-
Notifications
You must be signed in to change notification settings - Fork 118
Pending Release Notes
punitmundra edited this page Feb 21, 2025
·
986 revisions
Chef lets you choose your upgrade journey based on your current version of Chef Automate. You can do all the version upgrades manually.
Your Current Version | Upgrade To |
---|---|
Any version before 20220329091442 | 20220329091442 |
20220329091442 | 3.0.x |
3.0.49 | 4.x |
See the Chef Automate 4.x upgrade documentation for more information.
- Infra Server in Automate now allows organisations to be accessed having dex or assets as substring. (#8744)
- Fixes the issue which was stopping Automate to load more than 100 controls for a node in the compliance reports page. (#8673)
- Fixes the issue which was stopping Automate for expanding the control test results for a node in case the number of tests exceeds 50. (#8673)
(examples: new security configurations)
- The X-XSS-Protection and CSP-header values are now configurable. (#8767)
- Removing the plain text password for Automate / Automate HA from the config's.
(examples: dependency updates, CVE fixes)
- Updated
open-policy-agent/opa
to v0.42.0 which solves
CVE-2022-33082
- Updated
lodash
to v4.17.19 which solves
CVE-2020-8203
- Update
crypto
to v0.31.0 which solves
CVE-2024-45337
This release uses:
- Chef Habitat version:1.6.1205/20241107140309
- Chef Habitat Builder version: 9497/20221221224518
- Chef Infra Server version: 15.10.27/20250102025130
- Chef InSpec version: 4.56.61/20240809111842
This release uses:
- Postgres: 13.18
- OpenSearch: 1.3.20
- Nginx: 1.25.4
- Haproxy: 1.25.4
- Dex: 2.35.0
This release supports the following external chef products:
- Chef Infra Server version: 14.0.58+
- Chef Inspec version: 4.3.2+
- Chef Infra Client: 17.0.242+
- Chef Habitat: 0.81+
This release is built on the following framework versions:
- GoLang: 1.22.5
- OpenJDK: 11.0.22+7
- Angular: 17.3.0
View the package manifest for the latest release.