Breeze RMM v0.83.2 — a large feature release: a new Vulnerability Management module, a QuickBooks Online accounting connection, TD SYNNEX EC Express distributor pricing, a redesigned network topology view, deeper Sentry observability, billing/quote presentation polish, and the US production crash-loop hotfix.
Summary
- Vulnerability Management (BE-16, Phases 1–4) — vulnerability detection, risk scoring, remediation workflow, and RBAC, with AI tools and events wired in. (#1861)
- QuickBooks Online — Phase A — the connection foundation: OAuth connect/disconnect for syncing accounting data (optional; off until configured). (#1849)
- TD SYNNEX EC Express pricing connector — real-time price & availability lookups by SKU, alongside the existing Digital Bridge transactional integration. (#1848)
- Network topology redesign — a measured backbone with host attachment, a Cytoscape-based view, and manual mapping. (#1842)
- Observability — per-request tenant/user Sentry context, a PII-scrubbing
beforeSend, and an uncaught-exception handler, so production errors are attributable and safe. (#1823, #1824) - Billing & quotes — presentation refresh plus typed-name e-signature. (#1862)
- Config-policy monitoring & compliance now surface in the portal. (#1873, #1874, #1875)
- US crash-loop hotfix — the API now survives a Postgres connection-teardown write race that was crash-looping the US droplet. (#1880)
Self-Hosting / Upgrade Notes
Upgrading from v0.83.1 → v0.83.2. Standard path: bump BREEZE_VERSION, then docker compose pull api web && docker compose up -d (run pnpm install if you build from source). No compose changes and no new containers, and no new required environment variables — every new var below is optional and the related feature stays dormant until you set it.
- Database — nothing required. 10 new migrations apply automatically on boot (
autoMigrate, unlessAUTO_MIGRATE=false); all idempotent, all new tables/columns/permissions with no large-table rewrites or backfills: vulnerability management + OS-facts tables, QuickBooks accounting connections, TD SYNNEX EC Express, network-topology layout/provenance/manual-nodes + topology write permission, the vuln risk-accept permission, and a config-policy run tenant-key backfill (small, logs its row count). - Recommended for all production self-hosters: #1880 fixes a Postgres connection-teardown write race that crash-looped the US droplet (manifesting as repeated API restarts and user logouts). If you've seen that pattern, upgrade.
New optional configuration
| Name | Required? | Purpose / notes |
|---|---|---|
QBO_CLIENT_ID, QBO_CLIENT_SECRET, QBO_REDIRECT_URI, QBO_ENVIRONMENT
| Optional | QuickBooks Online connect flow (#1849). All four must be set to enable it (QBO_ENVIRONMENT is sandbox or production); otherwise the connect endpoint reports "not configured" and nothing else changes.
|
NVD_API_KEY
| Optional | API key for NVD enrichment in Vulnerability Management. Unset is fine — NVD sync just falls back to slower unauthenticated rate limits (logged as a warning). |
SENTRY_DSN, SENTRY_PROFILES_SAMPLE_RATE
| Optional | Error monitoring / profiling. No-op if unset; with a DSN set you now get per-request tenant/user context and PII-scrubbed events. |
DB_CONTEXTLESS_WRITE_STRICT
| Optional (opt-in) | Fail-closed gate that throws if a DB write happens without a tenant context, for operators who want to enforce the tenant-isolation contract hard. Leave unset for normal operation. |
- TD SYNNEX EC Express credentials are entered in-app (Integrations → Distributors), not via environment variables.
- Reminder: any env var you set must also be mapped in the
apiserviceenvironment:block of your compose file — compose only interpolates the vars you list there.
What's Changed
- feat(catalog): TD SYNNEX EC Express pricing connector by @ToddHebebrand in #1848
- fix(web): orange dot for pending-reboot in device status column; "Upd"→"Updating" by @ToddHebebrand in #1850
- fix(reliability): compute uptime from observed availability, not the current boot session by @ToddHebebrand in #1851
- docs(ml): device-instability shadow model — execution addendum + Phase A plan by @ToddHebebrand in #1853
- fix(software-inventory): load list for "All Orgs" (aggregate across accessible orgs) by @ToddHebebrand in #1852
- chore(deps): bump google.golang.org/api from 0.284.0 to 0.286.0 in /agent by @dependabot[bot] in #1837
- chore(deps): bump the aws-sdk group in /agent with 2 updates by @dependabot[bot] in #1836
- fix(web): safelist runtime-built u-*-N utilities so prod CSS keeps them (#1829) by @bdunncompany in #1830
- fix(security): stop reporting unencrypted devices as encrypted (#1831) by @bdunncompany in #1834
- fix(installer): Windows install.bat must require elevation + stop reporting false success (#1832) by @bdunncompany in #1833
- Update mcp-server.mdx by @CookieSource in #1617
- fix(patches): repair Linux OS patch logic by @ramphex in #1775
- feat(accounting): QuickBooks integration — Phase A (connection foundation) by @ToddHebebrand in #1849
- docs: sharpen Codex delegation guidance from benchmark by @ToddHebebrand in #1826
- feat(observability): per-request tenant/user Sentry context (#1379 B2) by @ToddHebebrand in #1823
- feat(observability): beforeSend PII scrub + uncaughtException handler (#1379 B3+B4) by @ToddHebebrand in #1824
- feat(observability): dbWriteExpectingRows helper + apply to last_login_at (#1379 A2) by @ToddHebebrand in #1825
- feat(observability): opt-in contextless-write strict gate + login last_login_at contract test (#1379 A1+A3) by @ToddHebebrand in #1827
- docs: sync technical docs for v0.83.0 by @ToddHebebrand in #1843
- fix(helper): honor per-session --config flag in tray config (#1856) by @ToddHebebrand in #1858
- fix(automations): config-policy runs RLS-visible in portal (correct tenant key) (#1855) by @ToddHebebrand in #1860
- fix(alerts): repair config-policy offline rules + remove dead network metric (#1857) by @ToddHebebrand in #1859
- fix(test): repair auth.test.ts db.update mock for #1825 .returning() (main is red) by @ToddHebebrand in #1867
- feat(billing): quote/invoice presentation refresh + typed-name e-signature by @ToddHebebrand in #1862
- feat(topology): network topology redesign — measured backbone, host attachment, Cytoscape view, manual mapping (#1728) by @ToddHebebrand in #1842
- feat(web): surface config-policy monitoring + compliance status in portal (#1873, #1874) by @ToddHebebrand in #1875
- fix(web): Breeze Assist tab — show tray toggles when deploy off + honest badge (#1863) by @bdunncompany in #1864
- chore(deps): bump softprops/action-gh-release from 3.0.0 to 3.0.1 in the github-actions group by @dependabot[bot] in #1868
- chore(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in #1869
- Device overview UI polish: automated activity, collapsing Activity pane, clearer Reliability by @ToddHebebrand in #1877
- feat(vuln): BE-16 vulnerability management — detection, risk scoring, remediation, RBAC + AI tools/events (Phases 1–4) by @ToddHebebrand in #1861
- docs(superpowers): sync stray planning docs + QA logs from shared working copy by @ToddHebebrand in #1847
- fix(agent,api): watchdog version telemetry + local-source registration (#1802) by @ToddHebebrand in #1817
- fix(api): survive postgres connection-teardown write race (US crash-loop hotfix) by @ToddHebebrand in #1880
New Contributors
- @CookieSource made their first contribution in #1617
Full Changelog: v0.83.1...v0.83.2