·
12 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Operational roles can inspect workspace-wide activity while actions stay limited by current runner and pack access. Console runbook starts keep the release and plan you reviewed, and changed plans ask for another review.
Console and access
- SSO groups show role, runner, and pack access together. Edit roles in place and filter members on the provider page. Connection defaults remain locked; group mappings can add access.
- Profile has compact details, separate verified email changes, clearer MFA and sign-in guidance, and more useful session information with ten sessions per page.
- Approval recovery distinguishes catalog failures, unavailable actions, and changed contracts. Runner/pack access changes preserve entered notes, inputs, and unsaved runbook edits while refreshing controls.
- SIEM export tokens are paginated. Large lists and catalog refreshes avoid repeated work. Retained runbook output renders without an associated action attempt.
Security and clients
- Shared reads do not authorize execution, cancellation, approval, or access changes. Use separate workspaces when teams must not see each other's operational records.
- Owners always have workspace-wide action access. Existing Owner scopes are normalized with an audit record; use Admin for scoped administration.
- Runner credential rotation uses the authenticated connection. The dispatch journal appends durable transitions and compacts periodically.
- Windows Hermes and Goose setup uses native configuration paths. Setup guidance includes co:op, and agent requests have clearer reason, evidence, and expected-result guidance.
Packs and billing
- New Stripe and Braintree packs cover billing investigation, refunds, disputes, and related corrections.
- The Airflow pack supports Airflow 2 (API v1) and Airflow 3 (API v2). Jobs, assets, and backfills require Airflow 3.
- GCP project discovery follows the current credentials; Cloudflare analytics reports GraphQL errors; pack limits follow backend and per-run constraints.
- Checkout returns to its original workspace. Monthly reports go to every Owner, and unsubscribing turns reports off for the whole workspace.
Upgrade notes
- This release includes seven forward migrations. Existing unused console-generated runner setup keys get a 24-hour lifetime; generate a new setup command if an old one has expired. Used keys and manually created keys retain their expiry.
- Owner access normalization is audited and does not restore narrower grants on rollback. Rolling back the new group-access constraints can fail if newer independent grants still need them.