Crossplane
v2.1.8Orchestration & ManagementCrossplane v2.1.8 is a patch release fixing a Usage controller bug where spurious owner updates triggered repeated composition reconciliations. The release also bumps the sigstore stack (cosign, rekor, timestamp-authority, sigstore-go) and gRPC/stdlib packages (golang.org/x/net, golang.org/x/text) to pull in upstream security fixes, plus Go to 1.25.12.
securitysigstore/cosign security update to v2.6.3
sigstore/cosign updated to v2.6.3 to pick up upstream security fixes. The fix ships in v2.1.8 and applies to all Crossplane deployments.
securitySecurity bumps: gRPC, golang.org/x/net, golang.org/x/text
grpc, golang.org/x/net, and golang.org/x/text updated to incorporate upstream CVE fixes. The fix ships in v2.1.8 and applies to all Crossplane deployments.
Key changes (4)
- Security: sigstore/cosign updated to v2.6.3 for CVE fixes
- Security: gRPC, golang.org/x/net, golang.org/x/text bumped for upstream CVE fixes
- Fix: Usage controller now checks all ownerReferences, stopping spurious owner updates and reconciliation loops
- Go toolchain bumped to 1.25.12
A weekly email arrives when a release needs action. Like the security patches in this release.