This release includes 1 security fix for security teams reviewing exposed deployments.
Published 26d
Dashboards & Home Pages
✓ No known CVEs patched
This release patches 1 known CVE
Topics
asset-management
building
web
dataplatform
device-management
edge-computing
+14 more
energy
energy-management
energy-monitor
fleet-management
fleet-telematics
iot
iot-application
iot-platform
modbus
mqtt
mqtt-broker
ota-update
rules-engine
smartcity
Affected surfaces
auth
Summary
AI summaryUpdates Other changes, 🐞 Bug fixes, and ⭐ Enhancements across a mixed release.
Full changelog
What's Changed
🔒 Security updates
- (CVE pending) on Authenticated SQL Injection in Datapoint Crosstab Export
🎉 New features
- Feature: Add map preset filter by @Ekhorn in https://github.com/openremote/openremote/pull/2802
⭐ Enhancements
- Replace Material UI menus with Vaadin components by @MartinaeyNL in https://github.com/openremote/openremote/pull/2911
- insights line-chart improvements by @Hackerberg43 in https://github.com/openremote/openremote/pull/2725
🐞 Bug fixes
- Fix timezone handling for datapoints export by @ebariaux in https://github.com/openremote/openremote/pull/2882
- Show pointer cursor for entire legend header by @Ekhorn in https://github.com/openremote/openremote/pull/2938
- Fix KPI panel showing 'add attribute' button while it should not by @MartinaeyNL in https://github.com/openremote/openremote/pull/2954
- Fix stale attribute panel by @Hackerberg43 in https://github.com/openremote/openremote/pull/2721
Other changes
- Bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2905
- Bump tar from 7.5.11 to 7.5.16 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2890
- Bump com.hivemq:hivemq-mqtt-client from 1.3.13 to 1.3.15 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2878
- Bump brace-expansion from 1.1.12 to 1.1.15 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2907
- Entrypoint changes affecting heap dump storage and
OR_JAVA_OPTSby @richturner in https://github.com/openremote/openremote/pull/2868 - Bump netty from 4.2.12.Final to 4.2.15.Final by @dependabot[bot] in https://github.com/openremote/openremote/pull/2909
- Bump picomatch from 2.3.1 to 2.3.2 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2908
- Bump @rive-app/webgl2 from 2.35.4 to 2.38.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2897
- Bump launch-editor from 2.11.0 to 2.14.1 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2888
- Bump linqts from 1.15.0 to 3.2.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2914
- Upgrade typescript-generator plugin to 4.1.1 by @wborn in https://github.com/openremote/openremote/pull/2912
- Fix anchore/scan-action image name by @wborn in https://github.com/openremote/openremote/pull/2918
- Dedupe yarn.lock file and upgrade ESLint dependencies by @MartinaeyNL in https://github.com/openremote/openremote/pull/2917
- Bump @typescript-eslint/eslint-plugin from 8.61.0 to 8.61.1 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2920
- Bump @rsdoctor/rspack-plugin and socket.io-parser to latest version by @MartinaeyNL in https://github.com/openremote/openremote/pull/2924
- Bump actions/cache from 5.0.5 to 6.0.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2926
- Bump playwright from 1.57.0 to 1.59.1 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2906
- Remove unused CSS deps, simplebar and Material elevation by @MartinaeyNL in https://github.com/openremote/openremote/pull/2930
- Bump ajv from 8.12.0 to 8.20.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2898
- Bump UI dependency express from 4.21.2 to 4.22.2 by @MartinaeyNL in https://github.com/openremote/openremote/pull/2942
- Bump @rive-app/webgl2 from 2.38.0 to 2.38.1 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2940
- Bump @reduxjs/toolkit from 1.9.7 to 2.12.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2927
- Bump i18next-http-backend from 1.4.5 to 4.0.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2947
- Upgrade to Jackson 2.21.4 by @MartinaeyNL in https://github.com/openremote/openremote/pull/2944
- Bump artemis from 2.53.0 to 2.54.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2877
- Bump micrometer from 1.16.5 to 1.17.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2879
- Add support for DevContainers by @denniskuijs in https://github.com/openremote/openremote/pull/2933
- Add preset filters to the demo setup by @Ekhorn in https://github.com/openremote/openremote/pull/2950
- Adjust dependabot rebase strategy by @Ekhorn in https://github.com/openremote/openremote/pull/2943
- Bump actions/setup-java from 5.3.0 to 5.4.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2945
- Bump niftyModbus from 0.17.0 to 1.4.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2915
- Bump junit from 6.0.3 to 6.1.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2952
- Bump aws-actions/configure-aws-credentials from 6.2.0 to 6.2.1 by @dependabot[bot] in https://github.com/openremote/openremote/pull/2962
- Upgrade protobuf-gradle-plugin to 0.10.0 by @wborn in https://github.com/openremote/openremote/pull/2960
- Update UI dependencies axios to 1.18.1 and form-data to 4.0.6 by @MartinaeyNL in https://github.com/openremote/openremote/pull/2925
Full Changelog: https://github.com/openremote/openremote/compare/1.25.0...1.26.0
Security Fixes
- (CVE pending) Authenticated SQL Injection in Datapoint Crosstab Export
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About OpenRemote
IoT Asset management, Flow Rules and WHEN-THEN rules, Data visualization, Edge Gateway.
Related context
Related tools
Earlier breaking changes
- v1.24.0 Requires PostgreSQL versions 15.14+ or 17.9+; older versions will fail to boot.
- v1.24.0 PostgreSQL TimescaleDB now uses HyperCore compression by default.
- v1.24.0 Upgraded to Groovy version 5.0, impacting Groovy rules and tests.
- v1.24.0 Replace obsolete Keycloak adapter with Nimbus based JWT token verifier.
Beta — feedback welcome: [email protected]