2025.7 - Required
| Version | |
|---|---|
| 2025.7.0 | July 25, 2025 |
| 2025.7.1 | August 8, 2025 |
System Requirements Update
Ensure your infrastructure meets the latest requirements for optimal performance and security:
| Component | Minimum Version | Recommended Version |
|---|---|---|
| KOTS | 1.117.3 | Latest |
| Kubernetes | 1.28 ⚠️ | 1.32 |
| PostgreSQL | 15 | 16 |
| Redis | 6 | 7 |
| ggscout | 0.16.6 | Latest |
Helm & Upgrade Considerations
To ensure compatibility, please review Helm values updates from the previous version. Air gap deployment? Find all the images and tag names in the air gap install page.
⚠️ Important: This is a required release and cannot be skipped.
Upgrading to 2025.7
Machine Learning engine is now enabled by default. Ensure your infrastructure meets the ML requirements.
If you're concerned about resource usage, you can lower the priority of ML pods to ensure other critical services are scheduled first.
Feature highlights
- Jira and Confluence Data Center historical scanning — scan past content for secrets. Learn more
- Auto-ignore invalid incidents playbook — automatically clear confirmed invalid secrets. Learn more
Secrets Detection Engine
- v2.141 — 12 new detectors (Kubernetes User Certificate with Port, NVIDIA, Alchemy v2, OpenRouter, Duffel, Apify, Jina, Deno Account, Segment Workspace v2, Resend, VKontakte, Fireworks AI), 6 improved, 10 new checkers.
- v2.142 — 2 new detectors (AI71, AMP), 9 improved (Kubernetes Docker, MySQL, Sourcegraph, GitHub, HashiCorp Vault, Confluent, GitHub Fine-Grained PAT, Slack, DigitalOcean Spaces), 2 new checkers.
- v2.143 — 7 new detectors (GitLab Incoming Mail, Coze PAT, Tavus, Heroku Platform, SSH with port, Tableau Cloud PAT, Notion v2), 7 improved, 6 new checkers. All JWT detectors now only catch signed JWTs.
Enhancements
- Custom tags API key/value filtering, auto-resolve revoked secrets playbook, custom remediation links. See SaaS release: Jun 19.
- Jira DC leaker emails. See SaaS release: Jun 30.
- Custom tags API documentation. See SaaS release: Jul 21.
- GitLab multi-hook support. See SaaS release: Jul 23.
Fixes
- Custom tags bulk assignment, Azure DevOps token handling. See SaaS release: Jun 19.
- GitHub installation checks. See SaaS release: Jun 30.
- Teams email notifications. See SaaS release: Jul 7.
- SCIM case-insensitive emails. See SaaS release: Jul 21.
- Deletion line scanning. See SaaS release: Jul 28.
Hotfixes
2025.7.1
Release Date: August 8, 2025
Fixes
- Self-Hosted:
- Embedded Cluster with Embedded Redis configuration to use
bitnamilegacy/redisregistry following Bitnami's registry changes. - ML Secret Engine updated to version 20250806 fixing critical CVE-2025-54381.
- NHI Scout bumped to version 0.18.2.
- Embedded Cluster with Embedded Redis configuration to use