Skip to navigation

Platform 6.6.0 is a minor release that adds validation APIs across Platform components, expands audit logging, and introduces a rich text editor for Agent Prompts. This release also includes security updates, bug fixes, and enhancements across Core, Gateway Manager, Integrations, Work Center, and NSO Service Manager.

For more information on new features introduced in this release, see Platform 6.6 feature announcement.

ComponentFeatureDescription
Agent ProjectsRich text editor for Agent Prompts (ENG-27470)Replaced the plain text editor in Agent Prompts with a rich text editor.
Configuration ManagerGolden configuration validation API (ENG-26750)Added a validation API for golden configurations and improved validation checks when you create or update them.
CoreAudit logging for authorization, service, and Studio resources (ENG-27886)Added audit logging for authorization, service, and Studio resources.
CorePlatform encryption key rotation script (ENG-27147)Added a script to rotate Platform encryption keys.
CoreAudit logging capabilities (ENG-26769, ENG-27172)Enabled log.audit capabilities in services and Platform.
CoreWeb server metrics endpoint (ENG-25533)Added an OpenTelemetry-compatible /metrics/webserver endpoint that exposes web server request, error, and latency metrics for monitoring and observability.
Gateway ManagerDelete dialog styling for certificates (ENG-28165)Improved the styling of the delete dialog for Gateway Manager certificates.
Gateway ManagerVirtual cluster load balancing (ENG-27425)Made minor improvements to load balancing for virtual clusters.
Gateway ManagerResource payload validation API (ENG-26751)Added a validation API endpoint that checks resource payloads before you create them. Also improved validation on the create and update endpoints to reject invalid or dangerous payloads more reliably.
Configuration Manager EnterpriseJSON compliance reports written to GridFS (ENG-27199)Large JSON compliance reports are now written to GridFS.
Configuration Manager EnterpriseDevice compliance reports written to GridFS (ENG-27198)Large device compliance reports are now written to GridFS.
Inventory ManagerSemantic validation for inventory documents (ENG-26749)Added semantic validation for inventory, node, action, and tag documents. Validation runs automatically on create and update. You can also check a draft before saving with the new POST /v1/validate endpoint. This ensures FlowAI builder skills persist only valid changes.
MOPMOP validation API (ENG-26773)Added a validation API that verifies the form and shape of templates using backend and frontend logic.
Operations ManagercomponentType required with componentId or componentName (ENG-26443)Operations Manager now requires componentType whenever you set componentId or componentName.
Operations ManagerGBAC read-requires-write on createAutomation (ENG-26442)Enforced the GBAC read-requires-write rule on createAutomation.
Operations ManagerValidation for componentName-only automation updates (ENG-26441)Added validation for automation updates that set only componentName.
Operations ManagerManual trigger validation (ENG-26440)Operations Manager now validates manual trigger formId and formData at write time.
StudioTransformation validation API (ENG-26772)Added a validation API for transformations.
Studio, Workflow engineKeys with reserved characters (ENG-27145)Added support for resolving keys that contain ?, (, [, or {. Platform no longer treats these characters as reserved.
TemplatesTemplate validation API (ENG-26793)Added a validate template API endpoint that checks the structure of a template using frontend and backend rules.
WorkflowsDeep validation option for workflow import (ENG-27588, ENG-27589, ENG-27590)Added an option to the import workflows API call for deep validation. Validation now warns when the position field is missing.
ComponentFeatureDescription
CoreStale adapter method and task configurations (ENG-27920)Fixed an issue where restarting an adapter left Platform showing outdated method and task configurations.
CoreexportService and exportProfile errors (ENG-27543)Fixed an issue where exportService and exportProfile always threw an error instead of returning a result.
CoreDuplicate service fork (ENG-27333)Fixed a race condition that could fork a service twice and leave an untracked duplicate process when a restart, start, or reboot overlapped with another operation on the same service.
CoreMissing views property in pronghorn.json (ENG-27329)Fixed an issue where a missing views property in a pronghorn.json file caused UIs to crash with a “Something Went Wrong” message.
CoreMongoDB oplog growth in looped workflows (ENG-27251)Fixed excessive MongoDB oplog growth in looped workflows.
CoreOpenAPI 3.0 import rejected for boolean exclusiveMinimum (ENG-26838)Fixed an issue where OpenAPI 3.0 integration imports were rejected when exclusiveMinimum was a boolean.
CoreIntegration worker memory leak (ENG-26833)Fixed a slow memory leak in the Integration worker. Per-request loggers left behind an exception handler, which caused memory use to grow over the life of a long-running process.
FlowAITool discovery failure isolation (ENG-27678)Tool discovery now isolates a failure to the specific tool that failed instead of blocking the whole collection.
