Skip to content

chore(deps): update dependency opentofu/opentofu to v1.13.0 - #2969

Merged
berendt merged 1 commit into
mainfrom
renovate/opentofu-opentofu-1.x
Oct 4, 2026
Merged

berendt merged 1 commit into
mainfrom
renovate/opentofu-opentofu-1.x

Conversation

@renovate

@renovate renovate Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change Pending
opentofu/opentofu minor v1.12.6 → v1.13.0 v1.13.1
opentofu/opentofu minor 1.12.6 → 1.13.0 1.13.1

Release Notes

opentofu/opentofu (opentofu/opentofu)

v1.13.0

Compare Source

OpenTofu 1.13.0

We're proud to announce that OpenTofu 1.13.0 is now officially available! 🎉

Highlights

Windows on ARM64 is now a supported platform

Starting with OpenTofu v1.13.0 we are now offering official packages targeting Windows on the ARM64 (also known as "aarch64") CPU architecture.

Reducing unknowns during planning

OpenTofu v1.13 introduces a number of new functions that are all intended to allow module authors to give OpenTofu additional hints about what they know to be true even though OpenTofu cannot infer it automatically.

Linting Experiment

OpenTofu v1.13 includes some very early work towards built-in "linting" features in OpenTofu, although we are hoping to eventually incorporate other similar needs such as policy enforcement into a single comprehensive feature.

Symbol Libraries Experiment

We're considering a new kind of artifact called a "Symbol Library", which is a reusable collection of values, functions, and type aliases that can be imported from all of the same source types that are already supported for modules.

Compatibility Notes

  • base64gzip produces results that are equivalent but not byte-for-byte identical to previous versions, this is due to a required golang version upgrade
  • WinRM is no longer supported for provisioners
  • macOS: Requires macOS 13 Ventura or later
  • OpenTofu v1.13 will be the last series that includes official releases for 32 bit CPUs

Reference

Thank you for your continued support and testing of the OpenTofu project!

v1.12.7

Compare Source

SECURITY ADVISORIES:

  • When using either a remote-exec or file provisioner to connect to an attacker-controlled SSH server, the server could previously deadlock the connection by sending certain unexpected packet types. (#​4551)

    This addresses the upstream Go security advisories CVE-2026-78662 and CVE-2026-56855.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Signed-off-by: Renovate Bot <bot@renovateapp.com>
@renovate renovate Bot added the renovate label Oct 3, 2026
@berendt
berendt merged commit afbf532 into main Oct 4, 2026
4 checks passed
@berendt
berendt deleted the renovate/opentofu-opentofu-1.x branch October 4, 2026 08:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants