This was a security patch to address several CVEs.
Added
- Added PostgreSQL support as a backing store to VSecM Safe.
- Fixed a bug that affected the polling interval to be faster than normal
in VSecM Sidecar. - Added use case examples on SPIFFE federation and Web Crypto API.
- Initiated a PoC VSecM Relay Client and VSecM Relay Server to enable
cross-cluster secret sharing.
Security
- Fixed GHSA-xr7q-jx4m-x55m Private tokens could appear in logs if context
containing gRPC metadata is logged in
github.com/grpc/grpc-go
Below are the generated release notes of every commit since the last release cut:
What's Changed
- Introducing initial helm-chart for version 0.28.1 by @v0lkan in #1193
- v0.28.1 manifests by @v0lkan in #1194
- docs by @v0lkan in #1195
- Add
raw
as a Secret Kind by @v0lkan in #1202 - External Secrest Operation Building Blocks by @v0lkan in #1204
- Unit test is added - Signed-off-by: Emincan Oguz <mailto:emincanoguz1… by @emincanoguz11 in #1209
- VSecM Clerk Initial Work by @v0lkan in #1212
- Using the new Go SDK by @v0lkan in #1213
- Minimally Working Version of VSecM Scout by @v0lkan in #1214
- Adding unit tests by @abhishek44sharma in #1217
- Remove Esteban from codeowners by @v0lkan in #1219
- Improving unit tests coverage by @abhishek44sharma in #1218
- Add project status notice by @v0lkan in #1220
- Add project status notice by @v0lkan in #1221
- Bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 by @dependabot in #1225
- Bump filippo.io/age from 1.1.1 to 1.2.1 by @dependabot in #1224
- Bump golang.org/x/crypto from 0.28.0 to 0.31.0 in /examples/workshop_web_encryption/secret-server by @dependabot in #1223
- Bump golang.org/x/net from 0.30.0 to 0.33.0 in /examples/workshop_web_encryption/secret-server by @dependabot in #1222
- Bump golang.org/x/crypto from 0.26.0 to 0.31.0 in /examples/workshop_vsecm_eso/app by @dependabot in #1226
- Bump golang.org/x/crypto from 0.26.0 to 0.31.0 in /examples/workshop_spiffe_federation/apps/edge-store by @dependabot in #1227
- Bump golang.org/x/crypto from 0.26.0 to 0.31.0 by @dependabot in #1228
- Bump golang.org/x/crypto from 0.24.0 to 0.31.0 in /examples/workshop_spiffe_federation/apps/control-plane-server by @dependabot in #1229
- Bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 in /examples/workshop_vsecm_eso/hack by @dependabot in #1231
- Bump golang.org/x/net from 0.28.0 to 0.33.0 by @dependabot in #1230
- Bump golang.org/x/net from 0.28.0 to 0.33.0 in /examples/workshop_spiffe_federation/apps/edge-store by @dependabot in #1232
- Bump golang.org/x/net from 0.28.0 to 0.33.0 in /examples/workshop_vsecm_eso/app by @dependabot in #1233
- Bump golang.org/x/net from 0.26.0 to 0.33.0 in /examples/workshop_spiffe_federation/apps/control-plane-server by @dependabot in #1234
- Bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 in /examples/workshop_vsecm_eso/app by @dependabot in #1235
- v0.28.1 by @v0lkan in #1236
- build fix by @v0lkan in #1237
New Contributors
- @emincanoguz11 made their first contribution in #1209
Full Changelog: v0.28.0...v0.28.1