Circuit Breaker v0.4.2 — Release Notes
Target release: upcoming 0.4.2 cut
Previous release: v0.4.0
Branch: dev
Highlights
v0.4.2 is a reliability and trust release. Two navigation entries that had never delivered on their promise now do: Intelligence opens on a fleet vulnerability console, and Monitors gains the alert-rule surface its engine had been running without. Around that, the release tightens the topology and map experience, makes vulnerability and impact reporting more accurate, keeps air-gapped installs from making outbound requests, and hardens agent lifecycle and connection handling so uninstall and revoke flows behave the way operators expect.
What changed in v0.4.2
Fleet Intelligence and Alerting
Two pages that previously promised more than they delivered are now complete.
- The Intelligence page opens on a Vulnerabilities tab: a fleet-wide vulnerability console with one assessment state per hardware item, compute unit, and service. Fleet counts keep readiness apart from findings — an entity that cannot be assessed is counted as Needs identity and never folded into a number that could read as clean. Rows expand to the same findings and evidence the entity’s own panel shows, and every degraded state (no feed, stale feed, capped pass, air-gapped install) renders as itself rather than as an all-clear.
- An entity reported as Needs identity can be corrected without leaving the fleet view. The identity drawer opens from the row, accepts whatever you type, keeps your entered values if a save fails, and refreshes the fleet on success.
- The capacity and right-sizing content that used to be the whole Intelligence page moves to an Operations tab, which also surfaces flapping assets for the first time — flap detection had been recording incidents on every analytics pass that no page ever read. A capacity forecast projected to saturate inside its warning threshold is now visibly distinguished.
- The Monitors page becomes a two-tab shell with an Alert rules tab. The metric alerting engine shipped complete but unreachable — no page could create a rule, show one, or report one firing. You can now list, create, edit and delete rules, preview a prospective rule against samples already collected before switching it on, and see the six assessments the evaluator actually decides rather than a flattened OK/Alerting.
- A rule that is not evaluating now says why — whether the host has never reported that metric, has stopped reporting recently, or reports with gaps too wide to measure a breach across. Those are three different problems with three different fixes, and they previously all surfaced as one word.
Topology, Impact, and Security Signals
The biggest user-facing improvements are in the network views that help operators understand what is exposed and why.
- The vulnerability panel on hardware, compute, and service detail pages no longer shows a misleading “No known vulnerabilities” result when the assessment is incomplete or stale. It now reflects the actual assessment state and explains whether the findings came from a complete, partial, or stale feed.
- The Impact panel is now easier to interpret: it explains what is being counted, distinguishes true dependency impact from physical/network connectivity, and clearly shows when a traversal stopped because of a limit instead of implying there is no impact.
- Asset relationships are better labelled and more transparent, especially when a graph is inferred rather than directly observed.
These changes make it easier to trust the data when evaluating risk and service exposure.
Map and Topology Stability
Map and graph handling received several fixes that make the interface behave consistently instead of silently ignoring changes.
- Sigma map rendering previously produced an empty map because it sent a payload format the backend did not support. That was corrected.
- Map node deletion was restored after a bad lookup prevented remove actions from working.
- Tag and hardware-role filters now compose correctly instead of one overwriting the other.
- Slow topology responses no longer overwrite newer map state with stale nodes and edges.
- Cloud View and map topology refreshes no longer race each other and cause duplicate transformations.
- Sigma map data is now scoped to the correct active map and include tokens rather than pulling unrelated map entities into the view.
- Saved map layouts are now versioned and readable across older and newer frontend/server combinations, reducing upgrade or rollback surprises.
In practice, this means map views stay correct and predictable during refreshes, filter changes, and partially upgraded deployments.
Air-Gap Friendly Deployment Behavior
Circuit Breaker is designed to work well in self-hosted, offline, and restricted environments, and v0.4.2 keeps that promise.
