This release includes 1 security fix for security teams reviewing exposed deployments.
Topics
+14 more
Affected surfaces
Summary
AI summaryUpdates Other changes, fix, and π Security updates across a mixed release.
Full changelog
β οΈ Important notes / Before you upgrade β οΈ
-
The Energy- related source code, together with the Demo setup, have been moved to separate extension artifacts.
These artifacts are still included in theopenremote/openremoteDocker image, therefore no breaking changes are introduced.
Users can now install and build their own extensions; read more about this on our documentation website. -
Deprecation warning for custom projects: using
openremoteVersioningradle.propertiesis now deprecated,
and a warning is sent when used. Instead, users should set theopenremoteversion in thegradle/libs.versions.tomlfile.
What's Changed
π Security updates
- (CVE pending) on Cross-tenant IDOR in
setAssetLinksallows cross-realm alarm-asset link persistence via validation bypass
β Enhancements
- Improve Gradle plugin and dependency version catalog configuration by @wborn in https://github.com/openremote/openremote/pull/3058
π Bug fixes
- Fix services migration in development when the keystore file is missing by @Ekhorn in https://github.com/openremote/openremote/pull/3044
Other changes
- [Extensions] Remove Energy and Demo Setup extensions by @denniskuijs in https://github.com/openremote/openremote/pull/3008
- [CI/CD] Add CI/CD workflow for extensions by @denniskuijs in https://github.com/openremote/openremote/pull/3007
- Fix staging workflow issue by @denniskuijs in https://github.com/openremote/openremote/pull/3036
- Bump websocket-driver from 0.7.4 to 0.7.5 by @dependabot[bot] in https://github.com/openremote/openremote/pull/3040
- Bump groovy from 5.0.6 to 5.0.7 by @dependabot[bot] in https://github.com/openremote/openremote/pull/3029
- Remove energy assets and duplicate tests from asset.test.ts by @Ekhorn in https://github.com/openremote/openremote/pull/3048
- Fix issues with Extensions CI/CD by @denniskuijs in https://github.com/openremote/openremote/pull/3046
- Fix Gradle deprecations by @wborn in https://github.com/openremote/openremote/pull/3043
- fix: Add missing permissions to extensions CI/CD workflow by @denniskuijs in https://github.com/openremote/openremote/pull/3049
- fix: extensions CI/CD uses wrong GH token by @denniskuijs in https://github.com/openremote/openremote/pull/3050
- fix: Change extensions workflow parameter names to lowerCase by @denniskuijs in https://github.com/openremote/openremote/pull/3052
- Bump the vaadin group across 1 directory with 22 updates by @dependabot[bot] in https://github.com/openremote/openremote/pull/3038
- fix: Extensions CI/CD issues by @denniskuijs in https://github.com/openremote/openremote/pull/3059
- Update Process CI/CD JSON GitHub Action SHA by @denniskuijs in https://github.com/openremote/openremote/pull/3062
- Bump actions/setup-java from 5.5.0 to 5.6.0 by @dependabot[bot] in https://github.com/openremote/openremote/pull/3055
- Bump github/codeql-action/upload-sarif from 4.37.0 to 4.37.1 by @dependabot[bot] in https://github.com/openremote/openremote/pull/3054
- Read OpenRemote version from Gradle version catalog by @wborn in https://github.com/openremote/openremote/pull/3065
- Bump openremote/openremote/.github/actions/process-cicd-json from 3125aa44c8977c7a373bd22a3c4dd0ccb56ca44c to f667c603a447af79dda980f1dd1d734fd4679b2e by @dependabot[bot] in https://github.com/openremote/openremote/pull/3067
- fix: CI/CD Deployment issue with extensions by @denniskuijs in https://github.com/openremote/openremote/pull/3069
- fix: Release issue with demo-setup by @denniskuijs in https://github.com/openremote/openremote/pull/3076
Full Changelog: https://github.com/openremote/openremote/compare/1.26.2...1.27.0
Breaking Changes
- Removal of `openremoteVersion` in `gradle.properties`; use version catalog instead.
Security Fixes
- (CVE pending) Fix crossβtenant IDOR in `setAssetLinks` that allowed persistence of alarmβasset links across realms via validation bypass.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About OpenRemote
IoT Asset management, Flow Rules and WHEN-THEN rules, Data visualization, Edge Gateway.
Related context
Related tools
Earlier breaking changes
- v1.24.0 Requires PostgreSQL versions 15.14+ or 17.9+; older versions will fail to boot.
- v1.24.0 PostgreSQL TimescaleDB now uses HyperCore compression by default.
- v1.24.0 Upgraded to Groovy version 5.0, impacting Groovy rules and tests.
- v1.24.0 Replace obsolete Keycloak adapter with Nimbus based JWT token verifier.
Beta — feedback welcome: [email protected]