Skip to content

Pending Release Notes

Kallol Roy edited this page Oct 31, 2025 · 997 revisions

Upgrade Journey

Chef lets you choose your upgrade journey based on your current version of Chef Automate. You can do all the version upgrades manually.

Your Current Version Upgrade To
Any version before 20220329091442 20220329091442
20220329091442 3.0.x
3.0.49 4.x

See the Chef Automate 4.x upgrade documentation for more information.

New Features

Improvements

Compliance Profile Updates

Bug Fixes

Maintenance

Backward Incompatibilities

Security

Security Improvements

(examples: new security configurations)

Security Updates

(examples: dependency updates, CVE fixes)

  • Update go-viper to fix the following CVEs

CWE-117

  • Update nginx to 1.28.0 to resolve the following CVEs

CVE-2024-24989
CVE-2024-24990
CVE-2024-7347
CVE-2024-32760
CVE-2024-35161
CVE-2025-23419

  • Update tar-fs from version to 3.1.1 addresses the following CVE:

CVE-2025-59343

  • Update from cross-spawn 7.0.3 to 7.0.6 fixes:

CVE-2024-21538

  • Update from Ha-proxy to 2.8.15 resolves the following CVEs:

CVE-2023-40225
CVE-2023-45539
CVE-2023-25725
CVE-2023-0836
CVE-2022-0711
CVE-2021-40346
CVE-2021-39240
CVE-2021-39241
CVE-2021-39242

  • Update OpenSearch to the Tuxcare OpenSearch 1.3.20.tuxcare.1.0.2 address the following CVEs:

CVE-2025-25193
CVE-2024-47554
CVE-2021-28170
CVE-2025-48924
CVE-2024-38820
CVE-2025-48913
CVE-2024-38819
CVE-2024-38828
CVE-2024-38820
CVE-2025-22233

  • Update Postgres 13.22 resolves the following CVEs:

CVE-2025-8714
CVE-2025-8715
CVE-2025-8713

  • Update OpenJDK to 17.0.16+8 addresses the following CVEs:

CVE-2025-30749
CVE-2025-30754
CVE-2025-50059
CVE-2025-50106

Chef Packaged Product Versions

This release uses:

  • Chef Habitat version:
  • Chef Habitat Builder version:
  • Chef Infra Server version:
  • Chef InSpec version:

Service Versions

This release uses:

  • Postgres:
  • OpenSearch:
  • Nginx:
  • Haproxy:

Supported External Chef Products

This release supports the following external chef products:

  • Chef Infra Server version: 14.0.58+
  • Chef Inspec version: 4.3.2+
  • Chef Infra Client: 17.0.242+
  • Chef Habitat: 0.81+

View the package manifest for the latest release.

Clone this wiki locally