v12.1.0
HumanAIGC/EMOv12.1.0Jul 1, 2026by github-actions[bot]
AI Summary
A major version update introducing significant security hardening, including a new hardened Docker image variant, new environment variables for owner management, and various bug fixes.
Key Highlights
- Introduced hardened Docker image and distroless variant (DHI)
- Added PROJECT_OWNER_ENABLED environment variable
- Replaced tooltip with Reka UI and added v-kbd component
- Updated bundled esbuild to 0.28.1 for security
Breaking Changes
- Limited sensitive system mutations defined by GRAPHQL_SINGLE_USE_MUTATIONS to single use
- Removed `/utils/hash/generate` and `/utils/hash/verify` endpoints
- Hardened upload path validation to prevent writes to extension and temporary storage directories
- Updated GraphQL WebSocket restrictions to match HTTP endpoint
- Added CORS_ORIGIN checks for websocket connections
New Features
- PROJECT_OWNER_ENABLED environment variable
- Reka UI tooltip replacement
- v-kbd component support
Full Release Notes
### ⚠️ Potential Breaking Changes
- **@directus/api**
- Limited sensitive system mutations defined by GRAPHQL_SINGLE_USE_MUTATIONS to single use ([#27801](https://github.com/directus/directus/pull/27801) by @br41nslug)
- Removed `/utils/hash/generate` and `/utils/hash/verify` endpoints ([#27774](https://github.com/directus/directus/pull/27774) by @br41nslug)
- Fixed failed TUS file replacements leaving orphaned file records. Hardened upload path validation to prevent writes to extension and temporary storage directories ([#27803](https://github.com/directus/directus/pull/27803) by @br41nslug)
- Updated GraphQL WebSocket restrictions to match the HTTP endpoint and hid validation hints when introspection is disabled ([#27801](https://github.com/directus/directus/pull/27801) by @br41nslug)
- Added CORS_ORIGIN checks for websocket connections ([#27812](https://github.com/directus/directus/pull/27812) by @br41nslug)
- **@directus/specs**
- Removed `/utils/hash/generate` and `/utils/hash/verify` endpoints ([#27774](https://github.com/directus/directus/pull/27774) by @br41nslug)
- **@directus/sdk**
- Removed `/utils/hash/generate` and `/utils/hash/verify` endpoints ([#27774](https://github.com/directus/directus/pull/27774) by @br41nslug)
- Hardened the published Docker image and added a distroless Docker Hardened Image (DHI) variant alongside it. The standard image now applies outstanding OS-level patches at build time and drops `npm`/`npx` from the runtime; the new DHI variant is published under a `-dhi` tag suffix ([#27670](https://github.com/directus/directus/pull/27670) by @br41nslug)
### ✨ New Features & Improvements
- **@directus/app**
- Added `PROJECT_OWNER_ENABLED` env var to allow disabling owner info collection and sync ([#27802](https://github.com/directus/directus/pull/27802) by @ComfortablyCoding)
- Replaced tooltip with Reka UI one ([#27029](https://github.com/directus/directus/pull/27029) by @HZooly)
- Added `v-kbd` component and support `{ text, kbd }` syntax in tooltip ([#27029](https://github.com/directus/directus/pull/27029) by @HZooly)
- Updated bundled `esbuild` to `0.28.1` (resolves GHSA-gv7w-rqvm-qjhr) ([#27738](https://github.com/directus/directus/pull/27738) by @br41nslug)
- **@directus/api**
- Added `PROJECT_OWNER_ENABLED` env var to allow disabling owner info collection and sync ([#27802](https://github.com/directus/directus/pull/27802) by @ComfortablyCoding)
- **@directus/env**
- Added `PROJECT_OWNER_ENABLED` env var to allow disabling owner info collection and sync ([#27802](https://github.com/directus/directus/pull/27802) by @ComfortablyCoding)
### 🐛 Bug Fixes & Optimizations
- **@directus/app**
- Restored pre-v12 back button behavior: returns to the previously visited item/page when navigating via a relation, and to the collection listing when landing on an item directly ([#27799](https://github.com/directus/directus/pull/27799) by @robluton)
- Fixed the public page foreground image rendering side-by-side with the shader background instead of overlaying it ([#27782](https://github.com/directus/directus/pull/27782) by @alvarosabu)
- Added clearable indicator to input hash field ([#27729](https://github.com/directus/directus/pull/27729) by @robluton)
- Added lazy loading of social icons on v-button ([#27724](https://github.com/directus/directus/pull/27724) by @alvarosabu)
