Version 2.18.1 (March 2025)
Version 2.18.1 (March 2025)
Welcome to the Zowe Version 2.18.1 release!
See Bug fixes for a list of issues addressed in this release.
Download v2.18.1 build: Want to try new features as soon as possible? You can download the v2.18.1 build from Zowe.org.
New features and enhancements
Zowe Version 2.18.1 contains the enhancements that are described in the following topics.
Zowe API Mediation Layer
- The Zowe client AT-TLS setting
network.tls.client.attls
is now supported. (#3825)
Bug fixes
Zowe Version 2.18.1 contains the bug fixes that are described in the following topics.
Zowe API Mediation Layer
- Fixed login filter check causing 400 Invalid credentials. (#4014)
- Added missing OIDC documentation to OpenAPI. (#4013)
- Added newPassword to Open API Documentation of the login endpoint. (#4002)
- Fixed four slashes support in SSE class. (#4001)
- Fixed failing LoginFilter in AccessToken generate filter chain. (#3984)
- Fixed the ssl.protocol default value. (#3994)
- Improved PassTicket logging. (#3996)
- Fixed 'exampleSetFlag' leaking in api doc. (#3934)
- Fixed Cloud Gateway configuration. (#3956)
- Fixed initialization of the API Catalog. (#3959)
- Improved error handling in case of failure when retrieving API doc. (#3936)
- Improved untrusted certificate message when certificate is not forwarded. (#3926)
- User can now configure the TLS version and cipher suite list. (#3943)
- Fixed order of Cloud Gateway filters and solve the conflict with RequestAttributesProvider. (#3965)
- Fixed z/OSMF static definition file processing. (#3975)
- Removed global setup of keystores. (#3702)
- Fixed Sonar analysis issues. (#3800)
- Changed port to handle AT-TLS client aware mode. (#3863)
- Updated default javax.net.ssl log level. (#3872)
- The insecureHttpWarning message is now thrown only when AT-TLS is not enabled. (#3810)
- Fixed WebSocket session opening to be non-blocking and callback-based. (#3695)
- Fixed Zowe CLI plugin and enable manual trigger only. (#3804)
Zowe CLI
Zowe CLI (Core)
- Added support for the
--encoding
flag to thezowe upload dir-to-uss
command to allow for encoding uploaded directories for command group consistency. (#2356)
Zowe CLI Imperative Framework
- Updated transitive dependencies for technical currency. (#2425)
- Resolved an issue where extraneous base profiles were created in project configurations when a nested profile property was updated. (#2404)
- Fixed an issue where the
ProfileInfo.profileManagerWillLoad
method failed if profiles were not yet read from disk. (#2284) - Fixed an issue where the
ProfileInfo.updateKnownProperty
method could rewrite the team configuration file to disk without any changes when storing a secure value. (#2324) - Updated the
cross-spawn
dependency for technical currency. (#2374) - Fixed issues flagged by Coverity. (#2292)
- Updated
dataobject-parser
dependency for technical currency. (#2262) - Updated
fs-extra
andjsonfile
dependencies for technical currency. (#2264)
CICS Plug-in for Zowe CLI
- Removed bundled dependencies from npm package and restored the npm-shrinkwrap file. (#188)
DB2 Plug-in for Zowe CLI
- Updated
ibm_db
dependency to support Node.js 22 on Windows.
Zowe Explorer
Zowe Explorer (Core)
- See the Zowe Explorer changelog for updates included in this release.
Zowe Explorer API
- See the Zowe Explorer API changelog for updates included in this release.
Zowe Explorer FTP Extension
- See the Zowe Explorer FTP Extension changelog for updates included in this release.
Zowe Explorer ESLint Plug-in
- See the Zowe Explorer ESLint Plug-in changelog for updates included in this release.
Vulnerabilities fixed
Zowe discloses fixed vulnerabilities in a timely manner giving you sufficient time to plan your upgrades. Zowe does not disclose the vulnerabilities fixed in the latest release as we respect the need for at least 45 days to decide when and how you upgrade Zowe. When a new release is published, Zowe publishes the vulnerabilities fixed in the previous release. For more information about the Zowe security policy, see the Security page on the Zowe website.
The following security issues were fixed by the Zowe security group in version 2.18.0.
- BDSA-2024-4117
- BDSA-2024-3717
- BDSA-2024-0402
- BDSA-2024-0625
- BDSA-2024-1160