RepoJournal
HashiCorp

@hashicorp

Terraform, Vault, Consul - infra-as-code for ops teams

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

One email a day. Unsubscribe in one click.

Pick a date

Topics: Go Infrastructure Full archive →

The Wire · Showcase

BOUNDARY PATCHES CRITICAL DATABASE DEPENDENCY ACROSS ALL VERSIONS

By RepoJournal · Filed · About HashiCorp

Boundary shipped emergency security updates across v0.19, v0.20, and v0.21 to address four critical PostgreSQL driver vulnerabilities that could affect every deployment.

All three active Boundary versions [1][2][3] patched the same set of jackc/pgx vulnerabilities (GHSA-j88v-2chj-qfwx, GO-2026-4771, GO-2026-4772, GHSA-9jj7-4m8r-rfcm) plus NTLMSSP authentication flaws that expose connections to manipulation. The v0.21.3 release [1] also introduced support for IBM Passport Advantage Online licensing to expand Boundary Enterprise eligibility, alongside a new debug flag for pprof endpoints. Terraform providers across AWS are undergoing systematic hardening: five services (Kendra, IVS Chat, IoT, FIS, Firehose) [4][5][6][7][8] replaced deprecated Node.js Lambda runtimes to satisfy lint checks and prepare for runtime EOL. The Azure provider shipped v4.71.0 [9] with new CDN Frontdoor security policy data source and updated storage API to 2025-08-01, while the team continues building list resource support for subnet operations. Nomad's scheduler got a critical fix [10] for a NUMA-aware device allocation bug that caused false node exhaustion during task preemption—stale allocator state was persisting across eviction, triggering phantom resource limits that blocked valid workload placement.

One email a day. Unsubscribe in one click.

Action items

References

  1. [1] Boundary v0.21.3 — PostgreSQL driver security patches
  2. [2] Boundary v0.19.5 — PostgreSQL driver security patches
  3. [3] Boundary v0.20.3 — PostgreSQL driver security patches
  4. [4] Terraform AWS Kendra — deprecated Node.js runtime replacement
  5. [5] Terraform AWS IVS Chat — deprecated Node.js runtime replacement
  6. [6] Terraform AWS IoT — deprecated Node.js runtime replacement
  7. [7] Terraform AWS FIS — deprecated Node.js runtime replacement
  8. [8] Terraform AWS Firehose — deprecated Node.js runtime replacement
  9. [9] Terraform Azure v4.71.0 — CDN Frontdoor and storage API updates
  10. [10] Nomad scheduler — stale device allocator bug fix

Quick answers

What shipped in HashiCorp on May 1, 2026?
Boundary shipped emergency security updates across v0.19, v0.20, and v0.21 to address four critical PostgreSQL driver vulnerabilities that could affect every deployment. In total, 87 commits, 23 pull requests, and 4 releases landed.

More from @hashicorp

Daily updates, in your inbox

Follow HashiCorp

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

One email a day. Unsubscribe in one click. Read a past issue →

Elsewhere on the wire

Want every project, not just this one?