Zum Inhalt springen

Hashicorp Release Notes

54 Einträge aus 2 Quellen. Zuletzt aktualisiert:

Folge Hashicorp, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-beta1 mit store-Block und Modul-Imports

Terraform 1.16.0-beta1 bringt u. a. gespeicherte private Provider-Daten, den store-Block in terraform_data, import-Blöcke in Modulen und -json-Ausgabe für state show und workspace list.

1.16.0-beta1 (July 23, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260715 mit s390x und caller-Symbol

Terraform 1.16.0-alpha20260715 bringt u. a. gespeicherte private Provider-Daten, den store-Block in terraform_data, import-Blöcke in Modulen, Builds für Linux s390x und ein neues caller-Symbol in der Action-Konfiguration.

1.16.0-alpha20260715 (July 15, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260708 mit s390x und caller-Symbol

Terraform 1.16.0-alpha20260708 bringt u. a. gespeicherte private Provider-Daten, den store-Block in terraform_data, import-Blöcke in Modulen, Builds für Linux s390x und ein neues caller-Symbol in der Action-Konfiguration.

1.16.0-alpha20260708 (July 08, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.15.8: init-Fehler bei Service-Discovery-Alias behoben

Terraform 1.15.8 behebt einen terraform init-Fehler bei Providern über einen Service-Discovery-Alias des Backends und ändert die Ausgabe sowie die Reihenfolge von Ereignissen bei Provider- und Modulinstallation.

1.15.8 (July 8, 2026)

BUG FIXES:

  • Fix terraform init error when installing providers sourced from a service-discovery alias advertised by the configured backend (such as localterraform.com)

NOTES:

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38838)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38838)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260706 mit s390x und caller-Symbol

Terraform 1.16.0-alpha20260706 bringt u. a. gespeicherte private Provider-Daten, den store-Block in terraform_data, import-Blöcke in Modulen, Builds für Linux s390x und ein neues caller-Symbol in der Action-Konfiguration.

1.16.0-alpha20260706 (July 06, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260701

Die Alpha-Version bringt unter anderem einen store-Block in terraform_data für ephemere und sensible Werte, import-Blöcke in Modulen, Builds für Linux s390x, JSON-Ausgabe für workspace list und on_failure-Modi für Resource Action Triggers.

1.16.0-alpha20260701 (July 01, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260626

Die Alpha-Version bringt unter anderem einen store-Block in terraform_data für ephemere und sensible Werte, import-Blöcke in Modulen, Builds für Linux s390x, JSON-Ausgabe für workspace list und on_failure-Modi für Resource Action Triggers.

1.16.0-alpha20260626 (June 26, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260624

Die Alpha-Version bringt unter anderem einen store-Block in terraform_data für ephemere und sensible Werte, import-Blöcke in Modulen, Builds für Linux s390x, JSON-Ausgabe für workspace list und on_failure-Modi für Resource Action Triggers.

1.16.0-alpha20260624 (June 24, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.15.7

Version 1.15.7 ergänzt Nebenläufigkeitssicherheit für configs.Parser und SourceBundleParser und behebt die Validierung von Variablen in Submodulen während init.

1.15.7 (June 24, 2026)

BUG FIXES:

  • Add concurrency safety to configs.Parser and SourceBundleParser (#38745)

  • Fix submodule variable validation during init (#38770)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.0.3: Sicherheitskorrekturen und ACL-Änderung bei LIST

Vault 2.0.3 schließt mehrere Sicherheitslücken, darunter eine LIST-ACL-Umgehung bei Pfaden mit abschließendem Schrägstrich, leitet nicht-kanonische Pfade um und ergänzt eine Beta-Unterstützung für AI Agents (Enterprise).

SECURITY:

  • auth/radius: Added case_insensitive_names toggle to prevent username collisions and enable case-insensitive user handling.
  • core/acl: Fix LIST ACL bypass where a trailing-slash request could skip a more-specific deny rule.
  • core: Use constant-time recovery token comparison
  • secrets/spiffe (enterprise): Ensure template values are properly escaped.
  • transform (enterprise): Add appropriate db specific quoting and escaping.

CHANGES:

  • auth/cf: Update plugin to v0.23.1
  • core/acl: LIST requests with a trailing slash now correctly respect more-specific deny policies. Previously, a deny on path "kv/*" { deny } could be bypassed for LIST kv/private/ if a broader allow path "kv/*" also existed. Policies relying on the previous (incorrect) behavior may now be denied.
  • core: Vault will now redirect non-canonicalized paths (containing /./, /../, or //) to a cleaned path, instead of rejecting these requests
  • secrets/azure: Update plugin to v0.26.5+ent

FEATURES:

  • AI Agent Support (Beta/Enterprise): Adds beta support for first-class AI agents. Adds an Agent Registry to register agents, and adds support for using Vault as an OAuth resource server for registered agent entities. When configured, allows OAuth 2.0 JWTs to be used to directly authorize …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260617

Die Alpha-Version bringt unter anderem einen store-Block in terraform_data für ephemere und sensible Werte, import-Blöcke in Modulen, Builds für Linux s390x, JSON-Ausgabe für workspace list und on_failure-Modi für Resource Action Triggers.

1.16.0-alpha20260617 (June 17, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.15.6

Version 1.15.6 behebt unter anderem falsch gelistete removed-Ressourcen in planned_values der JSON-Plandatei, einen Panic in console, Exit-Codes bei variablenbezogenen Fehlern und zwei Randfälle bei der Modulinstallation.

1.15.6 (June 10, 2026)

BUG FIXES:

  • Fixed an issue where resources being removed from state via removed block were incorrectly listed under planned_values in json representations of the plan file. (#38665)

  • console: Fixed a panic caused by evaluating an expression involving deprecated values (#38676)

  • Fix exit code for plan, query, and refresh commands for variable-related errors (#38685)

  • Fix two module installation edge cases with null and sensitive/ephemeral module sources (#38704)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.0.2: cap_ipc_lock entfernt, SSH-RSA-Limit

Vault 2.0.2 entfernt die Capability cap_ipc_lock in Containern (disable_mlock = true wird empfohlen), begrenzt RSA-Schlüssel bei secrets/ssh auf 8192 Bit, hebt Go auf 1.26.4 an und behebt Fehler bei Plugin-Signaturen und im Transit-UI.

BREAKING CHANGES:

  • containers: Remove cap_ipc_lock capability on vault at build time to allow running Vault in common container runtimes. Vault in containers will no longer be able to call mlock() to lock memory. Operators should set disable_mlock = true in Vault's configuration. Runtime operators are advised to disable swapping to guarantee data safety.
  • secrets/ssh: RSA key sizes are now limited to a maximum size of 8192 bits addressing CVE-2026-39829

CHANGES:

  • core: Bump Go version to 1.26.4
  • secrets/azure (enterprise): Update plugin to v0.26.4+ent

BUG FIXES:

  • plugins: Fix plugin signature verification failure with expired pgp key when registering a plugin.
  • ui/transit: Fix key version dropdown selected state when editing a transit key.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260603

Die Alpha-Version bringt unter anderem PlannedPrivate-Daten für Provider, einen store-Block in terraform_data, import-Blöcke in Modulen, Builds für Linux s390x und -json für workspace list und terraform state show.

1.16.0-alpha20260603 (June 03, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.15.5

Version 1.15.5 unterstützt Modulversionen, die zu null evaluieren (bei dynamischen Modulquellen), und behebt einen Absturz bei init für Module mit leerer Quelle.

1.15.5 (May 27, 2026)

ENHANCEMENTS:

  • Support for module version evaluating to null (in the context of dynamic module sources) (#38632)

BUG FIXES:

  • Fix crash on init for modules with empty source (#38628)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.15.4

Version 1.15.4 liefert Builds für Linux s390x (zLinux) und verhindert, dass bei init Provider-Binaries in symbolisch verlinkte Verzeichnisse installiert werden.

1.15.4 (May 20, 2026)

NEW FEATURES:

  • We now produce builds for Linux s390x (zLinux) (#38615)

BUG FIXES:

  • init: Prevent provider binaries from being installed into symlinked directories (#38611)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.0.1: Sicherheitsupdates und IPC_LOCK in Containern

Vault 2.0.1 setzt die Capability cap_ipc_lock beim Build, sodass Container-Runtimes IPC_LOCK ergänzen müssen, aktualisiert mehrere Abhängigkeiten wegen Sicherheitslücken und verlangt für das Zusammenführen von Identity-Entities die sudo-Capability.

BREAKING CHANGES:

  • containers: set cap_ipc_lock capability on vault at build time. Container runtimes will need to add IPC_LOCK capabilities when running the vault container.

SECURITY:

  • api: Update golang.org/x/net to resolve GO-2026-4918"
  • core/identity: reject wildcards in rendered identity templates
  • core: Resolve GHSA-j88v-2chj-qfwx by removing our dependency on github.com/jackc/pgx/v3 and github.com/jackc/pgx/v4
  • core: Update github.com/Azure/go-ntlmssp to fix security vulnerability v0.1.1.
  • core: Update github.com/apache/thrift to fix security vulnerability GHSA-wf45-q9ch-q8gh
  • core: Update github.com/jackc/pgx/v5 to fix security vulnerability GHSA-j88v-2chj-qfwx.
  • core: Update golang.org/x/net to resolve GO-2026-4918"
  • core: Validate both path and file_path cannot be empty for requests to sys/audit/{path}
  • sdk: Resolve GHSA-j88v-2chj-qfwx by removing our dependency on github.com/jackc/pgx/v3 and github.com/jackc/pgx/v4
  • sdk: Update github.com/Azure/go-ntlmssp to fix security vulnerability v0.1.1.
  • sdk: Update github.com/jackc/pgx/v5 to fix security vulnerability GHSA-j88v-2chj-qfwx.
  • sdk: Update golang.org/x/net to resolve GO-2026-4918"

