Repository navigation
v0.6.5
Release Date: August 9, 2026
π Features & Privacy
- Core Crypto, Blind Indexing & Context-Aware API Filtering β Introduced
PrivacyServicein@beechcms/corewith AES-256-GCM encryption for confidential fields and HMAC-SHA256 Blind Indexing for searchable classified fields. API endpoints automatically handle data decryption and masking based on caller permissions. The dashboard editing interface allows clear-text management of confidential fields, avoiding double encryption or double hashing during updates, and displays compact badges for classified fields. (#278) - Demo Data Ingestion & Privacy-Aware UI Widgets β Integrated the pipeline for demo data ingestion and updated dashboard widgets to support data privacy. Entry creation now automatically populates
created_atandupdated_attimestamps. (#280)
π Bug Fixes
- Seed update with confidential fields β Updated the legacy policy check in
apply-policies.tsthat erroneously blocked updates for seeds containing confidential fields. (#281) - Fix crash GET
/list/:seedon malformed JSON filters β Added array validation and safe object lookup for the JSONfiltersparameter, preventing runtime exceptions when invalid filters are sent. (#194, #272) - QStash webhook payload validation β Introduced schema validation for incoming QStash webhooks before processing to prevent D1 DB crashes on malformed payloads. (#198, #271)
- Clearing fields via null value β Fixed the logic in content update endpoints so that explicitly sending
nullvalues correctly resets the field content instead of preserving the old value. (#205, #273) - Triggering automations and Activity Log on public write endpoints β Ensured the dispatch of activity log events and execution of automations for the public endpoints
public-addandpublic-edit. (#204, #269) - Growth trend calculation with zero baseline β Fixed the calculation of the growth/decline percentage in widgets when the previous period's value is zero. (#195, #268)
- SQL reserved keywords validation in branch aliases β Branch aliases are now validated against the SQL reserved keywords list to avoid generating invalid table or column identifiers. (#211, #267)
- Fallback to valid cache on
getRegistryVersionerror β Improved the resilience of the seed registry cache, allowing fallback to the last valid version in case of temporary failures. (#225, #265) - Concurrent requests deduplication in
getHydratedRegistryβ Prevented race conditions and duplicate D1 queries during simultaneous registry hydrations by deduplicating in-flight Promises. (#216, #263) - Fix malformed
message.bodydestructuring inDispatchQueueBatchβ Fixed queue message consumption to safely handle and destructure batch messages without throwing a TypeError. (#214, #262) - Associating circular dependency errors with affected slugs β Schema validation reports now associate circular dependency errors directly with the involved slugs. (#199, #266)
- Widget formula operator validation (
formula.op) β The dashboard widgets schema now validatesformula.op, ensuring that only supported mathematical operators are used. (#193, #270) - TipTap coercion for RichText fields and CDN image URLs without extensions β Media validation now accepts CDN image URLs without file extensions (e.g., Unsplash, Imgix) and automatically converts plain text strings in RichText fields into valid TipTap structures. (#281)
- Robust date parsing and React state fix β Improved
DatePickerInputto handle ISO strings and epoch second timestamps. Resolved the ref mutation warning in the Kanban hook (useKanbanDrag) by moving the update intouseEffect. (#281) - Support for space-separated CLI commands β The CLI alias resolver now accepts space-separated commands (e.g., converting
db resettodb:reset). (#281)
π§Ή Housekeeping & Security
- Dead code removal
matchesFilterGroupβ Removed the unusedmatchesFilterGroupfunction from the dashboard's filter and dynamic columns support files. (#229, #264) - Dependabot security alerts resolution β Updated dependencies and configured pnpm overrides to resolve vulnerabilities reported by Dependabot. (#277)
- Test execution time optimization with happy-dom and forks pool β Drastically reduced the execution time of the Vitest test suite using the
happy-domenvironment and theforksexecution pool. (#275) - Increased
maxBufferin dev-cli tunnel β Increased the buffer limit ingetTunnelUrlto prevent buffer overflow crashes with extensivedocker-composelogs. (#281)
π Upgrading
This release contains no breaking changes to existing schemas or API contracts. The upgrade is safe for all deployments.