Skip to content

Update dependency opentofu to v1.12.5 - #15

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/opentofu-1.x
Open

Update dependency opentofu to v1.12.5#15
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/opentofu-1.x

Conversation

@renovate

@renovate renovate Bot commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
opentofu tools patch 1.12.21.12.5

Release Notes

opentofu/opentofu (opentofu)

v1.12.5

Compare Source

SECURITY ADVISORIES:

  • Previous releases in the v1.12 series could be affected by several vulnerabilities:

    • The Encrypted Client Hello implementation (which is used by OpenTofu through the go stdlib) would leak the pre-shared key identities during the handshake,
      allowing a passive network observer who can collect handshakes to de-anonymize the hostname of the server, even when ECH was being used.

    This is fixed now by (#​4363)

BUG FIXES:

  • Fixed bug where implicit moves and provider address changes would incorrectly cause providers.MovedResourceState to be used in place of providers.UpgradeResourceState (#​4375)

Full Changelog: opentofu/opentofu@v1.12.4...v1.12.5

v1.12.4

Compare Source

BUG FIXES:

  • tofu plan -out no longer fails when the plan includes a resource with lifecycle { destroy = false } that needs replacement, which previously errored with invalid change action ForgetThenCreate. (#​4324)
  • Moved block now correctly compares provider source addresses. (#​4280)[#​4280]
  • Correct Source Provider Address now passed into Provider MoveResource requests. (#​4355)[#​4355]

Full Changelog: opentofu/opentofu@v1.12.3...v1.12.4

v1.12.3

Compare Source

BUG FIXES:
  • Properly handle TF_ENCRYPTION with only blank spaces. (#​4265)
  • The value resulted from the lifecycle.enabled evaluation now has its deprecation marks processed correctly (#​4162)
  • Update documentation to clarify the usage restriction of ephemeral values in lifecycle.enabled. (#​4220)
  • tofu console -lock=false now works as intended. (#​4291)
SECURITY ADVISORIES:
  • Previous releases in the v1.12 series could read an arbitrary file during certain git operations via a maliciously crafted URL (#​4293)

Full Changelog: opentofu/opentofu@v1.12.2...v1.12.3


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/opentofu-1.x branch from 6b8a58a to 4902bf7 Compare July 12, 2026 18:34
@renovate renovate Bot changed the title Update dependency opentofu to v1.12.3 Update dependency opentofu to v1.12.4 Jul 13, 2026
@renovate
renovate Bot force-pushed the renovate/opentofu-1.x branch 2 times, most recently from 5848bcc to 5391408 Compare July 17, 2026 00:54
@renovate renovate Bot changed the title Update dependency opentofu to v1.12.4 Update dependency opentofu to v1.12.5 Jul 21, 2026
@renovate
renovate Bot force-pushed the renovate/opentofu-1.x branch from 5391408 to 2737c4c Compare July 21, 2026 18:48
@renovate
renovate Bot force-pushed the renovate/opentofu-1.x branch from 2737c4c to 02a2d88 Compare July 30, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants