NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #701 by repository stars
Last release 6 days ago
02 Oct 2026
Ships on a steady schedule
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
5960 releases · first in 2017
azure_blob BundlePublisher plugin for publishing the trust bundle to Azure Blob Storage
azure_blob BundlePublisher plugin for publishing the trust bundle to Azure Blob Storage (#7030)trust_bundle_spiffe_workload_api agent configuration option to fetch the initial trust bundle from a Workload API endpoint, simplifying nested agent deployments (#7148)disable_workload_api and disable_sds_api agent options to disable the Workload API and SDS APIs on the public endpoint (#7122)disable_kubelet_client option for the k8s workload attestor (#7142)use_pod_uid_for_agent_id option in the k8s_psat node attestor to derive agent IDs from pod UIDs instead of node UIDs (#7123)enable_namespace_labels option in the k8s workload attestor, producing ns-label selectors from namespace labels (#7094)account_list_file option in the aws_iid node attestor to source the verify_organization account list from a file instead of the AWS Organizations API (#7092)debug getinfo command in the spire-server and spire-agent CLIs to access the Debug APIs (#7133)svid.v1 API client and marshalling support for WIT-SVID keys (#7132, #7134)k8s workload attestor, reducing attestation latency and redundant kubelet requests (#7085)gcp_kms Key Manager plugin no longer requires key_identifier_value to be 36 characters long (#7140)memory Key Manager is used with a node attestor that does not support re-attestation (#7139)allow_insecure_scheme warning to describe the actual safety condition instead of implying development-only use (#7165)aws_iid node attestor (#7138)hashicorp_vault Key Manager plugin no longer triggers unrecognized parameter warnings in Vault and OpenBao audit logs (#7150)One column per quarter.
Deprecation warnings now use dedicated log markers, making them easier to detect in logs
x509pop node attestor (#6911)disable_group_name_selectors option for the Windows workload attestor (#6957)log_selectors configuration item for the agent (#6981)aws_kms Key Manager plugin (#7006)spire-agent (#7017)github.com/docker/docker dependencies to their github.com/moby/moby equivalents to resolve CVEs (#7078)allow_insecure_scheme is enabled (#6970)aws_iid node attestor (#6879)URISanSelectors for the agent SPIFFE ID template (#6872)azure_imds node attestation for standalone VMs (#6807)azure_imds plugin signature validation (#6960)spire upstream authority plugin now validates a missing Workload API endpoint (#7008)gcp_kms plugin no longer intermittently fails to retrieve a newly created public key (#6924)mountinfo lines with an empty mount source (#7044)Unavailable (#7045)http_challenge agent name validation regex (#7066)spire-agent now attempts to enable SE_DEBUG_PRIVILEGE at startup on Windows (#7073)Fixed an issue in the azure_imds server node attestor plugin where attested document validation anchored the first certificate in the PKCS7 certificat
azure_imds server node attestor plugin where attested document validation anchored the first certificate in the PKCS7 certificate bag to the trusted Azure roots, while the signature was verified against a separate signer certificate resolved from the PKCS7 SignerInfo. An attacker could place a legitimate Azure metadata certificate in the bag alongside content signed by an unrelated certificate and have a forged attested document accepted, impersonating an arbitrary virtual machine during node attestation. Thank you Carlo Teubner for reporting this issue.golang.org/x/net to v0.55.0 and golang.org/x/crypto to v0.52.0.🚨 This is a potentially breaking change if you make use of the JSON output of the CLI 🚨
account_id selector for aws_iid nodeattestor (#6697)iss claim support for WIT-SVIDs (#6857)spire-server and spire-agent CLI (#6789)spiffe_id node selector to help aliasing individual nodes (#6865)spire-agent api fetch x509 returns bundles in sorted alphabetic order by trust domain (#6784)k8s_psat node attestor includes the cluster in the attestation failure logs (#6785)sigstore support in k8s and docker attestors was promoted out of experimental (#6901, #6906)spire-agent WorkloadAPI server now specifies a read buffer size which may improve memory usage with large number of connections (#6875)🚨 This is a potentially breaking change if you make use of the JSON output of the CLI 🚨
