RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Sep 2026Clear ×
Crossplanev2.4.1Orchestration & ManagementYesterdaySep 15, 2026

A maintenance release with a package-revision handoff fix and dependency security updates. It includes the gRPC advisory GHSA-2v4p-qf9q-27wj and refreshes the Go toolchain and related dependencies.

Action needed (3)

  • securityhighgoogle.golang.org/grpc update for GHSA-2v4p-qf9q-27wj

    google.golang.org/grpc is updated to v1.83.2 to pick up upstream fixes, including advisory GHSA-2v4p-qf9q-27wj. The update ships with the release's dependency security refresh.

  • securityThe Go toolchain update

    The Go toolchain is updated to 1.26.7 as part of the dependency security updates. The release also updates google.golang.org/grpc to v1.83.2, golang.org/x/crypto to v0.56.0, github.com/crossplane/crossplane/apis/v2 to v2.4.0, and refreshes the lock file.

  • securitygolang.org/x/crypto update

    golang.org/x/crypto is updated to v0.56.0 as part of the dependency security updates. The same refresh updates the Go toolchain to 1.26.7, google.golang.org/grpc to v1.83.2, and refreshes the lock file.

Source
Crossplanev2.3.6Orchestration & ManagementYesterdaySep 15, 2026

A maintenance release fixes package-revision handoff failures and updates security-sensitive dependencies. It adds no newly announced operator configuration requirements.

Action needed (2)

  • securityThe golang.org/x/crypto dependency update

    The golang.org/x/crypto module is updated to v0.56.0 for a security-related dependency change.

  • securityThe google.golang.org/grpc dependency update

    The google.golang.org/grpc module is updated to v1.83.2 for a security-related dependency change.

Source
Crossplanev2.2.6Orchestration & ManagementYesterdaySep 15, 2026

A security-focused maintenance release with updates to the Go toolchain and dependencies for upstream CV fixes. Package-revision handoffs are also corrected so incoming revisions can take control of established objects without manual intervention.

Action needed (3)

  • securityhighThe google.golang.org/grpc update for GHSA-2v4p-qf9q-27wj

    google.golang.org/grpc is updated to v1.83.2 to pick up upstream CVE fixes, including advisory GHSA-2v4p-qf9q-27wj. The updated dependency ships in this release.

  • securityThe Go toolchain security update

    The Go toolchain is updated to 1.26.7 to pick up upstream CVE fixes. The lock file is also refreshed.

  • securityThe golang.org/x/crypto security update

    golang.org/x/crypto is updated to v0.56.0 to pick up upstream CVE fixes. The updated dependency ships in this release.

Source
Crossplanev1.20.13Orchestration & ManagementYesterdaySep 15, 2026

A security-focused maintenance release updates the Go toolchain and dependencies. It includes upstream vulnerability fixes, including a disclosed gRPC advisory.

Action needed (2)

  • securityhighgoogle.golang.org/grpc update and GHSA-2v4p-qf9q-27wj fixes

    The release updates google.golang.org/grpc to v1.83.2 and includes a combined set of vulnerable dependency updates for upstream CVE fixes. This includes the gRPC advisory GHSA-2v4p-qf9q-27wj.

  • securityGo toolchain update to 1.26.7

    The release bumps the Go toolchain to 1.26.7.

Source
Daprv1.18.4Orchestration & ManagementSep 9, 2026

A workflow-heavy maintenance release corrects reliability, state-management, signing, and pub/sub delivery defects. It also changes binary gRPC metadata filtering for output bindings, with no newly announced operator configuration requirements.

Action needed (1)

  • breakingBinary gRPC metadata propagation in InvokeBinding, removed

    Binary gRPC metadata with keys ending in -bin is no longer copied from incoming gRPC calls into output binding component metadata for InvokeBinding.

Source
wasmCloudv2.9.0Orchestration & ManagementSep 8, 2026

A feature release that adds plugin, runtime, concurrency, and observability capabilities. It also corrects runtime defects and enforces guest-memory limits.

Action needed (1)

  • breakingThe max-guest-memory limit is enforced

    This release enforces the max-guest-memory limit.

Plan ahead (1)

  • deprecatedThe deprecated --enable-meters flag alias

Source
Browse by month