- The UI no longer loads web fonts from Google Fonts. All font families are now self-hosted, so a
CB_AIRGAP=truedeployment no longer triggers outbound font requests. - This release also tightens resource and layout compatibility behaviors for mixed-version deployments and self-hosted rollbacks.
Agent Deployment and Connection Resilience
This release includes a focused set of fixes for agent lifecycle and connection handling, especially around uninstall and revoke behavior.
- Agents that remove themselves with
cb-agent uninstallnow show a clear Uninstalled state rather than a misleading Revoked state. - The uninstall flow now waits for the server acknowledgement, reports failures honestly, and exits non-zero when the server never confirms delivery.
- The
/linkstream now flushes the delivery acknowledgement before dropping the connection, preventing false “completed uninstall” states. - Agent-initiated revokes now cancel in-flight discovery work and push the status change to open fleet views, matching the behavior of operator-initiated revokes.
- PEER disconnects during the hello exchange are now handled as ordinary disconnects rather than raising unhandled ASGI exceptions.
This makes deployment and fleet operations far more resilient when agents disconnect, reinstall, or are intentionally removed.
Readability and Accessibility
- Secondary text is legible in every theme. Across the shipped presets, 20 of 28 preset/mode pairs put muted text below the WCAG AA contrast threshold against the surface behind it. Both text tokens are now floored to AA against every surface they can land on, blending only as far as the threshold requires — a colour that already passed is left untouched, so palettes keep their hue wherever the hue was readable.
- The navigator’s search field no longer draws a permanent focus ring that read as a border.
- The Alert rules tab’s “no notification destination” banner now links to the page that actually creates one, instead of naming a Settings tab that does not exist.
Release Hygiene and Versioning
scripts/check_version_parity.pygained a--writemode.make version-syncnow updates the registered version files in one step instead of relying on manual matching.- The version metadata was aligned to the 0.4.2 release line in the project tracking files.
Dependency Security
anyiomoves to 4.14.2, the fixed release for CVE-2026-63374 (TLS certificate spoofing via IDNA 2003 host-name encoding) and CVE-2026-64847. The vulnerable version was pinned in the generated requirements every shipped image installs from.- The backend’s three dependency files —
pyproject.toml,poetry.lockand the generatedrequirements.txt— are now checked against each other on every build, so a security floor raised in one can no longer leave the shipped containers on the old pin.
Upgrade Notes
- No special migration steps are required for standard upgrades. Migration
0116_metric_alert_reason_coderuns automatically; the column is nullable with no backfill, so an alert rule the evaluator has not reached since the upgrade reads “has not been evaluated yet” rather than borrowing an explanation it was never given. The scheduled evaluator fills each rule in on its next pass. - Layout compatibility is improved for mixed-version frontend/server setups and rollback scenarios.
- If you operate in an air-gapped environment, this release is safer to deploy because it avoids external font loading.
- Any configuration that depends on map or topology state should be reviewed once after upgrade to confirm the new assumptions and filters behave as expected.
Recommended Next Steps After Upgrade
- Open the topology and map views and confirm filters and delete actions behave as expected.
- Open Intelligence and confirm the fleet vulnerability counts look right, then check that anything reported as Needs identity can be corrected from the row.
- Open Monitors → Alert rules, create one rule against a metric you already collect, and use the preview to confirm it would fire the way you expect before enabling it.
- Review the vulnerability and impact panels for a few test devices or services to check that impact and assessment state are now explained clearly.
- If you manage deployed agents, verify uninstall and revoke flows in a low-risk environment and confirm the fleet view reflects the correct state.
- If your deployment is air-gapped or heavily restricted, verify that no external font or browser dependency is being requested.
Summary
v0.4.2 is a focused quality and reliability release: it finishes two pages that had been advertising capability they did not yet deliver, makes the user experience less misleading, fixes several map and topology regressions, strengthens agent connection handling, and improves safety for offline/self-hosted deployments. It is a practical upgrade for anyone running Circuit Breaker in a real environment where observability, reliability, and operational clarity matter.
