WorkflowGen 10.3.1 strengthens file-upload and Node.js dependency security, expands the WorkflowGen MCP Server preview, introduces recurring action notification reminders, adds Windows Server 2022 Docker and Helm support, and includes targeted Portal, Administration, and PostgreSQL corrections.
Important
-
After upgrading, set
ApplicationDefaultFileUploadPdfSecurityProfiletoCompatibilityorStrictto enable PDF-specific validation.Off, missing, blank, or unknown values disable this protection. -
The Helm chart now defaults WorkflowGen Windows workloads to
ltsc2022. Existing Windows Server 2019 deployments must setwindows.ostoltsc2019before upgrading, and Windows container image versions must match their Windows nodes.
Security
-
Bug (#4636): Prevented process folder managers from retrieving delete-confirmation counts for processes outside their authorized folders.
-
Bug (#4646): Improved handling of stored file names displayed in the Administration process-data editor.
-
Update (#4738): Replaced vulnerable UUID dependencies in the Auth, GraphQL, Webhooks, and SCIM modules with the Node.js built-in secure UUID generator.
-
Update (#4776, #4791, #4805, #4815): Updated and pinned Node.js and MCP dependencies to address production security advisories affecting transitive packages, request parsing, and SAML processing.
-
Update: Updated the bundled and supported Node.js runtime to 22.23.2 LTS for the July 2026 security fixes.
-
Improvement (#4847, #4859): Added configurable active-content and structural validation for PDFs uploaded through WorkflowGen forms and corrected validation of malformed files, postback attachments, and same-name replacements. The default
Compatibilityprofile blocks detected active content and malformed PDFs while allowing encrypted PDFs, XFA, and object streams;Strictalso blocks those formats. API, remote-launch, and administration process-data uploads are unchanged.
Portal
-
Bug (#3945): Restored URL and email detection, icons, and styling in Dashboard and User Portal process-data list columns.
-
Bug (#4121): Kept saved standard-search view metadata and replacement behavior consistent with Advanced View.
-
Bug (#4466): Preserved the selected quick-search field and value after sorting, refreshing, paging, or switching result views.
-
Bug (#4651, #4827): Kept User Portal navigation available when request or action searches and launches return not-found or access-denied errors.
-
Bug (#4808): Restored user-profile setting saves from process form pages.
-
Bug (#4842): Restored bulk selection in the saved views list.
-
Bug (#4856): Restored automatic refresh for eligible dashboard saved-view popups and kept Advanced View result counts synchronized after refreshes.
-
Bug (#4868): Prevented long detected data links from expanding request and action follow-up pages beyond the viewport.
Administration
-
New Feature (#4606): Added recurring prior-overdue and overdue action email reminders with configurable start offsets, repeat intervals, and optional occurrence limits for SQL Server and PostgreSQL.
-
Improvement (#4635): Removed obsolete process multi-delete handling and revalidated deletion authorization against each process’s folder.
-
Improvement (#4708): Hardened SMTP OAuth token exchange handling and required secure HTTPS token endpoints.
-
Bug (#4711): Corrected HTML entity decoding in SMTP OAuth plain-text email fallbacks.
-
Bug (#4765): Fixed PostgreSQL failures when changing process-data storage methods.
-
Bug (#4802): Fixed recipient selection and layout behavior when editing additional process notifications.
-
Bug (#4848): Improved Global Lists editor icon visibility in dark theme.
-
Bug (#4851): Preserved Global Lists row values when reordering a row while another field is focused.
-
Bug (#4862): Fixed Quick Approval configuration saves on PostgreSQL without requiring database cleanup.
-
Bug: Corrected process time-limit duration persistence when saving a process definition.
WorkflowGen MCP Server Preview
-
New Feature (#4706, #4732): Expanded discovery tools and added process XPDL import and export with inline or signed resource delivery.
-
Security (#4709): Strengthened OAuth security for the WorkflowGen MCP Server Preview.
-
Improvement (#4713): Made the SQL Server MCP database update transactional.
-
Bug (#4718, #4720, #4721): Corrected OAuth resource metadata, favorite identity resolution, and application-root OAuth routing.
-
Improvement (#4772): Improved Global List pagination performance for large environments.
-
Improvement (#4773): Added clearer diagnostics for in-memory and development OAuth configurations.
-
Update (#4774): Hardened artifact download names, signed resource URLs, and staged-file cleanup.
-
New Feature (#4784): Added JSON-native MCP import and export for applications and Global Lists, including large-artifact upload and signed resource support.
-
Security: Updated WorkflowGen MCP Server dependencies to address known security vulnerabilities.
-
Bug: Fixed MCP file imports when allowed folders are configured using relative paths.
Docker And Kubernetes
-
New Feature (#4742): Added WorkflowGen v10 Windows Server 2022 Docker image build, test, and publication support while retaining Windows Server 2019 images.
-
New Feature (#4744): Added Helm
windows.osand shared Windows node-selector configuration, defaulting new deployments toltsc2022.
Notes
-
Node.js modules are
GraphQL v5.4.4,Webhooks v6.3.4,Auth v3.3.5,SCIM v3.3.4, andMCP v0.1.1. All WorkflowGen Node.js applications require Node.js 22.23.2 LTS. -
The WorkflowGen MCP Server remains in Preview.
-
SQL Server 2025 and PostgreSQL 17.6 update scripts include the recurring-notification database changes.
-
For background on the WorkflowGen MCP Server preview, SMTP OAuth 2.0, and earlier 10.3 changes, refer to the WorkflowGen 10.3.0 Preview release notes.
Installation Packs
For PostgreSQL 17.6 and SQL Server 2025
WorkflowGen 10.3.1 (Upgrade)
WorkflowGen 10.3.1 (Clean Install - Manual)
For SQL Server 2025 only
WorkflowGen 10.3.1 (Clean Install - PowerShell)
Documentation
WorkflowGen 10.3.1 Upgrade Guide: English - Français
WorkflowGen 10.3 Manual Installation Guide: English - Français
WorkflowGen 10.3 PowerShell Installation: English - Français
WorkflowGen 10.3 Technical Guide: English - Français
WorkflowGen 10.3 Administration Guide: English - Français
WorkflowGen 10.3 User Portal Guide: English - Français
WorkflowGen 10.3 Integration Guide: English
WorkflowGen 10.3 for Azure: English - Français
WorkflowGen 10.x for Docker: English - Français
WorkflowGen Documentation: English - Français