vjgit96 a277209fe4 ci: push nightly .devX Docker images to langflowai/langflow and fix db-migration-validation image references (#13836)
* ci: push nightly .devX docker images to langflowai/langflow in addition to langflowai/langflow-nightly

Mirrors PyPI behaviour where .devX releases are published under the
'langflow' package name (not 'langflow-nightly'). The Docker nightly
workflow now tags and pushes every nightly image to both repos:

- langflowai/langflow-nightly:{ver}  (existing)
- langflowai/langflow:{ver}          (new — matches PyPI)
- langflowai/langflow-nightly:latest (existing)
- langflowai/langflow:latest         (new)

Same mirroring applied to the base and main-all variants, and to GHCR.

The arch-specific intermediate tags (used to assemble multi-arch
manifests) remain under the '-nightly' repos; only the final merged
manifests are additionally published to the canonical 'langflow' repos.

Fixes: LE-1667

* ci: update db-migration-validation to use canonical langflowai/langflow image

The db-migration-validation workflow was still referencing the old
langflowai/langflow-nightly image for its nightly upgrade step.
Now that .devX images are also pushed to langflowai/langflow (canonical
repo, matching PyPI), update all consumer-side references:

- nightly_build.yml: nightly_tag now passes langflowai/langflow:<tag>
- db-migration-validation.yml: default and shell fallbacks updated to
  langflowai/langflow:latest; inline comments updated to match

The langflowai/langflow-nightly images remain in use as intermediate
arch-specific staging tags inside docker-nightly-build.yml only.

Relates to: LE-1667

* ci: fix stale langflow-nightly package name reference in comment

The nightly is published as canonical .devN pre-releases of langflow /
langflow-base (not as separate langflow-nightly / langflow-base-nightly
packages). Update the generate-shared-tag step comment to accurately
reflect this since the rename that happened in the 1.10 release cycle.

Relates to: LE-1353, LE-1667

* fix(ci): do not set :latest on canonical langflow repo for nightly .devX images

Nightly .devX images should not overwrite the stable :latest tag on
langflowai/langflow. The :latest (and :base-latest) floating tags are
only set on the -nightly repos (langflowai/langflow-nightly), which
are explicitly nightly-only. The canonical langflowai/langflow repo
only receives the versioned tag (e.g. :1.11.0.dev20250522), matching
PyPI behaviour where langflow==1.11.0.dev20250522 is published but
never becomes the 'latest' release index entry.

Addresses PR review comment from @jordanrfrazier.

Relates to: LE-1667

* fix(ci): prevent shell injection from inputs.nightly_tag in db-migration-validation

Pass inputs.nightly_tag through an env: block and reference it as
$INPUT_NIGHTLY_TAG in the shell script rather than expanding the
GitHub Actions expression directly inside run:. Direct expansion of
${{ inputs.* }} in shell scripts allows an attacker-controlled input
to inject arbitrary shell commands (CWE-78).

Flagged by CodeRabbit security review.

Relates to: LE-1667
2026-06-25 19:16:10 -07:00
2026-06-09 13:16:48 -07:00
2025-03-20 00:05:55 +00:00
2026-04-23 17:49:53 -07:00
2024-06-04 09:26:13 -03:00
2026-06-23 16:12:43 -07:00

Langflow logo

Release Notes PyPI - License PyPI - Downloads Twitter YouTube Channel Discord Server Ask DeepWiki

Langflow is a powerful platform for building and deploying AI-powered agents and workflows. It provides developers with both a visual authoring experience and built-in API and MCP servers that turn every workflow into a tool that can be integrated into applications built on any framework or stack. Langflow comes with batteries included and supports all major LLMs, vector databases and a growing library of AI tools.

Highlight features

  • Visual builder interface to quickly get started and iterate.
  • Source code access lets you customize any component using Python.
  • Interactive playground to immediately test and refine your flows with step-by-step control.
  • Multi-agent orchestration with conversation management and retrieval.
  • Deploy as an API or export as JSON for Python apps.
  • Deploy as an MCP server and turn your flows into tools for MCP clients.
  • Observability with LangSmith, LangFuse and other integrations.
  • Enterprise-ready security and scalability.

🖥️ Langflow Desktop

Langflow Desktop is the easiest way to get started with Langflow. All dependencies are included, so you don't need to manage Python environments or install packages manually. Available for Windows and macOS.

📥 Download Langflow Desktop

Quickstart

Requires Python 3.103.14 and uv (recommended package manager).

Install

From a fresh directory, run:

uv pip install langflow -U

The latest Langflow package is installed. For more information, see Install and run the Langflow OSS Python package.

Run

To start Langflow, run:

uv run langflow run

Langflow starts at http://127.0.0.1:7860.

That's it! You're ready to build with Langflow! 🎉

📦 Other install options

Run from source

If you've cloned this repository and want to contribute, run this command from the repository root:

make run_cli

For more information, see DEVELOPMENT.md.

Docker

Start a Langflow container with default settings:

docker run -p 7860:7860 langflowai/langflow:latest

Langflow is available at http://localhost:7860/. For configuration options, see the Docker deployment guide.

🛡️ Security

For security information, see our Security Policy.

🚀 Deployment

Langflow is completely open source and you can deploy it to all major deployment clouds. To learn how to deploy Langflow, see our Langflow deployment guides.

Stay up-to-date

Star Langflow on GitHub to be instantly notified of new releases.

Star Langflow

👋 Contribute

We welcome contributions from developers of all levels. If you'd like to contribute, please check our contributing guidelines and help make Langflow more accessible.


Star History Chart

❤️ Contributors

langflow contributors

Description
Langflow is a powerful tool for building and deploying AI-powered agents and workflows.
Readme MIT 2.3 GiB
Languages
Python 64.5%
TypeScript 23.4%
JavaScript 11.4%
CSS 0.3%
Makefile 0.2%
Other 0.1%