github LanternOps/breeze v0.67.1

latest releases: v0.121.1-hotfix.2, v0.121.1-hotfix.1, v0.121.0...
4 months ago

⚠️ Critical for v0.67.0 self-hosters

If you're running v0.67.0, upgrade to v0.67.1 before your next agent upgrade cycle. v0.67.0 shipped Windows binaries with no embedded version metadata, which caused the MSI installer to silently refuse to overwrite existing breeze-agent.exe in many real-world upgrade scenarios. The install would report success while the binary on disk was still the old one. v0.67.1 embeds VersionInfo correctly and broadens the kill-processes step (#944, #949).

Verify after upgrade:

Get-Item 'C:\Program Files\Breeze\breeze-agent.exe' | Select-Object -ExpandProperty VersionInfo | Select FileVersion, ProductVersion
# FileVersion: 0.67.1, ProductVersion: 0.67.1

🛡️ Operator-visible improvements

  • Windows service auto-restart is now configured on MSI deploys. After install, sc qfailure BreezeAgent shows 5s/10s/30s restart escalation with a 24h reset window. Complements the watchdog auto-restart that shipped in v0.67.0 — that handles the "main agent wedged but still alive" case; this handles the "main agent crashed hard" case (#853, #944, #949).
  • Authenticated Redis required in production. REDIS_PASSWORD must be set when NODE_ENV=production or the API refuses to boot. If you're on a self-hosted deploy without a Redis password configured, set one before upgrading (#909).
  • Docker images pinned to Node 24 LTS — supply-chain hardening (#908).
  • SSRF protection on outbound integration URLs (DNS providers, SentinelOne) plus MFA gating on admin suspend/provision routes (#918).
  • Audit-log sanitizer + Sentry-side redaction on background sync jobs (#923).
  • Cross-org device relocation — new admin endpoint POST /devices/:id/move-org with a dual-axis audit trail (#875). New admin endpoint POST /devices/provision for pre-creating device rows (#902).
  • Decommission-bypass re-enrollment — re-enrolling a device on a hostname whose previous row was decommissioned now mints a fresh device.id and renames the old row to free the slot. Audit history on the old row is preserved (#914, #924).
  • Sidebar version-staleness indicator — the sidebar footer's API version colors red when behind the latest GitHub release, green when current (#903).

🔧 Workflow fixes

  • Enrollment keys are no longer burned on failed enrollments. Hostname collisions and device-limit errors used to consume a single-use key's only allowed use even though no device was created. The key's usage_count is now incremented only after the device row is successfully written (#946, #948).
  • Enrollment-key API rejects unknown fields. A misspelled maxUses (canonical: maxUsage) used to silently fall through to the default of 1. Now returns 400 with the offending key in the error (#945, #947).
  • Re-enrollment without prior token on a decommissioned row no longer 401s when the existing row is in decommissioned status (#896).

🐧 Agent fixes

  • Agent supervises BreezeWatchdog from inside itself (Layer A4) so a stopped watchdog gets restarted by the main agent the same way the watchdog restarts the main agent (#854, #860).
  • Domain Controller management-state detection falls back to the registry when dsregcmd /status fails — DCs return non-zero from dsregcmd in many configurations (#895).

🔍 Security launch-readiness

  • 45-commit hardening sweep covering site-scoped RBAC, drift checks, audit-trail integrity, OAuth client soft-revocation on suspicious approval, and more (#864, #868, #872, #900, #904).

📦 Upgrade

Self-hosted (/opt/breeze):

ssh root@<droplet> "cd /opt/breeze && \
  cp .env .env.bak-pre-0.67.1 && \
  sed -i 's/^BREEZE_VERSION=.*/BREEZE_VERSION=0.67.1/' .env && \
  docker compose pull api web && \
  docker compose up -d binaries-init api web"

# Verify
curl -sf https://<your-domain>/health | jq .version
# "0.67.1"

Windows agent: msiexec /i breeze-agent.msi /qn SERVER_URL=<your-url> ENROLLMENT_KEY=<key> ENROLLMENT_SECRET=<secret> over the v0.67.0 install. The MSI handles MajorUpgrade cleanly.


