github TracecatHQ/tracecat 1.1.0
Tracecat 1.1.0

4 hours ago

Breaking changes

  • chore(integrations)!: Remove legacy Google SecOps Python actions (#3583)
  • feat(api)!: Consolidate invitations into one table with role grants (#3453)
  • fix(agents)!: Enforce sandbox memory budgets with cgroups (#3654)
  • feat(engine+agents)!: Unify execution backend configuration (#3656)
  • feat(agents)!: Surface underlying error as agent.executor.unclassified (#3676)
  • feat(rbac+ui)!: Pin roles to their level; drop workspace RBAC pages (#3682)
  • fix(engine)!: Enforce executor sandbox memory with cgroups (#3668)
  • feat(engine)!: Remove legacy workflow interactions (#3716)

Security

  • fix(audit): Resolve client IPs on Fargate behind Service Connect (#3695)
  • fix(audit): Bypass Service Connect proxy for Fargate ALB traffic (#3696)

Case management

  • fix(cases): Scroll wide markdown tables in descriptions and comments (#3534)
  • fix(cases): Hide Mermaid source alongside rendered diagrams (#3542)
  • fix(cases): Strip NUL bytes from case comment content (#3594)
  • fix(cases): Return 404 when removing an unattached tag (#3642)
  • feat(cases+ui): Add JSON custom field type with highlighted editor (#3711)
  • feat(cases+actions): Accept short IDs for case_id inputs (#3713)
  • feat(cases+tables): Add, edit and view linked rows from the case page (#3719)
  • fix(ui+cases): Bound alert dialogs to the viewport and scroll (#3720)
  • fix(ui+cases): Sort case tasks alphabetically (#3718)
  • feat(tables+cases): Search and sort rows by column (#3728)
  • docs(cases+tables): Add aggregate and search cheatsheet (#3731)
  • fix(tables+cases): Keep rows visible while a row query loads (#3735)
  • feat(cases+tables): View related cases for a linked table row (#3745)

Tables

  • feat(tables): Add resumable chunking for long text (#3512)
  • fix(tables): Bind lookup values with column types (#3567)
  • feat(tables): Add semantic search storage and shared contracts (#3503)
  • feat(tables): Reuse AI providers for search embeddings (#3518)
  • feat(tables): Track semantic search indexing lifecycle (#3572)
  • feat(tables+actions): Add ranked semantic table search (#3576)
  • feat(tables): Add semantic search column controls (#3577)
  • fix(tables): Load parent metadata before column mutations (#3649)
  • fix(tables): Return actionable errors for invalid table rows (#3645)
  • feat(tables+ui): Replace vector search status strip with header badge (#3712)
  • feat(tables+ui): Show semantic search columns on badge and headers (#3727)
  • feat(enterprise+tables): Gate semantic search behind an entitlement (#3730)
  • fix(tables): Reject empty row updates with a 400 instead of a 500 (#3752)