FlowAI, Operations Manager, Work CenterRedis rolling restart handling (ENG-26590)Fixed how FlowAI, Operations Manager, and Work Center handle a Redis rolling restart.
Gateway ManagerStale text in delete confirmation dialogs (ENG-28154)Fixed an issue where Gateway delete confirmation dialogs displayed stale text.
Gateway ManagerGateway certificate toggle (ENG-27564)Fixed a UI issue when toggling Gateway certificates.
IntegrationsBare string responses with dynamic retrieval (ENG-28568, ENG-29247, ENG-28969)Fixed authentication and Gateway-routed requests for integration models that use x-itential-dynamic-retrieval with a bare string response.
IntegrationsVariable substitution for path-level and operation-level parameters (ENG-27670)Fixed OpenAPI integration variable substitution so x-itential-variable values declared on path-level or operation-level parameters are injected into outgoing requests.
IntegrationsOversized OpenAPI model import (ENG-27378)Fixed an issue where importing an OpenAPI integration model over 15 MB could succeed despite a warning. Platform now rejects oversized models with a clear error message.
IntegrationsAWS Signature v4 with non-standard hostnames (ENG-27372)Added support for explicitly declaring the AWS region and service on an integration. AWS Signature v4 authentication now works with non-standard hostnames.
JSON formsDynamic dropdown 404 with special characters in adapter name (ENG-9540)Fixed an issue where a JSON form dynamic dropdown returned a 404 error when the adapter it queried had a space or other special character in its name.
JSON formsForm clipped when errors are present (ENG-7534)Fixed an issue where a JSON form was visually clipped when form errors were present and you selected a radio button.
JSON formsAdd Validation tooltip (ENG-5865)Removed the tooltip from the Add Validation button in the JSON form configure dialog.
JSON formsDuplicate wizard step numbers (ENG-5860)Fixed an issue where a dynamic dropdown with a JSON Schema transformation (JST) source and a field dependency displayed two wizard steps numbered “3” instead of “3” and “4”.
JSON formsDynamic dropdown API display (ENG-5159)Fixed an issue with how dynamic dropdowns display API data.
Lifecycle ManagerBroken redirect (ENG-10761)Fixed a broken redirect in Lifecycle Manager.
Lifecycle ManagerScrollbar flicker in Firefox (ENG-5382)Fixed an issue where the scrollbar flickered in the Instance History and Instance Groups history lists in Firefox.
MOP, Studio, WorkflowsBlank ID overwrote existing ID (ENG-27183)Fixed an issue where an existing ID could be overwritten with a blank ID, which caused errors.
NSO Service ManagerTrace context for NSO 6.3 and later (ENG-27014)Improved trace context support for NSO 6.3 and later to provide better request tracing across additional supported methods.
Operations ManagerBrowser freeze on long job ancestor chains (ENG-29014)Fixed an issue where opening the details page of a job with a very long ancestor chain froze or crashed the browser tab. An example is a recursive child job tens of thousands of levels deep. The job breadcrumb now looks up only the root job and the 10 nearest ancestors. Users without permission to view jobs no longer trigger the ancestor lookup.
Operations Manager, Work CenterAdditional debug logging (ENG-27156)Added debug logging to Operations Manager and Work Center.
PlatformMisaligned array field columns (ENG-27614)Fixed an issue in JSON Schema Form array fields where row columns were misaligned with the column header. This happened when a schema combination (allOf or if-then) added a column for only some rows.
ProjectsPagination controls hidden by banner (ENG-28241)Fixed an issue where the pagination controls on the Projects list view became inaccessible when a banner was displayed.
ProjectsAdd to project search filter (ENG-4882)Fixed the filter in the add to project search dialog so it searches all documents instead of only the current page.
Projects, StudioEmpty area below tree navigation lists (ENG-4204)Fixed an issue where an empty, non-functional area appeared below the last item in some tree-based navigation lists.
Projects, TransformationsJST tour popup stays visible (ENG-13439)Fixed an issue where the JSON Schema transformation (JST) “Take a Tour!” onboarding popup stayed visible after you left the JST editor without dismissing it.
StudioRun Service nested query saved to wrong field (ENG-28436)Fixed an issue where a task query on a field nested in the Run Service task’s params object saved to a duplicate top-level field, so the task received an empty value at runtime. Queries now target the intended field.
Studio, Templates, TransformationsIn-flight work lost during restart (ENG-26870)Fixed an issue where in-flight work in the JST transformation, MOP retry, and Template Builder services could be lost or left incomplete during a Platform restart. These services now complete or safely hand off in-flight work during shutdown.
TransformationsMultiple tabs opened on click (ENG-27029)Fixed an issue where a transformation opened multiple tabs when you selected it.
TransformationsStop method scroll reset in JST builder (ENG-4985)Fixed an issue where the Stop method scroll position reset in the JST builder.
TransformationsReordering user function inputs broke mappings (ENG-3311)Fixed an issue where reordering the inputs on a user function could break existing input mappings.
Work CenterAssignee dropdown and column (ENG-28591)Fixed an issue where the Assignee dropdown didn’t populate until you typed a filter, and the Assignee column could show a raw account ID instead of the user’s name. An older account record crashed the account list lookup. The lookup now handles these records.
WorkflowsTask input values restored from another task (ENG-29225)Fixed an issue in the Workflow Editor where switching a task input back to Job, Static, or Task could restore a value from a different task’s input with the same name. Platform now remembers previous values for each task and each input.
WorkflowsRun Service task parameters (ENG-28541)Fixed existing workflows with Run Service tasks that were previously modified incorrectly. The queried value is now stored correctly in the task parameters.
WorkflowsJob variable input validation (ENG-27668)Fixed an issue where running a workflow with a task input set to a job variable with an inline query failed input validation when you provided an object or array. The workflow input schema now accepts objects and arrays for these variables.
Workflows.xlsm upload on Windows (ENG-26434)Fixed an issue where uploading .xlsm files on Windows failed.
WorkflowsEdit buttons shifted by long names (ENG-14388)Fixed an issue where long names pushed the edit buttons down. The edit options now stay on the same line.
WorkflowsDuplicate x and y coordinates (ENG-9373)Fixed an issue where an item stored more than one set of x and y coordinates. Each item now has only one set.
WorkflowsChild job not run for empty loop array (ENG-5444)Platform now displays a clear message when a child job never ran because the loop array was empty.

This release includes security updates that address vulnerabilities in third-party packages and Platform components.

ComponentFeatureDescription
Admin EssentialsPrototype pollution in Integration Model viewer (ENG-28232)Fixed a client-side prototype pollution vulnerability (CVE-2026-93753) in the Integration Model viewer. Imported OpenAPI and Swagger documents are now sanitized to remove __proto__, constructor, and prototype keys before rendering. This closes a bypass in the deepmerge dependency, which has no upstream fix.
CoreReDoS in brace-expansion (ENG-28894)Updated brace-expansion, which minimatch uses internally for glob pattern matching, to patched versions to resolve a denial-of-service (ReDoS) vulnerability (CVE-2026-102277).
Coreaxios vulnerability (ENG-28881)Updated axios to resolve a security vulnerability.
CoreCRLF injection in form-data (ENG-28474)Updated form-data to 4.0.6 to resolve a CRLF injection vulnerability (CVE-2026-12143). The vulnerable code path isn’t reachable from Platform first-party code.
Coreproxy-addr vulnerability (ENG-27978)Overrode the proxy-addr dependency to resolve a known vulnerability.
Coremoment vulnerability (ENG-27977)Updated moment to resolve a security vulnerability.
CoreMemory leak in compression (ENG-27932)Updated compression to resolve a memory-leak vulnerability.
CoreReDoS in path-to-regexp (ENG-27889)Updated path-to-regexp, which Express uses internally, to the latest patched version to resolve a denial-of-service (ReDoS) vulnerability (CVE-2026-4867).
Coreundici vulnerability (ENG-27496)Updated undici to resolve a security vulnerability.
Corefast-uri vulnerability (ENG-27465)Updated fast-uri to resolve a security vulnerability.
Core@xmldom/xmldom vulnerability (ENG-27392)Updated the transitive @xmldom/xmldom dependency to resolve a security vulnerability.
Corejs-yaml vulnerability (ENG-27390)Updated js-yaml to resolve a security vulnerability.
CoreUnmaintained json-stringify-safe dependency (ENG-26693)Replaced the unmaintained json-stringify-safe dependency with safe-stable-stringify for worker-thread message serialization and JSON Schema sanitization.
Gateway ManagerThird-party dependency updates (ENG-28266, ENG-27909, ENG-27908, ENG-27891, ENG-27890, ENG-27887)Updated third-party dependencies to resolve security vulnerabilities.
Gateway Managerws vulnerability (ENG-27892)Updated ws to resolve security vulnerabilities.
Gateway ManagerHTML sanitizer vulnerability in monaco-editor (ENG-26372)Updated monaco-editor, the code editor bundled with Gateway Manager, to resolve a vulnerability (CVE-2026-65898) in its embedded HTML sanitizer.
Gateway Manager, Inventory ManagerThird-party dependency updates (ENG-29474)Updated third-party dependencies to resolve security vulnerabilities.
Inventory ManagerThird-party dependency updates (ENG-28264, ENG-27910)Updated third-party dependencies to resolve security vulnerabilities.
Legacy FormsUnused wicked-good-xpath polyfill (ENG-26695)Removed the unused wicked-good-xpath polyfill from the Form Builder task path.
NSO Service ManagerXSS in DOMPurify (app-service_management) (ENG-29479)Resolved a cross-site scripting (XSS) vulnerability by updating DOMPurify to a secure version in app-service_management.
NSO Service ManagerDouble decoding in fast-uri (app-nso_manager) (ENG-29472)Resolved a double decoding of the same data vulnerability (CVE-2026-75899) by updating fast-uri to a secure version in app-nso_manager.
NSO Service ManagerXSS in DOMPurify (app-nso_manager) (ENG-29463)Resolved a cross-site scripting (XSS) vulnerability by updating DOMPurify to a secure version in app-nso_manager.
NSO Service ManagerUncontrolled recursion in brace-expansion (app-nso_manager) (ENG-29457)Resolved an uncontrolled recursion vulnerability (CVE-2026-102276) by updating brace-expansion to a secure version in app-nso_manager.
NSO Service ManagerCase sensitivity in fast-uri (app-service_management) (ENG-29227)Resolved an improper handling of case sensitivity vulnerability (CVE-2026-86472) by updating fast-uri to a secure version in app-service_management.
NSO Service ManagerInfinite loop in uri-js (app-service_management) (ENG-29226)Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the affected uri-js dependency with a drop-in replacement in app-service_management.
NSO Service ManagerSSRF in axios (app-nso_manager) (ENG-29111)Resolved a server-side request forgery (SSRF) vulnerability (CVE-2026-101898) by updating axios to 1.20.0 in app-nso_manager.
NSO Service ManagerInfinite loop in uri-js (app-nso_manager) (ENG-28512)Resolved an infinite loop vulnerability (CVE-2026-93690) by replacing the affected uri-js dependency with a secure replacement in app-nso_manager.
NSO Service ManagerDirectory traversal in Moment (app-nso_manager) (ENG-28511)Resolved a directory traversal vulnerability (CVE-2026-17495) by updating moment to a secure version in app-nso_manager.
NSO Service ManagerInterpretation conflict in fast-uri (app-service_management) (ENG-28510)Resolved an interpretation conflict vulnerability (CVE-2026-84292) by updating fast-uri to 3.1.7 in app-service_management.
Operations Manageraxios vulnerability (ENG-29405)Updated axios in Operations Manager 23.2 to resolve a security vulnerability.
PlatformDependency updates (ENG-28288)Updated Platform dependencies to resolve security vulnerabilities.
StudioDeprecated lodash.isequal dependency (ENG-26696)Replaced the deprecated lodash.isequal dependency with isDeepStrictEqual from node:util on the server and equals from ramda in browser-bundled code. This internal change doesn’t affect user-facing behavior.
Work CenterMultiple vulnerabilities in axios (ENG-28877, ENG-28875, ENG-28873, ENG-28871, ENG-28870)Updated axios to a patched release to resolve multiple high-severity vulnerabilities, including ReDoS, denial of service, improper input validation, and prototype pollution.
Work CenterUncontrolled recursion in brace-expansion (ENG-28739)Resolved a high-severity uncontrolled recursion vulnerability (CVE-2026-102276) in the brace-expansion dependency used by nestjs-platform by updating the transitive dependency to a patched version.
Work CenterUncontrolled recursion in backend dependency (ENG-28731)Resolved a high-severity uncontrolled recursion vulnerability, which could cause denial of service, by updating a third-party dependency of the Work Center backend service to a patched version.
Work CenterIP spoofing in proxy-addr (ENG-27956, ENG-27942)Resolved a critical vulnerability (CVE-2026-90711) in proxy-addr. A crafted X-Forwarded-For header could spoof the client IP address and bypass IP-based access control, rate limiting, geolocation, and audit logging.
Work Centermulter vulnerability (ENG-27928)Resolved a vulnerability in the multer package.
Work CenterPrototype pollution in joi (ENG-27843)Updated joi in work-center-service from 18.2.3 to 18.2.9 to resolve a prototype pollution vulnerability (CVE-2026-90771).
Work Centerjs-yaml vulnerability (ENG-27416)Resolved a vulnerability in the js-yaml package.
Work CenterNested dependency vulnerability in shared library (ENG-27405)Resolved a vulnerability in a nested dependency of a shared library that Work Center and Agent Session Manager use.
ComponentFeatureDescription
NSO Service ManagerNode.js 22 and npm 10 support (ENG-27541, ENG-27540, ENG-27539)Updated package metadata in app-service_management, app-nso_manager, and adapter-nso to support Node.js 22 and npm 10.
ComponentVersion
FlowAI1.2.0
Gateway Manager1.2.4
Inventory Manager1.2.19
NSO Service Manager6.6.0
Configuration Manager Enterprise6.6.0