github hasura/graphql-engine v2.50.0

4 hours ago

Changelog

This is a patch release for v2.50.

Bug fixes and improvements

Server

  • IMPORTANT: fix a bug in the mssql backend that could in certain cases allow an authenticated user to observe data they were not authorized for. All MS SQL Server users are encouraged to upgrade. More details to be released.
  • server: add cascade option to the remove_remote_schema API.
  • Async actions now preserve the originating GraphQL request's distributed trace context (W3C TraceContext / B3). The async actions processor continues the original trace when invoking the action handler webhook instead of starting a new, disconnected trace, restoring end-to-end visibility in OTel-compatible tracing backends. (Enterprise/cloud only) (Enterprise/cloud only)
  • Add HASURA_GRAPHQL_DISABLE_ADMIN_SECRET and --disable-admin-secret to ignore the x-hasura-admin-secret request header and use configured webhook, JWT, SSO, or collaborator-token authentication instead.
  • event trigger names now undergo stricter validation, and must only contain alphanumeric, underscore and hyphen characters. Formerly this was only a warning on replace_metadata. Server upgrades over metadata containing non-conforming names should continue to work, but names must be fixed before the next replace_metadata.
  • Restore the pre-existing naming behaviour as the default. A previous change made the September-2023 naming convention the unconditional default, which was a breaking change for existing OSS/EE users. The September-2023 behaviour is once again opt-in, now via the HASURA_FF_NAMING_CONVENTION_SEP_2023 environment variable (true/false, case-insensitive, default false).
  • Improve the performance of order_by ...asc_nulls_first and ...desc_nulls_last in the MSSQL backend (contributed by Behzad Fattahi)

CLI

  • cli: fix security vulnerabilities in cli-ext dependencies (bumps vulnerable transitive packages including @babel/traverse, tar, lodash, and immutable).

Data Connector

  • super-connector: upgraded the Quarkus platform (3.33.1.1 -> 3.33.2.1, for quarkus-vertx-http) to remediate CVE-2026-50559 (HIGH: authorization bypass in HTTP path-based policies via encoded characters) flagged by the container image scan. (Enterprise/cloud only)

Build

  • docs: fix security vulnerabilities in documentation-site dependencies (bumps vulnerable packages including tar, shell-quote, postcss, svgo, immutable, serialize-javascript, lodash, axios, sharp, dompurify, uuid, and wrangler to patched versions).
  • Upgraded frontend/console npm dependencies to remediate HIGH/CRITICAL security advisories (axios, semver, and transitive packages via Yarn resolutions). No user-facing behaviour change.
  • cli-migrations-v3: add the HASURA_GRAPHQL_DISALLOW_INCONSISTENT_METADATA environment variable to the enable --disallow-inconsistent-metadata for the metadata apply command.
  • Fixed Postgres SSL connection failures for the self-hosted Ubuntu image when
    running on FIPS-enabled hosts. Since v2.49.5 (Ubuntu Noble base), OpenSSL tried
    to load a FIPS provider that is not shipped in the container, causing libpq SSL
    context initialization to fail (could not create SSL context: could not load the shared library) and fall back to a rejected cleartext connection. The
    image now sets OPENSSL_FORCE_FIPS_MODE=0 (upstream-documented workaround for
    Ubuntu bug LP#2141933) so it boots and negotiates TLS to Postgres on FIPS hosts.
    This is a container bootability fix and is not a FIPS certification claim.

Don't miss a new graphql-engine release

NewReleases is sending notifications on new releases.