Atlantis Updates & Release Notes

Follow

12 updates curated from 1 source by the Releasebot Team. Last updated: Aug 21, 2026

Get this feed:
  • Aug 20, 2026
    • Date parsed from source:
      Aug 20, 2026
    • First seen by Releasebot:
      Aug 21, 2026
    Atlantis logo

    Atlantis

    v0.47.1

    Atlantis fixes a security issue preventing pull request input from reaching a shell.

    What's Changed

    Security changes

    • fix: prevent pull request input from reaching a shell (GHSA-rjh2-4xgw-p2hj) by @jamengual in #6792

    Full Changelog: v0.47.0...v0.47.1

    Thanks to @krewenki for the security review of this fix, and to @pseudomorph for reviewing.

    Original source
  • Aug 18, 2026
    • Date parsed from source:
      Aug 18, 2026
    • First seen by Releasebot:
      Aug 19, 2026
    Atlantis logo

    Atlantis

    v0.47.0

    Atlantis releases v0.47.0 with new drift API and plan storage options, stronger GitHub and webhook handling, improved lock and apply workflows, plus multiple security, dependency, and documentation updates.

    What's Changed

    Exciting New Features πŸŽ‰

    • feat(#303): include commit SHA in working directory lock errors by @ShankyJS in #6646
    • feat: Expose plan_output on POST /api/drift/detect and clarify drift API workflow docs by @albertorm95 in #6709
    • feat: add --plan-store-dir to decouple plan file storage from data-dir by @sakkiii in #6636

    Provider GitHub

    • fix: handle malformed plans and VCS transport failures by @chenrui333 in #6672
    • fix: make GitHub token rotation concurrency-safe by @chenrui333 in #6670

    Bug fixes πŸ›

    • fix: wire SkipPRRequirements for no-PR API and drift remediation contexts by @albertorm95 in #6664
    • fix: exempt readiness probe from web authentication by @chenrui333 in #6669
    • fix: avoid nil terraform client dereference in NewServer by @Atul-Koundal in #6697
    • fix: accept 2xx responses as success in HTTP webhooks by @gautamrizwani in #6648
    • fix: only require a managed plan file for managed apply workflows by @jamengual in #6781
    • fix: scope misspell "did you mean" check to default executable name by @npwolf in #6690
    • fix: NoOpLocker.Unlock returns non-nil lock, breaking DELETE /locks error handling by @ricardbejarano in #6775

    Security changes

    • fix(deps): update module golang.org/x/text to v0.39.0 [security] (main) by @renovate[bot] in #6687
    • chore(deps): update module github.com/klauspost/compress to v1.18.7 [security] (main) by @renovate[bot] in #6706
    • chore(deps): update module golang.org/x/mod to v0.40.0 [security] (main) by @renovate[bot] in #6771
    • chore(deps): update dependency mermaid to v11.16.1 [security] (main) by @renovate[bot] in #6744

    Documentation

    • docs: Promote Terraform distribution agnosticism in Terragrunt example by @lachlankidson in #6620
    • chore(deps): Bump dompurify from 3.4.11 to 3.4.12 by @dependabot[bot] in #6688
    • chore(deps): update lodash-es to 4.18.1 by @chenrui333 in #6673

    Dependencies

    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to e7292be in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6702
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to bb153df in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6705
    • chore(deps): update golang:1.26.5 docker digest to 3aff665 in testing/dockerfile (main) by @renovate[bot] in #6716
    • chore(deps): update redis:8.6-alpine docker digest to cd218f4 in docker-compose.yml (main) by @renovate[bot] in #6722
    • fix(deps): update github.com/hashicorp/terraform-config-inspect digest to 2fb54c2 in go.mod (main) by @renovate[bot] in #6730
    • chore(deps): update dependency opentofu/opentofu to v1.12.5 in dockerfile (main) by @renovate[bot] in #6735
    • chore(deps): update step-security/harden-runner digest to b09bb98 in .github/workflows/scorecard.yml (main) by @renovate[bot] in #6757
    • fix(deps): update module github.com/go-playground/validator/v10 to v10.30.3 in go.mod (main) by @renovate[bot] in #6770
    • fix(deps): update module github.com/hashicorp/hc-install to v0.9.5 in go.mod (main) by @renovate[bot] in #6774
    • chore(deps): update docker/dockerfile:1 docker digest to ecfaec9 in dockerfile (main) by @renovate[bot] in #6780

    Other Changes πŸ”„

    • chore(deps): bump Alpine curl to 8.20.0-r0 by @albertorm95 in #6665
    • fix: bump alpine base image to 3.23.5 to update libssl3/libcrypto3 by @albertorm95 in #6708

    New Contributors

    • @ShankyJS made their first contribution in #6646
    • @sakkiii made their first contribution in #6636
    • @gautamrizwani made their first contribution in #6648

    Full Changelog: v0.46.0...v0.47.0

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Atlantis and hundreds of other software products.

    Create account
  • Jun 30, 2026
    • Date parsed from source:
      Jun 30, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.46.0

    Atlantis adds OpenTofu .tofu and .tofu.json support, expands project discovery and autoplan coverage, and tightens plan and apply safety. It also broadens E2E test coverage, improves CI and coverage reporting, and adds automated top-issue ranking for maintainers.

    Highlights

    OpenTofu .tofu support: Atlantis now detects OpenTofu versions from .tofu and .tofu.json files, includes those files in default autoplan and project discovery behavior, and detects Terraform Cloud/Enterprise workspace configuration from .tf.json, .tofu, and .tofu.json projects.

    Broader core workflow coverage: The E2E harness now activates expanded fixtures from runatlantis/atlantis-tests#21001, covering multi-project targeting, autodiscovery, configured JSON projects, custom workflow environment behavior, and long-output status contexts.

    Safer plan/apply behavior: This release hardens apply validation against stale head/base plan state, preserves on_apply locks during plan cleanup, and fixes /api/plan with policy checks enabled while preserving per-project /api/apply behavior.

    Project Health

    Top-Ranking Atlantis Issues πŸ“Š Maintainers and contributors can now use #6608 to see open Atlantis issues ranked by community thumbs-up reactions. The ranking is a signal for prioritization and contribution, not a roadmap commitment or acceptance guarantee.

    Atlantis now uploads Go coverage to GitHub Code Quality, lints the separate e2e Go module, and has automated top-issue ranking to make maintenance work more visible.

    We welcome contributors across bug reports, focused fixes, documentation improvements, issue reproduction, and issue moderation/triage.

    Call For Adopters

    If your organization uses Atlantis and can share a sanitized setup or adoption note, runatlantis/examples is a good place to contribute it. Public examples help users learn from real deployments, help the project document its ecosystem, and can become future candidates for atlantis-tests fixture coverage.

    What's Next

    We are also looking at flag lifecycle improvements so Atlantis has a clearer path for introducing, documenting, deprecating, and eventually removing server flags.

    What's Changed

    Exciting New Features πŸŽ‰

    • feat(e2e): activate new fixture coverage from atlantis-tests#21001 by @chenrui333 in #6601
    • feat: support OpenTofu .tofu/.tofu.json version auto-detection by @chenrui333 in #6600
    • feat: workspace detection for .tofu/.tofu.json, shared project indicators by @chenrui333 in #6603
    • Provider Bitbucket
    • fix: validate current head and base plan state by @chenrui333 in #6605

    Bug fixes πŸ›

    • fix: preserve on_apply locks during plan cleanup by @chenrui333 in #6606
    • fix: normalize TestExecute_Flags path assertions by @Atul-Koundal in #6612
    • fix: POST /api/plan panics when ATLANTIS_ENABLE_POLICY_CHECKS=true by @Abzaek in #6484

    Dependencies

    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to aa0051c in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6607

    Other Changes πŸ”„

    • ci(e2e): add lint coverage and harden cleanup safety by @chenrui333 in #6602
    • ci: upload Go coverage to GitHub Code Quality by @chenrui333 in #6604
    • ci: add top-ranking issues automation by @chenrui333 in #6610
    • test: close BoltDB instances in locks controller tests by @Atul-Koundal in #6611
    • test: add on_apply lock preservation scenario by @chenrui333 in #6609

    New Contributors

    @Abzaek made their first contribution in #6484

    Full Changelog: v0.45.0...v0.46.0

    Original source
  • Jun 28, 2026
    • Date parsed from source:
      Jun 28, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.45.0

    Atlantis releases alpha drift detection and remediation APIs, plus localization, automerge, and notification upgrades. This minor update also improves Slack and GitHub handling, streamlines project detection, and includes several provider, execution, and security fixes.

    This minor release adds alpha drift detection and remediation APIs, new localization and automerge controls, notification improvements, and several provider and execution fixes.

    Highlights

    • Added alpha drift detection, status, remediation, remediation history, and drift webhook APIs. These APIs are alpha and their request/response behavior may change in future releases. (#6360)
    • Added runtime localization support with built-in English and Spanish catalogs plus custom YAML overrides. (#6506)
    • Added automerge controls for default merge method and disabling automerge labels. (#6573, #6593)
    • Improved GitHub team allowlists to honor team hierarchy. (#6365)

    Alpha: Drift detection and remediation APIs

    • Added alpha drift detection APIs, drift status API, drift remediation API, and remediation history/result read endpoints. (#6360)
    • Added drift webhook notifications, including Slack and HTTP webhook support. (#6360)
    • Added --enable-drift-detection for drift detection/status/history behavior.
    • Added --enable-drift-remediation for destructive remediation apply.
    • Drift APIs require API authentication with X-Atlantis-Token and repository allowlist authorization.
    • Remediation action:"apply" requires cached positive drift with has_drift:true for the same repo/ref/base branch/project/path/workspace.
    • Drift API inputs include ref, path, workspace, repository, and allowlist safety validation.
    • Operators should test carefully before production use, especially with hooks, policy checks, allowlists, multi-project repos, and custom workflows.

    Features

    • Added --language and --language-config-file to localize Atlantis pull request comments and override language catalog strings. (#6506)
    • Added --automerge-method to set a default merge method for automerging, currently implemented for GitHub. (#6573)
    • Added --disable-automerge-label to disable automerge label behavior. (#6593)
    • Extended autodiscover.ignore_paths to targeted -d commands. (#6466)
    • Streamed project failure text to the job page. (#6414)

    Fixes

    • Scoped regex project plans correctly when --restrict-file-list is enabled. (#6598)
    • Detected OpenTofu versions using the project distribution. (#6597)
    • Re-downloaded Terraform/OpenTofu binaries when the existing binary appears invalid. (#6454)
    • Unified Terraform/Terragrunt project directory detection, including .tf, .tf.json, and terragrunt.hcl indicators. (#6455)
    • Hardened path handling for CWE-22 path-expression issues. (#6254)
    • Preserved Docker healthcheck port fallback behavior. (#6588)
    • Clarified status-update logging when no URL is available. (#6595)

    Provider fixes

    • Bitbucket Cloud: validate pagination next URLs before following them. (#6260)
    • GitHub: only apply GitHub App checkout behavior to GitHub repositories. (#6119)
    • GitHub: support child-team inheritance for GH_TEAM_ALLOWLIST. (#6365)

    Notifications and webhooks

    • Slack notifications now show the pull request head branch instead of the base branch. (#6316)
    • Slack notifications can include the pull request description. (#6540)
    • Documentation now clarifies Slack payload fields and GitHub team hierarchy behavior. (#6596)

    New Contributors

    • @hussein-mimi made their first contribution in #6365
    • @JFryy made their first contribution in #6072
    • @ronaldmiranda made their first contribution in #6573
    • @emanuelbesliu made their first contribution in #6466
    • @rym-dd made their first contribution in #6540
    • @eamonryan made their first contribution in #6414
    • @kiwibel made their first contribution in #6316
    • @zonorti made their first contribution in #6119

    Full Changelog: v0.44.1...v0.45.0

    Original source
  • Jun 26, 2026
    • Date parsed from source:
      Jun 26, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.44.1

    Atlantis ships a patch release with safer apply behavior, more accurate GitHub and GitLab support, and better plan and output rendering. It also refreshes the runtime base to Debian 13 Trixie and updates key dependencies, with multiple correctness and documentation fixes.

    This patch release focuses on provider correctness, safer apply behavior, plan/output rendering fixes, and refreshed runtime foundations.

    Highlights

    Broader GitHub Enterprise support: existing GitHub Enterprise Server behavior is preserved, and GitHub Enterprise Cloud *.ghe.com tenants now use the correct REST and GraphQL API endpoint patterns.

    The Debian-based Atlantis image now uses Debian 13 Trixie with refreshed pinned system packages including curl, git, OpenSSH, GnuPG, OpenSSL, and libcap.

    Apply safety is improved by failing closed when apply-lock backends cannot be reached and by correctly evaluating pull request status for API apply requirements.

    Mergeability and status behavior is more accurate across GitHub, GitLab, GitHub App checkout flows, and no-change apply statuses.

    Terraform/OpenTofu plan output rendering now handles to forget, multi-unit summaries, heredoc/multiline-string diffs, and very long single-line command output more reliably.

    Provider fixes

    • GitHub: support GitHub Enterprise Cloud *.ghe.com API URL patterns. (#6339)
    • GitHub: truncate status contexts to GitHub's 255-character limit. (#6541)
    • GitHub App: skip unused source remotes on fork-safe checkout paths. (#6568)
    • GitLab: filter mergeability status checks by the merge request ref/SHA. (#6557)
    • GitLab: scope project apply mergeability to the project being applied. (#6543)
    • Azure DevOps: guard nil pull request status values while parsing pull events. (#6496)
    • Gitea: avoid nil response dereferences while logging API errors. (#6442)

    Apply, plan, and output fixes

    • Fail closed when the apply lock backend cannot be reached instead of allowing applies to proceed on lock-check errors. (#6533)
    • Populate pull request status before API apply requirement evaluation so approved and mergeable are enforced correctly. (#6535)
    • Show no-change plans as up to date in apply statuses instead of implying they were applied. (#6498)
    • Preserve and aggregate to forget plan statistics. (#6570)
    • Aggregate multi-unit plan summaries correctly. (#6490)
    • Remove stale .tfplan files when refreshing a working directory to a new ref. (#6358)
    • Skip non-git directories when finding pending plans. (#6453)
    • Preserve command output lines longer than 64 KiB. (#6544)
    • Color changed lines inside heredoc and multiline-string diffs. (#6561)
    • Fix a divergence check order issue. (#6452)

    Runtime and maintenance

    • Updated the Debian image base to Debian 13 Trixie. (#6572)
    • Updated OpenTofu and CI/test image digests. (#6549, #6580, #6581)
    • Removed the obsolete check-lint Makefile target. (#6554)
    • Pinned scorecard-related Go and npm commands for OpenSSF compliance. (#6480)
    • Updated website and CI dependencies, including security-related frontend dependency updates. (#6563, #6564, #6565, #6566)

    Documentation

    • Clarified GitHub App merge checkout behavior. (#6577)
    • Clarified recent status, locking, VCS, pending-plan, and output-handling behavior. (#6578, #6582)

    New Contributors

    • @lachlankidson made their first contribution in #6572
    • @Atul-Koundal made their first contribution in #6570
    • @gBarczyszyn made their first contribution in #6535
    • @vklindukh made their first contribution in #6568
    • @nburns made their first contribution in #6498
    • @Cesarsk made their first contribution in #6543
    • @SAY-5 made their first contribution in #6496
    • @cpaulik made their first contribution in #6561
    • @SamuelMolling made their first contribution in #6490
    • @the-nando made their first contribution in #6452
    • @adnankobir made their first contribution in #6339

    Full Changelog: v0.44.0...v0.44.1

    Original source
  • Similar to Atlantis with recent updates:

  • Jun 10, 2026
    • Date parsed from source:
      Jun 10, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.44.0

    Atlantis releases sticky policy approvals, Redis cluster support, and a merge fix that uses leader election to unblock parallel plans. This update also includes provider GitHub improvements, bug fixes, security updates, and refreshed documentation.

    What's Changed

    Exciting New Features πŸŽ‰

    • feat: sticky policy approvals by @pseudomorph in #6271
    • feat: Redis cluster support. by @daanvinken in #6295

    Provider GitHub

    • fix(deps): bump go-github to v88 and migrate to options-pattern constructor by @jamengual in #6537

    Bug fixes πŸ›

    • fix: Only check the remote branch on merge strategy by @lukemassa in #6177

    Security changes

    • chore(deps): update module golang.org/x/net to v0.53.0 [security] (main) by @renovate[bot] in #6457
    • chore(deps): update dependency mermaid to v11.15.0 [security] (main) by @renovate[bot] in #6462
    • fix(deps): update module github.com/slack-go/slack to v0.23.1 [security] (main) by @renovate[bot] in #6477
    • chore(deps): update module golang.org/x/crypto to v0.52.0 [security] (main) by @renovate[bot] in #6500
    • chore(deps): update module golang.org/x/sys to v0.44.0 [security] (main) by @renovate[bot] in #6502
    • chore(deps): update module golang.org/x/net to v0.55.0 [security] (main) by @renovate[bot] in #6501

