v2.0.2

elizaOS/elizav2.0.2Jun 5, 2026by ryancragun

AI Summary

This release updates Vault container configuration to remove the IPC lock capability for broader runtime compatibility and addresses security vulnerabilities by limiting RSA key sizes. It also includes dependency bumps and bug fixes for plugin verification and UI components.

Key Highlights

  • Vault container compatibility improvements (removed cap_ipc_lock capability)
  • Security enhancement: RSA key size limit to address CVE-2026-39829
  • Fixed plugin signature verification failure with expired PGP keys
  • Fixed key version dropdown selected state in transit UI

Breaking Changes

  • Remove cap_ipc_lock capability on vault at build time (requires disable_mlock = true)
  • RSA key sizes limited to a maximum of 8192 bits

Full Release Notes

BREAKING CHANGES:

* containers: Remove `cap_ipc_lock` capability on `vault` at build time to allow running Vault in common container runtimes. Vault in containers will no longer be able to call `mlock()` to lock memory. Operators should set `disable_mlock = true` in Vault's configuration. Runtime operators are advised to disable swapping to guarantee data safety.
* secrets/ssh: RSA key sizes are now limited to a maximum size of 8192 bits addressing CVE-2026-39829

CHANGES:

* core: Bump Go version to 1.26.4
* secrets/azure (enterprise): Update plugin to [v0.26.4+ent](https://github.com/hashicorp/vault-plugin-secrets-azure-enterprise/releases/tag/v0.26.4+ent)

BUG FIXES:

* plugins: Fix plugin signature verification failure with expired pgp key when registering a plugin.
* ui/transit: Fix key version dropdown selected state when editing a transit key.