Skip to content

Release history

infisical releases

Infisical is the open-source platform for secrets, certificates, and privileged access management.

All releases

76 shown

Review required
v0.160.10 Mixed
Auth

EAB key redaction + NTLM/Kerberos + PKI policies

No immediate action
v0.160.9 Bug fix

Vault namespace listing fix

Review required
v0.160.8 New feature
Auth RBAC Crypto / TLS

Telemetry, revocation, PKI UI, env soft delete, MLD‑SA KMS

No immediate action
v0.160.7 New feature

Cancel pending certificates

Config change
v0.160.6 Mixed
Auth

Redlock fix + cleanup bump + webhook improvements

Review required
v0.160.5 New feature
Auth RBAC Crypto / TLS

API, secret‑sync, LDAP, login, certificates, telemetry, docs

No immediate action
v0.160.4 Mixed

RBAC events + telemetry metrics + PKI CRL

No immediate action
v0.160.3 Mixed

Cert export, backend ops, enrollment removal

No immediate action
v0.160.2 Mixed

Permission audit + PKI migration + PAM fix

Review required
v0.160.1 Breaking risk
Auth RBAC

Honey token fix + cron timeout + PAM RDP

No immediate action
v0.160.0 New feature

Login redirect

Review required
v0.159.29 Breaking risk
Auth RBAC

Reviewer permission removal

v0.159.28 New feature
Notable features
  • Announcements for cloud and self-hosted deployments
  • Tab and stepper components added to the UI library
  • Project actions: create access and request access permissions
Full changelog

What's Changed

  • docs(honeytokens): fix broken usage links and clarify setup copy by @jakehulberg in https://github.com/Infisical/infisical/pull/6367
  • feature: tab and stepper components by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6334
  • feat: add PostHog telemetry events for honey tokens by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6373
  • fix: see docs to configure github message by @mathnogueira in https://github.com/Infisical/infisical/pull/6370
  • improvement: revamp secret overview secret update and delete confirmation modals by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6357
  • improvement: require change email confirmation by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6375
  • fix: add doc on multiple --path for infisical run by @mathnogueira in https://github.com/Infisical/infisical/pull/6378
  • feature: announcements for cloud and self-hosted by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6355
  • docs: add permissions section to honey tokens documentation by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6384
  • fix: add ldap dynamic secret template valdiation by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6385
  • chore(dev): add Bull Board service to docker-compose.dev.yml by @victorvhs017 in https://github.com/Infisical/infisical/pull/6376
  • feat(permission): add project actions for creating and requesting access by @victorvhs017 in https://github.com/Infisical/infisical/pull/6359
  • fix(platfor-339): index identity_access_tokens.subOrganizationId for cascade delete by @PrestigePvP in https://github.com/Infisical/infisical/pull/6377
  • docs(permissions): update organization permissions documentation to include 'request-access' action for projects by @victorvhs017 in https://github.com/Infisical/infisical/pull/6390
  • chore(upgrade-impact): backfill recent release data by @PrestigePvP in https://github.com/Infisical/infisical/pull/6273
  • fix: use UPGRADE_TOOL_GITHUB_TOKEN secret in upgrade impact workflow by @PrestigePvP in https://github.com/Infisical/infisical/pull/6394

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.27...v0.159.28

v0.159.27 Bug fix
Notable features
  • Added export and cell scroll to Postgres web access (pam)
  • Supported RDP access for Active Directory domain accounts (pam)
Full changelog

What's Changed

  • docs(pki): list supported subject attributes for certificate policies by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6337
  • fix(aws-auth): escape regex metacharacters in ARN allowlist matching by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6344
  • feat(pam): add export and cell scroll to postgres web access by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6321
  • improvement(platfor-315): tolerate newer migration history on startup by @PrestigePvP in https://github.com/Infisical/infisical/pull/6329
  • feat(pam): support RDP access for Active Directory domain accounts by @bernie-g in https://github.com/Infisical/infisical/pull/6255
  • fix(request): rollback saferequest changes by @victorvhs017 in https://github.com/Infisical/infisical/pull/6353
  • fix(inc-52): etag expiration by @PrestigePvP in https://github.com/Infisical/infisical/pull/6354
  • fix(honey-tokens): validate signing key, stack name and region by @mathnogueira in https://github.com/Infisical/infisical/pull/6352
  • fix: resolved dashobard not loading when honey token permission was missing by @akhilmhdh in https://github.com/Infisical/infisical/pull/6361
  • feat: improved logging message for audit log queue by @akhilmhdh in https://github.com/Infisical/infisical/pull/6363
  • docs(projectpage): resize project overview screenshots by @jakehulberg in https://github.com/Infisical/infisical/pull/6362
  • fix: resolved sub org id selection in legacy loading by @akhilmhdh in https://github.com/Infisical/infisical/pull/6347
  • improvement(frontend): fix select default text and icon display by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6317

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.26...v0.159.27

v0.159.25 New feature
Notable features
  • Support syncing secrets to Vercel team with all custom environments
  • Add custom CRL distribution points in PKI CAs
Full changelog

What's Changed

  • improvement(navigation): go to role details when click on a row by @adilsitos in https://github.com/Infisical/infisical/pull/6241
  • feat(secret-sync): support syncing to vercel team with all custom environments by @varonix0 in https://github.com/Infisical/infisical/pull/6136
  • fix(approvals): add request ID to approval request mail by @varonix0 in https://github.com/Infisical/infisical/pull/6247
  • fix: update textarea styling to prevent modal overflow by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6248
  • fix: limit ACME requests to 5 minutes for external CAs by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6222
  • docs(mcp): add AI agents callout and MCP setup page by @jakehulberg in https://github.com/Infisical/infisical/pull/6240
  • chore: disable Telemetry in CI by @maidul98 in https://github.com/Infisical/infisical/pull/6253
  • fix(kubernetes-auth): configurable TLS verification for identity Kubernetes auth by @victorvhs017 in https://github.com/Infisical/infisical/pull/6256
  • feat: add custom CRL distribution points in PKI CAs by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6224
  • fix: add missing ECDSA_P521 in the UI by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6252
  • fix(pam): default access duration to policy max by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6206
  • fix(k8s-auth): align TLS verification with CA presence and empty CA storage by @victorvhs017 in https://github.com/Infisical/infisical/pull/6261

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.24...v0.159.25

v0.159.24 Security relevant
Security fixes
  • Enforce TLS verification for identity auth providers
Full changelog

What's Changed

  • chore: add logout to create org modal by @sheensantoscapadngan in https://github.com/Infisical/infisical/pull/6103
  • fix: enforce TLS verification for identity auth providers by @victorvhs017 in https://github.com/Infisical/infisical/pull/6242

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.23...v0.159.24

v0.159.23 Breaking risk
Notable features
  • Gateway pools for high-availability failover
  • Venafi TPP external CA integration
  • Per-tab Postgres connections with isolated transactions for PAM
Full changelog

What's Changed

  • feat: updated secret sharing delete to have 7 day grace by @akhilmhdh in https://github.com/Infisical/infisical/pull/6160
  • fix(vercel-sync): filter team shared env vars to sync-owned set by @victorvhs017 in https://github.com/Infisical/infisical/pull/6144
  • chore(cache-keys): move cache keys to single file by @adilsitos in https://github.com/Infisical/infisical/pull/6162
  • feat(secret-rotation): support supabase by @mathnogueira in https://github.com/Infisical/infisical/pull/6130
  • improvement(secrets-overview): remove tooltip delay duration on overview page table actions and add more options tooltip by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6145
  • feat(frontend): add button to reveal secret reference values by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6143
  • fix(pki): reject EST simple re-enroll with revoked client cert by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6163
  • docs(pki-discovery): document ALLOW_INTERNAL_IP_CONNECTIONS option by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6157
  • fix(pki): report correct enrollment type in auto-renewal error by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6159
  • fix(signup): restore "Team Invite" attribution source for invited users by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6141
  • docs: rename Agent Sentinel to Agent Vault with external link in Products nav by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6176
  • fix(ui): brighten "Create New Connection" option in connection dropdown by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6192
  • fix(ui): auto-switch environment view after uploading secrets by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6188
  • chore: delete .github/workflows/one-time-secrets.yaml by @maidul98 in https://github.com/Infisical/infisical/pull/6203
  • fix(db): gate OAuth verified migration on accepted users by @victorvhs017 in https://github.com/Infisical/infisical/pull/6173
  • fix(scim): preserve orgId when listing groups by @victorvhs017 in https://github.com/Infisical/infisical/pull/6207
  • improvement: add rotation icon to rotated secrets in single env display by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6053
  • docs: remove projectName from audit log documentation by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6209
  • chore: removed dependencies and api key service by @akhilmhdh in https://github.com/Infisical/infisical/pull/6161
  • docs: add Prevent Value Reuse constraint to secret validation rules by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6212
  • feat: add gateway pools for high-availability failover by @bernie-g in https://github.com/Infisical/infisical/pull/6050
  • improvement: unrevert upgrade aws-sdk v2 to v3 by @PrestigePvP in https://github.com/Infisical/infisical/pull/5905
  • feat(pam): per-tab Postgres connections with isolated transactions by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6154
  • feat: add Venafi TPP external CA integration by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6032
  • improvement(eng-4874): memoize org findByID by @PrestigePvP in https://github.com/Infisical/infisical/pull/6164
  • improvement(frontend): update secret sharing UI by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6121
  • fix(docs): replace broken Kubernetes icon URL with Font Awesome dharmachakra by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6217
  • feat(e2e-tests): fips mode by @varonix0 in https://github.com/Infisical/infisical/pull/6214
  • feat(secrets-overview): add tag, metadata and multiline encoding support to csv upload by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6156
  • fix(email): include confirmation code in email subject line by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6218
  • feat: added filter to audit log and improves the crypto by @akhilmhdh in https://github.com/Infisical/infisical/pull/6155
  • feat(auth): store machine identity auth as identity actor by @mathnogueira in https://github.com/Infisical/infisical/pull/6101
  • feat: user controlled ssl rejection option for dynamic secret by @akhilmhdh in https://github.com/Infisical/infisical/pull/6204
  • feat: resolved hashedPassword not set for bootstrap admin by @akhilmhdh in https://github.com/Infisical/infisical/pull/6221
  • improvement(secret-migration): add more paths in vault migration by @adilsitos in https://github.com/Infisical/infisical/pull/6215
  • fix: fail on Schema generation for analytics by @maidul98 in https://github.com/Infisical/infisical/pull/6223
  • improvement(frontend): add design.md and new batch of component stories by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6211
  • fix(gateway): add support for gateway v2 on vault migration by @adilsitos in https://github.com/Infisical/infisical/pull/6227
  • improvement(secrets-rotation): allow move between environments and folders by @adilsitos in https://github.com/Infisical/infisical/pull/6220
  • fix: missing gateway-v2 handling on venafi tpp by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6226
  • feat(smtp): add SMTP_HELO_HOST to set the EHLO/HELO hostname by @quarckster in https://github.com/Infisical/infisical/pull/6229

New Contributors

  • @quarckster made their first contribution in https://github.com/Infisical/infisical/pull/6229

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.22...v0.159.23

v0.159.22 New feature
Notable features
  • Gitpod support for secret sync
Full changelog

What's Changed

  • feat(secret-sync): add support for gitpod (Ona) by @adilsitos in https://github.com/Infisical/infisical/pull/6119
  • chore: more updates on by @akhilmhdh in https://github.com/Infisical/infisical/pull/6149
  • fix(api): use Bitbucket user workspaces endpoint for listing by @victorvhs017 in https://github.com/Infisical/infisical/pull/6152
  • chore: rename developer to member by @varonix0 in https://github.com/Infisical/infisical/pull/6148

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.21...v0.159.22

v0.159.21 Bug fix

Minor fixes and improvements.

Full changelog

What's Changed

  • fix(group): run filters, ordering and pagination in backend by @mathnogueira in https://github.com/Infisical/infisical/pull/6114

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.20...v0.159.21

v0.159.20 Mixed
Security fixes
  • Disallow TOTP token reuse
Notable features
  • Prevent TOTP token reuse
  • Travis CI sync support
  • DigiCert CertCentral CA
Full changelog

What's Changed

  • fix: table re-render without debounce by @varonix0 in https://github.com/Infisical/infisical/pull/6104
  • fix: only lockout if identity lockout is enabled by @varonix0 in https://github.com/Infisical/infisical/pull/6120
  • feat: updated the mfa check by @akhilmhdh in https://github.com/Infisical/infisical/pull/6115
  • fix: cert-manager nav by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6126
  • feat: updated more checks by @akhilmhdh in https://github.com/Infisical/infisical/pull/6127
  • fix: resolved the user id going null by @akhilmhdh in https://github.com/Infisical/infisical/pull/6128
  • chore: address read after write issue for secret folders by @sheensantoscapadngan in https://github.com/Infisical/infisical/pull/6056
  • fix: certificate patches by @sheensantoscapadngan in https://github.com/Infisical/infisical/pull/6129
  • improvement(secrets-232): memoize project ID look up and remove unneeded checks. by @PrestigePvP in https://github.com/Infisical/infisical/pull/6118
  • fix(eng-4868): disallow reusing TOTP tokens by @PrestigePvP in https://github.com/Infisical/infisical/pull/6112
  • feat: more updates on checks by @akhilmhdh in https://github.com/Infisical/infisical/pull/6131
  • fix(frontend): prevent Add Sync modal overflow on small/zoomed viewports by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6133
  • fix(frontend): invalidate approval request queries at project scope by @victorvhs017 in https://github.com/Infisical/infisical/pull/6135
  • feat(kms): bulk export private keys by @victorvhs017 in https://github.com/Infisical/infisical/pull/6083
  • feat: add a reason field before PAM account access by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6096
  • fix(migration): drop queue_jobs trigger before dropping table by @leeyspaul in https://github.com/Infisical/infisical/pull/6110
  • feat: prevent reuse of previous secret values by @varonix0 in https://github.com/Infisical/infisical/pull/6123
  • feat: display pam aws credentials for cli access by @x032205 in https://github.com/Infisical/infisical/pull/6122
  • feat(sync-secret): add app connection and secret sync for Travis CI by @adilsitos in https://github.com/Infisical/infisical/pull/6097
  • fix: hiccups found in the application by @PrestigePvP in https://github.com/Infisical/infisical/pull/6138
  • feat: add DigiCert CertCentral External CA by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6125
  • fix: fixes for secret sharings and other areas by @PrestigePvP in https://github.com/Infisical/infisical/pull/6146

New Contributors

  • @leeyspaul made their first contribution in https://github.com/Infisical/infisical/pull/6110

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.19...v0.159.20

v0.159.19 Breaking risk
Breaking changes
  • Secret rotation v1 removed - migrate to newer implementation
Notable features
  • PAM with dedicated domains section
  • PKI post-quantum cryptography readiness pie chart and trend
  • AWS ACM Public CA support
Full changelog

What's Changed

  • feat(pam): move ad server resources to dedicated domains section by @x032205 in https://github.com/Infisical/infisical/pull/5982
  • feat: remove upgrade-path page and backend service by @mathnogueira in https://github.com/Infisical/infisical/pull/6085
  • feat: updated default config for request by @akhilmhdh in https://github.com/Infisical/infisical/pull/6099
  • feat(pki): pqc readiness pie + trend chart and inventory preset views by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6084
  • feat: resovled ts error and new token type by @akhilmhdh in https://github.com/Infisical/infisical/pull/6100
  • docs(selfhost): render kubernetes logo on self-hosting overview card by @jakehulberg in https://github.com/Infisical/infisical/pull/6098
  • fix(pki): rename Unstable* v3 imports in PQC dashboard by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6102
  • feat: removed secret rotation v1 by @akhilmhdh in https://github.com/Infisical/infisical/pull/6105
  • feat(frontend): show systemd CLI command in re-enroll gateway modal by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6107
  • fix: pam nav by @x032205 in https://github.com/Infisical/infisical/pull/6109
  • fix: resolved user group addition failing by @akhilmhdh in https://github.com/Infisical/infisical/pull/6113
  • feat(pki): add AWS ACM Public CA support by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6069

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.18...v0.159.19

v0.159.18 Mixed
Notable features
  • Vercel sync
Full changelog

What's Changed

  • fix(frontend): prevent duplicated 'v' in on-prem version badge by @Erwan-loot in https://github.com/Infisical/infisical/pull/6068
  • fix: resolved recovery account failing in frontend by @akhilmhdh in https://github.com/Infisical/infisical/pull/6092
  • feat: add new vercel sync feature by @maidul98 in https://github.com/Infisical/infisical/pull/6093

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.17...v0.159.18

v0.159.17 Mixed
Notable features
  • Unified external migrations UI with in-platform Doppler support
  • Ghost accordion variant for components
Full changelog

What's Changed

  • improvement(components): add ghost accordion variant, accordion stories and remove unstable v3 prefix by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6081
  • feat(webhook): fix UI by @adilsitos in https://github.com/Infisical/infisical/pull/6086
  • feature: doppler in-platform migration and unified external migrations UI by @IgorHorta in https://github.com/Infisical/infisical/pull/5875
  • fix: one-password auto-fill by @varonix0 in https://github.com/Infisical/infisical/pull/6082

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.16...v0.159.17

v0.159.16 New feature
Notable features
  • Project permission caching
  • Gateway authentication for Kubernetes
  • Webhook editing with event selection
Full changelog

What's Changed

  • fix: null values for unknown pki dashboard fields by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6066
  • chore: condition update by @akhilmhdh in https://github.com/Infisical/infisical/pull/6055
  • docs(dockerswarm): consolidate self-hosting overview cards into single grid by @jakehulberg in https://github.com/Infisical/infisical/pull/6038
  • feat: restructure Certificate Manager navigation by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6044
  • docs(vercelvideo): add walkthrough video to Vercel Sync page by @jakehulberg in https://github.com/Infisical/infisical/pull/6073
  • feature(cache): project permission caching by @maidul98 in https://github.com/Infisical/infisical/pull/6042
  • docs(pam): effectiveness note for command blocking by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6070
  • feat(pam): gateway auth for kubernetes by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6021
  • chore: hubSpot UTK tracking for cloud instances signup by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6071
  • chore: improve PostHog dedicated instances flow by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6045
  • fix(platfor-290): remove distinct on lookup by @PrestigePvP in https://github.com/Infisical/infisical/pull/6079
  • feat(auth): reapply and adapt #6029 to match the new auth system by @mathnogueira in https://github.com/Infisical/infisical/pull/6072
  • feat(login-v2): flag users that are still using V2 login by @mathnogueira in https://github.com/Infisical/infisical/pull/6074
  • feat(webhook): add edit and event selection by @adilsitos in https://github.com/Infisical/infisical/pull/5984

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.15...v0.159.16

v0.159.15 Mixed
Notable features
  • Audit logs date range picker redesigned
  • Auth token query staleTime set to 0 for fresh data retrieval
Full changelog

What's Changed

  • feat(audit-logs): redesign the date range picker by @mathnogueira in https://github.com/Infisical/infisical/pull/6033
  • fix(frontend): invalidate auth token after org select; default query staleTime by @victorvhs017 in https://github.com/Infisical/infisical/pull/6002
  • chore: bump transitive dependencies by @x032205 in https://github.com/Infisical/infisical/pull/6054
  • Revert "fix(frontend): invalidate auth token after org select; default query staleTime" by @maidul98 in https://github.com/Infisical/infisical/pull/6058
  • Revert "feat: add insights page to secrets management product type" by @varonix0 in https://github.com/Infisical/infisical/pull/6060
  • fix: remove recharts and pki dashboard by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6061
  • fix(frontend): invalidate auth token after org select; default query staleTime by @maidul98 in https://github.com/Infisical/infisical/pull/6059
  • fix: add back recharts, pki dashboard and manually chunk rechart dependencies by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6063
  • fix: reapply "feat: add insights page to secrets management product type" by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6064
  • fix(frontend): set staleTime to 0 for auth token query to ensure fresh data retrieval by @victorvhs017 in https://github.com/Infisical/infisical/pull/6065

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.14...v0.159.15

v0.159.14 Mixed
Security fixes
  • Dependabot security vulnerability fixes
Notable features
  • Gateway enrollment token flow
  • Inventory and dashboard rework for PKI
  • Insights page for secrets management
Full changelog

What's Changed

  • fix: use actual actor as distinctId for IntegrationSynced PostHog event by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6028
  • feat: add deployment_type, instance_type, and region to PostHog telemetry by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/5976
  • feat(login): show login SMTP errors in case of misconfiguration by @mathnogueira in https://github.com/Infisical/infisical/pull/6029
  • Revert "feat(login): show login SMTP errors in case of misconfiguration" by @akhilmhdh in https://github.com/Infisical/infisical/pull/6039
  • feature(cache): project permission caching by @victorvhs017 in https://github.com/Infisical/infisical/pull/6031
  • feat: refactor of auth by @akhilmhdh in https://github.com/Infisical/infisical/pull/5947
  • fix: improved response for the discovery endpoint by @x032205 in https://github.com/Infisical/infisical/pull/6040
  • Revert "feature(cache): project permission caching" by @maidul98 in https://github.com/Infisical/infisical/pull/6041
  • feat: inventory+dashboard rework on PKI by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/5958
  • fix: made totp verify lax by @sheensantoscapadngan in https://github.com/Infisical/infisical/pull/6049
  • improvement(eng-4792): speed up CI by @PrestigePvP in https://github.com/Infisical/infisical/pull/6018
  • fix: dependabot security vulnerabilities by @x032205 in https://github.com/Infisical/infisical/pull/6035
  • improvement: make email verifcation required banner less spooky by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6051
  • feat: add insights page to secrets management product type by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5968
  • improvement(frontend): reduce default integration and approval polling intervals by @victorvhs017 in https://github.com/Infisical/infisical/pull/6003
  • fix(pam): increase web access idle timeout from 5 to 20 minutes by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6052
  • feat: gateway enrollment token flow by @bernie-g in https://github.com/Infisical/infisical/pull/6020
  • feat: add oci standard labels to Dockerfile.standalone-infisical by @Erwan-loot in https://github.com/Infisical/infisical/pull/5323
  • feat: add dynamic challenges to SCEP by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6023
  • feat: add bulk tag modal to overview page by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6043

New Contributors

  • @Erwan-loot made their first contribution in https://github.com/Infisical/infisical/pull/5323

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.13...v0.159.14

v0.159.13 New feature
Notable features
  • Account policies for PAM
Full changelog

What's Changed

  • docs(proxy): add description for event based cache refresh by @adilsitos in https://github.com/Infisical/infisical/pull/6030
  • feat(pam): account policies by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/5971

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.12...v0.159.13

v0.159.12 New feature
Notable features
  • Post-Quantum Crypto algorithms to PKI
  • MS Teams workflow support
  • Access approval revoke functionality
v0.159.10 Mixed
Notable features
  • AI session insights for privileged access management
  • Real-time session log sync via incremental batch uploads
  • Request-scoped memoization for optimized database reads
v0.159.9 New feature
Notable features
  • NetScaler PKI sync integration added
  • resourceType permission condition support for PAM resources and accounts
v0.159.8 Bug fix

UI improvements, password generator validation, and project permission enhancements.

Full changelog

What's Changed

  • fix(ua-identity): check if provided orgSlug is equal to org slug by @adilsitos in https://github.com/Infisical/infisical/pull/5928
  • docs(removal): remove Docker Swarm documentation entirely by @jakehulberg in https://github.com/Infisical/infisical/pull/5933
  • fix: remove old route redirect compatibility by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5921
  • improvement: migrate add/edit folder modal to v3 components by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5927
  • docs(update): add self-hosting video to Docker Compose doc by @jakehulberg in https://github.com/Infisical/infisical/pull/5931
  • fix: display boolean values as true/false instead of t/f in Data Explorer by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/5935
  • feat: enable full PostHog telemetry for all instance types by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/5893
  • improvement: improve affected resources table col proportions by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5907
  • feat: password generator secret validation rules by @varonix0 in https://github.com/Infisical/infisical/pull/5930
  • fix: added missing project permissions by @varonix0 in https://github.com/Infisical/infisical/pull/5934

Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.7...v0.159.8

v0.159.6 Breaking risk
Breaking changes
  • Custom roles restricted to Enterprise plans; creation enforcement begins June 1, 2026. Pro users must use additional privileges or upgrade.
Notable features
  • SSH certificate provider for dynamic secrets
  • User field added to secret.change webhooks
  • Tag filtering in overview dashboard
v0.159.5 Maintenance
Notable features
  • SSH PAM Exec and SFTP Support
  • Active Session Termination
v0.159.4 New feature
Notable features
  • Vertical navbar layout
  • Secret access insights sheet
  • Magic number validation for sharing
v0.159.2 New feature
Notable features
  • PAM Windows rotation
  • Postgres in-browser data explorer
  • Webhook support for rotations
v0.159.1 Bug fix

Fixed project template editing to prevent unnecessary updates and improved job logging reliability.

v0.159.0 New feature
Notable features
  • Approval request expiration time
  • New PKI alert types
v0.158.21 New feature
Notable features
  • Custom roles in org invites
  • IP address SAN support
  • Azure Key Vault certificate import option
v0.158.20 New feature
Notable features
  • SCEP enrollment method
  • Automated AD CS intermediate CA signing
  • Infisical-to-Infisical sync
v0.158.19 New feature
Notable features
  • PKI certificate metadata RBAC conditions
  • HP iLO password rotation
v0.158.18 New feature
Notable features
  • Code-signing PKI support
  • Windows local account and dependency discovery
  • Helm OCI registry push
v0.158.17 New feature
Notable features
  • PostHog identity tracking
  • PAM card grid UI
  • Redis web access
v0.158.14 New feature
Notable features
  • machine identity PostHog events
  • secrets-overview batch operations
  • credential rotations
v0.158.12 New feature
Notable features
  • PostHog approval workflow tracking
  • SPIFFE machine authentication
  • Unix rotation fallback mechanism
v0.158.11 Bug fix

Fixed secret value overwrites in batch operations, restored service account names in Helm charts, and improved ACME DNS configuration for PKI.

v0.158.10 New feature
Notable features
  • Redis stream-based log aggregator
  • Dynamic secret PostHog tracking
v0.158.9 New feature
Notable features
  • PostHog org enrichment
  • Helm extraEnv support
  • Redis cluster KMS support
v0.158.8 New feature
Notable features
  • Clickhouse dynamic secret provider
  • PAM web and SSH browser access
  • Vault secret import
v0.158.7 New feature
Notable features
  • Permission forbid rule priority
  • Daily PKI expiration alerts
  • Kubernetes auth wildcard/regex support
v0.158.6 New feature
Notable features
  • Environment creation on overview page
  • Secret import support
  • Bulk operation timeout prevention
v0.158.5 New feature
Notable features
  • New membership API
  • Azure DNS ACME provider
  • AWS Private CA integration
v0.158.4 Bug fix

Improved secret rotation validation to detect and prevent credential conflicts before attempting external system rotations.

v0.158.3 New feature
Notable features
  • PAM web launcher for PostgreSQL
  • Windows Server support
  • Fly.io automatic redeployment
v0.158.1 New feature
Notable features
  • Event architecture revamp
  • PKI Cloudflare sync
  • dbt app connection and secret rotation
v0.158.0 New feature
Notable features
  • Certificate policy creation from profiles
  • OpenRouter API key rotation
  • Windows local account rotation
v0.157.0 New feature
Notable features
  • PKI approval workflows
  • User account recovery
  • MCP server support
v0.156.2 New feature
Notable features
  • Support for encrypted metadata for secrets
  • Enhanced LDAP authentication error handling and validation
Full changelog

What's Changed

  • fix: unhide all api paths in dev mode by @varonix0 in https://github.com/Infisical/infisical/pull/5220
  • feat: support for encrypted metadata for secrets by @akhilmhdh in https://github.com/Infisical/infisical/pull/5203
  • fix: enhance LDAP authentication error handling and validation by @luizbafilho in https://github.com/Infisical/infisical/pull/5213

New Contributors

  • @luizbafilho made their first contribution in https://github.com/Infisical/infisical/pull/5213

Full Changelog: https://github.com/Infisical/infisical/compare/v0.156.1...v0.156.2

v0.156.1 Maintenance

Removed dev dependencies from final Docker build output and updated dependencies.

v0.156.0 Mixed
Notable features
  • Granular PII filtering with configurable entity types in agent-sentinel
  • One-action approve-and-merge button for change requests
  • V3 button stabilization with stories
Full changelog

