- Fixed critical security issues including arbitrary file reads on SSH nodes, added TLS peer certificate cluster‑name verification, and introduced an escape hatch for non‑FIPS AWS endpoints.
- Added several features such as securityContext to the tbot Helm chart, debug UNIX socket control, support for multiple active CAs in export endpoints, audit log statistics, continuous profiling with Pyroscope, and Microsoft RDS license c...
- Updated core dependencies (Go 1.23.6, OpenSSL 3.0.16) and removed Desktop Access support on arm64 FIPS builds, marking its deprecation.