v9.1.2
Breaking Changes
This is a security release to ensure existing Shield deployments are not impacted by CVEs found in earlier libraries and OSs. In providing this release, some functionality was unfortunately lost due to changes upstream that contained the security fixes.
-
This boshrelease requires the ubuntu-jammy stemcell, because shield was compiled against it to resolve OS CVEs and bugs.
-
This release contains shield v8.8.6. This version contains many library updated in order to resolve outstanding vulnerabilities, but as a side effect, the libraries needed for the Azure plugin introduced an incompatibility upstream. This will be resolved in a future release, but for now, don't upgrade if you are using the Azure plugin
-
Due to updates to vault for security reasons, this version of shield no longer is able to initialize a new shield deployment, but can still update an existing shield deployment. This will be resolved in a future release, but in the mean time, deploy with the v9.1.0 deployment.
Software Updates
- Updated shield from 8.8.5 to 8.8.6
- Updated nginx from 1.22.0 to 1.25.1
- Updated pcre from pcre-8.45 to pcre2-10.42
- Updated vault from 1.11.4 to 1.14.0
- Updated sqlite from 3390400 to 3420000
Deployment
releases:
- name: shield
version: 9.1.2
url: https://github.com/shieldproject/shield-boshrelease/releases/download/v9.1.2/shield-9.1.2.tgz
sha1: b9df5d9137f13947681a217a99637651545c4dea
Full Changelog: v9.1.0...v9.1.2