What Infisical/infisical shipped
Written by FoxPlug from public releases; not affiliated with Infisical. An automatic summary of the public release, pull request and commit data of github.com/Infisical/infisical. Infisical did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Gateway resource now supports Terraform with new DELETE endpoint and rename through PATCH, plus GATEWAY_UPDATE and GATEWAY_DELETE audit events. Pull request #8257
- Move destination picker redesigned with v3 Combobox, fixed positioning, and inline creation to compare locations without leaving the workflow. Pull request #7554
- Machine identity alerts now support multiple event types per identity with a dedicated alerts list for enabling, disabling, editing, and adding alerts. Pull request #8270
- CLI upgraded to version 0.43.136 with new scanning engine that reduces false positives from 364 findings to 221 by filtering low-confidence detections. Pull request #8293
- External CA certificates now store real subject, SANs, algorithms and extensions decoded from the authority response instead of the request. Pull request #8249
- Digital Ocean secret sync fixed to avoid syncing during deployment, handle secret names with hyphens, and prevent deletion of unmanaged secrets. Pull request #8333
- Azure Key Vault secret names now preserve hyphens on import and validate for conflicts before sync to prevent data loss. Pull request #8268
- SPIFFE authentication now accepts the native SPIFFE bundle format from spire-server with x509-svid and jwt-svid keys. Pull request #8287
- CLI login for new signups now completes by preserving the
callback_portparameter through signup pages to return tokens to the CLI. Pull request #8322 - Agent Vault access bundle grant picker now shows only ungranted members to clarify who already holds the bundle. Pull request #8292
Why it matters
This week brings infrastructure improvements for Terraform users, refined secret management workflows, and fixes for external integrations. The scanning engine upgrade reduces false positives, certificate handling becomes more accurate, and cloud sync operations are more reliable and safer.
Changelog entry
- Gateway: Add Terraform support with DELETE endpoint, PATCH rename, and audit events Pull request #8257
- UI: Redesign move destination picker with v3 Combobox and inline creation Pull request #7554
- Machine identity: Support multiple alerts per identity with dedicated list management Pull request #8270
- CLI: Upgrade to 0.43.136 with new scanning engine reducing false positives Pull request #8293
- PKI: External CA now stores decoded certificate attributes instead of request data Pull request #8249
- Secret sync: Fix Digital Ocean to handle hyphens, prevent sync during deployment, protect unmanaged secrets Pull request #8333
- Secret sync: Azure Key Vault preserves hyphens and validates for conflicts before import Pull request #8268
- SPIFFE auth: Accept native SPIFFE bundle format from spire-server Pull request #8287
- CLI: Fix login for new signups by preserving
callback_portthrough signup pages Pull request #8322 - Agent Vault: Show only ungranted members in access bundle grant picker Pull request #8292
- UI: Fix secret list refresh after mutations to use correct query keys Pull request #8336
- UI: Rebalance secrets Name column for better layout on narrow widths Pull request #8316
- Alerts: Fix missing alert notifications for external CA issuance Pull request #8304
- UI: Align embedded audit log cards with v3 design Pull request #8305
- UI: Migrate project KMIP clients page to v3 components Pull request #8306
- UI: Improve keyboard navigation in Create Secret sheet Pull request #8222
- UI: Centralize wide sheet sizes with form, wide, and workspace options Pull request #8312
- UI: Keep secrets toolbar controls together at narrow widths Pull request #8291
- Security: Redact headers and JWTs in identity auth logs Pull request #8295
- Infrastructure: Spread per-pod refresh timers to reduce load spikes Pull request #8291
This week: Terraform gateway support, redesigned move picker, multi-alert machine identities, upgraded scanning with fewer false positives, external CA certificates store real attributes, Digital Ocean and Azure syncs are safer and more correct.