What's Changed

  • feat(agent-sentinel): add granular PII filtering with configurable entity types by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/5201
  • improvement(frontend): add button to approve and merge change request in one action if tenable by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5206
  • feature(frontend): stabilize v3 button with stories by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5175
  • fix(pam): k8s create account not working due to rotation by @x032205 in https://github.com/Infisical/infisical/pull/5219
  • improvement(oidc): don't send organization invitation email if the server doesn't have email login enabled by @victorvhs017 in https://github.com/Infisical/infisical/pull/5216
  • docs: multiple operator namespaces by @varonix0 in https://github.com/Infisical/infisical/pull/5223

Full Changelog: https://github.com/Infisical/infisical/compare/v0.155.7...v0.156.0

v0.155.7

{ "summary": "Added support for issuing intermediate CAs via certificate profiles, Cassandra dynamic secret support for vault-migration, and name-based RBAC permission conditions for MCP endpoints in agent-sentinel. Fixed frontend commit comparison display and improved host validation errors.", "summary_short": "Added intermediate CA support, Cassandra dynamic secrets, and MCP endpoint RBAC conditions.", "summary_short_alt": "Implemented intermediate CA issuance, Cassandra dynamic secrets,

v0.155.6 New feature
⚠ Upgrade required
  • Certificate template has been renamed to certificate policy — users relying on this terminology in workflows or documentation should update references accordingly.
Notable features
  • Unix/Linux password rotation support added
  • Certificate template renamed to certificate policy (may affect UI references and documentation)
v0.155.5 New feature
⚠ Upgrade required
  • Node.js version updated to 20.20.0; ensure your environment matches this version if self-hosting.
Notable features
  • Bearer Token authentication support for MCP servers in agent-sentinel
  • Custom branding support for secret-share
v0.155.4 New feature
Notable features
  • SSH app connection support
  • Reduced toast notification duration
Full changelog

What's Changed

  • improvement(frontend): decrease toast duration by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5159
  • feat: ssh app connection by @akhilmhdh in https://github.com/Infisical/infisical/pull/5169
  • fix(agent-sentinel): oauth double-click issue by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/5168
  • chore: add Mintlify GTM integration to docs.json by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/5173
  • fix: list project identities by @varonix0 in https://github.com/Infisical/infisical/pull/5174

Full Changelog: https://github.com/Infisical/infisical/compare/v0.155.3...v0.155.4

v0.155.3 Bug fix
Notable features
  • Improved dynamic secret username templating for more flexible customization
  • API-level searchable Vercel projects fix
v0.155.2 New feature
Notable features
  • WebAuthn and PAM session MFA support
  • Redis resource access for PAM
  • Databricks secrets rotation
v0.155.1 Mixed
Notable features
  • Oracle DB wallet support on self-hosted instances
  • PAM request access modal callout
  • Updated project group membership page with v3 component additions
Full changelog

What's Changed

  • improvement(frontend): update project group membership page and v3 component additions by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5072
  • feat(pam): request access modal callout by @x032205 in https://github.com/Infisical/infisical/pull/5108
  • feature(oracle): allow usage of wallet for oracleDB on self hosted instances by @x032205 in https://github.com/Infisical/infisical/pull/4879

Full Changelog: https://github.com/Infisical/infisical/compare/v0.155.0...v0.155.1

v0.155.0 New feature
⚠ Upgrade required
  • k8s operator has been moved out of the main repo; update any CI/CD pipelines or references accordingly.
  • SCIM external group mappings endpoint has been renamed; update any SCIM automation or API clients.
  • New .env.dev.example file added for contributors; review updated environment variable references.
Breaking changes
  • k8s operator removed from main repository (PR #5059); users relying on the operator from this repo must migrate to its new location.
  • SCIM external group mappings endpoint was renamed (PR #5053); API integrations using this endpoint must be updated.
Security fixes
  • Removed requester email from access grant URL to prevent PII leakage (PR #5041).
  • Fixed credentials hash calculation in external KMS (PR #5036).
Notable features
  • Kubernetes support for PAM (PR #4981).
  • Certificate-based SSH auth for PAM (PR #5042).
  • Auto-request access to PAM accounts (PR #5050).

Beta — feedback welcome: [email protected]