RATATOSKRATATOSK
Sign in

Kyverno

v1.15.3Security
Jan 27, 2026

ACTION 1OTHER 6

Kyverno v1.15.3 contains correctness fixes and a Go toolchain update that addresses standard library CVEs. It also changes enforcement behavior around namespaces, labels, and context size.

Action needed (1)

  • securityThe Go toolchain version, updated for standard library CVEs

    The Go toolchain version is updated to address standard library CVEs. The update ships in Kyverno v1.15.3.

All 6 other recorded changesadditions 3 · fixes 2

additions (3)

  • * Backport label exclusion to 1.15 by @aerosouund in https://github.com/kyverno/kyverno/pull/14178
  • * add check for namespace (Cherry-pick #14109) by @kyverno-bot in https://github.com/kyverno/kyverno/pull/14114
  • * feat(engine): add context size limit by @realshuting in https://github.com/kyverno/kyverno/pull/14846

fixes (2)

  • * fix(controllers): stop status-driven hot-loops (cherry pick #14096) by @fjogeleit in https://github.com/kyverno/kyverno/pull/14095
  • * fix(chart): correct background-controller automountServiceAccount logic (Cherry-pick #13878) by @kyverno-bot in https://github.com/kyverno/kyverno/pull/14104
Add Kyverno to your stack

A weekly email arrives when a release needs action. Like the security patches in this release.

Add to stack