Zum Inhalt springen

Atlantis Updates & Release Notes

4 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge Atlantis, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Atlantis

Atlantis Version 0.48.1: Sicherheitskorrektur für Repo-Allowlist

Version 0.48.1 behebt eine Sicherheitslücke (GHSA-fwc4-2f3p-7qm7), indem das Präfix verankert wird, wenn eine Repo-Allowlist-Regel einen Platzhalter mitten im String enthält.

<!-- Release notes generated using configuration in .github/release.yml at release-0.48 -->

What's Changed

Security changes

Full Changelog: https://github.com/runatlantis/atlantis/compare/v0.48.0...v0.48.1

Thanks to @arpitjain099 for reporting and reviewing this fix, and to @pseudomorph for reviewing.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Atlantis

Atlantis v0.48.0: Plan-Verifizierung und schlanke Images ohne Terraform

Atlantis v0.48.0 hasht den geladenen Apply-Plan, speichert Plan-Ergebnisse vor der Erfolgsmeldung und wendet den verifizierten Plan-Snapshot an, bietet neue schlanke Alpine- und Debian-Slim-Images ohne Terraform/OpenTofu und entfernt veraltete Terraform-Versionen aus den Standard-Images, während ab v0.49.0 die Debian- und Alpine-Images keine gebündelten Terraform- oder OpenTofu-Binaries mehr enthalten.

Atlantis v0.48.0

### Terraform and OpenTofu Binaries Removed from Debian and Alpine Images

Starting with Atlantis v0.49.0, the Debian- and Alpine-based Docker images will no longer include bundled Terraform or OpenTofu binaries.

Users can continue to use Atlantis' automatic binary download functionality to fetch and use the Terraform or OpenTofu versions required by their workflows.

This change allows the Atlantis project to focus its security and maintenance efforts on the Atlantis application and its container images, rather than taking responsibility for the security lifecycle, vulnerability management, and distribution of third-party Terraform and OpenTofu binaries.

Users who require pre-installed binaries can continue to build custom Atlantis images based on the official images.

Highlights

  • Safer plan/apply lifecycle. Atlantis now hashes the loaded apply plan, persists plan results before reporting success, and applies the verified managed-plan snapshot.
  • New slim container images. Alpine and Debian slim images are available without bundled Terraform or OpenTofu, for deployments that provide their own tooling.
  • Terraform and runtime compatibility. End-of-life Terraform versions without security support were removed from the standard images. The bundled versions, Debian and Alpine bases, Go toolchain, OpenTofu, Conftest, and Git LFS were refreshed. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Atlantis

Atlantis v0.47.1: Sicherheitslücke GHSA-rjh2-4xgw-p2hj behoben

Atlantis v0.47.1 behebt eine Sicherheitslücke (GHSA-rjh2-4xgw-p2hj), indem Eingaben aus Pull Requests nicht mehr an eine Shell gelangen können.

<!-- Release notes generated using configuration in .github/release.yml at release-0.47 -->

What's Changed

Security changes

Full Changelog: https://github.com/runatlantis/atlantis/compare/v0.47.0...v0.47.1

Thanks to @krewenki for the security review of this fix, and to @pseudomorph for reviewing.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Atlantis

Atlantis v0.47.0: plan_output bei Drift-Erkennung und --plan-store-dir

Atlantis v0.47.0 nimmt die Commit-SHA in Fehlermeldungen zu Working-Directory-Sperren auf, liefert plan_output bei POST /api/drift/detect, führt --plan-store-dir zur Trennung der Plan-Dateien vom data-dir ein und behebt mehrere Fehler, darunter GitHub-Token-Rotation, Readiness-Probe ohne Web-Authentifizierung und die Akzeptanz von 2xx-Antworten bei HTTP-Webhooks.

<!-- Release notes generated using configuration in .github/release.yml at main -->

What's Changed

Exciting New Features 🎉

Provider GitHub

Bug fixes 🐛

Originalquelle(öffnet in neuem Tab)Problem melden