github LanternOps/breeze v0.119.0

3 hours ago

Breeze RMM v0.119.0: physical network topology and monitoring, Windows time sync, Xero accounting, multi-org report series, and brokered backup writes, plus a security hardening pass across the server, agent and Breeze Helper.

⚠️ Self-hosters on v0.118.x: TURN relaying stays broken until you edit your coturn configuration. The v0.118.0–v0.118.2 Compose files pass --denied-peer-ip=:: to coturn, which coturn reads as "every address". Every relayed (TURN) connection has been refused since v0.118.0. Delete that line (- '--denied-peer-ip=::' in the coturn command: of docker-compose.yml or deploy/docker-compose.prod.yml, or denied-peer-ip=:: in a standalone /etc/turnserver.conf), then restart coturn. guided-setup.sh --upgrade does not edit your Compose file, so this is a manual step on every install (#7536).

⚠️ S3 restores now need HTTPS end to end and an agent on v0.118 or later. Restores, test restores and verification from S3 or S3-compatible storage go only through a short-lived storage session, and there is no fallback. A plain-http:// MinIO endpoint, an API that agents reach over plain HTTP, or an unset or mismatched PUBLIC_API_URL refuses every S3 restore. Move to HTTPS before upgrading (#7237).

⚠️ Behaviour changes that need attention. See Self-Hosting / Upgrade Notes for details.

  • Live device inspection (processes, services, scheduled tasks, event logs, files, registry and the live session list) now needs devices:execute. Org Viewer, Partner Viewer and the seeded approver roles lose it (#7538, #7540).
  • On devices whose remote access policy is Require consent, VNC is refused, and desktop starts need a consent-capable agent. Two consent audit actions are renamed (#7288, #7390).
  • Approver assurance becomes the platform default for high- and critical-risk approvals from 2026-11-05 (#7395).
  • Notification channel and settings secrets are stored encrypted and returned masked. If you run a separate worker container, roll it together with api (#7533, #7254).

Security — action required

Self-hosted operators should upgrade to 0.119.0 and let agents update:

  • GHSA-9qpw-p6rx-5f2h (High, agent 0.62.9–0.118.2): restoring a Windows backup as a Hyper-V VM could run code from that backup as SYSTEM on the Hyper-V host. Fixed in agent 0.119.0 (#7484).
  • GHSA-c445-q84m-rph4 (Medium, server 0.108.0–0.118.2): on servers whose API runs in a non-UTC time zone, tokens issued shortly before a password change kept working and SSO re-authentication accepted stale sign-ins. Hosted and default Compose (UTC) were not affected (#7492).
  • GHSA-vjq5-x2g3-pjhq (Low, server ≤ 0.118.2): AI file tools could read restricted folders through alternate path spellings (#7485).

Security — hardening

This release includes security hardening across:

  • live device inspection permissions;
  • site scoping of fleet security, threat and analytics reads;
  • stored notification-channel and settings secrets;
  • AI tools and AI sessions;
  • remote-session consent enforcement;
  • backup restore storage access;
  • TURN relaying;
  • request auditing and approvals;
  • dependency updates for upstream advisories.

Self-hosters are encouraged to upgrade the server and let agents and Breeze Helper update to 0.119.0. (#7538, #7540, #7529, #7530, #7533, #7254, #7258, #7543, #7448, #7390, #7288, #7237, #7536, #7501, #7500, #7525, #7395, #7504, #7528)

