RATATOSKRATATOSK
Sign in

Crossplane

v2.1.8Orchestration & Management
Jul 23, 2026

Crossplane v2.1.8 is a patch release fixing a Usage controller bug where spurious owner updates triggered repeated composition reconciliations. The release also bumps the sigstore stack (cosign, rekor, timestamp-authority, sigstore-go) and gRPC/stdlib packages (golang.org/x/net, golang.org/x/text) to pull in upstream security fixes, plus Go to 1.25.12.

  • securitysigstore/cosign security update to v2.6.3

    sigstore/cosign updated to v2.6.3 to pick up upstream security fixes. The fix ships in v2.1.8 and applies to all Crossplane deployments.

  • securitySecurity bumps: gRPC, golang.org/x/net, golang.org/x/text

    grpc, golang.org/x/net, and golang.org/x/text updated to incorporate upstream CVE fixes. The fix ships in v2.1.8 and applies to all Crossplane deployments.

Key changes (4)

  • Security: sigstore/cosign updated to v2.6.3 for CVE fixes
  • Security: gRPC, golang.org/x/net, golang.org/x/text bumped for upstream CVE fixes
  • Fix: Usage controller now checks all ownerReferences, stopping spurious owner updates and reconciliation loops
  • Go toolchain bumped to 1.25.12
Add Crossplane to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack