<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Vault - Package Updates]]></title><description><![CDATA[<p dir="auto">You can use this thread to track updates to the Vault package.</p>
<p dir="auto"><strong>Please open issues in a separate topic instead of replying here.</strong></p>
]]></description><link>https://forum.cloudron.io/topic/2783/vault-package-updates</link><generator>RSS for Node</generator><lastBuildDate>Tue, 15 Sep 2026 15:27:46 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/2783.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 06 Jul 2020 20:44:54 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Vault - Package Updates on Wed, 02 Sep 2026 07:32:52 GMT]]></title><description><![CDATA[<p dir="auto">[1.84.0]</p>
<ul>
<li>Update vault to 2.1.0</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v2.1.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>core: Update <a href="http://go.etcd.io/etcd/client/pkg/v3" target="_blank" rel="noopener noreferrer nofollow ugc">go.etcd.io/etcd/client/pkg/v3</a> to v3.7.1 to fix security vulnerability GO-2026-6107.</li>
<li>core: Update <a href="http://software.sslmate.com/src/go-pkcs12" target="_blank" rel="noopener noreferrer nofollow ugc">software.sslmate.com/src/go-pkcs12</a> to v0.7.2 to fix security vulnerability GO-2026-5052.</li>
<li><strong>Agent Registry UI (enterprise)</strong>: Adds a new Agentic Security section to the primary navigation with an Agent Registry page where operators can view, search, and manage registered AI agents, their associated Vault entities and aliases, assigned policies, and operational status.</li>
<li><strong>Automatic DNS-01 Challenge Fulfillment for PKI External CA</strong>: Integrate with the following DNS providers for automatic DNS-01 challenge fulfillment: AWS Route53, Azure DNS, Google Cloud DNS, and BIND and other RFC2136-compliant servers.</li>
<li><strong>PKI <a href="https://github.com/PKCS/vault/issues/12" target="_blank" rel="noopener noreferrer nofollow ugc">PKCS#12</a> and JKS Support</strong>: Adds support for <a href="https://github.com/PKCS/vault/issues/12" target="_blank" rel="noopener noreferrer nofollow ugc">PKCS#12</a> (PFX) and Java keytool (JKS) certificate bundles to relevant PKI endpoints. Bundles are returned as base64-encoded, password-protected files.</li>
<li><strong>SLH-DSA support for Hybrid sign/verify in Transit engine (enterprise)</strong>: Add support for SLH-DSA as the PQC component for Hybrid sign/verify operations. This is compatible with both ECDSA (p-256, P-384, P-521) and <a href="https://github.com/hashicorp/vault/commit/Ed25519" target="_blank" rel="noopener noreferrer nofollow ugc"><code>Ed25519</code></a>.</li>
<li>agent/pki-external-ca: Fix CA chain extraction from Vault PKI API responses where <code>ca_chain</code> field was always empty in templates due to incorrect type handling of array responses</li>
<li>api: Account for the HTTP Age header when calculating a lease's remaining lifetime, so that leases read or renewed through a caching proxy such as Vault Agent are renewed before they expire.</li>
<li>core/login: Fix panic on malformed login requests. Vault now returns an error for malformed login payloads instead of dropping the client connection (no data loss).</li>
<li>secrets/database: Sanitize the caller-controlled DisplayName before it is used in generated usernames to prevent SQL injection via username templates. Adds a configuration warning when a username_template references DisplayName without a truncate function.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/128856</link><guid isPermaLink="true">https://forum.cloudron.io/post/128856</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 02 Sep 2026 07:32:52 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Wed, 05 Aug 2026 00:04:48 GMT]]></title><description><![CDATA[<p dir="auto">[1.83.5]</p>
<ul>
<li>Update vault to 2.0.4</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v2.0.4" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>containers: The following packages have been removed from UBI based container images: gnupg, openssl, procps.</li>
<li>acl: Fix privilege-escalation vulnerability where a <code>denied_parameters</code> constraint on the <code>policies</code> request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the <code>policies</code> parameter to lowercase before evaluating <code>allowed_parameters</code>/<code>denied_parameters</code> constraints.</li>
<li>core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with duplicate attributes now always fails, and the VAULT_ALLOW_PENDING_REMOVAL_DUPLICATE_HCL_ATTRIBUTES environment variable that previously restored the legacy behavior has been removed.</li>
<li>secrets: Added ability to view secrets in YAML format</li>
<li>auth/cert: Support login via x-forwarded cert headers even with tls disabled on the vault listener.</li>
