- Added custom CRL distribution points for PKI CAs and made TLS verification configurable for identity Kubernetes auth, plus a limit on ACME requests for external CAs.
- Introduced secret syncing to Vercel teams with custom environments, added missing ECDSA P521 support in the UI, and included request IDs in approval emails.
- Improved navigation to role details, updated textarea styling to prevent modal overflow, defaulted PAM access duration to policy max, and added documentation for AI agents and MCP setup.