{"id":"src_9BKTBbOcSYaDb4mrSpXOW","slug":"boundary-releases","name":"Boundary","type":"github","url":"https://github.com/hashicorp/boundary","orgId":"org_Yj55_xJFX2PSbzXjXof_V","productId":"prod_FDFHqwEnBvjqNm73w50se","productSlug":"boundary","org":{"id":"org_Yj55_xJFX2PSbzXjXof_V","slug":"hashicorp","name":"HashiCorp"},"isPrimary":false,"isHidden":false,"discovery":"curated","metadata":"{\"evaluatedMethod\":\"github\",\"evaluatedAt\":\"2026-04-07T23:43:11.311Z\",\"wellKnownSweptAt\":\"2026-10-01T06:01:26.362Z\",\"sourceActor\":{\"nextAlarmAt\":null,\"lastAlarmAt\":\"2026-10-08T16:43:18.030Z\",\"managed\":false}}","notice":null,"kind":"platform","stars":null,"starsFetchedAt":null,"releaseCount":78,"releasesLast30Days":0,"avgReleasesPerWeek":0,"latestVersion":"v0.21.3","latestDate":"2026-04-30T15:23:16.000Z","changelogUrl":null,"hasChangelogFile":true,"lastFetchedAt":"2026-05-08T16:50:00.558Z","lastPolledAt":"2026-04-08T00:00:35.795Z","changeDetectedAt":null,"trackingSince":"2020-10-14T15:15:23.000Z","releases":[{"id":"rel_H21Hzxc9nOKKCZsu7AOs8","version":"v0.21.3","type":"feature","title":"v0.21.3","summary":"Updated jackc/pgx/v5 to v5.9.2 to address GHSA-j88v-2chj-qfwx, GO-2026-4771, GO-2026-4772, and GHSA-9jj7-4m8r-rfcm, and Azure/go-ntlmssp to v0.1.1 to address GHSA-pjcq-xvwq-hhpj. Added support for IBM Passport Advantage Online licensing and a debug flag to expose pprof endpoints.","titleGenerated":"Boundary v0.21.3 updates dependencies to address security vulnerabilities","titleShort":"Security dependencies updated; PAO licensing support added","breaking":"unknown","importance":null,"content":"## 0.21.3 (2026/04/28)\n\n### New and Improved\n\n* Added support for IBM Passport Advantage Online licensing. You can now use PAO to enable Boundary Enterprise.\n* Added support for new `debug` flag to expose pprof endpoints for debugging purposes. ([PR](https://github.com/hashicorp/boundary/pull/6644))\n* Updated internal dependencies.\n\n### Security\n\n* Updated jackc/pgx/v5 dependency to v5.9.2 to address GHSA-j88v-2chj-qfwx, GO-2026-4771, GO-2026-4772, and GHSA-9jj7-4m8r-rfcm ([PR](https://github.com/hashicorp/boundary/pull/6607), [PR](https://github.com/hashicorp/boundary/pull/6617))\n* Updated Azure/go-ntlmssp dependency to v0.1.1 to address GHSA-pjcq-xvwq-hhpj ([PR](https://github.com/hashicorp/boundary/pull/6625))\n\n","publishedAt":"2026-04-30T15:23:16.000Z","fetchedAt":"2026-05-08T16:49:59.400Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.21.3","media":[],"coverageCount":0},{"id":"rel_O7s-7nfO86FRvVse2TTmH","version":"v0.19.5","type":"feature","title":"v0.19.5","summary":"Updated jackc/pgx/v5 to v5.9.2 to address multiple vulnerabilities (GHSA-j88v-2chj-qfwx, GO-2026-4771, GO-2026-4772, GHSA-9jj7-4m8r-rfcm) and Azure/go-ntlmssp to v0.1.1 to address GHSA-pjcq-xvwq-hhpj. Added a debug flag to expose pprof endpoints for debugging purposes.","titleGenerated":"Boundary v0.19.5 updates dependencies to fix security vulnerabilities","titleShort":"Security: pgx and NTLM dependencies patched","breaking":"unknown","importance":null,"content":"## 0.19.5 (2026/04/24)\n\n### New and Improved\n* Added support for new `debug` flag to expose pprof endpoints for debugging purposes. ([PR](https://github.com/hashicorp/boundary/pull/6644))\n\n### Security\n\n* Updated jackc/pgx/v5 dependency to v5.9.2 to address GHSA-j88v-2chj-qfwx, GO-2026-4771, GO-2026-4772, and GHSA-9jj7-4m8r-rfcm ([PR](https://github.com/hashicorp/boundary/pull/6607), [PR](https://github.com/hashicorp/boundary/pull/6617))\n* Updated Azure/go-ntlmssp dependency to v0.1.1 to address GHSA-pjcq-xvwq-hhpj ([PR](https://github.com/hashicorp/boundary/pull/6625))\n\n","publishedAt":"2026-04-30T15:21:42.000Z","fetchedAt":"2026-05-08T16:49:59.400Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.19.5","media":[],"coverageCount":0},{"id":"rel_8wOIweqVaF14AB8SVQh9J","version":"v0.20.3","type":"feature","title":"v0.20.3","summary":"Updated jackc/pgx/v5 to v5.9.2 and Azure/go-ntlmssp to v0.1.1 to address multiple security vulnerabilities. Added a debug flag to expose pprof endpoints for debugging purposes.","titleGenerated":"Boundary v0.20.3 updates dependencies to address security vulnerabilities","titleShort":"Security: pgx and NTLMSSP vulnerabilities patched","breaking":"unknown","importance":null,"content":"## 0.20.3 (2026/04/24)\n\n### New and Improved \n* Added support for new `debug` flag to expose pprof endpoints for debugging purposes. ([PR](https://github.com/hashicorp/boundary/pull/6644))\n\n### Security\n\n* Updated jackc/pgx/v5 dependency to v5.9.2 to address GHSA-j88v-2chj-qfwx, GO-2026-4771, GO-2026-4772, and GHSA-9jj7-4m8r-rfcm ([PR](https://github.com/hashicorp/boundary/pull/6607), [PR](https://github.com/hashicorp/boundary/pull/6617))\n* Updated Azure/go-ntlmssp dependency to v0.1.1 to address GHSA-pjcq-xvwq-hhpj ([PR](https://github.com/hashicorp/boundary/pull/6625))\n\n","publishedAt":"2026-04-30T15:09:29.000Z","fetchedAt":"2026-05-08T16:49:59.400Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.20.3","media":[],"coverageCount":0},{"id":"rel_DgxwG6omxUM1jrDkyr6B7","version":"v0.21.2","type":"feature","title":"v0.21.2","summary":"## 0.21.2 (2026/04/06)\n\n### New and Improved\n\n* cli: Added optional flags `-sort-by` and `-sort-direction` to `boundary search`. These flags can be us...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.21.2 (2026/04/06)\n\n### New and Improved\n\n* cli: Added optional flags `-sort-by` and `-sort-direction` to `boundary search`. These flags can be used to control sorting when searching the client cache and the resource is `sessions` or `targets`. ([PR](https://github.com/hashicorp/boundary/pull/6383))\n* The client cache search API now supports the `sort_by` and `sort_direction` query parameters when searching `sessions` or `targets`. ([PR](https://github.com/hashicorp/boundary/pull/6383))\n\n","publishedAt":"2026-04-07T15:32:19.000Z","fetchedAt":"2026-04-08T00:01:11.910Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.21.2","media":[],"coverageCount":0},{"id":"rel_r5zxNjt6s9V0GWKl8_RjO","version":"v0.21.1","type":"feature","title":"v0.21.1","summary":"## 0.21.1 (2026/02/10)\n\n### Security\n\n* Go version bumped to 1.25.7 to address CVE-2025-61730 ([PR](https://github.com/hashicorp/boundary/pull/6409))\n...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.21.1 (2026/02/10)\n\n### Security\n\n* Go version bumped to 1.25.7 to address CVE-2025-61730 ([PR](https://github.com/hashicorp/boundary/pull/6409))\n* Go Cryptography dependency update to address CVE-2025-58181 and CVE-2025-47914\n  ([PR](https://github.com/hashicorp/boundary/pull/6272))\n\n","publishedAt":"2026-02-13T13:52:10.000Z","fetchedAt":"2026-04-08T00:01:11.910Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.21.1","media":[],"coverageCount":0},{"id":"rel_v3N55v3uIRcJ9YY_6G4al","version":"v0.21.0","type":"feature","title":"v0.21.0","summary":"## 0.21.0 (2025/11/12)\n\n### New and Improved\n\n* ui: Optimized loading of table filters and improved table search support ([PR](https://github.com/hash...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.21.0 (2025/11/12)\n\n### New and Improved\n\n* ui: Optimized loading of table filters and improved table search support ([PR](https://github.com/hashicorp/boundary-ui/pull/3053))\n\n### Bug fixes\n\n* ui: Show username for OIDC auth method in user menu ([PR](https://github.com/hashicorp/boundary-ui/pull/2930))\n\n","publishedAt":"2025-12-11T17:18:44.000Z","fetchedAt":"2026-04-08T00:01:11.910Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.21.0","media":[],"coverageCount":0},{"id":"rel_WVqrvZlE2PFTiwE4Qw2ua","version":"v0.20.1","type":"feature","title":"v0.20.1","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2025-11-03T18:46:15.000Z","fetchedAt":"2026-04-08T00:01:11.910Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.20.1","media":[],"coverageCount":0},{"id":"rel_i4HsQhksM2Kf5zTbg_UlH","version":"v0.20.0","type":"feature","title":"v0.20.0","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2025-09-25T15:26:25.000Z","fetchedAt":"2026-04-08T00:01:11.910Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.20.0","media":[],"coverageCount":0},{"id":"rel_ELdxMgsCvdaufz9gXv7Fw","version":"v0.19.3","type":"feature","title":"v0.19.3","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2025-07-10T13:03:54.000Z","fetchedAt":"2026-04-08T00:01:12.177Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.19.3","media":[],"coverageCount":0},{"id":"rel_caOxLJh0yNLxFxpCxNgfR","version":"v0.19.2","type":"feature","title":"v0.19.2","summary":"## 0.19.2 (2025/04/28)\n\n### New and Improved\n\n* ui: Populate subject for OIDC account name displays.\n  ([PR](https://github.com/hashicorp/boundary-ui/...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.19.2 (2025/04/28)\n\n### New and Improved\n\n* ui: Populate subject for OIDC account name displays.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2757)).\n* ui: Improved performance when initially fetching large sets of resources.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2752)).\n* ui: Improved search & filtering behavior when using search field.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2735)).\n\n### Bug fixes\n\n* Fixed an issue in the worker where closing an SSH channel failed to exit a\n  loop, which would cause a massive spike in CPU usage over time. This change\n  only affects Enterprise.\n* ui: Fix an issue where the user could not change the key_type of a\n  Vault SSH Certificate credential library.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2790)).\n\n","publishedAt":"2025-05-08T17:05:22.000Z","fetchedAt":"2026-04-08T00:01:12.177Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.19.2","media":[],"coverageCount":0},{"id":"rel_tp3qVAlVjPOj7JMgJkduf","version":"v0.19.1","type":"feature","title":"v0.19.1","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2025-03-04T18:32:32.000Z","fetchedAt":"2026-04-08T00:01:12.177Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.19.1","media":[],"coverageCount":0},{"id":"rel_nDtX_oStSYeFOoH9Ybhbl","version":"v0.19.0","type":"feature","title":"v0.19.0","summary":"## 0.19.0 (2025/01/31)\n### New and Improved\n\n* Introduces soft-delete for users within the client cache.\n  ([PR](https://github.com/hashicorp/boundary...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.19.0 (2025/01/31)\n### New and Improved\n\n* Introduces soft-delete for users within the client cache.\n  ([PR](https://github.com/hashicorp/boundary/pull/5173)).\n* GCP dynamic host catalog: Add dynamic host catalog support for \n  discovering GCP Compute Engine VM Instances.\n  ([PR](https://github.com/hashicorp/boundary/pull/5229)).\n* The worker domain has been refactored to create clear domain functions for worker operations, improve readability and \nmaintainability of worker queries, and improve DB performance. ([PR](https://github.com/hashicorp/boundary/pull/5338)).\n* Adds support for dual-stack networking for AWS operations.\n  ([PR](https://github.com/hashicorp/boundary-plugin-aws/pull/52)) \n  * **Note**: As a consequence of updating AWS SDK dependencies to enable\n    dual-stack support, this Boundary release may consume more memory. From our\n    testing, the increase seems to be around 1.6x, however this\n    may vary depending on your deployment architecture.\n* The worker <-> controller communications have been refactored to improve performance\n  and reliability at large scale. Workers older than v0.19.0 will remain supported\n  until the release of v0.20.0, in accordance with\n  [our worker/controller compatiblity policy](https://developer.hashicorp.com/boundary/docs/enterprise/supported-versions#control-plane-and-worker-compatibility).\n* Add concurrency limit on the password hashing of all password auth methods.\n  ([PR](https://github.com/hashicorp/boundary-plugin-aws/pull/5437)).\n\n  This avoids bursty memory and CPU use during concurrent password auth method\n  authentication attempts. The number of concurrent hashing operations\n  can be set with the new `concurrent_password_hash_workers` configuration\n  value in the controller stanza, or the new\n  `BOUNDARY_CONTROLLER_CONCURRENT_PASSWORD_HASH_WORKERS` environment variable.\n  The default limit is 1.\n* ui: Improve worker filter workflow for targets, vault credential-stores, and storage-buckets. ([PR](https://github.com/hashicorp/boundary-ui/pull/2614)).\n\n### Bug fixes\n\n* Fix bug in applying BOUNDARY_MAX_RETRIES for boundary cli. Previously\n  setting this environment variable would result in a max retries of 2,\n  regardless of the value set.\n  ([PR](https://github.com/hashicorp/boundary/pull/5385)).\n* Fix bug in parsing IPv6 addresses. Previously setting a target address or the\n  initial upstream address in the config file would result in a malformed value.\n  ([PR](https://github.com/hashicorp/boundary/pull/5221)).\n* Fix an issue where, when starting a session, the connection limit always displays 0.\n  ([PR](https://github.com/hashicorp/boundary/pull/5396)).\n* Fix bug which caused the `children` keyword not to apply the appropriate\n  permissions for a number of resources.\n    ([PR](https://github.com/hashicorp/boundary/pull/5418)).\n\n","publishedAt":"2025-02-10T20:09:25.000Z","fetchedAt":"2026-04-08T00:01:12.177Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.19.0","media":[],"coverageCount":0},{"id":"rel_k_R-hxaqRIkNRA2WseEs-","version":"v0.18.2","type":"feature","title":"v0.18.2","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2024-12-12T19:06:20.000Z","fetchedAt":"2026-04-08T00:01:12.177Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.18.2","media":[],"coverageCount":0},{"id":"rel_rW3RSNvE_mfq5FmXzfg32","version":"v0.18.1","type":"feature","title":"v0.18.1","summary":"## 0.18.1 (2024/11/21)\n### New and Improved\n\n* Delete terminated sessions in batches to avoid long running jobs.\n  ([PR](https://github.com/hashicorp/...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.18.1 (2024/11/21)\n### New and Improved\n\n* Delete terminated sessions in batches to avoid long running jobs.\n  ([PR](https://github.com/hashicorp/boundary/pull/5201))\n\n### Bug fixes\n\n* Fix an issue where users would lose access to managed groups if\n  there are more than 10,000 managed groups in the auth method used.\n  ([PR](https://github.com/hashicorp/boundary/pull/5242))\n* Fix an issue where only the first 10,000 members of a managed group\n  are returned when getting the managed group, and a similar issue where\n  only the first 10,000 managed groups an account is part of is included\n  when getting the account.\n  ([PR](https://github.com/hashicorp/boundary/pull/5245))\n\n","publishedAt":"2024-11-21T23:22:25.000Z","fetchedAt":"2026-04-08T00:01:12.440Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.18.1","media":[],"coverageCount":0},{"id":"rel_a0xbLWbufn71PbedsnoT9","version":"v0.18.0","type":"feature","title":"v0.18.0","summary":"## 0.18.0 (2024/10/01)\n### New and Improved\n\n* Add support for dynamic host catalog plugins running in Boundary workers:\n  Boundary plugins that handl...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.18.0 (2024/10/01)\n### New and Improved\n\n* Add support for dynamic host catalog plugins running in Boundary workers:\n  Boundary plugins that handle dynamic host catalog operations (such as the\n  [AWS](https://github.com/hashicorp/boundary-plugin-aws/tree/main/plugin/service/host)\n  and [Azure](https://github.com/hashicorp/boundary-plugin-azure) plugins) can\n  now run on workers. ([PR](https://github.com/hashicorp/boundary/pull/5137))\n\n* Dynamic host catalogs worker filter support (Enterprise and HCP Boundary\n  only): Operators can now set a worker filter when creating a dynamic host\n  catalog. When set, all of the plugin requests will be sent to the matching\n  worker for processing. ([PR](https://github.com/hashicorp/boundary/pull/5137))\n\n* AWS dynamic host catalogs `AssumeRole` authentication support: Operators can\n  now set-up AWS dynamic host catalogs using Amazon's `AssumeRole`\n  authentication paradigm by providing a valid Role ARN when creating the host\n  catalog. ([PR](https://github.com/hashicorp/boundary/pull/5137) and\n  [PR](https://github.com/hashicorp/boundary-plugin-aws/pull/49))\n\n* Improved MinIO storage plugin compatibility with other services by dropping\n  the checksum headers in `PutObject`.\n  ([PR](https://github.com/hashicorp/boundary-plugin-minio/pull/23))\n\n* ui: Add UI support for searching and pagination of aliases.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2498))\n\n* ui: Add UI support for filtering and pagination of session recordings.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2502))\n\n* ui: Improve multi-scope grants select/deselect process.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2435))\n\n### Bug Fixes\n\n* Prevented a data-race in Boundary's event logging system.\n  ([PR](https://github.com/hashicorp/boundary/pull/5139))\n\n* Update Storage Bucket type icon in Target view.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2503))\n\n* Allow user to retry with authentication is pending with OIDC.\n  ([PR](https://github.com/hashicorp/boundary-ui/pull/2512))\n\n### Deprecations/Changes\n\n* Remove deprecated `controllers` field from the worker config, which was deprecated in 0.9.0 for\n`initial_upstreams`([PR](https://github.com/hashicorp/boundary/pull/5125))\n\n","publishedAt":"2024-10-14T19:35:32.000Z","fetchedAt":"2026-04-08T00:01:12.440Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.18.0","media":[],"coverageCount":0},{"id":"rel_qQo8qO4jaXz3c1Hg9Da6a","version":"v0.17.2","type":"feature","title":"v0.17.2","summary":"## 0.17.2 (2024/09/25)\n\n### Changes\n\n* The Go API properly uses the passed in value for `WithRecursive` and\n  `WithSkipCurlOutput` instead of always s...","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.17.2 (2024/09/25)\n\n### Changes\n\n* The Go API properly uses the passed in value for `WithRecursive` and\n  `WithSkipCurlOutput` instead of always setting to true regardless of the\n  passed-in value. ([PR](https://github.com/hashicorp/boundary/pull/5066))\n\n","publishedAt":"2024-10-14T14:03:27.000Z","fetchedAt":"2026-04-08T00:01:12.440Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.17.2","media":[],"coverageCount":0},{"id":"rel_L17oL4JNS0q1qwR8FSzCt","version":"v0.16.3","type":"feature","title":"v0.16.3","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2024-08-22T23:36:27.000Z","fetchedAt":"2026-04-08T00:01:12.440Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.16.3","media":[],"coverageCount":0},{"id":"rel_U4ewW4QB46HfnXp1rSAxC","version":"v0.17.1","type":"feature","title":"v0.17.1","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2024-08-22T20:50:11.000Z","fetchedAt":"2026-04-08T00:01:12.440Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.17.1","media":[],"coverageCount":0},{"id":"rel_f6DI9s438cryUO4v8BRnZ","version":"v0.17.0","type":"feature","title":"v0.17.0","summary":"## 0.17.0 (2024/07/17)\n\n","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"## 0.17.0 (2024/07/17)\n\n","publishedAt":"2024-07-31T20:12:12.000Z","fetchedAt":"2026-04-08T00:01:12.696Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.17.0","media":[],"coverageCount":0},{"id":"rel_VvEaLUP73qCTr0IbnfObb","version":"v0.15.5","type":"feature","title":"v0.15.5","summary":"","titleGenerated":null,"titleShort":null,"breaking":"unknown","importance":null,"content":"","publishedAt":"2024-07-31T16:37:47.000Z","fetchedAt":"2026-04-08T00:01:12.696Z","url":"https://github.com/hashicorp/boundary/releases/tag/v0.15.5","media":[],"coverageCount":0}],"pagination":{"nextCursor":"2024-07-31T16:37:47.000Z|2026-04-08T00:01:12.696Z|rel_VvEaLUP73qCTr0IbnfObb","limit":20},"summaries":{"rolling":null,"monthly":[]}}