<li>Proxy/Agent: Fixed a bug where auth method headers accumulated on the shared API client across re-auth cycles.</li>
<li>audit: Fix a regression from CVE-2025-6000 that broke enabling audit devices on Windows when a plugin directory was configured.</li>
<li>auth/cert: Add support for x-forwarded cert headers coming from AWS ALBs.</li>
<li>core: Preserve URL query parameters when redirecting API requests containing duplicate slashes to their canonical path. Previously, the redirect dropped parameters such as <code>?list=true</code>, potentially changing the result of the request.</li>
<li>secrets-sync: Fix GCP Secret Manager destinations losing their per-region KMS key on Vault restart.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/127723</link><guid isPermaLink="true">https://forum.cloudron.io/post/127723</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 05 Aug 2026 00:04:48 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 18 Jun 2026 07:08:03 GMT]]></title><description><![CDATA[<p dir="auto">[1.83.4]</p>
<ul>
<li>Update vault to 2.0.3</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v2.0.3" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>auth/radius: Added case_insensitive_names toggle to prevent username collisions and enable case-insensitive user handling.</li>
<li>core/acl: Fix LIST ACL bypass where a trailing-slash request could skip a more-specific deny rule.</li>
<li>core: Use constant-time recovery token comparison</li>
<li>core/acl: LIST requests with a trailing slash now correctly respect more-specific deny policies. Previously, a deny on <code>path "kv/*" { deny }</code> could be bypassed for <code>LIST kv/private/</code> if a broader allow <code>path "kv/*"</code> also existed. Policies relying on the previous (incorrect) behavior may now be denied.</li>
<li>core: Vault will now redirect non-canonicalized paths (containing <code>/./</code>, <code>/../</code>, or <code>//</code>) to a cleaned path, instead of rejecting these requests</li>
<li><strong>AI Agent Support (Beta/Enterprise)</strong>: Adds beta support for first-class AI agents. Adds an Agent Registry to register agents, and adds support for using Vault as an OAuth resource server for registered agent entities. When configured, allows OAuth 2.0 JWTs to be used to directly authorize requests to Vault, without needing a Vault token.</li>
<li>core/rotationMgr: Fix storage routing for local mounts in namespaces to prevent metadata replication and ensure GDPR compliance.</li>
<li>secrets/pki: Fix PKI certificate issuance not_after time to respect max TTL.</li>
<li>secrets/transit: Add managed key support to Transit rewrap endpoint.</li>
<li>storage/raft: reject <code>performance_multiplier</code> values less than or equal to zero</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/125866</link><guid isPermaLink="true">https://forum.cloudron.io/post/125866</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 18 Jun 2026 07:08:03 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Sat, 06 Jun 2026 07:59:10 GMT]]></title><description><![CDATA[<p dir="auto">[1.83.3]</p>
<ul>
<li>Update vault to 2.0.2</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v2.0.2" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>containers: Remove <code>cap_ipc_lock</code> capability on <code>vault</code> at build time to allow running Vault in common container runtimes. Vault in containers will no longer be able to call <code>mlock()</code> to lock memory. Operators should set <code>disable_mlock = true</code> in Vault's configuration. Runtime operators are advised to disable swapping to guarantee data safety.</li>
<li>secrets/ssh: RSA key sizes are now limited to a maximum size of 8192 bits addressing CVE-2026-39829</li>
<li>plugins: Fix plugin signature verification failure with expired pgp key when registering a plugin.</li>
<li>ui/transit: Fix key version dropdown selected state when editing a transit key.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/125555</link><guid isPermaLink="true">https://forum.cloudron.io/post/125555</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Sat, 06 Jun 2026 07:59:10 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Wed, 20 May 2026 09:50:44 GMT]]></title><description><![CDATA[<p dir="auto">[1.83.2]</p>
<ul>
<li>Update vault to 2.0.1</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/124909</link><guid isPermaLink="true">https://forum.cloudron.io/post/124909</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 20 May 2026 09:50:44 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Wed, 13 May 2026 10:38:48 GMT]]></title><description><![CDATA[<p dir="auto">[1.83.1]</p>
<ul>
<li>fix: update doc links from /apps/ to /packages/</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/124682</link><guid isPermaLink="true">https://forum.cloudron.io/post/124682</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 13 May 2026 10:38:48 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Wed, 15 Apr 2026 05:53:13 GMT]]></title><description><![CDATA[<p dir="auto">[1.83.0]</p>
<ul>
<li>Update vault to 2.0.0</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v2.0.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>PKI External CA (Enterprise): A new plugin that provides the ability to acquire PKI certificates from Public CA providers through the ACME protocol</li>
<li>IBM PAO License Integration: Added IBM PAO license support, allowing usage of Vault Enterprise with an IBM PAO license key.</li>
<li>A new configuration stanza <code>license_entitlement</code> is required in the Vault config to use an IBM license. For more details, see</li>
<li>the <a href="https://developer.hashicorp.com/vault/docs/license#ibm-pao-license-keys" target="_blank" rel="noopener noreferrer nofollow ugc">License documentation</a>.</li>
<li>KMIP Bring Your Own CA: Add new API to manage multiple CAs for client verification and make it possible to import external CAs.</li>
<li>LDAP Secrets Engine Enterprise Plugin: Add the new LDAP Secrets Engine Enterprise plugin. This enterprise version adds support for self-managed static roles and Rotation Manager support for automatic static role rotation. New plugin configurations can be set as "self managed", skipping the requirement for a bindpass field and allowing static roles to use their own password to rotate their credential. Automated static role credential rotation supports fine-grained scheduled rotations and retry policies through Vault Enterprise.</li>
<li>Login MFA TOTP Self-Enrollment (Enterprise): Simplify creation of login MFA TOTP credentials for users, allowing them to self-enroll MFA TOTP using a QR code (TOTP secret) generated during login. The new functionality is configurable on the TOTP login MFA method configuration screen and via the <code>enable_self_enrollment</code> parameter in the API.</li>
<li>Plugins (Enterprise): Allow overriding pinned version when creating and updating database engines</li>
<li>Plugins (Enterprise): Allow overriding pinned version when enabling and tuning auth and secrets backends</li>
<li>Template Integration for PublicPKICA: Vault Agent templates are now automatically re-rendered when a PKI external CA certificate is issued or renewed.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/123434</link><guid isPermaLink="true">https://forum.cloudron.io/post/123434</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 15 Apr 2026 05:53:13 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Wed, 11 Mar 2026 11:25:32 GMT]]></title><description><![CDATA[<p dir="auto">[1.82.5]</p>
<ul>
<li>Fixup doc URL</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/121642</link><guid isPermaLink="true">https://forum.cloudron.io/post/121642</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Wed, 11 Mar 2026 11:25:32 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 05 Mar 2026 09:51:50 GMT]]></title><description><![CDATA[<p dir="auto">[1.82.4]</p>
<ul>
<li>Update vault to 1.21.4</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.21.4" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/121282</link><guid isPermaLink="true">https://forum.cloudron.io/post/121282</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 05 Mar 2026 09:51:50 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 08 Jan 2026 07:52:09 GMT]]></title><description><![CDATA[<p dir="auto">[1.82.2]</p>
<ul>
<li>Update vault to 1.21.2</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.21.2" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>auth/oci: bump plugin to v0.20.1</li>
<li>core: Bump Go version to 1.25.5</li>
<li>packaging: Container images are now exported using a compressed OCI image layout.</li>
<li>packaging: UBI container images are now built on the UBI 10 minimal image.</li>
<li>secrets/azure: Update plugin to v0.25.1+ent. Improves retry handling during Azure application and service principal creation to reduce transient failures.</li>
<li>storage: Upgrade aerospike client library to v8.</li>
<li>core/activitylog (enterprise): Resolve a stability issue where Vault Enterprise could encounter a panic during month-end billing activity rollover.</li>
<li>http: skip JSON limit parsing on cluster listener.</li>
<li>quotas: Vault now protects plugins with ResolveRole operations from panicking on quota creation.</li>
<li>replication (enterprise): fix rare panic due to race when enabling a secondary with Consul storage.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/118125</link><guid isPermaLink="true">https://forum.cloudron.io/post/118125</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 08 Jan 2026 07:52:09 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 20 Nov 2025 08:36:42 GMT]]></title><description><![CDATA[<p dir="auto">[1.82.1]</p>
