- Added new commands and options such as Sub‑CA creation via `tctl auth create`, interactive role prompting, Oracle Cloud region support, and expanded scope features for OpenSSH and session recording.
- Fixed numerous bugs across desktop connections, empty‑file uploads, scp filename handling, server discovery checks, role impersonation, UI visibility, and other components.
- Patched critical security issues including an SSRF flaw in AWS app access, capped AWS STS AssumeRole duration, sanitized AWS console logs, and upgraded the crypto library to v0.53.0.