github engity-com/bifroest v1.0.0-beta1

latest release: docs/v1.0.0-beta1
pre-release3 hours ago

⚠️ This is a pre-release ⚠️

Highlights

  • Audit logs: Signed, tamper-evident event journals with verification and export tools, optional encryption, and delivery to S3, SFTP or WebDAV.
  • Session recording: Verifiable recordings of SSH shell and command output, with optional encryption and export. Recording works independently of audit logging.
  • SSH gateway: Connect to SSH targets with host-key verification and separate credentials; SSH user certificates and Bifröst-to-Bifröst delegation are also supported.
  • Native macOS support: Host service and local-account sessions on Intel and Apple Silicon.
  • Windows local access: Local authorization and S4U impersonation run sessions as the selected local account, with ConPTY for interactive terminals.
  • OIDC refresh: Proactive token refresh can end Bifröst sessions and connections when the identity provider rejects a refresh grant.
  • Release artifacts: Per-variant SBOMs, third-party notices, checksums and a release manifest.

Upgrading from v0.7.x

  • OIDC requires refresh tokens by default; existing sessions without them may be disposed. Windows local flows must now select a local account.
  • Review the upgrade guide for session-storage, timeout and cleanup changes.

What's Changed

  • Add tamper-evident audit logging and remote delivery by @blaubaer in #531
  • Add SSH environments, user certificates, and Bifroest delegation by @blaubaer in #525
  • Add secure session recording by @blaubaer in #552
  • Bind reverse forwards in target environments by @blaubaer in #563
  • Add allowlisted SSH subsystem forwarding by @blaubaer in #562
  • Add Windows local impersonation and ConPTY by @blaubaer in #564
  • Dispose sessions with incompatible IMP protocol revisions by @blaubaer in #578
  • Update managed dependencies by @bitfrost-build-bot[bot] in #581
  • Add Windows local authorization by @blaubaer in #582
  • Add native macOS support by @blaubaer in #580
  • Add proactive OIDC session refresh and access revocation by @blaubaer in #594
  • Migrate to ssh-server-go v0.2.3 and harden execution lifecycles by @blaubaer in #522
  • Bump github.com/coreos/go-oidc/v3 from 3.20.0 to 3.21.0 by @dependabot[bot] in #520
  • Bump github.com/docker/cli from 29.7.2+incompatible to 29.8.0+incompatible by @dependabot[bot] in #519
  • Bump github.com/moby/moby/api from 1.55.0 to 1.56.0 by @dependabot[bot] in #521
  • Bump github.com/google/go-containerregistry from 0.22.0 to 0.22.1 by @dependabot[bot] in #518
  • Bump golang.org/x/oauth2 from 0.36.0 to 0.37.0 by @dependabot[bot] in #523
  • Bump golang.org/x/sys from 0.47.0 to 0.48.0 by @dependabot[bot] in #524
  • Stop bundling netapi32.dll by @blaubaer in #526
  • Bump golang.org/x/crypto from 0.56.0 to 0.57.0 by @dependabot[bot] in #527
  • Add end-to-end license compliance by @blaubaer in #530
  • Bump github/codeql-action/init from 4.37.9 to 4.38.0 by @dependabot[bot] in #537
  • Harden user repository watcher lifecycle by @blaubaer in #544
  • Bump golang.org/x/net from 0.58.0 to 0.59.0 by @dependabot[bot] in #533
  • Bump github.com/engity-com/ssh-server-go from 0.2.3 to 0.2.4 by @dependabot[bot] in #532
  • Fix process identity and Podman detection by @blaubaer in #545
  • Bump github.com/go-delve/delve from 1.27.1 to 1.27.2 by @dependabot[bot] in #534
  • Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.113.0 to 1.113.1 by @dependabot[bot] in #536
  • Bump importlib-metadata from 8.7.0 to 9.0.1 in /docs by @dependabot[bot] in #543
  • Bump certifi from 2026.2.25 to 2026.7.22 in /docs by @dependabot[bot] in #542
  • Bump wcmatch from 11.0 to 11.0.1 in /docs by @dependabot[bot] in #541
  • Bump pymdown-extensions from 11.0.1 to 11.0.2 in /docs by @dependabot[bot] in #539
  • Bump pygments from 2.19.2 to 2.21.0 in /docs by @dependabot[bot] in #540
  • Update managed dependencies by @bitfrost-build-bot[bot] in #546
  • Bump github.com/aws/aws-sdk-go-v2/credentials from 1.20.4 to 1.20.5 by @dependabot[bot] in #547
  • Update managed dependencies by @bitfrost-build-bot[bot] in #548
  • Update managed dependencies by @bitfrost-build-bot[bot] in #551
  • Update managed dependencies by @bitfrost-build-bot[bot] in #556
  • Bump the codeql-actions group across 1 directory with 3 updates by @dependabot[bot] in #555
  • Bump github.com/mattn/go-zglob from 0.0.6 to 0.0.8 by @dependabot[bot] in #554
  • Bump github.com/docker/cli from 29.8.0+incompatible to 29.8.1+incompatible by @dependabot[bot] in #549
  • Bump github.com/echocat/slf4g/native from 1.8.4 to 1.9.0 by @dependabot[bot] in #558
  • Update managed dependencies by @bitfrost-build-bot[bot] in #560
  • Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.113.1 to 1.113.2 by @dependabot[bot] in #557
  • Log when no authentication flow matches by @blaubaer in #561
  • Bump github.com/aws/smithy-go from 1.28.1 to 1.28.2 by @dependabot[bot] in #553
  • Build platform binaries in separate CI jobs by @blaubaer in #565
  • Bump the codeql-actions group with 3 updates by @dependabot[bot] in #570
  • Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.113.2 to 1.113.4 by @dependabot[bot] in #569
  • Bump github.com/aws/aws-sdk-go-v2/credentials from 1.20.5 to 1.20.6 by @dependabot[bot] in #571
  • Bump k8s.io/api from 0.37.0 to 0.37.1 by @dependabot[bot] in #567
  • Make interval checkpoint failure test deterministic by @blaubaer in #572
  • Stabilize remote artifact delivery flush tests on Windows by @blaubaer in #573
  • Bump k8s.io/client-go from 0.37.0 to 0.37.1 by @dependabot[bot] in #574
  • Bump github.com/klauspost/compress from 1.19.2 to 1.20.1 by @dependabot[bot] in #575
  • Bump urllib3 from 2.7.0 to 2.8.0 in /docs by @dependabot[bot] in #577
  • Bump golang.org/x/image from 0.12.0 to 0.41.0 by @dependabot[bot] in #576
  • Bump github.com/docker/cli from 29.8.1+incompatible to 29.8.2+incompatible by @dependabot[bot] in #579
  • Bump github.com/ebitengine/purego from 0.10.2 to 0.11.1 by @dependabot[bot] in #584
  • Bump github.com/shirou/gopsutil/v4 from 4.26.8 to 4.26.9 by @dependabot[bot] in #585
  • Bump github.com/engity-com/ssh-server-go from 0.4.0 to 0.4.1 by @dependabot[bot] in #586
  • Bump packaging from 26.0 to 26.3 in /docs by @dependabot[bot] in #592
  • Bump markdown from 3.10.3 to 3.11 in /docs by @dependabot[bot] in #591
  • Bump idna from 3.19 to 3.20 in /docs by @dependabot[bot] in #590
  • Bump pyparsing from 3.3.2 to 3.3.3 in /docs by @dependabot[bot] in #589
  • Bump pymdown-extensions from 11.0.2 to 12.1 in /docs by @dependabot[bot] in #588
  • Bump jdx/mise-action from 4.3.0 to 5.0.0 by @dependabot[bot] in #587
  • Update managed dependencies by @bitfrost-build-bot[bot] in #593
  • Prepare 1.0.0-beta1 by @blaubaer in #583

New Contributors

  • @bitfrost-build-bot[bot] made their first contribution in #546

Full Changelog: v0.7.7...v1.0.0-beta1

Don't miss a new bifroest release

NewReleases is sending notifications on new releases.