RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Rookv1.19.9Storage & DataAug 19, 2026

A maintenance release with security guidance for CVE-2025–30156 and updates across Ceph authentication, core behavior, Multus networking, and the Ceph base image. The release also includes a workaround for a Ceph authentication rotation race.

Action needed (1)

  • securityCVE-2025–30156 upgrade guidance

    Rook users are advised to upgrade to Rook v1.20.5 or v1.19.9 with Ceph v20.2.4 or v19.2.6 in response to CVE-2025–30156.

Source
Rookv1.19.8Storage & DataJul 28, 2026

v1.19.8 is a maintenance release with a security-related dependency update and behavioral improvements. The recorded dependency change updates the vulnerable go text package from v0.37 to a newer version.

Action needed (1)

  • securityThe go text package, updated from v0.37

    The go text package is updated from v0.37 to the latest version because v0.37 has a vulnerability. This dependency update ships in v1.19.8.

Source
TiKVv8.5.7Storage & DataJul 9, 2026

A feature and maintenance release with new configuration and resource-management capabilities, plus corrections for invalid timestamp handling, memory use, and stability. It also upgrades vulnerable third-party dependencies and aligns compatibility fixes with upstream.

Action needed (1)

  • securityThird-party dependency upgrades for TiKV 8.5

    TiKV 8.5 upgrades vulnerable third-party dependencies and aligns the required compatibility fixes with upstream.

Check if affected (1)

  • breakingInvalid max_ts updates rejected by default

    Applies if you do not set storage.max-ts.action-on-invalid-update.

Source
Harborv2.15.2Storage & DataJul 2, 2026

A maintenance release with a forced internal PostgreSQL major-version upgrade, a redis to valkey cache backend replacement, dependency and component updates, and defect corrections. Token and blob-mount validation is hardened.

Action needed (1)

  • securityToken and blob-mount source validation

    Blob-mount source projects are validated, and tokens without iat are rejected.

Check if affected (2)

  • breakingThe bundled PostgreSQL version, upgraded

    Applies if you use PostgreSQL.

  • breakingThe cache backend, changed from redis to valkey

    Applies if you use redis.

Source
Rookv1.19.6Storage & DataMay 27, 2026

This release includes a security-related dependency update in CI. The change affects builds that use golang.org/x/net.

Action needed (1)

  • securitycriticalThe golang.org/x/net dependency, updated to v0.55.0

    CI updates golang.org/x/net from its previous version to v0.55.0 to fix GO-2026-5026.

Source
Harborv2.15.1Storage & DataMay 6, 2026

Harbor v2.15.1 is a maintenance release with defect corrections, behavior changes, and dependency and base-image updates. It also updates photon packages to fix CVEs.

Action needed (1)

  • securityphoton packages CVE fixes

    The photon packages are updated to fix CVEs in Harbor v2.15.1.

Source
Vitessv24.0.0Storage & DataApr 30, 2026

A broad feature and maintenance release adds routing, streaming, tracing, backup and restore, observability, and tablet-management capabilities alongside correctness, performance, and dependency updates. Operators should review changed defaults, backup behavior, removed endpoints and metrics, deprecated features, and security fixes affecting external decompression.

Action needed (3)

  • securityClear-text logging of sensitive information

    The release addresses a code scanning alert about clear-text logging of sensitive information.

  • securityDirectory traversal protection in GetBackups

    The file backup storage GetBackups RPC no longer permits directory traversal paths.

  • breakingStricter VTGate SELECT list validation

    VTGate rejects an unqualified * after a comma in a SELECT list.

Check if affected (12)

  • securityOpt-in compressor commands from MANIFEST

    Applicability is not stated in the release notes.

  • securityExternal decompressor commands from backup MANIFEST

    Applies if you use backup storage.

  • securityBackup MANIFEST path traversal protection

    Applies if backupengine runs.

  • + 9 more on the release page

Plan ahead (4)

  • deprecatedThe glog deprecationremoval planned in v25

    Applies if you use glog.

  • deprecatedThe OpenTracing backend deprecationsremoval planned in v25

    Applies if you use opentracing-jaeger or opentracing-datadog.

  • deprecatedVTOrc Snapshot Topology deprecationremoval planned in v25

    Applies if you configure --snapshot-topology-interval.

  • + 1 more on the release page
Source
Harborv2.15.0Storage & DataMar 20, 2026

A feature and compatibility release adds registry, cache, signing, profiling, and configuration capabilities. It changes proxy-cache behavior, removes GCR replication, and includes dependency, base-component, and defect corrections.

Action needed (2)

  • securityBearer token validation

    Harbor rejects bearer tokens issued before project creation.

  • breakingPort 9443 removed from the webhook event check

    Port 9443 is removed from the Harbor IP used for webhook event checks.

Check if affected (2)

  • breakingThe pull-through cache is replaced by proxy cache

    Applies if you use pull-through cache in Harbor.

  • breakingGCR replication removal

    Applies if you use GCR replication in Harbor.

Source
Harborv2.13.5Storage & DataMar 10, 2026

Bearer tokens issued before project creation are rejected. The release also updates dependencies and components and removes payload data from the configuration audit log.

Action needed (1)

  • securityRejection of bearer tokens issued before project creation

    The security enforcement rejects bearer tokens issued before project creation.

Source
Harborv2.14.3Storage & DataMar 10, 2026

This release updates base images, dependencies, and Trivy components, and changes the audit-log payload. It also rejects bearer tokens issued before project creation.

Action needed (1)

  • securityBearer tokens issued before project creation rejected

    The security fix rejects bearer tokens issued before project creation.

Source
Vitessv23.0.1Storage & DataFeb 4, 2026

Vitess v23.0.1 is a maintenance release focused on bug fixes and behavior corrections. It also adds CLI and TabletManager capabilities and updates dependencies.

Action needed (1)

  • securityThe golang.org/x/crypto dependency, updated

    Vitess v23.0.1 updates golang.org/x/crypto from 0.42.0 to 0.45.0.

Source
Longhornv1.11.0Storage & DataJan 29, 2026

A substantial feature and maintenance release with V2 Data Engine changes, new capabilities, dependency updates, numerous fixes, and hotfix image replacements. It also deprecates V2 Backing Image functionality and includes a fix for an SPDK v25.05 CVE issue without a disclosed advisory identifier.

Action needed (1)

  • securityThe SPDK v25.05 CVE issue fix

    The CVE issue in SPDK v25.05 is fixed in this release.

Check if affected (7)

  • breakingThe longhornio/longhorn-instance-manager:v1.11.0 image replacement

    Applies if you use longhornio/longhorn-instance-manager:v1.11.0.

  • breakingThe longhornio/longhorn-manager:v1.11.0 image replacement

    Applies if you use longhornio/longhorn-manager:v1.11.0.

  • breakingBackupstore-related settings removal

    Applies if you configure backupstore related settings.

  • + 4 more on the release page

Plan ahead (2)

  • deprecatedBacking Image for the V2 Data Engine deprecationremoval planned in v1.12.0

    Applies if you use Backing Image and the V2 Data Engine.

  • deprecatedV2 Backing Image Feature deprecation

    Applies if you use the V2 Backing Image Feature.

Source
Browse by month