Skip to content

v0.6.5

Choose a tag to compare

@fdemusso fdemusso released this 08 Aug 22:24
· 101 commits to master since this release

Release Date: August 9, 2026


πŸ”’ Features & Privacy

  • Core Crypto, Blind Indexing & Context-Aware API Filtering β€” Introduced PrivacyService in @beechcms/core with AES-256-GCM encryption for confidential fields and HMAC-SHA256 Blind Indexing for searchable classified fields. API endpoints automatically handle data decryption and masking based on caller permissions. The dashboard editing interface allows clear-text management of confidential fields, avoiding double encryption or double hashing during updates, and displays compact badges for classified fields. (#278)
  • Demo Data Ingestion & Privacy-Aware UI Widgets β€” Integrated the pipeline for demo data ingestion and updated dashboard widgets to support data privacy. Entry creation now automatically populates created_at and updated_at timestamps. (#280)

πŸ› Bug Fixes

  • Seed update with confidential fields β€” Updated the legacy policy check in apply-policies.ts that erroneously blocked updates for seeds containing confidential fields. (#281)
  • Fix crash GET /list/:seed on malformed JSON filters β€” Added array validation and safe object lookup for the JSON filters parameter, preventing runtime exceptions when invalid filters are sent. (#194, #272)
  • QStash webhook payload validation β€” Introduced schema validation for incoming QStash webhooks before processing to prevent D1 DB crashes on malformed payloads. (#198, #271)
  • Clearing fields via null value β€” Fixed the logic in content update endpoints so that explicitly sending null values correctly resets the field content instead of preserving the old value. (#205, #273)
  • Triggering automations and Activity Log on public write endpoints β€” Ensured the dispatch of activity log events and execution of automations for the public endpoints public-add and public-edit. (#204, #269)
  • Growth trend calculation with zero baseline β€” Fixed the calculation of the growth/decline percentage in widgets when the previous period's value is zero. (#195, #268)
  • SQL reserved keywords validation in branch aliases β€” Branch aliases are now validated against the SQL reserved keywords list to avoid generating invalid table or column identifiers. (#211, #267)
  • Fallback to valid cache on getRegistryVersion error β€” Improved the resilience of the seed registry cache, allowing fallback to the last valid version in case of temporary failures. (#225, #265)
  • Concurrent requests deduplication in getHydratedRegistry β€” Prevented race conditions and duplicate D1 queries during simultaneous registry hydrations by deduplicating in-flight Promises. (#216, #263)
  • Fix malformed message.body destructuring in DispatchQueueBatch β€” Fixed queue message consumption to safely handle and destructure batch messages without throwing a TypeError. (#214, #262)
  • Associating circular dependency errors with affected slugs β€” Schema validation reports now associate circular dependency errors directly with the involved slugs. (#199, #266)
  • Widget formula operator validation (formula.op) β€” The dashboard widgets schema now validates formula.op, ensuring that only supported mathematical operators are used. (#193, #270)
  • TipTap coercion for RichText fields and CDN image URLs without extensions β€” Media validation now accepts CDN image URLs without file extensions (e.g., Unsplash, Imgix) and automatically converts plain text strings in RichText fields into valid TipTap structures. (#281)
  • Robust date parsing and React state fix β€” Improved DatePickerInput to handle ISO strings and epoch second timestamps. Resolved the ref mutation warning in the Kanban hook (useKanbanDrag) by moving the update into useEffect. (#281)
  • Support for space-separated CLI commands β€” The CLI alias resolver now accepts space-separated commands (e.g., converting db reset to db:reset). (#281)

🧹 Housekeeping & Security

  • Dead code removal matchesFilterGroup β€” Removed the unused matchesFilterGroup function from the dashboard's filter and dynamic columns support files. (#229, #264)
  • Dependabot security alerts resolution β€” Updated dependencies and configured pnpm overrides to resolve vulnerabilities reported by Dependabot. (#277)
  • Test execution time optimization with happy-dom and forks pool β€” Drastically reduced the execution time of the Vitest test suite using the happy-dom environment and the forks execution pool. (#275)
  • Increased maxBuffer in dev-cli tunnel β€” Increased the buffer limit in getTunnelUrl to prevent buffer overflow crashes with extensive docker-compose logs. (#281)

πŸš€ Upgrading

This release contains no breaking changes to existing schemas or API contracts. The upgrade is safe for all deployments.