
  • Exclude npm and include gradle in dependabot config by @ebariaux in https://github.com/openremote/openremote/pull/2815
  • Bump docker/build-push-action from 7.1.0 to 7.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2860
  • Bump aws-actions/configure-aws-credentials from 6.1.0 to 6.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2857
  • Bump github/codeql-action from 4.35.0 to 4.36.2 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2854
  • Bump aws-actions/amazon-ecr-login from 2.1.3 to 2.1.5 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2856
  • Bump tspascoal/get-user-teams-membership from 3.0.0 to 4.0.2 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2859
  • Add ignore rule for openremote/openremote actions by @Ekhorn in https://github.com/openremote/openremote/pull/2862
  • Bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2863
  • Comment NPM ecosystem in dependabot.yml by @wborn in https://github.com/openremote/openremote/pull/2867
  • Bump docker/login-action from 4.1.0 to 4.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2864
  • Bump docker/setup-qemu-action from 4.0.0 to 4.1.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2865
  • Bump docker/setup-buildx-action from 4.0.0 to 4.1.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2866
  • Minor DB compose and metrics settings by @richturner in https://github.com/openremote/openremote/pull/2834
  • Bump bouncyCastle from 1.83 to 1.84 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2858
  • Bump byteBuddy from 1.16.1 to 1.18.10 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2855
  • Bump org.xerial:sqlite-jdbc from 3.53.0.0 to 3.53.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2870
  • Bump grpc from 1.80.0 to 1.82.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2861
  • Hide realm picker for non-admin users by @Ekhorn in https://github.com/openremote/openremote/pull/2872
  • UI bugfix for asset pagination in Rules UI not working anymore by @MartinaeyNL in https://github.com/openremote/openremote/pull/2875
  • Bump aws-actions/amazon-ecr-login from 2.1.5 to 2.1.6 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2876
  • Bump actions/setup-java from 5.2.0 to 5.3.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2883
  • Detect changes of UI files outside UI dir by @Ekhorn in https://github.com/openremote/openremote/pull/2891
  • Bump js-yaml from 4.1.0 to 4.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2887
  • Bump ws from 7.5.10 to 7.5.11 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2889
  • Align dependabot with yarnrc npmMinimalAgeGate setting by @Ekhorn in https://github.com/openremote/openremote/pull/2892
  • Group and ignore some npm dependencies by @Ekhorn in https://github.com/openremote/openremote/pull/2899
  • Bump vaadin from 25.1.3 to 25.1.4 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2902
  • Remove or-vaadin-icon component by @Ekhorn in https://github.com/openremote/openremote/pull/2904

Full Changelog: https://github.com/openremote/openremote/compare/1.24.2...1.25.0

Breaking Changes

  • Removed `or-vaadin-icon` component

Security Fixes

  • (CVE pending) Fixed Insecure Direct Object Reference (IDOR) in the bulk alarm deletion endpoint

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track OpenRemote

Get notified when new releases ship.

Sign up free

About OpenRemote

IoT Asset management, Flow Rules and WHEN-THEN rules, Data visualization, Edge Gateway.

All releases →

Related context

Earlier breaking changes

  • v1.24.0 Requires PostgreSQL versions 15.14+ or 17.9+; older versions will fail to boot.
  • v1.24.0 PostgreSQL TimescaleDB now uses HyperCore compression by default.
  • v1.24.0 Upgraded to Groovy version 5.0, impacting Groovy rules and tests.
  • v1.24.0 Replace obsolete Keycloak adapter with Nimbus based JWT token verifier.

Beta — feedback welcome: [email protected]