github LanternOps/breeze v0.83.2

latest releases: v0.119.0, v0.118.2, v0.118.1...
3 months ago

Breeze RMM v0.83.2 — a large feature release: a new Vulnerability Management module, a QuickBooks Online accounting connection, TD SYNNEX EC Express distributor pricing, a redesigned network topology view, deeper Sentry observability, billing/quote presentation polish, and the US production crash-loop hotfix.

Summary

  • Vulnerability Management (BE-16, Phases 1–4) — vulnerability detection, risk scoring, remediation workflow, and RBAC, with AI tools and events wired in. (#1861)
  • QuickBooks Online — Phase A — the connection foundation: OAuth connect/disconnect for syncing accounting data (optional; off until configured). (#1849)
  • TD SYNNEX EC Express pricing connector — real-time price & availability lookups by SKU, alongside the existing Digital Bridge transactional integration. (#1848)
  • Network topology redesign — a measured backbone with host attachment, a Cytoscape-based view, and manual mapping. (#1842)
  • Observability — per-request tenant/user Sentry context, a PII-scrubbing beforeSend, and an uncaught-exception handler, so production errors are attributable and safe. (#1823, #1824)
  • Billing & quotes — presentation refresh plus typed-name e-signature. (#1862)
  • Config-policy monitoring & compliance now surface in the portal. (#1873, #1874, #1875)
  • US crash-loop hotfix — the API now survives a Postgres connection-teardown write race that was crash-looping the US droplet. (#1880)

Self-Hosting / Upgrade Notes

Upgrading from v0.83.1 → v0.83.2. Standard path: bump BREEZE_VERSION, then docker compose pull api web && docker compose up -d (run pnpm install if you build from source). No compose changes and no new containers, and no new required environment variables — every new var below is optional and the related feature stays dormant until you set it.

  • Database — nothing required. 10 new migrations apply automatically on boot (autoMigrate, unless AUTO_MIGRATE=false); all idempotent, all new tables/columns/permissions with no large-table rewrites or backfills: vulnerability management + OS-facts tables, QuickBooks accounting connections, TD SYNNEX EC Express, network-topology layout/provenance/manual-nodes + topology write permission, the vuln risk-accept permission, and a config-policy run tenant-key backfill (small, logs its row count).
  • Recommended for all production self-hosters: #1880 fixes a Postgres connection-teardown write race that crash-looped the US droplet (manifesting as repeated API restarts and user logouts). If you've seen that pattern, upgrade.

New optional configuration

Name Required? Purpose / notes
QBO_CLIENT_ID, QBO_CLIENT_SECRET, QBO_REDIRECT_URI, QBO_ENVIRONMENT Optional QuickBooks Online connect flow (#1849). All four must be set to enable it (QBO_ENVIRONMENT is sandbox or production); otherwise the connect endpoint reports "not configured" and nothing else changes.
NVD_API_KEY Optional API key for NVD enrichment in Vulnerability Management. Unset is fine — NVD sync just falls back to slower unauthenticated rate limits (logged as a warning).
SENTRY_DSN, SENTRY_PROFILES_SAMPLE_RATE Optional Error monitoring / profiling. No-op if unset; with a DSN set you now get per-request tenant/user context and PII-scrubbed events.
DB_CONTEXTLESS_WRITE_STRICT Optional (opt-in) Fail-closed gate that throws if a DB write happens without a tenant context, for operators who want to enforce the tenant-isolation contract hard. Leave unset for normal operation.
  • TD SYNNEX EC Express credentials are entered in-app (Integrations → Distributors), not via environment variables.
  • Reminder: any env var you set must also be mapped in the api service environment: block of your compose file — compose only interpolates the vars you list there.

What's Changed

  • feat(catalog): TD SYNNEX EC Express pricing connector by @ToddHebebrand in #1848
  • fix(web): orange dot for pending-reboot in device status column; "Upd"→"Updating" by @ToddHebebrand in #1850
  • fix(reliability): compute uptime from observed availability, not the current boot session by @ToddHebebrand in #1851
  • docs(ml): device-instability shadow model — execution addendum + Phase A plan by @ToddHebebrand in #1853
  • fix(software-inventory): load list for "All Orgs" (aggregate across accessible orgs) by @ToddHebebrand in #1852
  • chore(deps): bump google.golang.org/api from 0.284.0 to 0.286.0 in /agent by @dependabot[bot] in #1837
  • chore(deps): bump the aws-sdk group in /agent with 2 updates by @dependabot[bot] in #1836
  • fix(web): safelist runtime-built u-*-N utilities so prod CSS keeps them (#1829) by @bdunncompany in #1830
  • fix(security): stop reporting unencrypted devices as encrypted (#1831) by @bdunncompany in #1834
  • fix(installer): Windows install.bat must require elevation + stop reporting false success (#1832) by @bdunncompany in #1833
  • Update mcp-server.mdx by @CookieSource in #1617
  • fix(patches): repair Linux OS patch logic by @ramphex in #1775
  • feat(accounting): QuickBooks integration — Phase A (connection foundation) by @ToddHebebrand in #1849
  • docs: sharpen Codex delegation guidance from benchmark by @ToddHebebrand in #1826
  • feat(observability): per-request tenant/user Sentry context (#1379 B2) by @ToddHebebrand in #1823
  • feat(observability): beforeSend PII scrub + uncaughtException handler (#1379 B3+B4) by @ToddHebebrand in #1824
  • feat(observability): dbWriteExpectingRows helper + apply to last_login_at (#1379 A2) by @ToddHebebrand in #1825
  • feat(observability): opt-in contextless-write strict gate + login last_login_at contract test (#1379 A1+A3) by @ToddHebebrand in #1827
  • docs: sync technical docs for v0.83.0 by @ToddHebebrand in #1843
  • fix(helper): honor per-session --config flag in tray config (#1856) by @ToddHebebrand in #1858
  • fix(automations): config-policy runs RLS-visible in portal (correct tenant key) (#1855) by @ToddHebebrand in #1860
  • fix(alerts): repair config-policy offline rules + remove dead network metric (#1857) by @ToddHebebrand in #1859
  • fix(test): repair auth.test.ts db.update mock for #1825 .returning() (main is red) by @ToddHebebrand in #1867
  • feat(billing): quote/invoice presentation refresh + typed-name e-signature by @ToddHebebrand in #1862
  • feat(topology): network topology redesign — measured backbone, host attachment, Cytoscape view, manual mapping (#1728) by @ToddHebebrand in #1842
  • feat(web): surface config-policy monitoring + compliance status in portal (#1873, #1874) by @ToddHebebrand in #1875
  • fix(web): Breeze Assist tab — show tray toggles when deploy off + honest badge (#1863) by @bdunncompany in #1864
  • chore(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.1 in the github-actions group by @dependabot[bot] in #1868
  • chore(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in #1869
  • Device overview UI polish: automated activity, collapsing Activity pane, clearer Reliability by @ToddHebebrand in #1877
  • feat(vuln): BE-16 vulnerability management — detection, risk scoring, remediation, RBAC + AI tools/events (Phases 1–4) by @ToddHebebrand in #1861
  • docs(superpowers): sync stray planning docs + QA logs from shared working copy by @ToddHebebrand in #1847
  • fix(agent,api): watchdog version telemetry + local-source registration (#1802) by @ToddHebebrand in #1817
  • fix(api): survive postgres connection-teardown write race (US crash-loop hotfix) by @ToddHebebrand in #1880

New Contributors

Full Changelog: v0.83.1...v0.83.2

Don't miss a new breeze release

NewReleases is sending notifications on new releases.