Release Notes - v5.0.0 🚀
May 19, 2026
This major release (v5.0.0) marks a significant milestone in the framework, introducing critical security updates to mitigate vulnerabilities, maintenance improvements through automated agent skill synchronization, standardization and renaming of key interface labels across PEEC and POQTROL modules, and multiple fixes and mathematical optimizations in Quattrol 365 statistics generators.
🌐 General
Security & Patches (#1141)
- Vulnerability Mitigation:
- Updated
nodemailerto version^8.0.5infunctions/package.json. - Updated
uuidto version^14.0.0both in root andfunctions/package.json. - Added defensive sanitization against CRLF injection attacks in
SmtpNotifierclass (functions/src/notifications/service/impl/smtpnotification.ts). - Updated dependencies and refreshed lockfiles (
bun.lock).
- Updated
- Alerts and Documentation:
- Added detailed guide to export Dependabot alerts to markdown format and updated project dependencies to use caret-based ranges (
^). - Parameterized Dependabot alert export example in
README.md.
- Added detailed guide to export Dependabot alerts to markdown format and updated project dependencies to use caret-based ranges (
Agent and Skill Maintenance (#1163)
- Skill Synchronization Script:
- Replaced git submodules with a standalone shell script for agent skill synchronization.
- Initial addition of
gemini-gemsas git submodule and subsequent migration to the simplified script workflow. - Implemented directory existence validation in
sync-skillsscript and optimized agent import structure.
- Code Review Guidelines:
- Added documentation guidelines and best practices for integrating and utilizing the Linus Torvalds code review skill in agents.
Environment & Configuration (#1181)
- Development Tools:
- Removed obsolete IDX configuration files from the repository.
- Updated recommended VS Code extensions list.
- Internationalization & UI Tweaks:
- Fixed minor typos in generated reports.
- Updated product configuration constants in the setup wizard.
📊 Quattrol 365
Features (#1133)
- rmdev Bias Calculation:
- Added validation and bias calculation for IET in statistics generators when the
rmdevflag is active. - Implemented informative notice regarding
rmdevconfiguration usage in metrics calculation. - Added robust validations to prevent runtime errors arising from empty data or division by zero.
- Updated and added unit tests covering statistics generator behavior.
- Resolved merge conflict in module files.
- Added validation and bias calculation for IET in statistics generators when the
Bug Fixes (#1167, #1166)
- Data Entry and Ranges:
- Added method to automatically update the range date when registering or adding new data.
- Implemented design recommendations and technical optimizations suggested by agents.
- Added fallback strategy when range queries return no averages.
- Title and UI Adjustments:
- Reverted IET title back to ICT term in export files and statistical reports.
- Added informational message for users in the UI when the outlier deviation rejection option (
remdev%) is active.
🔬 PEEC & 📈 POQTROL
Refactor (#1181)
- Interface Label Renaming:
- Renamed UI labels for certifications, summaries, and participations across all frontend constants and corresponding validation tests.