> This page is for Itential Gateway, version 5 (default).
> For other versions, use one of these documentation indexes:
> - 5 (default): https://docs.itential.com/itential-gateway/5/llms.txt
> - 4: https://docs.itential.com/itential-gateway/4/llms.txt

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.itential.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.itential.com/_mcp/server.

# Gateway 5.5.3

Itential Gateway 5.5.3 is a maintenance release containing one bug fix and three security fixes.

#### Bug fixes (1)

| Issue                                                          | Description                                                                                                                                                                                                                                                           |
| -------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Missing sshpass package in the container image** (ENG-28306) | Fixed an issue where the Gateway 5 container image didn't include `sshpass`, which the Gateway 4 container image provides. Automation playbooks, such as Ansible playbooks, that use `sshpass` for password-based SSH now run correctly inside the Gateway container. |

#### Security fixes (3)

| Issue                                                      | Description                                                                                                                                                                                                                                                                                                                                                                                                              |
| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Replaced archived mapstructure dependency** (ENG-26702)  | Replaced the archived `github.com/mitchellh/mapstructure` dependency with its actively maintained fork, `github.com/go-viper/mapstructure/v2`. No configuration changes are required.                                                                                                                                                                                                                                    |
| **API key file readable by other local users** (ENG-26731) | Fixed an issue where `iagctl login` saved the API key to the `api.key` file with permissions that let other local users read it. Gateway now creates the file with owner-only permissions (`0600`) and updates an existing `api.key` file to `0600` the next time you run `iagctl login`.                                                                                                                                |
| **Updated third-party dependencies** (ENG-27907)           | Updated `google.golang.org/grpc`, `golang.org/x/crypto`, and `github.com/mark3labs/mcp-go` to address known security vulnerabilities. These updates include a fix for SSH channel deadlocks that could occur when Gateway connects to git remotes and network devices. Also updated `github.com/aws/aws-sdk-go-v2/service/dynamodb` and `go.uber.org/zap` as routine maintenance. No configuration changes are required. |