chore(deps): update dependency spiffe/spire to v1.11.2 #534
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.5.1
->1.11.2
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
spiffe/spire (spiffe/spire)
v1.11.2
Compare Source
Added
gcp_secretmanager
SVIDStore plugin now supports specifying the regions where secrets are created (#5718)trust_domain
label for all metrics (#5673)Changed
Fixed
jwt_issuer
configuration is set in the OIDC Discovery Provider (#5690)jwt_issuer
configuration in the OIDC Discovery Provider (#5690)Security
v1.11.1
Compare Source
Added
Changed
Fixed
Known Issues
jwt_issuer
configuration property in oidc-discovery-provider is not compatible with deployments that use a server port other than 443 (#5696)jwt_issuer
configuration property in oidc-discovery-provider (#5697)v1.11.0
Compare Source
Added
Changed
x509_svid_cache_max_size
configuration option. (#5383, #5531)Removed
entry create
andentry update
commands (#5483)Fixed
v1.10.4
Compare Source
Fixed
v1.10.3
Compare Source
Fixed
v1.10.2
Compare Source
Added
http_challenge
NodeAttestor plugin (#4909)Changed
Fixed
aws_iid
NodeAttestor to properly handle multiple network interfaces (#5300)sql_transaction_timeout
setting in the experimental events-based cache (#5345)v1.10.1
Compare Source
Added
aws_rolesanywhere_trustanchor
BundlePublisher plugin (#5048)Changed
spire
UpstreamAuthority to optionally use the Preferred TTL on intermediate authorities (#5264)Fixed
v1.10.0
Compare Source
Added
plugin_data_file
configurable (#5166)Changed
k8s_psat
NodeAttestor attestor to no longer fail when a cluster is not configured (#5216)Fixed
Deprecated
x509_svid_cache_max_size
anddisable_lru_cache
in agent configuration (#5150)Removed
disable_reattest_to_renew
agent configurable (#5217)key_metadata_file
configurable from theaws_kms
,azure_key_vault
andgcp_kms
server KeyManagers (#5207)use_msi
configurable from theazure_key_vault
server KeyManager andazure_msi
NodeAttestor (#5207, #5209)exclude_sn_from_ca_subject
server configurable (#5203)v1.9.6
Compare Source
Added
gcp_cloudstorage
BundlePublisher plugin (#4961)aws_iid
node attestor can now check if the AWS account ID is part of an AWS Organization (#4838)Changed
Fixed
v1.9.5
Compare Source
Security
v1.9.4
Compare Source
Security
v1.9.3
Compare Source
Security
v1.9.2
Compare Source
Added
retry_bootstrap
option to SPIRE Agent to retry failed bootstrapping with SPIRE Server, with a backoff, in lieu of failing the startup process (#4597)v1.9.1
Compare Source
Security
v1.9.0
Compare Source
Added
uniqueid
CredentialComposer plugin that adds the x509UniqueIdentifier attribute to workload X509-SVIDs (#4862)Changed
aws_kms
,azure_key_vault
, andgcp_kms
KeyManager plugins no longer require storing metadata files on disk (#4700)Fixed
Deprecated
k8s_sat
NodeAttestor plugin (#4841)Removed
v1.8.11
Compare Source
Security
v1.8.10
Compare Source
Security
v1.8.9
Compare Source
Security
v1.8.8
Compare Source
Security
v1.8.7
Compare Source
Added
use_sync_authorized_entries
experimental setting (#4648)Changed
Removed
v1.8.6
Compare Source
Security
v1.8.5
Compare Source
Added
azure_msi
NodeAttestor plugin andazure_key_vault
KeyManager plugin (#4568)EnableHostnameLabel
field in Server and Agenttelemetry
configuration section that enables addition of a hostname label to metrics (#4584)Changed
serialNumber
attribute in theSubject
DN (#4585)Deprecated
use_msi
configuration fields inazure_msi
NodeAttestor plugin andazure_key_vault
KeyManager plugin are deprecated in favor of the chained Azure SDK credential loading strategy (#4568)Fixed
v1.8.4
Compare Source
Security
v1.8.3
Compare Source
Added
Changed
Fixed
insecureBootstrap
andtrustBundleUrl
configurables are now mutually exclusive (#4532)v1.8.2
Compare Source
Security
v1.8.1
Compare Source
Security
v1.8.0
Compare Source
Added
azure_key_vault
KeyManager plugin (#4458)spire-server
CLI (#4371)aws_iid
NodeAttestor can now be used in AWS Gov Cloud and China regions (#4427)status_code
andstatus_message
fields in SPIRE Agent logs on gRPC errors (#4262)Changed
Fixed
systemd
plugin (#4360)k8s
WorkloadAttestor plugin that failed attestation in some scenarios (#4468)Removed
v1.7.6
Compare Source
Security
v1.7.5
Compare Source
Security
v1.7.4
Compare Source
Security
v1.7.3
Compare Source
Security
v1.7.2
Compare Source
Added
aws_s3
BundlePublisher plugin (#4355)Fixed
v1.7.1
Compare Source
Added
Changed
Fixed
spire-server agent show
command to properly show the "Can re-attest" attribute (#4288)v1.7.0
Compare Source
Added
Fixed
connection closed by user
(#4165)Removed
v1.6.5
Compare Source
Fixed
v1.6.4
Compare Source
Added
agent purge
command for removing stale agent records (#3982)Fixed
v1.6.3
Compare Source
Added
created_at
field (#3975)spire-server agent
CLI commands and Agent APIs now show if agents can be re-attested and supportsby_can_reattest
filtering (#3880)spire-server entry create
,spire-server entry show
andspire-server entry update
CLI commands now support hint information, allowing hinting to workloads the intended use of the SVID (#3926, #3787)Fixed
vault
UpstreamAuthority plugin to properly set the URI SAN (#3971)v1.6.2
Compare Source
Security
v1.6.1
Compare Source
Fixed
v1.6.0
Compare Source
Added
spire-server mint
andspire-server token generate
CLI commands now support the-output
flag (#3800)spire-agent api
CLI command now supports the-output
flag (#3818)Changed
Fixed
Removed
k8s-workload-registar
is no longer released and maintained (#3853)x509_svid_ttl
fromregistered_entries
table (#3808)enabled
flag from InMem telemetry config (#3796)default_svid_ttl
configurable (#3795)omit_x509svid_uid
configurable (#3794)v1.5.6
Compare Source
Added
Security
v1.5.5
Compare Source
Security
v1.5.4
Compare Source
Added
aws_iid
NodeAttestor plugin (#3640)awssecret
UpstreamAuthority plugin (#3578)spire-server federation
CLI commands now support the-output
flag (#3660)Fixed
-output
flag now properly shows the default value for the flag (#3713)v1.5.3
Compare Source
Added
gcp_kms
KeyManager plugin is now available (#3410, #3638, #3653, #3655)spire-server agent
,spire-server bundle
, andspire-server entry
CLI commands now support-output
flag (#3523, #3624, #3628)Changed
Fixed
v1.5.2
Compare Source
Security
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.