Open
Conversation
a9383a6 to
7ae53fe
Compare
7ae53fe to
dcd0b90
Compare
dcd0b90 to
79e3d74
Compare
79e3d74 to
0bf5198
Compare
0bf5198 to
4f40fd5
Compare
4f40fd5 to
5a1d20e
Compare
5a1d20e to
28569c0
Compare
28569c0 to
1d8b8c3
Compare
1d8b8c3 to
288d0c8
Compare
288d0c8 to
231a51f
Compare
231a51f to
7f40ea8
Compare
7f40ea8 to
6a5f0f5
Compare
6a5f0f5 to
092b296
Compare
092b296 to
94ae5f1
Compare
94ae5f1 to
1a06d2d
Compare
1a06d2d to
6e85025
Compare
6e85025 to
26efac2
Compare
26efac2 to
a36631b
Compare
a36631b to
9c5b83d
Compare
9c5b83d to
b812f95
Compare
e775872 to
69a689e
Compare
69a689e to
6a8ebb1
Compare
6a8ebb1 to
2b28e60
Compare
2b28e60 to
9b942ba
Compare
5e79cf9 to
a642b9a
Compare
a642b9a to
e08ff69
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.17.3→1.21.4Release Notes
hashicorp/vault (vault)
v1.21.4Compare Source
v1.21.3Compare Source
February 05, 2026
SECURITY:
CHANGES:
FEATURES:
IMPROVEMENTS:
BUG FIXES:
?with=<path>query param correctly displays only the specified mount when multiple mounts of the same auth type are configured withlisting_visibility="unauth"v1.21.2Compare Source
v1.21.1Compare Source
November 19, 2025
SECURITY:
CHANGES:
IMPROVEMENTS:
sys/reporting/scanendpoint which will output a set of files containing information about Vault state to the location specified by thereporting_scan_directoryconfig item.vault.route.read-snapshot.{mount_point}andvault.route.list-snapshot.{mount_point}metrics.server_flag,client_flag,code_signing_flag, andemail_protection_flagparameters for creating/updating a role.BUG FIXES:
alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.key_usageextension so details accurately reflect certificate values.basic_constraints_valid_for_non_cais correctly set.v1.21.0Compare Source
October 22, 2025
SECURITY:
CHANGES:
recover_snapshot_idquery parameter to pass the snapshot ID for recover operations, in favor of aX-Vault-Recover-Snapshot-Idheader. Vault will still accept the query parameter for backward compatibility. Also support setting the HTTP method toRECOVERfor recover operations, in addition toPOSTandPUT.timestampin export API response totoken_creation_time.max_json_depth,max_json_string_value_length,max_json_object_entry_count,max_json_array_element_count.FEATURES:
versioned KV secrets. This allows lookup of attribution information for each
version of KV v2 secrets from CLI and API.
enable_self_enrollmentparameter in the API.IMPROVEMENTS:
-downloadoption for plugin register (beta)vault recovercommand with a-fromflag, users can specify the path of the item in the snapshot.enterprise_urlfield to enable support for self-hosted GitHub Enterprise Server instances.sys/internal/counters/activity/cumulative. For each namespace in the response it returns the sum of its own client counts and that of all its child namespaces.alias_metadata.alias_metadata.alias_metadata.x_forwarded_for_client_cert_header, to fix TLS certificate auth errors with Google Cloud Application Load Balancer.alias_metadata.alias_metadata.alias_metadata.alias_metadata.alias_metadata.alias_metadata.-forceflag tovault operator raft snapshot unloadcommand to force deletion of a loaded snapshot.policies, and with it the selection of "seal" to use entropy augmentation.
vault.route.read-snapshot.{mount_point}andvault.route.list-snapshot.{mount_point}metrics.forcequery parameter to theDELETE sys/storage/raft/snapshot-load/{snapshot_id}endpoint to allow for forced deletion of snapshots. This is useful when the snapshot is in a state that prevents normal deletion, such as being in the process of loading.sys/internal/counters/activity/*endpoints.autoload_enabledoption to raft automated snapshot configurations. When enabled, this option will automatically load raft snapshots into Vault, which can then be used for recovery operations.roleURL query string parameterroleURL query string parameternamespace_path,mount_pathandmount_typefilters to attribution tableDEPRECATIONS:
BUG FIXES:
development_clustersetting being overwritten on performance secondaries upon cluster reload.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.alias_metadatanow populates alias custom metadata field instead of alias metadata.+) paths with existing prefix rules inglob_paths, so clients receive a complete view of glob-style permissions. This unblocks UI sidebar navigation checks and namespace access banners.rotation_statementsfield.ed25519keys that were imported with derivation enabledsys/internal/ui/mountsso mount paths match serve value+,*v1.20.4Compare Source
September 24, 2025
SECURITY:
CHANGES:
IMPROVEMENTS:
x_forwarded_for_client_cert_header, to fix TLS certificate auth errors with Google Cloud Application Load Balancer. [GH-31501]BUG FIXES:
Configuration
📅 Schedule: Branch creation - "every weekend" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.