github LanternOps/breeze v0.65.16

latest releases: v0.121.1-hotfix.2, v0.121.1-hotfix.1, v0.121.0...
4 months ago

Routine upgrade — no new env vars, no manual pre-deploy steps. 18 migrations auto-apply idempotently on container start (including #750's device-child org_id backfill — indexed, small, one-time).

✨ Features

  • Wake-on-LAN — relay-aware dispatch, audit trail, agent magic-packet handler (#703)
  • Third-party patching — package catalog, CVE enrichment, AI release smoke tests (#690, #735)
  • Pluggable remote-desktop launchers — RustDesk / ScreenConnect / TeamViewer / … (#680)
  • Mobile approval mode — MCP step-up trusted-device surface, phase 1 (#611, #745)
  • Per-link expiry picker on Add Device (#739) · Pushover notification channel (#676) · drag-to-reorder organizations (#681) · set_auto_update command (#692) · Windows GUI user-helper (#699) · devices list page-size + 500 cap (#705, #748) · WS-A action feedback & error legibility (#740)

🐛 Fixes

  • Pending-partner login regression — verified signups no longer trapped in an auth loop (#718)
  • Device-child org_id RLS cascade — stops agent inventory upsert RLS failures after a device org move (#750)
  • Mobile biometric consent binding + silent-failure hardening (#745, #746)
  • scripts.is_system RLS visibility (#715) · approval reaper + account-deletion RLS (#743) · offline-consistent patch rollback (#734) · public registration re-enabled · BINARY_SOURCE=local manifest signing (#625) · orgs/sites explicit orgId (#732) · Site form validation (#708)

🔒 Security

Numerous CVE-clearing dependency bumps + supply-chain guard hardening.


Verified before tag: main CI green · #718 / #746 / #750 e2e-tested locally · 2026-05-15 QA sweep covered ~13 PRs + 38 nav routes · prior P0 hosted-deploy blocker #646 closed.


