CARVIEW |
Select Language
HTTP/2 200
date: Thu, 31 Jul 2025 10:49:00 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"b56e50ffabfa3f039698b158e2673f5d"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: no-referrer-when-downgrade
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=rT9iKuPQ5Y6HHEh18Y7EFzTuGAd9fxI6V%2BOBruui2xu81M3BI8%2BeCouTtHXhX6ajPskBWwVANkdMz8W%2FAnwwEkXWVHFIWY4ikPpmMDMQ7fOn0WDG877a3IeAhkGceRtKjtoSwEr8Qy6jA4sgnMpP3S0Y24ayPzPm3zQntzgcCT52OJzEQIt8CY9D%2BhztOx5PsIw6Zy%2FVlzbd9hHgCPWPjYfzlCynBPuHs0ZBWxDwQ1v5SSZR1fI4Hi53vaqfRW%2F5GUUHRiC6kMl9Qethg6cmVw%3D%3D--MqSjWdeotxuEui91--oQXfN%2BFW1Yx9cDWxWPbwgg%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.522499745.1753958939; Path=/; Domain=github.com; Expires=Fri, 31 Jul 2026 10:48:59 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Fri, 31 Jul 2026 10:48:59 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: 94BA:21A23A:872FD7:A2734C:688B4A1B
Releases · spiffe/spire · GitHub
01 Jul 21:39
17 Jun 21:39
Loading
17 Jun 20:49
Loading
07 May 15:40
Loading
21 Mar 19:39
Loading
13 Feb 21:08
Loading
12 Dec 19:48
Loading
24 Oct 20:08
Loading
13 Sep 18:45
Loading
Skip to content
Navigation Menu
{{ message }}
-
Notifications
You must be signed in to change notification settings - Fork 516
Releases: spiffe/spire
Releases · spiffe/spire
v1.12.4
2433513
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Added
k8s_configmap
BundlePublisher plugin (#6105, #6139)- UpstreamAuthority.SubscribeToLocalBundle RPC to stream updates in the local trust bundle (#6090)
- Integration tests running on ARM64 platform (#6059)
- The OIDC Discovery Provider can now read the trust bundle from a file (#6025)
Changed
- The "Container id not found" log message in the
k8s
WorkloadAttestor has been lowered to Debug level (#6128) - Improvements in lookup performance for entries (#6100, #6034)
- Agent no longer pulls the bundle from
trust_bundle_url
if it is not required (#6065)
Fixed
Assets 14
- sha256:fb1f04c7dd82422e1d8cc55e2dedff65eda3d1f1fb40a787c5b1b6309d46436f50.9 MB
2025-07-01T21:39:45Z - sha256:566b4a403d52f814689da61f705615d31db1a9dc137552b280680711b9f79906103 Bytes
2025-07-01T21:39:46Z - sha256:f42725fdd3fe738eefc99df5a97c4dd5375224efd8bd4dd2f891c90229499fc146 MB
2025-07-01T21:39:45Z - sha256:fa26bd9db21a492c753b5afdca262ef0d12e4121eba727c1485b183a065c72e9103 Bytes
2025-07-01T21:39:46Z - sha256:6dcb8f0e4aec63622f75c3e974c1ed45ec78f62b7cabc7286dd854612d4b6fdb51.6 MB
2025-07-01T21:39:45Z - sha256:8b9037f5e6fb99aad2d1b896f18e9dacb9568d90aada6c25797caa32df9b9a12167 Bytes
2025-07-01T21:39:46Z - sha256:93270cf63511d0a0e6a1e7ca9a4f58856d4cbc6b088390779d2119b14e7f10d85.43 MB
2025-07-01T21:39:45Z - sha256:ab79230f9dfde8e31c26e8e42610b7fef12b84f13a8c5df36ed0a7f19aca69d3110 Bytes
2025-07-01T21:39:46Z - sha256:b2dc787de5bb1ed79cee83cd24957454caf6bc7a4b693a132ccf50a4d60ce9764.99 MB
2025-07-01T21:39:46Z - sha256:401166daf5f8d4ed998c9dad8f71f6a020e2416800df341de80f46dbf02cf5aa110 Bytes
2025-07-01T21:39:47Z -
2025-07-01T20:12:32Z -
2025-07-01T20:12:32Z - Loading
v1.12.3
Compare
Security
- Fixed an issue in spire-agent where the WorkloadAPI.ValidateJWTSVID endpoint did not enforce the presence of the exp (expiration) claim in JWT-SVIDs, as required by the SPIFFE specification.
This vulnerability has limited impact: by default, SPIRE does not issue JWT-SVIDs without an expiration claim. Exploitation would require federating with a misconfigured or non-compliant trust domain.
Thanks to Edoardo Geraci for reporting this issue.
Assets 14
v1.11.3
Compare
Security
- Fixed an issue in spire-agent where the WorkloadAPI.ValidateJWTSVID endpoint did not enforce the presence of the exp (expiration) claim in JWT-SVIDs, as required by the SPIFFE specification.
This vulnerability has limited impact: by default, SPIRE does not issue JWT-SVIDs without an expiration claim. Exploitation would require federating with a misconfigured or non-compliant trust domain.
Thanks to Edoardo Geraci for reporting this issue.
Assets 14
v1.12.2
v1.12.1
162778a
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Added
- Support for Unix sockets in trust bundle URLs (#5932)
- Documentation improvements and additions (#5989, #6012)
Changed
sql_transaction_timeout
replaced byevent_timeout
and value reduced to 15 minutes (#5966)- Experimental events-based cache performance improvements by batch fetching updated entries (#5970)
- Improved error messages when retrieving CGroups (#6030)
Fixed
- Corrected invalid
user-agent
value in OIDC Discovery Provider debug logs (#5981)
Assets 14
v1.12.0
26c063b
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Added
- Support for any S3 compatible object storage such as MinIO in the
aws_s3
BundlePublisher plugin (#5757) - Support for Rego V1 in the authorization policy engine (#5769)
- Support for SAN-based selectors in the
x509pop
NodeAttestor plugin (#5775)
Changed
- Agents now use the SyncAuthorizedEntries API for periodically synchronization of authorized entries by default (#5906)
- Timestamps in logs are now formatted to include nanoseconds (#5798)
- Improved entry lookup performance in NewJWTSVID and BatchNewX509SVID server RPCs (#5819)
- Increased the maximum number of idle database connections to 100 (#5853)
- The maximum idle time per database connection is now set to 30 seconds (#5853)
- Small documentation improvements (#5873, #5876)
- The experimental events-based cache now supports reading events from read-only replicas when data staleness is tolerated, enhancing read performance (#5911)
- The
use_legacy_downstream_x509_ca_ttl
server setting is now set to false by default (#5917)
Deprecated
use_sync_authorized_entries
experimental agent setting (#5906)use_legacy_downstream_x509_ca_ttl
server setting (#5917)
Removed
- The deprecated
k8s_sat
NodeAttestor plugin (#5703)
Fixed
- Issue where agents did not receive entry updates when new entries with the same entry ID were created while
use_sync_authorized_entries
was enabled (#5764)
Assets 14
v1.11.2
eaffdfa
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Added
gcp_secretmanager
SVIDStore plugin now supports specifying the regions where secrets are created (#5718)- Support for expanding environment variables in the OIDC Discovery Provider configuration (#5689)
- Support for optionally enabling
trust_domain
label for all metrics (#5673) - The JWKS URI returned in the discovery document can now be configured in the OIDC Discovery Provider (#5690)
- A server path prefix can now be specified in the OIDC Discovery Provider (#5690)
Changed
Fixed
- Regression in the hydration of the experimental event-based cache that caused a delay in availability (#5842)
- Do not log an error when the Envoy SDS v3 API connection has been closed cleanly (#5835)
- SVIDStore plugins to properly parse metadata in entry selectors containing ':' characters (#5750)
- Compatibility with deployments that use a server port other than 443 when the
jwt_issuer
configuration is set in the OIDC Discovery Provider (#5690) - Domain verification is now properly done when setting the
jwt_issuer
configuration in the OIDC Discovery Provider (#5690)
Security
- Fixed to properly call the CompareObjectHandles function when it's available on Windows systems, as an extra security measure in the peertracker (#5749)
Assets 14
v1.11.1
32cc98e
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Added
- The Go based text/template engine used in various plugins has been extended to include a set of functions from the SPRIG library (#5593, #5625)
- The JWT-SVID cache in the agent is now configurable (#5633)
- The JWT issuer is now configurable in the OIDC Discovery Provider (#5657)
Changed
- CA journal now relies on the authority ID instead of the issued time when updating the status of keys (#5622)
Fixed
- Spelling and grammar fixes (#5571)
- Handling of IPv6 address consistently for the binding address of the server and health checks (#5623)
- Link to Telemetry documentation in the Contributing guide (#5650)
- Handling of registration entries with revision number 0 when the agent syncs entries with the server (#5680)
Known Issues
Assets 14
v1.11.0
ca35234
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Added
- Support for forced rotation and revocation (https://github.com/orgs/spiffe/projects/21)
- New EJBCA UpstreamAuthority plugin for SPIRE Server (#5378)
- Support for variables in templates contained in the config file (#5576)
- Support for the configuration validation RPC on all built-in plugins (#5303)
- Improved logging when built-in plugins panic (#5476)
- Improved CPU and memory resource usage for concurrent Kubernetes Workload attestation (#5408)
- Documentation additions and improvements (#5589, #5588, #5499, #5433, #5430, #5269)
Changed
- SPIRE Agent LRU identity cache is now unconditionally enabled. The LRU size can be controlled via the
x509_svid_cache_max_size
configuration option. (#5383, #5531) - Entry API RPCs return per-entry InvalidArgument status when creating/updating malformed entries (#5506)
- Support for CGroups v2 in K8s and Docker workload attestors is now enabled by default (#5454)
Removed
- Deprecated -ttl flag from the SPIRE Server
entry create
andentry update
commands (#5483) - Official support for MySQL 5.X. While SPIRE may continue to work with this version, no explicit testing will be performed by the project (#5487)
Fixed
Assets 14
2 people reacted
v1.10.4
9c4d83a
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Compare
Fixed
- Add missing commits to spire-plugin-sdk and spire-api-sdk releases (spiffe/spire-api-sdk#66, spiffe/spire-plugin-sdk#39)
Assets 14
Previous Next
You can’t perform that action at this time.