CHANGES:

  • auth/jwt: Update plugin to v0.26.3
  • core: Bump Go version to 1.26.3
  • identity: Require sudo capability to invoke the identity entity merge API endpoint (identity/entity/merge).
  • secrets/azure: Update plugin to v0.26.2+ent …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-alpha20260513

Die Alpha-Version bringt PlannedPrivate-Daten für Provider, einen store-Block in terraform_data, Builds für Linux s390x und -json-Ausgabe für workspace list und terraform state show, außerdem wird bastion_host_key des Provisioners nun korrekt angewendet.

1.16.0-alpha20260513 (May 13, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.0.0: Docker-Helper-Migration und Sicherheitsfixes

Vault 2.0.0 migriert die Docker-Helper im SDK auf github.com/moby/moby als Breaking Change und enthält zahlreiche Sicherheitskorrekturen, etwa zu AWS-Auth-Caching, Zertifikatserneuerung und Authorization-Header.

BREAKING CHANGES:

  • sdk/helpers/docker: Migrate docker helpers from github.com/docker/docker to github.com/moby/moby. This was necessary as github.com/docker/docker is no longer maintained. Resolves GHSA-x744-4wpc-v9h2 and GHSA-pxq6-2prw-chj9.

SECURITY:

  • Upgrade cloudflare/circl to v1.6.3 to resolve CVE-2026-1229
  • Upgrade filippo.io/edwards25519 to v1.1.1 to resolve GO-2026-4503
  • api/auth/gcp: Update go.opentelemetry.io/otel/sdk to fix CVE-2026-39883.
  • api/auth: Update github.com/go-jose/go-jose to fix security vulnerability CVE-2026-34986 and GHSA-78h2-9frx-2jm8.
  • auth/aws: fix an issue where a user may be able to bypass authentication to Vault due to incorrect caching of the AWS client
  • auth/cert: ensure that the certificate being renewed matches the certificate attached to the session.
  • core: Correctly remove any Vault tokens from the Authorization header when this header is forwarded to plugin backends. The header will only be forwarded if "Authorization" is explicitly included in the list of passthrough request headers.
  • core: Resolve GO-2026-4518 and GHSA-jqcq-xjh3-6g23 by upgrading to github.com/jackc/pgx/v5
  • core: Update github.com/aws/aws-sdk-go-v2/ to fix security vulnerability GHSA-xmrv-pmrh-hhx2.
  • core: Update github.com/go-jose/go-jose to fix security vulnerability CVE-2026-34986 and GHSA-78h2-9frx-2jm8.
  • core: Update github.com/hashicorp/go-getter to fix security vulnerability GHSA-92mm-2pjq-r785. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 1.21.4: Sicherheitsupdates und Verbesserungen

Vault 1.21.4 aktualisiert Abhängigkeiten wegen Sicherheitslücken, hebt Go auf 1.25.7 an, entfernt das Massenlöschen von Secrets Engines in der UI und bringt Verbesserungen sowie Fehlerbehebungen, vor allem für Enterprise.

SECURITY:

  • Upgrade cloudflare/circl to v1.6.3 to resolve CVE-2026-1229
  • Upgrade filippo.io/edwards25519 to v1.1.1 to resolve GO-2026-4503
  • vault/sdk: Upgrade cloudflare/circl to v1.6.3 to resolve CVE-2026-1229
  • vault/sdk: Upgrade go.opentelemetry.io/otel/sdk to v1.40.0 to resolve GO-2026-4394

CHANGES:

  • core: Bump Go version to 1.25.7
  • mfa/duo: Upgrade duo_api_golang client to 0.2.0 to include the new Duo certificate authorities
  • ui: Remove ability to bulk delete secrets engines from the list view.

IMPROVEMENTS:

  • core/seal: Enhance sys/seal-backend-status to provide more information about seal backends.
  • secrets/kmip (Enterprise): Obey configured best_effort_wal_wait_duration when forwarding kmip requests.
  • secrets/pki (enterprise): Return the POSTPKIOperation capability within SCEP GetCACaps endpoint for better legacy client support.

BUG FIXES:

  • core (enterprise): Buffer the POST body on binary paths to allow re-reading on non-logical forwarding attempts. Addresses an issue for SCEP, EST and CMPv2 certificate issuances with slow replication of entities
  • core/identity (enterprise): Fix excessive logging when updating existing aliases
  • core/managed-keys (enterprise): client credentials should not be required when using Azure Managed Identities in managed keys.
  • plugins (enterprise): Fix bug where requests to external plugins that modify storage weren't populating the X-Vault-Index response header. …

Originalquelle(öffnet in neuem Tab)Problem melden