Harness Release Notes Summaries
Explore release notes from the last 30 days across the Harness Platform and modules.
INFO
Please review the full module release notes by selecting a module in the sidebar, or using the View full release notes links beside each module summary.
Looking for available features rather than recent changes? You can explore Beta and Limited GA features across Harness modules on the Feature Availability page.
Platform Release Notes
Platform
View full release notes →Access Control & Permissions
- Added the ability to clone existing Access Control roles directly from the UI to simplify role creation.
- Added the ability to clone existing Resource Groups directly from the UI for faster access control configuration.
- Improved SCIM user group provisioning to prevent identifier collisions and ensure accurate group memberships.
Secrets & Notifications
- Added cross-project access for Google Cloud Secret Manager secrets using dynamic project ID expressions.
- Fixed an issue where editing notification rules displayed incorrect identifiers for project-scoped service accounts.
Delegate
View full release notes →Security & Dependency Updates
- Updated third-party dependencies, including Jackson, gRPC, and MongoDB drivers, to address known security vulnerabilities.
- Updated the bundled Source Code Management (SCM) client tool to the latest version to resolve security vulnerabilities.
- Resolved multiple security vulnerabilities across delegate core libraries and packages.
Deployment Improvements
- Fixed an issue in Helm blue-green deployments where incorrect step outputs caused subsequent selector swaps to fail.
- Ensured Horizontal Pod Autoscalers (HPA) and Pod Disruption Budgets (PDB) are properly re-created during the blue-green scale-up step.
- Updated benign Helm standard error messages, such as missing release warnings on fresh installs, to log as warnings instead of errors.
Pipeline & Integration Fixes
- Fixed an issue where dot-notation variables were created as flat keys instead of properly nested objects when generating new YAML or JSON release repo files.
- Improved error handling for the Jenkins build trigger to show a clear error message when expected response headers are missing.
Code Repository
View full release notes →Pull Request & Code Review
- Added support for ordering reviewers by status to easily track review progress.
- Added the ability to edit files directly from the pull request view based on user permissions.
- Added support for pasting images directly into pull request comment threads.
- Added a button to quickly jump to the top of file diffs when reviewing changes.
- Fixed an issue where opening a pull request from the review requested list redirected to the repository homepage.
- Fixed broken branch links on pull request pages that previously led to 404 errors.
- Fixed pull request label filtering so key-value searches return the correct matching results.
Branch & Merge Management
- Added a branch rule to block merges when the target branch is out of date, supporting automatic rebase during merge.
- Fixed an issue where the auto-merge menu displayed merge strategies that were disabled for the repository.
- Fixed a visual issue where branch search highlighting was displayed incorrectly.
Repository & Tag Management
- Fixed an issue where tags from a previous repository remained visible after switching repositories.
- Fixed an issue where tag comparison incorrectly returned a 404 error or reported no differences.
- Improved error handling and feedback when contributor permissions are missing during Helm changes.
AI for DevOps & Automation
Continuous Integration
View full release notes →Build Performance & Cloud Infrastructure
- Introduced global queuing for macOS builds on Harness Cloud to improve capacity utilization and minimize stockout failures.
- Added stage-level configuration to reduce initialization time for stages with large step definitions.
- Optimized Build and Push step performance on Kubernetes by eliminating intermediate image serialization.
- Added Windows Server 2025 support across Cache, GCS, S3, Artifactory, and Buildx plugins.
Container & Image Builds
- Added custom CA certificate and proxy support to Docker and Buildx plugins for secure builds behind TLS-intercepting egress proxies.
- Fixed an issue where container image builds failed due to overly strict symbolic link validation.
- Resolved intermittent image pull failures affecting BuildKit-based build and push steps.
- Surfaced actionable guidance when builds encounter public container registry rate limits on cloud runners.
- Upgraded Git, Docker, Buildx, and Kaniko plugins with the latest reliability and stability improvements.
Pipeline Security & Execution
- Resolved secret resolution failures in pipelines operating behind egress proxies.
- Fixed an issue where secrets failed to resolve during database schema clone steps on Kubernetes infrastructure.
- Fixed an issue where pipeline sequence ID expressions evaluated to null during manual pipeline runs.
- Fixed an issue where security drift monitoring tools blocked Git plugin execution in database workflows.
- Upgraded internal CLI components to remediate known security vulnerabilities.
Infrastructure as Code Management
View full release notes →Workspace & Cost Management
- Redesigned the Workspace Overview tab to surface live cloud costs, optimization recommendations, resource counts, and recent activity at a glance.
- Introduced Ephemeral Workspaces to automatically tear down infrastructure and optionally delete workspace records upon expiration.
AWS CDK Support
- Added Drift and Destroy pipeline steps to identify out-of-band CloudFormation changes and safely tear down managed stacks.
- Added an Approval step to CDK pipelines to gate deployments on manual reviews of diff outputs.
- Expanded CDK language support to include Java, JavaScript, and Go, in addition to Python and TypeScript.
Governance & Security
- Introduced module lifecycle rules in the Module Registry to automatically classify module versions as Supported, Update Required, or Deprecated.
- Resolved provisioner download failures behind TLS-intercepting proxies by adding support for custom corporate CA certificate bundles.
Artifact Registry
View full release notes →General Updates
- Refer to the Artifact Registry Release Notes page for detailed updates documented for this period.
AI for Testing & Resilience
Feature Management & Experimentation
View full release notes →General Updates
- Refer to the Feature Management & Experimentation release notes page for updates documented during this period.
Chaos Engineering
View full release notes →Load Testing
- Added an Advanced Configuration section to customize worker pod resources and define execution plane pod cleanup policies.
- Enabled pulling load test images directly from your own image registry.
- Resolved image registry connection and retrieval issues during load test executions.
- Fixed a crash that occurred when selecting a service within load test template steps.
- Added controls to manage the visibility of risk services in load tests.
- Improved the overall reliability of load test configuration and execution.
Execution Tracking & Visibility
- Introduced a dedicated Executions tab in Chaos and Load Testing modules to view all experiment and test runs in a single place.
- Added visibility into experiment executions and execution node details on a per-service basis.
Templates & Step Configuration
- Fixed an issue where fault, probe, and action step templates failed to display variables and runtime inputs at account and organization scopes.
- Resolved synchronization issues with action and probe templates.
Pipeline & Infrastructure Scanning
- Refreshed the pipeline scan interface with an on-demand scan action and an enhanced details column.
- Hardened pipeline and infrastructure scans for improved reliability.
- Fixed sorting behavior when listing scan results.
Security & Platform Reliability
- Resolved gRPC package vulnerabilities across chaos engineering components.
- Updated infrastructure and database dependencies to remediate security vulnerabilities.
- Updated chaos runtime and discovery collector components for improved system stability.
Last updated Jul 23, 2026
Incident Investigation Improvements
- Enriched Root Cause Analysis investigations by allowing the AI Investigator to automatically incorporate outputs from custom runbooks, worker agents, and pipeline executions.
AI for Security & Compliance
Security Testing Orchestration
View full release notes →Integrations & Collaboration
- Added GitLab and Bitbucket support when creating pull requests directly from AI-based remediations.
- Enhanced Jira integration to automatically include vulnerability summaries and occurrence details in created tickets to streamline triage and prioritization.
Vulnerability & Exemption Management
- Added support for submitting bulk exemption requests across multiple vulnerabilities with a shared scope, duration, and reason.
- Fixed an issue where remediated vulnerabilities were not displayed on the Vulnerabilities tab unless resolved across all targets in a pipeline execution.
User Interface Improvements
- Fixed an issue where code snippets in the issue panel rendered with unreadable yellow highlighting.
Supply Chain Security
View full release notes →Access Control & Governance
- Added support for Resource Groups to manage access permissions for Supply Chain Security resources across Account, Organization, and Project levels.
- Resolved an issue where Repository Security Posture Management APIs did not consistently enforce role-based access control across all scopes.
Integrations & Artifact Security
- Added GitLab CI/CD integration to generate and ingest SBOMs, enforce security policies, verify SLSA provenance, and sign or verify software artifacts within pipelines.
- Made Artifact Registry integration for artifact signing and verification steps generally available.
SBOM & Policy Management
- Introduced AI Bill of Materials (AIBOM) support in CycloneDX format to provide visibility into AI components such as models, datasets, agents, and frameworks.
- Resolved an issue where SBOM processing failed to extract tool metadata from CycloneDX SBOMs generated by JFrog Xray.
- Fixed an issue where intermittent errors during SBOM policy enforcement and SLSA verification caused pipeline executions to fail.
AI for Cost & Optimization
Cloud Cost Management
View full release notes →AI Cost Management & Tracing
- View token usage alongside spend in AI Perspectives across Cost Explorer, perspective details, and reports.
- Analyze AI service traces with new trend comparisons and cost distribution histograms.
- Connect and manage Cursor accounts alongside OpenAI and Anthropic integrations.
- Spot high-cost AI operations faster with service traces sorted by cost by default.
- Drill down into AI Perspectives by provider, sub-provider, account ID, model, and token type when grouped by principal.
- Use context-aware AI chat quick actions that adapt terminology based on your current view.
Dashboards & Cost Analytics
- Filter Overview page tiles by cost category to focus on specific spend areas.
- Monitor spending health with enhanced time series charts for anomalies and clearer budget widgets.
- Fixed an issue where anomaly counts disappeared in Cost Explorer after updating cost preferences.
- Fixed an issue where clicking chart elements did not consistently apply filters across different grouping columns.
- Fixed an issue where contains filters on derived metrics returned incomplete results.
- Export full Perspective datasets instead of only the rows displayed on the current page.
- Resolved an issue where GCP Kubernetes nodes showed $0 costs in Perspectives.
Cost Optimization & Recommendations
- Track, review, and approve RDS Database Savings Plan purchases in Commitment Orchestration.
- Fixed an issue where manually applied recommendations continued to show an inferred-as-applied banner.
- Resolved an issue where manually applied Kubernetes workload recommendations remained stuck in a pending evaluation state.
- Fixed an issue where auto-inferred Kubernetes node pool recommendations displayed empty configuration details.
Cluster Orchestration & AutoStopping
- Track schedule states and countdowns to the next schedule window using live status badges.
- Fixed an issue where editing an RDS AutoStopping rule did not retain the previously selected proxy.
- Create tag-based AutoStopping rules using tag values that contain special characters.
AI DLC Insights
View full release notes →General Updates
- Refer to the dedicated AI DLC Insights release notes page for detailed updates documented during this period.