What elastic/kibana shipped
Written by FoxPlug from public releases; not affiliated with Elastic. An automatic summary of the public release, pull request and commit data of github.com/elastic/kibana. Elastic did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Saved workflows can now declare
settings.run_asto execute as a bound service account, using the existingxpack.security.serviceAccounts.enabledflag. Pull request #292599 - Workflows support shared profile-based access control, letting owners restrict individual workflows to selected users within a space. Pull request #290269
- Fixed parallel step lookups so branches correctly read outputs from their own branch steps instead of getting values from whichever branch wrote last. Pull request #293651
- Datadog connectors can now receive webhook events and emit
datadog.alertwhenmonitor_idandscopesare present. Pull request #291669 - Service accounts are now created with caller-specified roles instead of inheriting creator privileges, with
rolesrequired and non-empty. Pull request #292528 - Agent Builder conversation view now supports export and inspection tools, allowing download of full conversations as structured JSON files. Pull request #291849
- Alerting v2 rule details surface matching action policies including catch-all policies without leaving the rule view. Pull request #293304
- Test subject existence checks now distinguish between immediate DOM presence and waiting for element appearance, eliminating unnecessary waits. Pull request #293378
- SLO CRUD route schemas converted from io-ts to zod with
slo_definition_repositorydecode/encode updated accordingly. Pull request #287930 - Discover now correctly handles mixed TSDB and classic indices when switching from KQL to ESQL view. Pull request #292893
Why it matters
This week brings execution and access control improvements to workflows, better testing performance, and expanded integrations. Datadog webhook support and service account downscoping enhance security and operational flexibility. Conversation export and Alerting v2 improvements make building automation more transparent and observable.
Changelog entry
- Workflows: Saved workflows can declare
settings.run_asto execute as a bound service account usingxpack.security.serviceAccounts.enabledflag Pull request #292599 - Workflows: Added shared profile-based access control allowing owners to restrict workflows to selected users Pull request #290269
- Workflows: Fixed parallel step lookups to correctly read outputs from the reader's own branch Pull request #293651
- Connectors: Added Datadog inbound alert integration to receive webhook events and emit datadog.alert Pull request #291669
- Security: Service accounts now created with caller-specified roles instead of inheriting creator privileges Pull request #292528
- Agent Builder: Conversation and trace export functionality added with download as JSON Pull request #291849
- Alerting v2: Rule details now surface matching action policies including catch-all on artifacts card Pull request #293304
- Alerting: Surface UIAM API key grant failures when apiKeyType is uiam Pull request #292807
- Discover: Handle mixed TSDB and classic indices when switching from KQL to ESQL Pull request #292893
- SLO: Converted CRUD route schemas from io-ts to zod Pull request #287930
New: Workflows execute as service accounts, support profile-based access control, and Datadog webhooks now work. Service accounts can be downscoped, and Agent Builder conversations export to JSON.
This week in Kibana: workflows gain service account execution and profile-based access control for fine-grained permissions. Datadog connectors now receive webhooks, service accounts support downscoping, and parallel steps correctly resolve branch outputs. Agent Builder exports conversations as JSON, and Alerting v2 surfaces matching notification policies. Test subject checks now separate DOM presence from element waits.
Week of September 14, 2026
What shipped
- Jest now uses SWC as its only JavaScript and TypeScript transformer, removing Babel entirely for faster test execution. Pull request #281674
- The
oas_docspackage is now part of the pnpm workspace instead of a separate npm project, simplifying dependency management. Pull request #291649 - Fleet automatically triggers data stream rollover when custom analyzers cause mapping conflicts instead of failing silently. Pull request #291813
- JSM and Opsgenie connectors now truncate oversized message fields to 130 characters instead of failing rule actions entirely. Pull request #291698
- Fleet fixes
ambiguous_conflictfailures when installing packages into multiple spaces by properly handling dashboard asset orphans. Pull request #291648 - Custom integration policy UIs can now opt into a wider Fleet page layout to accommodate complex form layouts. Pull request #291871
- External inference endpoint creation now supports list-type fields displayed as tag inputs. Pull request #290352
- New Terms rules now halve their document fetch batch size when responses exceed Elasticsearch's maximum response size limit. Pull request #290058
- Report generation error messages now provide detailed context when PIT operations fail instead of generic unknown errors. Pull request #258464
- Discover now normalizes invalid time ranges from the URL to defaults during state management. Pull request #290358
Why it matters
This week focused on reliability improvements across Fleet integration management, testing infrastructure, and error handling. The Jest-to-SWC migration speeds up test execution while the workspace restructuring simplifies dependency updates. Multiple fixes to Fleet's package installation and connector behavior reduce silent failures and improve user experience.
Changelog entry
- Jest: Replaced Babel transformer with SWC for JavaScript and TypeScript compilation Pull request #281674
- OAS: Converted
oas_docsfrom npm to pnpm workspace package Pull request #291649 - Fleet: Added automatic data stream rollover for custom analyzer mapping conflicts Pull request #291813
- Connectors: JSM and Opsgenie now truncate oversized message fields to 130 characters Pull request #291698
- Fleet: Fixed
ambiguous_conflicterrors when installing packages into multiple spaces Pull request #291648 - Fleet: Custom integration forms can opt into wider page layout (1200px) Pull request #291871
- External Inference: Added support for list-type fields in endpoint creation Pull request #290352
- Alerting: New Terms rules now batch document fetches when response size exceeds limits Pull request #290058
- Reporting: Improved error reporting for PIT-based report generation failures Pull request #258464
- Discover: Time ranges from URLs are now normalized to valid defaults Pull request #290358
Week 40 shipped: Jest uses SWC now for faster tests, Fleet handles package conflicts better across spaces, and JSM/Opsgenie connectors stop failing on oversized messages.
This week in Kibana: We replaced Babel with SWC for Jest (faster test builds), moved oas_docs into the pnpm workspace (simpler dependency management), fixed Fleet's multi-space package installation conflicts, and improved connector resilience by gracefully handling field size limits. Also upgraded infrastructure tooling across the board.