A maintenance release focused primarily on dependency version updates across the project. The Linkerd proxy is updated to v2.366.0, with no security advisories or operator-enforced breaking changes described.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with security-related dependency and toolchain updates, along with routine dependency and runtime version changes. No advisory identifiers are stated.
Action needed (5)
securityVulnerable dependency fixes
Vulnerable dependencies were updated in the release-1.20 branch.
securityVulnerable dependency updates
Vulnerable dependencies were updated in the release-1.20 branch.
securityThe
github.module updatecom/go-git/go-git/v5 The
github.module was updated to versioncom/go-git/go-git/v5 v5.in the release-1.20 branch.19. 2 securityThe
golang.module updateorg/x/mod The
golang.module was updated to versionorg/x/mod v0.in the release-1.20 branch.40. 0 securityThe
Gotoolchain version1.25. 13 The
Gotoolchain was updated to version1.in the release-1.20 branch.25. 13
A maintenance release corrects binary checksum generation and deletion-protection indexing, and updates dependencies for upstream CVE fixes. The changes affect release verification, webhook deletion checks, and the dependency set shipped with the release.
Action needed (1)
securityDependency security updates
The release updates
cel-go,golang.,org/x/mod sigstore-go, andgo-git, along with a combined set of vulnerable dependency updates, to pick up upstream CVE fixes. It also bumpscrossplane-runtimetov2., which carries its own security dependency updates.2. 4
A maintenance release corrects binary checksum handling and the Usage index key, alongside updates to security-sensitive and build dependencies. The dependency changes require the new release, with no operator configuration migration stated.
Action needed (4)
securityThe
golang.dependency updateorg/x/mod The release updates
golang.as a security-related dependency change.org/x/mod securityThe
github.dependency, updated tocom/sigstore/sigstore-go v1.2. 1 The release updates
github.tocom/sigstore/sigstore-go v1.as a security-related dependency change.2. 1 securityThe
github.dependency, updated tocom/google/cel-go v0.30. 0 The release updates
github.tocom/google/cel-go v0.as a security-related dependency change.30. 0 securityThe
crossplane-runtimedependency, bumped tov2.3. 4 The release bumps
crossplane-runtimetov2.as a security-related dependency change.3. 4
This release adds attestors, plugins, configuration options, and CLI/API capabilities. It also updates dependencies and includes behavior changes and defect fixes, with no security advisories or explicitly described vulnerabilities.
Source ↗A substantial operator-focused maintenance release with broad bug and behavior fixes, alongside new scheduling, device, configuration, and observability capabilities. It also updates security-relevant dependencies and the runtime/toolchain while removing obsolete functionality that may affect compatibility and configuration.
Action needed (3)
security
tensorflow/tensorflowupgraded to2.21. 0rc0-gpu The
tensorflow/tensorflowdependency is upgraded from2.to20. 0rc0-gpu 2..21. 0rc0-gpu security
tensorflow/tensorflowupgraded to2.21. 0rc1-gpu The
tensorflow/tensorflowdependency is upgraded from2.to21. 0rc0-gpu 2..21. 0rc1-gpu security
golangsecurity upgradeThe
golangruntime is upgraded to address a security issue.
Check if affected (7)
breakingDRA components removed from the HAMi main chart
Applies if you use DRA components in the HAMi main chart.
breakingWebhook denial of privileged containers
Applies if you use the webhook.
breakingDeprecated scheduler policy configmap removed
Applies if you configure the deprecated scheduler policy configmap.
- + 4 more on the release page
A maintenance release with a Ceph security advisory, a disabled Rook manager module, and clearer CephX fallback errors. Users of Ceph are advised to upgrade, while CephX key fallback failures now report the actual error.
Check if affected (2)
security
CephCVE-2025–30156upgrade advisoryApplies if you depend on
Ceph.breakingThe
rook mgr module, disabledApplies if you enable the
rook mgr module.
A maintenance release with a security-driven Ceph upgrade recommendation and a disabled Rook manager module. It also adds or changes CephCluster and CephX error-reporting behavior.
Action needed (1)
breakingThe Rook manager module, disabled
The Rook manager module is disabled in this release.
Check if affected (1)
security
Cephupgrade recommendation for CVE-2025-30156Applies if you use
Ceph.
A release with breaking operational changes, new runtime behavior, and correctness fixes. It also updates the Go toolchain and dependencies for security fixes, including changes that affect CLI publication, package operation, and resource deletion.
