diff --git a/docs/.vuepress/pr-feed-config.json b/docs/.vuepress/pr-feed-config.json index 9de61230c..0d6e8e11a 100644 --- a/docs/.vuepress/pr-feed-config.json +++ b/docs/.vuepress/pr-feed-config.json @@ -3,7 +3,7 @@ "version": "6.1.0", "lastSelfHostedDate": "2026-08-03", "lastSaasRelease": "2026-07-27", - "lastSaasCut": "rba/6.1-RBA-20260722-c2f5c32-6b43fa2", + "lastSaasCut": "rba/6.2-RBA-20260827-f8023f4-c988b05", "description": "Last self-hosted release version and date" } } diff --git a/docs/.vuepress/public/feeds/development-atom.xml b/docs/.vuepress/public/feeds/development-atom.xml index dbcdea3b2..e35326bdd 100644 --- a/docs/.vuepress/public/feeds/development-atom.xml +++ b/docs/.vuepress/public/feeds/development-atom.xml @@ -3,273 +3,168 @@ Rundeck Development Updates - 2026-07-27T21:13:28.438Z + 2026-08-27T20:36:52.188Z https://docs.rundeck.com/feeds/development Recent merged pull requests and development updates from Rundeck - Runner operation metrics: Busy status, live utilization bars, and expandable stat cards + Fix git-export SSH fetch failing with ConnectionException: Stream closed - rundeck-pr-rundeckpro-4803 - 2026-07-22T01:02:57.000Z - Runner operation metrics: Busy status, live utilization bars, and expandable stat cards (Merged: Jul 22, 2026) + rundeck-pr-rundeck-10506 + 2026-08-27T18:17:07.000Z + Fix git-export SSH fetch failing with ConnectionException: Stream closed (Merged: Aug 27, 2026) - Fix compact report processor silently disabled by bootstrap cleanup failures + Add native Prometheus execution metrics (Micrometer) - rundeck-pr-rundeckpro-4880 - 2026-07-21T20:02:39.000Z - Fix compact report processor silently disabled by bootstrap cleanup failures (Merged: Jul 21, 2026) + rundeck-pr-rundeck-10486 + 2026-08-25T16:32:03.000Z + Add native Prometheus execution metrics (Micrometer) (Merged: Aug 25, 2026) - Fix: API REST metrics trigger SQL errors + Generate API and webhook tokens using a CSPRNG - rundeck-pr-rundeck-10186 - 2026-07-21T19:47:25.000Z - Fix: API REST metrics trigger SQL errors (Merged: Jul 21, 2026) + rundeck-pr-rundeck-10436 + 2026-08-20T16:12:49.000Z + Generate API and webhook tokens using a CSPRNG (Merged: Aug 20, 2026) - Bump linkify-it to 5.0.1+ to fix ReDoS CVEs + Fix plaintext password storage in JettyCompatibleSpringSecurityPasswordEncoder - rundeck-pr-rundeckpro-4823 - 2026-07-15T21:21:05.000Z - Bump linkify-it to 5.0.1+ to fix ReDoS CVEs (Merged: Jul 15, 2026) + rundeck-pr-rundeck-10475 + 2026-08-20T15:48:01.000Z + Fix plaintext password storage in JettyCompatibleSpringSecurityPasswordEncoder (Merged: Aug 20, 2026) - Parse blankIfUnexpandable from script plugin YAML config + Fix CVE-2026-64607 in httpclient5 buildscript classpath - rundeck-pr-rundeck-10319 - 2026-07-14T22:21:21.000Z - Parse blankIfUnexpandable from script plugin YAML config (Merged: Jul 14, 2026) + rundeck-pr-rundeck-10474 + 2026-08-19T17:34:54.000Z + Fix CVE-2026-64607 in httpclient5 buildscript classpath (Merged: Aug 19, 2026) - Bump attribute-match-node-enhancer to 1.0.3 + Normal users are not able to see job history any more - rundeck-pr-rundeck-10331 - 2026-07-10T23:09:08.000Z - Bump attribute-match-node-enhancer to 1.0.3 (Merged: Jul 10, 2026) + rundeck-pr-rundeck-10476 + 2026-08-19T16:45:41.000Z + Normal users are not able to see job history any more (Merged: Aug 19, 2026) - add date formater for api/** endpoints + Add certRoleName config metadata for Vault storage cert auth - rundeck-pr-rundeck-10318 - 2026-07-10T21:07:13.000Z - add date formater for api/** endpoints (Merged: Jul 10, 2026) + rundeck-pr-rundeckpro-4952 + 2026-08-17T21:30:28.000Z + Add certRoleName config metadata for Vault storage cert auth (Merged: Aug 17, 2026) - Persist useName in job reference step to prevent UUID reversion + Add Japanese (ja) translations for Rundeck Pro UI - rundeck-pr-rundeck-10314 - 2026-07-10T20:56:17.000Z - Persist useName in job reference step to prevent UUID reversion (Merged: Jul 10, 2026) + rundeck-pr-rundeckpro-4939 + 2026-08-14T18:14:44.000Z + Add Japanese (ja) translations for Rundeck Pro UI (Merged: Aug 14, 2026) - Fix label not being saved + Recognize JDBC/native Jetty JAAS role principals - rundeck-pr-rundeck-10235 - 2026-07-10T16:50:34.000Z - Fix label not being saved (Merged: Jul 10, 2026) + rundeck-pr-rundeck-10454 + 2026-08-13T22:24:38.000Z + Recognize JDBC/native Jetty JAAS role principals (Merged: Aug 13, 2026) - add a new index to the execution table + Fix execution summary Start Time column Showing Step Identifiers - rundeck-pr-rundeck-9964 - 2026-07-10T16:27:17.000Z - add a new index to the execution table (Merged: Jul 10, 2026) + rundeck-pr-rundeck-10440 + 2026-08-13T18:30:50.000Z + Fix execution summary Start Time column Showing Step Identifiers (Merged: Aug 13, 2026) - - Fix Node UI paging to respect rundeck.gui.matchedNodesMaxCount, and a… + windows-cmd-quoting - rundeck-pr-rundeck-10234 - 2026-07-10T16:04:20.000Z - - Fix Node UI paging to respect rundeck.gui.matchedNodesMaxCount, and a… (Merged: Jul 10, 2026) + rundeck-pr-rundeckpro-4931 + 2026-08-12T17:05:37.000Z + windows-cmd-quoting (Merged: Aug 12, 2026) - Fix System Report runner health counts always reporting 0 + Migrate bundled AWS Plugins from AWS SDK v1 to v2 - rundeck-pr-rundeckpro-4809 - 2026-07-09T21:48:36.000Z - Fix System Report runner health counts always reporting 0 (Merged: Jul 9, 2026) + rundeck-pr-rundeckpro-4927 + 2026-08-10T21:28:10.000Z + Migrate bundled AWS Plugins from AWS SDK v1 to v2 (Merged: Aug 10, 2026) - Fix ACL policy API returning JSON instead of YAML + Update nanoid for CVE-2026-67213 - rundeck-pr-rundeck-10295 - 2026-07-07T17:55:08.000Z - Fix ACL policy API returning JSON instead of YAML (Merged: Jul 7, 2026) + rundeck-pr-rundeck-10438 + 2026-08-10T20:24:31.000Z + Update nanoid for CVE-2026-67213 (Merged: Aug 10, 2026) - Fix i18n fallback for dynamically registered plugin messages + Fix CVE-2026-71497 by forcing jsoup 1.23.1 - rundeck-pr-rundeck-10246 - 2026-07-06T18:24:42.000Z - Fix i18n fallback for dynamically registered plugin messages (Merged: Jul 6, 2026) + rundeck-pr-rundeck-10439 + 2026-08-10T19:55:58.000Z + Fix CVE-2026-71497 by forcing jsoup 1.23.1 (Merged: Aug 10, 2026) - Fix compacted execution output API returning mixed-type entries array + Azure Key Vault: preserve all *:encrypted flags - rundeck-pr-rundeck-10219 - 2026-06-30T18:07:17.000Z - Fix compacted execution output API returning mixed-type entries array (Merged: Jun 30, 2026) + rundeck-pr-rundeckpro-4921 + 2026-08-10T13:19:17.000Z + Azure Key Vault: preserve all *:encrypted flags (Merged: Aug 10, 2026) - Add option to choose what value is used for GCP Resource Model hostname + Publish rundeckpro Docker images as multi-platform (linux/amd64 + linux/arm64) - rundeck-pr-rundeckpro-4790 - 2026-06-28T02:50:28.000Z - Add option to choose what value is used for GCP Resource Model hostname (Merged: Jun 28, 2026) + rundeck-pr-rundeckpro-4923 + 2026-08-04T19:21:56.000Z + Publish rundeckpro Docker images as multi-platform (linux/amd64 + linux/arm64) (Merged: Aug 4, 2026) - Fix Jira plugin createmeta fallback for Jira Cloud team-managed projects + Enforce project-level authorization on execution metrics API - rundeck-pr-rundeckpro-4782 - 2026-06-26T19:57:01.000Z - Fix Jira plugin createmeta fallback for Jira Cloud team-managed projects (Merged: Jun 26, 2026) + rundeck-pr-rundeck-10419 + 2026-08-03T18:03:37.000Z + Enforce project-level authorization on execution metrics API (Merged: Aug 3, 2026) - Bump py-winrm-plugin to 3.2.0 + Fix Remote URL option Auth Type lost after saving and reopening job - rundeck-pr-rundeck-10205 - 2026-06-26T18:10:06.000Z - Bump py-winrm-plugin to 3.2.0 (Merged: Jun 26, 2026) + rundeck-pr-rundeck-10413 + 2026-07-30T20:23:39.000Z + Fix Remote URL option Auth Type lost after saving and reopening job (Merged: Jul 30, 2026) - Convert adhoc page to Vue SPA + SCM: Restore plugin resilience when Git server is temporarily unreachable - rundeck-pr-rundeck-10138 - 2026-06-26T16:48:08.000Z - Convert adhoc page to Vue SPA (Merged: Jun 26, 2026) + rundeck-pr-rundeck-10214 + 2026-07-28T19:37:47.000Z + SCM: Restore plugin resilience when Git server is temporarily unreachable (Merged: Jul 28, 2026) - Fix SSM Node Executor to use regional STS endpoints for opt-in regions + Allow Java 21 and 25 in preinst.sh version check - rundeck-pr-rundeckpro-4748 - 2026-06-26T14:21:20.000Z - Fix SSM Node Executor to use regional STS endpoints for opt-in regions (Merged: Jun 26, 2026) + rundeck-pr-rundeck-10410 + 2026-07-28T18:48:20.000Z + Allow Java 21 and 25 in preinst.sh version check (Merged: Jul 28, 2026) - Add Configurable Group Name Attribute And Prefix Filter To Azure Group + Fix blackout calendar ignoring non-GMT schedule TimeZone - rundeck-pr-rundeckpro-4760 - 2026-06-26T00:49:35.000Z - Add Configurable Group Name Attribute And Prefix Filter To Azure Group (Merged: Jun 26, 2026) + rundeck-pr-rundeckpro-4807 + 2026-07-27T20:21:08.000Z + Fix blackout calendar ignoring non-GMT schedule TimeZone (Merged: Jul 27, 2026) - Fix Hostname -> hostname in tool tip on node filter input + Migrate cloud-aws-plugins EC2/ECS/RDS/Lambda from AWS SDK v1 to v2 - rundeck-pr-rundeck-10162 - 2026-06-25T20:40:01.000Z - Fix Hostname -> hostname in tool tip on node filter input (Merged: Jun 25, 2026) + rundeck-pr-rundeckpro-4825 + 2026-07-24T19:17:48.000Z + Migrate cloud-aws-plugins EC2/ECS/RDS/Lambda from AWS SDK v1 to v2 (Merged: Jul 24, 2026) - Preserve accumulated data vars when secureOption storagePath uses node variable + Fix project home executions stat links missing last-day filter - rundeck-pr-rundeck-10220 - 2026-06-25T20:20:40.000Z - Preserve accumulated data vars when secureOption storagePath uses node variable (Merged: Jun 25, 2026) - - - Add default time filter to activity/executions listing - - rundeck-pr-rundeck-10190 - 2026-06-25T19:48:51.000Z - Add default time filter to activity/executions listing (Merged: Jun 25, 2026) - - - Fix AWS Secrets Manager assume-role session expiry causing ExpiredTokenException - - rundeck-pr-rundeckpro-4776 - 2026-06-25T15:54:28.000Z - Fix AWS Secrets Manager assume-role session expiry causing ExpiredTokenException (Merged: Jun 25, 2026) - - - Fix StorageTreeFactory stopping at first gap in provider index sequence - - rundeck-pr-rundeck-10225 - 2026-06-25T14:03:07.000Z - Fix StorageTreeFactory stopping at first gap in provider index sequence (Merged: Jun 25, 2026) - - - Audit failed login attempts when using rundeck.jaaslogin=true - - rundeck-pr-rundeck-10212 - 2026-06-24T15:37:19.000Z - Audit failed login attempts when using rundeck.jaaslogin=true (Merged: Jun 24, 2026) - - - Fix inline script step with Args not working with AWS SSM - - rundeck-pr-rundeckpro-4752 - 2026-06-18T18:30:23.000Z - Fix inline script step with Args not working with AWS SSM (Merged: Jun 18, 2026) - - - Fix cannot manage user class for usernames containing slashes - - rundeck-pr-rundeckpro-4705 - 2026-06-17T20:30:40.000Z - Fix cannot manage user class for usernames containing slashes (Merged: Jun 17, 2026) - - - Fix PagerDuty Notification Start Incident Workflow trigger - - rundeck-pr-rundeckpro-4757 - 2026-06-17T20:10:32.000Z - Fix PagerDuty Notification Start Incident Workflow trigger (Merged: Jun 17, 2026) - - - Fix legacy MySQL JDBC driver class at startup - - rundeck-pr-rundeckpro-4753 - 2026-06-17T18:46:17.000Z - Fix legacy MySQL JDBC driver class at startup (Merged: Jun 17, 2026) - - - Fix KeyStorageSelector state not resetting on reopen - - rundeck-pr-rundeck-10155 - 2026-06-16T20:28:47.000Z - Fix KeyStorageSelector state not resetting on reopen (Merged: Jun 16, 2026) - - - Fix job import resetting dispatch mode when node filter is empty - - rundeck-pr-rundeck-10171 - 2026-06-16T20:28:15.000Z - Fix job import resetting dispatch mode when node filter is empty (Merged: Jun 16, 2026) - - - Fix Remote URL auth headers not appended when fetching option values - - rundeck-pr-rundeck-10152 - 2026-06-16T20:26:43.000Z - Fix Remote URL auth headers not appended when fetching option values (Merged: Jun 16, 2026) - - - Remove usernames from System Report - - rundeck-pr-rundeckpro-4755 - 2026-06-16T17:39:52.000Z - Remove usernames from System Report (Merged: Jun 16, 2026) - - - Fixes bulk edit when using NextUI - - rundeck-pr-rundeck-10189 - 2026-06-15T21:10:46.000Z - Fixes bulk edit when using NextUI (Merged: Jun 15, 2026) - - - Fix node filter attributes incorrectly wrapped in double quotes - - rundeck-pr-rundeck-10157 - 2026-06-15T18:10:02.000Z - Fix node filter attributes incorrectly wrapped in double quotes (Merged: Jun 15, 2026) - - - Improve audit log userInfo.username showing null or anonymous for job runs - - rundeck-pr-rundeck-10168 - 2026-06-15T17:22:49.000Z - Improve audit log userInfo.username showing null or anonymous for job runs (Merged: Jun 15, 2026) + rundeck-pr-rundeck-10402 + 2026-07-24T17:03:27.000Z + Fix project home executions stat links missing last-day filter (Merged: Jul 24, 2026) \ No newline at end of file diff --git a/docs/.vuepress/public/feeds/development.xml b/docs/.vuepress/public/feeds/development.xml index bb1805879..f1e180afb 100644 --- a/docs/.vuepress/public/feeds/development.xml +++ b/docs/.vuepress/public/feeds/development.xml @@ -5,273 +5,168 @@ https://docs.rundeck.com/docs Recent merged pull requests and development updates from Rundeck en-us - Mon, 27 Jul 2026 21:13:28 GMT + Thu, 27 Aug 2026 20:36:52 GMT - Runner operation metrics: Busy status, live utilization bars, and expandable stat cards + Fix git-export SSH fetch failing with ConnectionException: Stream closed https://docs.rundeck.com/docs/history/updates/ - Runner operation metrics: Busy status, live utilization bars, and expandable stat cards (Merged: Jul 22, 2026) - Wed, 22 Jul 2026 01:02:57 GMT - rundeck-pr-rundeckpro-4803 + Fix git-export SSH fetch failing with ConnectionException: Stream closed (Merged: Aug 27, 2026) + Thu, 27 Aug 2026 18:17:07 GMT + rundeck-pr-rundeck-10506 - Fix compact report processor silently disabled by bootstrap cleanup failures + Add native Prometheus execution metrics (Micrometer) https://docs.rundeck.com/docs/history/updates/ - Fix compact report processor silently disabled by bootstrap cleanup failures (Merged: Jul 21, 2026) - Tue, 21 Jul 2026 20:02:39 GMT - rundeck-pr-rundeckpro-4880 + Add native Prometheus execution metrics (Micrometer) (Merged: Aug 25, 2026) + Tue, 25 Aug 2026 16:32:03 GMT + rundeck-pr-rundeck-10486 - Fix: API REST metrics trigger SQL errors + Generate API and webhook tokens using a CSPRNG https://docs.rundeck.com/docs/history/updates/ - Fix: API REST metrics trigger SQL errors (Merged: Jul 21, 2026) - Tue, 21 Jul 2026 19:47:25 GMT - rundeck-pr-rundeck-10186 + Generate API and webhook tokens using a CSPRNG (Merged: Aug 20, 2026) + Thu, 20 Aug 2026 16:12:49 GMT + rundeck-pr-rundeck-10436 - Bump linkify-it