Notes
🛡️ Security notices
- Bump dependency newrelic/nrjmx to v2.14.0 in #2336 to address CVE-2026-54399 and CVE-2026-54428
- Bump dependency newrelic/nri-prometheus to v2.30.4 in #2335
- Bump google.golang.org/grpc from 1.83.1 to 1.83.2 in #2342 to address CVE-2026-84445
- Bump containerd to v1.7.35 in #2340 to address CVE-2026-53495
- Bump dependency newrelic/nri-flex to v1.18.13 in #2343 to address CVE-2026-56855 and CVE-2026-78662
🐞 Bug fixes
- replace deprecated MemoryLimit with MemoryMax for systemd >=231 in #2337
- add groupfs check for tmp file ownership in #2345
Support statement:
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent.
We recommend updating to the latest agent version as soon as it's available. If you can't upgrade to the latest version, update your agents to a version no more than 90 days old. Read more about keeping agents up to date.
See the New Relic Infrastructure agent EOL policy for information about agent releases and support dates.
メモ
🛡️ セキュリティアップデート
- #2328でセキュリティ脆弱性CVE-2026-84304を解決するために、
google.golang.org/grpcを1.83.1に更新しました
🐞 バグ修正
- 安全なディレクトリチェック時の許可されたマウントパスの検証 #2325
サポートステートメント:
エージェントの新しいバージョンがリリースされました。標準的な手順に従って、infrastructureエージェントをアップデートしてください。
最新のエージェントバージョンが利用可能になり次第、アップデートすることをお勧めします。最新バージョンにアップグレードできない場合は、エージェントを90日以内のバージョンにアップデートしてください。エージェントを最新状態で維持するについて詳しくお読みください。
エージェントのリリースとサポート日に関する情報については、New Relic InfrastructureエージェントのEOLポリシーをご覧ください。
メモ
🛡️ セキュリティ通知
flex#2323 のセキュリティ脆弱性 CVE-2026-56854 を解決するために、 をバージョンv1.18.12に更新しました。
サポートステートメント:
エージェントの新しいバージョンがリリースされました。標準的な手順に従って、infrastructureエージェントをアップデートしてください。
最新のエージェントバージョンが利用可能になり次第、アップデートすることをお勧めします。最新バージョンにアップグレードできない場合は、エージェントを90日以内のバージョンにアップデートしてください。エージェントを最新状態で維持するについて詳しくお読みください。
エージェントのリリースとサポート日に関する情報については、New Relic InfrastructureエージェントのEOLポリシーをご覧ください。
メモ
🛡️ セキュリティ通知
- #2321 で、セキュリティ CVE-2026-56854 を修正するために http://golang.org/x/crypto を v0.55.0 に更新しました
🐞 バグ修正
- #2312 で、Queue Length を取得するように WMI フォールバックを拡張しました
- #2307 で、SCM の競合時に Start-Service を再試行し、開始前にライセンスキーを検証するようにしました
サポートステートメント:
エージェントの新しいバージョンがリリースされました。標準的な手順に従って、infrastructureエージェントをアップデートしてください。
最新のエージェントバージョンが利用可能になり次第、アップデートすることをお勧めします。最新バージョンにアップグレードできない場合は、エージェントを90日以内のバージョンにアップデートしてください。エージェントを最新状態で維持するについて詳しくお読みください。
エージェントのリリースとサポート日に関する情報については、New Relic InfrastructureエージェントのEOLポリシーをご覧ください。
エージェントの新しいバージョンがリリースされました。標準的な手順に従って、infrastructureエージェントをアップデートしてください。New Relicでは、エージェントを定期的に、少なくとも3か月ごとにアップグレードすることを推奨します。本リリースより、サポートされる最も古いバージョンはinfrastructureエージェント 1.65.3です。
かわった
Notes
🛡️ Security notices
- Fixed a remote code execution vulnerability caused by path traversal in #2292
- Added explicit permissions to GitHub Actions workflows to reduce token scope in #2232
- Bumped google.golang.org/grpc from 1.79.3 to 1.82.1 in go.mod in #2296
- Bumped embedded OHI versions (nri-docker, nri-flex) to fix known CVEs in #2302
- bump vulnerable dependencies flagged by Trivy scan in #2301
🚀 Enhancements
- Added support for ignoring default integration locations via disable_plugin_default_dir_scan in #2290
- Made environment variables used by Agent Control public in #2293
- Added OCI tag support to match AWS tags (Phase 1 + Phase 2) in #2295
- Enabled NRIA_DISABLE_PLUGIN_DEFAULT_DIR_SCAN by default for Agent-Control-managed agents in #2300
- Removed nri-flex from agent-control artifacts in #2291
🐞 Bug fixes
- Restored missing job permissions for release and canary workflows in #2303
Support statement:
A new version of the agent has been released. Follow standard procedures to update the Infrastructure agent.
We recommend updating to the latest agent version as soon as it's available. If you can't upgrade to the latest version, update your agents to a version no more than 90 days old. Read more about keeping agents up to date.
See the New Relic Infrastructure agent EOL policy for information about agent releases and support dates.