RATATOSKRATATOSK
Sign in

Crossplane

v2.2.4Orchestration & Management
Jul 23, 2026

Crossplane v2.2.4 is a security patch addressing multiple medium-severity dependency vulnerabilities in cosign, gRPC, and Go standard libraries (x/net, x/text), plus a fix for Usage controller reconciliation that was checking only the first ownerReference and causing repeated updates on composed resources.

  • securitysigstore cosign security update to v3.0.6

    sigstore cosign dependency updated to v3.0.6 to address security vulnerabilities. The fix ships in v2.2.4 and applies to all Crossplane deployments using the signing and verification features.

  • securitygRPC and standard library security updates

    gRPC, golang.org/x/net, and golang.org/x/text dependencies updated for security fixes. The updates ship in v2.2.4 and apply unconditionally across Crossplane.

Key changes (4)

  • Security: cosign, gRPC, x/net, and x/text dependencies patched for medium-severity vulnerabilities
  • Usage controller now checks all ownerReferences when determining spec.by resource ownership, preventing repeated reconciliation cycles and XR circuit breaker trips for composed Usages
  • sigstore stack (rekor, timestamp-authority, sigstore-go) updated alongside cosign
  • Container images built with buildGoModule to enable standard vulnerability scanning
Add Crossplane to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack