RepoJournal
HashiCorp

@hashicorp

Terraform, Vault, Consul — infra-as-code for ops teams

Pick a date

The Wire · Showcase

PACKER PLUGIN VAGRANT MOVES TO 1.1.8, CONSUL PATCHES VULNERABLE DEPENDENCIES

By RepoJournal · Filed · About HashiCorp

Packer plugin Vagrant is stepping into v1.1.8 while Consul hardens its dependency chain against known vulnerabilities.

The Packer plugin Vagrant team prepared v1.1.8 [1][2], completing the version bump and copyright header compliance work needed for the release. Over in Consul, engineers merged overrides for vulnerable packages [3][4], tightening the security posture of the orchestrator's dependency graph. On the Vagrant side, routine maintenance continues with updates to ruby/setup-ruby [5] adding support for Ruby 4.0.5 in CI pipelines, while lock-threads bumped to 6.0.2 [6] to keep GitHub Actions automation current. Nomad driver Podman continues nightly snapshot releases [7] for early testing. Nothing critical lands today, but the Consul dependency hardening deserves attention if you're running recent versions.

Action items

References

  1. [1] version: prepare v1.1.8-dev ↗ hashicorp/packer-plugin-vagrant
  2. [2] Merge pull request #155 from taru-garg-hashicorp/prepare-1.1.8 hashicorp/packer-plugin-vagrant
  3. [3] add overrides for vulnerable packages ↗ hashicorp/consul
  4. [4] add overrides for vulnerable packages (#23610) hashicorp/consul
  5. [5] Bump ruby/setup-ruby from 1.299.0 to 1.310.0 ↗ hashicorp/vagrant
  6. [6] Bump dessant/lock-threads from 5.0.1 to 6.0.2 ↗ hashicorp/vagrant
  7. [7] nightly ↗ hashicorp/nomad-driver-podman

FAQ

What changed in HashiCorp on June 1, 2026?
Packer plugin Vagrant is stepping into v1.1.8 while Consul hardens its dependency chain against known vulnerabilities.
What should HashiCorp teams do about it?
Review Consul's vulnerable package overrides in your current deployment • Monitor Packer plugin Vagrant v1.1.8 release when it ships • Test Nomad driver Podman nightly against your workloads for early feedback
Which HashiCorp repositories shipped on June 1, 2026?
hashicorp/packer-plugin-vagrant, hashicorp/consul, hashicorp/vagrant, hashicorp/nomad-driver-podman

Related across the cluster

For your repos

The showcase is a teaser.
Your wire is the product.

Same engine. Different stack. Below: what changes when the wire is yours.

Showcase wire

  • 14 famous open source orgs
  • One wire per day
  • Public, generic
  • Read on the web, when you remember

Your wire

  • Up to 1,500 of your repos - orgs, deps, vendors
  • Morning and evening briefs
  • Action items routed to your team
  • Slack delivery, email, breaking-news CVE alerts

Want a hands-on demo first? Ask a current user for an invite link.