- Fixed CVE‑2021‑32923: corrected lease renewal logic to prevent token and dynamic secret leases with zero‑second TTL from becoming non‑expiring (security fix).
- Updated the agent and GCP auth plugin to use the IAM Service Account Credentials API for JWT signing, improving GCP Auto Auth support (feature/enhancement).