Kyverno
v1.15.3SecurityJan 27, 2026
Kyverno v1.15.3 contains correctness fixes and a Go toolchain update that addresses standard library CVEs. It also changes enforcement behavior around namespaces, labels, and context size.
Action needed (1)
securityThe Go toolchain version, updated for standard library CVEs
The Go toolchain version is updated to address standard library CVEs. The update ships in Kyverno v1.15.3.
All 6 other recorded changesadditions 3 · fixes 2
additions (3)
- * Backport label exclusion to 1.15 by @aerosouund in https://github.com/kyverno/kyverno/pull/14178
- * add check for namespace (Cherry-pick #14109) by @kyverno-bot in https://github.com/kyverno/kyverno/pull/14114
- * feat(engine): add context size limit by @realshuting in https://github.com/kyverno/kyverno/pull/14846
fixes (2)
- * fix(controllers): stop status-driven hot-loops (cherry pick #14096) by @fjogeleit in https://github.com/kyverno/kyverno/pull/14095
- * fix(chart): correct background-controller automountServiceAccount logic (Cherry-pick #13878) by @kyverno-bot in https://github.com/kyverno/kyverno/pull/14104
Add Kyverno to your stack
A weekly email arrives when a release needs action. Like the security patches in this release.