- Fixed multiple bugs causing crashes, invalid refreshes, and unnecessary evaluations during destroy and apply operations.
- Added security hardening: limited tar header size, capped regex complexity, and rejected environment variables with NUL characters to prevent memory abuse.
- Introduced AzureRM backend support for generic OIDC authentication and improved variable type handling before applying defaults.