OpenTofu
Linux Foundation-governed, MPL-licensed fork of Terraform, with real production adoption at companies including Boeing, Capital One, and AMD.
https://opentofu.orgUpdate history
OpenTofu 1.12.5 patches a vulnerability in the Encrypted Client Hello implementation used via the Go standard library, where pre-shared key identities were leaked during the handshake, letting a passive network observer de-anonymize the server hostname even when ECH was in use. It also fixes a bug where implicit moves and provider address changes incorrectly triggered providers.MovedResourceState instead of providers.UpgradeResourceState.
Matters for: Relevant for teams running OpenTofu v1.12.x in environments where network traffic may be passively observed and hostname confidentiality matters, such as regulated infrastructure at organizations like Boeing, Capital One, or AMD.
Get the badge
Show that OpenTofu is tracked on StackFollow in your project's README.
[](https://stackfollow.xyz/tools/opentofu)