These are release notes for API portal for VMware Tanzu.

v1.0.31

Release Date: October 28, 2022

Included in This Release

  • Resolved vulnerabilities: CVE-2022-31684 and CVE-2022-37434

v1.0.30

Release Date: October 27, 2022

Included in This Release

  • Resolved vulnerability: CVE-2022-42003

v1.0.29

Release Date: October 13, 2022

Included in This Release

  • Resolved vulnerability: CVE-2022-42004

v1.0.28

Release Date: October 3, 2022

Included in This Release

  • Resolved vulnerability in base image: USN-5627-1

v1.0.27

Release Date: September 23, 2022

Included in This Release

  • Resolved following CVEs: CVE-2022-2526

v1.0.26

Release Date: August 26, 2022

Included in This Release

  • Resolved following CVEs: CVE-2022-37434

v1.0.25

Release Date: August 11, 2022

Included in This Release

  • Resolved following CVEs: CVE-2021-4209 and CVE-2022-2509

v1.0.24

Release Date: July 13, 2022

Included in This Release

  • Resolved following CVEs: CVE-2022-34903

v1.0.23

Release Date: July 5, 2022

Included in This Release

  • Resolved following CVEs: CVE-2022-2068

v1.0.22

Release Date: July 5, 2022

Included in This Release

  • Resolved following CVEs: CVE-2022-1304

v1.0.21

Release Date: June 6, 2022

Included in This Release

  • Resolved following security vulnerabilities: USN-5446-1

v1.0.20

Release Date: May 25, 2022

Included in This Release

  • Resolved following CVEs: CVE-2022-22970

v1.0.19

Release Date: May 23, 2022

Included in This Release

  • Resolved following CVEs: CVE-2019-20838, CVE-2020-14155

v1.0.18

Release Date: May 18, 2022

Included in This Release

  • Resolved following CVEs: CVE-2022-1292, CVE-2022-1343, CVE-2022-1434, CVE-2022-1473

v1.0.17

Release Date: April 19, 2022

Included in This Release

  • Added option to ignore SSL certificate validation

v1.0.16

Release Date: April 14, 2022

Included in This Release

  • Resolved CVE-2018-25032

v1.0.15

Release Date: March 31, 2022

Included in This Release

v1.0.14

Release Date: March 29, 2022

Included in This Release

  • Resolved multiple CVEs - recommend upgrade from the previous versions

v1.0.13

Release Date: March 18, 2022

Included in This Release

  • Resolved multiple CVEs - recommend upgrade from the previous versions

v1.0.12

Release Date: March 1, 2022

Included in This Release

  • Resolved multiple CVEs - recommend upgrade from the previous versions

v1.0.11

Release Date: February 17, 2022

Included in This Release

  • Resolved multiple CVEs - recommend upgrade from the previous versions
  • Added the configuration to disable Privilege Escalation for the server container to better align with Kubernetes Pod security standards

v1.0.10

Release Date: January 27, 2022

Included in This Release

  • Resolved CVE-2022-0235 for node-fetch vulnerabilities - recommend upgrade from the previous versions

v1.0.9-sr.1

Release Date: March 31, 2022

Included in This Release

v1.0.9

Release Date: January 4, 2022

Included in This Release

  • Resolved CVE-2021-45105 and CVE-2021-44832 for Log4J vulnerabilities - recommend upgrade from the previous versions

v1.0.8

Release Date: December 16, 2021

Included in This Release

  • Resolved CVE-2021-45046 for Log4J vulnerability - recommend upgrade from the previous versions

v1.0.7

Release Date: December 10, 2021

Included in This Release

  • Display the user name when the user is authenticated
  • Resolved CVEs issues - recommend upgrade from the previous versions

v1.0.6

Release Date: November 24, 2021

Included in This Release

  • Automated namespace creation when using tanzu CLI to deploy a new API portal

v1.0.5

Release Date: November 22, 2021

Included in This Release

  • Added ability to deploy API portal instances into multiple namespaces using Carvel toolchain
  • Improved the UI styling for API details

v1.0.4

Release Date: November 12, 2021

Included in This Release

  • Enable the direct visit to the view detail page when a single API group is configured with the API portal
  • Enable the user to apply default resource allocation and allow override configuration for API portal instances during installation

Known Issues

  • TAP installation only: API portal 1.0.4 will not automatically create its namespace when installed through TAP CLI. This issue has been addressed on version 1.0.6. Versions 1.0.4 and 1.0.5 can still be installed but users must create themselves the namespace before using tanzu package install api-portal command.

v1.0.3

Release Date: October 13, 2021

Included in This Release

  • Fixed the installation for the Tanzu Application Service deployments by adding the jars folder in the installation package
  • Resolved the CVE issues; recommend upgrade from the previous versions

v1.0.2

Release Date: September 27, 2021

Included in This Release

  • Added the following authorization flows to the API portal: OpenID and Bearer token
  • Added the Tanzu CLI installation

v1.0.1

Release Date: June 30, 2021

Included in This Release

*Fixed the issue where API Portal does not read OpenAPI specs from Git if the spec JSON file contains newline characters

v1.0.0

Release Date: April 28, 2021

Included in This Release

  • Installer for both Kubernetes and Tanzu Application Service targets
  • Display API group documentation from multiple OpenAPI v2 & v3 source locations
  • Find APIs based on text-based search
  • Try out APIs through web browser interface
  • Configurable OpenID Connect (OIDC) Single Sign-On authentication support
  • Customizable OpenAPI source cache refresh frequency
  • Horizontal scaling for high availability configurations
  • Works seamlessly with Spring Cloud Gateway commercial products on Kubernetes and Tanzu Application Service
check-circle-line exclamation-circle-line close-line
Scroll to top icon