<ul>
<li>Update vault to 1.21.1</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.21.1" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/115681</link><guid isPermaLink="true">https://forum.cloudron.io/post/115681</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 20 Nov 2025 08:36:42 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 23 Oct 2025 06:24:38 GMT]]></title><description><![CDATA[<p dir="auto">[1.82.0]</p>
<ul>
<li>Update vault to 1.21.0</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.21.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>auth/ldap: fix MFA/TOTP enforcement bypass when username_as_alias is enabled.</li>
<li>activity: Renamed <code>timestamp</code> in export API response to <code>token_creation_time</code>.</li>
<li>http: Add JSON configurable limits to HTTP handling for JSON payloads: <code>max_json_depth</code>, <code>max_json_string_value_length</code>, <code>max_json_object_entry_count</code>, <code>max_json_array_element_count</code>.</li>
<li><strong>AES-CBC in Transit</strong> (Enterprise): Add support for encryption and decryption with AES-CBC in the Transit Secrets Engine.</li>
<li><strong>KV v2 Version Attribution</strong>: Vault now includes attribution metadata for versioned KV secrets. This allows lookup of attribution information for each version of KV v2 secrets from CLI and API.</li>
<li><strong>Login MFA TOTP Self-Enrollment (Enterprise)</strong>: Simplify creation of login MFA TOTP credentials for users, allowing them to self-enroll MFA TOTP using a QR code (TOTP secret) generated during login. The new functionality is configurable on the TOTP login MFA method configuration screen and via the <code>enable_self_enrollment</code> parameter in the API.</li>
<li>activity (enterprise): Fix <code>development_cluster</code> setting being overwritten on performance secondaries upon cluster reload.</li>
<li>auth/cert: Recover from partially populated caches of trusted certificates if one or more certificates fails to load.</li>
<li>auth/spiffe: Address an issue updating a role with overlapping workload_id_pattern values it previously contained.</li>
<li>core: Role based quotas now work for cert auth</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/114318</link><guid isPermaLink="true">https://forum.cloudron.io/post/114318</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 23 Oct 2025 06:24:38 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 25 Sep 2025 06:45:22 GMT]]></title><description><![CDATA[<p dir="auto">[1.81.4]</p>
<ul>
<li>Update vault to 1.20.4</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.20.4" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>core: Update <a href="http://github.com/ulikunitz/xz" target="_blank" rel="noopener noreferrer nofollow ugc">github.com/ulikunitz/xz</a> to fix security vulnerability GHSA-25xm-hr59-7c27. (<a href="https://github.com/hashicorp/vault/commit/ce4b42642403f30370dde0a39e9a04991c387291" target="_blank" rel="noopener noreferrer nofollow ugc">ce4b4264</a>)</li>
<li>database/snowflake: Update plugin to <a href="https://github.com/hashicorp/vault-plugin-database-snowflake/releases/tag/v0.14.2" target="_blank" rel="noopener noreferrer nofollow ugc">v0.14.2</a> (<a href="https://github.com/hashicorp/vault/commit/9f06df77b48024350fbc67b7d9a7eaaa5d0022fa" target="_blank" rel="noopener noreferrer nofollow ugc">9f06df77</a>)</li>
<li>Raft: Auto-join will now allow you to enforce IPv4 on networks that allow IPv6 and dual-stack enablement, which is on by default in certain regions. (<a href="https://github.com/hashicorp/vault/commit/1fd38796639ed861fc2fa1b58f138caad8fc0950" target="_blank" rel="noopener noreferrer nofollow ugc">1fd38796</a>)</li>
<li>auth/cert: Support RFC 9440 colon-wrapped Base64 certificates in <code>x_forwarded_for_client_cert_header</code>, to fix TLS certificate auth errors with Google Cloud Application Load Balancer. [<a href="https://github.com/hashicorp/vault/pull/31501" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31501</a>]</li>
<li>secrets/database (enterprise): Add support for reading, listing, and recovering static roles from a loaded snapshot. Also add support for reading static credentials from a loaded snapshot. (<a href="https://github.com/hashicorp/vault/commit/24cd1aa5961bfbed396251aebd3490dcfc7a106f" target="_blank" rel="noopener noreferrer nofollow ugc">24cd1aa5</a>)</li>
<li>secrets/ssh: Add support for recovering the SSH plugin CA from a loaded snapshot (enterprise only). (<a href="https://github.com/hashicorp/vault/commit/0087af9da59692351e7a3c3f5269af9de082a52e" target="_blank" rel="noopener noreferrer nofollow ugc">0087af9d</a>)</li>
<li>auth/cert: Recover from partially populated caches of trusted certificates if one or more certificates fails to load. [<a href="https://github.com/hashicorp/vault/pull/31438" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31438</a>]</li>
