github LanternOps/breeze v0.86.0

latest releases: v0.119.0, v0.118.2, v0.118.1...
3 months ago

Breeze RMM 0.86.0 — Astro 7 / Tailwind 4 / Vite 8 frontend modernization, plus quotes & invoices polish and a batch of correctness fixes.

This is a large frontend build-toolchain release (494 files) but a light upgrade for operators: no database migrations, no new required environment variables, no feature flags, and no runtime breaking changes.

Summary

  • Frontend stack — both apps/web and apps/portal migrated to Tailwind 4 and upgraded to Astro 7 + Vite 8 (Rolldown). Build-time only; prod images and runtime behavior unchanged (#1991, #1995, #2008).
  • Quotes & invoices — totals now compute from one shared source of truth so the editor, line totals, and live-totals rail can't disagree; plus optimistic reordering and accessibility polish (#2011).
  • Reliability scoring — the #1967 event-classification de-junk is now complete for macOS and Linux, with a server-side hardware-error gate so stale/old-agent junk can no longer depress hardware scores (#2005).
  • Fixes — self-hosted Windows short-link installer 500s, Site address/contact persistence, and the device Effective Config tab now showing warranty (and other) feature cards (#2002, #2001, #2003).
  • Hardening — silent 0-row writes on four update/delete endpoints now surface as real errors instead of fake success (#2001).

Improved

  • Quotes & invoices polish — Quote totals are computed from a single shared computeQuoteTotals helper, so the optimistic editing UI, per-line totals, and the right-rail "Live totals" can no longer disagree with each other or with the next server load, even at sub-cent rounding. Adds optimistic block/line reordering (debounced, with a duplicate-id guard protecting sort_order), a unified save/dirty-state model, and accessibility improvements (live regions, focus management, WCAG target sizing). No schema changes. (#2011)

Fixed

  • Reliability scoring de-junk for macOS & Linux — extends the 0.85.0 Windows-only event-classification fix (#1967) to macOS and Linux: macOS IOKit/App Store chatter and JetsamEvent reports, and routine Linux kernel chatter (USB/ACPI), are no longer misclassified as hardware faults or device crashes. A server-side isGenuineHardwareError gate at the scoring and offenders chokepoints means junk from historical data and from devices still on old agent binaries can't depress the hardware factor. Per-app crashes now count as a downweighted app_crash — crash tiles still show every crash, but per-app crashes weight well below a BSOD/kernel panic in the score. Scores self-heal within hours via the existing recompute automation; no operator action required. (#2005)
  • Effective Config tab now shows warranty (and other) feature cards — the device Effective Configuration tab previously rendered a hardcoded list of 8 feature types and silently dropped the rest, so a device with a warranty policy showed no warranty card (hiding the source of unexpected warranty alerts). It now renders warranty plus other baseline types; enforced features get full cards, and unassigned baselines collapse into a single "Not enforced — using Breeze Defaults" chip strip. Web device-detail page only. (#2003)
  • Public Windows short-link installer 500s (self-hosted) — on self-hosted 0.85.0, public Windows installer short links (/s/<code>) returned HTTP 500 for every request: the public path creates a child enrollment key with createdBy: null and the installer helper coerced it to "", invalid for the nullable uuid foreign key. Now passes null through cleanly. Dashboard Direct Download and macOS short links were never affected. Self-hosters on 0.85.0 hitting this should upgrade. (#2002)
  • Site address & contact now persist — editing a customer Site (Settings → Organizations → site → Details) and clicking Save silently discarded the address/contact fields, because the page sent a flat field shape while the API stores nested JSONB and Zod stripped the unknown keys. Now maps flat ↔ nested on read and write. (#2001)

Security

  • Silent 0-row write guards (defense-in-depth) — added explicit failure responses to update/delete handlers that previously returned 200 + null on a 0-row write (an RLS rejection or post-SELECT race), which read to clients as a fake success: PATCH /orgs/sites/:id, PATCH /discovery/profiles/:id, POST /discovery/assets/:id/link, DELETE /monitors/:id. These tables already have RLS forced, so cross-tenant writes were already prevented — this converts a silent fake-success into a real error. (#2001)

Self-Hosting / Upgrade Notes

No breaking changes at runtime. The Astro 7 / Tailwind 4 / Vite 8 change is build-time only — production Docker images, the upgrade command, and runtime behavior are unchanged.

  1. Upgrade command. Bump BREEZE_VERSION=0.86.0 in .env, then docker compose pull api web && docker compose up -d. If you build from source, run a fresh pnpm install after pulling — dependencies changed substantially (drops @astrojs/tailwind / postcss / autoprefixer; adds @tailwindcss/vite + tailwindcss@4; Astro/Vite/adapter major bumps). Build commands are unchanged (astro build / astro preview work as before). Node pin is unchanged (v22.20.0).
  2. Database — nothing required. No migrations in this release.
  3. No new required environment variables.
  4. Behavior changes & feature flags. No feature flags added. Two server-side scoring/UI behaviors changed, both self-applying with no per-org opt-in or grandfathering: reliability scores recompute to exclude misclassified macOS/Linux events (self-heals within hours, #2005), and the Effective Config tab's layout/counts changed to surface all enforced feature types (#2003).

Full Changelog: v0.85.0...v0.86.0


What's Changed

Full Changelog: v0.85.0...v0.86.0

Don't miss a new breeze release

NewReleases is sending notifications on new releases.