to 5.0.1+ to fix ReDoS CVEs + Fix plaintext password storage in JettyCompatibleSpringSecurityPasswordEncoder https://docs.rundeck.com/docs/history/updates/ - Bump linkify-it to 5.0.1+ to fix ReDoS CVEs (Merged: Jul 15, 2026) - Wed, 15 Jul 2026 21:21:05 GMT - rundeck-pr-rundeckpro-4823 + Fix plaintext password storage in JettyCompatibleSpringSecurityPasswordEncoder (Merged: Aug 20, 2026) + Thu, 20 Aug 2026 15:48:01 GMT + rundeck-pr-rundeck-10475 - Parse blankIfUnexpandable from script plugin YAML config + Fix CVE-2026-64607 in httpclient5 buildscript classpath https://docs.rundeck.com/docs/history/updates/ - Parse blankIfUnexpandable from script plugin YAML config (Merged: Jul 14, 2026) - Tue, 14 Jul 2026 22:21:21 GMT - rundeck-pr-rundeck-10319 + Fix CVE-2026-64607 in httpclient5 buildscript classpath (Merged: Aug 19, 2026) + Wed, 19 Aug 2026 17:34:54 GMT + rundeck-pr-rundeck-10474 - Bump attribute-match-node-enhancer to 1.0.3 + Normal users are not able to see job history any more https://docs.rundeck.com/docs/history/updates/ - Bump attribute-match-node-enhancer to 1.0.3 (Merged: Jul 10, 2026) - Fri, 10 Jul 2026 23:09:08 GMT - rundeck-pr-rundeck-10331 + Normal users are not able to see job history any more (Merged: Aug 19, 2026) + Wed, 19 Aug 2026 16:45:41 GMT + rundeck-pr-rundeck-10476 - add date formater for api/** endpoints + Add certRoleName config metadata for Vault storage cert auth https://docs.rundeck.com/docs/history/updates/ - add date formater for api/** endpoints (Merged: Jul 10, 2026) - Fri, 10 Jul 2026 21:07:13 GMT - rundeck-pr-rundeck-10318 + Add certRoleName config metadata for Vault storage cert auth (Merged: Aug 17, 2026) + Mon, 17 Aug 2026 21:30:28 GMT + rundeck-pr-rundeckpro-4952 - Persist useName in job reference step to prevent UUID reversion + Add Japanese (ja) translations for Rundeck Pro UI https://docs.rundeck.com/docs/history/updates/ - Persist useName in job reference step to prevent UUID reversion (Merged: Jul 10, 2026) - Fri, 10 Jul 2026 20:56:17 GMT - rundeck-pr-rundeck-10314 + Add Japanese (ja) translations for Rundeck Pro UI (Merged: Aug 14, 2026) + Fri, 14 Aug 2026 18:14:44 GMT + rundeck-pr-rundeckpro-4939 - Fix label not being saved + Recognize JDBC/native Jetty JAAS role principals https://docs.rundeck.com/docs/history/updates/ - Fix label not being saved (Merged: Jul 10, 2026) - Fri, 10 Jul 2026 16:50:34 GMT - rundeck-pr-rundeck-10235 + Recognize JDBC/native Jetty JAAS role principals (Merged: Aug 13, 2026) + Thu, 13 Aug 2026 22:24:38 GMT + rundeck-pr-rundeck-10454 - add a new index to the execution table + Fix execution summary Start Time column Showing Step Identifiers https://docs.rundeck.com/docs/history/updates/ - add a new index to the execution table (Merged: Jul 10, 2026) - Fri, 10 Jul 2026 16:27:17 GMT - rundeck-pr-rundeck-9964 + Fix execution summary Start Time column Showing Step Identifiers (Merged: Aug 13, 2026) + Thu, 13 Aug 2026 18:30:50 GMT + rundeck-pr-rundeck-10440 - - Fix Node UI paging to respect rundeck.gui.matchedNodesMaxCount, and a… + windows-cmd-quoting https://docs.rundeck.com/docs/history/updates/ - - Fix Node UI paging to respect rundeck.gui.matchedNodesMaxCount, and a… (Merged: Jul 10, 2026) - Fri, 10 Jul 2026 16:04:20 GMT - rundeck-pr-rundeck-10234 + windows-cmd-quoting (Merged: Aug 12, 2026) + Wed, 12 Aug 2026 17:05:37 GMT + rundeck-pr-rundeckpro-4931 - Fix System Report runner health counts always reporting 0 + Migrate bundled AWS Plugins from AWS SDK v1 to v2 https://docs.rundeck.com/docs/history/updates/ - Fix System Report runner health counts always reporting 0 (Merged: Jul 9, 2026) - Thu, 09 Jul 2026 21:48:36 GMT - rundeck-pr-rundeckpro-4809 + Migrate bundled AWS Plugins from AWS SDK v1 to v2 (Merged: Aug 10, 2026) + Mon, 10 Aug 2026 21:28:10 GMT + rundeck-pr-rundeckpro-4927 - Fix ACL policy API returning JSON instead of YAML + Update nanoid for CVE-2026-67213 https://docs.rundeck.com/docs/history/updates/ - Fix ACL policy API returning JSON instead of YAML (Merged: Jul 7, 2026) - Tue, 07 Jul 2026 17:55:08 GMT - rundeck-pr-rundeck-10295 + Update nanoid for CVE-2026-67213 (Merged: Aug 10, 2026) + Mon, 10 Aug 2026 20:24:31 GMT + rundeck-pr-rundeck-10438 - Fix i18n fallback for dynamically registered plugin messages + Fix CVE-2026-71497 by forcing jsoup 1.23.1 https://docs.rundeck.com/docs/history/updates/ - Fix i18n fallback for dynamically registered plugin messages (Merged: Jul 6, 2026) - Mon, 06 Jul 2026 18:24:42 GMT - rundeck-pr-rundeck-10246 + Fix CVE-2026-71497 by forcing jsoup 1.23.1 (Merged: Aug 10, 2026) + Mon, 10 Aug 2026 19:55:58 GMT + rundeck-pr-rundeck-10439 - Fix compacted execution output API returning mixed-type entries array + Azure Key Vault: preserve all *:encrypted flags https://docs.rundeck.com/docs/history/updates/ - Fix compacted execution output API returning mixed-type entries array (Merged: Jun 30, 2026) - Tue, 30 Jun 2026 18:07:17 GMT - rundeck-pr-rundeck-10219 + Azure Key Vault: preserve all *:encrypted flags (Merged: Aug 10, 2026) + Mon, 10 Aug 2026 13:19:17 GMT + rundeck-pr-rundeckpro-4921 - Add option to choose what value is used for GCP Resource Model hostname + Publish rundeckpro Docker images as multi-platform (linux/amd64 + linux/arm64) https://docs.rundeck.com/docs/history/updates/ - Add option to choose what value is used for GCP Resource Model hostname (Merged: Jun 28, 2026) - Sun, 28 Jun 2026 02:50:28 GMT - rundeck-pr-rundeckpro-4790 + Publish rundeckpro Docker images as multi-platform (linux/amd64 + linux/arm64) (Merged: Aug 4, 2026) + Tue, 04 Aug 2026 19:21:56 GMT + rundeck-pr-rundeckpro-4923 - Fix Jira plugin createmeta fallback for Jira Cloud team-managed projects + Enforce project-level authorization on execution metrics API https://docs.rundeck.com/docs/history/updates/ - Fix Jira plugin createmeta fallback for Jira Cloud team-managed projects (Merged: Jun 26, 2026) - Fri, 26 Jun 2026 19:57:01 GMT - rundeck-pr-rundeckpro-4782 + Enforce project-level authorization on execution metrics API (Merged: Aug 3, 2026) + Mon, 03 Aug 2026 18:03:37 GMT + rundeck-pr-rundeck-10419 - Bump py-winrm-plugin to 3.2.0 + Fix Remote URL option Auth Type lost after saving and reopening job https://docs.rundeck.com/docs/history/updates/ - Bump py-winrm-plugin to 3.2.0 (Merged: Jun 26, 2026) - Fri, 26 Jun 2026 18:10:06 GMT - rundeck-pr-rundeck-10205 + Fix Remote URL option Auth Type lost after saving and reopening job (Merged: Jul 30, 2026) + Thu, 30 Jul 2026 20:23:39 GMT + rundeck-pr-rundeck-10413 - Convert adhoc page to Vue SPA + SCM: Restore plugin resilience when Git server is temporarily unreachable https://docs.rundeck.com/docs/history/updates/ - Convert adhoc page to Vue SPA (Merged: Jun 26, 2026) - Fri, 26 Jun 2026 16:48:08 GMT - rundeck-pr-rundeck-10138 + SCM: Restore plugin resilience when Git server is temporarily unreachable (Merged: Jul 28, 2026) + Tue, 28 Jul 2026 19:37:47 GMT + rundeck-pr-rundeck-10214 - Fix SSM Node Executor to use regional STS endpoints for opt-in regions + Allow Java 21 and 25 in preinst.sh version check https://docs.rundeck.com/docs/history/updates/ - Fix SSM Node Executor to use regional STS endpoints for opt-in regions (Merged: Jun 26, 2026) - Fri, 26 Jun 2026 14:21:20 GMT - rundeck-pr-rundeckpro-4748 + Allow Java 21 and 25 in preinst.sh version check (Merged: Jul 28, 2026) + Tue, 28 Jul 2026 18:48:20 GMT + rundeck-pr-rundeck-10410 - Add Configurable Group Name Attribute And Prefix Filter