- Fix for CVE‑2021‑32923: prevents non‑expiring token and dynamic secret leases by correcting zero‑TTL handling.
- Agent and GCP auth now use IAM Service Account Credentials API for JWT signing; added LifetimeWatcher retries, AWS validation error details, optional HTTP response headers, and AWS role session name support.
- Multiple bug fixes and enhancements: MongoDB timeout/customization and multi‑threaded throughput, various plugin, UI, and core stability fixes.