0.87.0 (2026-09-30)
⚠ BREAKING CHANGES
- remove images and repositories from package secret during connected deploys (#5402)
- helm: only label pod templates of built-in workload kinds (#5360)
- disable artifact server by default (#5417)
- migrate SignBlobOptions to a pointer (#5411)
- package: move signing out of publish (#5387)
- switch to api.Package from v1alpha1.ZarfPackage throughout repository (#5379)
- public operational type (#5345)
Features
- add explicit git server mode to state (#5395) (a8e695d)
- add validation for api package (#5393) (cebc6ee)
- component sign and verify (#5358) (9c58f59)
- component: sign published manifests (#5386) (0c61d2f)
- dev: add --components flag to dev inspect values-files (#5413) (13b7af6)
- disable artifact server by default (#5417) (720f29e)
- migrate SignBlobOptions to a pointer (#5411) (b94f06b)
- package: move signing out of publish (#5387) (438b6c5)
- public operational type (#5345) (6c9d7ce)
- remove migrated fields on api.Package (#5390) (ed97710)
- signing: unify signing option handling (#5385) (4ee0d5c)
- v1beta1: componet import validation (#5384) (ce0abd9)
- v1beta1: store multiple API versions in Deployed packages (#5250) (bcfbc65)
Bug Fixes
- assemble: cleanup temporary directory on error (#5407) (d07690e)
- create: run OnSuccess and OnFailure actions during create (#5406) (dd7301b)
- helm: handle charts that render resources inside list kinds (#5344) (1f7bbc9)
- helm: only label pod templates of built-in workload kinds (#5360) (7be076a)
- init: propagate secret updates on init mode changes (#5398) (c18603a)
- remove images and repositories from package secret during connected deploys (#5402) (1653ca2)
- replace github.com/defenseunicorns/pkg with local versions (#5324) (379379a)
- values: preserve inferred types across null overlays (#5412) (9213afd)
Refactoring
What's Changed
🚀 Updates
- chore(main): release 0.87.0 by @zarf-release-please[bot] in #5374
Full Changelog: v0.87.0-rc1...v0.87.0
Verifying Init Packages
The init packages in this release are signed with keyless Sigstore signing. Verify with:
amd64:
zarf package verify zarf-init-amd64-v0.87.0.tar.zst \
--certificate-identity "https://github.com/zarf-dev/zarf/.github/workflows/release.yml@refs/tags/v0.87.0" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"arm64:
zarf package verify zarf-init-arm64-v0.87.0.tar.zst \
--certificate-identity "https://github.com/zarf-dev/zarf/.github/workflows/release.yml@refs/tags/v0.87.0" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com"See RELEASES.md for details.