Cumulusci

Latest version: v4.3.0

Safety actively analyzes 723954 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 8 of 57

3.70.0

- The `retrieve_changes` and `list_changes` tasks now properly exclude metadata types that `SFDX` is unable to process. These include: `AuraDefinition`, `ExperienceResource`, and `LightningComponentResource` by jstvz in https://github.com/SFDO-Tooling/CumulusCI/pull/3443
- The `deploy_remote_site_settings` task has been updated to load the correct Remote Site Settings records for OmniStudio by jofsky in https://github.com/SFDO-Tooling/CumulusCI/pull/3444

3.69.0

Changes 🎉

- Added support for debugging and breakpoints in Playwright-based
Robot Framework by boakley in
https://github.com/SFDO-Tooling/CumulusCI/pull/3408
- Added option for deploy task to remove selected components from the
bundle by jkasturi-sf in
https://github.com/SFDO-Tooling/CumulusCI/pull/3421
- Added documentation for using OmniStudio in Cumulus flows by
bethbrains in https://github.com/SFDO-Tooling/CumulusCI/pull/3427
- Update creation of OmniStudio Remote Site Settings for new
Salesforce domain patterns (e.g. .\*scratch.my.salesforce,
\*.demo.my.salesforce, etc.) by jofsky in
https://github.com/SFDO-Tooling/CumulusCI/pull/3424
- Added --debug flag to the deploy_marketing_cloud_package task by
TheBitShepherd in
https://github.com/SFDO-Tooling/CumulusCI/pull/3430

3.68.1

- Revert a change in parsing config files which was incompatible with some configs

3.68.0

Critical Changes 🎉

- Upgraded Robot Framework from version 4.1.3 to version 6. As with most Robot Framework updates, there are a host of new features and a few deprecated features and backwards incompatibilities. For a complete list consult the [Robot Framework release notes](https://github.com/robotframework/robotframework/releases) in https://github.com/SFDO-Tooling/CumulusCI/pull/3417

Changes 🎉

- Add support for InstallKey, sourceOrg, release keys on 2GP version create by davidmreed in https://github.com/SFDO-Tooling/CumulusCI/pull/3403
- We now support the `Territory2`, `Territory2Model`, `Territory2Type`, and `Territory2Rule` MetaData types. by TheBitShepherd in https://github.com/SFDO-Tooling/CumulusCI/pull/3406
- Add `push_upgrade_org` flow to test in simulated push upgrade environment by davidmreed in https://github.com/SFDO-Tooling/CumulusCI/pull/3286
- Fixed bug preventing the `deploy_omni_studio_site_settings` task from deploying to scratch orgs with the new `.scratch.` domain names by jofsky in https://github.com/SFDO-Tooling/CumulusCI/pull/3411
- All new keychain details are serialized using JSON, not pickle by bethbrains in https://github.com/SFDO-Tooling/CumulusCI/pull/3390
- Snowfakery (upgraded to 3.4) can now generate Event or Meeting Schedules similar to Calendar Apps
- Snowfakery now has a Salesforce.ContentFile feature for generating Content Versions

Issues Fixed 🩴

- Bumped key_size from 2048 to 4096 on advice from a security audit by boakley in https://github.com/SFDO-Tooling/CumulusCI/pull/3389
- Fixed an issue where unknown deploy statuses could cause polling to hang in the deploy_marketing_cloud_package task by TheBitShepherd in https://github.com/SFDO-Tooling/CumulusCI/pull/3394
- Fixed an injection vulnerability related to unquoted csv writers by TheBitShepherd in https://github.com/SFDO-Tooling/CumulusCI/pull/3404

3.67.1

Not secure
Issues Fixed

- We added some javascript files that were missing from the 3.67.0 release

3.67.0

Not secure
Critical Changes

- CumulusCI now supports GitHub Enterprise. (3256)
- CumulusCI will no longer be supporting installations via `brew`. See our docs for the officially supported install method via pipx.(3382)

Changes

- When using Playwright instead of Selenium, we now have limited support for writing keywords in JavaScript. For more information, see the topic "Writing keywords in JavaScript" in the documentation under "Playwright Technology Preview". (3378)
- Auto-load dataset matching org shape name(3384)
- Updated the dependency resolvers used for commit-status builds (2GP and Unlocked Package parallel testing) to allow resolution to "fall back" from release branches like `feature/240` to the repository's main branch.(3386)
- There is a new Playwright-based keyword `Wait until salesforce is ready`. This keyword is automatically called by the Open Test Browser keyword in the SalesforcePlaywright library. In addition to waiting for the page to be rendered, it will auto attempt to detect a classic page on initial render, and automatically switch to a lightning page if one is detected.(3387)
- CumulusCI now supports the `CustomIndex` metadata type.(3391)
- CumulusCI now supports performing source transformations during the `deploy` task, including find-and-replace of user-defined tokens. (3383)
- Includes [Snowfakery 3.3](https://github.com/SFDO-Tooling/Snowfakery/releases/tag/v3.3.0) with new datetime features and find_record optimization.

Issues Fixed

- Fixed a bug when using blank dates in upserts and updates.(3361)
- Fixed an issue where committing changes to a repository above a certain size caused timeouts to occur. (3379)
- CumulusCI now uses the `defusedxml` library to more securely parse xml.(3375)

Page 8 of 57

Links

Releases

Has known vulnerabilities

© 2025 Safety CLI Cybersecurity Inc. All Rights Reserved.