github langflow-ai/langflow v1.12.4
1.12.4

2 hours ago

What's Changed

🐛 Bug Fixes

  • fix: reject mixed blocked DNS answers with IP allowlists by @erichare in #15334
  • fix(agent): compute recursion_limit accounting for middleware graph nodes by @premtiwari508 in #15362
  • fix(ci): keep PR filenames out of shell scripts by @erichare in #15328
  • fix(twelvelabs): confine Split Video file reads by @erichare in #15336
  • fix(auth): replace Passlib with bcrypt on release-1.12.4 by @erichare in #15368
  • fix(api): fail closed on unowned v1 build jobs by @erichare in #15335
  • fix: enforce admin policy for assistant execution by @erichare in #15337
  • fix(lfx): skip unsupported files when errors are silent by @erichare in #15329
  • fix: scope chat memory operations to flow and owner by @erichare in #15346
  • fix: validate public flows after group expansion by @erichare in #15342
  • fix(tracing): isolate tracer startup failures on 1.12.4 by @erichare in #15364
  • fix(amazon): correct S3 uploader strategy and file inputs on 1.12.4 by @erichare in #15366
  • fix(ssrf): pin direct Requests helper connections by @erichare in #15340
  • fix: validate database connector bootstrap targets by @erichare in #15332
  • fix: allow administrator-scoped database TLS files by @erichare in #15405
  • fix: reject ambiguous Couchbase IPv4 seed prefixes by @erichare in #15406
  • fix(frontend): keep model picked during a model refresh by @Cristhianzl in #15367
  • fix(lfx): stop flow loads from resetting settings by @Cristhianzl in #15372
  • fix: block known pickle deserializers in generated components by @erichare in #15345
  • fix(security): protect Bing Search URL from run tweaks by @erichare in #15330
  • fix: restrict Celery broker messages to JSON by @erichare in #15344
  • fix(mcp): reject direct Node runtime options in stdio configs by @erichare in #15338
  • fix(files): sanitize batch archive entry names by @erichare in #15339
  • fix(agents): show iteration limit notice after text by @Cristhianzl in #15369
  • fix(watsonx): validate credentials with a regional model by @erichare in #15353
  • fix: hide stored flow credentials from shared readers by @erichare in #15343
  • fix(deps): 1.12.4 dependency upgrades by @Adam-Aghili in #15427
  • fix: surface credential decryption failures at the default log level by @erichare in #15434
  • fix(knowledge-bases): keep ingested chunks within Chunk Size when a separator is set by @erichare in #15421
  • fix(authz): allow only one role per user per assignment scope by @erichare in #15426
  • fix(schema): sanitize underscore-prefixed field names in create_input_schema_from_json_schema by @TINGyu123644 in #15411
  • fix(lfx): keep table markdown proportional to data by @Cristhianzl in #15370
  • fix(lfx): apply Chat Output clean data to single tables by @Cristhianzl in #15420
  • fix(lfx): reject inputs shadowed by component methods by @Cristhianzl in #15373
  • fix(authz): reject unknown result and actor_type filters on the audit query by @tarciorodrigues in #15424
  • fix(release): scope the bundle PyPI guard to the build's lfx line by @erichare in #15437
  • fix(authz): reject role assignments for inactive users by @erichare in #15453
  • fix(frontend): keep flow lock saved during node update by @Cristhianzl in #15439

📝 Documentation Updates

✅ Tests

  • test: give TestPerformIngestionTask its own database by @erichare in #15423

New Contributors

Full Changelog: v1.12.3...v1.12.4

Don't miss a new langflow release

NewReleases is sending notifications on new releases.