Argo
v3.3.14CI/CD & App DeliveryArgo v3.3.14 is a maintenance release with fixes for secret handling and pprof configuration, along with dependency updates tied to two CVEs. The secret-handling fixes and dependency updates are most relevant to deployments that use the affected interfaces or dependencies.
Action needed (2)
securityhigh
brace-expansion2.1.4 and 1.1.18 for CVE-2026-69152Argo v3.3.14 updates
brace-expansionto 2.1.4 and 1.1.18 in/uifor CVE-2026-69152.securitymedium
DOMPurify3.4.7 for CVE-2026-49978Argo v3.3.14 updates
DOMPurifyto 3.4.7 for CVE-2026-49978.
Check if affected (2)
securityThe
SSD CLIsecret mask, spoofing preventedApplies if you use the
SSD CLI.The server-side
SSD CLIsecret masking fix prevents secret mask spoofing in Argo v3.3.14.securityThe
last-applied-configurationannotation, secret hiddenApplies if your workflows use the
last-applied-configurationannotation.The
ssdfix hides secrets in thelast-applied-configurationannotation in Argo v3.3.14.
All 2 other recorded changesfixes 2
fixes (2)
- * 7242ed2d3cd3a5bb106a1922834244977de83b9f: fix(controller): reuse server-side diff result when masking Secret data (#27858) (#29076) (@1ovsss)
- * 80f08f9de360a22abbb314a5b6b18a71b9a4140c: fix: register pprof endpoints in repo-server using the params config map (cherry-pick #26237 for 3.3) (#29032) (@gdsoumya)
A weekly email arrives when a release needs action. Like the security patches in this release.