github LanternOps/breeze v0.83.0

latest releases: v0.118.2, v0.118.1, v0.118.0...
pre-release3 months ago

Breeze RMM v0.83.0 — 73 commits since v0.82.1 (18 features, 34 fixes, dependency & CVE sweep).

Highlights

  • Partner-wide management across all orgs — partner-owned configuration policies (#1724), partner-wide SentinelOne integration (#1735), and org-independent (partner-scoped) patch update rings & approvals (#1764).
  • PAM — reusable signer-group (trusted-publisher) catalog (#1771), rule-matching cluster with command-line/negation/default-unmatched verdicts (#1761), and uac_intercept elevations bridged to the mobile approval surface (#1254).
  • Remote sessions — end-user consent & notification before a session starts (#1694).
  • Device reliability — device-type-aware uptime weighting (#1721), a sortable Device Reliability column, and an Ask-AI / mark-outcome workflow on the reliability card.
  • Quotes → Contracts — accepted quote recurring lines auto-create draft contracts (#1759); contracts auto-renew with renewal notices (#1765).
  • Virtual/VDI detection — hypervisor identified as an orthogonal device attribute (#1387).
  • Mobile & UX — responsive data tables app-wide (ResponsiveTable primitive, #1760) and a unified chip-centric filter bar with saved views (#1762).

Features

  • Scripts: scope changer on the edit screen (#1734)
  • Integrations: surface Huntress inbound webhook URL + secret in the GUI (#1737)
  • Devices: sortable Device Reliability column (#1720)
  • Observability: tag Postgres RLS-deny (42501) errors in Sentry (#1379)

Fixes

Stability / performance

  • #1105 connection-hold mitigations: monitor checks now enqueue outside the DB transaction (#1840), and the txn-around-slow-work tripwire is wired into the slow primitives (#1806).
  • ML: seasonal anomaly baselines must be ready before scoring (#1675).
  • Huntress: retry transient sync failures + surface real sync status (#1736).
  • Patches: reconcile orphaned scheduled patch_jobs never enqueued to the executor (#1733).
  • API: stop masking S3 transport faults as 404s in viewer/software download paths (#1808, #1802).

Agent

  • UAC discovery on Windows 11 (correct LUA event ids + target extraction) (#1816)
  • Watchdog component now auto-updates (#1800)
  • Pressure-aware RAM usage reporting on macOS (#1717)

Web / UX

  • Preserve Monaco editor theme across View-Transition navigation (#1589)
  • Keep AI chat panel pinned to bottom on submit + streaming (#1713)
  • Preserve sidebar nav scroll position across navigation (#1714)
  • Process drilldown empty states + drillable area charts (#1722)
  • Device Activity pane as an index-backed last-N feed (#1726)

Discovery / inventory

  • Project SNMP data into the asset list so the detail modal renders it (#1731)
  • Guard the Network Discovery page in All-Orgs mode (#1727)
  • Per-site device count in GET /orgs/sites (#1790)
  • Warranty: re-sync when hardware inventory first identifies a device (#1732) and surface refresh feedback (#1723)

Security

  • Hardened OAuth bearer-token authorization — org-level client blocks are now honored for partner-scoped bearers (#1656).
  • Backslash-safe ILIKE escaping for ticket/mobile search (#99).

Dependencies

  • 15 dependency updates (hono, bullmq, twilio, @anthropic-ai/sdk, @sentry/astro, lucide-react, node, and others).
  • CVE remediations: dompurify/babel/otel via overrides (#1767), tar (GHSA-3pv8-6f4r-ffg2), and quinn-proto 0.11.15 (RUSTSEC-2026-0185) in the helper.

Self-Hosting / Upgrade Notes

Upgrading from v0.82.1 → v0.83.0. Standard path: bump BREEZE_VERSION in /opt/breeze/.env, then docker compose pull api web && docker compose up -d. If you build from source, run pnpm install (dependencies changed). This is a feature-heavy release but an easy upgrade — no new required environment variables and no compose/container changes (unlike v0.82.0, which added the portal container — that requirement is unchanged here).

  • Database — nothing required. 13 new migrations apply automatically on boot (autoMigrate, unless AUTO_MIGRATE=false); each is idempotent and wrapped in its own transaction. They are all new tables/columns/indexes — no large-table rewrites or backfills: partner-scoped config policies, update rings, and patch approvals; partner-wide SentinelOne mapping; the PAM signer-group catalog, matching cluster, and approval↔elevation link; contracts auto-renew; ticket-comment editing; the device virtualization/VDI attribute; Huntress sync-result columns; remote-session-consent settings; and audit-log device-feed indexes.
  • Watchdog now auto-updates (#1800). The watchdog component is registered and promoted alongside the main agent, so it no longer stays pinned at an old version. No operator action — but expect watchdog binaries to start tracking releases. (This works with the new AGENT_AUTO_PROMOTE flag shipped in v0.83.1.)
  • Connection-hold mitigations (#1105). Monitor checks now enqueue outside the DB transaction (#1840) and a txn-around-slow-work tripwire is wired into the slow primitives (#1806). Relevant if you've seen connection-pool exhaustion / "too many clients" under load.
  • Partner-scoped patch rings & approvals change how partner admins scope update approvals (now org-independent). No migration action; review your ring configuration if you manage patching at the partner level.
  • Pre-release: v0.83.0 was tagged as a pre-release pending production verification; the stable line continues at v0.83.1+.

Full commit log: v0.82.1...v0.83.0

What's Changed

Full Changelog: v0.82.1...v0.83.0

Don't miss a new breeze release

NewReleases is sending notifications on new releases.