RepoJournal
HashiCorp

@hashicorp

Terraform, Vault, Consul - infra-as-code for ops teams

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

One email a day. Unsubscribe in one click.

Pick a date

Topics: Go Infrastructure Full archive →

The Wire · Showcase

CONSUL AND DATAPLANE 2.0 SHIP WITH CRITICAL CRYPTO PATCHES

By RepoJournal · Filed · About HashiCorp

HashiCorp shipped major versions across Consul, Consul-K8s, and Consul Dataplane overnight, all patching the same cryptographic vulnerabilities that hit the Go ecosystem this spring.

Consul v2.0.0 [2] and Consul Dataplane v2.0.0 [1] both land with mandatory upgrades to golang.org/x/crypto and golang.org/x/net, closing the CVEs that forced every Go shop to scramble weeks ago. Consul-K8s follows suit [3] with the same dependency chain remediation across all modules, replacing go-jose/v3 with v4 to fix GHSA-c5q2-7r4c-mv6g. The dataplane release also bumps the UBI base image to 9.8 [1] and suppresses spurious OSV scanner false positives in RHEL RPM paths [4], which matters if you're running supply chain scanning in production. On the breaking changes front: Consul 2.0 increases default HTTP timeouts from 30 seconds to 15 minutes [2], a significant shift for long-polling blocking queries that could affect your connection pooling assumptions. Envoy gets pinned to 1.37.2 and Go to 1.26 [2], so you're looking at a coordinated upgrade across your entire service mesh.

One email a day. Unsubscribe in one click.

Action items

References

  1. [1] v2.0.0 ↗ hashicorp/consul-dataplane
  2. [2] v2.0.0 ↗ hashicorp/consul
  3. [3] deps: upgrade dependencies to address CVEs in golang.org/x/crypto and golang.org/x/net ↗ hashicorp/consul-k8s
  4. [4] chore: suppress OSV scanner false positives for UBI base RPM paths ↗ hashicorp/consul-dataplane

Quick answers

What shipped in HashiCorp on May 24, 2026?
HashiCorp shipped major versions across Consul, Consul-K8s, and Consul Dataplane overnight, all patching the same cryptographic vulnerabilities that hit the Go ecosystem this spring. In total, 2 commits, 2 pull requests, and 2 releases landed.
Who contributed to HashiCorp on May 24, 2026?
1 developer shipped this update, including santoshpulluri.
What were the notable HashiCorp updates?
v2.0.0, v2.0.0, and deps: upgrade dependencies to address CVEs in golang.org/x/crypto and golang.org/x/net.

More from @hashicorp

Daily updates, in your inbox

Follow HashiCorp

Keep up with HashiCorp in about 3 minutes a day: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

One email a day. Unsubscribe in one click. Read a past issue →

Elsewhere on the wire

Want every project, not just this one?