2025.7 - Required
| Version | |
|---|---|
| 2025.7.0 | July 25, 2025 |
| 2025.7.1 | August 8, 2025 |
System Requirements Update
Ensure your infrastructure meets the latest requirements for optimal performance and security:
| Component | Minimum Version | Recommended Version |
|---|---|---|
| KOTS | 1.117.3 | Latest |
| Kubernetes | 1.28 ⚠️ | 1.32 |
| PostgreSQL | 15 | 16 |
| Redis | 6 | 7 |
| ggscout | 0.16.6 | Latest |
Helm & Upgrade Considerations
To ensure compatibility, please review Helm values updates from the previous version. Air gap deployment? Find all the images and tag names in the air gap install page.
⚠️ Important: This is a required release and cannot be skipped.
Machine Learning engine is now enabled by default. Ensure your infrastructure meets the ML requirements.
If you're concerned about resource usage, you can lower the priority of ML pods to ensure other critical services are scheduled first.
Feature highlights
- Jira and Confluence Data Center historical scanning — scan past content for secrets. Learn more
- Auto-ignore invalid incidents playbook — automatically clear confirmed invalid secrets. Learn more
Secrets Detection Engine
- v2.141 — 12 new detectors (Kubernetes User Certificate with Port, NVIDIA, Alchemy v2, OpenRouter, Duffel, Apify, Jina, Deno Account, Segment Workspace v2, Resend, VKontakte, Fireworks AI), 6 improved, 10 new checkers.
- v2.142 — 2 new detectors (AI71, AMP), 9 improved (Kubernetes Docker, MySQL, Sourcegraph, GitHub, HashiCorp Vault, Confluent, GitHub Fine-Grained PAT, Slack, DigitalOcean Spaces), 2 new checkers.
- v2.143 — 7 new detectors (GitLab Incoming Mail, Coze PAT, Tavus, Heroku Platform, SSH with port, Tableau Cloud PAT, Notion v2), 7 improved, 6 new checkers. All JWT detectors now only catch signed JWTs.
Enhancements
- Custom tags API key/value filtering, auto-resolve revoked secrets playbook, custom remediation links. Learn more.
- Jira DC leaker emails. Learn more.
- Custom tags API documentation. Learn more.
- GitLab multi-hook support. Learn more.
Fixes
- Custom tags bulk assignment, Azure DevOps token handling. Learn more.
- GitHub installation checks. Learn more.
- Teams email notifications. Learn more.
- SCIM case-insensitive emails. Learn more.
- Deletion line scanning. Learn more.
Hotfixes
2025.7.1
Release Date: August 8, 2025
Fixes
- Self-Hosted:
- Embedded Cluster with Embedded Redis configuration to use
bitnamilegacy/redisregistry following Bitnami's registry changes. - ML Secret Engine updated to version 20250806 fixing critical CVE-2025-54381.
- NHI Scout bumped to version 0.18.2.
- Embedded Cluster with Embedded Redis configuration to use