Crossplane
v2.1.4Orchestration & ManagementCrossplane v2.1.4 is a maintenance release with security-related dependency updates. It also includes corrections for shared transitive dependency upgrades, so the release concerns operators tracking dependency and security fixes.
Action needed (4)
securityThe
github.module, updated tocom/quic-go/quic-go v0.57. 0 The release updates the
github.module tocom/quic-go/quic-go v0.as a security-related dependency change.57. 0 security
sigstoredependency updates for CVEsThe release updates
sigstoredependencies to fix CVEs.securityThe
github.module, updated tocom/theupdateframework/go-tuf/v2 v2.4. 1 The release updates the
github.module tocom/theupdateframework/go-tuf/v2 v2.as a security-related dependency change.4. 1 securityThe
github.module, updated tocom/go-chi/chi/v5 v5.2. 4 The release updates the
github.module tocom/go-chi/chi/v5 v5.as a security-related dependency change.2. 4
All 2 other recorded changesfixes 2
fixes (2)
- fix one of the issues reported in #3423, where shared transitive dependencies could not be upgraded successfully
- fix(render): propagate root composite identity through nested XR trees
A weekly email arrives when a release needs action. Like the security patches in this release.