    Documentation

    • feat: add PROJECT_NAME as a usable environment variable in pre and post hooks by @nvanheuverzwijn in #6438
    • chore: Update website footer with LF copyright wording by @lukemassa in #6456
    • docs: Document in which time interval metrics are reported by @IchordeDionysos in #6308
    • chore(deps): update dependency vue to v3.5.34 in package.json (main) by @renovate[bot] in #6474
    • chore: Clarify role of AI tooling in PRs by @lukemassa in #6465
    • chore(deps): Bump uuid from 11.1.0 to 14.0.0 by @dependabot[bot] in #6505
    • docs: document cancel command in allow-commands and atlantis help by @jamengual in #6536
    • chore(deps): update dependency markdownlint-cli to v0.48.0 in package.json (main) by @renovate[bot] in #6513

    Dependencies

    • chore(deps): update ghcr.io/runatlantis/atlantis:latest docker digest to eb08c98 in dockerfile.dev (main) by @renovate[bot] in #6450
    • chore(deps): update debian:12.13-slim docker digest to 67b30a6 in dockerfile (main) by @renovate[bot] in #6458
    • chore(deps): update redis:8.6-alpine docker digest to d146f83 in docker-compose.yml (main) by @renovate[bot] in #6471
    • chore(deps): update ngrok/ngrok:latest docker digest to 1d5daa8 in docker-compose.yml (main) by @renovate[bot] in #6485
    • chore(deps): update dependency opentofu/opentofu to v1.12.0 in dockerfile (main) by @renovate[bot] in #6486
    • chore(deps): update docker/dockerfile:1 docker digest to 87999aa in dockerfile (main) by @renovate[bot] in #6509

    Other Changes πŸ”„

    • fix: use leader election in MergeAgain to unblock parallel plans when PR is behind base by @josepmedialdea in #6470
    • chore: Remove unnecessary utility SlicesContains by @lukemassa in #6508

    New Contributors

    • @IchordeDionysos made their first contribution in #6308
    • @josepmedialdea made their first contribution in #6470
    • @daanvinken made their first contribution in #6295

    Full Changelog: v0.43.0...v0.44.0

    Original source
  • May 5, 2026
    • Date parsed from source:
      May 5, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.43.0

    Atlantis releases v0.43.0 with broader VCS support, stronger security, and a long list of bug fixes. It improves Azure DevOps, GitHub, GitLab, and Gitea behavior, tightens comment parsing, and adds docs updates plus dependency refreshes.

    What's Changed

    Provider AzureDevops

    • fix: webhook authentication for Azure DevOps Server by @Zamiell in #6159

    Provider GitHub

    • fix(github): Fall back to git blobs API for large files in GetFileContent by @jayceebernardino in #6401

    Provider GitLab

    • fix: support GitLab hosted under a URL subpath by @philslab-ninja in #6406
    • fix(gitlab): prevent PullIsMergeable from self-blocking on Atlantis commit statuses by @gian25-work in #6369

    Bug fixes πŸ›

    • fix(events): make undiverged honor module autoplanning by @krewenki in #6428
    • fix: Prevent infinite Gitea pagination loops by @shblue21 in #6032
    • fix: trigger PR event handling on PR updates for Gitea/Forgejo by @kfkonrad in #6178
    • fix: prevent diffKeywordRegex from falsely matching YAML key=value list items in heredocs by @GMartinez-Sisti in #6422
    • fix: cancellation bug for parallel invocations without execution_order and a larger amount of tasks than the poolSize by @ramonvermeulen in #6215
    • fix: respect autodiscover.ignore_paths during apply-all by @jholm117 in #6397
    • fix(events): prevent autoplan module recursion cycles by @krewenki in #6025
    • fix: Reorder autodiscover logic by @lukemassa in #6240
    • fix: include error values in init_step_runner log messages by @kuishou68 in #6382
    • fix: use read lock for clone reuse check to unblock parallel plans by @matthewmrichter in #6376
    • fix(kustomize): pin image tag to v0.42.0 instead of latest by @nicknikolakakis in #6400

    Security changes

    • fix: harden VCS comment parsing against injection with configurable blocked-args by @Copilot in #6225
    • build(docker): strip file capabilities from image filesystem by @milindc2031 in #6363

    Documentation

    • docs: add AI_USAGE_POLICY.md by @Copilot in #6347
    • docs: fix --emoji-reaction supported VCS list (remove Azure DevOps, add Gitea) by @akihiro17 in #6407
    • docs: update Azure DevOps allowlist format for visualstudio.com URLs by @nimro in #6083
    • docs: Add CloudScript to adopters list by @xcloudscript in #6411

    Dependencies

    • chore(deps): update node.js to v24.15.0 in .node-version (main) by @renovate[bot] in #6423
    • chore(deps): Bump dompurify from 3.2.6 to 3.4.1 by @dependabot[bot] in #6420
    • chore(deps-dev): Bump postcss from 8.5.8 to 8.5.12 by @dependabot[bot] in #6432
    • chore(deps): update ghcr.io/runatlantis/atlantis:latest docker digest to a8873d7 in dockerfile.dev (main) by @renovate[bot] in #6418
    • chore(deps): update debian:12.13-slim docker digest to f9c6a2f in dockerfile (main) by @renovate[bot] in #6421
    • chore(deps): update ngrok/ngrok:latest docker digest to 013f046 in docker-compose.yml (main) by @renovate[bot] in #6424
    • chore(deps): update alpine docker tag to v3.23.4 in dockerfile (main) by @renovate[bot] in #6429
    • chore(deps): update ngrok/ngrok:latest docker digest to f737dcc in docker-compose.yml (main) by @renovate[bot] in #6434
    • chore(deps): update ngrok/ngrok:latest docker digest to 6ead432 in docker-compose.yml (main) by @renovate[bot] in #6436
    • chore(deps): update dependency hashicorp/terraform to v1.14.9 in testdrive/utils.go (main) by @renovate[bot] in #6446

    Other Changes

    • docs: Add CloudScript to adopters list by @xcloudscript in #6411

    New Contributors

    • @xcloudscript made their first contribution in #6411
    • @shblue21 made their first contribution in #6032
    • @jayceebernardino made their first contribution in #6401
    • @kuishou68 made their first contribution in #6382
    • @kfkonrad made their first contribution in #6178
    • @ramonvermeulen made their first contribution in #6215
    • @matthewmrichter made their first contribution in #6376
    • @nicknikolakakis made their first contribution in #6400
    • @milindc2031 made their first contribution in #6363
    • @jholm117 made their first contribution in #6397
    • @philslab-ninja made their first contribution in #6406
    • @gian25-work made their first contribution in #6369
    • @krewenki made their first contribution in #6428
    • @Zamiell made their first contribution in #6159
    • @nimro made their first contribution in #6083

    Full Changelog: v0.42.0...v0.43.0

    Original source
  • Apr 21, 2026
    • Date parsed from source:
      Apr 21, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.42.0

    Atlantis releases v0.42.0 with targeted undiverged requirements, Azure DevOps and GitHub fixes, and key bug fixes for lock messages, CloudFormation stack lists, and a working directory deadlock. It also includes security and dependency updates plus refreshed docs.

    What's Changed

    Breaking Changes πŸ› 

    • feat: add targeted undiverged requirement by @pseudomorph in #6120

    Provider AzureDevops

    • fix: make go-generate by @icholy in #6390

    Provider GitHub

    • fix(github): check ruleset required reviewer approvals in IsMergeable… by @blackknight467 in #6374

    Bug fixes πŸ›

    • fix: respect executable name in lock message by @daftping in #6165
    • fix: diff cloudformation stack list items by @fzipi in #6069
    • fix: prevent deadlock in working_dir.go by @nvanheuverzwijn in #6409

    Security changes

    • chore(deps): update dependency vite to v6.4.2 [security] (main) by @renovate[bot] in #6367

    Documentation

    • chore(deps): update dependency vue to v3.5.31 in package.json (main) by @renovate[bot] in #6352
    • chore(deps): update dependency @playwright/test to v1.59.1 in package.json (main) by @renovate[bot] in #6366
    • chore(deps): update dependency vue to v3.5.32 in package.json (main) by @renovate[bot] in #6368
    • docs: fix npm command in CONTRIBUTING.md by @icholy in #6388
    • docs: add gitea-base-url to Gitea startup example by @vechiato in #6396
    • docs: update renamed terragrunt's TERRAGRUNT_* env var by @dullest in #6080

    Dependencies

    • chore(deps): update ghcr.io/runatlantis/atlantis:latest docker digest to 634ffcd in dockerfile.dev (main) by @renovate[bot] in #6349
    • chore(deps): update dependency hashicorp/terraform to v1.14.8 in testdrive/utils.go (main) by @renovate[bot] in #6354
    • fix(deps): update module github.com/go-playground/validator/v10 to v10.30.2 in go.mod (main) by @renovate[bot] in #6357
    • fix(deps): update module github.com/moby/patternmatcher to v0.6.1 in go.mod (main) by @renovate[bot] in #6359
    • chore(deps): update debian:12.13-slim docker digest to 4724b8c in dockerfile (main) by @renovate[bot] in #6370
    • chore(deps): update docker/dockerfile:1 docker digest to 2780b5c in dockerfile (main) by @renovate[bot] in #6372
    • chore(deps): update codelytv/pr-size-labeler digest to 095a41f in .github/workflows/pr-size-labeler.yml (main) by @renovate[bot] in #6380
    • chore(deps): update ngrok/ngrok:latest docker digest to 068852d in docker-compose.yml (main) by @renovate[bot] in #6383
    • chore(deps): update dependency opentofu/opentofu to v1.11.6 in dockerfile (main) by @renovate[bot] in #6391
    • chore(deps): update redis:8.6-alpine docker digest to c5e375a in docker-compose.yml (main) by @renovate[bot] in #6402
    • chore(deps): bump go to 1.25.8 and hc-install to v0.9.4 by @edbighead in #6410

    Other Changes πŸ”„

    • chore: Add lukemassa to MAINTAINERS.md by @lukemassa in #6395
    • chore: Specify uid for consistent uids over images by @GMartinez-Sisti in #6212
    • fix: update PullStatus between execution group runs by @joekohlsdorf in #6102
    • chore: add Vend to the list of adopters by @kasperbrandenburg in #6344

    New Contributors

    • @daftping made their first contribution in #6165
    • @icholy made their first contribution in #6388
    • @vechiato made their first contribution in #6396
    • @joekohlsdorf made their first contribution in #6102
    • @kasperbrandenburg made their first contribution in #6344
    • @blackknight467 made their first contribution in #6374
    • @dullest made their first contribution in #6080

    Full Changelog: v0.41.0...v0.42.0

    Original source
  • Mar 27, 2026
    • Date parsed from source:
      Mar 27, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.41.0

    Atlantis adds intelligent comment splitting, improves GitHub and Gitea status handling, tightens git operation fencing, and ships multiple bug, security, documentation, and dependency updates in this release.

    Atlantis is now hosting CNCF-supported community meeting on Wednesday 4PM UTC! The meeting will be bi-weekly.

    Please bear with the maintainer team as we kick-start this process. Hope to see you all there!

    Agenda and Notes can be found here (as well as links to the LFX zoom to add to your calendar):

    https://docs.google.com/document/d/1EzseHmT4Zarj-_7MO8ud5mHByIJGIHS7JdoNNK9ZckU/edit?tab=t.0

    What's Changed

    Exciting New Features πŸŽ‰

    • feat: intelligent comment splits by @pseudomorph in #5786
    • feat: migrate locking mocks from pegomock to uber-go/mock (Phase 1) by @jamengual in #6253

    Provider GitHub

    • fix(github): Correct draft PR mergeability status by @usmonster in #6110
    • fix(deps): upgrade go-github v71 β†’ v83 by @Copilot in #6222

    Bug fixes πŸ›

    • fix: intelligent comment split issues by @pseudomorph in #6216
    • fix: fetch pull request status during autoplan to respect plan_requirements by @Gosorasora in #6186
    • fix: duplicated custom policy check output in pull request comment by @jt-wise in #6219

    Security changes

    • fix(deps): patch minimatch/markdown-it via npm overrides by @Copilot in #6239
    • chore(deps): update module github.com/cloudflare/circl to v1.6.3 [security] (main) by @renovate[bot] in #6269

    Documentation

    • feat: Add .github/copilot-instructions.md for agent onboarding by @Copilot in #6124
    • chore(deps): update dependency @playwright/test to v1.58.0 in package.json (main) by @renovate[bot] in #6129
    • docs: policy check by @albertorm95 in #6167
    • docs: fix naming of directory in example by @KurtLehnardt in #6175
    • chore(deps): update dependency @types/node to v22.19.11 in package.json (main) by @renovate[bot] in #6195
    • chore(deps): update dependency @playwright/test to v1.58.2 in package.json (main) by @renovate[bot] in #6194
    • chore(deps): update dependency vue to v3.5.28 in package.json (main) by @renovate[bot] in #6197
    • fix: terraform_distribution availability version in docs (v0.25.0 β†’ v0.33.0) by @CPWu in #6214
    • chore(deps): update dependency mermaid to v11.12.3 in package.json (main) by @renovate[bot] in #6234
    • chore(deps): update node.js to v24 in .node-version (main) by @renovate[bot] in #6244
    • docs: consolidating documentation for agents and Copilot by @Copilot in #6329
    • chore(deps): update dependency vue to v3.5.30 in package.json (main) by @renovate[bot] in #6338

    Dependencies

    • chore(deps): update ghcr.io/runatlantis/atlantis:latest docker digest to bdf219f in dockerfile.dev (main) by @renovate[bot] in #6130
    • chore(deps): update dependency opentofu/opentofu to v1.11.4 in dockerfile (main) by @renovate[bot] in #6127
    • chore(deps): update redis:7.4-alpine docker digest to 02f2cc4 in docker-compose.yml (main) by @renovate[bot] in #6132
    • chore(deps): update terraform random to v3.8.1 in server/controllers/events/testdata/test-repos/state-rm-single-project/versions.tf (main) by @renovate[bot] in #6138
    • fix(deps): update module golang.org/x/term to v0.39.0 in go.mod (main) by @renovate[bot] in #6142
    • fix(deps): update module github.com/spf13/viper to v1.21.0 in go.mod (main) by @renovate[bot] in #6140
    • fix(deps): update module github.com/spf13/cobra to v1.10.2 in go.mod (main) by @renovate[bot] in #6139
    • fix(deps): update module golang.org/x/text to v0.33.0 in go.mod (main) by @renovate[bot] in #6143
    • chore(deps): update debian:12.13-slim docker digest to 98f4b71 in dockerfile (main) by @renovate[bot] in #6148
    • chore(deps): update ngrok/ngrok:latest docker digest to 2226144 in docker-compose.yml (main) by @renovate[bot] in #6161
    • chore(deps): update alpine docker tag to v3.23.3 in dockerfile (main) by @renovate[bot] in #6169
    • chore(deps): update ngrok/ngrok:latest docker digest to 07bd8fa in docker-compose.yml (main) by @renovate[bot] in #6191
    • fix(deps): update github.com/shurcool/githubv4 digest to 2402fdf in go.mod (main) by @renovate[bot] in #6193
    • fix(deps): update module code.gitea.io/sdk/gitea to v0.23.2 in go.mod (main) by @renovate[bot] in #6199
    • fix(deps): update module github.com/alicebob/miniredis/v2 to v2.36.1 in go.mod (main) by @renovate[bot] in #6200
    • fix(deps): update github.com/hashicorp/terraform-config-inspect digest to f4be3ba in go.mod (main) by @renovate[bot] in #6192
    • chore(deps): update dependency hashicorp/terraform to v1.14.5 in testdrive/utils.go (main) by @renovate[bot] in #6196
    • fix(deps): update module golang.org/x/text to v0.34.0 in go.mod (main) by @renovate[bot] in #6211
    • fix(deps): update module github.com/redis/go-redis/v9 to v9.17.3 in go.mod (main) by @renovate[bot] in #6208
    • fix(deps): update module github.com/go-playground/validator/v10 to v10.30.1 in go.mod (main) by @renovate[bot] in #6203
    • fix(deps): update module golang.org/x/term to v0.40.0 in go.mod (main) by @renovate[bot] in #6210
    • fix(deps): update module github.com/golang-jwt/jwt/v5 to v5.3.1 in go.mod (main) by @renovate[bot] in #6204
    • fix(deps): update module github.com/hashicorp/hcl/v2 to v2.24.0 in go.mod (main) by @renovate[bot] in #6206
    • fix(deps): update module github.com/bmatcuk/doublestar/v4 to v4.10.0 in go.mod (main) by @renovate[bot] in #6201
    • fix(deps): update module github.com/bradleyfalzon/ghinstallation/v2 to v2.17.0 in go.mod (main) by @renovate[bot] in #6202
    • fix(deps): update module github.com/petergtz/pegomock/v4 to v4.3.0 in go.mod (main) by @renovate[bot] in #6207
    • fix(renovate): config for go-github updates by @Copilot in #6171
    • chore(deps): update dependency opentofu/opentofu to v1.11.5 in dockerfile (main) by @renovate[bot] in #6235
    • chore(deps): update redis docker tag to v8 in docker-compose.yml (main) by @renovate[bot] in #6245
    • chore(deps): pin gcr.io/oss-fuzz-base/base-builder-go docker tag to 4fdcdc7 in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6259
    • chore(deps): update debian:12.13-slim docker digest to 74d56e3 in dockerfile (main) by @renovate[bot] in #6266
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to 153f35f in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6268
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to ff0fd2c in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6273
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to c90cf6f in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6275
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to be4ca29 in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6276
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to 3023a59 in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6278
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to 2b3cf9e in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6279
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to 92d6572 in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6282
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to c5c6517 in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6288
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to 939c41f in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6289
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to bb738df in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6290
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to b0a1a6f in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6293
    • chore(deps): update gcr.io/oss-fuzz-base/base-builder-go docker digest to b940188 in .clusterfuzzlite/dockerfile (main) by @renovate[bot] in #6296
    • chore(deps): update ngrok/ngrok:latest docker digest to de80ead in docker-compose.yml (main) by @renovate[bot] in #6313
    • chore(deps): update redis:8.6-alpine docker digest to 2afba59 in docker-compose.yml (main) by @renovate[bot] in #6314
    • chore(deps): update debian:12.13-slim docker digest to f065376 in dockerfile (main) by @renovate[bot] in #6318
    • chore(deps): update docker/dockerfile:1 docker digest to 4a43a54 in dockerfile (main) by @renovate[bot] in #6320
    • fix(deps): update github.com/hashicorp/terraform-config-inspect digest to 813a975 in go.mod (main) by @renovate[bot] in #6327
    • chore(deps): update dependency hashicorp/terraform to v1.14.7 in testdrive/utils.go (main) by @renovate[bot] in #6331
    • chore(deps): update redis:8.6-alpine docker digest to 81b6f81 in docker-compose.yml (main) by @renovate[bot] in #6334
    • chore(deps): update ngrok/ngrok:latest docker digest to d43df23 in docker-compose.yml (main) by @renovate[bot] in #6343

    Other Changes πŸ”„

    • fix: more comprehensive fencing of git operations by @pseudomorph in #6230
    • chore: Adding Rapid7 to the list of adopters by @snorlaX-sleeps in #6336
    • fix(gitea): add src as context for gitea status updates by @maddawik in #5975

    New Contributors

    • @usmonster made their first contribution in #6110
    • @Copilot made their first contribution in #6124
    • @KurtLehnardt made their first contribution in #6175
    • @CPWu made their first contribution in #6214
    • @Gosorasora made their first contribution in #6186
    • @maddawik made their first contribution in #5975
    • @jt-wise made their first contribution in #6219

    Full Changelog: v0.40.0...v0.41.0

    Original source
  • Jan 30, 2026
    • Date parsed from source:
      Jan 30, 2026
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.40.0

    Atlantis adds project-name locking, tighter command locking, and safer repo reuse handling, while fixing API defaults and plan policy requirements. This release also refreshes docs and dependencies as the team prepares for a stable 1.0.0.

    The core Atlantis team is preparing for a stable 1.0.0 release! Please reach out if you are working on a potentially breaking change that might affect our planning. πŸš€

    What's Changed

    Exciting New Features πŸŽ‰

    • fix: Add project name to locking key by @carmennavarreteh in #6004

    Bug fixes πŸ›

    • fix: Do not add "passed_policy" as a plan or import requirement by @lukemassa in #6027
    • chore: Fallback to force clone on any error attempting repo reuse by @lukemassa in #6011
    • fix: API Controller CommentCommand.Name defaults to Apply instead of Plan by @rjmsilveira in #6090

    Documentation

    • chore(deps): update dependency markdownlint-cli to v0.47.0 in package.json (main) by @renovate[bot] in #6059
    • fix: Assume divergence until established otherwise by @aggrand in #5955
    • docs(runatlantis.io): Fix typos in documentation files by @hsusanoo in #6063
    • chore(deps): update node.js to v22.21.1 in .node-version (main) by @renovate[bot] in #6076
    • chore(deps): update dependency @types/node to v22.19.5 in package.json (main) by @renovate[bot] in #6084
    • docs: Update API Endpoints params by @albertorm95 in #6092
    • chore(deps): update node.js to v22.22.0 in .node-version (main) by @renovate[bot] in #6096
    • docs: Add alpha API notice to API endpoints documentation by @jamengual in #6097
    • chore(deps): update dependency vue to v3.5.27 in package.json (main) by @renovate[bot] in #6105

    Dependencies

    • chore(deps): update ghcr.io/runatlantis/atlantis:latest docker digest to 9bb5658 in dockerfile.dev (main) by @renovate[bot] in #6055
    • chore(deps): update debian:12.12-slim docker digest to d5d3f9c in dockerfile (main) by @renovate[bot] in #6057
    • chore(deps): update dependency open-policy-agent/conftest to v0.66.0 in dockerfile (main) by @renovate[bot] in #6061
    • chore(deps): update dependency open-policy-agent/conftest to v0.66.0 in testing/dockerfile (main) by @renovate[bot] in #6064
    • chore(deps): update dependency opentofu/opentofu to v1.11.2 in dockerfile (main) by @renovate[bot] in #6067
    • chore(deps): update ngrok/ngrok:latest docker digest to d20e963 in docker-compose.yml (main) by @renovate[bot] in #6082
    • chore(deps): update dependency opentofu/opentofu to v1.11.3 in dockerfile (main) by @renovate[bot] in #6089
    • chore(deps): update debian docker tag to v12.13 in dockerfile (main) by @renovate[bot] in #6091
    • chore(deps): update terraform random to v3.8.0 in server/controllers/events/testdata/test-repos/state-rm-single-project/versions.tf (main) by @renovate[bot] in #6099
    • fix(deps): update module code.gitea.io/sdk/gitea to v0.22.1 in go.mod (main) by @renovate[bot] in #6111
    • fix(deps): update github.com/hashicorp/terraform-config-inspect digest to 7854796 in go.mod (main) by @renovate[bot] in #6112

    Other Changes πŸ”„

    • chore: Add project command output struct by @lukemassa in #5964
    • fix: Add project name to command locking by @carmennavarreteh in #6086
    • chore(deps): manual upgrade to Alpine 3.23 by @Vlaaaaaaad in #6051

    New Contributors

    • @aggrand made their first contribution in #5955
    • @hsusanoo made their first contribution in #6063
    • @carmennavarreteh made their first contribution in #6086
    • @Vlaaaaaaad made their first contribution in #6051

    Full Changelog: v0.39.0...v0.40.0

    Original source
  • Dec 29, 2025
    • Date parsed from source:
      Dec 29, 2025
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.39.0

    Atlantis adds a new cancel command to stop queued operations, along with bug fixes for custom policy checks and GitHub CodeQL handling. This release also includes provider cleanup and dependency updates.

