Skip to content

Releases: Perruer/keelflow

Keelflow 3.2.1

Choose a tag to compare

@github-actions github-actions released this 25 Sep 15:00

A small release with fixes and one change to where new installations keep their data.

Data folder

New installations keep their data in the platform's data folder instead of another dot folder in the home directory:

  • Linux: $XDG_DATA_HOME/keelflow (by default ~/.local/share/keelflow)
  • macOS: ~/Library/Application Support/keelflow
  • Windows: %LOCALAPPDATA%\keelflow

Existing data is never moved. A ~/.keelflow or ~/.flowise that holds files keeps being used, and so does the /home/node/.keelflow volume in the Docker image. KEELFLOW_HOME still overrides everything. Thanks to the reader on Habr who suggested it.

Fixes

  • Evaluations fall back to the local server when APP_URL is not set.
  • The stats endpoint answers a malformed request with a JSON 400 instead of echoing the parser error.
  • The data and log folders are created together with their parent folders.

Upgrade

docker pull ghcr.io/perruer/keelflow:3.2.1

Full list: CHANGELOG.

Keelflow 3.2.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 13:14

First release of Keelflow, the security-maintained continuation of Flowise. It starts from Flowise 3.1.4, the last Flowise release, and runs on the same databases, flows, credentials and API keys.

Install

docker run -d --name keelflow -p 3000:3000 -v ~/.keelflow:/home/node/.keelflow ghcr.io/perruer/keelflow:3.2.0

Coming from the Flowise image? Keep your volume and change only the image: a volume at /home/node/.flowise is picked up automatically. See Migrating from Flowise.

Highlights

  • Apache-2.0 only. Flowise's open source edition signed users in with code under the FlowiseAI Commercial License. That code is removed from the repository and its history, and replaced by an independent owner account with API keys and server-side sessions.
  • Security fixes for advisories published after Flowise's end of life: cross-workspace credential access during flow runs (GHSA-27w2-26m5-x82c), unauthenticated registration (GHSA-v5w9-prxf-w882), the queue dashboard open to any signed-in user (GHSA-rpcc-gw54-mfgx); SSO account takeovers no longer apply because SSO is gone.
  • vm2 3.12.2: closes the sandbox escapes in Custom Function and Custom Tool nodes.
  • Dependencies: known advisories in the lockfile down from 385 to 153, critical from 19 to 1 (install-time only).
  • No calls home: the web UI no longer loads an affiliate tracker, Google Fonts or the GitHub API, and the model list ships with the app.
  • Datasets, evaluations, evaluators and server logs are available without a paid plan.
  • Tested upgrade path: CI builds a database with the published flowise@3.1.4 migrations and starts Keelflow on it; sign-in and API keys are checked on SQLite, Postgres, MySQL and MariaDB.

Not carried over

SSO, invitations, roles, several users and switching workspaces (Flowise Enterprise features), Stripe billing, and the @flowiseai/agentflow / @flowiseai/observe SDKs.

Full list: CHANGELOG.md