Skip to content

Security patch release

Choose a tag to compare

@amc1999 amc1999 released this 19 Jun 05:58
· 9 commits to master since this release

2026-06-18: v1.17.13

This is a security patch release and it is highly recommended for all openM++ users.

Following included in this release:

  • c++ core: security fix: remove polyfill.io from model documentation
  • c++ core: improve error handling if number of sub-values exceeding number of random streams
  • c++ core: fix an possible MPI model deadlock if number of CPU cores exceeds number of sub-values
  • c++ and Go: enforce SQLite database referential integrity
  • Go: fix sql error if microdata entities group deleted from database
  • Go: support native Go database drivers for MySQL, PostgreSQL, MS SQL
  • Go and UI: read-only model publishing, users can view models but not run or update
  • UI: in table info dialog show expression dimension label only if notes are not empty

Security risk due to use of polyfill.io in model documentation

Model documentation was using obsolete version of 3rd party polyfill.io library which may have security vulnerability. Please rebuild the model and use updated model documentation HTML. Do NOT enter anything if model documentation display login prompt as on screenshot below:
image

Read-only models publishing

This is a first release which allow to publish models in read-only mode. If back-end oms web-service started as:

oms -oms.Readonly

then user can only view model data, download parameter or output table. But would not be able to run the model, edit parameters, delete or upload anything.

Download source code and binaries:

Download release documentation archive:

Download cluster version (MPI):

IMPORTANT:
Full version of OpenM++ source code always included into "Download" links above.
Please do NOT use "Source code (zip)" or "Source code (tar.gz)" archives from "Assets" links below.
It is auto-generated by GitHub release tools and contains only half of OpenM++ source code.