NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #648 by repository stars
Last release 2 days ago
28 Sep 2026
Ships on a steady schedule
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
5958 releases · first in 2017
Envoy SDSv2 API is deprecated and now disabled by default
connection closed by user (#4165)Regression causing X509 CAs minted by an UpstreamAuthority plugin to be rejected if they have the digitalSignature key usage set
One column per quarter.
ARM64 binaries are now included in the release artifacts
agent purge command for removing stale agent records (#3982)Entry API responses now include the created_at field
created_at field (#3975)spire-server agent CLI commands and Agent APIs now show if agents can be re-attested and supports by_can_reattest filtering (#3880)spire-server entry create, spire-server entry show and spire-server entry update CLI commands now support hint information, allowing hinting to workloads the intended use of the SVID (#3926, #3787)vault UpstreamAuthority plugin to properly set the URI SAN (#3971)Updated to Go 1.20.3 to address CVE-2023-24534
Different CA TTL than configured
The deprecated enabled flag from InMem telemetry config
spire-server mint and spire-server token generate CLI commands now support the -output flag (#3800)spire-agent api CLI command now supports the -output flag (#3818)k8s-workload-registar is no longer released and maintained (#3853)x509_svid_ttl from registered_entries table (#3808)enabled flag from InMem telemetry config (#3796)default_svid_ttl configurable (#3795)omit_x509svid_uid configurable (#3794)Updated to Go 1.19.8 to address CVE-2023-24534
Updated to Go 1.19.6 and golang.org/x/net v0.7.0 to address CVE-2022-41723, CVE-2022-41724, CVE-2022-41725.
Support to run SPIRE as a Windows service
aws_iid NodeAttestor plugin (#3640)awssecret UpstreamAuthority plugin (#3578)spire-server federation CLI commands now support the -output flag (#3660)-output flag now properly shows the default value for the flag (#3713)A new gcp_kms KeyManager plugin is now available (#3410, #3638, #3653, #3655)
gcp_kms KeyManager plugin is now available (#3410, #3638, #3653, #3655)spire-server agent, spire-server bundle, and spire-server entry CLI commands now support -output flag (#3523, #3624, #3628)Updated to Go 1.19.4 to address CVE-2022-41717.
The deprecated default_svid_ttl configurable is now correctly observed after fixing a regression introduced in 1.5.0
default_svid_ttl configurable is now correctly observed after fixing a regression introduced in 1.5.0 (#3583)k8s-workload-registrar is deprecated in favor of SPIRE Controller Manager
/v1/entry API includes new jwt_svid_ttl field (#3445)k8s-workload-registrar and oidc-discovery-provider CLIs now print their version when the -version flag is set (#3475)azure_msi NodeAttestor plugin (#3488)ttl protobuf field in /v1/entry API is renamed to x509_ttl (#3445)join_token to avoid conflicts with the builtin plugin (#3469)spire-server run command now supports DNS names for the configured bind address (#3421)k8s-workload-registrar is deprecated in favor of SPIRE Controller Manager (#3526)default_svid_ttl configuration field is deprecated in favor of default_x509_svid_ttl and default_jwt_svid_ttl fields (#3445)-ttl flag in spire-server entry create and spire-server entry update commands is deprecated in favor of -x509SVIDTTL and -jwtSVIDTTL flags (#3445)-format flag in spire-agent fetch jwt CLI command is deprecated in favor of -output flag (#3528)InMem telemetry collector is deprecated and no longer enabled by default (#3492)azure_msi builtin NodeResolver plugin (#3470)Updated to Go 1.19.6 and golang.org/x/net v0.7.0 to address CVE-2022-41723, CVE-2022-41724, CVE-2022-41725.
Updated to Go 1.19.4 to address CVE-2022-41717.
Updated to Go 1.19.3 to address CVE-2022-41716. This vulnerability only affects users configuring external Server or Agent plugins on Windows.
Experimental support for limiting the number of SVIDs in the agent's cache
Updated minimum TLS version to 1.2 for the k8s-workload-registrar CRD mode webhook and the oidc-discovery-provider when using ACME
The X509-SVID Subject field now contains a unique ID to satisfy RFC 5280 requirements
Updated to Go 1.18.6 to address CVE-2022-27664
The deprecated webhook mode from the k8s-workload-registrar
Updated to Go 1.18.8 to address CVE-2022-41716. This vulnerability only affects users configuring external Server or Agent plugins on Windows.
Updated minimum TLS version to 1.2 for the k8s-workload-registrar CRD mode webhook and the oidc-discovery-provider when using ACME
Updated to Go 1.18.6 to address CVE-2022-27664
Updated to Go 1.18.4 to address CVE-2022-1705, CVE-2022-32148, CVE-2022-30631, CVE-2022-30633, CVE-2022-28131, CVE-2022-30635, CVE-2022-30632, CVE-202…
Support for K8s workload attestation when the Kubelet is run as a standalone component
entry show command (#3135)The windows workload attestor gained a new sha256 selector that can attest the SHA256 digest of the workload binary
windows workload attestor gained a new sha256 selector that can attest the SHA256 digest of the workload binary (#3100)join_token node attestor is attempted to be overridden by an external plugin (#3045)The webhook mode for the K8s Workload Register has been deprecated
Updated to Go 1.17.12 to address CVE-2022-1705, CVE-2022-32148, CVE-2022-30631, CVE-2022-30633, CVE-2022-28131, CVE-2022-30635, CVE-2022-30632, CVE-20…
Ability to revert SPIFFE cert validation to standard X.509 validation in Envoy (#3009,#3014,#3020,#3034)
Updated to Go 1.17.9 to address CVE-2022-24675, CVE-2022-28327, CVE-2022-27536
SPIRE Server and Agent log files can be rotated by sending the SIGUSR2 signal to the process
SIGUSR2 signal to the process (#2703)DigitalSignature KeyUsage bit in its CA certificate (#2896)k8sbundle Notifier plugin in SPIRE Server no longer consumes excessive CPU cycles (#2857)The SPIRE Agent fetch jwt CLI command now supports JSON output
fetch jwt CLI command now supports JSON output (#2650)alg parameter in JWKs to increase compatibility (#2771)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →