← Back to all sparks
T

ThingsBoard

ANALYTICS
Velocity5.0

IoT platform for device management, data collection, processing and visualization

ThingsBoard patches aggressively across two release lines while quietly adding IoT Hub and AI model support.

iot-platformsecurity-hardeningedge-computingai-integrationmulti-branch-releasekafka
Current state
ThingsBoard is in sustained patch mode across 4.2.x (LTS) and 4.3.x (current), resolving dozens of CVEs per release cycle. Beneath the security churn, the 4.3.x line has accumulated real additions since spring: IoT Hub integration, AI model structured output support for multiple providers, LZ4 Kafka compression, automatic SSL cert reload without restarts, and an HTML container widget. The dual-track model shows an enterprise customer base that demands long-term stability alongside continuous development.
Where it's heading
The parallel LTS and current release trains signal a maturing platform with paying enterprise customers who cannot absorb breaking changes. The AI model integration thread — structured outputs, Vertex AI location routing — suggests ThingsBoard is building a rule-engine layer that can route telemetry decisions through LLMs, not just static rules. This points toward an edge-to-AI data fabric positioning rather than dashboarding alone.
Prediction
The next substantive release will likely deepen the AI rule-engine integration with more providers or an agent-style action node. The IoT Hub connector introduced in 4.3.1.3 will likely be backported to 4.2.x once stabilized. Security patch cadence will continue regardless.

Recent moves

  1. 4d ago

    ThingsBoard 4.3.1.5: CVE batch + edge sync fixes

    4.3.1.5 closes seventeen CVEs across the dependency tree and fixes a Sparkplug metric naming bug and edge sync stability issues. No user-visible features; this is pure security maintenance keeping the 4.3.x branch current.

    View source ↗
  2. 4d ago

    ThingsBoard 4.2.2.5: LTS security backport

    4.2.2.5 backports the same CVE batch from 4.3.1.5 to the LTS line, plus the edge sync strand fix. Confirms ThingsBoard's commitment to keeping the 4.2.x branch security-current for enterprise deployments.

    View source ↗
  3. 20d ago

    ThingsBoard 4.3.1.4 Release

    4.3.1.4 patches another large CVE batch — over thirty in two PRs — alongside minor UI corrections: chart axis tick sizing, a Digital Gauge zero-value validation fix, and a calculated field test running against stale data. All corrections, no new surface area.

    View source ↗
  4. 20d ago

    ThingsBoard 4.2.2.4 Release

    4.2.2.4 is the LTS backport of 4.3.1.4's security batch with a subset of the UI fixes. Same security-maintenance pattern as the prior LTS releases.

    View source ↗
  5. 2mo ago

    ThingsBoard 4.3.1.3 Release

    4.3.1.3 is the most substantive patch release in the trailing window: IoT Hub integration lands in the rule engine, AI model nodes gain structured output support for additional providers with a Vertex AI routing fix, and the transport layer gets integer overflow and queue prefix fixes. The UI receives a meaningful bug sweep — Switch Control widget, mobile layout transitions, WebGL map fallback. This round of additions is incremental but broad.

    View source ↗
  6. 2mo ago

    ThingsBoard 4.2.2.3 Release

    4.2.2.3 backports the IoT Hub and AI model improvements from 4.3.1.3 to the LTS line alongside the security batch, minus some 4.3-specific UI improvements. LTS customers get the core capability additions without the experimental UX surface.

    View source ↗