PrefectHQ
prefect
Blog
Docs
Changelog
Blog
Docs
Changelog
Overview
Optimizations
Branches
Benchmarks
Runs
Performance History
Latest Results
Sync and retry submodule updates on every pull When submodules are enabled, an existing checkout pinned to a commit_sha now runs the submodule step on every pull, even when the commit is already checked out, so an update that failed on an earlier pull is retried. The step runs `git submodule sync --recursive` before `git submodule update --init --recursive` so URL changes in `.gitmodules` are picked up.
digit50:fix/git-storage-pinned-commit-checkout
55 minutes ago
Restore the worker environment after each process pool task `_run_task_in_subprocess` applied each submit's environment snapshot on top of the worker's existing environment, so a reused worker process kept variables set by earlier tasks. The worker environment is now restored after every task, so each task sees only its own snapshot.
digit50:fix/process-pool-runner-context-per-submit
1 hour ago
Update submodules when checking out a new commit_sha With `include_submodules=True`, an existing checkout that moves to a new `commit_sha` only ran `git checkout`, leaving submodule working trees at the previous pin. It now runs `git submodule update --init --recursive` after the checkout, matching the `--recurse-submodules` used by the clone and pull paths.
digit50:fix/git-storage-pinned-commit-checkout
3 hours ago
Restore the worker environment after each process pool task `_run_task_in_subprocess` applied each submit's environment snapshot on top of the worker's existing environment, so a reused worker process kept variables set by earlier tasks. The worker environment is now restored after every task, so each task sees only its own snapshot.
digit50:fix/process-pool-runner-context-per-submit
3 hours ago
Serialize context on every ProcessPoolTaskRunner submit ProcessPoolTaskRunner cached the serialized context and environment on the first submit and reused them for the rest of the runner's lifetime, so tags and settings entered around later submits never reached the subprocess. This drops the cache and computes both on each submit, as ThreadPoolTaskRunner effectively does. Closes #23371
digit50:fix/process-pool-runner-context-per-submit
4 hours ago
Check out a new commit_sha when the git checkout already exists `GitRepository.is_current_commit` compared `git rev-parse <commit_sha>` with the configured SHA and never read HEAD, so any full SHA counted as already checked out and `pull_code` skipped the fetch and checkout. It now resolves both HEAD and the configured commit in the destination and compares them, which also lets an abbreviated SHA of the current commit match. Closes #23370
digit50:fix/git-storage-pinned-commit-checkout
4 hours ago
fix(server): zero-trust proxy default, safe scan/auto-ban defaults, CORS outside guard Align the guard integration with the review findings landed on the sibling fastapi-guard PRs: - guard_trusted_proxies no longer falls back to RFC1918 ranges: Prefect servers are often reached from private-network peers, and trusting private-range proxies let any of them spoof X-Forwarded-For past the blocklist and rate limits. Operators behind a reverse proxy set guard_trusted_proxies to the proxy addresses. - attach_guard moves before the CORS middleware so the guard nests inside it (last-added is outermost): guard-generated 403/429 responses leave with CORS headers instead of opaque network failures for cross-origin clients. The CSRF and request-limit middlewares added after it also stay outside the guard. - detection_scan_body defaults off (flow runs and deployment manifests are data, not commands the server executes; URL, query, and header screening stays on) and enable_rate_limit_auto_ban defaults on (the advertised auto-ban behavior). Both fixed at the safe default for now instead of growing two more settings; knobs can follow on request. Tests pin the zero-trust default and both hardcoded defaults.
rennf93:feat/fastapi-guard-security-middleware
5 hours ago
Fix `prefect deploy` dropping list items templated from step outputs `apply_values(..., remove_notset=False)` kept unresolved dict values but silently dropped unresolved list items. `prefect deploy` applies environment variables to the whole deployment config with `remove_notset=False` before build steps run, so a list item such as `tags: ["{{ get-commit-hash.stdout }}"]` was removed before its step output was available. Keep the original list item when `remove_notset` is False, matching the dict behavior.
MohammadHijjawi97:fix-deploy-list-step-output-placeholders
5 hours ago
Latest Branches
CodSpeed Performance Gauge
0%
Check out a new commit_sha when the git checkout already exists
#23382
1 hour ago
75e5d3b
digit50:fix/git-storage-pinned-commit-checkout
CodSpeed Performance Gauge
0%
Serialize context on every ProcessPoolTaskRunner submit
#23383
1 hour ago
8ecdbd2
digit50:fix/process-pool-runner-context-per-submit
CodSpeed Performance Gauge
-1%
feat(server): Add optional fastapi-guard security middleware (default off)
#23379
5 hours ago
3d9c6ff
rennf93:feat/fastapi-guard-security-middleware
© 2026 CodSpeed Technology
Home
Terms
Privacy
Docs