- Fixed critical security issues: arbitrary file reads on SSH nodes and TLS peer certificate cluster name validation to prevent auth bypasses; added securityContext to the tbot Helm chart.
- Updated core dependencies (Go 1.23.6, OpenSSL 3.0.16) and introduced multiple active CAs, workload‑identity enhancements, and customizable base URL for client‑tools managed updates.
- Implemented numerous bug fixes and improvements such as PostgreSQL privilege auto‑provisioning, session renewal stability, Kubernetes exec termination handling, and reduced CPU consumption for role mapping.