# Open OnDemand 2.0.31 now available

**URL:** <https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492>\
**Category:** Announcements\
**Created:** [May 19, 2021, 8:20pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492 "2021-05-19T20:20:03Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [May 19, 2021, 8:20pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/1 "2021-05-19T20:20:03Z")

</div>

We are pleased to announce the release of Open OnDemand 2.0.

Highlights of Open OnDemand 2.0 include the list below. Please note that there are breaking changes and they’re detailed in the 2.0 Release notes linked below.

- Pinned Apps: Enhanced app launch interface using large app icons on the dashboard
- Custom dashboard widgets and layout
- New File Manager app
- Tighter integration between the Dashboard, Active Jobs, and Files apps
- Adding metadata to app manifests
- Shell app now has themes
- Configurations in an ondemand.d directory
- Changes in All Apps page layout
- ERB formats for Message of the day
- Control whether an app link opens in a new window using manifest attribute
- Memcached Ruby gem available for use in apps
- Dependency updates

Release notes and upgrade information can be found here:  
[https://osc.github.io/ood-documentation/release-2.0/release-notes/v2.0-release-notes.html](https://osc.github.io/ood-documentation/release-2.0/release-notes/v2.0-release-notes.html)

Also note that there may be more patches released in the 2.0 series. Watch the Milestone for 2.0.x  
[OOD2.0 Patch Release Milestone · GitHub](https://github.com/OSC/ondemand/milestone/12) for the upcoming updates to 2.0. You can also watch for releases on Github to get notifications of when releases are made!

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [May 19, 2021, 8:25pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/2 "2021-05-19T20:25:25Z")

</div>



---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [May 27, 2021, 4:05pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/3 "2021-05-27T16:05:09Z")

</div>

Version 2.0.9 is now available and you should upgrade.

Highlights are:

- A critical bug was fixed in uploading directories. In 2.0.8 the first file uploaded turns into a directory with no executable permissions. The workaround is to chmod on the directory, move and rename the file - or just delete the file and re-upload it.
- `staged_root` is now available in the `submit.yml.erb` context. So you can do something like this, separating stdout and stderr in the submit file:

```auto
script:
  error_path: "<%= staged_root %>/error.log"
```

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [June 10, 2021, 5:54pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/4 "2021-06-10T17:54:35Z")

</div>

We’ve found an issue in the file editor zeroing files. Sites with 2.0.x should disable the file-editor by changing permissions on the directory or this file. This will ensure your users don’t accidentally zero out their files when using the file-editor. We’re working on a fix and will post to this announcement once we have one ready.

```auto
/var/www/ood/apps/sys/file-editor/
/var/www/ood/apps/sys/file-editor/manifest.yml

```

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [June 10, 2021, 5:54pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/5 "2021-06-10T17:54:42Z")

</div>



---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [June 17, 2021, 4:12pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/6 "2021-06-17T16:12:16Z")

</div>



---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [June 17, 2021, 4:14pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/7 "2021-06-17T16:14:10Z")

</div>

2.0.10 now public that fixes the file editor bug that zeros out files with non ASCII characters. Sites using 2.0.x version should upgrade as soon as they’re able.

This should be the last critical bug in the 2.0.x release. In the next 2 weeks or so we’ll publish 2.0.11 that should just have minor tweaks for edge cases.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [July 20, 2021, 2:34pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/9 "2021-07-20T14:34:58Z")

</div>



---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [July 20, 2021, 2:35pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/10 "2021-07-20T14:35:02Z")

</div>

2.0.13 is now public.

It contains a security fix for kuberenetes & Open ID Connect users. kubectl commands ran as root logged to syslog and these entries contain OIDC tokens. If you run kubernetes with OIDC you should upgrade immediately.

It also fixes peer to peer app sharing and the new pinned apps features. Sites that run p2p app sharing will have to pin all the `usr` apps to have parity with a 1.8- dashboard landing page. App icons no longer show up by default.

Other items of note:

- `OOD_NAVBAR_TYPE` correctly uses `light`
- File previews now correctly show utf-8 characters
- Sites can now disable ‘ssh to compute node’ on a per cluster basis (along with the site wide, global setting)
- Similar to 1.8, 2.0 can now disable shell button in the files app, though the mechanism has changed. It’s no longer controlled through an environment variable, rather a yaml config in `ondemand.d` files.

