Skip to content

Commit 0fae3a4

Browse files
authored
chore: update NIM patch release notes (#1608)
* chore: update NIM patch release notes
1 parent 07eb3fa commit 0fae3a4

File tree

1 file changed

+60
-18
lines changed

1 file changed

+60
-18
lines changed

content/nim/releases/release-notes.md

Lines changed: 60 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -34,13 +34,13 @@ This release includes the following updates:
3434
- {{% icon-feature %}} **Expanded options for configuring security policies with F5 WAF for NGINX**<a name="2-21-0-whats-new-Expanded-options-for-configuring-security-policies-with-F5-WAF-for-NGINX-45801"></a>
3535

3636
You can now configure additional policy settings for F5 WAF for NGINX directly in the NGINX Instance Manager web interface, including:
37-
37+
3838
- Signature sets
3939
- Signature exceptions
4040
- Parameters
4141
- URLs
4242
- Cookies
43-
43+
4444
For more information, see the [F5 WAF for NGINX Integration Guide](https://docs.nginx.com/nginx-instance-manager/waf-integration/).
4545

4646
- {{% icon-feature %}} **Added support for bot signatures management in NGINX Instance Manager**<a name="2-21-0-whats-new-Added-support-for-bot-signatures-management-in-NGINX-Instance-Manager-45827"></a>
@@ -90,21 +90,21 @@ This release includes the following updates:
9090
- {{% icon-feature %}} **On-demand WAF policy compilation (bundle creation) in NGINX Instance Manager web interface**<a name="2-21-0-whats-new-On-demand-WAF-policy-compilation-(bundle-creation)-in-NGINX-Instance-Manager-web-interface-46672"></a>
9191

9292
This release adds on-demand compilation of WAF policies in the NGINX Instance Manager web interface. Pre-compiling policies helps reduce publish times and improve reliability.
93-
93+
9494
Previously, NGINX Instance Manager reused compiled bundles when available and compiled policies during publish if no bundle existed. This could slow down or occasionally fail. You can now compile policies in advance so they’re ready for immediate deployment to instances or instance groups.
95-
95+
9696
**What’s new**
97-
97+
9898
- **Web interface support for policy compilation:** Under **WAF > Policies**, select a policy and choose **Compile (bundle creation)** to start compilation on demand.
9999
- **Compilation status visibility:** A new **Compilation Status** column shows which policies are already compiled and which need compilation.
100100
- **Faster publishing:** When a compiled bundle exists for a selected policy, NGINX Instance Manager uses it to speed up publishing to instances and instance groups.
101-
101+
102102
**Upgrade and compatibility**
103-
103+
104104
- No breaking changes. Existing workflows continue to function as before. On-demand compilation through the web interface complements the existing API and can improve publish speed and reduce failures during WAF policy deployment.
105-
105+
106106
**Limitations**
107-
107+
108108
- By default, the **Compile** action uses the latest revision of the selected policy, the most recent compiler version, and the newest versions of attack signatures, bot signatures, and threat campaigns.
109109

110110
### Resolved issues {#2-21-0-resolved-issues}
@@ -129,19 +129,33 @@ NGINX Instance Manager 2.20.1 supports upgrades from these previous versions:
129129

130130
If your NGINX Instance Manager version is older, you may need to upgrade to an intermediate version before upgrading to the target version.
131131

132+
### Security updates{#2-18-1-security-updates}
133+
134+
{{< call-out "important" >}}
135+
For the protection of our customers, NGINX doesn’t disclose security issues until an investigation has occurred and a fix is available.
136+
{{< /call-out >}}
137+
138+
This release includes the following security updates:
139+
140+
- {{% icon-resolved %}} **Note on CVEs in this patch release**<a name="2-18-1-security-updates-CVEs-46911"></a>
141+
142+
This release does not include new fixes for security vulnerabilities (CVEs) present in this version. To receive security updates, please upgrade to the latest NGINX Instance Manager version. CVEs present in the latest version will be fixed in the upcoming 2.21.1 patch release.
143+
132144
### Changes in default behavior{#2-20-1-changes-in-behavior}
133145

134146
This release has the following changes in default behavior:
135147

136148
- {{% icon-feature %}} **Support for Entrust-CA deprecated**<a name="2-20-1-changes-in-behavior-Support-for-Entrust-CA-deprecated-46910"></a>
137149