To Azure Group + Fix blackout calendar ignoring non-GMT schedule TimeZone https://docs.rundeck.com/docs/history/updates/ - Add Configurable Group Name Attribute And Prefix Filter To Azure Group (Merged: Jun 26, 2026) - Fri, 26 Jun 2026 00:49:35 GMT - rundeck-pr-rundeckpro-4760 + Fix blackout calendar ignoring non-GMT schedule TimeZone (Merged: Jul 27, 2026) + Mon, 27 Jul 2026 20:21:08 GMT + rundeck-pr-rundeckpro-4807 - Fix Hostname -> hostname in tool tip on node filter input + Migrate cloud-aws-plugins EC2/ECS/RDS/Lambda from AWS SDK v1 to v2 https://docs.rundeck.com/docs/history/updates/ - Fix Hostname -> hostname in tool tip on node filter input (Merged: Jun 25, 2026) - Thu, 25 Jun 2026 20:40:01 GMT - rundeck-pr-rundeck-10162 + Migrate cloud-aws-plugins EC2/ECS/RDS/Lambda from AWS SDK v1 to v2 (Merged: Jul 24, 2026) + Fri, 24 Jul 2026 19:17:48 GMT + rundeck-pr-rundeckpro-4825 - Preserve accumulated data vars when secureOption storagePath uses node variable + Fix project home executions stat links missing last-day filter https://docs.rundeck.com/docs/history/updates/ - Preserve accumulated data vars when secureOption storagePath uses node variable (Merged: Jun 25, 2026) - Thu, 25 Jun 2026 20:20:40 GMT - rundeck-pr-rundeck-10220 - - - Add default time filter to activity/executions listing - https://docs.rundeck.com/docs/history/updates/ - Add default time filter to activity/executions listing (Merged: Jun 25, 2026) - Thu, 25 Jun 2026 19:48:51 GMT - rundeck-pr-rundeck-10190 - - - Fix AWS Secrets Manager assume-role session expiry causing ExpiredTokenException - https://docs.rundeck.com/docs/history/updates/ - Fix AWS Secrets Manager assume-role session expiry causing ExpiredTokenException (Merged: Jun 25, 2026) - Thu, 25 Jun 2026 15:54:28 GMT - rundeck-pr-rundeckpro-4776 - - - Fix StorageTreeFactory stopping at first gap in provider index sequence - https://docs.rundeck.com/docs/history/updates/ - Fix StorageTreeFactory stopping at first gap in provider index sequence (Merged: Jun 25, 2026) - Thu, 25 Jun 2026 14:03:07 GMT - rundeck-pr-rundeck-10225 - - - Audit failed login attempts when using rundeck.jaaslogin=true - https://docs.rundeck.com/docs/history/updates/ - Audit failed login attempts when using rundeck.jaaslogin=true (Merged: Jun 24, 2026) - Wed, 24 Jun 2026 15:37:19 GMT - rundeck-pr-rundeck-10212 - - - Fix inline script step with Args not working with AWS SSM - https://docs.rundeck.com/docs/history/updates/ - Fix inline script step with Args not working with AWS SSM (Merged: Jun 18, 2026) - Thu, 18 Jun 2026 18:30:23 GMT - rundeck-pr-rundeckpro-4752 - - - Fix cannot manage user class for usernames containing slashes - https://docs.rundeck.com/docs/history/updates/ - Fix cannot manage user class for usernames containing slashes (Merged: Jun 17, 2026) - Wed, 17 Jun 2026 20:30:40 GMT - rundeck-pr-rundeckpro-4705 - - - Fix PagerDuty Notification Start Incident Workflow trigger - https://docs.rundeck.com/docs/history/updates/ - Fix PagerDuty Notification Start Incident Workflow trigger (Merged: Jun 17, 2026) - Wed, 17 Jun 2026 20:10:32 GMT - rundeck-pr-rundeckpro-4757 - - - Fix legacy MySQL JDBC driver class at startup - https://docs.rundeck.com/docs/history/updates/ - Fix legacy MySQL JDBC driver class at startup (Merged: Jun 17, 2026) - Wed, 17 Jun 2026 18:46:17 GMT - rundeck-pr-rundeckpro-4753 - - - Fix KeyStorageSelector state not resetting on reopen - https://docs.rundeck.com/docs/history/updates/ - Fix KeyStorageSelector state not resetting on reopen (Merged: Jun 16, 2026) - Tue, 16 Jun 2026 20:28:47 GMT - rundeck-pr-rundeck-10155 - - - Fix job import resetting dispatch mode when node filter is empty - https://docs.rundeck.com/docs/history/updates/ - Fix job import resetting dispatch mode when node filter is empty (Merged: Jun 16, 2026) - Tue, 16 Jun 2026 20:28:15 GMT - rundeck-pr-rundeck-10171 - - - Fix Remote URL auth headers not appended when fetching option values - https://docs.rundeck.com/docs/history/updates/ - Fix Remote URL auth headers not appended when fetching option values (Merged: Jun 16, 2026) - Tue, 16 Jun 2026 20:26:43 GMT - rundeck-pr-rundeck-10152 - - - Remove usernames from System Report - https://docs.rundeck.com/docs/history/updates/ - Remove usernames from System Report (Merged: Jun 16, 2026) - Tue, 16 Jun 2026 17:39:52 GMT - rundeck-pr-rundeckpro-4755 - - - Fixes bulk edit when using NextUI - https://docs.rundeck.com/docs/history/updates/ - Fixes bulk edit when using NextUI (Merged: Jun 15, 2026) - Mon, 15 Jun 2026 21:10:46 GMT - rundeck-pr-rundeck-10189 - - - Fix node filter attributes incorrectly wrapped in double quotes - https://docs.rundeck.com/docs/history/updates/ - Fix node filter attributes incorrectly wrapped in double quotes (Merged: Jun 15, 2026) - Mon, 15 Jun 2026 18:10:02 GMT - rundeck-pr-rundeck-10157 - - - Improve audit log userInfo.username showing null or anonymous for job runs - https://docs.rundeck.com/docs/history/updates/ - Improve audit log userInfo.username showing null or anonymous for job runs (Merged: Jun 15, 2026) - Mon, 15 Jun 2026 17:22:49 GMT - rundeck-pr-rundeck-10168 + Fix project home executions stat links missing last-day filter (Merged: Jul 24, 2026) + Fri, 24 Jul 2026 17:03:27 GMT + rundeck-pr-rundeck-10402 \ No newline at end of file diff --git a/docs/history/updates/index.md b/docs/history/updates/index.md index b3cddb44d..8cf33221f 100644 --- a/docs/history/updates/index.md +++ b/docs/history/updates/index.md @@ -1,7 +1,7 @@ --- title: Recent Updates description: Latest merged changes from the Rundeck development team -date: 2026-07-27T21:13:28.424Z +date: 2026-08-27T20:36:52.174Z feed: true index: true --- @@ -10,222 +10,134 @@ index: true Stay up to date with the latest changes and improvements from the Runbook Automation development team. -This page shows recently merged pull requests from both the Runbook Automation product repository and the open source Rundeck repository merged since the last self-hosted release of [6.0.1](/history/6_x/version-6.0.1.md) on July 15, 2026. +This page shows recently merged pull requests from both the Runbook Automation product repository and the open source Rundeck repository merged since the last self-hosted release of [6.1.0](/history/6_x/version-6.1.0.md) on August 3, 2026. ## Recent Changes -#### ::circle-dot:: Runner operation metrics: Busy status, live utilization bars, and expandable stat cards +#### ::circle-dot:: Fix git-export SSH fetch failing with ConnectionException: Stream closed [PR #10506](https://github.com/rundeck/rundeck/pull/10506) - Runners now expose real-time operation metrics in the Runner Management UI. Each runner and replica row shows a live utilization progress bar (running / max operations) in the new **Operations** column. Clicking a row expands a panel with five stat cards — Utilization %, Running, Max, Queued, and Completed — giving operators an at-a-glance view of capacity without leaving the management page. + Fixed an intermittent issue where Git SCM export and import operations over SSH could fail with a "Stream closed" connection error during fetch or remote listing, preventing synchronization with Git repositories used for project jobs and configuration. - Runners also report a new `Busy` health status (yellow badge) when their operation queue backs up under heavy concurrent job load. Previously this showed as `Unhealthy` (red) — the same signal as a broken or offline runner — making it impossible to distinguish capacity saturation from an actual failure. Older runners that don't yet report metrics show a warning in the expand panel prompting an upgrade. +#### ::circle-dot:: Add native Prometheus execution metrics (Micrometer) [PR #10486](https://github.com/rundeck/rundeck/pull/10486) -#### ::circle-dot:: Fix compact report processor silently disabled by bootstrap cleanup failures + Rundeck now natively emits per-project/status execution counts and durations, a running-executions gauge, and system/execution-mode gauges on `/monitoring/prometheus`, without requiring an external exporter. - <!