What's Changed

  • test(patches): align approval tests with raw db.execute path (#821) by @bdunncompany in #855
  • fix(devices): reject duplicate refresh_inventory commands with 409 (#830) by @bdunncompany in #856
  • feat(devices): expose mainAgentSilentSince + watchdogStatus on list endpoint (#800 web-UI gap) by @bdunncompany in #861
  • fix(devices): dedup refresh_inventory on the bulk endpoint too (#830 follow-up) by @bdunncompany in #863
  • feat(devices): amber 'Agent silent (watchdog OK)' badge on device row (#800 web-UI gap) by @bdunncompany in #862
  • Customer launch readiness: RBAC + site-scope + MFA + config hardening by @ToddHebebrand in #864
  • fix(api): tolerate canonical-case repo in release manifest verifier (#866) by @ToddHebebrand in #867
  • security: SP2 launch-readiness — site-scoped RBAC + drift check by @ToddHebebrand in #868
  • feat(dns-security): emit dns.threat.blocked from sync so event-bus consumers can subscribe by @bdunncompany in #843
  • fix(web): surface remote-access launcher skip-reason instead of silently falling back to WebRTC by @bdunncompany in #869
  • chore(api): drop legacy mcp:write→ai:execute back-compat expansion (TODO past 2026-05-15) by @bdunncompany in #870
  • chore: knock three #714 nits — provider-id UUID, dead TRIVY_FS_RAN var, dead EffectiveOrgSettings field by @bdunncompany in #871
  • fix(api): soft-revoke OAuth client on self-reported suspicious approval (close ~15min access-token window) by @bdunncompany in #872
  • chore(preflight): mirror the Gitleaks secret-scan CI gate locally (#714) by @bdunncompany in #873
  • fix(agent): isolate TestRunCleansUpTempFile workDir — kill the intermittent Test Agent CI red by @bdunncompany in #874
  • fix(agent/backup): close mtime race in TestRunBackup_WithRetention by @bdunncompany in #894
  • chore(deps): Bump the github-actions group with 4 updates by @dependabot[bot] in #876
  • chore(deps): Bump github.com/aws/aws-sdk-go-v2/credentials from 1.19.16 to 1.19.17 in /agent by @dependabot[bot] in #879
  • chore(deps): Bump google.golang.org/api from 0.279.0 to 0.280.0 in /agent by @dependabot[bot] in #882
  • chore(deps): Bump github.com/pion/webrtc/v4 from 4.2.12 to 4.2.13 in /agent by @dependabot[bot] in #883
  • chore(deps): Bump serde_json from 1.0.149 to 1.0.150 in /apps/viewer/src-tauri by @dependabot[bot] in #892
  • chore(deps): Bump serde_json from 1.0.149 to 1.0.150 in /apps/helper/src-tauri by @dependabot[bot] in #893
  • chore(deps): Bump node from e71ac5e to 7c6af15 in /apps/web by @dependabot[bot] in #897
  • chore(deps): Bump node from e71ac5e to 7c6af15 in /apps/api by @dependabot[bot] in #898
  • chore(deps): Bump node from e71ac5e to 7c6af15 in /docker by @dependabot[bot] in #899
  • chore(deps): Bump the typescript-tooling group with 2 updates by @dependabot[bot] in #877
  • feat(web): DevicesPage walks /devices cursor (#742 PR 3b — web) by @bdunncompany in #778
  • feat(web): inline edit for Display Name on device Details tab by @bdunncompany in #787
  • fix(installer): apply SCM service-recovery actions on MSI deploys by @bdunncompany in #853
  • fix(web): render permission-aware empty state on platform-admin 403 (#721) by @bdunncompany in #857
  • feat(web): version staleness indicator in sidebar by @ToddHebebrand in #903
  • security: launch-readiness hardening (45-commit sweep) by @ToddHebebrand in #900
  • feat(agent): supervise BreezeWatchdog from inside the agent (Layer A4, Discussion #854) by @bdunncompany in #860
  • security: code-scanning sweep — bounds check, dep bumps by @ToddHebebrand in #904
  • fix(agent/mgmtdetect): fall back to registry when dsregcmd fails on DCs by @bdunncompany in #895
  • feat(dns-security): scaffold web UI — sidebar entry, /dns-security page, Integrations tab by @bdunncompany in #847
  • fix(agents/enroll): allow re-enrollment without prior token when existing row is decommissioned by @bdunncompany in #896
  • feat(devices): POST /devices/provision for admin pre-creation of device rows by @bdunncompany in #902
  • chore(deps): Bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.22.18 to 1.22.19 in /agent by @dependabot[bot] in #881
  • chore(deps): Bump the testing group across 1 directory with 2 updates by @dependabot[bot] in #887
  • chore(deps): Bump astro from 6.3.5 to 6.3.8 in the astro group across 1 directory by @dependabot[bot] in #878
  • chore(deps): Bump hono from 4.12.19 to 4.12.23 in the hono group across 1 directory by @dependabot[bot] in #885
  • chore(deps): Bump pg and @types/pg by @dependabot[bot] in #889
  • chore(deps): Bump posthog-react-native from 4.44.3 to 4.45.16 by @dependabot[bot] in #888
  • chore(deps): Bump react-native-screens from 4.23.0 to 4.25.2 by @dependabot[bot] in #891
  • chore(deps): Bump postcss from 8.5.14 to 8.5.15 in the tailwind group across 1 directory by @dependabot[bot] in #884
  • chore(deps): Bump @tanstack/react-query from 5.100.11 to 5.100.14 in the tanstack group across 1 directory by @dependabot[bot] in #880
  • chore(deps): Bump @react-native-async-storage/async-storage from 3.0.2 to 3.1.0 by @dependabot[bot] in #890
  • feat(devices): POST /devices/:id/move-org for cross-org device relocation by @bdunncompany in #875
  • feat(db): scaffold PAM elevation_requests + elevation_audit schema (Discussion #858 Track 1) by @bdunncompany in #905
  • feat(api): PAM software-policy bridge (Discussion #858 Track 2) by @bdunncompany in #906
  • feat(agent): offline PAM rule cache (Discussion #858 Track 7) by @bdunncompany in #907
  • fix(agents/enroll): mint fresh device.id on decom-bypass (closes #914) by @bdunncompany in #924
  • security: audit-sanitizer + global Sentry capture + sync-job redaction + CI hygiene by @ToddHebebrand in #923
  • security: SSRF allowlists + MFA-gate admin/suspend + provision auth fail-closed by @ToddHebebrand in #918
  • fix(redis): require authenticated Redis in production deploys by @ToddHebebrand in #909
  • fix(docker): pin api/web images to Node 24 LTS by @ToddHebebrand in #908
  • fix(enrollment-keys): reject unknown fields on POST/PATCH (closes #945) by @ToddHebebrand in #947
  • fix(enrollment): only consume key after successful device insert (closes #946) by @ToddHebebrand in #948
  • fix(installer): embed VERSIONINFO + broaden KillBreezeProcesses (closes #944) by @ToddHebebrand in #949

Full Changelog: v0.67.0...v0.67.1

Don't miss a new breeze release

NewReleases is sending notifications on new releases.