RATATOSKRATATOSK
Sign in

Crossplane

v2.1.4Orchestration & Management
Feb 3, 2026

ACTION 4OTHER 2

Crossplane v2.1.4 is a maintenance release with security-related dependency updates. It also includes corrections for shared transitive dependency upgrades, so the release concerns operators tracking dependency and security fixes.

Action needed (4)

  • securityThe github.com/quic-go/quic-go module, updated to v0.57.0

    The release updates the github.com/quic-go/quic-go module to v0.57.0 as a security-related dependency change.

  • securitysigstore dependency updates for CVEs

    The release updates sigstore dependencies to fix CVEs.

  • securityThe github.com/theupdateframework/go-tuf/v2 module, updated to v2.4.1

    The release updates the github.com/theupdateframework/go-tuf/v2 module to v2.4.1 as a security-related dependency change.

  • securityThe github.com/go-chi/chi/v5 module, updated to v5.2.4

    The release updates the github.com/go-chi/chi/v5 module to v5.2.4 as a security-related dependency change.

All 2 other recorded changesfixes 2

fixes (2)

  • fix one of the issues reported in #3423, where shared transitive dependencies could not be upgraded successfully
  • fix(render): propagate root composite identity through nested XR trees
Add Crossplane to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack