Skip to content

chore(deps): update dependency opentofu/opentofu to v1.12.6 - #15

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/opentofu-opentofu-1.x
Open

chore(deps): update dependency opentofu/opentofu to v1.12.6#15
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/opentofu-opentofu-1.x

Conversation

@renovate

@renovate renovate Bot commented Jul 13, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
opentofu/opentofu patch 1.12.31.12.6

Release Notes

opentofu/opentofu (opentofu/opentofu)

v1.12.6

Compare Source

SECURITY ADVISORIES:

  • When interacting with OCI Distribution registries for module or provider package installation, earlier versions of OpenTofu could incorrectly resend credentials intended for the original origin to the target of an HTTP redirect. (#​4422)
  • When interacting with an attacker-controlled remote state backend or provider/module registry, tofu init in earlier versions of OpenTofu could potentially cause high CPU usage and/or high memory usage resolving crafted relative URLs in the API responses. (#​4472)

Full Changelog: opentofu/opentofu@v1.12.5...v1.12.6

v1.12.5

Compare Source

SECURITY ADVISORIES:

  • Previous releases in the v1.12 series could be affected by several vulnerabilities:

    • The Encrypted Client Hello implementation (which is used by OpenTofu through the go stdlib) would leak the pre-shared key identities during the handshake,
      allowing a passive network observer who can collect handshakes to de-anonymize the hostname of the server, even when ECH was being used.

    This is fixed now by (#​4363)

BUG FIXES:

  • Fixed bug where implicit moves and provider address changes would incorrectly cause providers.MovedResourceState to be used in place of providers.UpgradeResourceState (#​4375)

Full Changelog: opentofu/opentofu@v1.12.4...v1.12.5

v1.12.4

Compare Source

BUG FIXES:

  • tofu plan -out no longer fails when the plan includes a resource with lifecycle { destroy = false } that needs replacement, which previously errored with invalid change action ForgetThenCreate. (#​4324)
  • Moved block now correctly compares provider source addresses. (#​4280)[#​4280]
  • Correct Source Provider Address now passed into Provider MoveResource requests. (#​4355)[#​4355]

Full Changelog: opentofu/opentofu@v1.12.3...v1.12.4


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update dependency opentofu/opentofu to v1.12.4 chore(deps): update dependency opentofu/opentofu to v1.12.5 Jul 21, 2026
@renovate
renovate Bot force-pushed the renovate/opentofu-opentofu-1.x branch from 1dd3de1 to 1c5cf5f Compare July 21, 2026 12:07
@renovate renovate Bot changed the title chore(deps): update dependency opentofu/opentofu to v1.12.5 chore(deps): update dependency opentofu/opentofu to v1.12.6 Aug 19, 2026
@renovate
renovate Bot force-pushed the renovate/opentofu-opentofu-1.x branch from 1c5cf5f to 8bbe0ba Compare August 19, 2026 14:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants