Typebot - Package Updates
-
[1.22.2]
- Update typebot.io to 3.14.2
- Full Changelog
- Add confirm dialog before plan upgrade with existing customer 48cdd3b
-
[1.23.0]
- Update typebot.io to 3.15.0
- Full Changelog
- Add WhatsApp typing indicator [ea2a87d]
- Remove climate contribution messaging from billing and pricing pages [534588d]
- Allow s3 private URL access with PAT [62d3ba8]
- Autostart chat only if input has no information to display [883e282]
- Include session variables in http request sample body [6850b2a]
- Preserve empty lines when converting markdown to rich text [6ab7cbb]
- Fix typecheck lastActivityAt on schema [f29467d]
- Fix typing bubble animation transform value [1fb2ab3]
- Remove redundant error handling in getLastHourResults function [1baaf73]
- Fix grammar and clarity in README.md (#2324) [f50674c]
-
[1.23.1]
- Update typebot.io to 3.15.1
- Full Changelog
- Fix webhook listening not working [61b4987]
- Fix build fail react-emails [ae1a35c]
- Fix CI not sending email due to React not defined [d99a858]
-
[1.23.2]
- Update typebot.io to 3.15.2
- Full Changelog
- Fix app router automatically adding
transfer-encoding: chunkedheader to backend requests 69efa2f
-
[1.24.0]
- Update typebot.io to 3.16.0
- Full Changelog
- Introduce Spaces [1541877]
- Add prompt and new models to OpenAI transcription [03973f4]
- Add onboarding email workflow and unsubscribe flow [406ef51]
- Add new OpenAI and Anthropic models [d0d33d1]
- Move metadata to share page [75eaf4b]
- Improve IconPicker loading [a0be7a4]
- Make group title hitbox fit text [3611245]
- Ordered list insert buttons + safe placeholders [9e709d7]
- Improve image alt text accessibility [d0f7075]
- Fix dots icons, bolder [2e34c7c]
-
[1.24.1]
- Update typebot.io to 3.16.1
- Full Changelog
- baptisteArno/typebot.io (baptisteArno/typebot.io)
- Compare Source
-
P Package Updates locked this topic on
-
[1.25.0]
- Update typebot.io to 3.17.1
- Full Changelog
- Fix upload proxy public URL (#2508)
- Add Ask Model action using OpenAI Responses API (#2455)
- Add time filter to results export and fix CSV download on R2 (#2449)
- (openai) Add Ask Model file search controls (#2483)
- Handle GA script load failure to prevent bot from hanging (#2446)
- Fix transcript compute crash on choice items with session-var display condition (#2468)
- Fix credential access control and remove vulnerable S3 upload endpoint (#2459)
- Fix SSRF bypass via DNS rebinding in HTTP request and script fetch flows (#2461)
- Add SSRF_ALLOWED_HOSTS env for self-hosted internal APIs (#2474)
- Sanitize CSV exports against formula injection (#2493)
-
[1.25.1]
- Update typebot.io to 3.17.2
- Full Changelog
- Configure WhatsApp forwarded events (#2528) [c5516cd]
- Configure WhatsApp webhook forwarding URL (#2529) [3db24c4]
- Fix landing page Discord URL (#2512) [b4a7aab]
- Fix missing result columns in CSV export (#2513) [08cb6ea]
- Fix OpenAI audio transcription uploads (#2521) [2fd5510]
- Fix OpenAI chat completions endpoint (#2522) [b252a9c]
- Fix embedded audio uploads (#2523) [c82ac43]
- Ignore expected WhatsApp webhook errors (#2527) [3b321f4]
- Block IPv6 unspecified SSRF targets (#2511) [f56c3c3]
-
[1.26.0]
- Update typebot.io to 3.18.0
- Full Changelog
- Add camera capture options to file uploads (#2560) [512c988]
- Add a separator label for date range answers (#2573) [6e6b0b2]
- Fix stored WhatsApp phone lookup fallback (#2531) [f00ccba]
- Fix embed video overlay in preview (#2532) [9224f4f]
- Fix S3 operations without full config (#2533) [248f751]
- Fix WhatsApp audio file upload URLs (#2539) [54e1fa1]
- Fix Android camera for image extension uploads (#2558) [e7be877]
- Honor the DATABASE_URL schema parameter in the Prisma PostgreSQL adapter (#2582) [f9a57c4]
- Fix sidebar block drag on Android touch devices (#2569) [6796f58]
- Fix custom domain deletion ownership checks (#2541) [06575df]
-
[1.27.0]
- Update typebot.io to 3.19.0
- Full Changelog
- If you use Webhook blocks, you must now set
WEBHOOK_RELAY_SECRETto the same secret in builder, viewer and your PartyKit server. This also applies to Webhook blocks used in previews and WhatsApp flows. Missing or mismatched secrets prevent Webhook responses from resuming conversations. - The first URL in
NEXT_PUBLIC_VIEWER_URLmust use a different hostname fromNEXTAUTH_URL. Different ports on the same hostname are insufficient. Configure a separate viewer hostname before upgrading so builder previews remain available. - SMTP configuration tests now validate destinations and pin the connection to a validated IP address. Private SMTP servers require an exact hostname entry in
SSRF_ALLOWED_HOSTS; this instance-wide allowlist permits RFC1918 addresses only. Loopback, link-local and metadata endpoints remain blocked. - Resolve variables in Forge option arrays.
- Strengthen preview isolation, linked draft permissions and preview session creation.
- Restrict WhatsApp sessions to internal runtime access.
- Authenticate webhook responses and relay subscriptions, and enforce webhook ownership and write access.
- Protect SMTP configuration tests and special-use IP ranges against SSRF.
- Block external sign-in redirects and serialize concurrent email verification attempts.
- Restrict guest workspace access and prevent writes during read-only typebot migrations.
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login