[3.3.0] - 2026-08-04
Added
AzureAuthenticatorfor authenticating via Azure IMDS, supporting both
system-assigned and user-assigned managed identities. (CNJR-14056)GCPAuthenticatorfor authenticating with a GCP instance metadata identity
token, includingrefreshJwtfor token renewal. (CNJR-14056)AWSIAMAuthenticatorfor authenticating with AWS IAM credentials. The
software.amazon.awssdkstsandauthdependencies are marked optional, so
they are not pulled into consumers that do not use AWS authentication.CertAuthenticatorfor certificate-based (mTLS) authentication, with
Conjur.newFromCertificatefactory methods that read configuration from
CONJUR_AUTHN_CERT_SERVICE_ID,CONJUR_AUTHN_CERT_FILE,
CONJUR_AUTHN_CERT_KEY_FILE, and the optionalCONJUR_AUTHN_CERT_HOST_ID
(omit for SPIFFE mode), or accept PEM content directly. (CNJR-14055)
Security
- Pin
io.nettynetty-codec,netty-handler,netty-codec-http, and
netty-codec-http2to 4.1.136.Final viadependencyManagementto address CVEs
in the versions transitively pulled byawssdk:netty-nio-client.