Skip to content

v3.3.0

Latest

Choose a tag to compare

@conjur-jenkins conjur-jenkins released this 10 Sep 19:02

[3.3.0] - 2026-08-04

Added

  • AzureAuthenticator for authenticating via Azure IMDS, supporting both
    system-assigned and user-assigned managed identities. (CNJR-14056)
  • GCPAuthenticator for authenticating with a GCP instance metadata identity
    token, including refreshJwt for token renewal. (CNJR-14056)
  • AWSIAMAuthenticator for authenticating with AWS IAM credentials. The
    software.amazon.awssdk sts and auth dependencies are marked optional, so
    they are not pulled into consumers that do not use AWS authentication.
  • CertAuthenticator for certificate-based (mTLS) authentication, with
    Conjur.newFromCertificate factory methods that read configuration from
    CONJUR_AUTHN_CERT_SERVICE_ID, CONJUR_AUTHN_CERT_FILE,
    CONJUR_AUTHN_CERT_KEY_FILE, and the optional CONJUR_AUTHN_CERT_HOST_ID
    (omit for SPIFFE mode), or accept PEM content directly. (CNJR-14055)

Security

  • Pin io.netty netty-codec, netty-handler, netty-codec-http, and
    netty-codec-http2 to 4.1.136.Final via dependencyManagement to address CVEs
    in the versions transitively pulled by awssdk:netty-nio-client.