github baptisteArno/typebot.io v3.17.0

4 hours ago

New features

  • ✨ Add Ask Model action using OpenAI Responses API (#2455) [20d11a5]
  • 👌 Add time filter to results export and fix CSV download on R2 (#2449) [90bc7a9]
  • 👌 (openai) Add Ask Model file search controls (#2483) [fa7cc8c]

UI/UX Improvements

Fixed

  • 🐛 Handle GA script load failure to prevent bot from hanging (#2446) [d3c15f3]
  • 🐛 Fix PostHog tracking by updating cookie domain to typebot.com (#2447) [55b2900]
  • 🐛 Add missing date-fns dependencies to @typebot.io/results [e1530b6]
  • 🐛 Fix transcript compute crash on choice items with session-var display condition (#2468) [050f906]
  • 🐛 Fix monthly cron tx timeout when deleting archived typebots (#2481) [85eb843]
  • 🐛 Fix Pexels video picker infinite loading loop (#2479) [b72a374]
  • 🐛 Fix WhatsApp webhook verification (#2498) [e296c87]
  • 🐛 Fix PartyKit deploy workflow gate (#2500) [c549cec]

Security

  • 🐛 Fix credential access control and remove vulnerable S3 upload endpoint (#2459) [7ae4c00]
  • 🐛 Fix SSRF bypass via DNS rebinding in HTTP request and script fetch flows (#2461) [b25c41b]
  • 🐛 Fix SSRF safe dispatcher DNS lookup handling (#2462) [892870f]
  • 🔒️ Add SSRF_ALLOWED_HOSTS env for self-hosted internal APIs (#2474) [5b5f82d]
  • 🔒️ Upgrade vulnerable deps (ai v5, nodemailer v8, otel sdk-node 0.217) (#2491) [6f289f6]
  • 🔧 Hash API tokens (#2492) [fdcc178]
  • 🐛 Sanitize CSV exports against formula injection (#2493) [89682dd]
  • 🐛 Prevent cross-typebot webhook resume IDOR (#2494) [6f915c3]
  • 🐛 Fix WhatsApp status forwarding SSRF protection (#2497) [30cbc61]
  • 🐛 Fix WhatsApp preview webhook authorization (#2499) [36a6186]
  • 🐛 Fix Google Sheets OAuth callback authorization (#2501) [c0ffd82]
  • 🐛 Fix unsafe upload URL generation (#2502) [a64e82b]

Content

  • 📝 Add chatbot automation blog post (#2443) [0969c4e]
  • 📝 Add "Whatsapp Automation Chatbot" blog post (#2444) [b145784]
  • 📝 Update blog posts links (#2445) [f9d2a75]
  • 📝 Remove urgent support section from help docs (#2464) [da165df]
  • 📝 Fill common docs gaps (logs, user commands, downgrade, persistent input) (#2466) [70b7fdf]
  • 📝 Add Pro-only callout, workspace switcher doc, external messaging guide (#2470) [b9002d8]
  • 📝 Document graph edge pitfall and theme republish requirement (#2471) [60a77f0]
  • 📝 Document VAT ID for B2B reverse charge (#2473) [3e98f92]
  • 📝 Document status page and analytics completion criteria (#2480) [30682a2]
  • 📝 Add new blog posts batch (#2484) [85a1c37]
  • 📝 Added faq dir + cover image to articles (#2485) [367de01]
  • 📝 Update blog content (#2489) [77fd228]
  • 📝 Add auth failure troubleshooting section to self-hosting docs (#2495) [091db9e]

Internal

  • 🔧 Upgrade Claude Code GitHub Actions workflows (#2460) [6b30ff3]
  • 🐛 Fix missing workspace membership check in getSheets endpoint (#2467) [91d2a98]
  • 🐛 Fix Google Sheets picker 401 by setting Cloud Project AppId (#2486) [8e67415]
  • 🐛 Add trigger_onepick OAuth param for Google Sheets picker (#2487) [babe333]
  • ⏪ Revert Google Sheets picker fixes (#2486, #2487) (#2488) [67c7c86]
  • 📝 Update commit skill and ignore .pi [060033b]
  • 🔧 Add WhatsApp status forward URL update script (#2496) [5861031]

Don't miss a new typebot.io release

NewReleases is sending notifications on new releases.