What's Changed

  • feat(mobile): phase 1 — approval mode (MCP step-up trusted-device surface) by @ToddHebebrand in #611
  • feat: Drag-to-reorder organizations on the settings page by @bdunncompany in #681
  • feat(alerts): Pushover notification channel with partner-level inheritance + at-rest encryption by @bdunncompany in #676
  • fix(alerts): consolidate channel types + readable errors (#677, #678, #679) by @ToddHebebrand in #686
  • fix(web): adopt extractApiError project-wide by @ToddHebebrand in #689
  • fix(api): scope lifecycle middleware to /me/* and /admin/* (#683) by @ToddHebebrand in #688
  • feat(web): switch device list view when changing organizations from device detail by @bdunncompany in #682
  • fix(security): bump supply-chain guard's pinned node version from 22 to 26 by @bdunncompany in #693
  • feat(agent,api): add set_auto_update command (#671) by @ToddHebebrand in #692
  • docs(contributing): mirror CI gate locally before pushing by @bdunncompany in #685
  • feat(patches): third-party patching with catalog, CVE enrichment, and AI release smoke tests by @ToddHebebrand in #690
  • fix(agent/config): atomically fsync+rename agent.yaml and secrets.yaml (#642) by @ToddHebebrand in #695
  • docs(cert): backup certification system design + Plan 1 foundation by @ToddHebebrand in #691
  • chore(deps): bump protobufjs and fast-xml-builder via pnpm overrides to clear Trivy HIGH CVEs by @bdunncompany in #697
  • fix(release-manifest): hardening + tests from #635 review by @ToddHebebrand in #701
  • feat(agent,windows): ship GUI-subsystem breeze-user-helper.exe to suppress logon console flash by @bdunncompany in #699
  • chore(deps): clear 12 Trivy HIGH CVEs (glob/minimatch/pnpm/tar) + bump pnpm to 10.33.4 by @ToddHebebrand in #704
  • chore(deps): post-#704 cleanup — dev pin, --legacy TODO, supply-chain coverage, workflow inputs by @ToddHebebrand in #706
  • chore(deps): override devalue 5.6.4-5.8.0 to clear CVE-2026-42570 by @ToddHebebrand in #707
  • fix(api,agent): truncate connection inventory strings to column widths (#504) by @ToddHebebrand in #711
  • feat: Wake-on-LAN — relay-aware dispatch, audit trail, agent magic-packet handler by @bdunncompany in #703
  • feat(web): per-page-size selector on Devices list (Discussion #684) by @bdunncompany in #705
  • feat: Pluggable remote-desktop launcher (RustDesk / ScreenConnect / TeamViewer / ...) (#610) by @bdunncompany in #680
  • chore(git): untrack stale .claude/worktrees gitlinks by @ToddHebebrand in #717
  • fix(api): GET /orgs/sites honors explicit organizationId over ambient orgId (#723) by @ToddHebebrand in #732
  • feat(api): schedule CVE enrichment job + accept osvEcosystem on catalog (#731) by @ToddHebebrand in #735
  • fix(api): include version in GET /patches list response (#729) by @ToddHebebrand in #733
  • fix(api): rollback uses queueCommandForExecution for offline-consistent results (#730) by @ToddHebebrand in #734
  • feat(web): WS-A — action feedback & error legibility (runAction) (#720, #725, #727, #678) by @ToddHebebrand in #740
  • fix(api): restore approval reaper + account-deletion admin queue (RLS system-scope bypass) by @ToddHebebrand in #743
  • fix(mobile): bind biometric consent to the request the user saw (#696 Critical #3) by @ToddHebebrand in #745
  • feat(web,api): per-link expiry picker on Add Device modal (Discussion #629) by @bdunncompany in #739
  • fix(api): scripts.is_system rows visible to partner-scope and org-scope readers (#633) by @bdunncompany in #715
  • fix(web,api): persist user role change in Settings → Users + .strict() guard (#710) by @bdunncompany in #713
  • perf(api): /devices latest-metrics — LATERAL+LIMIT 1 over GROUP BY MAX by @bdunncompany in #747
  • feat(devices): raise /devices limit cap to 500 for small-MSP fleets by @bdunncompany in #748
  • fix(web,api): relax Site form validation (Discussion #628) by @bdunncompany in #708
  • fix(api): createCustomFieldSchema accepts null options + deviceTypes by @bdunncompany in #749
  • chore(deps): Bump github.com/Azure/azure-sdk-for-go/sdk/storage/azblob from 1.6.4 to 1.7.0 in /agent by @dependabot[bot] in #756
  • chore(deps): Bump google.golang.org/api from 0.278.0 to 0.279.0 in /agent by @dependabot[bot] in #759
  • chore(deps): Bump the typescript-tooling group with 2 updates by @dependabot[bot] in #760
  • chore(deps): Bump @tanstack/react-query from 5.100.10 to 5.100.11 in the tanstack group by @dependabot[bot] in #763
  • chore(deps): Bump hono from 4.12.18 to 4.12.19 in the hono group by @dependabot[bot] in #764
  • chore(deps): Bump bullmq from 5.76.2 to 5.76.10 by @dependabot[bot] in #765
  • chore(deps): Bump @anthropic-ai/sdk from 0.95.2 to 0.96.0 by @dependabot[bot] in #766
  • chore(deps): Bump expo-local-authentication from 55.0.13 to 55.0.14 by @dependabot[bot] in #768
  • chore(deps): Bump tauri-build from 2.6.1 to 2.6.2 in /apps/helper/src-tauri by @dependabot[bot] in #770
  • chore(deps): Bump tauri from 2.11.1 to 2.11.2 in /apps/viewer/src-tauri by @dependabot[bot] in #771
  • chore(deps): Bump tauri from 2.11.1 to 2.11.2 in /apps/helper/src-tauri by @dependabot[bot] in #772
  • chore(deps): Bump tauri-build from 2.6.1 to 2.6.2 in /apps/viewer/src-tauri by @dependabot[bot] in #773
  • fix(agent/api): suppress console window for user-helper child spawns on Windows by @bdunncompany in #755
  • fix(web): action-toast accessibility + flush-on-mount so wake feedback is visible (#720) by @bdunncompany in #722
  • fix(auth): let pending partners authenticate so billing redirect works (#718) by @ToddHebebrand in #774
  • fix(mobile): surface interrupted/thrown biometric auth on the approval consent action (#746) by @ToddHebebrand in #775
  • fix(api): cascade devices.org_id to device-child tables on org move (#750) by @ToddHebebrand in #776

Full Changelog: v0.65.15...v0.65.16

Don't miss a new breeze release

NewReleases is sending notifications on new releases.