-- +#### ::circle-dot:: Generate API and webhook tokens using a CSPRNG [PR #10436](https://github.com/rundeck/rundeck/pull/10436) - To include as part of release notes, label as "release-notes/include" and fill in this section. Copilot can help. - --> + <!-- If you have suggested content that would describe this PR to other Rundeck community users, please enter it here.--> + Fixed: API and webhook auth tokens are now generated using a cryptographically secure random number generator (CSPRNG) instead of a non-cryptographic PRNG. -#### ::circle-dot:: Fix: API REST metrics trigger SQL errors [PR #10186](https://github.com/rundeck/rundeck/pull/10186) +#### ::circle-dot:: Fix plaintext password storage in JettyCompatibleSpringSecurityPasswordEncoder [PR #10475](https://github.com/rundeck/rundeck/pull/10475) - Fixed an issue where retrieving execution metrics through the REST API generated repeated SQL conversion errors in the logs when using the H2 database, ensuring clean logs and reliable metrics responses. + Fixed: user account passwords authenticated via the realm.properties (non-JAAS) path are now hashed with BCrypt when set/changed, instead of being stored in plaintext. -#### ::circle-dot:: Bump linkify-it to 5.0.1+ to fix ReDoS CVEs + 🤖 Generated with [Claude Code](https://claude.com/claude-code) +#### ::circle-dot:: Fix CVE-2026-64607 in httpclient5 buildscript classpath [PR #10474](https://github.com/rundeck/rundeck/pull/10474) - Addressed two security advisories (CVE-2026-48801 and CVE-2026-59887) in a third-party library used to render Markdown links in the Rundeck UI. The vulnerability could allow specially crafted text to consume excessive CPU and slow down the interface; this update upgrades the affected library to a fixed version. -#### ::circle-dot:: Parse blankIfUnexpandable from script plugin YAML config [PR #10319](https://github.com/rundeck/rundeck/pull/10319) + This release addresses CVE-2026-64607 in Apache HttpClient 5 build dependencies (Medium severity). The affected library is used during build only and is not shipped as part of the Rundeck application package. +#### ::circle-dot:: Normal users are not able to see job history any more [PR #10476](https://github.com/rundeck/rundeck/pull/10476) - Fixed an issue where shell variable references such as `${VAR}` and `${VAR:-default}` in scripts run by script-based step plugins could be stripped out before the shell had a chance to evaluate them, causing those variables to resolve to empty values. Script plugins can now preserve these expressions so they expand correctly at runtime. -#### ::circle-dot:: Bump attribute-match-node-enhancer to 1.0.3 [PR #10331](https://github.com/rundeck/rundeck/pull/10331) + Fixed a bug where users whose ACL granted only the job `view` action (without `read` or + `view_history`) could not see execution history from the executions API, even though the + correct total count was reported. +#### ::circle-dot:: Add certRoleName config metadata for Vault storage cert auth - The bundled Attribute Match Node Enhancer plugin now supports attribute value substitution, letting you build new node attributes and tags from a node's existing attributes using `${attribute}` syntax (for example, `image-${ec2.imageId}` or `endpoint=${host}:${port}`). This makes it possible to derive richer, dynamic metadata for nodes without external scripting. The update also adds a new "is present" match operator (`~~`), so enhancement rules can target nodes based simply on whether an attribute exists, regardless of its value, complementing the existing "not present" (`!!`) operator. -#### ::circle-dot:: add date formater for api/** endpoints [PR #10318](https://github.com/rundeck/rundeck/pull/10318) + Added an optional **Cert Role Name** setting for Vault Key Storage when using TLS certificate authentication. Some Vault deployments require an explicit certificate role name in the login request and return permission denied without it; you can now configure this in System Configuration under Key Storage (Advanced). When left unset, Vault certificate authentication behaves as before. +#### ::circle-dot:: Add Japanese (ja) translations for Rundeck Pro UI - Fixed a change in API date formatting introduced by the Grails 7 / Spring Boot 3 upgrade, where date/time fields in API responses began including milliseconds (e.g. `2026-03-25T21:16:50.123Z`). API date values are once again returned in second-precision UTC ISO-8601 format (e.g. `2026-03-25T21:16:50Z`) across both JSON and XML and for all API versions, restoring compatibility for existing API integrations. - Jira: [https://pagerduty.atlassian.net/browse/RUN-4550](url) - - This pull request standardizes the serialization of all `Date` values in Rundeck API responses to use second-precision W3C/ISO-8601 format in UTC (e.g., `2026-03-25T21:16:50Z`), removing milliseconds. This change restores backward compatibility for API consumers after an upgrade to Grails 7 / Spring Boot 3, which began including milliseconds by default. The update is enforced for all API versions and is covered by comprehensive tests across affected endpoints. - - **API Date Serialization Standardization:** - - * Introduced a custom marshaller in `ApiMarshallerRegistrar` to serialize all `Date` values in API JSON and XML responses with second-precision W3C/ISO-8601 format (no milliseconds), and registered it for every API version. [[1]](diffhunk://#diff-6afb34835773788e379a495581b6dd0cb550244b8808fb69458313141c32ccaaR24-R52) [[2]](diffhunk://#diff-6afb34835773788e379a495581b6dd0cb550244b8808fb69458313141c32ccaaR92-R96) - * Updated `RdExecutionController` to configure Jackson's `ObjectMapper` to use the same date format for consistency in controller responses. [[1]](diffhunk://#diff-2b3ad1e0a2a304a03bfb4120c23f81bb53bba12166209a5629a2157ada3dadbbR3-R9) [[2]](diffhunk://#diff-2b3ad1e0a2a304a03bfb4120c23f81bb53bba12166209a5629a2157ada3dadbbR24-R28) - - **Test Coverage and Verification:** - - * Added `ApiDateMarshallerSpec` to verify that all relevant DTOs and endpoints serialize dates without milliseconds, for both JSON and XML, across all API versions. - * Updated and extended tests in `ApiControllerSpec`, `MenuControllerSpec`, and `RdExecutionControllerSpec` to assert that API responses do not include milliseconds in date fields. [[1]](diffhunk://#diff-62006b966c57c204ead5071093e47ac70df5e0ff3888cab22a7737666a1ccfd9R136-R210) [[2]](diffhunk://#diff-62006b966c57c204ead5071093e47ac70df5e0ff3888cab22a7737666a1ccfd9L361-R437) [[3]](diffhunk://#diff-62006b966c57c204ead5071093e47ac70df5e0ff3888cab22a7737666a1ccfd9L418-R494) [[4]](diffhunk://#diff-6e07be9b49269a1459df118da029d8635ccddda6dd5d6d8cb12c714ed0e5b9cdR19-R21) [[5]](diffhunk://#diff-6e07be9b49269a1459df118da029d8635ccddda6dd5d6d8cb12c714ed0e5b9cdR2428-R2438) [[6]](diffhunk://#diff-6e07be9b49269a1459df118da029d8635ccddda6dd5d6d8cb12c714ed0e5b9cdL2439-R2448) [[7]](diffhunk://#diff-6e07be9b49269a1459df118da029d8635ccddda6dd5d6d8cb12c714ed0e5b9cdR2460-R2461) [[8]](diffhunk://#diff-e5d266ba462bf481bc5e162a7a36e8da4b428538f671aed204a8d38c4d36a60aR32-R47) - - This ensures consistent, backward-compatible date formatting for all API consumers, preventing regressions and aligning with previous API behavior. + Added Japanese (ja) translations for Rundeck Pro's Enterprise UI, including calendars, cluster management, runners, licensing, security, job favorites, and other Pro-specific features. Add `?lang=ja` to a project URL to switch to Japanese for the session. Some areas are not yet translated, including parts of the Runner UI and OSS screens such as Dashboard and Project Settings. -#### ::circle-dot:: Persist useName in job reference step to prevent UUID reversion [PR #10314](https://github.com/rundeck/rundeck/pull/10314) +#### ::circle-dot:: Recognize JDBC/native Jetty JAAS role principals [PR #10454](https://github.com/rundeck/rundeck/pull/10454) - Fixed an issue in the workflow editor where a Job Reference step set to reference a job by name would revert to referencing by UUID the next time the step was edited. The name-vs-UUID selection is now saved with the step and preserved across edits. + Fixed a bug where users authenticating via JAAS with a native Jetty login module (e.g. + `JDBCLoginModule`) could log in successfully but were assigned no roles, blocking all project + access. Roles are now correctly granted for these login modules, matching the behavior already + restored for LDAP in 6.0.1. -#### ::circle-dot:: Fix label not being saved [PR #10235](https://github.com/rundeck/rundeck/pull/10235) +#### ::circle-dot:: Fix execution summary Start Time column Showing Step Identifiers [PR #10440](https://github.com/rundeck/rundeck/pull/10440) - Fixed an issue where the label (description) on a Job Reference step was not saved—both when adding a new job reference step and when editing an existing one—causing the label to disappear or revert after saving. Job Reference step labels are now preserved correctly. + Fixed an issue on the Execution Summary page where the Start Time column for collapsed node rows showed step identifiers (such as "Step: 2/1") instead of an actual timestamp when viewing conditional or branching workflows. The Start Time column now displays the node's earliest step start time. -#### ::circle-dot:: add a new index to the execution table [PR #9964](https://github.com/rundeck/rundeck/pull/9964) +#### ::circle-dot:: windows-cmd-quoting - Add indexes on `execution`, `referenced_execution`, and `job_file_record` to improve the performance of execution history queries and the Execution API. + Fixed an issue where Windows job commands failed when expanded job options or global variables contained spaces or special characters and the remote shell was cmd.exe (including WinRM with the cmd shell and SSH to Windows nodes). After a Rundeck 6.0 security change, those values were quoted with single quotes, which cmd.exe does not treat as string delimiters—breaking commands such as `powershell -File` when the script path contained spaces (for example, paths ending in `.ps1'`). Windows argument quoting now uses proper double-quote escaping so values are passed as a single argument while preserving injection protections against shell metacharacters such as `|`, `>`, and `&&`. -#### ::circle-dot:: - Fix Node UI paging to respect rundeck.gui.matchedNodesMaxCount, and a… [PR #10234](https://github.com/rundeck/rundeck/pull/10234) +#### ::circle-dot:: Migrate bundled AWS Plugins from AWS SDK v1 to v2 - Fixed incorrect paging on the Nodes page that occurred when the number of nodes shown per page was increased via the `rundeck.gui.matchedNodesMaxCount` setting. Page counts and the pager controls at the bottom of the page now calculate correctly based on the configured page size. + Completed the migration of Rundeck Pro AWS cloud plugins to AWS SDK v2 for the remaining services—including SSM run commands, S3, Athena, load balancers, EKS, Autoscaling, and CloudWatch Logs—following the earlier EC2, ECS, RDS, and Lambda migration. AWS integrations in cloud-aws-plugins now use the current SDK throughout, improving compatibility with modern AWS APIs and credential handling including SSM assume-role. -#### ::circle-dot:: Fix System Report runner health counts always reporting 0 +#### ::circle-dot:: Update nanoid for CVE-2026-67213 [PR #10438](https://github.com/rundeck/rundeck/pull/10438) - Fixed an issue where the System Report showed all runner health counts as zero (healthy, unhealthy, new, unknown, and down) even when runners were active and healthy. The report now accurately reflects each runner's current health status, so operators relying on the System Report get a correct view of their runner fleet. + This release addresses CVE-2026-67213 by updating the nanoid JavaScript dependency used in the Rundeck web UI to version 3.3.17, fixing a denial-of-service vulnerability that could cause excessive CPU use during ID generation. -#### ::circle-dot:: Fix ACL policy API returning JSON instead of YAML [PR #10295](https://github.com/rundeck/rundeck/pull/10295) +#### ::circle-dot:: Fix CVE-2026-71497 by forcing jsoup 1.23.1 [PR #10439](https://github.com/rundeck/rundeck/pull/10439) - Fixed an issue where the ACL policy API returned JSON with the policy wrapped in a `contents` field even when YAML was requested via the `Accept: application/yaml` header. The endpoint now correctly returns the raw YAML policy document again, restoring compatibility for ACL import, diff, and backup tooling that relies on YAML responses. + Upgraded jsoup to 1.23.1 to address CVE-2026-71497 in OpenAPI tooling dependencies. -#### ::circle-dot:: Fix i18n fallback for dynamically registered plugin messages [PR #10246](https://github.com/rundeck/rundeck/pull/10246) +#### ::circle-dot:: Azure Key Vault: preserve all *:encrypted flags - Fixed an issue where plugin-provided i18n messages would show raw translation keys instead of English text for users whose locale was not `en_US` and a specific key was missing in their locale's message catalogue. + Fixed an issue where secrets stored in Azure Key Vault could become undecryptable on Rundeck 6.0, causing jobs to fail with invalid environment variable values when reading Key Storage entries. When a secret carried more than one encryption metadata flag, only the first flag was preserved in Azure tags, which could drop the active encryption converter's marker and leave Rundeck returning raw ciphertext instead of the decrypted value. All encryption flags are now preserved when secrets are written to and read from Azure Key Vault. Secrets already saved with a missing flag must be re-saved through Rundeck or have the missing tag restored manually in Azure Key Vault. -#### ::circle-dot:: Fix compacted execution output API returning mixed-type entries array [PR #10219](https://github.com/rundeck/rundeck/pull/10219) +#### ::circle-dot:: Publish rundeckpro Docker images as multi-platform (linux/amd64 + linux/arm64) - Fixed the compacted execution output API (`GET /api/*/execution/{id}/output?compacted=true&format=json`), which previously returned a mix of full objects and bare strings in its `entries` array—causing errors in clients that expected every entry to be an object with a `log` field. As of API v59, all compacted log entries are returned as consistent objects (omitting only unchanged fields), while API v58 and earlier keep their existing behavior for backward compatibility. + <!