- Security hardening: fixed arbitrary file read vulnerability, added TLS peer certificate cluster name verification, blocked remote identity auth in git forwarder, and updated OpenSSL to 3.0.16.
- New capabilities: support for multiple active CAs, workload identity resource, Azure discovery integration, Microsoft RDS license caching, and options to disable S3 path‑style or use non‑FIPS AWS endpoints.
- Various bug fixes and performance tweaks: corrected Postgres privilege revocation, fixed Web UI MFA prompts, reduced CPU for role mapping, improved Kubernetes token handling, and resolved several UI crashes and regressions.