Argo
v3.4.8CI/CD & App DeliveryAug 27, 2026
A maintenance release focused on correctness fixes and security-related dependency updates. No configuration or default changes are documented.
Action needed (3)
securityhighThe
/uibrace-expansiondependency is updated for CVE-2026-14257 and CVE-2026-69152In
/ui, this release updatesbrace-expansionto versions 2.1.4 and 1.1.18 for CVE-2026-14257 and CVE-2026-69152.securityhighThe
js-yamldependency is updated for CVE-2026-59869This release updates the
js-yamldependency to address CVE-2026-59869.securitymediumThe
DOMPurifydependency is updated to 3.4.7 for CVE-2026-49978This release updates the
DOMPurifydependency to 3.4.7 for CVE-2026-49978.
All 4 other recorded changesfixes 4
fixes (4)
- * 90f81d5bc27491a97fb6d0ab0dc284a69ed14a08: fix(revert): auto-sync skipped when newer commit arrives during sync (cherry-pick #28692 for 3.4) (#29225) (@rumstead)
- * 924ab35b93689ddba28731bdaa45a189ac653ddc: fix: don't degrade Cluster API Cluster health while Ready is False during provisioning (cherry-pick #29237 for 3.4) (#29274) (@argo-cd-cherry-pick-bot[bot])
- * 9c771f6f7cbd4448fef1a11fb03be7579c1e2fd3: fix(notification-controller): deep-copy before mutating object from a shared cache (cherry-pick #29350 for 3.4) (#29353) (@argo-cd-cherry-pick-bot[bot])
- * bad3c481d2ceeaff1ad0e48b6c7c9fe23f77f118: fix(notification-controller): read appprojects from informer cache (#28815) (cherry-pick release-3.4) (#29346) (@antonu17)
Add Argo to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.