The Packer plugin SDK includes the latest version of the go-getter library, which has been updated to address the vulnerabilities listed in HCSEC-2022-13.
The updated SDK contains changes that can be breaking for some plugins as the updated go-getter settings in the SDK prevent reading/writing through symlinks and to sub-directories that require upward path traversal (e.g /tmp/.../etc/hosts). The updates also includes a 30 minute maximum timeout for file downloading, which can be an issue for very large or slow downloads if they exceed more than 30 minutes to complete.
hcp_packer_image data source for setting a
builder's source image.
GH-11832External plugins have been pinned to the following versions. Please see their respective changelogs for details on plugin specific bug fixes and improvements.
pause_after configuration argument to Powershell provisioner.
GH-11792env configuration argument in remote shell
provisioners. GH-11819Fetched April 8, 2026