* fix: Migrate to astral-tokio-tar to address CVE-2025-62518
Migrates from the abandoned tokio-tar library to the actively maintained astral-tokio-tar to address CVE-2025-62518 (TARmageddon), a high-severity RCE vulnerability (CVSS 8.1). The vulnerability involves a boundary-parsing bug in PAX/ustar header handling that enables file smuggling attacks via malicious TAR archives.
This is a drop-in replacement requiring only dependency updates in Cargo.toml files. The astral-tokio-tar library uses the same tokio_tar module name, so no source code changes are needed. All references to the vulnerable tokio-tar v0.3.1 have been removed from Cargo.lock and replaced with the patched astral-tokio-tar v0.5.6.
Related to previous PR #6943 which was closed due to CLA issues. Security disclosure available at https://edera.dev/stories/tarmageddon and patch details at https://github.com/astral-sh/tokio-tar/releases/tag/v0.5.6
* update
---------
Co-authored-by: Devdatta Talele <devtalele0@gmail.com>
Co-authored-by: Devdatta Talele <50290838+devdattatalele@users.noreply.github.com>
* data tables settings ui
* install runed
* zod 4 fixes
* use new toJSONSchema
* Migrate ducklake catalogs to more generic custom instance databases
* fix compilation
* Safety conversion for old duckdb ffi
* data tables settings
* ts client basis
* inline run works
* datatables work
* Revert "datatables work"
This reverts commit 6e1588d59e.
* datatables work (without leaking pg credentials)
* println
* separate sqlUtils.ts
* nit
* Separate custom instance db Select and Wizard components
* nit
* nit wording
* add tags to custom instance dbs
* error when trying to use ducklake as datatable or opposite
* show status in dropdown
* data table instance setup works
* sqk function for ducklake
* factorize logic
* fix temp reactivity
* Data table assetexplore
* Migrate S3 permissions to modal
* Revert "Migrate S3 permissions to modal"
This reverts commit 0631d03cb0.
* nit query -> fetch
* Custom instance setup new look
* run_language_executor separate fn
* run_inline param
* nit wording
* Better typed client
* Data tables display as assets in frontend
* asset db icon
* nit
* cleaner errors
* nit
* Fix sed calls in mac
* run_inline_script_preview in python client
* basic python datatable client
* datatable and datalake parser in python
* ducklake client python
* nit fix
* Fix migration producing NULL instead of {} when no custom databases
* merge conflict fail
* python ducklake client arg fix
* parse or infer sql types in ts client
* ts asset parser, detect datatable & ducklake R/W
* fix sql repl for other read ops than select
* export type SqlTemplateFunction
* rename list_custom_instance_pg_databases
* typecheck datatable and ducklake name in Typescript
* Fix typecheck datatable and ducklake in TS
* declare module overriding instead of extending
* infer_sql_type in python client
* SqlQuery object in python
* fix merge conflicts
* update const_format
* CI fix
* factor out to var_identifiers
* sqlx prepare
* unnecessary security (admin is required)
* clearer comment
* ee repo ref
* nit snake case
* claude step 1: detect var declarations
* move detect_sql_access_type to common mod
* claude step 2: detect when saved vars are queried
* Revert "claude step 2: detect when saved vars are queried"
This reverts commit 1e1f930568.
* Revert "claude step 1: detect var declarations"
This reverts commit f866f4819d.
* remove ducklake/datatable and default
* detect data table assigns in var_identifiers
* Python parser successfully infers R/W/RW from ducklake / datatable
* still register ducklake/datatable if not used as unknown R/W
* Go to settings button in Assets Dropdown on not found
* nit
* sqlx prepare fail
* manual fix, somehow sqlx prepare won't do it
* fix frontend ci
* ee repo ref
* ducklake_user doesnt exist in unit tests
* nit fix
* ui nit
* nit
* nit missing clone
* fork ducklakes and datatables
* fix surface hover bug
* stupid mistake
* better deeply reactive mutable derived
* Ducklake picker
* Editor bar data tables
* DuckDB supports datatables
* datatable in duckdb asset parser
* duckdb asset parser var_identifiers
* Revert "duckdb asset parser var_identifiers"
This reverts commit 88068b1a77.
* sqlx prepare
* Box pin in test_workflow_as_code to fix stack overflow
* stash
* sql asset parser parses most s3 literals
* nit
* Detect attach + handle returning RW
* detect assets used with dot notation
* detect implicit access with USE dl; syntax
* Add assets as unknown if var was never used
* Support default ducklake/datatable main in parser
* ignore asset parsing errors in frontend (avoid flow layout shift)
* super weird duplication (merge conflict ?)
* nits
* fix duckdb parser detecting too much as asset when RW ctx is unknown
* fix transparent assets btn
* missing arg
* nit styling
* asset parser specific table parsing
* fix resource specific table parsing
* More concise asset display in flows + better icons
* fix assets page filtering out resources with added table
* Fix frontend to support specific table assets
* Open DB Manager to specific table
* Specific table parser in Python and TS + unit tests
* Fix UPDATE setting access to None
* fix flow edge rendering on top of output picker
* python parser fix var override bug
* add ts test
* fix compilation
* sqlx prepare
* update parsers version
* fix missing schema key onDelete
* Grant permission to create schemas in custom instance databases
* Update pg query to return empty schemas
* Create schema
* Select nits
* support schemas in sql parser
* ts parser handle schema with sql parser result
* detect .schema() syntax
* detect schema syntax in python
* support .schema() in ts and py SDK
* open db manager to specific schema
* support reassignment in ts parser
* nit better unitest
* : syntax in ts
* datatable:schema syntax in python
* fix client py
* nit select dropdown darkmode
* object | null fetchOne
* ts client nits
* parse_sql_client_name fn
* getImportWmillTsStatement refactor in EditorBar
* text to json() in python client
* update parser versions
* pkg lock
* Sql query details in TS asset parser
* code transformation with type parameter in Editor
* Custom Language Worker, code substition works !
* Error marker mapping works
* hover info is correct
* completions work correctly
* other overrides
* type inference kinda works
* Position mapping tests
* refactor prepare_queries
* Refactor PgDatabase to share common code
* Pgdatabase in prepare_queries
* TokioPgConnection refactor
* refactor prepare_queries
* type parameter to sql function
* Fix deadlock
* nit fix
* Fix worker async call freezing because of svelte Proxy
* Force worker to recompute when we set queries
* nit refactor
* nits console logs
* wait that ts worker initialize
* monaco change file version
* update diagnostics
* Refactor for errors
* Show SQL errors in Monaco
* improve sdk
* cleaning refactor + MapResource + usePreparedAssetSqlQueries
* Fixes
* Fix error position mapping
* cache in typescript worker
* fix insert no values
* don't inject type if already present
* Support schema in prepare queries
* update parsers
* ChangeOnDeepInequality
* inferAsset ScriptEditor usage refactor
* sql query typecheck work in flow editor
* Assets and SQL Query check in Raw App Inline Editor
* pkg lock
* Fix DatatableSqlTemplateFunction nit
* prepare query schema nit
* duplicate diagnostics
* nit getScriptVersion mock
* Reprepare queries when switching workspaces
* nit fix
* nit fix
* fetch_one_scalar and execute in python client
* limit pg_connections
* -- prepare flag in postgres
* skip serializing
* fix destructuring undefined
* Prepare queries in workers instead of backend
* nit
* Execute search_path instructions normally
* nit fix
* Fix SET search_path issue in prepare
* only support preparing single-statement queries for now
* update parsers
* safety
* better remove_comments
* Fix getQueryStmtCountHeuristic
* getQueryStmtCountHeuristic tests
* comment out failing tests
* Fix getQueryStmtCountHeuristic impl
* only datatable
* Fix Python Enum and Literal schema generation with docstring descriptions
- Extract Enum class definitions and their string values
- Parse docstring Args: sections for parameter descriptions
- Map Enum type annotations to string enums with proper values
- Handle Enum.VALUE default values correctly
- Store descriptions in Arg.otyp field
- Add test case for enum with docstring parsing
* perf: optimize enum parser and fix default value handling
- Combine enum extraction and docstring parsing into single AST pass (2x performance improvement)
- Add support for IntEnum, StrEnum, Flag, IntFlag types
- Fix default values to use actual enum values (e.g., 'red') instead of member names (e.g., 'RED')
- Improve docstring parsing robustness with proper indentation tracking
- Clean up code structure with EnumInfo type for better maintainability
All tests pass. This addresses code review feedback for performance and correctness.
* perf: implement true lazy evaluation for enum parsing
- Only parse metadata when unknown types encountered
- Two-pass approach: parse types first, extract only if needed
- Zero overhead for scripts without enums
- Keyword checks + prepass filtering when extraction needed
* improve collapsible link
* do not show superadmin ws link when already in it
* improve OAuth UI
* sso/oauth instance settings ui
* refactor instance settings alerts WIP
* Indexer and Oauth to brand guidelines
* refactor ws error handler page
* Create a tab SMTP in the Instance Settings
* Ractivity isssue fix for tabs
* nit
* Add smtp settings status in Error handler
* Add smtp configuration status
* Display teams connection status for instance alerts
* nit
* Add critical alerts description
* nit
* nit
* improve ee display
* nit
* nit
* fix typo
* nit
* restore vit config
---------
Co-authored-by: Alexander Petric <alex@windmill.dev>
* fix: teams, need both guid and thread id format
* chore: update ee-repo-ref to 576abf6519d1aa12a2b989a58a123501206284fb
This commit updates the EE repository reference after PR #368 was merged in windmill-ee-private.
Previous ee-repo-ref: ae41589212f16ff0cec8516c66227f30e17c5564
New ee-repo-ref: 576abf6519d1aa12a2b989a58a123501206284fb
Automated by sync-ee-ref workflow.
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* fix(backend): put for loop itered in a separate table
* Update SQLx metadata
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* feat: email triggers custom cert
* chore: update ee-repo-ref to 6edb5e9ea22b88f81dc9ee2741ea679d9b22f61c
This commit updates the EE repository reference after PR #364 was merged in windmill-ee-private.
Previous ee-repo-ref: 4053446d2dff0310ecb89cf6e37f00b49217443a
New ee-repo-ref: 6edb5e9ea22b88f81dc9ee2741ea679d9b22f61c
Automated by sync-ee-ref workflow.
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* feat: improve teams search ux
* ee ref
* claude review
* chore: update ee-repo-ref to e218dfce97dcea56c6ef6032592dab812a3f5047
This commit updates the EE repository reference after PR #363 was merged in windmill-ee-private.
Previous ee-repo-ref: 1b95a24ab25d96e59d2f22588901e9d3ce6c72b3
New ee-repo-ref: e218dfce97dcea56c6ef6032592dab812a3f5047
Automated by sync-ee-ref workflow.
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* data tables settings ui
* install runed
* zod 4 fixes
* use new toJSONSchema
* Migrate ducklake catalogs to more generic custom instance databases
* fix compilation
* Safety conversion for old duckdb ffi
* data tables settings
* ts client basis
* inline run works
* datatables work
* Revert "datatables work"
This reverts commit 6e1588d59e.
* datatables work (without leaking pg credentials)
* println
* separate sqlUtils.ts
* nit
* Separate custom instance db Select and Wizard components
* nit
* nit wording
* add tags to custom instance dbs
* error when trying to use ducklake as datatable or opposite
* show status in dropdown
* data table instance setup works
* sqk function for ducklake
* factorize logic
* fix temp reactivity
* Data table assetexplore
* Migrate S3 permissions to modal
* Revert "Migrate S3 permissions to modal"
This reverts commit 0631d03cb0.
* nit query -> fetch
* Custom instance setup new look
* run_language_executor separate fn
* run_inline param
* nit wording
* Better typed client
* Data tables display as assets in frontend
* asset db icon
* nit
* cleaner errors
* nit
* Fix sed calls in mac
* run_inline_script_preview in python client
* basic python datatable client
* datatable and datalake parser in python
* ducklake client python
* nit fix
* Fix migration producing NULL instead of {} when no custom databases
* merge conflict fail
* python ducklake client arg fix
* parse or infer sql types in ts client
* ts asset parser, detect datatable & ducklake R/W
* fix sql repl for other read ops than select
* export type SqlTemplateFunction
* rename list_custom_instance_pg_databases
* typecheck datatable and ducklake name in Typescript
* Fix typecheck datatable and ducklake in TS
* declare module overriding instead of extending
* infer_sql_type in python client
* SqlQuery object in python
* fix merge conflicts
* update const_format
* CI fix
* factor out to var_identifiers
* sqlx prepare
* unnecessary security (admin is required)
* clearer comment
* ee repo ref
* nit snake case
* claude step 1: detect var declarations
* move detect_sql_access_type to common mod
* claude step 2: detect when saved vars are queried
* Revert "claude step 2: detect when saved vars are queried"
This reverts commit 1e1f930568.
* Revert "claude step 1: detect var declarations"
This reverts commit f866f4819d.
* remove ducklake/datatable and default
* detect data table assigns in var_identifiers
* Python parser successfully infers R/W/RW from ducklake / datatable
* still register ducklake/datatable if not used as unknown R/W
* Go to settings button in Assets Dropdown on not found
* nit
* sqlx prepare fail
* manual fix, somehow sqlx prepare won't do it
* fix frontend ci
* ee repo ref
* ducklake_user doesnt exist in unit tests
* nit fix
* ui nit
* nit
* nit missing clone
* fork ducklakes and datatables
* fix surface hover bug
* stupid mistake
* better deeply reactive mutable derived
* Ducklake picker
* Editor bar data tables
* DuckDB supports datatables
* datatable in duckdb asset parser
* duckdb asset parser var_identifiers
* Revert "duckdb asset parser var_identifiers"
This reverts commit 88068b1a77.
* sqlx prepare
* Box pin in test_workflow_as_code to fix stack overflow
* stash
* sql asset parser parses most s3 literals
* nit
* Detect attach + handle returning RW
* detect assets used with dot notation
* detect implicit access with USE dl; syntax
* Add assets as unknown if var was never used
* Support default ducklake/datatable main in parser
* ignore asset parsing errors in frontend (avoid flow layout shift)
* super weird duplication (merge conflict ?)
* nits
* fix duckdb parser detecting too much as asset when RW ctx is unknown
* fix transparent assets btn
* missing arg
* nit styling
* asset parser specific table parsing
* fix resource specific table parsing
* More concise asset display in flows + better icons
* fix assets page filtering out resources with added table
* Fix frontend to support specific table assets
* Open DB Manager to specific table
* Specific table parser in Python and TS + unit tests
* Fix UPDATE setting access to None
* fix flow edge rendering on top of output picker
* python parser fix var override bug
* add ts test
* fix compilation
* sqlx prepare
* update parsers version
* fix missing schema key onDelete
* Grant permission to create schemas in custom instance databases
* Update pg query to return empty schemas
* Create schema
* Select nits
* support schemas in sql parser
* ts parser handle schema with sql parser result
* detect .schema() syntax
* detect schema syntax in python
* support .schema() in ts and py SDK
* open db manager to specific schema
* support reassignment in ts parser
* nit better unitest
* : syntax in ts
* datatable:schema syntax in python
* fix client py
* nit select dropdown darkmode
* object | null fetchOne
* ts client nits
* parse_sql_client_name fn
* getImportWmillTsStatement refactor in EditorBar
* text to json() in python client
* update parser versions
* pkg lock
* fix(backend): better trigger listening logs
* chore: update ee-repo-ref to d347295041426d03039b747a148a71e3583c3a6b
This commit updates the EE repository reference after PR #362 was merged in windmill-ee-private.
Previous ee-repo-ref: 37b533704e1b40e616ac144bebeff574a5d048e1
New ee-repo-ref: d347295041426d03039b747a148a71e3583c3a6b
Automated by sync-ee-ref workflow.
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>
* SCIM 2.0 RFC compliance + displayName support
* chore: update ee-repo-ref to 9a4b392262c760fc52256ca00e4d751d9f42e79e
This commit updates the EE repository reference after PR #361 was merged in windmill-ee-private.
Previous ee-repo-ref: ee9310c785bdf65d5b3136b0a24e0018900e18d0
New ee-repo-ref: 9a4b392262c760fc52256ca00e4d751d9f42e79e
Automated by sync-ee-ref workflow.
---------
Co-authored-by: windmill-internal-app[bot] <windmill-internal-app[bot]@users.noreply.github.com>