Fleet - v0.3.9

Security

Fleet Release v0.3.9

Security Enhancements

  • Fleet was logging credentials to remote repositories (i.e., Git and Helm) on errors. The errors were then visible in the Rancher Dashboard UI, exposing the credentials. The fix was made upstream in the go-getter library to redact the sensitive information from the URL, and the go-getter module that Fleet uses was updated to this latest version (1.5.11) that has the fix. See #705.

Bug Fixes

  • Creating a GitRepo with clusters selected by labels and modifying the labels on the cluster so they no longer match now remove the bundle from the cluster. See #36241.

  • Support has been added for multiple JSON patches on a single resource; consequently, all patch operations in the operations list for a resource set will now be applied. See #36247.


Security

Security wording was detected, but no CVEs were found.

Details

date
March 28, 2022, 8:40 p.m.
name
v0.3.9
type
Patch
👇
Register or login to:
  • 🔍View and search all Fleet releases.
  • 🛠️Create and share lists to track your tools.
  • 🚨Setup notifications for major, security, feature or patch updates.
  • 🚀Much more coming soon!
Continue with GitHub
Continue with Google
or