Agents

  • fix(agents): Classify preparation permission denials (#3537)
  • feat(mcp): Nudge preset agent usage (#3554)
  • fix(agents): Preserve cancellation after cleanup timeout (#3555)
  • fix(agents): Classify registry lock failures as registry errors (#3506)
  • fix(agents): Preserve Slack errors during runtime cleanup (#3556)
  • refactor(agents): Share output schema normalization (#3562)
  • feat(skills): Add agent skill update and draft UDFs (#3561)
  • docs(agents): Document private CIDR allowlist for on-prem LLM providers (#3568)
  • fix(agents+integrations): Surface and block custom actions shadowing builtins (#3579)
  • feat(enterprise+skills): Add folders and tags for agent skills (#3553)
  • fix(agents): Distinguish gateway cooldown from provider throttling (#3538)
  • feat(agents): Add pluggable session backends (#3570)
  • fix(agents): Preserve chunked HTTP request bodies (#3610)
  • docs(skills): Block database migrations in patch releases (#3616)
  • fix(agents): Stop retrying user-denied tool calls after approval (#3630)
  • feat(agents): Add GPT-6 Astra and Claude Fable 5.1 to platform catalog (#3593)
  • fix(agents+mcp): Report current skill version on presets, never pin (#3617)
  • fix(agents): Tolerate unsigned thinking blocks in session history (#3598)
  • feat(agents): Add Claude Opus 5.5 and Sonnet 5.5 to platform catalog (#3651)
  • fix(agents): Preserve cancellation during runtime teardown (#3647)
  • fix(agents): Surface HTTP status and error code in LLM provider failures (#3515)
  • feat(agents): Add GPT-6 Sol, GPT-6 Luna, and GPT-6.1 Sol to catalog (#3660)
  • fix(agents): Normalize Read tool inputs at the LLM proxy (#3584)
  • fix(agents): Ignore ping keep-alive stream events (#3665)
  • feat(agents): Support child sessions and history forks (#3604)
  • fix(agents): Retry rate-limited LLM requests in the socket proxy (#3674)
  • fix(agents): Classify disabled model access as user config failure (#3673)
  • feat(agents): Add output_type override to ai.preset_agent (#3666)
  • fix(agents): Attribute mcp failures (#3602)
  • feat(agents): Stream foreground Pi child sessions (#3618)
  • feat(agents): Define mention syntax and reference contracts (#3684)
  • feat(agents): Discover and subscribe to AWS Bedrock models (#3694)
  • fix(agents): Block ScheduleWakeup and ListAgents Claude Code tools (#3699)
  • feat(agents+enterprise): Open source approvals and inbox, gate channels (#3710)
  • fix(ui): Show interrupted subagent child tools as interrupted (#3722)
  • fix(agents): Run Claude Code subagents in the foreground (#3723)
  • feat(agents+api): Add default agents and opt-in chat visibility (#3724)
  • fix(agents): Read reasoning_effort from newer agent payloads (#3725)
  • feat(agents): Allow approval-gated subagents on capable backends (#3734)
  • feat(ui+agents): Redesign agent preset builder and agents list (#3751)
  • docs(agents): Add distributed alerting example (#3753)

Tracecat MCP

  • fix(mcp): Allow clearing output_type in update_agent_preset (#3526)
  • feat(mcp): Action addressing and per-action execution results (#3544)
  • feat(mcp): Add workspace sync export and pull tools (#3566)
  • feat(mcp+ui): Auto-layout MCP workflows and compact run_if badges (#3658)
  • feat(mcp): Support attaching subagents to agent presets (#3650)
  • fix(mcp): Default agent presets to latest subagents and skills (#3686)

Core actions

  • fix(actions): Add region_name and cap threads in DuckDB action (#3559)
  • fix(actions): Cap malloc arenas in DuckDB action under RLIMIT_AS (#3643)

Functions

  • fix(functions): Preserve pinned Slack template compatibility (#3761)

Integrations

  • feat(integrations): Add Azure DevOps OAuth providers and HTTP templates (#3581)
  • feat(integrations): Add Perplexity MCP server (#3587)
  • feat(integrations): Add Rapid7 templates and bulk export MCP server (#3588)
  • docs(integrations): Document the OAuth redirect URI (#3590)
  • feat(integrations): Add TypeSafe System One API template (#3638)
  • fix(integrations): Handle OAuth token exchange failures (#3648)
  • docs: Clarify direct executor sandboxing limits (#3655)
  • feat(integrations): Add GitHub App provider for GitHub templates (#3669)
  • fix(integrations): Read full S3 object body in AWS Boto3 call_api (#3677)
  • perf(integrations): Read GitHub sync pulls from one commit tarball (#3688)
  • feat(integrations): Expand Wazuh API coverage for detection and response (#3703)
  • feat(integrations): Add Palo Alto Networks PAN-OS, Strata and Prisma Cloud templates (#3704)
  • feat(integrations): Add FortiSIEM actions and event query helper (#3709)
  • fix(integrations): Resolve workspace scopes in the OAuth callback (#3755)

Engine

  • fix(engine): Retry truncated S3 downloads during materialization (#3521)
  • feat(engine): Add org-gated per-action toggle to disable secret error withholding (#3497)
  • fix(engine): Avoid registry cache scans after warm actions (#3549)
  • fix(engine): Classify invalid for_each expressions as user errors (#3548)
  • fix(engine): Compile dependencies to reduce activity inputs (#3536)
  • fix(engine): Fall back when dependency compilation fails (#3563)
  • fix(engine): Surface workload stderr in sandbox workload failures (#3595)
  • feat(engine): Index table text in durable background batches (#3575)
  • fix(engine): Preserve errors with provenance-based secret masking (#3600)
  • fix(engine): Classify unreachable join failures as user errors (#3580)
  • fix(engine): Prevent duplicate attempts overwriting stored results (#3705)

API

  • feat(api): Return resource bodies from create and update endpoints (#3523)
  • feat(api): Add workflow draft read/replace endpoints (#3522)
  • fix(api): Tighten validation and response contracts for Terraform (#3525)
  • feat(api+ui): Show IP, user agent and last seen in organization sessions (#3501)
  • feat(api+ui): Add per-organization IP allowlist (#3502)
  • docs(api): Document organization IP allowlist and session visibility (#3509)
  • fix(api): Allow templated preset and alias refs in workspace sync export (#3519)
  • feat(api): SMTP delivery (#3401)
  • feat(api): Add invitation email outbox delivery (#3424)
  • feat(api+ui): Resend invitation emails (#3427)
  • fix(ui+api): Show real item counts on workflow folders (#3571)
  • feat(api+ui): Support AWS Secrets Manager as an external secret source (#3498)
  • feat(api): Add Bitbucket workspace Git sync (#3601)
  • fix(api): Return 422 for malformed workflow IDs (#3639)
  • fix(ui+api): Count nested workflows in folder view header (#3641)
  • feat(rbac): Synchronize membership with role changes (#3394)
  • feat(rbac): Any role grants organization membership (#3447)
  • fix(api): Handle interrupted webhook request bodies (#3652)
  • feat(rbac): Add SCIM data model (#3659)
  • feat(rbac): Add SCIM provisioning API (#3530)
  • fix(api): Make default settings initialization race-safe (#3667)
  • fix(ui+api): Explain SAML enforcement on social login errors (#3664)
  • feat(ui+rbac): Restore workspace add member button with org auto-invite (#3698)
  • refactor(api): Read SAML attributes from parsed assertion (#3706)
  • feat(ui+rbac): Add member access columns and invite-to-group (#3707)
  • fix(api+ui): Polish secret stores ui/ux (#3701)
  • fix(ui+api): AWS secret refs in Git sync, fix store setup docs (#3717)

User interface

  • fix(ui): Restore Tailwind peer/group variants dropped by selector parser (#3524)
  • fix(ui): Show chat panel divider and widen its drag target (#3551)
  • fix(ui): Stop toasting 403 responses (#3557)
  • fix(ui): Allow mouse wheel scrolling in folder picker dropdowns (#3569)
  • fix(ui): Use official Google SecOps logo for Google Chronicle (#3585)
  • feat(ui): Add SCIM organization settings (#3531)
  • fix(ui): Forward client IP on integration OAuth and GitHub App installs (#3687)
  • fix(ui): Show full template key names in the credential dialog (#3746)
  • fix(ui): Show tool results that arrive after a cancel in their cards (#3733)

Infrastructure

  • infra: Add pgvector support to application databases (#3500)
  • ci: Publish releases from branches and guard latest (#3560)
  • fix(infra): Merge alembic heads so upgrade head resolves (#3612)
  • ci: Enforce linear Alembic migrations (#3613)
  • fix(infra): Port alpha.2.1 migration re-parenting to main (#3614)
  • fix(infra): Read Compose healthcheck ports from container env (#3636)
  • feat(infra): Support disabling TLS verification for blob storage (#3637)
  • fix(infra): Replace MinIO image with Chainguard in Compose files (#3640)
  • docs(infra): Correct unified backend chart requirement (#3672)

Observability

  • fix(logging): Preserve originating LLM proxy failure stacks (#3442)

Documentation

  • docs: Align hosted MCP server count (#3543)
  • docs: Clarify alpha hotfix release branches (#3611)

Dependencies

  • build(deps): Update dependencies to remove obsolete overrides (#3547)
  • build(deps): Upgrade Claude Agent SDK to 0.2.160 (#3603)
  • build(deps): Patch PyJWT, urllib3, oauthlib and axios advisories (#3715)

Fixes

  • fix(build): Point 0.0.0.0 error message to existing docs page (#3533)

Build system

  • build: Shrink app images by removing duplicated layers (#3629)

Other changes

  • chore: Allow model invocation of gh-prerelease skill (#3496)
  • test: Remove redundant and placeholder tests (#3646)

Contributors

@daryllimyt, @topher-lo, @jordan-umusu, @aaron-tracecat and devin-ai-integration[bot]

Full changelog: 1.0.1...1.1.0

Don't miss a new tracecat release

NewReleases is sending notifications on new releases.