Skip to content

infisical

v0.161.3 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 1mo Secrets & Credentials
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Topics

acme certificate-management cli environment-variables go node-js
+9 more
pki postgresql private-ca secrets-management secret-manager secret-scanning security security-tools typescript

Affected surfaces

auth rbac crypto_tls

Summary

AI summary

Updates billing, pki, and chore across a mixed release.

Full changelog

What's Changed

  • fix(pki): enforce CA policy checks on certificate approval path by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6924
  • chore: add warning when empty ldap authorized user attributes by @Thiago-AS in https://github.com/Infisical/infisical/pull/6921
  • feat(billing): license server v2 customer billing page by @PrestigePvP in https://github.com/Infisical/infisical/pull/6898
  • fix(pam): validate gateway org ownership on resource and domain create/update by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6926
  • docs: fix broken link to Kubernetes cert-manager guide on Gloo Mesh page by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6933
  • fix(secrets-overview): search hidden secrets by @adilsitos in https://github.com/Infisical/infisical/pull/6932
  • fix(billing): conditionally render download button for paid invoices by @victorvhs017 in https://github.com/Infisical/infisical/pull/6935
  • fix: update org settings pages titles to reflect the nav selection by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6928
  • feat: email sanitization in secret sharing and invite org by @akhilmhdh in https://github.com/Infisical/infisical/pull/6931
  • docs(kubernetes-operator): embed overview video on operator overview page by @jakehulberg in https://github.com/Infisical/infisical/pull/6944
  • feat(license): dual-read v1/v2 entitlements with discrepancy logging by @PrestigePvP in https://github.com/Infisical/infisical/pull/6914
  • fix(error-handler): enhance error logging for expected client errors by @victorvhs017 in https://github.com/Infisical/infisical/pull/6950
  • improvement(project-role): add endpoint to get project role by id by @adilsitos in https://github.com/Infisical/infisical/pull/6934

Full Changelog: https://github.com/Infisical/infisical/compare/v0.161.2...v0.161.3

Security Fixes

  • Enforced CA policy checks on certificate approval path (pki)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track infisical

Get notified when new releases ship.

Sign up free

About infisical

Infisical is the open-source platform for secrets, certificates, and privileged access management.

All releases →

Related context

Earlier breaking changes

  • v1.0.0 Shared GitHub App host now bound to INF_APP_CONNECTION_GITHUB_APP_HOST environment variable.

Beta — feedback welcome: [email protected]