Action needed (15)
security
Goversion and dependency security updatesCrossplane now builds and runs with a newer
Goversion to include standard library CVE fixes. The release also includes security updates to Crossplane'sGodependencies.security
Go1.25. 10 Gowas updated to1.to fix standard library CVEs.25. 10 security
golang.org/x/crypto v0.52. 0 The
golang.module was updated toorg/x/crypto v0.for security fixes.52. 0 security
golang.org/x/sys v0.44. 0 The
golang.module was updated toorg/x/sys v0.for security fixes.44. 0 security
golang.org/x/net v0.55. 0 The
golang.module was updated toorg/x/net v0.for security fixes.55. 0 security
github.com/sigstore/cosign/v3 v3.0. 6 The
github.module was updated tocom/sigstore/cosign/v3 v3.for security fixes.0. 6 security
github.com/sigstore/rekor v1.5. 2 The
github.module was updated tocom/sigstore/rekor v1.for security fixes.5. 2 security
github.com/sigstore/timestamp-authority/v2 v2.1. 0 The
github.module was updated tocom/sigstore/timestamp-authority/v2 v2.for security fixes.1. 0 security
github.com/sigstore/sigstore-go v1.2. 0 The
github.module was updated tocom/sigstore/sigstore-go v1.for security fixes.2. 0 securityCombined
grpc,x/net, andx/textsecurity updatesCombined security updates were applied to
grpc,x/net, andx/text.security
golang.org/x/net v0.56. 0 The
golang.module was updated toorg/x/net v0.for security fixes.56. 0 security
golang.org/x/text v0.39. 0 The
golang.module was updated toorg/x/text v0.for security fixes.39. 0 securityVulnerable dependency updates
Vulnerable dependencies were updated for security fixes.
security
github.com/sigstore/sigstore-go v1.2. 1 The
github.module was updated tocom/sigstore/sigstore-go v1.for security fixes.2. 1 security
golang.org/x/mod v0.40. 0 The
golang.module was updated toorg/x/mod v0.for security fixes.40. 0
Check if affected (4)
breaking
Crossplane CLIpublication location and binary nameApplies if you use the
Crossplane CLI.breaking
spec.behavior inreplicas DeploymentRuntimeConfigApplies if
DeploymentRuntimeConfigconfiguresspec..replicas breakingNarrowed composed resource garbage collection
Applicability is not stated in the release notes.
- + 1 more on the release page
Plan ahead (1)
deprecated
Crossplane v1.support endremoval planned in v2.5 (Nov 2026)20 Applies when v2.5 is released in Nov 2026 and
Crossplane v1.runs.20
A maintenance release with correctness fixes and a security-related dependency update. The dependency update is recorded in the manifest and has no standalone operator impact.
Action needed (1)
securitySecurity updates for
golang.andorg/x/text golang.org/x/net The dependency manifest updates
golang.andorg/x/text golang.to include security updates.org/x/net
A substantial operator-facing release with new CLI, Helm, and policy capabilities alongside fixes and dependency updates. It also changes existing behavior through security fixes, deprecations, removals, and stricter constraints that may require review before upgrading.
Action needed (7)
securityhighIntermediate certificate limits
Intermediate certificates are limited to mitigate CVE-2026-32280. The fix ships in Kyverno v1.19.0.
securityhighGo toolchain 1.26.3
The Go toolchain was upgraded to 1.26.3 to resolve CVE-2026-39836. The updated toolchain ships in Kyverno v1.19.0.
securityRegenerated CRDs and documentation for GHSA-79gf-7frw-68m9
CRDs and documentation were regenerated after the API bump associated with GHSA-79gf-7frw-68m9. The updated artifacts ship in Kyverno v1.19.0.
securityUpdated
golang.andorg/x/crypto x/netdependenciesThe
golang.dependency was updated to v0.53.0 andorg/x/crypto x/netto v0.56.0 to resolve security CVEs. The dependency updates ship in Kyverno v1.19.0.securityPatched ORAS and sigstore vulnerabilities
The ORAS and sigstore dependencies were patched for CodeQL vulnerabilities. The dependency fixes ship in Kyverno v1.19.0.
securityCodeQL vulnerability fixes
Open CodeQL security vulnerabilities were addressed. The fixes ship in Kyverno v1.19.0.
security
cel-gov0.30.0cel-gowas updated to v0.30.0 to resolve CVE-2026-GHSA-gcjh-h69q-9w9g. The updated dependency ships in Kyverno v1.19.0.
Check if affected (6)
breakingRequired
--resourcefor the migrate commandApplies when the migrate command runs.
breakingDefault
userInfogroups and UID during background scansApplies when background scans run.
breaking
excludeBootstrapResourceswebhook flagApplies when you configure Fail webhooks.
- + 3 more on the release page
Plan ahead (1)
deprecatedDeprecation notices for legacy
kyverno.policy typesio Applies when you use legacy
kyverno.policy types.io
This release removes legacy CRD API versions and resource state metrics, and changes defaults for token mounting, feature gates, and container security contexts. It also adds Kafka and configuration capabilities and updates shipped dependencies.
Action needed (2)
breakingService Account token mounting
Service Account tokens are no longer auto-mounted into Pods. They are mounted through a volume instead.
breakingThe
ServerSideApplyPhase1feature gate, permanently enabledThe
ServerSideApplyPhase1feature gate has moved to GA and is permanently enabled. It can no longer be disabled.
Check if affected (3)
breakingLegacy CRD API versions, no longer supported
Applies before upgrading to Strimzi 1.0.0 or later if you use the
v1beta2,v1beta1, orv1alpha1APIs.breakingResource state metrics, removed
Applicability is not stated in the release notes.
breakingDefault
securityContextfor operator installationsApplies if you use the Cluster, Topic, and User Operator YAML installation files or the Cluster Operator Helm Chart.
A maintenance release with security guidance for CVE-2025–30156 and updates across Ceph authentication, core behavior, Multus networking, and the Ceph base image. The release also includes a workaround for a Ceph authentication rotation race.
Action needed (1)
security
CVE-2025–30156upgrade guidanceRook users are advised to upgrade to Rook
v1.or20. 5 v1.with Ceph19. 9 v20.or2. 4 v19.in response to2. 6 CVE-2025–30156.
A security-focused release with an advisory requiring Rook and Ceph upgrades. It also adds support for the new cephx key type, changes external version validation to ignore Ceph commit IDs, and fixes monitor registration in the v1 failover path.
Check if affected (1)
security
CephCVE-2025–30156advisoryApplies if you use
Ceph.
A maintenance release with disclosed security fixes, a cleartext vault-keystore password correction, a Quarkus dependency upgrade, and other bug corrections. The fixes cover account and permission flows, secret handling, and runtime dependencies.
Action needed (2)
securitymediumCVE-2026-59888 and CVE-2026-59889 fixes in
jackson-databindjackson-databindis upgraded to 2.21.5 to address CVE-2026-59888 and CVE-2026-59889. The dependency update ships in this Keycloak release.securitymediumCVE-2026-45292 OpenTelemetry Java SDK memory allocation correction
CVE-2026-45292 corrects unbounded memory allocation in W3C Baggage Propagation in the OpenTelemetry Java SDK.
Check if affected (6)
securitycriticalCVE-2026-18963 reset-credentials flow bypass correction
Applies if you use the
reset-credentials flow.securityhighCVE-2026-15571 predictable account-linking hash correction
Applies if you use
oidc.securitymediumCVE-2026-14613 fine-grained admin permissions bypass correction
Applies if you use the
admin/fine-grained-permissionsAPI.- + 3 more on the release page
A maintenance release with a Go toolchain update that includes disclosed CVE fixes, an ACL-check bypass correction, and changes to operator-visible defaults. It also adds features and corrects defects across the DNS server.
Action needed (1)
securityhigh
Go 1.security fixes26. 6 The release is built with
Go 1., including fixes for CVE-2026-56865, CVE-2026-56864, and CVE-2026-33818.26. 6
Check if affected (3)
security
plugin/aclautopath ACL checksApplies if you use
plugin/aclandautopath.breaking
plugin/forwarddefault connection attemptsApplies if you use
plugin/forward.breaking
plugin/hostsunsupported-type fallthroughApplies if you use
plugin/hosts.
A broad release with dependency updates, breaking changes to commands, authentication patterns, and connection APIs, plus new AWS connection support and updates across the catalog, scaffolder, search, and UI. It also includes Kubernetes plugin security fixes and an undisclosed security announcement.
Action needed (2)
breakingStrict TypeScript configuration schema validation
Package preparation now validates TypeScript configuration schemas strictly before publishing.
breakingPortable configuration schemas for root connection types
Connection types now use portable configuration schemas as the source of root connection types.
Check if affected (16)
securityKubernetes plugin security fixes
Applies if you use the Kubernetes plugin.
breakingBackend connection APIs, removed from package exports
Applies if you use
connectionsServiceRef,connectionsServiceFactory,DefaultConnectionsService,declareConnection,RootConnection, orAnyRootConnection.breakingNode.js snapshots in generated backend Dockerfiles
Applies if you configure generated backend Dockerfiles.
- + 13 more on the release page
Plan ahead (3)
deprecatedThe
plugin-web-librarytemplate, updated totoastApiRefApplies if you use the
plugin-web-librarytemplate.deprecatedZod v3 schemas, deprecated
Applies if you depend on Zod v3 schemas.
deprecatedThe
catalog.option, deprecatedproviders. backstageOpenapi. plugins Applies if you configure
catalog..providers. backstageOpenapi. plugins
A maintenance release with numerous operator-facing bug fixes and behavior corrections, alongside dependency and image updates. It also introduces a decoder-memory limit and fixes a CIDR policy bypass that could cause traffic drops after an agent restart.
Check if affected (1)
securityThe
endpointCIDR policy bypass, fixedApplicability is not stated in the release notes.
A maintenance release with bug fixes, diagnostic improvements, dependency and image updates, and improved DNS request validation. It contains no security advisories or explicitly described vulnerabilities.
Source ↗A maintenance release that adds host-firewall protocol support, corrects networking and stability defects, and changes runtime behavior and observability. It also updates dependencies and container images, including a gRPC security fix with no disclosed vulnerability.
Action needed (1)
securityThe
google.dependency, updated togolang. org/grpc v1.82. 1 The
google.module is updated togolang. org/grpc v1.in the v1.18 release line. The release note marks this dependency update as a security fix, but does not disclose the vulnerability.82. 1
A maintenance release with an API deprecation, operator-visible removals and default changes, new capabilities, performance improvements, and correctness fixes across discovery, PromQL, TSDB, and other components. No security advisories or explicitly described security vulnerabilities are included.
Action needed (1)
breakingDefault support for PromQL duration expressions
Duration expressions are enabled by default in PromQL. The
promql-duration-exprfeature flag is now a no-op.
Check if affected (1)
breakingThe
__meta_hetzner_datacenterlabel, removedApplies if you use
hcloudtargets.
Plan ahead (1)
deprecatedThe
statsquery parameter, deprecated for other valuesremoval date not announcedApplies if you set
statsto a value other thantrueorall.
A maintenance release with fixes to operator-visible Dashboard behavior and Helm chart rendering. The changes address Dashboard serving, workflow schedule details, authentication, token controls, and extra-object template rendering.
Source ↗A release that adds exporter queue batching controls, changes exporter and scraper metric behavior, and updates public API field shapes. Schema-based configuration migrations are also included, with no security advisories or security fixes disclosed.
Check if affected (2)
breakingThe
confighttp.field shape inServerConfig ConfigApplies if you use
extension/zpages.breakingThe
configauth.field shape inConfig AuthConfigApplies if you use
configauth..Config
A security-focused maintenance release updates the Go build dependency to 1. and addresses standard-library vulnerabilities used by OPA's HTTP handler and crypto builtins. Operators building their own binaries or images control the Go version used in those builds.
Action needed (1)
securitycritical
Go1.build dependency26. 6 OPA is built with
Go1., fixing standard-library vulnerabilities in code used by its HTTP handler and crypto builtins. The fixes address26. 6 GO-2026-5026,GO-2026-5972,GO-2026-6088,GO-2026-6089,GO-2026-6090,GO-2026-6091, andGO-2026-6218.
A maintenance release with an operator-relevant correctness fix. The remaining note concerns SPIFFE SVID authentication context passed to operation calls.
Source ↗A maintenance release with ordinary bug fixes across the project. No operator action is required beyond upgrading.
Source ↗A maintenance release for flagd-proxy resolves open Dependabot security alerts. The sync server also receives a gRPC keepalive enforcement policy update.
Action needed (1)
securityOpen Dependabot security alerts resolved
Open Dependabot security alerts are resolved in flagd-proxy v0.9.8.
A maintenance release focused on bug fixes in eventing, eventstream connections, and evaluation metrics recording. The recorded fixes do not indicate any operator action beyond upgrading.
Source ↗A maintenance release with operator-facing correctness fixes, runtime behavior changes, a new configuration flag, and cron parser updates backed by a dependency change. It contains no security advisories or explicitly described vulnerabilities.
Source ↗A maintenance release with routine dependency updates, a destination informer correction, and policy-controller behavior changes. It also expands Kubernetes and Gateway API support, with no disclosed security advisories or security-specific fixes.
