Notes
🛡️ Security notices
- Fixed a remote code execution vulnerability caused by path traversal in #2292
- Added explicit permissions to GitHub Actions workflows to reduce token scope in #2232
- Bumped google.golang.org/grpc from 1.79.3 to 1.82.1 in go.mod in #2296
- Bumped embedded OHI versions (nri-docker, nri-flex) to fix known CVEs in #2302
- bump vulnerable dependencies flagged by Trivy scan in #2301
🚀 Enhancements
- Added support for ignoring default integration locations via disable_plugin_default_dir_scan in #2290
- Made environment variables used by Agent Control public in #2293
- Added OCI tag support to match AWS tags (Phase 1 + Phase 2) in #2295
- Enabled NRIA_DISABLE_PLUGIN_DEFAULT_DIR_SCAN by default for Agent-Control-managed agents in #2300
- Removed nri-flex from agent-control artifacts in #2291
🐞 Bug fixes
- Restored missing job permissions for release and canary workflows in #2303
Support statement:
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent.
We recommend updating to the latest agent version as soon as it's available. If you can't upgrade to the latest version, update your agents to a version no more than 90 days old. Read more about keeping agents up to date.
See the New Relic Infrastructure agent EOL policy for information about agent releases and support dates.