Added
- X.509 CA metric with absolute expiration time in addition to TTL-based metric (#6303)
spire-agentconfiguration to source join tokens from files to support integration with third-party credential providers (#6330)- Capability to filter on caller path in
spire-serverRego authorization policies (#6320)
Changed
spire-serverwill use the SHA-256 algorithm for X.509-SVID Subject Key Identifiers when theGODEBUGenvironment variable containsfips140=only(#6294)- Attested node entries are now purged at a fixed interval with jitter (#6315)
oidc-discovery-providernow fails to initialize when started with unrecognized arguments (#6297)