NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #648 by repository stars
Last release 2 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 1 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
5959 releases · first in 2017
Nothing published for this version
Nothing published for this version
Nothing published for this version
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
SPIRE Agent now supports the Delegated Identity API for delegating SVID management to trusted platform components
use property on the JWKs it serves (#2634)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
SPIRE Agent can now store SVIDs with Google Cloud Secrets Manager
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The deprecated agent key file (svid.key) is proactively removed by the agent. It was only maintained to accommodate rollback from v1.0 to v0.12
issuer:cn selector with the common name of the issuing certificate (#2581)ca_pool configurable to identify which CA pool the signing CA resides in (#2569)svid.key) is proactively removed by the agent. It was only maintained to accommodate rollback from v1.0 to v0.12 (#2493)service_account_whitelist configurables have been removed from the SAT and PSAT Node Attestor plugins (#2543)projectid_whitelist configurable has been removed from the GCP IIT Node Attestor plugin (#2492)bundle_endpoint and registration_uds_path configurables have been removed from SPIRE Server (#2486,#2519)Ability to revert SPIFFE cert validation to standard X.509 validation in Envoy (#3009,#3014,#3020,#3034)
### Security - Fixed CVE-2021-44716
Fixed a nil pointer dereference when the deprecated allow_unsafe_ids setting was configured
allow_insecure_scheme setting (#2404)k8s-workload-registrar now supports identity template based workload registration (#2417)k8s-workload-registrar now uses SPIRE certificates for the validating webhook (#2321)vault UpstreamAuthority plugin now continues retrying to renew tokens on failures until the lease time is exceeded (#2445)allow_unsafe_ids setting was configured (#2477)domain configurable has been deprecated in favor of domains (#2404)LDevID-based TPM attestation can now be performed via a new tpm_devid NodeAttestor plugin (#2111, #2427)
tpm_devid NodeAttestor plugin (#2111, #2427)aws_iid NodeAttestor plugin now supports attesting nodes across multiple AWS accounts via AWS IAM role assumption (#2387)k8s_sat NodeAttestor plugin with Kubernetes v1.21 (#2423)aws_kms KeyManager plugin (#2390, #2397)k8s_psat NodeAttestor plugin that prevented it from being configured with kubeconfig files (#2421)SPIRE Server federation configuration in the federates_with bundle_endpoint block is now deprecated
vault UpstreamAuthority plugin now supports Kubernetes service account authentication (#2356)cert-manager UpstreamAuthority plugin is now available (#2274)count subcommands for agents, entries, and bundles (#2128)federates_with configuration block (#2340)allow_unauthenticated_verifiers configurable (#2102)jwt_key_type (#1991)federates_with when calling the entry API (#1967)ca_key_type (#2269). to avoid inadvertent changes in directory permisions (#2219)/tmp/spire-server/private/api.sock (#2075)/tmp/spire-agent/public/api.sock (#2075)federates_with bundle_endpoint block is now deprecated (#2340)gcp_iit NodeAttestor configurable projectid_whitelist is deprecated in favor of projectid_allow_list (#2253)k8s_sat and k8s_psat NodeAttestor configurable service_account_whitelist is deprecated in favor of service_account_allow_list (#2253)registration_uds_path/-registrationUDSPath configurable and flag has been deprecated in favor of socket_path/-socketPath (#2075)allow_agentless_node_attestors has been removed (#2098)aws_iid NodeResolver plugin has been removed as it has been obviated (#2191)noop NodeResolver plugin has been removed (#2189)proto/spire go module has been removed in favor of the new SDKs (#2161)enable_sds configurable has been removed (#2021)experimental bundle CLI subcommands have been removed (#2062)aws_kms KeyManager plugin (#2390)The k8s-workload-registrar now supports federation
k8s-workload-registrar now supports federation (#2160)k8s_bundle notifier plugin can now keep API service CA bundles up to date (#2193)k8s-workload-registrar now uses paging to support very large deployments of 10,000+ pods (#2227)Added aws_kms server KeyManager plugin that uses the AWS Key Management Service (KMS)
aws_kms server KeyManager plugin that uses the AWS Key Management Service (KMS) (#2066)gcp_cas UpstreamAuthority plugin that uses the Certificate Authority Service from Google Cloud Platform (#2172)aws_iid NodeAttestor plugin now supports running in a location with no public internet access available for the server (#2119)k8s notifier can now rotate Admission Controller Webhook CA Bundles (#2022)unix WorkloadAttestor plugin (#2048)k8s WorkloadAttestor plugin now emits selectors for both image and image ID (#2116)spire-server agent show command (#2133)Fixed file descriptor leak in peertracker
The Registration and Node APIs are deprecated, and a warning is logged on use
ExpiresAt to entry show output (#1973)k8s_psat:agent_node_ip selector (#1979)registration_api configuration section is deprecated in favor of server_api in the k8s-workload-registrar (#2001)Fixed file descriptor leak in peertracker
Error messages related to a specific class of software bugs are now rate limited
Added AWS PCA configurable allowing operators to provide additional CA certificates for inclusion in the bundle
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →