Release history
infisical releases
Infisical is the open-source platform for secrets, certificates, and privileged access management.
All releases
76 shown
Telemetry, revocation, PKI UI, env soft delete, MLD‑SA KMS
API, secret‑sync, LDAP, login, certificates, telemetry, docs
- Announcements for cloud and self-hosted deployments
- Tab and stepper components added to the UI library
- Project actions: create access and request access permissions
Full changelog
What's Changed
- docs(honeytokens): fix broken usage links and clarify setup copy by @jakehulberg in https://github.com/Infisical/infisical/pull/6367
- feature: tab and stepper components by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6334
- feat: add PostHog telemetry events for honey tokens by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6373
- fix: see docs to configure github message by @mathnogueira in https://github.com/Infisical/infisical/pull/6370
- improvement: revamp secret overview secret update and delete confirmation modals by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6357
- improvement: require change email confirmation by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6375
- fix: add doc on multiple
--pathforinfisical runby @mathnogueira in https://github.com/Infisical/infisical/pull/6378 - feature: announcements for cloud and self-hosted by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6355
- docs: add permissions section to honey tokens documentation by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6384
- fix: add ldap dynamic secret template valdiation by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6385
- chore(dev): add Bull Board service to docker-compose.dev.yml by @victorvhs017 in https://github.com/Infisical/infisical/pull/6376
- feat(permission): add project actions for creating and requesting access by @victorvhs017 in https://github.com/Infisical/infisical/pull/6359
- fix(platfor-339): index identity_access_tokens.subOrganizationId for cascade delete by @PrestigePvP in https://github.com/Infisical/infisical/pull/6377
- docs(permissions): update organization permissions documentation to include 'request-access' action for projects by @victorvhs017 in https://github.com/Infisical/infisical/pull/6390
- chore(upgrade-impact): backfill recent release data by @PrestigePvP in https://github.com/Infisical/infisical/pull/6273
- fix: use UPGRADE_TOOL_GITHUB_TOKEN secret in upgrade impact workflow by @PrestigePvP in https://github.com/Infisical/infisical/pull/6394
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.27...v0.159.28
- Added export and cell scroll to Postgres web access (pam)
- Supported RDP access for Active Directory domain accounts (pam)
Full changelog
What's Changed
- docs(pki): list supported subject attributes for certificate policies by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6337
- fix(aws-auth): escape regex metacharacters in ARN allowlist matching by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6344
- feat(pam): add export and cell scroll to postgres web access by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6321
- improvement(platfor-315): tolerate newer migration history on startup by @PrestigePvP in https://github.com/Infisical/infisical/pull/6329
- feat(pam): support RDP access for Active Directory domain accounts by @bernie-g in https://github.com/Infisical/infisical/pull/6255
- fix(request): rollback saferequest changes by @victorvhs017 in https://github.com/Infisical/infisical/pull/6353
- fix(inc-52): etag expiration by @PrestigePvP in https://github.com/Infisical/infisical/pull/6354
- fix(honey-tokens): validate signing key, stack name and region by @mathnogueira in https://github.com/Infisical/infisical/pull/6352
- fix: resolved dashobard not loading when honey token permission was missing by @akhilmhdh in https://github.com/Infisical/infisical/pull/6361
- feat: improved logging message for audit log queue by @akhilmhdh in https://github.com/Infisical/infisical/pull/6363
- docs(projectpage): resize project overview screenshots by @jakehulberg in https://github.com/Infisical/infisical/pull/6362
- fix: resolved sub org id selection in legacy loading by @akhilmhdh in https://github.com/Infisical/infisical/pull/6347
- improvement(frontend): fix select default text and icon display by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6317
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.26...v0.159.27
- Support syncing secrets to Vercel team with all custom environments
- Add custom CRL distribution points in PKI CAs
Full changelog
What's Changed
- improvement(navigation): go to role details when click on a row by @adilsitos in https://github.com/Infisical/infisical/pull/6241
- feat(secret-sync): support syncing to vercel team with all custom environments by @varonix0 in https://github.com/Infisical/infisical/pull/6136
- fix(approvals): add request ID to approval request mail by @varonix0 in https://github.com/Infisical/infisical/pull/6247
- fix: update textarea styling to prevent modal overflow by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6248
- fix: limit ACME requests to 5 minutes for external CAs by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6222
- docs(mcp): add AI agents callout and MCP setup page by @jakehulberg in https://github.com/Infisical/infisical/pull/6240
- chore: disable Telemetry in CI by @maidul98 in https://github.com/Infisical/infisical/pull/6253
- fix(kubernetes-auth): configurable TLS verification for identity Kubernetes auth by @victorvhs017 in https://github.com/Infisical/infisical/pull/6256
- feat: add custom CRL distribution points in PKI CAs by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6224
- fix: add missing ECDSA_P521 in the UI by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6252
- fix(pam): default access duration to policy max by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6206
- fix(k8s-auth): align TLS verification with CA presence and empty CA storage by @victorvhs017 in https://github.com/Infisical/infisical/pull/6261
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.24...v0.159.25
- Enforce TLS verification for identity auth providers
Full changelog
What's Changed
- chore: add logout to create org modal by @sheensantoscapadngan in https://github.com/Infisical/infisical/pull/6103
- fix: enforce TLS verification for identity auth providers by @victorvhs017 in https://github.com/Infisical/infisical/pull/6242
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.23...v0.159.24
- Gateway pools for high-availability failover
- Venafi TPP external CA integration
- Per-tab Postgres connections with isolated transactions for PAM
Full changelog
What's Changed
- feat: updated secret sharing delete to have 7 day grace by @akhilmhdh in https://github.com/Infisical/infisical/pull/6160
- fix(vercel-sync): filter team shared env vars to sync-owned set by @victorvhs017 in https://github.com/Infisical/infisical/pull/6144
- chore(cache-keys): move cache keys to single file by @adilsitos in https://github.com/Infisical/infisical/pull/6162
- feat(secret-rotation): support supabase by @mathnogueira in https://github.com/Infisical/infisical/pull/6130
- improvement(secrets-overview): remove tooltip delay duration on overview page table actions and add more options tooltip by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6145
- feat(frontend): add button to reveal secret reference values by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6143
- fix(pki): reject EST simple re-enroll with revoked client cert by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6163
- docs(pki-discovery): document ALLOW_INTERNAL_IP_CONNECTIONS option by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6157
- fix(pki): report correct enrollment type in auto-renewal error by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6159
- fix(signup): restore "Team Invite" attribution source for invited users by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6141
- docs: rename Agent Sentinel to Agent Vault with external link in Products nav by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6176
- fix(ui): brighten "Create New Connection" option in connection dropdown by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6192
- fix(ui): auto-switch environment view after uploading secrets by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6188
- chore: delete .github/workflows/one-time-secrets.yaml by @maidul98 in https://github.com/Infisical/infisical/pull/6203
- fix(db): gate OAuth verified migration on accepted users by @victorvhs017 in https://github.com/Infisical/infisical/pull/6173
- fix(scim): preserve orgId when listing groups by @victorvhs017 in https://github.com/Infisical/infisical/pull/6207
- improvement: add rotation icon to rotated secrets in single env display by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6053
- docs: remove projectName from audit log documentation by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6209
- chore: removed dependencies and api key service by @akhilmhdh in https://github.com/Infisical/infisical/pull/6161
- docs: add Prevent Value Reuse constraint to secret validation rules by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6212
- feat: add gateway pools for high-availability failover by @bernie-g in https://github.com/Infisical/infisical/pull/6050
- improvement: unrevert upgrade aws-sdk v2 to v3 by @PrestigePvP in https://github.com/Infisical/infisical/pull/5905
- feat(pam): per-tab Postgres connections with isolated transactions by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6154
- feat: add Venafi TPP external CA integration by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6032
- improvement(eng-4874): memoize org findByID by @PrestigePvP in https://github.com/Infisical/infisical/pull/6164
- improvement(frontend): update secret sharing UI by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6121
- fix(docs): replace broken Kubernetes icon URL with Font Awesome dharmachakra by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6217
- feat(e2e-tests): fips mode by @varonix0 in https://github.com/Infisical/infisical/pull/6214
- feat(secrets-overview): add tag, metadata and multiline encoding support to csv upload by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6156
- fix(email): include confirmation code in email subject line by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6218
- feat: added filter to audit log and improves the crypto by @akhilmhdh in https://github.com/Infisical/infisical/pull/6155
- feat(auth): store machine identity auth as identity actor by @mathnogueira in https://github.com/Infisical/infisical/pull/6101
- feat: user controlled ssl rejection option for dynamic secret by @akhilmhdh in https://github.com/Infisical/infisical/pull/6204
- feat: resolved hashedPassword not set for bootstrap admin by @akhilmhdh in https://github.com/Infisical/infisical/pull/6221
- improvement(secret-migration): add more paths in vault migration by @adilsitos in https://github.com/Infisical/infisical/pull/6215
- fix: fail on Schema generation for analytics by @maidul98 in https://github.com/Infisical/infisical/pull/6223
- improvement(frontend): add design.md and new batch of component stories by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6211
- fix(gateway): add support for gateway v2 on vault migration by @adilsitos in https://github.com/Infisical/infisical/pull/6227
- improvement(secrets-rotation): allow move between environments and folders by @adilsitos in https://github.com/Infisical/infisical/pull/6220
- fix: missing gateway-v2 handling on venafi tpp by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6226
- feat(smtp): add SMTP_HELO_HOST to set the EHLO/HELO hostname by @quarckster in https://github.com/Infisical/infisical/pull/6229
New Contributors
- @quarckster made their first contribution in https://github.com/Infisical/infisical/pull/6229
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.22...v0.159.23
- Gitpod support for secret sync
Full changelog
What's Changed
- feat(secret-sync): add support for gitpod (Ona) by @adilsitos in https://github.com/Infisical/infisical/pull/6119
- chore: more updates on by @akhilmhdh in https://github.com/Infisical/infisical/pull/6149
- fix(api): use Bitbucket user workspaces endpoint for listing by @victorvhs017 in https://github.com/Infisical/infisical/pull/6152
- chore: rename developer to member by @varonix0 in https://github.com/Infisical/infisical/pull/6148
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.21...v0.159.22
Minor fixes and improvements.
Full changelog
What's Changed
- fix(group): run filters, ordering and pagination in backend by @mathnogueira in https://github.com/Infisical/infisical/pull/6114
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.20...v0.159.21
- Disallow TOTP token reuse
- Prevent TOTP token reuse
- Travis CI sync support
- DigiCert CertCentral CA
Full changelog
What's Changed
- fix: table re-render without debounce by @varonix0 in https://github.com/Infisical/infisical/pull/6104
- fix: only lockout if identity lockout is enabled by @varonix0 in https://github.com/Infisical/infisical/pull/6120
- feat: updated the mfa check by @akhilmhdh in https://github.com/Infisical/infisical/pull/6115
- fix: cert-manager nav by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6126
- feat: updated more checks by @akhilmhdh in https://github.com/Infisical/infisical/pull/6127
- fix: resolved the user id going null by @akhilmhdh in https://github.com/Infisical/infisical/pull/6128
- chore: address read after write issue for secret folders by @sheensantoscapadngan in https://github.com/Infisical/infisical/pull/6056
- fix: certificate patches by @sheensantoscapadngan in https://github.com/Infisical/infisical/pull/6129
- improvement(secrets-232): memoize project ID look up and remove unneeded checks. by @PrestigePvP in https://github.com/Infisical/infisical/pull/6118
- fix(eng-4868): disallow reusing TOTP tokens by @PrestigePvP in https://github.com/Infisical/infisical/pull/6112
- feat: more updates on checks by @akhilmhdh in https://github.com/Infisical/infisical/pull/6131
- fix(frontend): prevent Add Sync modal overflow on small/zoomed viewports by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6133
- fix(frontend): invalidate approval request queries at project scope by @victorvhs017 in https://github.com/Infisical/infisical/pull/6135
- feat(kms): bulk export private keys by @victorvhs017 in https://github.com/Infisical/infisical/pull/6083
- feat: add a reason field before PAM account access by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6096
- fix(migration): drop queue_jobs trigger before dropping table by @leeyspaul in https://github.com/Infisical/infisical/pull/6110
- feat: prevent reuse of previous secret values by @varonix0 in https://github.com/Infisical/infisical/pull/6123
- feat: display pam aws credentials for cli access by @x032205 in https://github.com/Infisical/infisical/pull/6122
- feat(sync-secret): add app connection and secret sync for Travis CI by @adilsitos in https://github.com/Infisical/infisical/pull/6097
- fix: hiccups found in the application by @PrestigePvP in https://github.com/Infisical/infisical/pull/6138
- feat: add DigiCert CertCentral External CA by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6125
- fix: fixes for secret sharings and other areas by @PrestigePvP in https://github.com/Infisical/infisical/pull/6146
New Contributors
- @leeyspaul made their first contribution in https://github.com/Infisical/infisical/pull/6110
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.19...v0.159.20
- Secret rotation v1 removed - migrate to newer implementation
- PAM with dedicated domains section
- PKI post-quantum cryptography readiness pie chart and trend
- AWS ACM Public CA support
Full changelog
What's Changed
- feat(pam): move ad server resources to dedicated domains section by @x032205 in https://github.com/Infisical/infisical/pull/5982
- feat: remove upgrade-path page and backend service by @mathnogueira in https://github.com/Infisical/infisical/pull/6085
- feat: updated default config for request by @akhilmhdh in https://github.com/Infisical/infisical/pull/6099
- feat(pki): pqc readiness pie + trend chart and inventory preset views by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6084
- feat: resovled ts error and new token type by @akhilmhdh in https://github.com/Infisical/infisical/pull/6100
- docs(selfhost): render kubernetes logo on self-hosting overview card by @jakehulberg in https://github.com/Infisical/infisical/pull/6098
- fix(pki): rename Unstable* v3 imports in PQC dashboard by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6102
- feat: removed secret rotation v1 by @akhilmhdh in https://github.com/Infisical/infisical/pull/6105
- feat(frontend): show systemd CLI command in re-enroll gateway modal by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6107
- fix: pam nav by @x032205 in https://github.com/Infisical/infisical/pull/6109
- fix: resolved user group addition failing by @akhilmhdh in https://github.com/Infisical/infisical/pull/6113
- feat(pki): add AWS ACM Public CA support by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6069
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.18...v0.159.19
- Vercel sync
Full changelog
What's Changed
- fix(frontend): prevent duplicated 'v' in on-prem version badge by @Erwan-loot in https://github.com/Infisical/infisical/pull/6068
- fix: resolved recovery account failing in frontend by @akhilmhdh in https://github.com/Infisical/infisical/pull/6092
- feat: add new vercel sync feature by @maidul98 in https://github.com/Infisical/infisical/pull/6093
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.17...v0.159.18
- Unified external migrations UI with in-platform Doppler support
- Ghost accordion variant for components
Full changelog
What's Changed
- improvement(components): add ghost accordion variant, accordion stories and remove unstable v3 prefix by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6081
- feat(webhook): fix UI by @adilsitos in https://github.com/Infisical/infisical/pull/6086
- feature: doppler in-platform migration and unified external migrations UI by @IgorHorta in https://github.com/Infisical/infisical/pull/5875
- fix: one-password auto-fill by @varonix0 in https://github.com/Infisical/infisical/pull/6082
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.16...v0.159.17
- Project permission caching
- Gateway authentication for Kubernetes
- Webhook editing with event selection
Full changelog
What's Changed
- fix: null values for unknown pki dashboard fields by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6066
- chore: condition update by @akhilmhdh in https://github.com/Infisical/infisical/pull/6055
- docs(dockerswarm): consolidate self-hosting overview cards into single grid by @jakehulberg in https://github.com/Infisical/infisical/pull/6038
- feat: restructure Certificate Manager navigation by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6044
- docs(vercelvideo): add walkthrough video to Vercel Sync page by @jakehulberg in https://github.com/Infisical/infisical/pull/6073
- feature(cache): project permission caching by @maidul98 in https://github.com/Infisical/infisical/pull/6042
- docs(pam): effectiveness note for command blocking by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6070
- feat(pam): gateway auth for kubernetes by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/6021
- chore: hubSpot UTK tracking for cloud instances signup by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6071
- chore: improve PostHog dedicated instances flow by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6045
- fix(platfor-290): remove distinct on lookup by @PrestigePvP in https://github.com/Infisical/infisical/pull/6079
- feat(auth): reapply and adapt #6029 to match the new auth system by @mathnogueira in https://github.com/Infisical/infisical/pull/6072
- feat(login-v2): flag users that are still using V2 login by @mathnogueira in https://github.com/Infisical/infisical/pull/6074
- feat(webhook): add edit and event selection by @adilsitos in https://github.com/Infisical/infisical/pull/5984
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.15...v0.159.16
- Audit logs date range picker redesigned
- Auth token query staleTime set to 0 for fresh data retrieval
Full changelog
What's Changed
- feat(audit-logs): redesign the date range picker by @mathnogueira in https://github.com/Infisical/infisical/pull/6033
- fix(frontend): invalidate auth token after org select; default query staleTime by @victorvhs017 in https://github.com/Infisical/infisical/pull/6002
- chore: bump transitive dependencies by @x032205 in https://github.com/Infisical/infisical/pull/6054
- Revert "fix(frontend): invalidate auth token after org select; default query staleTime" by @maidul98 in https://github.com/Infisical/infisical/pull/6058
- Revert "feat: add insights page to secrets management product type" by @varonix0 in https://github.com/Infisical/infisical/pull/6060
- fix: remove recharts and pki dashboard by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6061
- fix(frontend): invalidate auth token after org select; default query staleTime by @maidul98 in https://github.com/Infisical/infisical/pull/6059
- fix: add back recharts, pki dashboard and manually chunk rechart dependencies by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6063
- fix: reapply "feat: add insights page to secrets management product type" by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6064
- fix(frontend): set staleTime to 0 for auth token query to ensure fresh data retrieval by @victorvhs017 in https://github.com/Infisical/infisical/pull/6065
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.14...v0.159.15
- Dependabot security vulnerability fixes
- Gateway enrollment token flow
- Inventory and dashboard rework for PKI
- Insights page for secrets management
Full changelog
What's Changed
- fix: use actual actor as distinctId for IntegrationSynced PostHog event by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6028
- feat: add deployment_type, instance_type, and region to PostHog telemetry by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/5976
- feat(login): show login SMTP errors in case of misconfiguration by @mathnogueira in https://github.com/Infisical/infisical/pull/6029
- Revert "feat(login): show login SMTP errors in case of misconfiguration" by @akhilmhdh in https://github.com/Infisical/infisical/pull/6039
- feature(cache): project permission caching by @victorvhs017 in https://github.com/Infisical/infisical/pull/6031
- feat: refactor of auth by @akhilmhdh in https://github.com/Infisical/infisical/pull/5947
- fix: improved response for the discovery endpoint by @x032205 in https://github.com/Infisical/infisical/pull/6040
- Revert "feature(cache): project permission caching" by @maidul98 in https://github.com/Infisical/infisical/pull/6041
- feat: inventory+dashboard rework on PKI by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/5958
- fix: made totp verify lax by @sheensantoscapadngan in https://github.com/Infisical/infisical/pull/6049
- improvement(eng-4792): speed up CI by @PrestigePvP in https://github.com/Infisical/infisical/pull/6018
- fix: dependabot security vulnerabilities by @x032205 in https://github.com/Infisical/infisical/pull/6035
- improvement: make email verifcation required banner less spooky by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6051
- feat: add insights page to secrets management product type by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5968
- improvement(frontend): reduce default integration and approval polling intervals by @victorvhs017 in https://github.com/Infisical/infisical/pull/6003
- fix(pam): increase web access idle timeout from 5 to 20 minutes by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/6052
- feat: gateway enrollment token flow by @bernie-g in https://github.com/Infisical/infisical/pull/6020
- feat: add oci standard labels to Dockerfile.standalone-infisical by @Erwan-loot in https://github.com/Infisical/infisical/pull/5323
- feat: add dynamic challenges to SCEP by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/6023
- feat: add bulk tag modal to overview page by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/6043
New Contributors
- @Erwan-loot made their first contribution in https://github.com/Infisical/infisical/pull/5323
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.13...v0.159.14
- Account policies for PAM
Full changelog
What's Changed
- docs(proxy): add description for event based cache refresh by @adilsitos in https://github.com/Infisical/infisical/pull/6030
- feat(pam): account policies by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/5971
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.12...v0.159.13
- Post-Quantum Crypto algorithms to PKI
- MS Teams workflow support
- Access approval revoke functionality
- AI session insights for privileged access management
- Real-time session log sync via incremental batch uploads
- Request-scoped memoization for optimized database reads
- NetScaler PKI sync integration added
- resourceType permission condition support for PAM resources and accounts
UI improvements, password generator validation, and project permission enhancements.
Full changelog
What's Changed
- fix(ua-identity): check if provided orgSlug is equal to org slug by @adilsitos in https://github.com/Infisical/infisical/pull/5928
- docs(removal): remove Docker Swarm documentation entirely by @jakehulberg in https://github.com/Infisical/infisical/pull/5933
- fix: remove old route redirect compatibility by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5921
- improvement: migrate add/edit folder modal to v3 components by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5927
- docs(update): add self-hosting video to Docker Compose doc by @jakehulberg in https://github.com/Infisical/infisical/pull/5931
- fix: display boolean values as true/false instead of t/f in Data Explorer by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/5935
- feat: enable full PostHog telemetry for all instance types by @devin-ai-integration[bot] in https://github.com/Infisical/infisical/pull/5893
- improvement: improve affected resources table col proportions by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5907
- feat: password generator secret validation rules by @varonix0 in https://github.com/Infisical/infisical/pull/5930
- fix: added missing project permissions by @varonix0 in https://github.com/Infisical/infisical/pull/5934
Full Changelog: https://github.com/Infisical/infisical/compare/v0.159.7...v0.159.8
- Sub-org to root-org secret access delegation
- Custom roles restricted to Enterprise plans; creation enforcement begins June 1, 2026. Pro users must use additional privileges or upgrade.
- SSH certificate provider for dynamic secrets
- User field added to secret.change webhooks
- Tag filtering in overview dashboard
- SSH PAM Exec and SFTP Support
- Active Session Termination
- Vertical navbar layout
- Secret access insights sheet
- Magic number validation for sharing
- PAM Windows rotation
- Postgres in-browser data explorer
- Webhook support for rotations
Fixed project template editing to prevent unnecessary updates and improved job logging reliability.
- Approval request expiration time
- New PKI alert types
- Custom roles in org invites
- IP address SAN support
- Azure Key Vault certificate import option
- SCEP enrollment method
- Automated AD CS intermediate CA signing
- Infisical-to-Infisical sync
- PKI certificate metadata RBAC conditions
- HP iLO password rotation
- Code-signing PKI support
- Windows local account and dependency discovery
- Helm OCI registry push
- PostHog identity tracking
- PAM card grid UI
- Redis web access
- machine identity PostHog events
- secrets-overview batch operations
- credential rotations
- PostHog approval workflow tracking
- SPIFFE machine authentication
- Unix rotation fallback mechanism
Fixed secret value overwrites in batch operations, restored service account names in Helm charts, and improved ACME DNS configuration for PKI.
- Redis stream-based log aggregator
- Dynamic secret PostHog tracking
- PostHog org enrichment
- Helm extraEnv support
- Redis cluster KMS support
- Clickhouse dynamic secret provider
- PAM web and SSH browser access
- Vault secret import
- Permission forbid rule priority
- Daily PKI expiration alerts
- Kubernetes auth wildcard/regex support
- Environment creation on overview page
- Secret import support
- Bulk operation timeout prevention
- New membership API
- Azure DNS ACME provider
- AWS Private CA integration
Improved secret rotation validation to detect and prevent credential conflicts before attempting external system rotations.
- PAM web launcher for PostgreSQL
- Windows Server support
- Fly.io automatic redeployment
- Event architecture revamp
- PKI Cloudflare sync
- dbt app connection and secret rotation
- Certificate policy creation from profiles
- OpenRouter API key rotation
- Windows local account rotation
- PKI approval workflows
- User account recovery
- MCP server support
- GitLab fullName support
- Users in project templates
- Support for encrypted metadata for secrets
- Enhanced LDAP authentication error handling and validation
Full changelog
What's Changed
- fix: unhide all api paths in dev mode by @varonix0 in https://github.com/Infisical/infisical/pull/5220
- feat: support for encrypted metadata for secrets by @akhilmhdh in https://github.com/Infisical/infisical/pull/5203
- fix: enhance LDAP authentication error handling and validation by @luizbafilho in https://github.com/Infisical/infisical/pull/5213
New Contributors
- @luizbafilho made their first contribution in https://github.com/Infisical/infisical/pull/5213
Full Changelog: https://github.com/Infisical/infisical/compare/v0.156.1...v0.156.2
Removed dev dependencies from final Docker build output and updated dependencies.
- Granular PII filtering with configurable entity types in agent-sentinel
- One-action approve-and-merge button for change requests
- V3 button stabilization with stories
Full changelog
What's Changed
- feat(agent-sentinel): add granular PII filtering with configurable entity types by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/5201
- improvement(frontend): add button to approve and merge change request in one action if tenable by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5206
- feature(frontend): stabilize v3 button with stories by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5175
- fix(pam): k8s create account not working due to rotation by @x032205 in https://github.com/Infisical/infisical/pull/5219
- improvement(oidc): don't send organization invitation email if the server doesn't have email login enabled by @victorvhs017 in https://github.com/Infisical/infisical/pull/5216
- docs: multiple operator namespaces by @varonix0 in https://github.com/Infisical/infisical/pull/5223
Full Changelog: https://github.com/Infisical/infisical/compare/v0.155.7...v0.156.0
{ "summary": "Added support for issuing intermediate CAs via certificate profiles, Cassandra dynamic secret support for vault-migration, and name-based RBAC permission conditions for MCP endpoints in agent-sentinel. Fixed frontend commit comparison display and improved host validation errors.", "summary_short": "Added intermediate CA support, Cassandra dynamic secrets, and MCP endpoint RBAC conditions.", "summary_short_alt": "Implemented intermediate CA issuance, Cassandra dynamic secrets,
- Certificate template has been renamed to certificate policy — users relying on this terminology in workflows or documentation should update references accordingly.
- Unix/Linux password rotation support added
- Certificate template renamed to certificate policy (may affect UI references and documentation)
- Node.js version updated to 20.20.0; ensure your environment matches this version if self-hosting.
- Bearer Token authentication support for MCP servers in agent-sentinel
- Custom branding support for secret-share
- SSH app connection support
- Reduced toast notification duration
Full changelog
What's Changed
- improvement(frontend): decrease toast duration by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5159
- feat: ssh app connection by @akhilmhdh in https://github.com/Infisical/infisical/pull/5169
- fix(agent-sentinel): oauth double-click issue by @saifsmailbox98 in https://github.com/Infisical/infisical/pull/5168
- chore: add Mintlify GTM integration to docs.json by @carlosmonastyrski in https://github.com/Infisical/infisical/pull/5173
- fix: list project identities by @varonix0 in https://github.com/Infisical/infisical/pull/5174
Full Changelog: https://github.com/Infisical/infisical/compare/v0.155.3...v0.155.4
- Improved dynamic secret username templating for more flexible customization
- API-level searchable Vercel projects fix
- WebAuthn and PAM session MFA support
- Redis resource access for PAM
- Databricks secrets rotation
- Oracle DB wallet support on self-hosted instances
- PAM request access modal callout
- Updated project group membership page with v3 component additions
Full changelog
What's Changed
- improvement(frontend): update project group membership page and v3 component additions by @scott-ray-wilson in https://github.com/Infisical/infisical/pull/5072
- feat(pam): request access modal callout by @x032205 in https://github.com/Infisical/infisical/pull/5108
- feature(oracle): allow usage of wallet for oracleDB on self hosted instances by @x032205 in https://github.com/Infisical/infisical/pull/4879
Full Changelog: https://github.com/Infisical/infisical/compare/v0.155.0...v0.155.1
- k8s operator has been moved out of the main repo; update any CI/CD pipelines or references accordingly.
- SCIM external group mappings endpoint has been renamed; update any SCIM automation or API clients.
- New .env.dev.example file added for contributors; review updated environment variable references.
- k8s operator removed from main repository (PR #5059); users relying on the operator from this repo must migrate to its new location.
- SCIM external group mappings endpoint was renamed (PR #5053); API integrations using this endpoint must be updated.
- Removed requester email from access grant URL to prevent PII leakage (PR #5041).
- Fixed credentials hash calculation in external KMS (PR #5036).
- Kubernetes support for PAM (PR #4981).
- Certificate-based SSH auth for PAM (PR #5042).
- Auto-request access to PAM accounts (PR #5050).