Highlights
Hardened messaging between nodes
Every row that moves between the nodes of a process travels through a queue on the RabbitMQ message broker, and the engine talks to that broker through the RabbitMQ Go client library. This release moves the engine, the SDK and the playpen template to version 1.13.0 of that library, which closes eleven published advisories, three of them rated critical. The fixes cover how the client parses the frames the broker sends, the TLS settings it derives from an amqps:// connection address, and how long it keeps broker credentials in memory. Playpens pick up the updated library through the automatic playpen upgrade when the upgraded service first starts. Go nodes and models build against it on their next run, with no change to their code.
Stronger API token validation
The web application’s REST API authenticates each request by validating the token it carries. The library behind that check, PyJWT, moves to 2.15.1 and closes ten advisories. The most serious strengthens the safeguard that keeps a public key from being accepted as a shared secret, and others tighten how signing keys are loaded and how key sets are fetched from an identity provider. Token-based sign-in works as before; see Authentication for how identity providers are configured.
An updated runtime for the message broker
The Erlang/OTP runtime that RabbitMQ runs on moves to 27.3.4.18, closing fifteen advisories, including a critical flaw in how a TLS 1.3 client authenticates the server it connects to. The deployment playbooks upgrade the runtime on every broker host.
Restart the message broker after upgrading
/opt/vor/bin/supervisorctl restart rabbitmq, as described in Restarting a service. Security
The release also includes these updates:
- The gRPC library behind the SDK API server moves to 1.83.2, closing a memory exhaustion issue that a crafted stream of HTTP/2 frames could trigger.
- The SSH library the engine uses to reach compute instances moves to its patched release, closing two denial-of-service issues.
- Django REST Framework moves to 3.18.1. It enforces the configured request size limit on JSON and form request bodies, and its admin renderer keeps protected data out of validation error pages.
- The Angular runtime moves to 21.2.23, which strengthens HTML sanitization of values bound through directive host bindings.
- The Moment date library moves to 2.31.0, which validates locale names before loading them.
- AnyIO, which the web application’s AI components depend on, moves to 4.14.2 and applies modern host name encoding when it verifies TLS certificates.
- The theme that renders this user guide moves to 9.7.7, which escapes search suggestions before displaying them.
Every update is checked against the project’s dependency scanners before release.
Administration & Deployment
Erlang/OTP 27.3.4.18. The foundation and RabbitMQ playbooks upgrade any host running an earlier Erlang/OTP release, and every installer checksum was verified against the downloaded package. The System Requirements page lists the updated packages. Go 1.26.8. Compute hosts receive the latest Go maintenance release, which playpens use to build Go nodes and models. Playpen code needs no change. The Third-Party Software page lists the bundled versions.
Upgrade Notes
Drop-in upgrade
Restart RabbitMQ on each broker host after the deployment completes, so the broker runs on the updated Erlang/OTP runtime. Playpens upgrade when the service first starts on the new version. On an installation that has disabled automatic upgrades, or for a playpen whose upgrade reports an error, run vor update playpen against the playpen directory.
Scripts that call the REST API directly should note two changes in Django REST Framework 3.18. Numeric fields accept finite values, so a request that writes NaN or Infinity into one receives a validation error. Validation errors for requests that submit a list of objects are returned as a dictionary.