Skip to content

2.12.0

Latest

Choose a tag to compare

@tomchop tomchop released this 02 Oct 18:22
afd4cdb

Pairs with yeti-feeds-frontend 2.12.0. prod/docker-compose.yaml drives both from one YETI_IMAGE_TAG, so deploy them together.

Upgrade notes

ACL changes now publish events (#1389). Creating an object emits three events where it previously emitted one: the object, its owner ACL, and one per group in rbac.default_acls. Event tasks whose acts_on is empty — the default, which matches everything — see the new traffic. Tasks with an explicit pattern do not yet: on Python 3.11+ event strings render as EventType.new:observable:url rather than new:observable:url, so a pattern starting with the event type never matches, and that includes all three shipped event tasks (#1399). Once #1399 is in, the shipped DatadogMetrics plugin ((new|update|delete)) will start reporting a yeti.object series with type:acl. Sharing and unsharing now publish too; unsharing previously logged a union_tag_not_found traceback and emitted nothing. The event payload is the whole relationship — source identity, target object, role — so access-control metadata reaches registered event tasks for the first time.

yara-python now requires >= 4.5.2 (#1383). 4.5.1 published no cp313 wheel, so on Python 3.13 it built from source without OpenSSL and rules using pe.imphash() failed to compile, taking the Neo23x0SignatureBase feed down with them. The image build now fails rather than shipping a yara without crypto support.

New: Google access token exchange (#1403). POST /api/v2/auth/google-access-token trades a Google OAuth access token for an API token, for clients that can mint access tokens without a browser but cannot get ID tokens. Off by default — the route is not registered, or listed in the OpenAPI schema, unless the server uses OIDC and auth.google_access_token_client_ids is set. Tokens are accepted only if issued to one of those clients, carrying identity scopes alone, for the verified address of an existing enabled user. See yeti.conf.sample for which OAuth clients are safe to list; prefer /oidc-callback-token wherever the client can obtain an ID token, since ID tokens are audience-bound.

Agents

  • Conversational agent instructions are stored as editable persona objects (#1365)
  • The chat proxy forwards the selected persona (#1368)
  • The agent service's tool list is proxied for the persona editor (#1370)
  • Persona writes publish events; they previously failed silently (#1386)

Security

  • Audit logs redact tokens and URL-encoded secrets (#1402)
  • Dependency bump clearing 20 advisories across anyio, authlib, h11, cryptography and pyopenssl — 3 critical, 9 high, 6 medium, 2 low (#1384)
  • yara-python built with OpenSSL support (#1383)

Fixes

  • Boolean filter values match exactly instead of by substring (#1367)
  • cisa_kev ignores non-CVSS keys in NVD metrics (#1374)
  • Feed, analytics and export task claims are atomic (#1377)
  • TweetLive moved out of deprecated (#1366)
  • YetiPackage.root_type is declared as the type it returns (#1398)