← Back to all sparks
D

Dify

AI-ASSISTANTS
Velocity2.5

Open-source platform for building, deploying, and operating LLM applications and agents.

Dify ships sandboxed Linux agent runtime and scoped knowledge base API keys.

agentic-runtimellm-opsknowledge-baseself-hostedworkflowsecurity
Current state
Dify has shifted from a workflow orchestrator into a dual-mode platform: traditional LLM workflow graphs and a sandboxed Linux agent runtime introduced experimentally in v1.16. Knowledge base management has matured with access now granular to individual datasets via scoped API keys. The v1.17 cycle completed the security hardening that followed the agentic surface expansion.
Where it's heading
The agent runtime path (v1.14 Agent x Skills → v1.16 Dify Agent) is Dify's primary bet: shell access, sandboxed execution, and a Skill ecosystem modeled on how shell-based LLM agents operate. Workflow canvas polish (keyboard movement, node locator, block selector) continues as a parallel track for existing users. The agent mode will likely exit experimental and get deeper toolchain integrations next.
Prediction
The next move is stabilizing Dify Agent out of experimental and expanding the plugin marketplace after the creator profile overhaul in v1.17.

Recent moves

  1. 6d ago

    v1.17.1 - Bug Fixes and Improvements

    Dataset-scoped API keys close a real security gap — integrations previously got workspace-wide access when they only needed one knowledge base. Keyboard movement for workflow nodes and the marketplace creator profile overhaul are UX wins that fit Dify's effort to make the canvas and ecosystem more navigable.

    View source ↗
  2. 1mo ago

    Release v1.16.1 - Bug Fixes and Security Enhancements

    Tool multi-select inputs and the workflow node locator are quality-of-life additions that land after a major feature wave — they reduce friction in building and debugging complex graphs without changing the product's direction.

    View source ↗
  3. 2mo ago

    Dify Agent: sandboxed Linux runtime ships in experimental

    ⚡ SPARK

    The v1.16 RC is where the agent thesis becomes concrete: a Linux sandbox, a skill builder, and tool integration that matches how shell-based agentic runtimes operate. This is Dify moving from 'build workflows with LLMs' to 'run LLM agents that operate like a computer.'

    View source ↗
  4. 4mo ago

    v1.14.2 - Security fixes, agent groundwork, workflow reliability, and deployment updates

    v1.14.2 is security hardening and workflow reliability cleanup after the agentic surface expansion in v1.14: tenant isolation, tool credential scoping, HITL tracing fixes. The 'agent groundwork' in the title is internal plumbing, not user-visible.

    View source ↗
  5. 4mo ago

    v1.14.1 - Security hardening, workflow stability, and cleaner self-hosted deployments

    v1.14.1 locks down secret key handling for self-hosted deployments and closes an IDOR on the account endpoint — security patch work that typically follows a major capability release.

    View source ↗
  6. 7mo ago

    1.14.0-rc1: New Agent x Skills for Production Workflows

    ⚡ SPARK

    1.14.0-rc1 introduced the sandboxed agent runtime, Skill Editor, and collaborative agent building that v1.16 later refined. This was the inflection where Dify committed to the shell-agent paradigm — the architecture decision that subsequent releases build on.

    View source ↗