- Fix CVE-2021-32923 where zero‑TTL token and secret leases became non‑expiring, affecting Vault 0.10.0‑1.7.1.
- Update GCP auto‑auth agent and auth method to use the IAM Service Account Credentials API for JWT signing.
- Various bug fixes: namespace password policies, lease renewal logic, numeric arguments in DB plugins, SetCredentials fallback, and UI namespace login bug.