- Security hardening: restrict SFTP for normal users, fix SSRF via reverse tunnel, filter macOS DYLD variables, prevent Access List privilege escalation, and upgrade crypto library to address CVE‑2023‑48795.
- Feature additions: promote access requests to access lists, add STS session tags for DynamoDB, support IAM join method, custom SAML attribute mapping, tsh latency command, GitHub Enterprise joining, and vpc‑id label for auto‑discovered R...
- Numerous bug fixes and improvements: websocket upgrade reliability, enhanced audit events, kube agent performance boost, lock expiration audit, PIV support on Windows, macOS 10.15 minimum, and various UI/CLI refinements.