2026.09.01 Release Notes
Download installers, container images, Helm charts, and other release assets from the Istari Customer Portal.
Breaking Changes
The Windows Service installer is removed
If you installed the Istari Digital Agent as a Windows service, that installer no longer exists and the service is removed when you upgrade. The agent runs as a logged-on user instead, so it starts when the operating account signs in rather than at boot.
Running the agent as a Windows service shipped as a beta in 11.4.0. It could not run tools that need a desktop session — Excel, Word, CAD applications and anything else driven through a GUI or COM — because a Windows service has no interactive session, and it did not find the configuration the installer wrote. It is now removed from the build rather than left in place as a beta.
The installer that carried it, istari-agent_X.Y.Z_win_service-amd64.msi, is replaced by istari-agent_X.Y.Z_windows-per-machine-amd64.msi. That installer still installs the agent for the whole machine under %ProgramFiles%\IstariDigital\istari_agent\, and it registers no service. See A per-machine Windows installer under Istari Digital Agent below.
Who is affected: only hosts where the agent was installed with the service MSI. Hosts installed with istari-agent_X.Y.Z_windows-amd64.msi are unaffected.
What to do
- Install this release's per-machine installer over the service install. It shares one product identity with the old installer, so it replaces it and removes the Istari Agent Launcher service as part of the upgrade. No manual step is needed on this path.
- Give the agent an account to run as. A service install did not need anyone signed in; this release does. The agent runs as a logged-on Windows user, so decide which account operates the host, and make sure that account has the agent's configuration and credentials file in its own profile. Install the agent on Windows covers both.
- Expect the agent to start at sign-in, not at boot. A host that was previously running the agent unattended from boot will be idle until someone signs in. Signing in starts the agent only if Run on startup was left ticked, and only for the account that ran the installer — if an administrator installs for someone else to operate, that operator launches the agent from the Start-menu or desktop shortcut instead.
Removing the service without upgrading. If you want the service gone and are not installing this release yet, stop and delete it from an elevated prompt, then uninstall Istari Agent from Apps & features:
sc.exe stop IstariAgentLauncher
sc.exe delete IstariAgentLauncher
Luminary Cloud CFD requires reference dimensions for force outputs
Luminary Cloud CFD 1.1.7 no longer falls back to a built-in sample wing. A job that requests force outputs (lift, drag, and so on) without cfd_config.reference_values.area_ref and cfd_config.reference_values.length_ref now fails early instead of running against the sample wing's dimensions. Lift and drag are requested by default, so this applies to any job that does not set both values.
Who is affected: any job that requests force outputs, which includes jobs that rely on the default outputs, and relied on the module's default reference dimensions or on its default flight condition. The generic default flight condition is now ISA sea level, Mach 0.3, 0° angle of attack.
What to do: set cfd_config.reference_values.area_ref and cfd_config.reference_values.length_ref for every job that requests force outputs, and set the flight condition explicitly if your results depend on it.
Assets
Docker Images
- Registry Service:
istaridigital.jfrog.io/customer-docker/registry-service:11.5.2 - Secure Connection Service:
istaridigital.jfrog.io/customer-docker/secure-connection-service:11.5.2 - Frontend Service:
istaridigital.jfrog.io/customer-docker/frontend-service:8.41.1 - MCP Service:
istaridigital.jfrog.io/customer-docker/mcp-service:0.9.3 - Identity Service:
istaridigital.jfrog.io/customer-docker/identity-service:2.1.0 - Docs Service:
istaridigital.jfrog.io/customer-docker/docs-service:6.15.0 - SpiceDB:
istaridigital.jfrog.io/customer-docker/istaridigital.com/spicedb-fips:v1.51.1 - SpiceDB Operator:
istaridigital.jfrog.io/customer-docker/istaridigital.com/spicedb-operator-fips:v1.24.0 - Zitadel (main image):
istaridigital.jfrog.io/customer-docker/istaridigital.com/zitadel:v3.4.7 - Zitadel (setup job):
istaridigital.jfrog.io/customer-docker/istaridigital.com/kubectl-iamguarded-fips:1.33.9
Note: The SpiceDB, SpiceDB Operator, and Zitadel images listed above use Chainguard hardened images. Chainguard images are minimal, security-hardened container images with significantly reduced CVE exposure.
-
NATS images (bundled with the NATS subchart in the Istari-Platform Chart; tags pinned by the chart):
- NATS Server:
istaridigital.jfrog.io/customer-docker/istaridigital.com/nats-fips:2.14.1 - NATS Config Reloader:
istaridigital.jfrog.io/customer-docker/istaridigital.com/nats-server-config-reloader-fips:0.23.0 - NATS Prometheus Exporter:
istaridigital.jfrog.io/customer-docker/istaridigital.com/prometheus-nats-exporter-fips:0.19.2 - NATS Box:
istaridigital.jfrog.io/customer-docker/istaridigital.com/nats-box-fips:0.19.5
- NATS Server:
-
Other bundled images (pinned by the Istari-Platform Chart):
- Jaeger:
istaridigital.jfrog.io/customer-docker/istaridigital.com/jaeger-fips:2.20.0 - Caddy (API Gateway):
istaridigital.jfrog.io/customer-docker/istaridigital.com/caddy-fips:2.11.4
- Jaeger:
Helm Charts
- SpiceDB Operator:
helm pull --repo https://bushelpowered.github.io/spicedb-operator-chart spicedb-operator --version 2.6.0 - Zitadel:
helm pull --repo https://charts.zitadel.com zitadel --version 8.13.4 - Istari-Platform Chart:
helm pull oci://istaridigital.jfrog.io/customer-charts/istari-platform --version 6.4.0 --username ${ISTARI_ARTIFACTORY_USERNAME} --password ${ISTARI_ARTIFACTORY_PASSWORD} - Zitadel Configurator:
helm pull oci://istaridigital.jfrog.io/customer-charts/istari-zitadel-configurator --version 1.11.1 --username ${ISTARI_ARTIFACTORY_USERNAME} --password ${ISTARI_ARTIFACTORY_PASSWORD}
SDK Clients
Agent
CLI
Integrations
Updates for the September 2026 Release
| Module Name | Version |
|---|---|
| ANSYS STK | 1.2.0 |
| C-Infinity AutoAssembler Module | 1.0.4 |
| Dassault Systèmes 3DExperience ENOVIA | 1.7.2 |
| Dassault Systèmes Cameo Enterprise Architect | 4.5.2 |
| Dassault Systèmes CATIA V5 | 2.5.8 |
| Google Workspace | 1.3.6 |
| IBM Rational DOORS Module | 1.4.2 |
| Jira & Confluence Data Extraction Module | 1.2.5 |
| Luminary Cloud CFD | 1.1.7 |
| MathWorks MATLAB (Base) | 2.3.8 |
| MathWorks MATLAB Simulink | 1.3.11 |
| Microsoft Office 365 | 1.6.6 |
| nTop | 0.4.13 |
| Open CAD | 1.1.11 |
| Open PDF | 1.8.0 |
| Open Spreadsheet | 2.3.16 |
| Open SysML | 1.0.11 |
| Open Text | 1.0.11 |
| PTC Creo Parametric | 3.3.7 |
| Siemens NX | 1.5.5 |
| SOLIDWORKS (@istari) | 1.2.3 |
| SysGit SysML v2 Tools | 1.0.3 |
| Zoo.dev | 1.0.8 |
All Compatible Modules
Click to expand full module compatibility list for the September 2026 release of the Istari Platform
| Module | Version |
|---|---|
| ANSYS HFSS | 1.1.2 |
| ANSYS STK | 1.2.0 |
| C-Infinity AutoAssembler Module | 1.0.4 |
| Dassault Systèmes 3DExperience CATIA (v6) | 1.4.2 |
| Dassault Systèmes 3DExperience ENOVIA | 1.7.2 |
| Dassault Systèmes Cameo Enterprise Architect | 4.5.2 |
| Dassault Systèmes CATIA V5 | 2.5.8 |
| Google Slides | 0.2.3 |
| Google Workspace | 1.3.6 |
| Hexagon MSC Nastran | 2.4.7 |
| Hexagon Nastran Extract | 2.4.10 |
| IBM Rational DOORS Module | 1.4.2 |
| Jira & Confluence Data Extraction Module | 1.2.5 |
| Luminary Cloud CFD | 1.1.7 |
| MathWorks MATLAB (Base) | 2.3.8 |
| MathWorks MATLAB Simulink | 1.3.11 |
| Microsoft Office 365 | 1.6.6 |
| Microsoft Office Excel | 2.4.3 |
| Microsoft Office PowerPoint | 1.1.2 |
| Microsoft Office Word | 2.3.11 |
| nTop | 0.4.13 |
| Open CAD | 1.1.11 |
| Open PDF | 1.8.0 |
| Open Spreadsheet | 2.3.16 |
| Open SysML | 1.0.11 |
| Open Text | 1.0.11 |
| PTC Creo Parametric | 3.3.7 |
| Siemens NX | 1.5.5 |
| SOLIDWORKS (@istari) | 1.2.3 |
| SysGit SysML v2 Tools | 1.0.3 |
| Zoo.dev | 1.0.8 |
Change Log
Istari Platform
Identity and access management moves into the platform
When the Identity Service is enabled, user management, tenant management, and role assignment are now handled directly within the Istari Platform rather than configured externally.
- New Platform Admin role and console. Platform administrators have a new Platform Admin Console for managing tenants, adding users to tenants, and assigning roles. This is where cross-tenant administration happens, and the console will gain more GUI-based configuration and management in future releases.
- App admins are now tenant admins. The role previously called app admin is now tenant admin. Tenant admins manage users, roles, and resources within their own tenant, and cannot view or act in other tenants.
- Platform tenant. A new top-level platform tenant provides the administrative context used to manage the platform itself and to extend the Platform Admin Console in future releases.
- Users belong to a single tenant. Each user account belongs to one tenant. This may change in a future release.
New Features
- Secure Connections: lowering a connection's access type now downgrades active Edit shares to View, while lowering its infosec level or saving tag rules that block active shares now unshares the affected resources automatically. See Changes That Affect Shared Resources.
- Secure Connections: infosec sharing has been relaxed, enabling some new connection possibilities. For a full compatibility matrix see Infosec Compatibility Between Platforms.
- Secure Connections: connection Shared IDs can be "namespaced" with slashes to indicate subfolders. For more details see Nested Shared IDs.
- Secure Connections: senders can now allow received files to be reshared over the receiver's own connections. For more details see Onward Sharing.
- Secure Connections: administrators can star connections.
- Secure Connections: permitted recipients now receive a notification when a partner shares, updates, or revokes a resource over a receiving connection. For more details see Notifications.
- Connected Sources - An experimental feature that lets you browse an app integration and connect its items to Istari as resources. Select a folder or a hierarchical model to connect everything under it at once.
Performance and Stability
- Completing a job on a model with a large job history no longer takes up to a minute — The final job-status update loaded the model's full entity, including its entire job history, twice per job resource, just to read one access-level field, so the cost grew with the model's job count and could exceed the agent's request timeout, after which retries sometimes marked a completed job as failed. The lookup now reads that field directly, and the cost no longer depends on the model's job count.
Bug Fixes
- Secure Connections: a sending connection's object store can no longer be changed while it has active shares.
- Secure Connections: a failed receive no longer duplicates resources in some cases.
- Secure Connections: service accounts no longer appear in access lists.
- Secure Connections: share refusal messages now use connection terminology.
Istari Digital Agent
New Features
-
A per-machine Windows installer —
istari-agent_X.Y.Z_windows-per-machine-amd64.msiinstalls the agent for the whole machine: the agent and its modules go to%ProgramFiles%\IstariDigital\istari_agent\, and its data and logs to%ProgramData%\IstariDigital\istari_agent\. It needs administrator rights. Use it where application-control policy on the host only permits programs to run from Program Files; the per-user installer,istari-agent_X.Y.Z_windows-amd64.msi, remains the default choice everywhere else.This installer replaces the Windows service MSI and is the same download renamed — see The Windows Service installer is removed under Breaking Changes. It registers no service. The agent runs as a logged-on user exactly as it does from a per-user install, and Run on startup, ticked by default, starts it when the operating account signs in. That startup entry belongs to the account that ran the installer rather than to the machine, so no other user who signs in starts an agent of their own. A Start-menu and desktop shortcut is installed either way, which is how to launch the agent on a host whose policy does not permit programs to start automatically from a user session. If Windows warns about the installer, or application control refuses it, Trusting the Windows installers covers verifying the signature and allow-listing the publisher for a managed fleet.
Moving an existing per-user install to a per-machine one takes two steps: uninstall Istari Agent from Apps & features, then run the per-machine installer. It refuses to run while a per-user install is present and says so, because Windows Installer only looks for an existing version of a program within the same install scope — a machine-wide installer does not see a per-user copy and cannot remove it, and left to itself would install alongside, leaving two agents registered. Configuration and credentials survive the switch. The configuration lives in the operating account's profile, and uninstalling removes only what the installer put on the host — a credentials file you placed under the old install folder is left where it is. Modules do not carry over. They stay in the per-user folder while the new install scans
%ProgramFiles%\IstariDigital\istari_agent\istari_modules, which the installer creates empty, so an administrator unpacks them there after the switch. Until that happens the agent runs with no modules and claims no jobs.Configuration remains per user in this release. On a per-machine install the installer seeds it into the profile of whoever ran the installer, so if an administrator installs the agent for someone else to operate, the operator supplies their own configuration — If a different account will operate the agent covers that case.
-
Modules install beside the agent on a per-machine install — On a per-machine install,
istari_modulesis under%ProgramFiles%\IstariDigital\istari_agent\, created by the installer and scanned by the agent. Installing or updating a module there is an administrator action: unpack it from an elevated prompt. The agent's own module auto-update cannot write to Program Files, and when it finds that it cannot, it records what to do in the log and leaves the installed modules alone rather than replacing one partially. On such a host, add modules with that unpack procedure rather than withstari module install, which does not yet know about the per-machine location — see Known Issues. -
Staging the installer where installers cannot be run — Sites that block running MSIs can unpack the agent's files without installing anything, using Windows Installer's administrative-install mode, and place them by hand. If this site does not allow installers to run has the command and lists what the installer would otherwise have done for you.
-
FIPS builds are now tagged and published under their own path — each release's FIPS variant (RPM/DEB/MSI) now carries a
fips=trueArtifactory property and uploads to afips/subpath (e.g.istari-agents/<version>/fips/for production builds), instead of sitting in the same folder as the standard build, distinguishable only by the-fipsfilename token. This is a packaging/publishing change only — the FIPS build itself works the same way it always has.
Fixes
-
A per-machine install now finds its modules — On a per-machine Windows install the agent looked for modules under
%ProgramData%\IstariDigital\istari_agent\, which is not where the installer creates the folder, so it found no modules at all and every job it was offered went unclaimed. The agent now scans theistari_modulesfolder beside its own executable, which is the folder the installer creates. -
A per-machine install now finds configuration and keys left by an earlier version — The agent looked for files carried over from an older install under
%ProgramFiles%\Istari Digital\, with a space, while every installer has always created%ProgramFiles%\IstariDigital\. On a per-machine install this meant an older global configuration file, or an existing signing key stored beside the agent, was silently not found. -
A fresh install no longer crashes at every sign-in before it is configured — The installer seeds a configuration file with placeholder values, and an agent started against it raised an unhandled exception, which on Windows meant a modal error dialog at every logon until someone edited the file. The agent now recognises placeholder values after environment-variable overrides are applied, logs which ones still need replacing, and exits cleanly. Linux and macOS share the same startup code and get the same behaviour.
-
An agent that cannot use its configuration now leaves a log — Startup messages, including the instruction to replace placeholder values, are written to the agent's log file before the configuration is read, so the support directory and the log exist even when the agent exits immediately. Previously that path produced no log at all. On Windows there is still no console output on that path; the log file is where to look.
-
Agent config secrets no longer appear in logs —
get_redacted_config()previously kept and logged the first 10 characters of the registry API token, module registry auth token, and identity-service secret at every startup and config reload. Each of those three values now renders as a constant<redacted>placeholder when set, andNonewhen absent — the log records whether a credential is configured, not any part of its value. -
Upgraded the bundled
cryptographylibrary to 50.0.1 to resolve CVE-2026-69247 (VSEC-3289), a timing-attack finding in PKCS#7 decryption. The agent's own use ofcryptography(RSA-OAEP, AES-GCM, SHA-256) never touches PKCS#7 and was not exploitable; the upgrade clears the finding at the dependency level rather than leaving a VEX exception to re-litigate every scan. -
--crypto-checkand--fips-checkoutput is visible from a Windows command prompt — The frozen Windows build runs without a console of its own, so these diagnostics produced their output where nobody could see it. They now attach to the prompt that launched them. Redirecting their output to a file works as before, and exit codes were never affected. Windows only.
Istari Digital CLI
Fixes
- The agent auto-updater no longer loops when a pre-release version is pinned — its version-parsing regex could not handle pre-release SemVer (e.g.
-pre.N), so a pinned pre-release build was treated as always out of date, and the updater reinstalled it in an infinite loop that filled host disks (OPS-3670). The updater now accepts full SemVer, including pre-release and build-metadata segments.
Integrations
- ANSYS STK 1.2.0 — First release for Ansys STK 13.1 on Windows.
@istari:extractreads a.vdfor a zip of one.scplus sidecars.@istari:runcomputes the Access pairs and Chains the scenario already stores.@istari:update_parameterswrites scenario times, enabled Access-constraint bounds, and conic sensor field-of-view angles back into the scenario and uploads the re-saved file as a new version of the model.@istari:extractalso writes aparametersartifact with that same key map. - Dassault Systèmes Cameo Enterprise Architect 4.5.2 — Every function, including
@istari:run_simulation, runs on macOS 14, 15, and 26 (Apple Silicon via Rosetta 2). Diagram export loads the full SysML plugin tree, so SysML and UAF diagrams export with their content on every platform. Diagram artifact filenames are Windows-safe; the original names stay indiagrams_metadata. Security patch: jackson-databind 2.22.3, with jackson-core and jackson-annotations following, bundled in the launcher jar. - Dassault Systèmes 3DExperience ENOVIA 1.7.1 —
@istari:batch_executeruns several ENOVIA functions in one job, with$variablesubstitution and optional per-step metadata. Optionaldassault_3dx_auth_urlmetadata covers a deployment whose 3DPassport and 3DSpace hosts differ. - PTC Creo Parametric 3.3.5 — Jobs can dispatch to Creo Parametric 12.0 agents. Supported Parametric lines are 10.0 and 12.0.
- IBM Rational DOORS Module 1.4.1 —
@istari:extract_doors_nextcan extract every module in a project in one job (scope: all_modules). A linked artifact keeps its own title and attributes.@istari:extract_rhapsodyreads published Rhapsody models, and an optionalroot_elementcovers servers whose model index is empty. - Microsoft Office 365 1.6.4 — Named cells return their values, multi-cell named ranges return the full block, and named ranges on hidden worksheets resolve. Auth and extract failures fail the job after writing
error_response. Declares macOS 26 so job creation matches agents that report that host OS. - Google Workspace 1.3.5 — An extraction recorded as an error in
metadata_reportfails the job after writing outputs. Declares macOS 26 so job creation matches agents that report that host OS. - Jira & Confluence Data Extraction Module 1.2.4 — An extraction recorded as unsuccessful in
metadata_reportfails the job after writing outputs. Declares macOS 26 so job creation matches agents that report that host OS. - Open PDF 1.8.0 —
@istari:extract_tableswrites each detected table as a grid (tables.jsonand one CSV per table). Page numbers indocling_text.jsonmatch the physical PDF page. Declares macOS 26 so job creation matches agents that report that host OS. - SOLIDWORKS (@istari) 1.2.0 —
@istari:extract_parameters_fullwrites properties, equations, and dimensions, including loaded assembly components.@istari:batch_executeruns an ordered list of functions against one model, passing an updated model from one step to the next.@istari:variable_sweepruns one function once per set of variable values, each iteration starting from the original model. - Luminary Cloud CFD 1.1.7 — Flow visualization follows the geometry bounding box, so millimetre and offset CAD render
flow_viz.pngof the model. Convergence checks apply to every requested force output. Defaults are a generic ISA sea-level condition (Mach 0.3, 0° AoA);cfd_config.reference_values.area_refandcfd_config.reference_values.length_refare required when force outputs are requested. Security patch:urllib32.8.0 (CVE-2026-97687, CVE-2026-97689) andPyJWT2.15.1 (CVE-2026-102273, CVE-2026-102275). - macOS 26 (Tahoe) support — These modules declare macOS 26 so job creation matches agents that report that host OS: Open Spreadsheet
2.3.14, Open Text1.0.11, Open SysML1.0.11, MathWorks MATLAB2.3.8, MathWorks MATLAB Simulink1.3.11, Luminary Cloud CFD1.1.3, SysGit1.0.3, C-Infinity AutoAssembler1.0.4, and Zoo.dev1.0.5. See the Updates for the September 2026 Release table and the All Compatible Modules list for pinned versions. - cad-geometry-toolkit security patch — Open CAD
1.1.10, nTop0.4.12, Dassault Systèmes CATIA V52.5.7, Siemens NX1.5.4, SOLIDWORKS (@istari)1.2.2, and PTC Creo Parametric3.3.6bundlecad-geometry-toolkit1.0.4, which upgrades fonttools to 4.66.0 (SNYK-PYTHON-FONTTOOLS-15869939) and picks up the pillow, urllib3, and lxml fixes. These versions include the Creo Parametric3.3.5, SOLIDWORKS (@istari)1.2.0, and Open CAD1.1.9changes listed above. - Dependency security patches — Dassault Systèmes 3DExperience ENOVIA
1.7.2, Jira & Confluence Data Extraction Module1.2.5, Open Spreadsheet2.3.16, Google Workspace1.3.6, and IBM Rational DOORS Module1.4.2upgrade urllib3 to 2.8.0 (CVE-2026-97687, CVE-2026-97689). Google Workspace1.3.6and IBM Rational DOORS Module1.4.2also upgrade oauthlib to 4.0.0 (CVE-2026-49265). Microsoft Office 3651.6.6upgrades urllib3 to 2.8.0 and pyjwt to 2.15.1 (CVE-2026-102272, CVE-2026-102267, CVE-2026-102274), and includes1.6.5(anyio 4.15.1, CVE-2026-63374). Open Spreadsheet2.3.16includes2.3.15(pypdf 6.19.0). Zoo.dev1.0.8bundles a patched OpenSSL (libssl33.0.2-0ubuntu1.30, CVE-2026-84782) in its Ubuntu binary, and includes1.0.6(anyio 4.15.1, CVE-2026-63374) and1.0.7(pymongo 4.18.2, CVE-2026-96749, CVE-2026-96748). These versions include the ENOVIA1.7.1, DOORS1.4.1, Microsoft Office 3651.6.4, Google Workspace1.3.5, Jira & Confluence1.2.4, Open Spreadsheet2.3.14, and Zoo.dev1.0.5changes listed above. - cad-geometry-toolkit 1.0.5 — Open CAD
1.1.11, nTop0.4.13, Dassault Systèmes CATIA V52.5.8, Siemens NX1.5.5, SOLIDWORKS (@istari)1.2.3, and PTC Creo Parametric3.3.7bundlecad-geometry-toolkit1.0.5, which upgrades urllib3 to 2.8.0 (CVE-2026-97687, CVE-2026-97689). They supersede the1.0.4versions in the previous bullet and include their changes. The macOS build of Open CAD1.1.11is not published with this release because it still bundlescad-geometry-toolkit1.0.3-pre.1, which does not include these fixes. Open CAD1.1.8remains the latest macOS build until a rebuilt macOS version is released.
Release Timeline
2026-09-30:
- Initial September 2026 release (planned)
Known Issues
stari module installdoes not target a per-machine Windows install. On Windows,stari module installandstari module updatewrite only to the per-user modules folder,%LOCALAPPDATA%\istari_agent\istari_modules, while a per-machine install's agent scans%ProgramFiles%\IstariDigital\istari_agent\istari_modules. A module installed with the CLI on such a host lands in a folder the agent never reads, and the CLI still reports success.stari module listandstari module uninstalllook in the per-user folder and in a machine-wide folder under%ProgramData%that the agent has never used, so on a per-machine hostlistcan report no modules while the agent is running them, anduninstallcannot remove one.- Workaround: on a per-machine install, add and update modules by unpacking the package from an elevated prompt, as described in Module deployment, and do not use
stari module installon that host. A fix is planned for a later release.