chore(deps): update dependency opentofu to v1.11.1 #13
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.10.6->v1.11.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
opentofu/opentofu (OPENTOFU)
v1.11.1Compare Source
BUG FIXES:
Full Changelog: opentofu/opentofu@v1.11.0...v1.11.1
v1.11.0Compare Source
OpenTofu 1.11.0
We're proud to announce that OpenTofu 1.11.0 is now officially available! 🎉
Highlights
This release cycle introduces major new capabilities and integrations:
Ephemeral Values and Write Only Attributes
Ephemeral resources allow you to work with confidential data, temporary credentials, and transient infrastructure without persisting them to your state.
The
enabledMeta-ArgumentIf you want to conditionally deploy a resource, you no longer have to use
count = var.create_my_resource ? 1 : 0, you can now add the newenabledmeta-argument to your resource to conditionally deploy it.Compatibility Notes
macOS: Requires macOS 12 Monterey or later
Azure Backend (
azurerm):endpointandARM_ENDPOINTconfiguration options are no longer supportedmsi_endpointandARM_MSI_ENDPOINToptions are no longer supportedenvironmentandmetadata_hostarguments are now mutually exclusiveissensitive() Function: Now correctly returns unknown results when evaluating unknown values. Code that previously relied on the incorrect behavior may need updates.
Testing with Mocks: Mock values generated during testing now strictly adhere to provider schemas. Test configurations with invalid mock values will need to be corrected.
S3 Module Installation: When installing module packages from Amazon S3 buckets using S3 source addresses OpenTofu will use the same credentials as the AWS CLI and SDK.
TLS and SSH Security:
draft-miller-ssh-cert-03specification-var/-var-fileduringtofu apply <planfile>:-var/-var-fileduringtofu apply <planfile>to pass again the values for ephemeral variables during apply-var/-var-fileto be used with non-ephemeral variables too, but it will error if the values given for this type of variables is different from the ones given during the plan creationTF_VARvalues should stay consistent betweenplanandapply <planfile>to avoid the errors mentioned aboveReference
Thank you for your continued support and testing of the OpenTofu project!
v1.10.8Compare Source
SECURITY ADVISORIES:
This release contains fixes for some security advisories related to previous releases in this series.
Incorrect handling of excluded subdomain constraint in conjunction with TLS certificates containing wildcard SANs
This release incorporates the upstream fixes for GO-2025-4175.
Excessive CPU usage when reporting error about crafted TLS certificate with many hostnames
This release incorporates the upstream fixes for GO-2025-4155.
Full Changelog: opentofu/opentofu@v1.10.7...v1.10.8
v1.10.7Compare Source
SECURITY ADVISORIES:
This release contains fixes for some security advisories related to previous releases in this series.
tofu initin OpenTofu v1.10.6 and earlier could potentially use unbounded memory if there is a direct or indirect dependency on a maliciously-crafted module package distributed as a "tar" archive.This would require the attacker to coerce a root module author to depend (directly or indirectly) on a module package they control, using the HTTP, Amazon S3, or Google Cloud Storage source types to refer to a tar archive.
This release incorporates the upstream fixes for CVE-2025-58183.
When making requests to HTTPS servers, OpenTofu v1.10.6 and earlier could potentially use unbounded memory or crash with a "panic" error if TLS verification involves an excessively-long certificate chain or a chain including DSA public keys.
This affected all outgoing HTTPS requests made by OpenTofu itself, including requests to HTTPS-based state storage backends, module registries, and provider registries. For example, an attacker could coerce a root module author to depend (directly or indirectly) on a module they control which then refers to a module or provider from an attacker-controlled registry. That mode of attack would cause failures in
tofu init, at module or provider installation time.Provider plugins contain their own HTTPS client code, which may have similar problems. OpenTofu v1.10.7 cannot address similar problems within provider plugins, and so we recommend checking for similar advisories and fixes in the provider plugins you use.
This release incorporates upstream fixes for CVE-2025-58185, CVE-2025-58187, and CVE-2025-58188.
BUG FIXES:
for_eachinsidedynamicblocks can now call provider-defined functions. (#3429)Full Changelog: opentofu/opentofu@v1.10.6...v1.10.7
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.