PackageTrack
Sign in Get early access

github.com/bitnami/sealed-secrets

v0.39.1 #444 most downloaded on Go modules bitnami/sealed-secrets

What this package is like to depend on

Last release 4 days ago

20 Aug 2026

Ships unpredictably

gaps range from 8 days to 8.2 years

Nearly every release is documented

notes for 17 of 18 stable releases

Nothing withdrawn

no release was ever pulled

9 years old

43 releases · first in 2017

32 releases in the last 12 months

see the full history below

Release timeline

43 releases · Jun 2017 to Aug 2026
2018 2019 2020 2021 2022 2023 2024 2025 2026
Release Pre-release

Releases

latest 43
  1. v0.39.2-0.20260820085735-e27ce45b1626 20 Aug 2026 pre-release

    Nothing published for this version

  2. v0.39.1 20 Aug 2026
    Release notes
    • Bump Golang to 1.26.7 (#2029)
    • Bump Golang to 1.26.6 (#2028)
    • Bump golang.org/x/crypto from 0.54.0 to 0.55.0 (#2026)
    • Bump github.com/onsi/ginkgo/v2 from 2.32.0 to 2.32.1 (#2027)
    • test(controller): fix flaky TestReadKey RSA key comparison (#2021)
    Open source →
  3. v0.39.1-0.20260819105146-74d25c0d05ae 19 Aug 2026 pre-release

    Nothing published for this version

  4. v0.39.1-0.20260819080030-08bbee246d74 19 Aug 2026 pre-release

    Nothing published for this version

  5. v0.39.1-0.20260818095852-070ad1668aae 18 Aug 2026 pre-release

    Nothing published for this version

  6. v0.39.0 18 Aug 2026
    Release notes
    • [Security] fix: stop /v1/verify from acting as a decryption oracle (#2019)
    • fix(controller): start HTTP early for large additional-namespaces lists (#2018)
    • Rate-limit the /v1/rotate endpoint (#1971)
    • test(controller): poll for server readiness instead of sleeping (#2010)
    • Bump github.com/prometheus/client_golang from 1.23.2 to 1.24.1 (#2016)
    • Bump k8s.io/code-generator from 0.36.2 to 0.36.3 (#2014)
    • Bump github.com/mattn/go-isatty from 0.0.23 to 0.0.24 (#2011)
    • Bump k8s.io/client-go from 0.36.2 to 0.36.3 (#2012)
    • Bump github.com/mattn/go-isatty from 0.0.22 to 0.0.23 (#2009)
    • Bump golang.org/x/crypto from 0.53.0 to 0.54.0 (#2007)
    • Bump distroless/static from 3592aa8 to 9197324 in /docker (#2008)
    • Allow setting hostUsers on deployment (#1978)
    • Add --metrics-omit-secret-labels to skip per-SealedSecret labels on condition_info (#1972)
    • Revert ArtifactHub repository metadata OCI push (#2005)
    Open source →
  7. v0.38.5-0.20260817105023-66db186e6b35 17 Aug 2026 pre-release

    Nothing published for this version

  8. v0.38.5-0.20260817100024-7f4a573e5250 17 Aug 2026 pre-release

    Nothing published for this version

  9. v0.38.5-0.20260817062356-1c69578c1cb0 17 Aug 2026 pre-release

    Nothing published for this version

  10. v0.38.5-0.20260811074640-0f805b98134a 11 Aug 2026 pre-release

    Nothing published for this version

  11. v0.38.5-0.20260729101128-de72a97b196d 29 Jul 2026 pre-release

    Nothing published for this version

  12. v0.38.5-0.20260729085440-fb7da1e9ba98 29 Jul 2026 pre-release

    Nothing published for this version

  13. v0.38.5-0.20260722095228-15aa43988fb0 22 Jul 2026 pre-release

    Nothing published for this version

  14. v0.38.5-0.20260715105451-159d530eaf3f 15 Jul 2026 pre-release

    Nothing published for this version

  15. v0.38.5-0.20260713075054-ce8e0726a451 13 Jul 2026 pre-release

    Nothing published for this version

  16. v0.38.5-0.20260706071940-6a6e888bc866 06 Jul 2026 pre-release

    Nothing published for this version

  17. v0.38.5-0.20260703130945-d6bd5908cc05 03 Jul 2026 pre-release

    Nothing published for this version

  18. v0.38.4 03 Jul 2026
    Release notes
    • Incomplete release for credentials problems
    Open source →
  19. v0.38.3 03 Jul 2026
    Release notes
    • Imcomplete release for credentials problems
    Open source →
  20. v0.38.2 03 Jul 2026
    Release notes
    • Publish Artifact Hub repository metadata for verified publisher status (#2000)
    • Add Artifact Hub badge to README (#1999)
    • Bump github.com/onsi/ginkgo/v2 from 2.30.0 to 2.32.0 (#1998)
    • Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 (#1997)
    • Bump k8s.io/client-go from 0.36.1 to 0.36.2 (#1996)
    • Bump k8s.io/api from 0.36.1 to 0.36.2 (#1994)
    • Bump github.com/onsi/gomega from 1.41.0 to 1.42.0 (#1995)
    • Bump k8s.io/code-generator from 0.36.1 to 0.36.2 (#1993)
    Open source →
  21. v0.38.2-0.20260702134948-33b890d5f87d 02 Jul 2026 pre-release

    Nothing published for this version

  22. v0.38.2-0.20260701063634-183e91c2fb21 01 Jul 2026 pre-release

    Nothing published for this version

  23. v0.38.2-0.20260624122139-5e4abed99401 24 Jun 2026 pre-release

    Nothing published for this version

  24. v0.38.2-0.20260624111036-792723c21f35 24 Jun 2026 pre-release

    Nothing published for this version

  25. v0.38.2-0.20260618131546-20c250b253b1 18 Jun 2026 pre-release

    Nothing published for this version

  26. v0.38.1 18 Jun 2026
    Release notes
    • Incomplete release for credentials problems
    Open source →
  27. v0.38.0 18 Jun 2026
    Release notes
    • feat: add ppc64le architecture support (#1973)
    • Adding default prometheusRule in helmChart to watch out of sync secrets (#1980)
    • Update security context defaults to comply with restricted pod security standard profile (#1981)
    • fix: add mutex locking to KeyRegistry to prevent data races (#1905)
    • Bump Golang to 1.26.4 (#1987)
    • Migrate all bitnami-labs references to bitnami org (#1983)
    • Change oci registry for publishing the chart (#1970)
    • Revert "Fix oci push" (#1979)
    • Bump golang.org/x/crypto from 0.52.0 to 0.53.0 (#1984)
    • Bump github.com/onsi/ginkgo/v2 from 2.29.0 to 2.30.0 (#1985)
    • Bump golang.org/x/crypto from 0.51.0 to 0.52.0 (#1977)
    • Bump github.com/onsi/ginkgo/v2 from 2.28.3 to 2.29.0 (#1976)
    • Bump github.com/onsi/gomega from 1.40.0 to 1.41.0 (#1975)
    Open source →
  28. v0.37.1-0.20260618094544-dc9f8fc1eb52 18 Jun 2026 pre-release

    Nothing published for this version

  29. v0.37.1-0.20260618092210-8ba4b5b27f98 18 Jun 2026 pre-release

    Nothing published for this version

  30. v0.37.1-0.20260617054857-fddaab340509 17 Jun 2026 pre-release

    Nothing published for this version

  31. v0.37.1-0.20260615120210-b7f26263b036 15 Jun 2026 pre-release

    Nothing published for this version

  32. v0.7.0 21 Mar 2018
    Release notes

    Big change for this release is the switch to per-key encrypted values.

    • ("Keys" as in "object key/value", not as in "encryption key". English is hard.)*
    • Previously we generated a single big encrypted blob for each Secret, now we encrypt each value in the Secret separately, with the keys in plain text. This allows:
      • Existing keys can now be renamed and deleted without re-encrypting the value(s).
      • New keys/values can be added to the SealedSecret without re-encrypting (or even having access to!) the existing values.
      • Note that (as before) the encrypted values are still tied to the namespace/name of the enclosing Secret/SealedSecret, so can't be moved to another Secret. (The cluster-wide annotation does allow this, with the corresponding caveats, as before)
    • The kubeseal tool does not yet have an option to output just a single value, but you can safely mix+match the individual values from kubeseal output with an existing SealedSecret. Improving kubeseal support for this feature is still an open action item.
    • Existing/older "all-in-one" SealedSecrets are declared deprecated, but will continue to be supported by the controller for the foreseeable future. New invocations of the kubeseal tool now produce per-key encrypted output - if you need to produce the older format, just use an older kubeseal. Please raise a github issue if you have a use-case that requires supporting "all-in-one" SealedSecrets going forward.
    • Note the CRD schema used for server-side validation in k8s >=1.9 has been temporarily removed, because it was unable to support the new per-key structure correctly (see kubernetes/kubernetes#59485).
    • Huge thanks to @sullerandras for the code and his persistence in getting this merged!
    Open source →
  33. v0.6.0 09 Feb 2018
    Release notes
    • Support "cluster wide" secrets, that are not restricted to the original namespace
      • Set sealedsecrets.bitnami.com/cluster-wide: "true" annotation
      • Warning: cluster-wide SealedSecrets can be decrypted by anyone who can create a SealedSecret in your cluster
    • Move to client-go v5.0
    • Move to bitnami-labs github org
    • Fix bug in schema validation for k8s 1.9
    Open source →
  34. v0.5.1 02 Oct 2017
    Release notes

    Note: this version moves TPR/CRD definition into a separate file. To install, you need controller.yaml and either sealedsecret-tpr.yaml or sealedsecret-crd.yaml

    • Add CRD definition and TPR->CRD migration documentation
    • Add kubeseal --fetch-cert to dump server cert to stdout, for later offline use with kubeseal --cert
    • Better sanitization of input object to kubeseal

    (v0.5.1 fixes a travis/github release issue with v0.5.0)

    Open source →
  35. v0.5.0 22 Sep 2017

    Nothing published for this version

  36. v0.4.0 14 Aug 2017
    Release notes
    • controller: deployment security hardening: non-root uid and read-only rootfs
    • kubeseal: Include oidc and gcp auth provider plugins
    • kubeseal: Add support for YAML output
    Open source →
  37. v0.3.1 11 Jul 2017
    Release notes
    • Add controller-norbac.yaml to the release build. This is controller.yaml without RBAC rules and related service account - for environments where RBAC is not yet supported, like Azure.
    • Fix missing controller RBAC ClusterRoleBinding in v0.3.0
    Open source →
  38. v0.3.0 21 Jun 2017
    Release notes

    Rename everything to better represent project scope. Better to do this early (now) and apologies for the disruption.

    • Rename repo and golang import path -> bitnami/sealed-secrets
    • Rename cli tool -> kubeseal
    • Rename SealedSecret apiGroup -> bitnami.com
    Open source →
  39. v0.2.1 21 Jun 2017
    Release notes
    • Fix invalid field resourceName in v0.2.0 controller.yaml (thanks @Globegitter)
    Open source →
  40. v0.2.0 20 Jun 2017
    Release notes
    • Client tool has better defaults, and can fetch the certificate automatically from the controller.
    • Improve release process to include pre-built Linux and OSX x86-64 binaries.
    Open source →
  41. v0.1.0 08 Jun 2017
    Release notes

    Basic functionality is complete.

    Open source →
  42. v0.0.1 05 Jun 2017
    Release notes
    • Clean up controller.jsonnet
    • Switch to quay.io (docker hub doesn't offer robot accounts??)
    • Add deploy section to .travis.yml
    Open source →
  43. v0.0.0-20260703130945-d6bd5908cc05 03 Jul 2026 pre-release

    Nothing published for this version

Every package, every release, already written down.

The archive is open and free. Watching your own project is what we are building next.

Browse the archive