Spiffe

Latest version: v0.1.5

Safety actively analyzes 714668 Python packages for vulnerabilities to keep your Python projects secure.

Scan your dependencies

Page 7 of 18

1.6.2

Security

- Updated to Go 1.20.3 to address CVE-2023-24534

1.6.1

Fixed

- Different CA TTL than configured (3934)

1.6.0

Added

- Support for customization of SVID and CA attributes through CredentialComposer plugins (3819, 3832, 3862, 3869)
- Experimental support to validate container images signatures through sigstore selectors (3159)
- Published scratch images now support ARM64 architecture (3607)
- Published scratch images are now signed using Sigstore (3707)
- `spire-server mint` and `spire-server token generate` CLI commands now support the `-output` flag (3800)
- `spire-agent api` CLI command now supports the `-output` flag (3818)
- Release images now include a non-root user and default folders (3811)
- Agent accepts bootstrap bundles in SPIFFE format (3753)
- Database index for registration entry hint column (3828)

Changed

- Plugins are configured and executed in the order they are defined (3797)
- Documentation improvements (3826, 3842, 3870)

Fixed

- Server crash when authorization layer was unable to talk to the datastore (3829)
- Timestamps in logs are now consistently in local time (3734)

Removed

- Non-scratch images are no longer published (3785)
- `k8s-workload-registar` is no longer released and maintained (3853)
- Unused database column `x509_svid_ttl` from `registered_entries` table (3808)
- The deprecated `enabled` flag from InMem telemetry config (3796)
- The deprecated `default_svid_ttl` configurable (3795)
- The deprecated `omit_x509svid_uid` configurable (3794)

1.5.6

Added

- A log message in the k8s-workload-registrar webhook when validation fails (4011)

Security

- Updated to Go 1.19.8 to address CVE-2023-24534

1.5.5

Security

- Updated to Go 1.19.6 and golang.org/x/net v0.7.0 to address CVE-2022-41723, CVE-2022-41724, CVE-2022-41725.

1.5.4

Added

- Support to run SPIRE as a Windows service (3625)
- Configure admin SPIFFE IDs from federated trust domains (3642)
- New selectors in the `aws_iid` NodeAttestor plugin (3640)
- Support for additional upstream root certificates to the `awssecret` UpstreamAuthority plugin (3578)
- Serial number and revision number to SVID minting logging (3699)
- `spire-server federation` CLI commands now support the `-output` flag (3660)

Fixed

- Service configurations provided by the gRPC resolver are now ignored by SPIRE Agent (3712)
- CLI commands that supported the `-output` flag now properly shows the default value for the flag (3713)

Page 7 of 18

© 2025 Safety CLI Cybersecurity Inc. All Rights Reserved.