The latest release of EximeeBPMS 1.4.0 constitutes another step in delivering the changes previously announced in the public product roadmap and on the project’s support page. This version focuses on closing all published security notices for Maven dependencies in the Community Edition, as well as expanding the platform’s capabilities in event-driven architecture, process history control, and the current technological baseline.
In light of these changes, what matters most for regulated institutions is not only the scope of the delivered features, but also the predictability of actions taken and the transparency of communication regarding changes that affect the security, maintenance, and compliance of production environments.
What you should know:
On April 17, 2025, a plan detailing components scheduled for deprecation and changes to be delivered in upcoming releases was published on the project’s Support page. From that moment on, platform development proceeded strictly according to the publicly announced path.
Releases from the 1.3.x line initiated the cleanup of selected platform components and laid the groundwork for subsequent changes, whereas version 1.4.0 executes the final stage of previously announced actions, delivering both functional updates and deprecations communicated to users before.
For institutions subject to compliance requirements, this is of paramount importance—the ability to track changes from announcement to delivery mitigates risks associated with unexpected technological shifts and enables better planning for production environment updates.
One of the areas covered by the changes is CMMN (Case Management Model and Notation), a standard used to model unstructured, ad-hoc business processes. Version 1.4.0 removes:
It is worth noting that development of CMMN was concluded by Camunda as early as 2020, and the standard was also omitted from the architecture of Camunda 8. Similarly, the recommended pattern in EximeeBPMS for unstructured processes has become BPMN 2.0 coupled with microservices architecture.
Version 1.4.0 delivers patches covering vulnerabilities associated with security notices, bringing the security level of the Community Edition to parity with the Commercial Edition.
Combined with existing mechanisms such as Script Guard (a feature that controls and blocks the execution of dangerous or unauthorized scripts within processes) and an ongoing dependency analysis process, this change represents a crucial element in the long-term maintenance of the platform in regulated environments.
From the perspective of security teams, the single most important aspect of this release is the closure of all six published security notices for the Community Edition, resolving a total of 38 CVE vulnerabilities in Maven dependencies. In BPMS-class systems, where processes integrate sensitive financial data, a lack of patch parity between the free and commercial editions often blocks deployments. Therefore, in version 1.4.0, we provide banking architectures with Zero Known Vulnerabilities in Maven dependencies right at the start of migration. As a result, organizations using EximeeBPMS can ground their future development plans on an up-to-date, actively maintained security baseline.
– Robert Mastalerek, Senior Fullstack Developer on the EximeeBPMS team
EximeeBPMS 1.4.0 also introduces native Business Events. This new functionality operates based on the Transactional Outbox pattern—a mechanism that guarantees data consistency by persisting the event in the same database transaction as the business state change. Consequently, it becomes possible to publish business events without the need to build custom integration layers based on process history analysis. Events can be forwarded both to Apache Kafka and to custom publishing mechanisms. This allows the process engine to act as a reliable source of events in architectures built around asynchronous data exchange.
Version 1.4.0 also expands process history configuration options. Administrators can exclude selected process definitions from history while maintaining the active history level for all other processes executed by the engine. This approach allows for better control over stored historical data volume and aligns configurations with organizational data retention requirements.
The 1.4.0 release defines the platform’s current technological baseline:
WebApps remain aligned with the public product roadmap, where details regarding the future direction of EximeeBPMS development are also available.
For teams responsible for compliance, security, and production environment maintenance, version 1.4.0 brings several key benefits:
| Change | Significance for compliance and security |
|---|---|
| Security notices closure | Risk mitigation regarding previously published security notices |
| Business Events | Improved integration with event-driven architectures |
| Selective process history | Greater control over data retention |
| Java 21 / Java 25 | Up-to-date technological baseline |
| Announced removals | Predictable change management process |
Before upgrading to version 1.4.0, special attention should be paid to several changes that may impact existing environments and the migration process:
A detailed description of the upgrade process can be found in the documentation:
The EximeeBPMS 1.4.0 release represents, above all, the consistent delivery of promises and previously announced changes. This version aligns security levels between the Community and Commercial editions while establishing a modern technological baseline that fully meets the rigorous demands of regulated institutions. By enriching the platform with essential compliance-supporting features—such as Business Events and selective process history management—it guarantees organizations greater control, stability, and predictability for their production environments.
Why is version 1.4.0 important for regulated institutions?
Version 1.4.0 focuses on delivering changes previously announced in the public product roadmap and project communications. It includes closing all six published security notices for Maven dependencies in the Community Edition, expanding platform capabilities in event-driven architecture, offering new options for process history management, and establishing a current technological baseline grounded in Java 21 and the Jakarta environment.
What does closing all six security notices for Community Edition mean?
It means delivering patches for all six published security notices regarding Maven dependencies and eliminating 38 CVE vulnerabilities affecting the Community Edition. As a result, the security level of the Community Edition has been brought to parity with the Commercial Edition. Combined with mechanisms like Script Guard and ongoing dependency analysis, this supports the long-term maintenance of regulated environments.
Does version 1.4.0 introduce changes related to CMMN?
Yes. In version 1.4.0, the CMMN engine and associated infrastructure elements—including CMMN-related tables and selected database structures—have been removed. These changes were previously announced in the public product roadmap.
What are Business Events in EximeeBPMS 1.4.0?
Business Events is a new feature that enables the publishing of business events without building custom integration layers based on process history analysis. The mechanism relies on the Transactional Outbox pattern and supports event-driven architectures used in enterprise environments.
What has changed in process history management?
Version 1.4.0 allows specific process definitions to be excluded from history while retaining the active history level for remaining processes run by the engine.
What are the technology requirements for EximeeBPMS 1.4.0?
Java 21 remains the required runtime environment for the platform, and compatibility with Java 25 has been verified in CI processes. EximeeBPMS 1.4.0 runs exclusively in the Jakarta environment. Detailed information on technology requirements can be found in the documentation.
Does version 1.4.0 require changes during migration from 1.3.0?
Yes. Organizations planning an upgrade should pay particular attention to:
A detailed breakdown of these changes is available in the guide Update from 1.3.0 to 1.4.0.
Powered by Consdata
hello@eximeebpms.org
+48 614 151 000
Consdata S.A.
Krysiewicza 9/14
61-825 Poznań
Poland