Skip to main content
Version: v3.1.x LTS

Version 2.18.1 (March 2025)

Version 2.18.1 (March 2025)

Welcome to the Zowe Version 2.18.1 release!

See Bug fixes for a list of issues addressed in this release.

Download v2.18.1 build: Want to try new features as soon as possible? You can download the v2.18.1 build from Zowe.org.

New features and enhancements

Zowe Version 2.18.1 contains the enhancements that are described in the following topics.

Zowe API Mediation Layer

  • The Zowe client AT-TLS setting network.tls.client.attls is now supported. (#3825)

Bug fixes

Zowe Version 2.18.1 contains the bug fixes that are described in the following topics.

Zowe API Mediation Layer

  • Fixed login filter check causing 400 Invalid credentials. (#4014)
  • Added missing OIDC documentation to OpenAPI. (#4013)
  • Added newPassword to Open API Documentation of the login endpoint. (#4002)
  • Fixed four slashes support in SSE class. (#4001)
  • Fixed failing LoginFilter in AccessToken generate filter chain. (#3984)
  • Fixed the ssl.protocol default value. (#3994)
  • Improved PassTicket logging. (#3996)
  • Fixed 'exampleSetFlag' leaking in api doc. (#3934)
  • Fixed Cloud Gateway configuration. (#3956)
  • Fixed initialization of the API Catalog. (#3959)
  • Improved error handling in case of failure when retrieving API doc. (#3936)
  • Improved untrusted certificate message when certificate is not forwarded. (#3926)
  • User can now configure the TLS version and cipher suite list. (#3943)
  • Fixed order of Cloud Gateway filters and solve the conflict with RequestAttributesProvider. (#3965)
  • Fixed z/OSMF static definition file processing. (#3975)
  • Removed global setup of keystores. (#3702)
  • Fixed Sonar analysis issues. (#3800)
  • Changed port to handle AT-TLS client aware mode. (#3863)
  • Updated default javax.net.ssl log level. (#3872)
  • The insecureHttpWarning message is now thrown only when AT-TLS is not enabled. (#3810)
  • Fixed WebSocket session opening to be non-blocking and callback-based. (#3695)
  • Fixed Zowe CLI plugin and enable manual trigger only. (#3804)

Zowe CLI

Zowe CLI (Core)

  • Added support for the --encoding flag to the zowe upload dir-to-uss command to allow for encoding uploaded directories for command group consistency. (#2356)

Zowe CLI Imperative Framework

  • Updated transitive dependencies for technical currency. (#2425)
  • Resolved an issue where extraneous base profiles were created in project configurations when a nested profile property was updated. (#2404)
  • Fixed an issue where the ProfileInfo.profileManagerWillLoad method failed if profiles were not yet read from disk. (#2284)
  • Fixed an issue where the ProfileInfo.updateKnownProperty method could rewrite the team configuration file to disk without any changes when storing a secure value. (#2324)
  • Updated the cross-spawn dependency for technical currency. (#2374)
  • Fixed issues flagged by Coverity. (#2292)
  • Updated dataobject-parser dependency for technical currency. (#2262)
  • Updated fs-extra and jsonfile dependencies for technical currency. (#2264)

CICS Plug-in for Zowe CLI

  • Removed bundled dependencies from npm package and restored the npm-shrinkwrap file. (#188)

DB2 Plug-in for Zowe CLI

  • Updated ibm_db dependency to support Node.js 22 on Windows.

Zowe Explorer

Zowe Explorer (Core)

  • See the Zowe Explorer changelog for updates included in this release.

Zowe Explorer API

Zowe Explorer FTP Extension

Zowe Explorer ESLint Plug-in

Vulnerabilities fixed

Zowe discloses fixed vulnerabilities in a timely manner giving you sufficient time to plan your upgrades. Zowe does not disclose the vulnerabilities fixed in the latest release as we respect the need for at least 45 days to decide when and how you upgrade Zowe. When a new release is published, Zowe publishes the vulnerabilities fixed in the previous release. For more information about the Zowe security policy, see the Security page on the Zowe website.

The following security issues were fixed by the Zowe security group in version 2.18.0.

  • BDSA-2024-4117
  • BDSA-2024-3717
  • BDSA-2024-0402
  • BDSA-2024-0625
  • BDSA-2024-1160