1.0.2
A security release — dependency updates that fix published vulnerabilities, WebAdmin security fixes, and a new production-hardening guide. Ships ASEE Flow Platform 1.0.2 with WebAdmin 1.0.2: from this release on, the platform and WebAdmin share one version. It is a drop-in update from 1.0.1: no API, process-model, or database-schema changes. The supported environments are those 1.0.1 shipped with, now written down per server version: Java 17 and 21, Tomcat 10.1 and WildFly 39.Platform
Each update moves to the newest patch of the same line, except the PostgreSQL driver, whose fix exists only on the 42.7 line.- Run and the Spring Boot starter now use the platform’s Jackson and Tomcat versions. They import Spring Boot’s version list, which used to override the platform’s choice; the platform’s versions now win.
- Docker images are rebuilt on the current Alpine 3.22 base, with OpenSSL 3.5.8 (CVE-2026-14456, high) and OpenJDK 17.0.19.
- ASEE Flow Run checks the JDK. Its start scripts now stop on a JDK above 21 with a clear message, instead of failing later in the bundled JavaScript engine — see Supported Environments.
- The Engine REST WAR can check a token’s audience. With single sign-on on Tomcat and WildFly, the new setting
org.camunda.bpm.engine.rest.security.oauth2.audienceslimits the REST API to tokens issued for it. Without it, the REST API accepts any valid token of its realm, as before — see Production hardening.
WebAdmin 1.0.2
- Spring Boot 3.5.16 and Jackson 2.21.7. WebAdmin 0.8.7 was built on Spring Boot 3.5.11; its Spring stack accounted for most critical findings in the Tomcat and WildFly images.
- UI dependencies. React Router 8.3.1 (GHSA-qwww-vcr4-c8h2) and axios 1.20.0 (twelve advisories published 2026-09-30); the API clients were regenerated with Orval 8.
formis the default login mode. Withoutaseeflow.webadmin.authentication, WebAdmin used to load no security of its own; it now uses form login.- Programs can call the REST API in
formmode. Where WebAdmin serves the engine REST API — Run and your own Spring Boot application — its REST chain accepts HTTP Basic as well as the login session, without opening the browser’s login dialog. - First administrator under form login. Camunda Admin’s first-user setup page is reachable while WebAdmin’s form login is active, so an empty user database can get its first administrator.
- Logout. Single sign-on logout in
oauth2mode now ends the Keycloak session. In the WAR, logout inbasicmode no longer answers404, and the logout redirect keeps the WAR’s context path. - No reload loop. When the engine REST API refuses a signed-in user, WebAdmin no longer reloads the page endlessly.
- Engine REST proxy passes errors on. Through WebAdmin’s proxy, the engine’s
400,403and404answers now reach the UI with their messages instead of a bare500. - Redeploying WebAdmin keeps the server’s engine running. On Tomcat and WildFly, undeploying or redeploying the WebAdmin WAR no longer closes the server’s shared process engine.
- Single sign-on through the proxy keeps working. In
oauth2mode, WebAdmin’s proxy now renews the user’s access token when it expires; before, every data call failed once it did — five minutes after login with Keycloak’s defaults. Each browser session keeps its own tokens, and when the identity provider ends the user’s session, WebAdmin sends the user to the login.
What you need to do
- Protect the engine REST API on Tomcat and WildFly. As in Camunda 7, the Engine REST WAR ships without authentication. Follow the production-hardening guide, which also covers Run, the demo users, and server settings.
- In your own Spring Boot application, the platform’s library versions don’t apply:
aseeflow-bommanages only ASEE Flow’s own artifacts. Override them yourself — Jackson 2.21.7 or later (jackson-bom.version) and embedded Tomcat 10.1.58 or later (tomcat.version). - On your own Tomcat or WildFly server, update the server, the JDBC driver and the JDK yourself.
Known issues
- WildFly 39.0.1’s own modules — Netty, Bouncy Castle, Artemis, CXF, Kafka and WildFly’s own Jackson 2.20.1 — carry known vulnerabilities (5 critical and 34 high in a scan of the 1.0.2 distribution). Most are not reachable with the shipped
standalone.xml. Only a newer WildFly fixes them; WildFly 41 is planned for ASEE Flow 2.0. - The javax variants — the WildFly 26 modules and subsystem, the javax web application, and Spring 5.3 (
engine-spring) — ship as in 1.0.1. No security fixes are possible for them; they are removed in ASEE Flow 2.0. - Spring Framework 6.2 and Spring Boot 3.5 are out of free support since 2026-06-30. A new advisory in them may not be fixable by a version update on the 1.x line.
1.0.1 — 2026-07-14
A maintenance release — dependency refreshes, WebAdmin UI and security updates, and a WildFly packaging fix. Ships ASEE Flow Platform 1.0.1 with WebAdmin 0.8.7. It is a drop-in update from 1.0.0: no API, process-model, or database-schema changes.Platform
- Dependency refresh. Third-party dependencies were updated within their compatible version lines — most notably Spring Boot
3.5.16, the final open-source patch of the Spring Boot 3.5 line (OSS support ended 2026-06-30), plus anhttpcore5alignment. - WildFly distribution. Fixed the
joda-timeand UUID-generator module descriptors to use version-tokenized module names, so they resolve correctly. - ASEE Flow Run. Added QA coverage asserting Run’s secure-by-default contract — the engine REST API stays protected out of the box.
- License Book. The bundled License Book now reports release versions (the
-SNAPSHOTqualifier was dropped).
WebAdmin 0.8.7
- UI toolchain modernization. Updated the front end to current majors — Vite 8, React Router 8, and TypeScript 6 — with the accompanying Ant Design and React-hooks lint fixes.
- Security. Resolved high-severity dependency-audit findings (including pinning a patched
lodash). - Pinned to ASEE Flow Platform 1.0.1.
1.0.0 — 2026-07-07
The first release of ASEE Flow. ASEE Flow 1.0 is based on Camunda Platform 7.24 and is source-compatible with it: the Java packages (org.camunda.bpm.*), the public API, and your BPMN 2.0, DMN 1.3, and CMMN 1.1 models
all keep working unchanged, and no database schema migration is required.
Moving from Camunda Platform 7.24 is a matter of switching the distribution and updating your Maven coordinates
— see Upgrade from Camunda 7.24.
Highlights
- Rebranded Maven coordinates. Dependencies move from the
org.camunda.bpmgroups toorg.aseeflow.bpm(withaseeflow-*artifact IDs). The Java package imports (org.camunda.bpm.*) are unchanged, so your existing code, process models, and configuration keep working — you update your build coordinates, not your code. - WebAdmin administrative UI. ASEE Flow ships WebAdmin as its administrative client — a modern replacement for the legacy web applications, with configurable authentication (Basic, Form, OAuth2, Keycloak) and REST security enabled by default.
- Commercial licensing. ASEE Flow is distributed under the ASEE Flow Commercial License (ASEE Software Solutions). Camunda-derived components remain under the Apache License 2.0, and bundled third-party libraries keep their own licenses — see the Licenses page and the License Book.
Compatibility
- Built on Camunda Platform 7.24; BPMN 2.0, CMMN 1.1, and DMN 1.3 support is unchanged.
- Source-compatible: the
org.camunda.bpm.*packages and public API are retained. - No database schema migration is required when moving from Camunda Platform 7.24.
- See supported environments for the certified JDK, application server, and database versions.