24.07 Release notes
Instabase 24.07 is a major release that introduces new features, enhancements, and bug fixes.
Subsequent patch releases typically contain bug fixes along with testing, optimizations, security fixes, and other internal changes.
Release 24.07.55
February 19, 2025
-
Resolved [CVE-2024-47874] | Updated
starlette
package to version 0.40.0. -
Resolved [CVE-2021-26291] | Updated
maven-core
package to version 3.8.1. -
Resolved [CVE-2017-1000487] | Updated
plexus-utils
package to version 3.0.16.
Release 24.07.54
February 12, 2025
-
Some account operation audit logs were empty.
-
The audit log for account creation logged the requestor username only if the account was created by an admin, but not if the account was created by the user.
-
The audit log for service account creation did not log the username of the user who initiated the request.
-
Resolved [CVE-2024-45341] Updated
go
to 1.22.11.
Release 24.07.53
February 7, 2025
This release contains no changes to user functionality.
Release 24.07.52
February 5, 2025
- Resolved CVE-2024-56201 | Upgraded
jinja2
to version 3.1.5.
Release 24.07.51
February 2, 2025
- Resolved [CVE-2024-47535] | Upgraded the
netty-common
package to version 4.1.115.
Release 24.07.50
January 30, 2025
This release contains no changes to user functionality.
Release 24.07.49
January 30, 2025
This patch was a version bump.
Release 24.07.48
January 30, 2025
-
Resolved [CVE-2024-47554] | Updated the
commons-io:commons-io
package to version 2.14.0. -
Resolved [CVE-2024-8096] | Updated
jaeger-agent
to 1.62.0. -
Resolved [CVE-2024-8309] | Updated the
langchain
package to version 0.2.5.
Release 24.07.47
January 29, 2025
-
Human review did not correctly give some needed warnings.
-
Errors with Azure Blob store storage systems were not translated into their corresponding HTTP error codes, but were logged as INTERNAL errors.
-
Resolved [CVE-2024-32002] | Removed
git
from theray-head
Docker image. -
Resolved [CVE-2018-1000021]
-
Updated the
bootstrap
library to version 5.
Release 24.07.46
January 23, 2025
This patch contains testing, optimizations, security, and minor internal changes. User functionality is unchanged.
Release 24.07.45
January 22, 2025
This patch contains testing, optimizations, security, and minor internal changes. User functionality is unchanged.
Release 24.07.44
January 22, 2025
-
Resolved [CVE-2024-56326] | Update
jinja
package to version 3.1.5. -
Resolved [CVE-2024-38820], [CVE-2024-38827] | Updated the
springframework#spring-context
library to version 6.1.14. -
Resolved [CVE-2024-45337] | Updated the
crypto
package to version 0.31.0. -
Resolved [CVE-2024-45337] | Updated the
jaeger
package to version 1.65.0.
Release 24.07.43
January 16, 2025
This release was a version bump and contained no changes.
Release 24.07.42
January 16, 2025
-
Resolved [CVE-2024-52804] | Updated the Python
tornado
package to version 6.4.2. -
Resolved [CVE-2023-28859] | Updated the
redis
package to version 4.6.0.
Release 24.07.41
January 10, 2025
- You can run accuracy reports on ground truth sets with class names greater than 31 characters.
Release 24.07.40
Release 24.07.40 was not released.
Release 24.07.39
December 18, 2024
-
Searching by job ID didn’t work reliably for certain formats.
-
Resolved [CVE-2023-28858] | Updated the
redis
package to version 4.5.3.
Release 24.07.38
December 11, 2024
-
Resolved [CVE-2023-29401] | Updated the
gin
package to version 1.9.1. -
Resolved [GHSA-78wr-2p64-hpwj] | Updated the
ray
package to version 2.39.0. -
Resolved [CVE-2024-3095] | Updated the
langchain
package to version 0.2.10. -
Resolved [CVE-2024-49767] | Updated
werkzeug
to version 3.0.6.
Release 24.07.37
December 4, 2024
-
Resolved [GHSA-h4gh-qq45-vh27] | Updated
cryptography
package to version 43.0.1. -
Resolved [CVE-2024-49767] | Updated
werkzeug
package to version 3.0.6. -
Resolved [CVE-2024-5187] | Updated
onnx
package to version 1.17.0.
Release 24.07.36
November 29, 2024
- Resolved [CVE-2024-37891] | Updated the
urllib3
package to version 1.26.20.
Release 24.07.35
November 27, 2024
-
If a username was in all uppercase letters, searching for the username did not return the user.
-
Batch requests to the model service experienced transient errors.
