← Back to all sparks
I

Infisical

INFRA · APIS
Velocity6.3

Open-source secret management platform for developers

Infisical ships multiple patch releases per week, hardening PKI, PAM, and secrets-sync with each drop.

secrets-managementsecurityopen-sourcepkidevopscompliance
Current state
Infisical has published nine patch releases in the first two weeks of September 2026 (v0.165.2–v0.165.11). The work spans PKI correctness (enforcing only policy-validated subject and SAN values in certificate issuance), PAM improvements (atomic secret minting, LDAP-backed Linux/Windows sync from a single connection), secret-sync reliability (Daytona duplicate detection, end-to-end test harness), and a security hardening measure deriving the cookie signing key from the KMS root key rather than a static secret.
Where it's heading
The KMIP server UI is migrating to v3 component patterns across multiple releases, and the validation rule API is being revamped — these are parallel modernization tracks running alongside continuous bug hardening. The breadth of touched subsystems (PKI, PAM, KMIP, dynamic secrets, LDAP, secret rotation, frontend) reflects a wide surface rather than deep focus. The end-to-end test harness for secret-sync is an investment in regression prevention at this release cadence.
Prediction
The KMIP migration and validation rule revamp will complete across the next several releases, and the PKI policy enforcement hardening suggests a compliance positioning push may follow. A major new capability (new auth method, new secret type, enterprise certification) is not visible in this window.

Recent moves

  1. 13h ago

    Infisical v0.165.11: KMIP UI migration, secret-sync tests, queue logging

    v0.165.11 advances the KMIP server page migration to v3 components, pins secret-sync behavior with an end-to-end test harness (an important investment at this release pace), and fixes queue job failure logging. Three distinct maintenance tracks advancing simultaneously.

    View source ↗
  2. 4d ago

    Infisical v0.165.10: PKI SAN enforcement, PAM atomic mint, validation rule revamp

    v0.165.10 tightens PKI certificate issuance to only allow policy-validated subject and SAN values — a correctness fix with real compliance implications. The PAM atomic secret mint and validation rule API revamp (flagged as a feature, not a fix) are the other notable changes in this release.

    View source ↗
  3. 6d ago

    Infisical v0.165.9: KMS-derived cookie signing, Daytona sync dedup

    Deriving the cookie signing key from the KMS root key (rather than a static signing secret) is a real security hardening — it ties session integrity to the KMS chain rather than to a separately managed credential. Daytona duplicate sync detection prevents double-provisioning for orgs using Daytona as a sync target.

    View source ↗
  4. 7d ago

    Infisical v0.165.8: telemetry cardinality fix, HP iLO 7 rotation

    Bounding HTTP metric cardinality prevents telemetry label explosion under high-volume request patterns — a quiet but important ops fix. The HP iLO 7 rotation prompt fix is a narrow integration correctness issue with no broader impact.

    View source ↗
  5. 8d ago

    Infisical v0.165.7: single LDAP connection for multi-platform sync

    Allowing one LDAP connection to back multiple Linux and Windows sync targets removes configuration overhead for organizations running mixed-OS environments against a shared LDAP directory. The AWS Secrets Manager many-to-one fix and concurrent secret reference load coalescing are correctness improvements at scale.

    View source ↗
  6. 11d ago

    Infisical v0.165.6: scan run auto-refresh, Unix rotation fix

    Auto-refreshing scan runs while a scan is active is a usability improvement that removes manual page reloads during monitoring. The Unix rotation prompt fragmentation fix is a narrow correctness issue in the secret rotation flow.

    View source ↗