<li>core: Role based quotas now work for cert auth (<a href="https://github.com/hashicorp/vault/commit/fc775deacee3ab2dd956b8ab7ab64847601c1685" target="_blank" rel="noopener noreferrer nofollow ugc">fc775dea</a>)</li>
<li>sys/mounts: enable unsetting allowed_response_headers [<a href="https://github.com/hashicorp/vault/pull/31555" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31555</a>]</li>
<li>ui: Fix page loading error when users navigate away from identity entities and groups list views. (<a href="https://github.com/hashicorp/vault/commit/8117096364d5fbb541124a6e057cd11b24eaa6f3" target="_blank" rel="noopener noreferrer nofollow ugc">81170963</a>)</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/112956</link><guid isPermaLink="true">https://forum.cloudron.io/post/112956</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 25 Sep 2025 06:45:22 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Fri, 29 Aug 2025 07:34:17 GMT]]></title><description><![CDATA[<p dir="auto">[1.81.3]</p>
<ul>
<li>Update vault to 1.20.3</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.20.3" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>core: Bump Go version to 1.24.6. (<a href="https://github.com/hashicorp/vault/commit/ce56e14e7466ae80e05d11a83c8f41db0f4653be" target="_blank" rel="noopener noreferrer nofollow ugc">ce56e14e</a>)</li>
<li>http: Add JSON configurable limits to HTTP handling for JSON payloads: <code>max_json_depth</code>, <code>max_json_string_value_length</code>, <code>max_json_object_entry_count</code>, <code>max_json_array_element_count</code>. [<a href="https://github.com/hashicorp/vault/pull/31069" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31069</a>]</li>
<li>sdk: Upgrade to go-secure-stdlib/plugincontainer@v0.4.2, which also bumps <a href="http://github.com/docker/docker" target="_blank" rel="noopener noreferrer nofollow ugc">github.com/docker/docker</a> to v28.3.3+incompatible (<a href="https://github.com/hashicorp/vault/commit/8f1721697bba123117f4f98dae4154ef9fe614e5" target="_blank" rel="noopener noreferrer nofollow ugc">8f172169</a>)</li>
<li>secrets/openldap (enterprise): update plugin to v0.16.1</li>
<li>auth/ldap: add explicit logging to rotations in ldap [<a href="https://github.com/hashicorp/vault/pull/31401" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31401</a>]</li>
<li>core (enterprise): improve rotation manager logging to include specific lines for rotation success and failure</li>
<li>secrets/database: log password rotation success (info) and failure (error). Some relevant log lines have been updated to include "path" fields. [<a href="https://github.com/hashicorp/vault/pull/31402" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31402</a>]</li>
<li>secrets/transit: add logging on both success and failure of key rotation [<a href="https://github.com/hashicorp/vault/pull/31420" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31420</a>]</li>
<li>ui: Use the Helios Design System Code Block component for all readonly code editors and use its Code Editor component for all other code editors [<a href="https://github.com/hashicorp/vault/pull/30188" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30188</a>]</li>
<li>core (enterprise): fix a bug where issuing a token in a namespace used root auth configuration instead of namespace auth configuration</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/112158</link><guid isPermaLink="true">https://forum.cloudron.io/post/112158</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 29 Aug 2025 07:34:17 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 07 Aug 2025 08:10:31 GMT]]></title><description><![CDATA[<p dir="auto">[1.81.2]</p>
<ul>
<li>Update vault to 1.20.2</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.20.2" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>auth/ldap: fix MFA/TOTP enforcement bypass when username_as_alias is enabled [<a href="https://github.com/hashicorp/vault/pull/31427" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31427</a>,<a href="https://discuss.hashicorp.com/t/hcsec-2025-20-vault-ldap-mfa-enforcement-bypass-when-using-username-as-alias/76092" target="_blank" rel="noopener noreferrer nofollow ugc">HCSEC-2025-20</a>].</li>
<li>agent/template: Fixed issue where templates would not render correctly if namespaces was provided by config, and the namespace and mount path of the secret were the same. [<a href="https://github.com/hashicorp/vault/pull/31392" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31392</a>]</li>
<li>identity/mfa: revert cache entry change from <a href="https://github.com/hashicorp/vault/issues/31217" target="_blank" rel="noopener noreferrer nofollow ugc">#​31217</a> and document cache entry values [<a href="https://github.com/hashicorp/vault/pull/31421" target="_blank" rel="noopener noreferrer nofollow ugc">GH-31421</a>]</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/111344</link><guid isPermaLink="true">https://forum.cloudron.io/post/111344</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 07 Aug 2025 08:10:31 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Fri, 25 Jul 2025 12:56:36 GMT]]></title><description><![CDATA[<p dir="auto">[1.81.1]</p>
<ul>
<li>Update vault to 1.20.1</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.20.1" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/110682</link><guid isPermaLink="true">https://forum.cloudron.io/post/110682</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 25 Jul 2025 12:56:36 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Fri, 27 Jun 2025 13:22:50 GMT]]></title><description><![CDATA[<p dir="auto">[1.81.0]</p>
<ul>
<li>Update vault to 1.20.0</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.20.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>core: require a nonce when cancelling a rekey operation that was initiated within the last 10 minutes. [GH-30794],[HCSEC-2025-11]</li>
<li>UI: remove outdated and unneeded js string extensions [GH-29834]</li>
<li>activity (enterprise): The sys/internal/counters/activity endpoint will return actual values for new clients in the current month.</li>
<li>activity (enterprise): provided values for <code>start_time</code> and <code>end_time</code> in <code>sys/internal/counters/activity</code> are aligned to the corresponding billing period.</li>
<li>activity: provided value for <code>end_time</code> in <code>sys/internal/counters/activity</code> is now capped at the end of the last completed month. [GH-30164]</li>
<li>api: Update the default API client to check for the <code>Retry-After</code> header and, if it exists, wait for the specified duration before retrying the request. [GH-30887]</li>
<li>auth/alicloud: Update plugin to v0.21.0 [GH-30810]</li>
<li>auth/azure: Update plugin to v0.20.2. Login requires <code>resource_group_name</code>, <code>vm_name</code>, and <code>vmss_name</code> to match token claims [GH-30052]</li>
<li>auth/azure: Update plugin to v0.20.3 [GH-30082]</li>
<li>auth/azure: Update plugin to v0.20.4 [GH-30543]</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/109373</link><guid isPermaLink="true">https://forum.cloudron.io/post/109373</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 27 Jun 2025 13:22:50 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Fri, 30 May 2025 18:38:10 GMT]]></title><description><![CDATA[<p dir="auto">[1.80.5]</p>
<ul>
<li>Update vault to 1.19.5</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.19.5" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/107926</link><guid isPermaLink="true">https://forum.cloudron.io/post/107926</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 30 May 2025 18:38:10 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Sat, 17 May 2025 07:24:03 GMT]]></title><description><![CDATA[<p dir="auto">[1.80.4]</p>
<ul>
<li>Update vault to 1.19.4</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.19.4" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>Update vault-plugin-auth-cf to v0.20.1 <a href="https://github.com/hashicorp/vault/pull/30586" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30586</a>]</li>
<li>auth/azure: Update plugin to v0.20.4 <a href="https://github.com/hashicorp/vault/pull/30543" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30543</a>]</li>
<li>core: Bump Go version to 1.24.3.</li>
<li>Namespaces (enterprise): allow a root token to relock a namespace</li>
<li>core (enterprise): update to FIPS 140-3 cryptographic module in the FIPS builds.</li>
<li>core: Updated code and documentation to support FIPS 140-3 compliant algorithms. <a href="https://github.com/hashicorp/vault/pull/30576" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30576</a>]</li>
<li>core: support for X25519MLKEM768 (post quantum key agreement) in the Go TLS stack. <a href="https://github.com/hashicorp/vault/pull/30603" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30603</a>]</li>
<li>ui: Replaces all instances of the deprecated event.keyCode with event.key <a href="https://github.com/hashicorp/vault/pull/30493" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30493</a>]</li>
<li>core (enterprise): fix a bug where plugin automated root rotations would stop after seal/unseal operations</li>
<li>plugins (enterprise): Fix an issue where Enterprise plugins can't run on a standby node when it becomes active because standby nodes don't extract the artifact when the plugin is registered. Remove extracting from Vault and require the operator to place the extracted artifact in the plugin directory before registration.</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/107269</link><guid isPermaLink="true">https://forum.cloudron.io/post/107269</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Sat, 17 May 2025 07:24:03 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 01 May 2025 07:58:14 GMT]]></title><description><![CDATA[<p dir="auto">[1.80.3]</p>
<ul>
<li>Update vault to 1.19.3</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.19.3" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/106491</link><guid isPermaLink="true">https://forum.cloudron.io/post/106491</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 01 May 2025 07:58:14 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Sat, 19 Apr 2025 08:09:49 GMT]]></title><description><![CDATA[<p dir="auto">[1.80.2]</p>
<ul>
<li>Update vault to 1.19.2</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.19.2" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>core: Bump Go version to 1.23.8</li>
<li>secrets/openldap: Update plugin to v0.15.4 [<a href="https://github.com/hashicorp/vault/pull/30279" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30279</a>]</li>
<li>secrets/openldap: Prevent static role rotation on upgrade when <code>NextVaultRotation</code> is nil. Fixes an issue where static roles were unexpectedly rotated after upgrade due to a missing <code>NextVaultRotation</code> value. Now sets it to either <code>LastVaultRotation + RotationPeriod</code> or <code>now + RotationPeriod</code>. [<a href="https://github.com/hashicorp/vault/pull/30265" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30265</a>]</li>
<li>secrets/pki (enterprise): Address a parsing bug that rejected CMPv2 requests containing a validity field.</li>
<li>secrets/pki: fix a bug where key_usage was ignored when generating root certificates, and signing certain intermediate certificates. [<a href="https://github.com/hashicorp/vault/pull/30034" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30034</a>]</li>
<li>secrets/transit: fix a panic when rotating on a managed key returns an error [<a href="https://github.com/hashicorp/vault/pull/30214" target="_blank" rel="noopener noreferrer nofollow ugc">GH-30214</a>]</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/105956</link><guid isPermaLink="true">https://forum.cloudron.io/post/105956</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Sat, 19 Apr 2025 08:09:49 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Fri, 04 Apr 2025 16:43:10 GMT]]></title><description><![CDATA[<p dir="auto">[1.80.1]</p>
<ul>
<li>Update vault to 1.19.1</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.19.1" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
</ul>
]]></description><link>https://forum.cloudron.io/post/105182</link><guid isPermaLink="true">https://forum.cloudron.io/post/105182</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Fri, 04 Apr 2025 16:43:10 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 06 Mar 2025 08:06:02 GMT]]></title><description><![CDATA[<p dir="auto">[1.80.0]</p>
<ul>
<li>Update base image to 5.0.0</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/102685</link><guid isPermaLink="true">https://forum.cloudron.io/post/102685</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 06 Mar 2025 08:06:02 GMT</pubDate></item><item><title><![CDATA[Reply to Vault - Package Updates on Thu, 06 Mar 2025 07:56:11 GMT]]></title><description><![CDATA[<p dir="auto">[1.17.0]</p>
<ul>
<li>Update vault to 1.19.0</li>
<li><a href="https://github.com/hashicorp/vault/releases/tag/v1.19.0" target="_blank" rel="noopener noreferrer nofollow ugc">Full Changelog</a></li>
<li>raft/snapshotagent (enterprise): upgrade raft-snapshotagent to v0.0.0-20241115202008-166203013d8e</li>
<li>raft/snapshotagent (enterprise): upgrade raft-snapshotagent to v0.2.0</li>
<li>api: Add to sys/health whether the node has been removed from the HA cluster. If the node has been removed, return code 530 by default or the value of the <code>removedcode</code> query parameter. [<a href="https://github.com/hashicorp/vault/pull/28991" target="_blank" rel="noopener noreferrer nofollow ugc">GH-28991</a>]</li>
<li>api: Add to sys/health whether the standby node has been able to successfully send heartbeats to the active node and the time in milliseconds since the last heartbeat. If the standby has been unable to send a heartbeat, return code 474 by default or the value of the <code>haunhealthycode</code> query parameter. [<a href="https://github.com/hashicorp/vault/pull/28991" target="_blank" rel="noopener noreferrer nofollow ugc">GH-28991</a>]</li>
<li>auth/alicloud: Update plugin to v0.20.0 [<a href="https://github.com/hashicorp/vault/pull/29613" target="_blank" rel="noopener noreferrer nofollow ugc">GH-29613</a>]</li>
</ul>
]]></description><link>https://forum.cloudron.io/post/102682</link><guid isPermaLink="true">https://forum.cloudron.io/post/102682</guid><dc:creator><![CDATA[Package Updates]]></dc:creator><pubDate>Thu, 06 Mar 2025 07:56:11 GMT</pubDate></item></channel></rss>