NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #388 by repository stars
Last release 7 days ago
01 Oct 2026
Ships unpredictably
gaps range from 8 days to 8.2 years
Nearly every release is documented
notes for 18 of 19 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
60 releases · first in 2017
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
[Security] Stop /v1/rotate from acting as a decryption oracle
9197324 to f2ea270 in /docker (#2038)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Bump golang.org/x/crypto from 0.54.0 to 0.55.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
[Security] fix: stop /v1/verify from acting as a decryption oracle
3592aa8 to 9197324 in /docker (#2008)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Incomplete release for credentials problems
Imcomplete release for credentials problems
Publish Artifact Hub repository metadata for verified publisher status
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Incomplete release for credentials problems
feat: add ppc64le architecture support
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Existing/older "all-in-one" SealedSecrets are declared deprecated, but will continue to be supported by the controller for the foreseeable future. New…
Big change for this release is the switch to per-key encrypted values.
kubeseal tool does not yet have an option to output just a single value, but you can safely mix+match the individual values from kubeseal output with an existing SealedSecret. Improving kubeseal support for this feature is still an open action item.kubeseal tool now produce per-key encrypted output - if you need to produce the older format, just use an older kubeseal. Please raise a github issue if you have a use-case that requires supporting "all-in-one" SealedSecrets going forward.Support "cluster wide" secrets, that are not restricted to the original namespace
sealedsecrets.bitnami.com/cluster-wide: "true" annotationNote: this version moves TPR/CRD definition into a separate file. To install, you need controller.yaml *and* either sealedsecret-tpr.yaml or sealedsec
Note: this version moves TPR/CRD definition into a separate file. To install, you need controller.yaml and either sealedsecret-tpr.yaml or sealedsecret-crd.yaml
kubeseal --fetch-cert to dump server cert to stdout, for later offline use with kubeseal --certkubeseal(v0.5.1 fixes a travis/github release issue with v0.5.0)
Nothing published for this version
controller: deployment security hardening: non-root uid and read-only rootfs
kubeseal: Include oidc and gcp auth provider pluginskubeseal: Add support for YAML outputAdd controller-norbac.yaml to the release build. This is controller.yaml without RBAC rules and related service account - for environments where RBAC
controller-norbac.yaml to the release build. This is controller.yaml without RBAC rules and related service account - for environments where RBAC is not yet supported, like Azure.Rename everything to better represent project scope. Better to do this early (now) and apologies for the disruption.
Rename everything to better represent project scope. Better to do this early (now) and apologies for the disruption.
bitnami/sealed-secretskubesealSealedSecret apiGroup -> bitnami.comFix invalid field resourceName in v0.2.0 controller.yaml (thanks @Globegitter)
resourceName in v0.2.0 controller.yaml (thanks @Globegitter)Client tool has better defaults, and can fetch the certificate automatically from the controller.
Basic functionality is complete.
Basic functionality is complete.
Switch to quay.io (docker hub doesn't offer robot accounts??)
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →