diff --git a/security/file_integrity_operator/file-integrity-operator-release-notes.adoc b/security/file_integrity_operator/file-integrity-operator-release-notes.adoc index 0d4ba8496c..e8cce8ad36 100644 --- a/security/file_integrity_operator/file-integrity-operator-release-notes.adoc +++ b/security/file_integrity_operator/file-integrity-operator-release-notes.adoc @@ -15,6 +15,32 @@ For an overview of the File Integrity Operator, see xref:../../security/file_int To access the latest release, see xref:../../security/file_integrity_operator/file-integrity-operator-updating.adoc#olm-preparing-upgrade_file-integrity-operator-updating[Updating the File Integrity Operator]. +[id="file-integrity-operator-release-notes-1-3-3"] +== OpenShift File Integrity Operator 1.3.3 + +The following advisory is available for the OpenShift File Integrity Operator 1.3.3: + +* link:https://access.redhat.com/errata/RHBA-2023:5652[RHBA-2023:5652 OpenShift File Integrity Operator Bug Fix and Enhancement Update] + +This update addresses a CVE in an underlying dependency. + +[id="file-integrity-operator-1-3-3-new-features-and-enhancements"] +=== New features and enhancements + +* You can install and use the File Integrity Operator in an {product-title} cluster running in FIPS mode. + +[IMPORTANT] +==== +To enable FIPS mode for your cluster, you must run the installation program from a {op-system-base} computer configured to operate in FIPS mode. For more information about configuring FIPS mode on RHEL, see (link:https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/security_hardening/assembly_installing-the-system-in-fips-mode_security-hardening[Installing the system in FIPS mode]) +==== + +[id="file-integrity-operator-1-3-3-bug-fixes"] +=== Bug fixes + +* Previously, some FIO pods with private default mount propagation in combination with `hostPath: path: /` volume mounts would break the CSI driver relying on multipath. This problem has been fixed and the CSI driver works correctly. (link:https://access.redhat.com/solutions/7017081[Some OpenShift Operator pods blocking unmounting of CSI volumes when multipath is in use]) + +* This update resolves CVE-2023-39325. (link:https://access.redhat.com/security/cve/CVE-2023-39325[*CVE-2023-39325*]) + [id="file-integrity-operator-release-notes-1-3-2"] == OpenShift File Integrity Operator 1.3.2