A maintenance release focused primarily on dependency version updates across the project. The Linkerd proxy is updated to v2.366.0, with no security advisories or operator-enforced breaking changes described.
Source ↗
Don't read release notes for 76 CNCF projects.
Alerts only when your stack needs action, and what to do about it.
76 projects · 867 analyses · this week 24 reviewed → 12 alerts
Latest alert · Aug 15, 2026 – Aug 22, 2026
Last 7 days
Action needed12 projects · 48details →
Crossplanev1.20.12 · v2.2.5 · v2.3.5 · v2.4.0security25Vulnerable dependency fixes 외 24건
Kyvernov1.19.0security7Intermediate certificate limits 외 6건
hamiv2.10.0security3tensorflow/tensorflow upgraded to 2.21.0rc0-gpu 외 2건
Check if affected11 projects · 53details →
Backstagev1.54.0security1breaking15Kubernetes plugin security fixes 외 15건
Keycloak26.7.2security6CVE-2026-18963 reset-credentials flow bypass correction 외 5건
Rookv1.20.6 · v1.19.10 · v1.20.5security3breaking1Ceph CVE-2025–30156 upgrade advisory 외 3건
Plan ahead4 projects · 6details →
Backstagev1.54.0deprecated3The plugin-web-library template, updated to toastApiRef 외 2건
Crossplanev2.4.0deprecated1Crossplane v1.20 support end
Kyvernov1.19.0deprecated1Deprecation notices for legacy kyverno.io policy types
A maintenance release corrects binary checksum handling and the Usage index key, alongside updates to security-sensitive and build dependencies. The dependency changes require the new release, with no operator configuration migration stated.
Action needed (4)
securityThe
golang.dependency updateorg/x/mod The release updates
golang.as a security-related dependency change.org/x/mod securityThe
github.dependency, updated tocom/sigstore/sigstore-go v1.2. 1 The release updates
github.tocom/sigstore/sigstore-go v1.as a security-related dependency change.2. 1 securityThe
github.dependency, updated tocom/google/cel-go v0.30. 0 The release updates
github.tocom/google/cel-go v0.as a security-related dependency change.30. 0 securityThe
crossplane-runtimedependency, bumped tov2.3. 4 The release bumps
crossplane-runtimetov2.as a security-related dependency change.3. 4
A maintenance release corrects binary checksum generation and deletion-protection indexing, and updates dependencies for upstream CVE fixes. The changes affect release verification, webhook deletion checks, and the dependency set shipped with the release.
Action needed (1)
securityDependency security updates
The release updates
cel-go,golang.,org/x/mod sigstore-go, andgo-git, along with a combined set of vulnerable dependency updates, to pick up upstream CVE fixes. It also bumpscrossplane-runtimetov2., which carries its own security dependency updates.2. 4
A maintenance release with security-related dependency and toolchain updates, along with routine dependency and runtime version changes. No advisory identifiers are stated.
Action needed (5)
securityVulnerable dependency fixes
Vulnerable dependencies were updated in the release-1.20 branch.
securityVulnerable dependency updates
Vulnerable dependencies were updated in the release-1.20 branch.
securityThe
github.module updatecom/go-git/go-git/v5 The
github.module was updated to versioncom/go-git/go-git/v5 v5.in the release-1.20 branch.19. 2 securityThe
golang.module updateorg/x/mod The
golang.module was updated to versionorg/x/mod v0.in the release-1.20 branch.40. 0 securityThe
Gotoolchain version1.25. 13 The
Gotoolchain was updated to version1.in the release-1.20 branch.25. 13
This release adds attestors, plugins, configuration options, and CLI/API capabilities. It also updates dependencies and includes behavior changes and defect fixes, with no security advisories or explicitly described vulnerabilities.
Source ↗