-
Resolved [CVE-2024-41131] | Updated the
form-recognizer
package to 2022-08-31.20241107.1-14d4cf9e. -
Resolved [CVE-2024-52304] | Updated
aiohttp
package to version 3.10.11. -
Resolved [[CVE-2024-49768]] (https://nvd.nist.gov/vuln/detail/CVE-2024-49768) | Updated the
waitress
package to version 3.0.1.
Release 24.07.34
November 20, 2024
-
You can no longer upload files with names longer than 210 characters into ML Studio or Solution Builder, as it breaks model training.
-
Model download performance has been improved.
-
Custom job ID strings that were not in UUID format would break human review.
-
Resolved [CVE-2024-7254] | Updated opensearch version to 2.18. <!–VTEST–47373–>
-
Resolved [CVE-2021-41495] | Updating package
numpy
to version 1.22.2. -
Resolved [CVE-2024-7254], [CVE-2024-47554] | Fixed vulnerability issues for
protoc
andcommons.io
in the conversion service. -
Resolved [CVE-2024-38808] | Update
spring-expression
to 5.3.39.
Release 24.07.33
November 14, 2024
-
Tasks could be marked as failed when
api-server
pods were temporarily overloaded. If this occurs now, the task is retried. -
Changing the classification of a document in a V2 flow caused human review to crash.
-
Resolved [CVE-2024-5452] | Upgraded
pytorch-lightning
package to version 2.4. -
Resolved [CVE-2024-28122] | Upgraded package
jwx
to version 1.2.29. -
Resolved [CVE-2024-35255] | Upgraded
azidentity
package to version 1.6.0. -
Security | Upgraded
/nats-server/v2
package to version 1.17.11.
Release 24.07.32
November 6, 2024
-
Job count, which was previously removed from the Flow Review due to performance issues, has been reinstated, but you must enable it in Admin > Configuration
-
Resolved [CVE-2016-2510] | Removed
libbsh-java
and dependentlibreoffice helper
packages. -
Resolved [CVE-2024-7254]
Release 24.07.31
October 31, 2024
-
Resolved [CVE-2022-1996] | Upgrade package
go-restful
to version 2.16. -
Resolved [CVE-2024-6345] | Upgraded package
setuptools
to version 70.0. -
Security | Upgraded
prometheus
to v2.55.0.
Release 24.07.30
October 30, 2024
-
Resolved [CVE-2020-26892] | Upgraded package
github.com/nats-io/jwt
to version 1.1.0 and packagegithub.com/nats-io/nats-server/v2
to version 2.1.9. -
Resolved [CVE-2023-39631] | Updated the
numexpr
package to 2.8.5. -
Resolved [CVE-2019-25211] | Updated the
cors
package to v1.6.0. -
Resolved [CVE-2023-5752] | Updated the
pip
package to 24.3.1. -
Resolved [CVE-2024-6345] | Updated
pip
setuptools
.
Release 24.07.29
October 24, 2024
-
Resolved [CVE-2024-8986] | Updated Grafana to version 11.3.0.
-
Resolved [[CVE-2024-7965]](https://nvd.nist.gov/vuln/detail/CVE-2024-7965| Updated the
google-chrome-stable
package to 129.0.6668.58-1.
Release 24.07.28
October 23, 2024
- For especially high volume, you can cap the maximum number of jobs logs buffered in RabbitMQ, to prevent RabbitMQ from running out of memory. To limit the queue length, set the desired value in the environment variable
RABBIT_MQ_JOB_LOGS_MAX_QUEUE_LENGTH
.
-
Resolved [CVE-2024-7965] | Upgraded
playwright
to 1.47.0 and validated the correct version of Chromium is installed. -
Resolved [CVE-2024-41110] | Upgraded package
github.com/docker/docker
to version 23.0.15,25.0.6,26.1.5,27.1.1 or later.
Release 24.07.27
October 22, 2024
-
You can update your previously trained and published models to use the latest version of
.ibformers
, providing improved inference and security. Upgrades are available for models that use.ibformers
2.0 or later and were trained in and published from ML Studio. -
You can now use uppercase letters in your username, service account names, and space names.
-
The redactor step in a flow failed if you tried to redact text using the
text_replace
property. -
Resolved [CVE-2023-7104] | The
github.com/mattn/go-sqlite3
package has been updated to version 1.14.18.
Release 24.07.26
October 16, 2024
This patch contains testing, optimizations, security, and minor internal changes. User functionality is unchanged.
Release 24.07.25
October 9, 2024
-
Production performance was improved in cases where the Instabase clusters were affected by poor performance by the Redis deployment.
-
Rarely, reading a 0-length file with the Text Editor failed.
Release 24.07.24
October 9, 2024
- Email attachments with the same name were overwritten. With this release, attachments are now indexed with a numeric suffix and are not overwritten.
Release 24.07.23
October 3, 2024
This release was a version bump and contained no changes.
Release 24.07.22
October 3, 2024
-
Empty list values were displayed incorrectly in human review.
-
Inline images in email files, such as embedded receipt images, rendered as blank and couldn’t be processed.
Release 24.07.21
September 26, 2024
-
Execution of flows with Reduce UDF steps in parallel branches encountered flow execution errors.
-
When uploading emails with attachments, some attachment filenames were not properly decoded.
Release 24.07.20
September 18, 2024
- An issue in an third-party library caused breakages in an internal LLM.
Release 24.07.19
September 13, 2024
This patch contains testing, optimizations, security, and minor internal changes. User functionality is unchanged.
Release 24.07.18
September 12, 2024
-
The tooltip for space and username input validation has been updated to clarify that only lowercase letters are allowed.
-
Some logs from model training did not show up in ML Studio.
Release 24.07.17
September 5, 2024
This patch contains testing, optimizations, security, and minor internal changes. User functionality is unchanged.
Release 24.07.16
September 4, 2024
-
The site setting Restricted file upload extensions now also prevents downloading files with the specified extension name or renaming a file to that name.
-
For flows with checkpoints following an STP checkpoint, input records were incorrectly tracked, resulting in missing documents.
-
SaaS only | This release enables case-sensitive comparison and lookup for records stored in the database, fixing multiple problems related to case sensitivity in document paths and the Flow Dashboard.
Release 24.07.15
August 30, 2024
-
Internal models that are no longer supported have been replaced by supported large language learning models (LLMs). This is an internal improvement and no action is required.
-
During human review, clicking on Mark document as reviewed did not move the focus to the next record.
Release 24.07.14
Generally available: August 20, 2024
New features
Platform
The PyTorch package in the model service has been upgraded from v1.7 to v2.3.
If you are using custom models that were not trained with the Instabase platform, and they are not compatible with PyTorch v2.3, you must update them to the new PyTorch version.
As part of this upgrade, the mmdet
package has been removed from the model service. Any models that are built using mmdet
no longer work and must be replaced with another model.
Solution Builder
- You can now make a Solution Builder project’s Resources directory accessible with custom code.
Enhancements
Platform
-
The model service prefetches models to local storage during startup, improving the performance of local model inference.
-
The interface for mounting drives has been improved:
-
You can update credentials based on the authentication type selected when mounting the drives.
-
For AWS drives, you can change the S3 access key and secret.
-
For Azure drives, you can rotate the service principal and connection string, depending on the original authentication method.
-
For Google Cloud Service, you can reupload the service account credentials.
-
-
This release upgrades an internal platform model with modest but consistent accuracy improvements in benchmarking.
-
Optimized the job service to improve flow execution speed when there is a burst load.
Solution Builder
- When running flows through the Solution Dashboard, you can configure step timeouts. To configure timeouts, adjust the Step timeout field in the Run a solution dialog. When set to default, the Instabase platform chooses an reasonable step timeout. Otherwise, select a timeout for your particular flow construction.
ML Studio
-
Text (multiple instances) fields, and list fields were introduced in public preview in 23.04 and are now generally available.
-
OCR text extraction and preprocessing of documents has been improved in ML Studio and the Reader app.
-
Provenance highlighting accuracy is improved when object detection is enabled.
Bug fixes
Platform
- In the interface for mounting drives, the AWS S3 Server-side encryption KMS key ID field now appears when SSE KMS is selected.
- SaaS only | This release enables case-sensitive comparison and lookup for records stored in the database, fixing multiple problems related to case sensitivity in document paths and the Flow Dashboard.
ML Studio
- Training speed for some models was degraded from an internal library upgrade in 24.04. This has been fixed.
Solution Builder
- Solution Builder projects with ampersand
(&)
characters in their names broke the ability to open model projects in ML Studio.
Flow
- When running a flow, the
out
folder in the selected output directory was not correctly cleaned up when thedelete_out_dir
was enabled.
Refiner
- An out-of-memory error sometimes occured when an internal Instabase model indexed Excel files.
Deprecations and removals
See the deprecations and removals page for the latest announcements, as well as previous deprecations and removals.
Deployment guide
- Workload autoscaling was introduced as a public preview feature in release 23.07 and remains in public preview. As a public preview feature, workload autoscaling is disabled by default. Workload autoscaling has several infrastructure requirements. For instructions on enabling workload autoscaling during your upgrade, see the workload autoscaling feature documentation.