Release notes have been updated for these items where they change.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [July 20, 2021, 2:35pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/11 "2021-07-20T14:35:07Z")

</div>



---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [September 15, 2021, 2:54pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/12 "2021-09-15T14:54:27Z")

</div>

2.0.16 is now publicly available.

It has mostly kuberenetes fixes in `ood_core`, but also includes a couple of other bug fixes of note:

- Fixed removing files when allowlists are in place - [1337](https://github.com/OSC/ondemand/issues/1337).
- Fixed an issue with non US keyboards could not use `+` keys in the shell app -  
[1214](https://github.com/OSC/ondemand/issues/1214).
- Sessions stores can now be overridden in [1321](https://github.com/OSC/ondemand/pull/1321).
- Files app shell buttons now correctly redirect to the given cluster in [1317](https://github.com/OSC/ondemand/pull/1317).
- Locales now correctly fallback to english in [1314](https://github.com/OSC/ondemand/pull/1314).

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 5, 2021, 8:29pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/13 "2021-10-05T20:29:29Z")

</div>

2.0.17, a security release, is now publicly available.

The only change/fix in this version is regarding SVG files in the file browser. SVG files may contain malicious javascript, which if viewed in open ondemand, can execute within that page’s context. 2.0.17 will now force the SVG file to be downloaded so users can inspect the file and/or open it in a new context.

Sites running 2.0.X should update as soon as they can. This does not affect versions 1.8 or below.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [October 6, 2021, 5:21pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/14 "2021-10-06T17:21:26Z")

</div>

I’m terribly sorry to do this, but 2.0.17 released yesterday was only a partial fix for insecure svg files.

2.0.17 incorrectly previewed files with extension .SVG (all caps) or a mix of capitalization and lowercase (like .SvG). 2.0.18 now treats all svg extensions the same – forcing the browser to download the file instead of previewing it.

Sites should update to 2.0.18 to ensure their customers don’t open malicious svg files within their site’s context.

Again, this does not affect versions 1.8 or below.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [April 12, 2022, 1:53pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/15 "2022-04-12T13:53:20Z")

</div>

Version 2.0.23 is now available.

Highlights from .20 are

- `Uppy`, a javascript dependency to upload files, has been updated to patch [NVD - CVE-2020-8205](https://nvd.nist.gov/vuln/detail/CVE-2020-8205). Though I don’t believe we were affected.
- Dynamic batch connect bug fixes
- Bugfix for uploading files when using nondefault umasks.

Here’s the full changelog for more details:

> **[Comparing v2.0.20...v2.0.23 · OSC/ondemand](https://github.com/OSC/ondemand/compare/v2.0.20...v2.0.23)**
>
> Supercomputing. Seamlessly. Open, Interactive HPC Via the Web - Comparing v2.0.20...v2.0.23 · OSC/ondemand

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [June 17, 2022, 7:02pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/16 "2022-06-17T19:02:17Z")

</div>

Open OnDemand 2.0.26 is now available. Items of note are

- Ruby On Rails security updates

- Phusion Passenger security updates

- Rack security updates

- Bugfixes

Note that because we released a new passenger version, you’ll have to update everything

```auto
yum update ondemand\*

```

See the full changelog here.

> **[Comparing v2.0.23...v2.0.26 · OSC/ondemand](https://github.com/OSC/ondemand/compare/v2.0.23...v2.0.26)**
>
> Supercomputing. Seamlessly. Open, Interactive HPC Via the Web - Comparing v2.0.23...v2.0.26 · OSC/ondemand

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [June 21, 2022, 2:57pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/17 "2022-06-21T14:57:02Z")

</div>

I’ve updated the release of 2.0.26 note above to detail all the security patches related to 2.0.26.

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [July 7, 2022, 8:26pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/18 "2022-07-07T20:26:29Z")

</div>

2.0.27 is now available that fixes a bug that was introduced in 2.0.26.

This is the bug that it fixes. For whatever reason, this doesn’t affect OSC systems because the ownership of this directory just rotates.

> <https://github.com/OSC/ondemand/issues/2090>
>
> After upgrading to ondemand 2.0.26 we discovered that the PUN wouldn't start, wi…th the following error:
> 
> \`Error -- nginx: \[emerg\] mkdir() "/opt/rh/ondemand/root/usr/share/nginx/passenger\_temp" failed (13: Permission denied)\`
> 
> in the browser.
> 
> At one level this appears to be an selinux issue, in that if selinux is disabled it creates the directory successfully
> However, it creates it as the user who happens to run the first PUN instance. This doesn't seem good.
> I think it makes a lot more sense to redirect it to where the other temp directories are using the passenger\_temp\_path directive.
> 
> 
> 
> ┆Issue is synchronized with this \[Asana task\](https://app.asana.com/0/1201735133575781/1202470714057100) by \[Unito\](https://www.unito.io)

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [August 12, 2022, 5:21pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/19 "2022-08-12T17:21:15Z")

</div>

Open OnDemand 2.0.28 is now available.

**Added**

- Support for Ubuntu 18.04 & 20.04 platforms.
- `fujitsu_tcs` support.
- Dex can now be ran behind the apache proxy by setting `dex_uri`. This means sites can use apache to proxy to dex instead of opening up 5556 or 5554 ports and accessing dex directly.

**Fixed**

- `passenger_options` can now correctly be used fixing a bug.
- PUNs environments are now sanitized, removing OIDC and/or other environment variables from `pun_root_pre_hook` that aren’t necessary.
- Dex `tls_cert` and `tls_key` get correctly set.
- Interactive jobs now correctly use TurboVNC 3.0+. Previously the now removed `-nohttpd` option was always given. `-nohttpd` will now only be used for TurboVNC versions \< 3.0.

**Changed**

- `ondemand-dex` has been upgraded from `2.27.0` to `2.32.0`. **Note that ondemand-dex users will need to upgrade this package as well**.

See the full changelog for more details.

> **[Release v2.0.28 · OSC/ondemand](https://github.com/OSC/ondemand/releases/tag/v2.0.28)**
>
> What's Changed
> 
> Backport #1793 passenger\_options fix to 2.0 by @njbooher in #2106
> Use ood\_packaging gem to build 2.0 packages by @treydock in #2139
> Support Ubuntu 20.04 packages with OnDemand 2.0 b...

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [November 15, 2022, 5:34pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/20 "2022-11-15T17:34:43Z")

</div>

Open OnDemand 2.0.29 is now available. The biggest change is around our NodeJS dependency. NodeJS 12 has come to end of life for all platforms, so it’s no longer receiving security patches. So we had to upgrade to NodeJS 14 at this time.

Instructions for upgrading are below and we’re updating our automation for the same.

**Added**

- The Job Composer now allows for job composer to copy environment. This will use `--EXPORT=ALL` instead of `--EXPORT=NONE` for Slurm (the default is NONE) schedulers to use `srun` during the jobs execution.
- The job composer can now hide job arrays based on the `OOD_HIDE_JOB_ARRAYS` environment variable.
- A new batch connect template - `vnc_container` has been added to support running batch connect applications in a container (documentation coming soon).

_Fixed_

- Dynamic batch connect settings for minimums and maximums can now apply to multiple items.
- Dynanic batch connect settings can now use `/` in the names.
- SSH to compute node buttons can be disabled when `OOD_BC_SSH_TO_COMPUTE_NODE` is set to false.

**Changed**

- We had to upgrade to node js 14 because 12 is end of life on all platforms and will not receive security updates.
- SHA1 hashes are used instead of MD5 for systems that have enabled FIPS.

See the instructions on upgrading from 2.0.28 to 2.0.29 here:  
[https://osc.github.io/ood-documentation/latest/release-notes/v2.0-release-notes.html#upgrading-to-v2-0-29](https://osc.github.io/ood-documentation/latest/release-notes/v2.0-release-notes.html#upgrading-to-v2-0-29)

See the full changelog here:

> **[Release Version 2.0.29 · OSC/ondemand](https://github.com/OSC/ondemand/releases/tag/v2.0.29)**
>
> What's Changed
> 
> Improved maintenance page handling of 503 errors \[release\_2.0\] by @treydock in #2202
> Do not display Open In Terminal button if SSH to compute is turned off by @treydock in #2210
> Fix...

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [February 7, 2023, 7:10pm UTC](https://discourse.openondemand.org/t/open-ondemand-2-0-31-now-available/1492/21 "2023-02-07T19:10:29Z")

</div>

Open OnDemand 2.0.31 is now available.

This release fixes:

- The linux host adapter now correctly interacts with `apptainer` and `singularity` both. Previous versions do not account for `apptainer`’s updates and sites that have upgraded to `apptainer` and use the linux host adapter may find issues specifically around the ability to delete linux host adapter jobs.
- Using 0s in `data-min-` or `data-max-` directives now works correctly.