-- CI/build-only change, no user-facing runtime behavior change until images are actually published multi-arch. Not marked for release notes. --> -#### ::circle-dot:: Add option to choose what value is used for GCP Resource Model hostname +#### ::circle-dot:: Enforce project-level authorization on execution metrics API [PR #10419](https://github.com/rundeck/rundeck/pull/10419) - The GCP resource model source now lets you choose which value is used as a discovered node's hostname—instance name, internal IP, or external IP—and set a default username for those nodes. Discovered GCP nodes also now expose both their internal IP and external IP as node attributes, making it easier to connect to instances across peered VPCs or different GCP projects. + The execution metrics API (`/executions/metrics`) now enforces project-level authorization: metrics are only returned for projects the requesting user is authorized to read. -#### ::circle-dot:: Fix Jira plugin createmeta fallback for Jira Cloud team-managed projects +#### ::circle-dot:: Fix Remote URL option Auth Type lost after saving and reopening job [PR #10413](https://github.com/rundeck/rundeck/pull/10413) - Fixed Jira issue creation failing on Jira Cloud team-managed projects with a "Failed to find issue type" error even when the issue type existed. Both the Jira "Create Issue" workflow/job step and the Jira issue-creation notification now fall back to a supported issue-type lookup so issues are created successfully in these projects, while behavior for Jira Server / Data Center is unchanged. + Fixed: Remote URL job option's Auth Type (Bearer Token / Basic / API Key) is now correctly restored when reopening a saved job for editing. -#### ::circle-dot:: Bump py-winrm-plugin to 3.2.0 [PR #10205](https://github.com/rundeck/rundeck/pull/10205) +#### ::circle-dot:: SCM: Restore plugin resilience when Git server is temporarily unreachable [PR #10214](https://github.com/rundeck/rundeck/pull/10214) - Resolved intermittent failures of Windows (WinRM) jobs using Kerberos authentication when many executions run concurrently. Previously, running large numbers of Kerberos WinRM jobs at the same time could fail with `GSSError: Credential cache is empty` because all executions shared a single Kerberos credential cache. Each execution now uses its own isolated credential cache, so high-concurrency WinRM workloads run reliably. + Fixed SCM plugin (git-export/git-import) incorrectly disabling itself when the Git server is temporarily unreachable. The plugin now recovers automatically when connectivity is restored, without requiring manual re-activation, and without repeatedly hammering the Git server during an outage — after fast retries are exhausted it polls once per `scmLoader.slowPoll.interval` (default 60s) instead of giving up. Users will see a clear "Git server unavailable" warning in the UI during outages instead of a stale or missing status. Also adds a configurable fetch/pull timeout for the git plugin (default 30s) to prevent a hung remote from blocking indefinitely. -#### ::circle-dot:: Convert adhoc page to Vue SPA [PR #10138](https://github.com/rundeck/rundeck/pull/10138) +#### ::circle-dot:: Allow Java 21 and 25 in preinst.sh version check [PR #10410](https://github.com/rundeck/rundeck/pull/10410) - The Commands (adhoc) page has been rebuilt as a modern Vue single-page application, available when the new NextUI option is enabled. This delivers faster, more responsive command execution and a consistent look and feel with the rest of the redesigned Rundeck interface. + Fixed RPM installation failing on hosts running Java 21 or 25 because the installer incorrectly rejected those JVM versions. The RPM pre-install check now accepts Java 17, 21, and 25, matching Rundeck's documented system requirements and allowing installation on newer Linux distributions such as RHEL/Rocky Linux 10 that no longer ship Java 17. -#### ::circle-dot:: Fix SSM Node Executor to use regional STS endpoints for opt-in regions +#### ::circle-dot:: Fix blackout calendar ignoring non-GMT schedule TimeZone - Fixed an issue where AWS SSM node command and script execution failed in opt-in regions (such as `eu-central-2`) when using cross-account role assumption, previously returning an `InvalidClientTokenId` error. A new optional `ssm-sts-region` setting also lets operators choose which region's STS endpoint is used for authentication, while existing configurations continue to work unchanged. + Fixed an issue where blackout (and allowed) calendars defined with a specific date or date range ignored the schedule's configured time zone and used the server's default time zone instead. On non-GMT schedules this caused the blackout to apply to the wrong calendar day, so jobs could run during a window that was supposed to block them. Blackout and allowed date/range calendars now correctly honor the schedule's time zone. Recurring daily, weekly, and monthly calendars were not affected. -#### ::circle-dot:: Add Configurable Group Name Attribute And Prefix Filter To Azure Group +#### ::circle-dot:: Migrate cloud-aws-plugins EC2/ECS/RDS/Lambda from AWS SDK v1 to v2 - The Azure (Entra ID) user group source can now be configured to use a specific directory attribute as the Rundeck group name (for example, `onPremisesSamAccountName` instead of the default `displayName`), and to optionally include only groups matching a name prefix. This lets administrators align group names between sign-in tokens and directory lookups—eliminating the need to maintain duplicate group names in ACLs—while existing configurations continue to behave exactly as before. + Updated the EC2, ECS, RDS, and Lambda AWS plugins to use AWS SDK v2, with no changes to plugin configuration. Assume-role authentication now automatically refreshes credentials, preventing expired-token failures on long-running jobs after about one hour. Also fixed the ECS "Stopped Task Details" step ignoring a configured access key, and updated the Lambda runtime list. -#### ::circle-dot:: Fix Hostname -> hostname in tool tip on node filter input [PR #10162](https://github.com/rundeck/rundeck/pull/10162) +#### ::circle-dot:: Fix project home executions stat links missing last-day filter [PR #10402](https://github.com/rundeck/rundeck/pull/10402) - Minor fix of capitalization on the word "hostname". - -#### ::circle-dot:: Preserve accumulated data vars when secureOption storagePath uses node variable [PR #10220](https://github.com/rundeck/rundeck/pull/10220) - - - Fixed an edge case where `data.*` variables set by log filter plugins (e.g. `key-value-data`) were lost in subsequent workflow steps when a secure option's storage path contained a node context variable such as `${node.name}`. - -#### ::circle-dot:: Add default time filter to activity/executions listing [PR #10190](https://github.com/rundeck/rundeck/pull/10190) - - - Adds a feature flag `rundeck.feature.activityDefaultTimeFilter.enabled` that, when enabled, scopes the activity/executions page to a configurable recent time window on first load. The window defaults to the last month and is configurable via `gui.activity.defaultTimeFilter` (accepted values: `1h`, `1d`, `1w`, `1m`). - -#### ::circle-dot:: Fix AWS Secrets Manager assume-role session expiry causing ExpiredTokenException - - - Fixed an issue where the AWS Secrets Manager key storage plugin, when configured with an assume-role ARN, stopped retrieving secrets after about one hour on long-running Rundeck instances and failed with `ExpiredTokenException`. The plugin now automatically refreshes the assumed-role session, so secrets remain accessible without needing to restart Rundeck. - -#### ::circle-dot:: Fix StorageTreeFactory stopping at first gap in provider index sequence [PR #10225](https://github.com/rundeck/rundeck/pull/10225) - - - Fixed an issue where key storage providers and converters configured with non-contiguous index numbers were silently skipped, making any keys stored under the skipped providers inaccessible. Rundeck now loads every configured storage provider regardless of gaps in the index sequence, so administrators no longer need to keep provider indexes perfectly consecutive when configuring key storage outside the UI (for example, via `rundeck-config.properties` or automated/API-driven setups). - -#### ::circle-dot:: Audit failed login attempts when using rundeck.jaaslogin=true [PR #10212](https://github.com/rundeck/rundeck/pull/10212) - - - Fixed: Failed login attempts are now audited when Rundeck is configured with `rundeck.jaaslogin=true`. Previously, JAAS authentication failures were silently dropped from the audit log. - -#### ::circle-dot:: Fix inline script step with Args not working with AWS SSM - - - Fixed a bug where inline script steps with `args` configured would fail with an S3 403 error when using the AWS SSM node executor. Script arguments are now correctly passed to the SSM `commandLine` parameter instead of being appended to the S3 URI. - -#### ::circle-dot:: Fix cannot manage user class for usernames containing slashes - - - Fix User Class management for usernames containing `/` (e.g. pronouns like `He/Him`). Assigning and removing User Class assignments now works correctly for these users. - -#### ::circle-dot:: Fix PagerDuty Notification Start Incident Workflow trigger - - - Fixed an issue where PagerDuty "Start Incident Workflow" notifications failed to trigger because the configured Incident ID and Incident Workflow ID were not being read correctly. These notifications now work as expected, and a clear error is logged if either required value is missing. - -#### ::circle-dot:: Fix legacy MySQL JDBC driver class at startup - - - Fixed a startup failure that occurred after upgrading when the database configuration still referenced the legacy MySQL JDBC driver class (`com.mysql.jdbc.Driver` or `com.mysql.cj.jdbc.Driver`). Rundeck now automatically substitutes the bundled MariaDB driver in these cases so the server starts successfully, and logs a warning directing operators to update their configuration. - -#### ::circle-dot:: Fix KeyStorageSelector state not resetting on reopen [PR #10155](https://github.com/rundeck/rundeck/pull/10155) - - - Fix PagerDuty V3 webhook: selecting a key from the Key Storage selector now correctly populates the Shared Secret Key field. - -#### ::circle-dot:: Fix job import resetting dispatch mode when node filter is empty [PR #10171](https://github.com/rundeck/rundeck/pull/10171) - - - Fixed an issue where jobs configured as "Dispatch to nodes" with an empty node filter were silently converted to "Execute locally" after export + reimport (via YAML, XML, Job Actions upload, SCM import, project archive import, or Terraform provider). - -#### ::circle-dot:: Fix Remote URL auth headers not appended when fetching option values [PR #10152](https://github.com/rundeck/rundeck/pull/10152) - - - Fixed a regression where Remote URL job options configured with API Key or Basic authentication were not sending the configured authentication headers or query parameters when fetching option values, causing the option dropdown to fail to load with an authentication error. - -#### ::circle-dot:: Remove usernames from System Report - - - The System Report no longer includes individual usernames or their userclass mappings. This improves privacy by ensuring user identities are not captured in generated system reports, while license allocation and usage totals continue to be reported. - -#### ::circle-dot:: Fixes bulk edit when using NextUI [PR #10189](https://github.com/rundeck/rundeck/pull/10189) - - - Fixed the layout of the bulk edit controls on the Jobs page when using the next-generation UI, correcting the alignment and structure of the header so bulk actions display properly. - -#### ::circle-dot:: Fix node filter attributes incorrectly wrapped in double quotes [PR #10157](https://github.com/rundeck/rundeck/pull/10157) - - - Fix node filter: saving a filter with multiple attributes (e.g. `osFamily: unix name:localhost`) no longer incorrectly wraps them in double quotes. Pre-quoted values are also preserved correctly when re-loading a saved filter. - -#### ::circle-dot:: Improve audit log userInfo.username showing null or anonymous for job runs [PR #10168](https://github.com/rundeck/rundeck/pull/10168) - - - Fix audit log `userInfo.username` for job run events. Scheduled jobs no longer show `null` and API/webhook-triggered jobs no longer show `__grails.anonymous.user__` — both now correctly reflect the user associated with the execution. + Fixed: the "Executions in the last Day" stat on the project home/list pages now links to the + Activity page pre-filtered to the last day, instead of showing all-time executions. @@ -248,6 +160,6 @@ The development updates are automatically generated from both our private reposi --- -**List Last updated:** 2026-08-03 +**List Last updated:** 2026-08-27 diff --git a/package-lock.json b/package-lock.json index d5ac6b1fc..3ea92d56f 100644 --- a/package-lock.json +++ b/package-lock.json @@ -6607,22 +6607,6 @@ } } }, - "node_modules/ajv/node_modules/fast-uri": { - "version": "4.1.2", - "resolved": "https://npm.artifacts.pd-internal.com/npm/fast-uri/-/fast-uri-4.1.2.tgz", - "integrity": "sha512-TyGmBcbDTZXcb2cj5MV89DrF42DKvb3y5DDUNh95iO+IMeAzMkVSxK1PZRrRIpc9yg8U2GhGdbofNa0LS/a4Bw==", - "funding": [ - { - "type": "github", - "url": "https://github.com/sponsors/fastify" - }, - { - "type": "opencollective", - "url": "https://opencollective.com/fastify" - } - ], - "license": "BSD-3-Clause" - }, "node_modules/ansi-html-community": { "version": "0.0.8", "resolved": "https://npm.artifacts.pd-internal.com/npm/ansi-html-community/-/ansi-html-community-0.0.8.tgz", @@ -8187,6 +8171,22 @@ "dev": true, "license": "MIT" }, + "node_modules/fast-uri": { + "version": "4.1.3", + "resolved": "https://npm.artifacts.pd-internal.com/npm/fast-uri/-/fast-uri-4.1.3.tgz", + "integrity": "sha512-7+72G6vLt7jjNas8SmSATx2qeyRIjxeqO3i4IkmDTxlqYZRKANhOe1bnovcp4WZmvsYrp60WyqPyHqgRiX0yXw==", + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/fastify" + }, + { + "type": "opencollective", + "url": "https://opencollective.com/fastify" + } + ], + "license": "BSD-3-Clause" + }, "node_modules/fdir": { "version": "6.5.0", "resolved": "https://npm.artifacts.pd-internal.com/npm/fdir/-/fdir-6.5.0.tgz", diff --git a/package.json b/package.json index cebccb911..2105d7089 100644 --- a/package.json +++ b/package.json @@ -61,7 +61,7 @@ "overrides": { "@apidevtools/json-schema-ref-parser": "^15.3.6", "nostics": "1.2.0", - "fast-uri": "4.1.2", + "fast-uri": "4.1.3", "brace-expansion": "5.0.9", "js-yaml": "4.3.1", "gray-matter": {