- Bumped version of @directus/license package ([#27785](https://github.com/directus/directus/pull/27785) by @AlexGaillard)
- Fixed array indexing (e.g. `field[0]` or `field.0`) in display and preview URL templates, so a template like `{{ categories[0].name }}` now resolves to the indexed value instead of rendering empty ([#27773](https://github.com/directus/directus/pull/27773) by @dstockton)
- Fixed a stored XSS vulnerability where the project color could break out of the generated favicon's SVG markup and inject arbitrary HTML ([#27810](https://github.com/directus/directus/pull/27810) by @br41nslug)
- Fixed an internal server error when validating out-of-range integer values ([#27321](https://github.com/directus/directus/pull/27321) by @sourav-18)
- Added interface settings for collection status field ([#27781](https://github.com/directus/directus/pull/27781) by @robluton)
- **@directus/api**
- Bumped version of @directus/license package ([#27785](https://github.com/directus/directus/pull/27785) by @AlexGaillard)
- Fixed a Local File Inclusion vulnerability in `MailService.renderTemplate` ([#27811](https://github.com/directus/directus/pull/27811) by @br41nslug)
- Fixed Postgres value too long errors being misattributed to an unrelated field ([#27768](https://github.com/directus/directus/pull/27768) by @MahinAnowar)
- Added validation to restrict geometry types to known types ([#27809](https://github.com/directus/directus/pull/27809) by @br41nslug)
- Fixed batch update failures in the MCP files tool ([#27121](https://github.com/directus/directus/pull/27121) by @aayushbaluni)
- Updated dependencies to resolve security advisories and removed obsolete override pins ([#27814](https://github.com/directus/directus/pull/27814) by @br41nslug)
- Fixed accountability overrides in the graphql websocket ([#27813](https://github.com/directus/directus/pull/27813) by @br41nslug)
- Fixed MCP OAuth role resolution to use the users role instead of the root role ([#27790](https://github.com/directus/directus/pull/27790) by @ComfortablyCoding)
- Bumped hono and vite dependencies ([#27820](https://github.com/directus/directus/pull/27820) by @br41nslug)
- Fixed pre-validation side effects in services ([#27800](https://github.com/directus/directus/pull/27800) by @br41nslug)
- Fixed public websocket accountability handling ([#27808](https://github.com/directus/directus/pull/27808) by @br41nslug)
- **@directus/extensions-sdk**
- Updated bundled `esbuild` to `0.28.1` (resolves GHSA-gv7w-rqvm-qjhr) ([#27738](https://github.com/directus/directus/pull/27738) by @br41nslug)
- **@directus/system-data**
- Updated bundled `esbuild` to `0.28.1` (resolves GHSA-gv7w-rqvm-qjhr) ([#27738](https://github.com/directus/directus/pull/27738) by @br41nslug)
- Added interface settings for collection status field ([#27781](https://github.com/directus/directus/pull/27781) by @robluton)
- **@directus/composables**
- Updated bundled `esbuild` to `0.28.1` (resolves GHSA-gv7w-rqvm-qjhr) ([#27738](https://github.com/directus/directus/pull/27738) by @br41nslug)
- **@directus/validation**
- Fixed an internal server error when validating out-of-range integer values ([#27321](https://github.com/directus/directus/pull/27321) by @sourav-18)
- **@directus/env**
- Limited sensitive system mutations defined by GRAPHQL_SINGLE_USE_MUTATIONS to single use ([#27801](https://github.com/directus/directus/pull/27801) by @br41nslug)
- **@directus/utils**
- Classified the embedded IPv4 of IPv6 transition forms (IPv4-compatible, NAT64, 6to4) in `IpBlocklist.checkAddress` so they cannot bypass an IPv4 deny rule ([#27698](https://github.com/directus/directus/pull/27698) by @joeltco)
- License keys correctly validate, even when NODE_ENV=development
### 📦 Published Versions
- `@directus/app@16.2.0`
- `@directus/api@37.0.0`
- `@directus/composables@11.5.1`
- `create-directus-extension@12.1.1`
- `@directus/env@6.1.0`
- `@directus/extensions@4.0.1`
- `@directus/extensions-registry@4.0.1`
- `@directus/extensions-sdk@18.0.1`
- `@directus/memory@4.0.1`
- `@directus/pressure@4.0.1`
- `@directus/specs@15.0.0`
- `@directus/storage-driver-azure@13.0.1`
- `@directus/storage-driver-cloudinary@13.0.1`
- `@directus/storage-driver-gcs@13.0.1`
- `@directus/storage-driver-s3@13.0.1`
- `@directus/storage-driver-supabase@4.0.1`
- `@directus/system-data@4.5.1`
- `@directus/themes@2.0.1`
- `@directus/utils@13.5.1`
- `@directus/validation@3.0.1`
- `@directus/sdk@23.0.0`