- Fixed medium‑severity security issue where a SCIM client could overwrite Teleport system roles (Okta integration) and updated go‑retryablehttp to address CVE‑2024‑6104.
- Added new features such as trust of system CAs for self‑hosted databases, a debug setting for event handler, tctl desktop bootstrap for AD environments, and UI enhancements like error display and VNet panel updates.
- Resolved multiple bugs including remote port‑forwarding validation, headless auth for SSO users, gRPC disconnections on cert expiry, Connect My Computer bind errors, and improved log rotation and updater channel handling.