gcp_iit node attestor will now use service account email from identity token so it no longer depends on use_instance_metadata being true (#6869)spire upstream authority plugin (#6773)azure_imds plugin for instances without a Network Security Group attached (#6795)azure_key_vault key manager plugin now supports Azure Managed HSM (#6751)aws_kms plugin which would revert rotated aliases (#6805)Fixed an issue in the azure_imds server node attestor plugin where attested document validation anchored the first certificate in the PKCS7 certificat
azure_imds server node attestor plugin where attested document validation anchored the first certificate in the PKCS7 certificate bag to the trusted Azure roots, while the signature was verified against a separate signer certificate resolved from the PKCS7 SignerInfo. An attacker could place a legitimate Azure metadata certificate in the bag alongside content signed by an unrelated certificate and have a forged attested document accepted, impersonating an arbitrary virtual machine during node attestation. Thank you Carlo Teubner for reporting this issue.golang.org/x/net to v0.55.0, golang.org/x/crypto to v0.52.0, and github.com/go-jose/go-jose/v4 to v4.1.4.Fixed an issue in the aws_iid server node attestor plugin where the RSA-2048 PKCS7 attestation path verified the PKCS7 signature against its embedded
aws_iid server node attestor plugin where the RSA-2048 PKCS7 attestation path verified the PKCS7 signature against its embedded content but returned the identity document parsed from a separate, attacker-controlled field of the attestation data. An attacker who controlled any EC2 instance could impersonate any other EC2 instance during node attestation, with all downstream attestation decisions operating on the forged identity. Thank you Tianshuo Han for reporting this issue.tx.Delete() did not report when no row was deleted. The fix uses a read-modify-write transaction with row locking and verifies that exactly one row was deleted. Thank you Tianshuo Han for reporting this issue.Upgrade Go to 1.26.2 to address CVE-2026-32282 , CVE-2026-32289 , CVE-2026-33810 , CVE-2026-27144 , CVE-2026-27143 , CVE-2026-32288 , CVE-2026-32283 ,…
- The version that the agent was reporting at startup would get replaced by an empty string every time the agent re-attests or re-news it's SVID
v1.14.4
Fixed
- The version that the agent was reporting at startup would get replaced by an empty string every time the agent re-attests or re-news it's SVID (#6763)
spire-agent version is now reported to spire-server via the PostStatus API and visible in GetAgent/ListAgents CLI output
spire-agent version is now reported to spire-server via the PostStatus API and visible in GetAgent/ListAgents CLI output (#6542)RequirePQKEM TLS policy now uses the standardized X25519MLKEM768 instead of the draft x25519Kyber768Draft00 (#6703)ReadOnlyEntry.Clone() was incorrectly copying the Admin boolean into the Downstream field when applying an output mask, causing clients of GetAuthorizedEntries and SyncAuthorizedEntries to receive corrupted authorization metadata. The Admin and Downstream booleana were not used in spire-agent so there was no impact from this (#6636)spire upstream authority plugin during shutdown that could cause a nil pointer dereference on the bundle client (#6590)aws_iid attestor AWS request timeout increased from 5s to 20s to prevent intermittent attestation failures in large AWS Organizations (#6558)VerifyPeerCertificate runs on every connection (#6715)Fixed an issue in the http_challenge server node attestor plugin which allowed an attacker to make an SSRF attack. The attacker could potentially redi
http_challenge server node attestor plugin which allowed an attacker to make an SSRF attack. The attacker could potentially redirect the server to a domain that they wouldn't normally have access. spire-server would make an unauthenticated GET request to that domain and return the first 64 bytes of the response to the attacker. Thank you, Oleh Konko (@1seal) for reporting this isuse.x509pop server node attestor plugin which allowed an attacker to make spire-server consume large and disproportionate mounts of CPU time for the node attestation process. Thank you Jakub Ciolek for reporting this issue.The uptime_in_ms gauge metric now uses float64 instead of integer
uptime_in_ms gauge metric now uses float64 instead of integer (#6532)aws_kms KeyManager plugin (#6525)Removed the deprecated 'retry_rebootstrap' agent config
azure_imds node attestor plugin for attesting nodes running in Microsoft Azure using the Azure Instance Metadata Service (IMDS) (#6312)disable_jwt_svids config (#6272)spire-server validate now supports validating plugin configuration (#6355)workload_x509_svid_key_type configuration option in spire-agent (#6389)docker:image_config_digest selector (#6391)certificate_id in CreateCertificateRequest for Enterprise tier compatibility (#6392)k8s and docker workload attestors now ignore cgroup mountinfo with root == / (#6462)Fixed an issue in the aws_iid server node attestor plugin where the RSA-2048 PKCS7 attestation path verified the PKCS7 signature against its embedded
aws_iid server node attestor plugin where the RSA-2048 PKCS7 attestation path verified the PKCS7 signature against its embedded content but returned the identity document parsed from a separate, attacker-controlled field of the attestation data. An attacker who controlled any EC2 instance could impersonate any other EC2 instance during node attestation, with all downstream attestation decisions operating on the forged identity. Thank you Tianshuo Han for reporting this issue.tx.Delete() did not report when no row was deleted. The fix uses a read-modify-write transaction with row locking and verifies that exactly one row was deleted. Thank you Tianshuo Han for reporting this issue.Upgrade Go to 1.25.9 to address CVE-2026-32282 , CVE-2026-32289 , CVE-2026-27144 , CVE-2026-27143 , CVE-2026-32288 , CVE-2026-32283 , CVE-2026-27140 ,…
Fixed an issue in the http_challenge server node attestor plugin which allowed an attacker to make an SSRF attack. The attacker could potentially redi
http_challenge server node attestor plugin which allowed an attacker to make an SSRF attack. The attacker could potentially redirect the server to a domain that they wouldn't normally have access. spire-server would make an unauthenticated GET request to that domain and return the first 64 bytes of the response to the attacker. Thank you, Oleh Konko (@1seal) for reporting this isuse.x509pop server node attestor plugin which allowed an attacker to make spire-server consume large and disproportionate mounts of CPU time for the node attestation process. Thank you Jakub Ciolek for reporting this issue.X.509 CA metric with absolute expiration time in addition to TTL-based metric
spire-agent configuration to source join tokens from files to support integration with third-party credential providers (#6330)spire-server Rego authorization policies (#6320)spire-server will use the SHA-256 algorithm for X.509-SVID Subject Key Identifiers when the GODEBUG environment variable contains fips140=only (#6294)oidc-discovery-provider now fails to initialize when started with unrecognized arguments (#6297)Upgrade Go to 1.25.2 to address CVE-2025-58187, CVE-2025-61723, CVE-2025-47912, CVE-2025-58185, and CVE-2025-58188
aws_iid NodeAttestor can now verify that nodes belong to specified EKS clusters
aws_iid NodeAttestor can now verify that nodes belong to specified EKS clusters (#5969)aws_s3, gcp_cloudstorage, and k8s_configmap BundlePublisher plugins now support setting a refresh hint for the published bundle (#6276)spire-server entry delete CLI command now properly displays results when no failures are involved (#6176)http_challenge NodeAttestor plugin, to prevent issues with web servers that cannot handle very large URLs (#6324)The deprecated use_legacy_downstream_x509_ca_ttl server configurable
rebootstrapMode and rebootstrapDelay in SPIRE Agent (#6227)agent_ttl compatibility with current ca_ttl (#6178)retry_bootstrap experimental agent setting (#5906)retry_bootstrap is enabled (#6164)use_legacy_downstream_x509_ca_ttl server configurable (#5703)use_rego_v1 server configurable (#6219)Upgrade Go to 1.24.8 to address CVE-2025-58187, CVE-2025-61723, CVE-2025-47912, CVE-2025-58185, and CVE-2025-58188
Upgrade Go to 1.24.6 for GO-2025-3849
k8s_configmap BundlePublisher plugin (#6105, #6139)
k8s_configmap BundlePublisher plugin (#6105, #6139)k8s WorkloadAttestor has been lowered to Debug level (#6128)trust_bundle_url if it is not required (#6065)subject_types_supported value in the discovery document is now properly populated by the OIDC Discovery Provider (#6126)…as required by the SPIFFE specification. This vulnerability has limited impact: by default, SPIRE does not issue JWT-SVIDs without an expiration claim…
Regression where PolicyCredentials set by CredentialComposer plugins were not correctly applied to CA certificates.
Support for Unix sockets in trust bundle URLs
sql_transaction_timeout replaced by event_timeout and value reduced to 15 minutes (#5966)user-agent value in OIDC Discovery Provider debug logs (#5981).The deprecated k8s_sat NodeAttestor plugin
aws_s3 BundlePublisher plugin (#5757)x509pop NodeAttestor plugin (#5775)use_legacy_downstream_x509_ca_ttl server setting is now set to false by default (#5917)use_sync_authorized_entries experimental agent setting (#5906)use_legacy_downstream_x509_ca_ttl server setting (#5917)k8s_sat NodeAttestor plugin (#5703)use_sync_authorized_entries was enabled (#5764)…as required by the SPIFFE specification. This vulnerability has limited impact: by default, SPIRE does not issue JWT-SVIDs without an expiration claim…
gcp_secretmanager SVIDStore plugin now supports specifying the regions where secrets are created
gcp_secretmanager SVIDStore plugin now supports specifying the regions where secrets are created (#5718)trust_domain label for all metrics (#5673)jwt_issuer configuration is set in the OIDC Discovery Provider (#5690)jwt_issuer configuration in the OIDC Discovery Provider (#5690)The Go based text/template engine used in various plugins has been extended to include a set of functions from the SPRIG library (#5593, #5625)
jwt_issuer configuration property in oidc-discovery-provider is not compatible with deployments that use a server port other than 443 (#5696)jwt_issuer configuration property in oidc-discovery-provider (#5697)Deprecated -ttl flag from the SPIRE Server entry create and entry update commands
x509_svid_cache_max_size configuration option. (#5383, #5531)entry create and entry update commands (#5483)Add missing commits to spire-plugin-sdk and spire-api-sdk releases (spiffe/spire-api-sdk#66, spiffe/spire-plugin-sdk#39)
Regression in agent health check, requiring the agent to have an SVID on disk to be healthy
http_challenge NodeAttestor plugin
http_challenge NodeAttestor plugin (#4909)aws_iid NodeAttestor to properly handle multiple network interfaces (#5300)sql_transaction_timeout setting in the experimental events-based cache (#5345)aws_rolesanywhere_trustanchor BundlePublisher plugin
aws_rolesanywhere_trustanchor BundlePublisher plugin (#5048)spire UpstreamAuthority to optionally use the Preferred TTL on intermediate authorities (#5264)The deprecated disable_reattest_to_renew agent configurable
plugin_data_file configurable (#5166)k8s_psat NodeAttestor attestor to no longer fail when a cluster is not configured (#5216)x509_svid_cache_max_size and disable_lru_cache in agent configuration (#5150)disable_reattest_to_renew agent configurable (#5217)key_metadata_file configurable from the aws_kms, azure_key_vault and gcp_kms server KeyManagers (#5207)use_msi configurable from the azure_key_vault server KeyManager and azure_msi NodeAttestor (#5207, #5209)exclude_sn_from_ca_subject server configurable (#5203)Opt-in support for CGroups v2 in K8s and Docker workload attestors
gcp_cloudstorage BundlePublisher plugin (#4961)aws_iid node attestor can now check if the AWS account ID is part of an AWS Organization (#4838)Updated to Go 1.21.10 to address CVE-2024-24788
Updated to google.golang.org/grpc v1.62.2 and golang.org/x/net v0.24.0 to address CVE-2023-45288
Updated to Go 1.21.9 to address CVE-2023-45288
Support for AWS IAM-based authentication with AWS RDS backed databases
retry_bootstrap option to SPIRE Agent to retry failed bootstrapping with SPIRE Server, with a backoff, in lieu of failing the startup process (#4597)Update Go to v1.21.8 to patch CVE-2024-24783
uniqueid CredentialComposer plugin that adds the x509UniqueIdentifier attribute to workload X509-SVIDs
uniqueid CredentialComposer plugin that adds the x509UniqueIdentifier attribute to workload X509-SVIDs (#4862)aws_kms, azure_key_vault, and gcp_kms KeyManager plugins no longer require storing metadata files on disk (#4700)k8s_sat NodeAttestor plugin (#4841)Updated to Go 1.21.10 to address CVE-2024-24788
Updated to google.golang.org/grpc v1.62.2 and golang.org/x/net v0.24.0 to address CVE-2023-45288
Updated to Go 1.21.9 to address CVE-2023-45288
Update Go to v1.21.8 to patch CVE-2024-24783
Agents can now be configured with an availability target, which establishes the minimum amount of time desired to gracefully handle server or agent do
use_sync_authorized_entries experimental setting (#4648)Updated to Go 1.21.5 to address CVE-2023-39326
use_msi configuration fields in azure_msi NodeAttestor plugin and azure_key_vault KeyManager plugin are deprecated in favor of the chained Azure SDK c…
azure_msi NodeAttestor plugin and azure_key_vault KeyManager plugin (#4568)EnableHostnameLabel field in Server and Agent telemetry configuration section that enables addition of a hostname label to metrics (#4584)serialNumber attribute in the Subject DN (#4585)use_msi configuration fields in azure_msi NodeAttestor plugin and azure_key_vault KeyManager plugin are deprecated in favor of the chained Azure SDK credential loading strategy (#4568)Updated to Go 1.21.4 to address CVE-2023-45283, CVE-2023-45284
SPIRE Agent distributes sync requests to the SPIRE server to mitigate thundering herd situations
insecureBootstrap and trustBundleUrl configurables are now mutually exclusive (#4532)Updated to google.golang.org/grpc v1.58.3 and golang.org/x/net v0.17.0 to address CVE-2023-39325, CVE-2023-44487
Updated to Go 1.21.3 to address CVE-2023-39325, CVE-2023-44487
azure_key_vault KeyManager plugin
azure_key_vault KeyManager plugin (#4458)spire-server CLI (#4371)aws_iid NodeAttestor can now be used in AWS Gov Cloud and China regions (#4427)status_code and status_message fields in SPIRE Agent logs on gRPC errors (#4262)systemd plugin (#4360)k8s WorkloadAttestor plugin that failed attestation in some scenarios (#4468)Updated to Go 1.20.12 to address CVE-2023-39326
Updated to Go 1.20.11 to address CVE-2023-45283, CVE-2023-45284
Updated to google.golang.org/grpc v1.58.3 and golang.org/x/net v0.17.0 to address CVE-2023-39325, CVE-2023-44487
Updated to Go 1.20.10 to address CVE-2023-39325, CVE-2023-44487
SPIRE Server bundle endpoint now includes bundle sequence number
aws_s3 BundlePublisher plugin (#4355)x509pop node attestor emits a new selector with the leaf certificate serial number
spire-server agent show command to properly show the "Can re-attest" attribute (#4288)Your coding agent can read these notes before it upgrades. Set up the MCP server →