RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

May 2026Clear ×
OpenCostv1.120.3ObservabilityMay 29, 2026

A maintenance release with dependency updates, correctness fixes, and new cloud and query capabilities. Configuration and output behavior also change, along with a Go dependency upgrade for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.

Action needed (1)

  • securityhighGo dependency upgrades for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986

    Go dependencies are upgraded for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.

Check if affected (1)

  • breakingThe MCP_SERVER_ENABLED default is false

    Applies if you do not configure MCP_SERVER_ENABLED.

Source
Prometheusv3.12.0ObservabilityMay 28, 2026

A feature and maintenance release with new operator-facing APIs, discovery integrations, feature flags, configuration options, and UI capabilities. It also addresses disclosed security issues, correctness and performance problems, and validation or constraint behavior.

Action needed (1)

  • breakingConcurrent fgprof profile rejection

    The API rejects concurrent fgprof profiles.

Check if affected (3)

  • securityRemote Write decoded-length constraint

    Applies if you use Remote Write.

  • securityPlaintext secret exposure in STACKIT SD

    Applies if you use STACKIT SD.

  • breakingDecompressed body-size limit for OTLP write requests

    Applies if you use OTLP.

Source
OpenCostv1.120.2ObservabilityMay 18, 2026

A maintenance release with dependency updates, operator-visible configuration and behavior changes, new integrations and capabilities, and correctness fixes. It also includes an explicitly disclosed security-related Go dependency upgrade.

Action needed (1)

Check if affected (2)

  • breakingThe provider config source, changed

    Applies if you configure provider config.

  • breakingThe MCP_SERVER_ENABLED default, changed to false

    Applies if you use the MCP server.

Source
Litmus3.29.0ObservabilityMay 18, 2026

Litmus 3.29.0 includes operator-facing changes across dependencies and platform behavior. This release includes a google.golang.org/grpc update to v1.79.3 for CVE-2026-33186.

Action needed (1)

  • securitycriticalThe google.golang.org/grpc dependency, updated for CVE-2026-33186

    The release updates google.golang.org/grpc to v1.79.3. The dependency update addresses CVE-2026-33186 in Litmus 3.29.0.

Source
Jaegerv2.18.0ObservabilityMay 13, 2026

A release with breaking removals, API and metric changes, bug corrections, and experimental capabilities. It also adds storage, MCP, UI, and tracing functionality, with no security advisories or security-specific fixes disclosed.

Action needed (2)

  • breakingThe min step api in metricstore, removed

    The min step api was removed from metricstore in this release.

  • breakingThe non-standard health MCP tool, removed

    The non-standard health MCP tool was removed from jaegermcp in this release.

Source
Browse by month