github windmill-labs/windmill v1.713.0

6 hours ago

1.713.0 (2026-05-31)

Features

  • flows: preserve step/subflow worker tags under a custom-tagged flow (#9375) (f0301b1)
  • oauth: support per-provider sandbox URLs (#9358) (2bf11dc)

Bug Fixes

  • ai: validate token_url for SSRF in OAuth credentials flow (#9385) (4b06881)
  • api: authorize and harden log-file reading endpoints (#9368) (bb90f4c)
  • apps: make public apps opt into cross-origin isolation via wm_coep (GIT-884) (#9374) (2c0c2c4)
  • auth: enforce monotonic privilege on user token lifecycle endpoints (#9371) (2ddf93d)
  • batch encryption-key rotation into one git-sync job (#9355) (04a0897)
  • cli: preserve user drafts on sync push and permissioned-as (#9381) (b0c3b01)
  • frontend: sanitize user markdown to prevent stored XSS (#9386) (def01b8)
  • security: re-pin cached hub scripts to CVE-patched versions (+ HUB_BASE_URL override for cache mode) (#9387) (edf340c)

Don't miss a new windmill release

NewReleases is sending notifications on new releases.