Skip to main content
Version: 1.12.x

Langflow release notes

This page summarizes significant changes to Langflow in each release. For all changes, see the Changelog.

Due to strict SemVer requirements, Langflow Desktop can have different patch versions than the core Langflow OSS Python package, but the major and minor versions are aligned.

Prepare to upgrade​

warning

Whenever possible, the Langflow team recommends installing new Langflow versions in a new virtual environment or VM before upgrading your primary installation. This allows you to import flows from your existing installation and test them in the new version without disrupting your existing installation. In the event of breaking changes or bugs, your existing installation is preserved in a stable state.

To avoid the impact of potential breaking changes and test new versions, the Langflow team recommends the following upgrade process:

  1. Recommended: Export your projects to create backups of your flows:

    curl -X GET \
    "$LANGFLOW_SERVER_URL/api/v1/projects/download/$PROJECT_ID" \
    -H "accept: application/json" \
    -H "x-api-key: $LANGFLOW_API_KEY"

    To export flows from the visual editor, see Import and export flows.

  2. Install the new version:

    • Langflow OSS Python package: Install the new version in a new virtual environment. For instructions, see Install and run the Langflow OSS Python package.
    • Langflow Docker image: Run the new image in a separate container, or upgrade your existing image. For more information, see Upgrade the Langflow Docker image.
    • Langflow Desktop: To upgrade in place, open Langflow Desktop, and then click Upgrade Available in the Langflow header. If you want to isolate the new version, you must install Langflow Desktop on a separate physical or virtual machine, and then import your flows to the new installation.
  3. Import your flows to test them in the new version, upgrading components as needed.

    When upgrading components, you can use the Create backup flow before updating option if you didn't previously export your flows.

  4. If you installed the new version in isolation, upgrade your primary installation after testing the new version.

    If you made changes to your flows in the isolated installation, you might want to export and import those flows back to your upgraded primary installation so you don't have to repeat the component upgrade process.

1.12.x​

Highlights of this release include the following changes. For all changes, see the Changelog.

Breaking changes​

  • Connector security (1.12.4)

    Update the server or the database URL before you upgrade if the connection matches one of these cases.

    If PGVector connects to localhost or 127.0.0.1, add that host to LANGFLOW_SSRF_ALLOWED_HOSTS. For example, LANGFLOW_SSRF_ALLOWED_HOSTS=localhost,127.0.0.1. Do the same for a private or container hostname, such as postgres. A public hostname needs no entry. MongoDB and Couchbase SRV targets must be allowlisted by their own hostnames, or by a wildcard such as *.cluster.internal. For more information, see SSRF protection.

    If an SQL Database URL starts with mysql+mysqlconnector://, add allow_local_infile=false to the query string. If it starts with mariadb+mariadbconnector://, add local_infile=false. Use ? when the URL has no query string, and & when it already has one: mysql+mysqlconnector://user:password@db.example.com/app?allow_local_infile=false. On a trusted single-tenant server, LANGFLOW_RESTRICT_LOCAL_FILE_ACCESS=false keeps the previous URLs working and also lets flows read local server files. For more information, see component hardening.

    If the URL points at a TLS certificate or key on the server, copy the file into a directory only an administrator can change, set LANGFLOW_DATABASE_TLS_FILES_DIR to that directory, and point the URL at the new path. For example, set LANGFLOW_DATABASE_TLS_FILES_DIR=/etc/langflow/db-tls and use postgresql://user:password@db.example.com/app?sslrootcert=/etc/langflow/db-tls/ca.pem. PostgreSQL sslrootcert, sslcert, and sslkey, and MySQL or MariaDB ssl_ca, ssl_cert, and ssl_key, can use files in that directory. For more information, see component hardening.

  • Custom component input names (1.12.4)

    A custom component input name can no longer match a method name on Component or CustomComponent, or a method defined by the custom component class.

    Names that commonly collide include index, start, stop, run, log, validate, and variables. Components that previously ran without reading self.<name> will also fail to load.

    To fix the collision, rename the custom component's input name and update any connections that target it. The display name is not affected.

    For more information, see Inputs.

  • MCP stdio Node.js launch options (1.12.4)

    MCP stdio configurations can no longer place Node.js runtime options or inspect before a server script, even when LANGFLOW_MCP_SERVER_INTERPRETER_HARDENING is false.

    For example, node --no-warnings server.js must be changed to node server.js. Options intended for the server may still follow its script, such as node server.js --server-option.

    Shell wrappers also reject sh/bash glob and brace expansion, and cmd variable, caret, or double-quote syntax. Use an approved launcher directly with separate command and arguments for those payloads.

  • langflow-base is now the minimal install

    Langflow 1.12 makes langflow-base a complete, version-aligned installation of the Langflow application. Replace any langflow-base~=0.x pins with langflow-base~=1.12.0 pins.

  • Ongoing breaking change: bundle separation

    Bundle separation concludes in 1.12. uv pip install langflow no longer installs all provider bundles, and includes only a curated list of providers.

    Saved flows continue to operate as expected, and existing component class names remain compatible. If a required provider package is not installed, the component is visible in the visual editor, but the flow won't build or run until you install the package.

    Langflow displays an error that names the missing package, so you can install it. To install a package, such as Exa, run uv pip install lfx-exa in your virtual environment.

    For more information, see Additional bundles.

  • Admin Page removed

    Langflow OSS no longer includes an Admin Page. The /admin route, the account-menu Admin Page link, and the user-management page are gone. Superusers can no longer manage users or passwords in the visual editor.

    To manage users, use the Users API. /login/admin is still the admin sign-in endpoint and page.

    For more information, see Manage users as an administrator.

New features​

  • OpenTelemetry export

    Langflow can export health traces, metrics, and logs over OTLP to your own backend.

    For more information, see OpenTelemetry, New Relic, and Instana.

  • Python Interpreter microVM sandbox

    Set LANGFLOW_SANDBOX_BACKEND=exec-sandbox to run the Python Interpreter component in a dedicated QEMU microVM instead of in the Langflow server process. The microVM is not included in a default uv pip install langflow installation. To install it, run uv pip install 'langflow[sandbox]'.

    For more information, see Isolate executions in a microVM.

  • Production preflight checks

    Set LANGFLOW_DEPLOYMENT_PROFILE=prod to probe your Langflow deployment before any workers start. The default remains dev, which skips prod checks.

    For more information, see Production preflight checks.

  • Disable the legacy MCP SSE transport

    Set LANGFLOW_MCP_SSE_ENABLED=false to return a 404 from the legacy SSE transport endpoint. Streamable HTTP is not affected.

    For more information, see Disable the legacy MCP SSE transport.

  • OrcaRouter bundle

    The OrcaRouter bundle adds an OrcaRouter language model component.

    For more information, see OrcaRouter.

  • IBM Confluent bundle

    The IBM Confluent bundle adds Kafka, Tableflow, and Real-Time Context Engine components.

    For more information, see IBM Confluent.

  • Deployment tweak policy

    Set LANGFLOW_TWEAKS_POLICY to control which component fields an API caller can override at run time.

    For more information, see Restrict API tweaks.

  • Catalog and model policy APIs

    Superusers can block or allow components, starter templates, model providers, and specific models.

    For more information, see Catalog and model policy.

1.11.x​

For 1.11.x release notes, see the 1.11.x documentation.

1.10.x​

For 1.10.x release notes, see the 1.10.x documentation.

1.9.x​

For 1.9.x release notes, see the 1.9.x documentation.

1.8.x​

For 1.8.x release notes, see the 1.8.x documentation.

Earlier releases​

See the Changelog.

Was this page helpful?

Support
Search