Infisical shipped major improvements this week: Terraform can now manage gateways with DELETE and rename support. The move destination picker was redesigned for better UX. Machine identity alerts now support multiple event types. The secret scanning engine upgraded to reduce false positives from 364 to 221. External CA certificates now store real subject data. Digital Ocean and Azure Key Vault syncs are safer with better hyphen handling and conflict detection. CLI login for signups completes properly. SPIFFE bundles use native format. Seven documentation updates keep guides current.
Week of September 14, 2026
What shipped
- Light mode support added, letting users choose System, Dark, or Light from the profile menu. Pull request #7708
- Event-triggered alerts now fire immediately on events instead of waiting for daily cron scans. Pull request #8072
- Agent Vault services can now filter by HTTP methods and path prefixes, add custom headers, and substitute placeholders. Pull request #8130
- Recursive secret syncs now push secrets from a folder and all folders beneath it to their destinations. Pull request #8087
- Certificate syncs in applications now pick certificates by filter, picking up new ones automatically as they are issued. Pull request #8107
- PowerDNS added as a DNS-01 provider for ACME certificate authorities, with Gateway routing and TLS proxy support. Pull request #8139
- Billing V2 now breaks down metered usage by organization and project, helping admins see where usage lives across their account. Pull request #8099
- Secrets bulk selection bar now includes copy to clipboard and copy to new source options via dropdown. Pull request #8189
- Validation rules can now prevent reusing values already present in the project. Pull request #8094
- Frontend build tooling upgraded from Vite 6.4.2 to Vite 8.2.2 with Rolldown. Pull request #8161
Why it matters
Light mode brings the application to users who prefer bright interfaces. Better event handling for alerts and certificate management makes the platform more responsive. Recursive syncs and filter-based certificate selection reduce manual configuration work for teams managing many secrets and certificates.
Changelog entry
- Light mode support added with System, Dark, and Light options in profile menu Pull request #7708
- Event-triggered alerts fire immediately on events instead of scheduled cron scans Pull request #8072
- Agent Vault services now support HTTP method and path filtering, custom headers, and placeholder substitution Pull request #8130
- Recursive secret syncs push secrets from a folder and all nested folders to destinations Pull request #8087
- Certificate syncs now pick certificates by filter, automatically picking up new issues Pull request #8107
- PowerDNS added as DNS-01 provider for ACME certificate authorities with Gateway routing support Pull request #8139
- Billing V2 usage breakdown now shows metered usage per organization and project Pull request #8099
- Secrets bulk selection bar adds dropdown with copy to clipboard and copy to new source options Pull request #8189
- Validation rules can prevent reusing values already present in the project Pull request #8094
- Frontend build tooling upgraded from Vite 6.4.2 to Vite 8.2.2 with Rolldown Pull request #8161
- Detail cards on access-control pages no longer collapse with adjacent wide tables Pull request #8216
- Agent Vault contrast improved in light mode with darker green color override Pull request #8220
- Certificate Manager pages migrated to v3 page headers with v3 tabs for page sections Pull request #8159
- User notifications render progressively with 20 initial notifications and more on demand Pull request #8205
- Server Console admin surfaces completed v3 treatment with updated table adapters and icons Pull request #8158
- Released images now scanned with Trivy for fixable CRITICAL and HIGH findings Pull request #8162
- Gateway v1 completely deprecated except for actual data Pull request #8127
- LDAP auth machine identity updates now require bind password when changing LDAP URL Pull request #8160
- Privilege boundary enforcement added when changing identity authentication methods on legacy systems Pull request #8061
v0.165.13 ships light mode, event-triggered alerts, recursive secret syncs, and filter-based certificate picks. PowerDNS support and better billing insights round out the week.
This week Infisical v0.165.13 brings light mode support so users can choose their preferred interface theme. Event-triggered alerts now fire immediately instead of waiting for daily scans. Recursive secret syncs push secrets from entire folder hierarchies, and certificate syncs pick certificates by filter to automatically handle new issues. PowerDNS joins as a DNS-01 provider, and billing V2 now shows usage broken down by organization and project.