This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+9 more
Affected surfaces
ReleasePort's take
Moderate signalVersion v0.162.3 introduces several new features (email check for telemetry, certificate upload support, Azure CLI access to PAM, Slack notifications for approvals, and variable formats in Workers) while deprecating the PAM assumer role and adding multiple bug‑fixes.
Why it matters: The removal of the PAM assumer role (severity 70) mandates immediate review of any dependent authentication flows; all other changes deliver new capabilities or stability improvements without mandatory action.
Summary
AI summaryBroad release touches https://github.com/Infisical/infisical/pull/7245, https://github.com/Infisical/infisical/pull/7220, https://github.com/Infisical/infisical/pull/7217, and https://github.com/Infisical/infisical/pull/7248.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Add email check for telemetry collection in SAML router Add email check for telemetry collection in SAML router Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Support certificate upload Support certificate upload Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Add Azure CLI access to PAM Add Azure CLI access to PAM Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Add Slack notifications for access approvals Add Slack notifications for access approvals Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Support JSON and plain text variables in Cloudflare Workers sync Support JSON and plain text variables in Cloudflare Workers sync Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Low |
Improve wording to explain CA host in ADCS Improve wording to explain CA host in ADCS Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Feature | Low |
Make certificate authority get cert endpoint public Make certificate authority get cert endpoint public Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Deprecation | High |
Remove PAM assumer role Remove PAM assumer role Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Batch delete expired identity access token revocations Batch delete expired identity access token revocations Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Check connection ID to define if sync is duplicated or not Check connection ID to define if sync is duplicated or not Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Validate certificate issuance Validate certificate issuance Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Allow up to 64-character slug on project create to match update Allow up to 64-character slug on project create to match update Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Low |
Improve safety of request updates Improve safety of request updates Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Bugfix | Low |
Show live usage on per-unit product dimensions in billing Show live usage on per-unit product dimensions in billing Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
| Refactor | Low |
Split daily resource cleanup into staggered jobs Split daily resource cleanup into staggered jobs Source: granite4.1:30b@2026-07-15-audit Confidence: low |
— |
Full changelog
Changed
- Split daily resource cleanup into staggered jobs (https://github.com/Infisical/infisical/pull/7245)
- Improve wording to explain what the CA host means in ADCS (https://github.com/Infisical/infisical/pull/7220)
- Make certificate authority get cert endpoint public (https://github.com/Infisical/infisical/pull/7217)
Added
- Add email check for telemetry collection in SAML router (https://github.com/Infisical/infisical/pull/7248)
- Support certificate upload (https://github.com/Infisical/infisical/pull/7237)
- Add Azure CLI access to PAM (https://github.com/Infisical/infisical/pull/7228)
- Add Slack notifications for access approvals (https://github.com/Infisical/infisical/pull/7218)
- Support JSON and plain text variables in Cloudflare Workers sync (https://github.com/Infisical/infisical/pull/7207)
Removed
- Remove PAM assumer role (https://github.com/Infisical/infisical/pull/7227)
Fixed
- Batch delete expired identity access token revocations (https://github.com/Infisical/infisical/pull/7238)
- Check connection ID to define if sync is duplicated or not (https://github.com/Infisical/infisical/pull/7235)
- Validate certificate issuance (https://github.com/Infisical/infisical/pull/7232)
- Allow up to 64-character slug on project create to match update (https://github.com/Infisical/infisical/pull/7231)
- Improve safety of request updates (https://github.com/Infisical/infisical/pull/7224)
- Show live usage on per-unit product dimensions in billing (https://github.com/Infisical/infisical/pull/7202)
- Correct License Server v2 dual-read comparison (https://github.com/Infisical/infisical/pull/7182)
Breaking Changes
- Removed PAM assumer role
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Related context
Related tools
Earlier breaking changes
- v1.0.0 Shared GitHub App host now bound to INF_APP_CONNECTION_GITHUB_APP_HOST environment variable.
Featured in
Beta — feedback welcome: [email protected]