Summary

  • Network topology is complete. Physical links come from switch (LLDP/CDP/FDB) and UniFi evidence. The release adds interface history and link health, site monitoring policies, bounded traceroute, impact and recent-changes views, and an Explain this AI investigation whose claims must cite evidence. The one diagnostic it may propose runs only after a fresh passkey approval. Switch it on per partner in Settings → Partner → Modules (#7096, #7117, #7147, #7424).
  • Windows time sync monitoring and enforcement. The agent reports W32Time configuration, time source, domain role, timezone and Time-Service events. There is a fleet Time page with 400-day evidence and CSV export, a time_sync monitor kind, and a Time sync tab in Configuration Policies that enforces NTP servers and timezone. Needs agent 0.119.0 (#7488, #7491, #7502, #7520, #7532).
  • Xero accounting. Connect a Xero organisation, map contacts and items, import customers, push and void invoices, and sync payments both ways. It stays hidden until XERO_CLIENT_ID is configured (#7226, #7263, #7286, #7290, #7295, #7297, #7301, #7399).
  • Multi-org report series. One definition produces a report for every organization, or for the ones you choose, with recipient rules and internal CC. Every run records its delivery status. Opt-in Combine merges existing near-identical per-org reports into a series (#7451, #7458, #7459, #7483). There is also a new Backup status report (#7426).
  • Backup. With the new agent, the backup helper uploads through short-lived server-issued signed URLs, and snapshots are attested after upload. S3 restores always use a storage session. A Windows rebuild host can rebuild a whole-machine snapshot into a VHDX and optionally create a Hyper-V VM. Cove-protected devices count in the customer portal (#7237, #7283, #7287, #7353, #7372, #7396, #7404, #7405, #7425, #7482, #7486).
  • Compliance alerts. Configuration-policy compliance violations raise alerts on the first failing check. An alert stays open until the device is compliant and closes when its rule no longer applies (#7223, #7518, #7527).

Added

  • Topology physical evidence (#7096). LLDP, CDP, FDB and UniFi evidence become physical links, or explicitly ambiguous attachments. A link can be hidden or restored per view. Manual cables can name ports (API only).
  • Topology operations (#7117). Interface history and link health, site monitoring policies that need MFA to arm, bounded traceroute, impact and recent-changes views, and five MCP read tools.
  • Topology "Explain this" (#7147). A site-pinned AI investigation whose claims must cite evidence. Its one proposed diagnostic runs only after a fresh passkey approval.
  • Time sync (#7488, #7491, #7502, #7520, #7532):
    • Device Info → Time.
    • The time_sync monitor kind, with built-in monitors provisioned partner-wide but not attached.
    • Fleet page Devices → Time with a domain view and CSV exports of current status and daily history.
    • Configuration Policies → Time sync tab: NTP servers, poll interval, expected or pinned timezone, auto-fix. Enforcement is domain-aware.
    • Resync, Set timezone and Apply policy commands.
    • Windows only; needs agent 0.119.0.
  • Xero (#7263, #7286, #7290, #7295, #7297, #7301, #7399). OAuth connect with an organisation picker, a mapping workbench and customer import, invoice push and void, payment pull (webhook plus sweep), and payment push.
  • Report delivery status (#7451). Every saved report and run shows its organization and delivery status. A scheduled run that reached nobody is recorded as no_recipients.
  • Multi-org report series (#7458, #7459), set through the report's Covers control, and opt-in Combine (#7483).
  • Backup status report (#7426), using Cove's "All devices" layout.
  • Third-party backup in the portal (#7425). Devices protected by Cove count in the portal backup tile, the posture report and the org narrative. Gated by the portal enable backups setting.
  • Windows rebuild hosts (#7283). A whole-machine snapshot is rebuilt into a VHDX, and a Hyper-V VM is optionally created.
  • Brokered backup writes and snapshot attestations (#7353, #7372, #7396, #7482, #7486). This turns on automatically for S3 destinations over HTTPS once the 0.119 backup helper is on the device. A snapshot shows as attested about 21–26 minutes after its upload ends.
  • AI Suggested Fixes, part 1 (#7275). Partner-wide fix memory with "Proven fix" badges, votes and a find_proven_fixes tool. Off by default (ml.remediation_suggestions.enabled).
  • AI tools (#7125, #7223). 42 more read-only tools are wired into chat and agents, and manage_monitor_definitions is available in chat.
  • Approval Security (#7395). An org or partner can choose Platform default, Required or Not required for approver assurance.
  • Unassigned Devices holding area (#7397). This ships dark, behind PRE_ASSIGNMENT_ENROLLMENT_ENABLED=false.
  • Roles (#7334). force_mfa is editable in Settings → Roles and the Roles API, and cloning a role copies it.
  • Patch jobs tab (#7375). AI- and API-created patch jobs are listed with per-device results.
  • Mobile (#7198). A Reboot now button on reboot-pending alerts.
  • M365 tenant panel (#7402). A Read access step then an Admin actions step, with a consent pre-flight.
  • Command palette (#7403). Recents and browser tabs show item names, and create actions have keyboard chords.
  • guided-setup.sh --upgrade [VERSION] (#7351) for digest-pinned installs. A version-mismatch warning appears in Administration → System → Connections.
  • /health reports binariesVersion (#7234).
  • Passwordless SSO accounts can rotate recovery codes, delete passkeys and disable MFA after an IdP re-authentication (#7371).

Improved

  • Anomaly episodes: persistence and novelty gates cut episode noise by about 87%, and the device badge and fleet findings count open episodes (#7166, #7160).
  • Metric history retention works by dropping per-bucket partitions, which gives disk space back. Day-level rollups are re-derived hourly instead of every 5 minutes (#7535, #7383).
  • Backup storage-session traffic has its own rate limits (600 per session, 1,200 per device, 20,000 per org per minute), so heartbeats are never starved (#7405).
  • Large topology maps lay out within the 3-second budget (#7424).
  • macOS remote desktop uses a persistent capture stream, for a much higher frame rate on macOS 14 and later (#7232).
  • Software installs show Sent to agent, Downloading or Installing, and a stale warning, instead of a silent Pending (#7370).
  • "Heartbeating but no logs" is a queryable device condition (Logs silent) (#7259).
  • Restore and verification screens show device names and reasons instead of IDs and JSON. Large restores journal their resume state instead of rewriting it per file (#7354, #7339).
  • Backup cleanup skips redundant bucket listings. The readiness score no longer counts a missing restore test twice (#7330, #7328).
  • Vulnerability Remediate: overlapping replays collapse into one, and the response reports findings that are already queued (#7368).
  • AI:
    • tool schemas state the constraints the server enforces;
    • run_script refusals give actionable reasons;
    • fleet-health top issues survive compaction;
    • web chat uses tool search, which cuts first-call context by about 71% (AI_TOOL_SEARCH);
    • AI file tools check the resolved path, not the spelling.
      (#7222, #7221, #7242, #7224, #7430, #7485)
  • AI surfaces say "AI isn't configured" when no model provider is usable. Failed desktop starts show their reason (#7522, #7344).
  • Audit Trail shows fallback rows as readable operations (#7382). Accessibility fixes: select names, icon-only controls and sidebar contrast (#7250, #7247, #7243, #7229).
  • Mobile and 1024 px layout fixes across tab rows, headers, breadcrumbs, tables, the report builder, invoice and quote lines, and the device overview strip (#7225, #7227, #7228, #7230, #7233, #7238, #7239, #7240, #7241, #7245, #7249).
  • Write actions are hidden from roles that lack the permission. Software Inventory and Software Policies get nav entries (#7342, #7338).
  • 39 English strings damaged by an earlier extraction are restored. Built-in alert rules are kept out of Needs conversion (#7377, #7359, #7261).
  • Quick Support copy follows whether the served Windows agent is signed. The SSO provider form defaults correctly in the All-organizations view (#7231, #7343).

Fixed

  • TURN relaying on self-hosted stacks had been refused for every peer since v0.118.0. See the coturn step above (#7536).
  • Breeze Assist on macOS and Linux had been stuck on "agent is still setting up" since v0.118.0. The fix ships as a Helper update (#7534).
  • Billing contact. The Billing tab's Billing contact overwrote the org's primary contact, and invoices followed the primary instead of the contact with the Billing role (#7519). See Upgrade Notes.
  • Compliance alerts now alert on the first failing check, no longer auto-resolve while the device still fails, and close when their rule no longer applies. The automation-policy path is fixed (#7518, #7527).
  • Convert to monitor for a single rule returned 500 on every call (#7524).
  • PAM: approvals that the server refused were stored or shown as approved. Critical-tier approvals now collect the re-authentication they require (#7500, #7525, #7374, #7220).
  • Windows: an elevated administrator can enroll again (a v0.118.0 regression). Remote-desktop clicks land on target on mixed-DPI monitors (#7421, #7391).
  • macOS: the agent keeps its /usr/local/bin location when that path is safe, so Full Disk Access survives the upgrade. WebRTC desktop at the login window is refused and points to VNC Relay (#7262, #7332).
  • Agent reliability:
    • no restart on wake from sleep;
    • the paths that left an agent stranded after credential rotation are closed;
    • command results the server parked are resubmitted (#7361, #7362, #7378).
  • Commands: a command's completed state commits together with its per-type records. Queue and agent hand-offs wait until the transaction commits (#7366, #7348, #7364).
  • Helper updates stop untracked helpers first and never overwrite a kept rollback backup (#7356, #7373).
  • Backup capture:
    • Windows whole-machine capture (VSS root path, registry hives read from the shadow copy);
    • on-demand SQL Server and Hyper-V jobs stuck pending;
    • multipart encryption not confirmed on MinIO;
    • a blank Hyper-V warning (#7294, #7480, #7481, #7473).
  • Backup restore:
    • Windows selective restore accepts browse-tree paths;
    • Restore-as-VM drops the offline driver step, and Hyper-V tools run from the host's System32;
    • Restore-as-VM and instant boot no longer return 404 from the UI (#7219, #7484, #7218).
  • Backup jobs:
    • backups wait for a new device's capability report;
    • per-file upload deadline cap and a 24-hour backup_run timeout;
    • skipped junctions and mount points are named in the job warning (#7503, #7360, #7327).
  • Timestamps stored without a UTC offset were misread on API hosts not running in UTC, affecting report schedules, discovery intervals and other time-based checks (#7492).
  • Billing: a quote or invoice sent with "no footer" later printed a newly added footer. Bulk invoice push did nothing in manual push mode (#7341, #7253).
  • Integrations:
    • Umbrella DNS sync failed above 10,000 events per window;
    • M365 executors would not start on Azure Container Apps workload-profile environments;
    • QuickBooks webhooks are no longer blocked by the partner guard (the signature check runs first) (#7260, #7434, #7340).
  • AI: the script builder had no tools, and full-profile agent runs logged an error on every run (#7392, #7437).
  • A failed Add Device attempt no longer leaves a live 30-day enrollment key (#7346).
  • Pre-release sweep fixes: org settings pages use the organization in the URL, plus report, billing and backup copy and states (#7218, #7355, #7514).

Self-Hosting / Upgrade Notes

Upgrade command. Check how your install pins its images: grep '^BREEZE_API_IMAGE_REF=' .env.

  • Digest-pinned (the value ends in @sha256:…, which is every guided-setup.sh install for v0.112.0 or later). Fetch the current installer, then run the upgrade:
    curl -fsSLO https://raw.githubusercontent.com/lanternops/breeze/main/scripts/guided-setup.sh
    bash guided-setup.sh --upgrade 0.119.0
    It verifies the release's signed image inventory, then rewrites BREEZE_VERSION and all four BREEZE_*_IMAGE_REF digests together, pulls and restarts. It refuses targets older than 0.112.0, which have no signed inventory, and refuses a downgrade unless --allow-downgrade is passed.
  • Fresh installs with guided-setup.sh now also refuse a release older than 0.112.0, or a version that is not an exact release (such as latest), unless you pass --allow-unverified-release (#7544).
  • Tag-form (the value ends in :${BREEZE_VERSION}). Set BREEZE_VERSION=0.119.0 in .env, then run docker compose pull api web portal && docker compose up -d, plus pnpm install if you build from source. If you run the split worker, include it with docker compose --profile worker-split pull worker && docker compose --profile worker-split up -d worker.
  • Do not upgrade by only editing BREEZE_VERSION. On a digest-pinned install that pulls the images you already run, so nothing upgrades. If you did that on an earlier upgrade, run guided-setup.sh --upgrade 0.119.0 now. It re-pins the digests even when the version already matches.
  • Delete the APP_VERSION: line from your own docker-compose.yml (the API environment block). The shipped Compose files no longer set it, because the image carries its own version. Until you remove it, /health keeps reporting BREEZE_VERSION instead of the running image, and the new version-mismatch warning cannot fire (#7351).
  • Coming from v0.117.x or earlier: read the v0.118.0 notes first (legacy alerting retirement, macOS paths, DR plan steps).
  • Full guide: Upgrade Guide.

Database: 50 migrations, applied automatically on first boot. They are idempotent and run through autoMigrate unless AUTO_MIGRATE=false. All of them run before the API starts serving, so a slow migration lengthens the upgrade outage but cannot race live traffic. They were exercised with a non-superuser migration role, as used on managed Postgres. Take a database backup first, and don't run pg_dump or long psql sessions while the new API is booting, because migrations wait on their locks.

  • One backfill scales with your backup history. 2026-11-08-120000-backup-snapshot-id-reservations writes one reservation row per existing backup_snapshots row. A local test took about 13 s per 300,000 snapshots; expect longer on slower storage. Check SELECT count(*) FROM backup_snapshots; before upgrading if you have a large backup history. The rest are quick: on the same test database, which held 500,000 alerts, they took under 7 s combined. One of them clears an unused password hash from portal logins that sign in with Entra ID (#7543).
  • notification_channels.config is dropped (#7258). v0.118.0 moved channel configuration to its own table and kept this column for one release. Rollback limit: on a v0.118.x image, alert delivery keeps working, but creating or editing a notification channel fails until you roll forward again. Do not roll back below v0.118.0.
  • Metric history storage (#7535). The migration only reshapes empty future months. Months written before this release keep their old layout until the nightly maintenance job rewrites each one, and gives its disk space back, once that month's 5-minute data has expired (90 days by default). To reclaim space sooner, set METRIC_ROLLUP_5M_RETENTION_DAYS=30 (the minimum). Add it to .env and to the api service's environment: block (and worker, if split), because the shipped Compose files do not map it. Then restart. The migration creates a metric_rollups_staging schema; if your database role cannot run CREATE SCHEMA, the migration only warns. In that case create the schema by hand (CREATE SCHEMA metric_rollups_staging AUTHORIZATION <migration role>;), or old months cannot be rewritten.

No new required environment variables. The API boots on an unchanged .env. New optional settings:

  • XERO_CLIENT_ID, XERO_CLIENT_SECRET, XERO_REDIRECT_URI, XERO_WEBHOOK_KEY, XERO_DAILY_CALL_LIMIT (default 1000). Unset keeps Xero hidden. An invalid XERO_DAILY_CALL_LIMIT refuses boot. Already mapped in both Compose files.
  • AI_TOOL_SEARCH (auto by default, on, off). off restores the previous behaviour. Mapped in docker-compose.yml; add it yourself if you use deploy/docker-compose.prod.yml.
  • APPROVER_ASSURANCE_DEFAULT_ENFORCE_FROM (default 2026-11-05T00:00:00Z). Moves the approver-assurance date; an unparseable value refuses boot.
  • PRE_ASSIGNMENT_ENROLLMENT_ENABLED (default false). Keeps the Unassigned Devices holding area dark.
  • METRIC_ANOMALY_EPISODE_MIN_BUCKETS (default 2). Not mapped in Compose.
  • Removed: METRIC_ROLLUP_MAX_DELETE_BATCHES is no longer read.
  • Never set BREEZE_BINARIES_VERSION in .env or Compose. It is baked into the image.

Behaviour changes.

