TopLogic - the automated application engine
  • Releases
  • Dokumentation
  • Github
  • Discord
  1. Home
  2. Releases
  3. TL_8.0.0-alpha7
  4. #29407

8.0.0-alpha7
TopLogic Release

2026-07-30

enhancement

critical
#29088
Model-based access rights
#29108
Lightweight UI definition layer (TL Views) based on React UI components
major
#28694
Description of model parts as formatted text (rich text)
#28708
Enable Standard Selection in (Tree) Tables and Grids via TL Script
#29102
Add com.top_logic.layout.react module for React/SSE integration
#29221
Automatic determination of possible authorization configurations
#29349
XML Parsing Functions for TL-Script via XMLImporter
#29374
TL Script: gzip()
#29389
Code Completion for Variables ($) in the TL Script Editor
#29396
Conversation display for TL Views: object list element, file chips, card panels
#29399
Info Service Notifications: Display at the bottom instead of the top, and keep them in place when hovering over them with the mouse
#29400
Introduce a first-class "operation mode" service for applications (OperationMode enum + ApplicationModeService)
minor
#29085
Re-login on session timeout instead of redirect to login page
#29089
Extend the TL Script functions log() and info() to include selectable message levels (INFO, WARN, ERROR)
#29195
Problems with HTML attributes and TL script
#29306
TL Script: dateFormat() should accept an explicit timezone to format Calendar values losslessly
#29382
Expose a public, classpath-driven overload of `Workspace.getAppPaths`
#29385
The app archetype should automatically generate a standard git-ignored local-credentials overlay (tl_config) by default
#29392
Transaction Abort on Non-2xx Response
#29398
Login Form: Use "Username" Instead of "Name"

defect

major
#29383
A dead SOCKET_APPENDER (Chainsaw, localhost:4445) in the default logging configuration can cause logging to stall and operations to abort under heavy load
#29384
The TL-Script functions `resetSequence` and `generateSequenceId` generate a different sequence ID than `SequenceDefaultProvider` (in terms of suffix and context order), so they cannot reset a provider-managed sequence with a dynamic context
#29394
Editable tables in the React UI: Generalized row-set bindings for tabular editing in forms
#29410
Attribut filename der Structured-Text-Bildablage case-sensitive (binär) speichern
#29419
Understandable save failures and form validation feedback in the React view layer
minor
#28816
Reference value attributes only generate errors with SingleSelection
#29359
Inappropriate tooltips on some main tabs
#29360
Occasional error message in the log: "mainLayout" is null.
#29361
Invalid database definition for tag
#29363
Missing validation of dialogs in GOTO statements to dialogs of invisible parents
#29380
Context-sensitive auto-numbering fails if the context and the numbered object are created within a single transaction
#29381
Double-clicking in a graphic component does not work reliably
#29390
Subtree selection ends too early if the lowest level is not included in the level filter
#29393
URL routing in the React view layer is broken: ForwardingReactContext does not delegate getRouteManager()
#29401
Images in an image drop zone cannot be copied or saved using the browser's context menu
#29402
Tree selection is lost when the view is refreshed (invalidated)
#29412
Flaky TestDynamicComponentService.testIncrementalUpdates: asserts on asynchronous WatchService event after a fixed 10ms sleep
#29416
Anzeige des Änderungslogs schlägt fehl, wenn parallel Änderungen committet werden
#29420
FlowDiagram: Fehlerfall im row-wise Sub-Grid: subGridCols=2 und subGridStartCol=1
#29426
FlowDiagram: Text in PDF-eingebettetem Diagramm ist nicht selektierbar

task

major
#29407
Security-Scan: npm-Abhängigkeiten der React-Module aktualisieren
#29408
Security-Scan: httpcore5 anheben; pdfbox-/azure-Findings bewerten
minor
#29415
Slim down the repository CLAUDE.md and consolidate developer guidance into skills and FAQ articles
task

major

#29407

Security-Scan: npm-Abhängigkeiten der React-Module aktualisieren

DependencyUpdate

Ein Security-Scan (Juli 2026) meldet mehrere verwundbare npm-Pakete in den package-lock.json der React-Module. Für alle existiert eine Fix-Version; das Update erfolgt durch Regenerieren der Lockfiles bzw. overrides-Einträge in der jeweiligen package.json.

Zu behebende Pakete

= Paket = = aktuell = = CVE / GHSA = = Fix-Version = = Art =
vite 6.4.1 / 6.4.2 CVE-2026-39363, -39365, -53571, -53632; GHSA-4w7w-66w2-5vf9, -p9ff-h696-f583, -fx2h-pf6j-xcff, -v6wh-96g9-6wx3 6.4.3 (deckt alle ab) Build/Dev
picomatch 4.0.3 CVE-2026-33671, -33672; GHSA-c2c7-rcm5-vvqj, -3v7f-55p6-f55p 4.0.4 Build (transitiv)
postcss 8.5.6 / 8.5.8 CVE-2026-41305; GHSA-qx2v-qp2m-jg93 8.5.10 Build (transitiv)
@babel/core 7.29.0 GHSA-4x5r-pxfx-6jf8 (CVE-2026-49356) 7.29.6 Build (transitiv)
markdown-it 14.1.1 CVE-2026-48988; GHSA-6v5v-wf23-fmfq 14.2.0 Laufzeit (WYSIWYG, transitiv)
linkify-it 5.0.0 CVE-2026-48801 (Fix 5.0.1), CVE-2026-59887 + GHSA-22p9-wv53-3rq4 (Fix 5.0.2) 5.0.2 Laufzeit (WYSIWYG, transitiv)

Betroffene Module

vite, picomatch, postcss, @babel/core liegen in den Lockfiles von:

  • com.top_logic.layout.react
  • com.top_logic.layout.react.codeedit
  • com.top_logic.layout.react.chartjs
  • com.top_logic.layout.react.wysiwyg
  • com.top_logic.model.search.react
  • com.top_logic.react.flow.server
  • com.top_logic.demo

markdown-it/`linkify-it` nur in com.top_logic.layout.react.wysiwyg.

Risikoeinordnung

vite/`postcss`/`picomatch`/`@babel/core` sind reine Build-/Dev-Abhängigkeiten (wirken nur auf Build-Rechner bzw. Dev-Server, nicht in der ausgelieferten Anwendung) — geringes Risiko, aber sauber zu schließen. markdown-it/`linkify-it` sind laufzeitrelevant (WYSIWYG-Editor, verarbeiten ggf. Nutzereingaben; ReDoS/quadratische Komplexität) — höhere Priorität.

Vorgehen

vite ist als ^6.0.0 deklariert, daher genügt ein Regenerieren der Lockfiles für 6.4.3. Für die transitiven Pakete overrides in der jeweiligen package.json setzen. Der JS/TS-Build läuft über das frontend-maven-plugin während mvn compile.

  • Get Started
  • Github
  • Discord
  • Das Unternehmen hinter TopLogic
  • Softwareentwicklung heute
  • Kontakt

© Copyright – Business Operation Systems GmbH

  • top-logic.com
  • Nutzungsbedingungen
  • Impressum
  • Rechtlicher Hinweis
  • Datenschutz
  • DE
  • Login