138150
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
139-
151+
140152
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
141-
153+
142154
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
143-
155+
144156
To prevent service interruptions and provide an extended window for customers to upgrade to version 2.21.0, we are also issuing minor patch releases for versions 2.18.1, 2.19.3, and 2.20.1.
157+
158+
For more information please see the [related KB Article](https://my.f5.com/manage/s/article/K000158775).
145159

146160
### Known issues {#2-20-1-known-issues}
147161

@@ -229,19 +243,33 @@ NGINX Instance Manager 2.19.3 supports upgrades from these previous versions:
229243

230244
If your NGINX Instance Manager version is older, you may need to upgrade to an intermediate version before upgrading to the target version.
231245

246+
### Security updates{#2-19-3-security-updates}
247+
248+
{{< call-out "important" >}}
249+
For the protection of our customers, NGINX doesn’t disclose security issues until an investigation has occurred and a fix is available.
250+
{{< /call-out >}}
251+
252+
This release includes the following security updates:
253+
254+
- {{% icon-resolved %}} **Note on CVEs in this patch release**<a name="2-19-3-security-updates-CVEs-46912"></a>
255+
256+
This release does not include new fixes for security vulnerabilities (CVEs) present in this version. To receive security updates, please upgrade to the latest NGINX Instance Manager version. CVEs present in the latest version will be fixed in the upcoming 2.21.1 patch release.
257+
232258
### Changes in default behavior{#2-19-3-changes-in-behavior}
233259

234260
This release has the following changes in default behavior:
235261

236262
- {{% icon-feature %}} **Support for Entrust-CA deprecated**<a name="2-19-3-changes-in-behavior-Support-for-Entrust-CA-deprecated-46909"></a>
237263

238-
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
264+
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
239265

240-
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
266+
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
241267

242-
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
268+
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
243269

244270
To prevent service interruptions and provide an extended window for customers to upgrade to version 2.21.0, we are also issuing minor patch releases for versions 2.18.1, 2.19.3, and 2.20.1.
271+
272+
For more information please see the [related KB Article](https://my.f5.com/manage/s/article/K000158775).
245273

246274
### Known issues {#2-19-3-known-issues}
247275

@@ -398,19 +426,33 @@ NGINX Instance Manager 2.18.1 supports upgrades from these previous versions:
398426

399427
If your NGINX Instance Manager version is older, you may need to upgrade to an intermediate version before upgrading to the target version.
400428

429+
### Security updates{#2-18-1-security-updates}
430+
431+
{{< call-out "important" >}}
432+
For the protection of our customers, NGINX doesn’t disclose security issues until an investigation has occurred and a fix is available.
433+
{{< /call-out >}}
434+
435+
This release includes the following security updates:
436+
437+
- {{% icon-resolved %}} **Note on CVEs in this patch release**<a name="2-18-1-security-updates-CVEs-46911"></a>
438+
439+
This release does not include new fixes for security vulnerabilities (CVEs) present in this version. To receive security updates, please upgrade to the latest NGINX Instance Manager version. CVEs present in the latest version will be fixed in the upcoming 2.21.1 patch release.
440+
401441
### Changes in default behavior{#2-18-1-changes-in-behavior}
402442

403443
This release has the following changes in default behavior:
404444

405445
- {{% icon-feature %}} **Support for Entrust-CA deprecated**<a name="2-18-1-changes-in-behavior-Support-for-Entrust-CA-deprecated-46907"></a>
406446

407-
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
447+
Entrust CA, used in NGINX Instance Manager licensing flows, will no longer be a trusted certificate authority for browsers. Previous versions of NGINX Instance Manager ship with an embedded licensing bundle that only accepts Entrust-signed certificates for the F5 licensing servers.
408448

409-
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
449+
**The current Entrust certificates used by older NGINX Instance Manager licensing flows will be replaced on February 15, 2026.**
410450

411-
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
451+
To avoid reliance on a single certificate authority, NGINX Instance Manager will trust multiple well-known CAs through an updated certificate bundle. NGINX Instance Manager 2.21 includes this updated bundle so JWT-based licensing and connectivity to the licensing endpoint service continue to work.
412452

413453
To prevent service interruptions and provide an extended window for customers to upgrade to version 2.21.0, we are also issuing minor patch releases for versions 2.18.1, 2.19.3, and 2.20.1.
454+
455+
For more information please see the [related KB Article](https://my.f5.com/manage/s/article/K000158775).
414456

415457
### Known issues {#2-18-1-known-issues}
416458

0 commit comments

Comments
 (0)