RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jul 2026Clear ×
Prometheusv3.13.2ObservabilityJul 30, 2026

Prometheus v3.13.2 updates dependencies for two disclosed vulnerabilities and includes related transitive dependency upgrades. It also fixes a PromQL SIGBUS crash when the data disk is full.

Action needed (2)

  • securityhighgolang.org/x/text update for CVE-2026-56852

    golang.org/x/text updates from v0.38.0 to v0.39.0 in Prometheus v3.13.2 for CVE-2026-56852.

  • securityhighgoogle.golang.org/grpc update for GHSA-hrxh-6v49-42gf

    google.golang.org/grpc updates from v1.81.1 to v1.82.1 in Prometheus v3.13.2 for GHSA-hrxh-6v49-42gf.

Source
Jaegerv2.20.0ObservabilityJul 20, 2026

A release with backend compatibility removals, forced migrations, new configuration and CLI capabilities, and correctness fixes across storage, extensions, and related components. It does not disclose security advisories or security-specific flaws.

Action needed (1)

  • breakingTemplate creation through esclient

    Template creation moves to esclient, and legacy mapping rendering is retired.

Check if affected (3)

  • breakingSupport for elasticsearch v6, removed

    Applies if you use elasticsearch v6.

  • breakingThe jaegermcp extension, merged into jaegerquery

    Applies if you use the jaegermcp extension.

  • breakingExpired stable feature gates, removed

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedThe legacy flag, deprecated

    Applies if you use legacy flag.

Source
Litmus3.31.0ObservabilityJul 15, 2026

Release 3.31.0 contains a dependency update addressing vulnerabilities in graphql/server. It also includes correctness fixes across probes, GraphQL, authentication, infrastructure, and experiment handling.

Action needed (1)

  • securityDependencies in graphql/server updated

    Dependencies in graphql/server are updated to fix vulnerabilities. The update ships in Release 3.31.0.

Source
Prometheusv3.5.5ObservabilityJul 9, 2026

Prometheus v3.5.5 includes a Go 1.25.12 toolchain change and a disclosed security fix in the UI. The security fix concerns the sanitize-html dependency and CVE-2026-53606.

Action needed (1)

  • securitymediumThe sanitize-html dependency update for CVE-2026-53606

    The Prometheus UI updates sanitize-html to v2.17.5 to fix CVE-2026-53606.

Source
Thanosv0.42.0ObservabilityJul 8, 2026

A release with security corrections, breaking configuration removals, and an output-field rename that may require operator or log-collector changes. It also adds TLS and cache configuration, query and tracing changes, and defect fixes across several Thanos components.

Action needed (1)

  • securitycriticalthanos-community/grpc-go fork update for CVE-2026-33186

    The thanos-community/grpc-go fork is bumped to fix CVE-2026-33186, an authorization bypass via malformed :path headers.

Check if affected (4)

  • securityReceive tenant ID validation

    Applies if you run Receive.

  • breakingQuery-Frontend time_taken field renamed to time_taken_ms

    Applies if you run Query-Frontend.

  • breaking--shipper.ignore-unequal-block-size flag removed

    Applies if you configure --shipper.ignore-unequal-block-size.

  • + 1 more on the release page
Source
Prometheusv3.13.0ObservabilityJul 1, 2026

A long-term support release with security-related dependency updates, PromQL changes, new APIs and configuration controls, and bug fixes. It also replaces a shipped license artifact and includes performance improvements.

Action needed (2)

  • securitycriticalThe sanitize-html dependency update

    The UI updates sanitize-html to address a cross-site scripting vulnerability, identified as CVE-2026-44990.

  • breakingThe third-party license artifact

    Third-party npm dependency licenses are embedded in the Prometheus binary and served at /assets/third-party-licenses.txt. This replaces the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images.

Check if affected (2)

  • securitymediumRedirect credential forwarding

    Applies if you use scraping, remote read/write, alerting, or service discovery.

  • breakingPromQL duration-expression function names

    Applies if you enable experimental-duration-expr and use min() and max().

Source
Browse by month