Source ↗A release with breaking behavior for legacy V2 linked-clone volumes, a Kubernetes v1.25 minimum, and stronger default network controls, including expanded mTLS enforcement. It also adds V2 data engine capabilities and metrics while correcting defects across V2 operations, backups, expansion, and infrastructure.
Check if affected (6)
breakingInternal
NetworkPolicyresources enabled by defaultApplies if a
NetworkPolicyprovider is available in the cluster.breakingCross-namespace Prometheus scraper access through the Longhorn Manager network policy
Applies if you use cross-namespace Prometheus scrapers.
breakingmTLS for all instance-manager gRPC services
Applies if you configure the
longhorn-grpc-tlssecret.- + 3 more on the release page
Plan ahead (1)
deprecatedLegacy V2 linked-clone volumes deprecated
Applies if you use V2 linked-clone volumes created in v1.12.0 or earlier.
A maintenance release with operator-facing behavior changes, compatibility improvements, and defect corrections. No security advisories or explicitly security-related fixes are mentioned.
Source ↗A maintenance release with Linux security fixes identified by CVEs. It also updates the Linux and ca-certificates dependencies.
Action needed (1)
securitycritical
Linuxsecurity updatesThe
Linuxupdate ships security fixes identified by the CVE advisories recorded for this change.
A security-focused release with Linux and OpenSSH fixes identified by CVE advisories. It also updates versions of Linux, ca-certificates, and OpenSSH.
Action needed (2)
securitycritical
Linuxsecurity fixesThe release includes
Linuxsecurity fixes identified by CVE advisories, including CVE-2026-68480.securityhigh
opensshsecurity fixesThe release includes
opensshsecurity fixes identified by CVE advisories, including CVE-2026-59995.
A maintenance release with correctness fixes and dependency updates tied to GO advisories. The changes affect Helm users through both general fixes and updated Go dependencies.
Action needed (2)
securitymediumThe
go.dependency upgrade foropentelemetry. io/otel GO-2026-5158go.was upgraded to v1.44.0 for advisoryopentelemetry. io/otel GO-2026-5158.securityThe
google.dependency upgrade forgolang. org/grpc GO-2026-6061google.was upgraded from 1.80.0 to 1.82.1 for advisorygolang. org/grpc GO-2026-6061.
A maintenance release with a security fix for an external authorization bypass and dependency updates for CVE fixes. It also updates the tested Kubernetes range to 1.32 through 1.34, Go to 1.25.12, and Envoy to v1.38.3.
Action needed (1)
securityDependency updates for CVE fixes
Dependencies were updated to fix CVEs. The updates ship in Contour v1.33.6.
Check if affected (1)
securityExternal authorization bypass with disabled
authPolicyApplies if
authPolicyis not configured.
A container runtime and CRI release that changes checkpoint-restore defaults and lifecycle, adds CRIU and Windows log-scrubbing configuration, and expands runtime support. It also includes fixes for CRI environment handling and mount-manager activation, plus dependency manifest updates that are not operator-facing.
Check if affected (3)
breakingThe
enable_experimental_restore_via_createdefaultApplies if you use
CreateContainer.breakingThe
ScrubLogsdefault on WindowsApplies if you run on Windows.
breakingCheckpoint restore without
CRIUApplies if you do not have
CRIUinstalled.
Plan ahead (1)
deprecatedRestore in
CreateContainer, deprecatedApplies if you use
CreateContainer.
A container runtime release with changes to CRI behavior, checkpoint restore handling, and configuration. It also adds CRI capabilities and fixes runtime and snapshotter defects.
Check if affected (3)
breakingCheckpoint restore in
CreateContainerdisabled by defaultApplies if you set
enable_experimental_restore_via_create.breaking
runtimeFeatures.enabled by defaultUserNamespacesHostNetwork Applies if you run CRI.
breakingLog scrubbing enabled by default on Windows
Applies if you run Windows.
Plan ahead (1)
deprecatedCheckpoint restore in
CreateContainerdeprecatedApplies if you use
CreateContainer.
NATS v2.14.5 updates the Go toolchain and two dependencies, and adds a configurable leafnode dial timeout for high-latency links. It fixes a logger deadlock and a JetStream defect involving idempotent stream creation, with no security advisories or security-specific fixes disclosed.
NATS v2.12.15 updates the Go toolchain and dependency manifests. It also fixes deadlocks in logging and a JetStream data-loss bug related to idempotent stream creation when an offline node catches up from a metalayer snapshot.
Source ↗