> This page is for Itential Gateway, version 4.
> For other versions, use one of these documentation indexes:
> - 5 (default): https://docs.itential.com/itential-gateway/5/llms.txt
> - 4: https://docs.itential.com/itential-gateway/4/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# Gateway 4.4.2

Itential Gateway 4.4.2 is a maintenance release containing three bug fixes and 10 security fixes.

#### Bug fixes (3)

| Issue                                                                           | Description                                                                                                                                                                                                                                                        |
| ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Fixed incomplete and inaccurate device sidebar search results** (ENG-25591)   | Fixed an issue where the device sidebar search didn't return devices in nested groups, and matching a group name returned all of the group's devices instead of only the matching ones. Search now traverses nested groups and filters results by the search term. |
| **Fixed stale device and group data after an inventory refresh** (ENG-27802)    | Fixed an issue where refreshing the external inventory didn't clear the device and group lookup caches, so lookups returned pre-refresh data until Gateway restarted. Gateway now clears these caches before reloading the inventory.                              |
| **Fixed cache files ignoring the global\_cache\_directory setting** (ENG-28148) | Fixed an issue where Gateway always wrote the `devices_cache.json` and `groups_cache.json` files to `/tmp` at startup, regardless of the `global_cache_directory` setting. Gateway now writes these files to the configured directory.                             |

#### Security fixes (10)

| Issue                                                                                                                                                           | Description                                                                                                                         |
| --------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| **Resolved vulnerabilities in fast-uri, js-yaml, and moment** (ENG-27402)                                                                                       | Updated the fast-uri, js-yaml, and moment packages to resolve Snyk-identified security vulnerabilities.                             |
| **Resolved vulnerabilities in fast-uri** (ENG-27403)                                                                                                            | Updated the fast-uri package to version 3.1.7 to resolve security vulnerabilities.                                                  |
| **Resolved a vulnerability in js-yaml** (ENG-27404)                                                                                                             | Updated the js-yaml package to resolve a Snyk-identified security vulnerability.                                                    |
| **Resolved a vulnerability in fast-uri** (ENG-27974)                                                                                                            | Updated the fast-uri package to resolve a Snyk-identified security vulnerability.                                                   |
| **Resolved a vulnerability in moment** (ENG-27975)                                                                                                              | Updated the moment package to resolve a Snyk-identified security vulnerability.                                                     |
| **Resolved vulnerabilities in axios** (ENG-28690, ENG-28904, ENG-28905, ENG-28906, ENG-28907, ENG-28908, ENG-28909, ENG-28910, ENG-28911, ENG-28912, ENG-28913) | Updated the axios package to version 1.20.0 to resolve security vulnerabilities.                                                    |
| **Resolved vulnerabilities in axios and brace-expansion** (ENG-28691)                                                                                           | Updated the axios package to version 1.20.0 and the brace-expansion override to version 5.0.12 to resolve security vulnerabilities. |
| **Resolved vulnerabilities in brace-expansion** (ENG-28692, ENG-28693, ENG-28694)                                                                               | Updated the brace-expansion override to version 5.0.12 to resolve security vulnerabilities.                                         |
| **Resolved vulnerabilities in urllib3** (ENG-29221, ENG-29223)                                                                                                  | Updated the urllib3 package to version 2.8.0 to resolve security vulnerabilities.                                                   |
| **Resolved vulnerabilities in Werkzeug** (ENG-29224)                                                                                                            | Updated the Werkzeug package to version 3.1.9 to resolve security vulnerabilities.                                                  |

#### Component version

| Component           | Version |
| ------------------- | ------- |
| automation\_gateway | 4.4.58  |