This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 2d
Infrastructure as Code
✓ No known CVEs patched
This release patches 2 known CVEs
Affected surfaces
deps
rce_ssrf
Summary
AI summaryBroad release touches BUG FIXES, deps, 1.16.0, and https://github.com/hashicorp/packer/pull/13673.
Full changelog
1.16.0 (July 24, 2026)
FEATURES:
- provenance: add new
provenancepost-processor andpacker verify-attestationcommand for
SLSA Build L1/L2 supply-chain attestations. Derives in-toto subjects from Packer artifacts,
builds SLSA Provenance v1 predicates with Git/CI metadata, and signs via local PEM key, cloud
KMS (awskms://,gcpkms://,azurekms://,hashivault://), or keyless Sigstore (Fulcio +
optional Rekor transparency log). Reference CI workflows for L2 keyless and L3-compatible
delegated-signing patterns are included underexamples/ci/.
GH-13667 - core/hcl2: add
rfc3339_parseandunix_timestamp_parsetemplate functions. Both accept
RFC 3339 timestamps;unix_timestamp_parseadditionally accepts Unix epoch integers.
GH-13669 - core/hcl2: add
continue_on_errormeta-argument to provisioner blocks. When set totrue,
a provisioner failure is logged and the build continues rather than halting.
GH-13674 - core/hcl2: variable
objecttypes now supportoptional()attribute modifiers, allowing
object variables to declare per-attribute defaults and omit fields that have a default set.
GH-13670
BUG FIXES:
- plugin/getter: prevent path traversal vulnerability in GitHub plugin getter filename handling.
GH-13680 - build: update build constraints to support arm architecture on FreeBSD.
GH-13650
SECURITY:
- security: drop
x/crypto/openpgpby upgradinggo-githubv33 → v75.
GH-13676 - security: suppress false positive for GO-2026-5932.
GH-13677 - deps: bump
golang.org/x/cryptoto v0.54.0.
GH-13672
DEPENDENCIES:
- deps: bump
github.com/hashicorp/packer-plugin-sdktov0.6.10.
GH-13673 - deps: bump
github.com/hashicorp/hcp-sdk-gotov0.174.0.
GH-13673 - deps: bump
github.com/zclconf/go-ctytov1.18.1.
GH-13673 - deps: bump
github.com/google/go-githubv33 → v75.
GH-13676 - deps: bump
golang.org/x/nettov0.56.0.
GH-13664 - deps: update various Go module dependencies.
GH-13673
INTERNAL:
Security Fixes
- GHSA: Path traversal vulnerability in GitHub plugin getter filename handling fixed (GH-13680).
- Dropped vulnerable `x/crypto/openpgp` by upgrading `go-github` from v33 to v75 (GH-13676).
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Packer
Packer is a tool for creating identical machine images for multiple platforms from a single source configuration.
Related context
Beta — feedback welcome: [email protected]