Release Notes
Release notes summarize user-visible changes to Dataira.
2026-08-14 — Fail-closed saved-result provenance
- Saved-result reads now fail closed across REST, dashboards, MCP, and governed reuse when datasource or authorization-generation provenance is absent.
- First-party and MCP saves require canonical datasource-backed query evidence; refreshes revalidate access and datasource generation around execution.
- Row-scoped SQL validation rejects repeated-table aliases that could leave one self-join occurrence unrestricted.
2026-08-14 — One consistent pin preference
- Conversations, saved metrics, dashboards, and collections share one pin control.
- Pin changes render immediately, persist to the end-user workspace, and sort pinned assets first after reload.
- The unused star preference and its SDK, agent-protocol, and database surface were removed before package publication.
What appears here
Current docs baseline
- Supported datasources: PostgreSQL, MySQL, BigQuery, ClickHouse.
- Connection modes: Remote and Tunnel, where supported.
- Embed packages: prerelease Node, headless client, and React workspace artifacts.
- Embed preview: chat, metrics, dashboards, Collections, and version history; selected dev/prerelease capabilities add discovery, refinement, governed agent CRUD, and safe Undo.
- Dev demo: two PostgreSQL sources plus private service-bound Company Spend OpenAPI/D1 data, with per-browser isolation, vendor ranking, and an in-page new-demo-user action.
- Dev preview: canonical same-origin OpenAPI 3.x JSON/YAML ingestion, reviewed side-effect-free GET/POST query or computation operations, private pinned-IP TLS egress, immutable source revisions, server credentials, bindings, budgets, and Node SDK/Analytical Pack lifecycle helpers. Async and GraphQL remain later.
- User surfaces: hosted app, embed SDK, MCP, datasource setup, and tunnel CLI.
Reading release notes
Look for changes that affect how you connect databases, ask questions, inspect SQL, or use MCP tokens.