Skip to main content

2025.05.18 Release Note

· 4 min read

This release reinforces Spider security.

Upgrade risk

info
  • No compatibility issue 👍
  • No breaking changes 👍

Key changes

How to upgrade

  1. Use Helm chart 4.8.0 from repository
  2. Adjust global.version field value to 2025.05.18 in your values.yaml
  3. Deploy
tip

See Reference documentation for details.

Versions

Spider

New versions of Spider components:

ComponentVersionDocker tag
Helm chart4.8.0-
Analysis UI12.22025.05.18
Controllers2.02025.05.18
Gossipers7.52025.05.18
Gociphers1.62025.05.18
Back office-2025.05.18
Login UI-2025.05.18
Monitoring UI-2025.05.18

Dependencies

These components are set up in the correct versions by the Helm chart:

DependencyVersionDocker tag
Elastic stack7.17.287.17.28
Redis77-alpine
Traefik2.112.11

Compatibility

Spider has been successfully tested under these versions of dependencies:

3rd party softwareVersion
Helm3.14 - 3.17
Kube1.24 - 1.31

List of changes

Helm chart

✨ New features
  • Use refresh tokens to enhance security
⚙️ Improvements
🐞 Bug fixes

Analysis UI

✨ New features
  • Use refresh tokens to enhance security
⚙️ Improvements
🐞 Bug fixes

Controllers

✨ New features
⚙️ Improvements
🐞 Bug fixes

Gossipers (Whisperers)

✨ New features
⚙️ Improvements
  • Upgraded to Go 1.24, improved performance
🐞 Bug fixes

Gociphers

✨ New features
⚙️ Improvements
  • Upgraded to Go 1.24, improved performance
  • Management of OpenSSL versions: 3.3.0 -> 3.3.3, 3.4.0 -> 3.4.2, 3.5.0
  • Management of Node OpenSSL embedded versions: 1.1.1a -> 3.0.16, included +quic versions
🐞 Bug fixes

Back office

✨ New features
  • Use refresh tokens to enhance security
  • Use Kube projected tokens to secure first service call to Config service
⚙️ Improvements
🐞 Bug fixes

Login UI

✨ New features
  • Use refresh tokens to enhance security
⚙️ Improvements
🐞 Bug fixes

Monitoring UI

✨ New features
  • Use refresh tokens to enhance security
⚙️ Improvements
🐞 Bug fixes

Online documentation

Main updated parts:

  • Setup.yaml reference - you may now set ttl for access and refresh tokens

Kube impacts

  • Config service has a new service account to allow calling tokenReview API
  • Each service now has its own service account, with default rights for most

API impacts

note

This section informs about any impact on Spider API, so you may adjust your scripts.

  • Customers service:
    • Refresh tokens emission
    • Access token renewal
    • Refresh token discarding / deletion

Data impacts

note

The table below tells if there are data mapping changes in Elasticsearch indices, associated or not with migrations (Yes ✅ / No ❌).
Migration are automated at upgrade time, but they may leave unattended indices that you have to remove manually.

IndexDescriptionMigration