- Fixed a critical bug where the application controller could fail to refresh applications, causing out‑of‑sync status.
- Added security hardening: X‑Frame‑Options and CSP headers for Swagger UI, OIDC config refresh on server restart, and signed container images with provenance.
- Included numerous bug fixes and performance tweaks (optimized UID map handling, reduced secret deepcopy, UI 401 handling, OCI metadata rendering, HTTP/2 enforcement, Helm insecure flag) and corrected a documentation path.
