This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+9 more
Affected surfaces
Summary
AI summaryUpdates feat, pam, and agent-proxy across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Adds secrets brokering for proxied services and agent proxy CA. Adds secrets brokering for proxied services and agent proxy CA. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Automatically adds org-admins to PAM and allows access requests to PAM. Automatically adds org-admins to PAM and allows access requests to PAM. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Adds optional basic auth password for agent-proxy and docs link on proxied service sheet. Adds optional basic auth password for agent-proxy and docs link on proxied service sheet. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Adds Windows and Linux servers PKI sync capability. Adds Windows and Linux servers PKI sync capability. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Allows region to be set for global scope in GCP sync. Allows region to be set for global scope in GCP sync. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Allows multiple projects to be selected in project grants. Allows multiple projects to be selected in project grants. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Feature | Medium |
Makes recovery code account-wide and revamps 2FA settings UI. Makes recovery code account-wide and revamps 2FA settings UI. Source: llm_adapter@2026-07-15 Confidence: low |
— |
| Bugfix | Medium |
Removes SECRETS_ACTIVATION_ENABLED env gate from secret activation. Removes SECRETS_ACTIVATION_ENABLED env gate from secret activation. Source: llm_adapter@2026-07-15 Confidence: high |
— |
| Bugfix | Medium |
Removes default agent and agent‑proxy roles. Removes default agent and agent‑proxy roles. Source: llm_adapter@2026-07-15 Confidence: high |
— |
Full changelog
What's Changed
- feat(secret-manager): secrets brokering (proxied services + agent proxy CA) by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/7246
- chore: make recovery code account wide and revamp 2FA settings UI by @Thiago-AS in https://github.com/Infisical/infisical/pull/7139
- improvement: remove SECRETS_ACTIVATION_ENABLED env gate from secret activation by @claude[bot] in https://github.com/Infisical/infisical/pull/7283
- feat(pam): automatically add org-admins to PAM and allow access requests to PAM by @bernie-g in https://github.com/Infisical/infisical/pull/7226
- improvement(agent-proxy): optional basic auth password + docs link on proxied service sheet by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/7296
- docs: revamp Kubernetes Operator guide by @jakehulberg in https://github.com/Infisical/infisical/pull/7201
- feat: add Windows and Linux servers PKI sync by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/7258
- feat: move helm chart docs to self hosting section by @mathnogueira in https://github.com/Infisical/infisical/pull/7146
- feat(pam): add descriptions to all page headers by @x032205 in https://github.com/Infisical/infisical/pull/7291
- feat: allow region to be set for global scope in GCP sync by @mathnogueira in https://github.com/Infisical/infisical/pull/7289
- feat: allow multiple projects to be selected in project grants by @mathnogueira in https://github.com/Infisical/infisical/pull/7279
- improvement(agent-proxy): remove agent and agent-proxy default roles by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/7297
Full Changelog: https://github.com/Infisical/infisical/compare/v0.162.6...v0.162.7
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Related context
Related tools
Earlier breaking changes
- v1.0.0 Shared GitHub App host now bound to INF_APP_CONNECTION_GITHUB_APP_HOST environment variable.
Beta — feedback welcome: [email protected]