    What's Changed

    Exciting New Features πŸŽ‰

    • feat: add atlantis cancel command to cancel queued operations by @bschaatsbergen and @ramonvermeulen in #5813
    Provider AzureDevops
    • chore: Remove pkg/errors by @lukemassa in #5988
    • chore: Move vcs code into own packages by @lukemassa in #5990
    Provider Bitbucket
    • chore: Cleanup redundant names in vcs packages by @lukemassa in #6041
    Provider GitHub
    • fix: handle global codeql checkrun correctly by @nvanheuverzwijn in #5927

    Bug fixes πŸ›

    • fix: correct error handling for custom policy checks with empty outputs by @dimisjim in #6017
    • fix: Custom policy check treats 0 failures output as failed and logs by @namcxn in #6019

    Documentation

    • build(deps): bump mdast-util-to-hast from 13.2.0 to 13.2.1 by @dependabot[bot] in #5992
    • chore: Create ADOPTERS.md by @GenPage in #6033
    • chore(deps): update dependency mermaid to v11.12.2 in package.json (main) by @renovate[bot] in #6045
    • chore(deps): update dependency vue to v3.5.26 in package.json (main) by @renovate[bot] in #6046
    • chore(deps): update dependency @playwright/test to v1.57.0 in package.json (main) by @renovate[bot] in #6050

    Dependencies

    • chore(deps): update debian:12.12-slim docker digest to e899040 in dockerfile (main) by @renovate[bot] in #6021
    • chore(deps): update ghcr.io/runatlantis/atlantis:latest docker digest to db84af5 in dockerfile.dev (main) by @renovate[bot] in #6028
    • chore(deps): update ngrok/ngrok:latest docker digest to 141f564 in docker-compose.yml (main) by @renovate[bot] in #6030
    • fix(deps): update module go.uber.org/zap to v1.27.1 in go.mod (main) by @renovate[bot] in #6048
    • chore(deps): update dependency hashicorp/terraform to v1.14.3 in testdrive/utils.go (main) by @renovate[bot] in #6053

    New Contributors

    • @namcxn made their first contribution in #6019

    Full Changelog: v0.38.0...v0.39.0

    Original source
  • Dec 20, 2025
    • Date parsed from source:
      Dec 20, 2025
    • First seen by Releasebot:
      Jul 29, 2026
    Atlantis logo

    Atlantis

    v0.38.0

    Atlantis releases version 0.38.0 with provider updates for Azure DevOps, GitHub, and GitLab, plus bug fixes for version command crashes, policy check errors, reclone handling, and mergeability detection. It also includes security updates, dependency refreshes, and documentation cleanup.

    What's Changed

    Provider AzureDevops

    chore: Add license references to files that don't have them by @lukemassa in #5977

    Provider GitHub

    fix: determine mergeability of GitHub workflows from check suite by @henriklundstrom in #5885

    Provider GitLab

    fix: resolve issue #5944 by @MihailoPlavsic34 in #5986

    Bug fixes πŸ›

    fix: Nil pointer dereference in atlantis version command by @Adamovix in #5971

    fix: Fail policy checks when Rego syntax errors occur by @edbighead in #5980

    fix: Close metric scope after tests finish by @lukemassa in #5889

    fix: Handle changing base branch in reclone by @lukemassa in #6005

    fix: Do not use name head for source remote by @lukemassa in #6010

    Security changes

    chore(deps): update module golang.org/x/crypto to v0.43.0 [security] (main) by @renovate[bot] in #5956

    chore(deps): update module golang.org/x/crypto to v0.45.0 [security] (main) by @renovate[bot] in #5974

    Documentation

    build(deps): bump vite from 5.4.20 to 5.4.21 by @dependabot[bot] in #5905

    docs: Consolidate release documentation by @lukemassa in #5946

    chore(deps): update dependency vue to v3.5.24 in package.json (main) by @renovate[bot] in #5966

    Dependencies

    chore(deps): update go to v1.25.4 in go.mod (main) by @renovate[bot] in #5943

    chore(deps): update ghcr.io/runatlantis/atlantis:latest docker digest to 26043ad in dockerfile.dev (main) by @renovate[bot] in #5951

    chore(deps): update ngrok/ngrok:latest docker digest to 168300d in docker-compose.yml (main) by @renovate[bot] in #5958

    chore(deps): update dependency opentofu/opentofu to v1.10.7 in dockerfile (main) by @renovate[bot] in #5965

    Other Changes πŸ”„

    chore: Remove invalid policy owner tests from command_runner_test by @lukemassa in #5963

    chore: Improve working dir lock error output by @lukemassa in #5960

    fix: add env variable DEFAULT_CONFTEST_VERSION to dockerfile so it's available at runtime by @nvanheuverzwijn in #5997

    New Contributors

    @Adamovix made their first contribution in #5971

    @rjmsilveira made their first contribution in #5926

    @MihailoPlavsic34 made their first contribution in #5986

    Full Changelog: v0.37.1...v0.38.0

    Original source

This is the end. You've seen all the release notes in this feed!

Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official product update announcements from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.