  • Live device inspection needs devices:execute (#7538, #7540). Process, service, scheduled-task, event-log, file and registry reads, and the live session list, need it. /devices/:id/sessions/live also accepts remote:access. Org Viewer, Partner Viewer and the two seeded approver roles lose live inspection, and custom roles that should keep it need devices:execute. MCP/API keys with only ai:read can no longer trigger live reads. analyze_disk_usage no longer scans on its own; pass refresh: true.
  • Site scoping (#7529, #7530). Fleet security posture, threats, the executive summary and OS distribution respect site-restricted access.
  • Remote consent (#7288, #7390):
    • On devices whose policy is Require consent, VNC tunnels, viewer-to-VNC fallback and VNC tickets return 409 CONSENT_REQUIRED_TRANSPORT_UNAVAILABLE. Technicians use the remote desktop viewer, which can ask.
    • Consent-mode desktop starts need an agent that supports the consent prompt; otherwise they return 409 CONSENT_UPGRADE_REQUIRED. Update agents on devices under a consent policy before upgrading the server.
    • An unreadable prompt policy refuses the start with 503 REMOTE_PROMPT_POLICY_UNAVAILABLE. To fix it, re-save the device's remote access policy.
    • The AI screenshot, screen-analysis and computer-control tools, and POST /devices/:id/diagnose, are refused on consent-mode devices. The refusal is audited as screen_access_consent_blocked.
    • Audit actions are renamed. An unanswered prompt is now session_consent_blocked_unanswered (was session_consent_denied). A prompt that could not be shown is now session_consent_blocked_unavailable (was session_consent_bypassed). Update saved audit filters, SIEM rules and exports. Rows written before the upgrade keep the old names.
  • S3 restores (#7237) need HTTPS end to end and an agent on v0.118 or later, with no fallback. Agents older than v0.118 get a 409 "Update the Breeze agent on this device". Keep MinIO's host and port when you switch to HTTPS; only the scheme may change, or earlier backups cannot be restored. Guide: https://docs.breezermm.com/backup/https-restores/. Local and NAS destinations, and backups themselves, are not affected.
  • Approver assurance (#7395). Partners that never saved an Approval Security choice need a registered approver device for high- and critical-risk approvals from 2026-11-05. A saved choice is kept. Move the date with APPROVER_ASSURANCE_DEFAULT_ENFORCE_FROM.
  • Secrets are encrypted and masked (#7533, #7254):
    • Notification secrets in partner, org and site settings (Slack webhook URL, webhook entries, Pushover tokens) are encrypted by an idempotent background sweep after the API's first boot. It uses the existing APP_ENCRYPTION_KEY, and there is no SQL migration.
    • Settings responses return secrets as ********. Integrations that GET and then PUT settings must send the marker back unchanged.
    • Changing a log-forwarding or Elasticsearch endpoint to a different origin needs the secret re-entered. A blank org Event Logs key now keeps the stored key instead of clearing it.
    • If you run a separate worker container (--profile worker-split), roll it together with api. An older worker would send the encrypted value.
    • If you ever roll back past this release, re-enter the partner Pushover defaults and the Slack URL, and re-add saved webhook entries.
  • Billing contact (#7519). An organization's invoice and quote recipient is now the org-level contact with the Billing role, with no fallback to the primary contact. The Billing tab is read-only and links to Contacts. No data is rewritten on upgrade. To find organizations whose invoices went to the primary contact because of the old behaviour, run the read-only detection query in PR #7519 with RLS bypassed (superuser or BYPASSRLS role). Then fix each organization in Contacts by giving the right contact the Billing role.
  • Compliance alerts (#7518, #7527). The built-in compliance alert templates switch to no-auto-resolve. Duplicate rule set names within one policy are now refused (400 DUPLICATE_COMPLIANCE_RULE_SET_NAME); PR #7527 has a query to find existing duplicates.
  • Built-in monitors. On first boot, every partner gets the built-in time-sync monitors. They are provisioned but not attached, so nothing alerts until you attach them. Opt out with BREEZE_BUILTIN_MONITORS_AUTOSEED=false.
  • AI configuration. Without a usable model provider, chat and the script builder answer 503 ai_not_configured instead of showing a false "ready" (#7522).
  • Non-UTC API hosts (#7492). Report schedules, discovery intervals and other time-based checks were shifted by the host's UTC offset. They are corrected with no action needed.

Agent and Breeze Helper: update to 0.119.0. These changes take effect on a device only once it runs the 0.119 agent or Helper:

  • time sync;
  • brokered backup writes and attestations;
  • the macOS Full Disk Access and login-window fixes;
  • mixed-DPI clicks;
  • wake from sleep and credential-rotation fixes;
  • helper-update fixes;
  • Restore-as-VM and instant-boot changes;
  • Assist on macOS and Linux (Helper update; users outside the breeze group see a "contact your administrator" message).

Devices under a Require consent policy need a consent-capable agent before the server upgrade (see above).

Macs moved by 0.118.0–0.118.2 stay in /Library/Breeze/bin, and a Full Disk Access grant already made there keeps working. Macs still on a stock, root-owned /usr/local/bin no longer move (#7262).

Breaking changes: none that remove an API or a setting. The soft-breaking changes above need attention before you upgrade:

  • TURN (manual coturn edit);
  • S3 restores over plain HTTP;
  • live inspection permission;
  • consent-mode VNC and the renamed audit actions;
  • masked settings secrets for GET-then-PUT integrations;
  • the approver-assurance date.

Known issues in this release:

  • Restore as new VM and instant boot create a Gen 2 VM with no EFI system partition, so the restored OS does not boot yet. File-level data in the VM is intact (#7493). Instant boot can also report success when bcdboot fails (#7494).
  • Topology explorer stays on "preparing" for sites without a topology-capable agent until an operator backfill runs (#7513).
  • Backup Status report preview tiles don't render, and its edit page shows the Devices builder (#7506).
  • Org Viewer sees a hydration error on every page, plus 403s from partner-only requests (#7498).

Full Changelog: v0.118.2...v0.119.0

What's Changed

Full Changelog: v0.118.2...v0.119.0

Don't miss a new breeze release

NewReleases is sending notifications on new releases.