RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Apr 2026Clear ×
OpenFeaturecore/v0.15.5CI/CD & App DeliveryApr 30, 2026

OpenFeature core/v0.15.5 is a maintenance release with operator-relevant corrections and a security-related dependency update. The security announcement does not identify a specific advisory in the release text.

Action needed (1)

  • securityOpen Dependabot security alerts resolved

    Open Dependabot security alerts were resolved in the OpenFeature core release.

Source
OpenFeatureflagd-proxy/v0.9.5CI/CD & App DeliveryApr 30, 2026

This release resolves open Dependabot security alerts in the flagd proxy. The release note does not identify which vulnerabilities or dependencies were fixed.

Action needed (1)

  • securityDependabot security alerts resolved

    The flagd-proxy/v0.9.5 release resolves open Dependabot security alerts. The release note does not identify the affected dependencies or vulnerabilities.

Source
Argov3.3.9CI/CD & App DeliveryApr 30, 2026

v3.3.9 is a maintenance release with a disclosed security fix and a go version update to resolve CVEs. It also includes bug fixes in the release.

Action needed (2)

  • securitycriticalGHSA-3v3m-wc6v-x4x3 security fix

    This release fixes the vulnerability identified by GHSA-3v3m-wc6v-x4x3.

  • securityThe go version update for CVE resolution

    The go version is bumped to resolve CVEs in v3.3.9.

Source
Argov3.2.11CI/CD & App DeliveryApr 30, 2026

Version v3.2.11 includes a disclosed security fix and additional correctness and dependency updates. The security fix is the release change that concerns users evaluating whether to upgrade.

Action needed (1)

  • securitycriticalSecurity fix for GHSA-3v3m-wc6v-x4x3

    Version v3.2.11 contains a security fix for the vulnerability identified by GHSA-3v3m-wc6v-x4x3.

Source
Vitessv24.0.0Storage & DataApr 30, 2026

A broad feature and maintenance release adds routing, streaming, tracing, backup and restore, observability, and tablet-management capabilities alongside correctness, performance, and dependency updates. Operators should review changed defaults, backup behavior, removed endpoints and metrics, deprecated features, and security fixes affecting external decompression.

Action needed (3)

  • securityClear-text logging of sensitive information

    The release addresses a code scanning alert about clear-text logging of sensitive information.

  • securityDirectory traversal protection in GetBackups

    The file backup storage GetBackups RPC no longer permits directory traversal paths.

  • breakingStricter VTGate SELECT list validation

    VTGate rejects an unqualified * after a comma in a SELECT list.

Check if affected (12)

  • securityOpt-in compressor commands from MANIFEST

    Applicability is not stated in the release notes.

  • securityExternal decompressor commands from backup MANIFEST

    Applies if you use backup storage.

  • securityBackup MANIFEST path traversal protection

    Applies if backupengine runs.

  • + 9 more on the release page

Plan ahead (4)

  • deprecatedThe glog deprecationremoval planned in v25

    Applies if you use glog.

  • deprecatedThe OpenTracing backend deprecationsremoval planned in v25

    Applies if you use opentracing-jaeger or opentracing-datadog.

  • deprecatedVTOrc Snapshot Topology deprecationremoval planned in v25

    Applies if you configure --snapshot-topology-interval.

  • + 1 more on the release page
Source
Karmadav1.17.2Orchestration & ManagementApr 30, 2026

v1.17.2 contains correctness fixes and a security-related Alpine base-image dependency update. The alpine update requires upgrading to receive the new base image.

Action needed (1)

  • securityThe alpine base image, updated to alpine:3.23.4

    The base image alpine has been updated from alpine:3.23.3 to alpine:3.23.4 to address security concerns. The update ships in v1.17.2.

Source
Karmadav1.15.8Orchestration & ManagementApr 30, 2026

A maintenance release includes corrected operator and scheduler behavior, along with an updated Alpine base image. The Alpine update addresses security concerns.

Action needed (1)

  • securityThe alpine base image, updated

    The base image alpine was updated from alpine:3.23.3 to alpine:3.23.4 to address security concerns. The update ships in the release.

Source
KServev0.18.0AI & MLApr 29, 2026

A release with operator-facing fixes, new capabilities, API and configuration changes, and dependency updates. It also includes fixes for CVE-2026-32597 in PyJWT and CVE-2026-30922 in pyasn1.

Action needed (3)

  • securityhighCVE-2026-32597 PyJWT validation fix

    PyJWT crit header validation was fixed for CVE-2026-32597.

  • securityhighCVE-2026-30922 pyasn1 fix

    The pyasn1 dependency was updated to address CVE-2026-30922 and its denial-of-service vulnerability.

  • breakingRequired MaxReplicas field

    MaxReplicas is now required and must use the int32 type.

Check if affected (2)

  • breakingRemoval of the scheduler cert-hash restart annotation

    Applies if you configure cert-hash.

  • breakingPYTHONPATH blocked by ISVC and ServingRuntime webhooks

    Applies if you configure PYTHONPATH.

Source
Kyvernov1.18.0SecurityApr 29, 2026

A substantial feature and maintenance release with new operator capabilities plus configuration, Helm, and CLI improvements. It also includes defect, output, dependency, and security fixes, including remediation for several CVE-related issues.

Action needed (4)

  • securityhighIntermediate certificate limit for CVE-2026-32280

    Intermediate certificates are limited to mitigate CVE-2026-32280 in this release.

  • securityhighGo toolchain upgraded to 1.26.2 for CVE-2026-32283

    The Go toolchain is upgraded to 1.26.2 to fix CVE-2026-32283.

  • securitymediumgo-tuf/v2 upgraded to v2.4.1 for CVE-2026-24686

    go-tuf/v2 is upgraded to v2.4.1 to fix CVE-2026-24686.

  • securityStandard library CVE fixes

    Standard library CVEs are fixed in this release.

Check if affected (2)

  • breakingRestricted ConfigMap access for namespaced policies

    Applies if you use namespaced policies.

  • breakingFinalizers and uninstall workarounds removed

    Applies if uninstall runs.

Source
NATSv2.12.8Networking & MessagingApr 27, 2026

A maintenance release with a security fix, correctness fixes, a performance improvement, and dependency and toolchain manifest updates. Most changes take effect through the release itself without additional operator action.

Action needed (1)

  • securityBearer JWT disclosure fix in /connz

    The /connz monitoring endpoint no longer discloses bearer JWTs. The fix ships in the NATS monitoring endpoint.

Source
OpenFGAv1.15.0SecurityApr 27, 2026

This release updates the Go toolchain alongside changes to authorization behavior. The Go update addresses standard library vulnerabilities documented in the Go 1.26.2 release notes.

Action needed (1)

  • securityThe Go toolchain version, updated to 1.26.2

    The toolchain Go version is updated to 1.26.2 to address Go standard library vulnerabilities documented in the Go 1.26.2 release notes.

Source
Flatcar Container Linuxlts-4081.3.7Provisioning & RuntimeApr 27, 2026

This is primarily a security-focused Flatcar release with a large set of disclosed Linux fixes. It also includes a QEMU launcher performance correction and updates to Linux and ca-certificates dependencies.

Action needed (1)

  • securitycriticalLinux security fixes

    Linux is updated with fixes for the disclosed advisories, including CVE-2023-52435, the CVE-2025-* and CVE-2026-* advisories listed for this release. The fixes ship in Flatcar lts-4081.3.7.

Source
Flatcar Container Linuxstable-4593.2.0Provisioning & RuntimeApr 27, 2026

A security- and maintenance-focused release with updates to Linux and bundled components, along with dependency updates. It also corrects minimal-initrd regressions and changes service startup, SSH defaults, kernel-module availability, and other operator-visible behavior and layout.

Action needed (18)

Check if affected (1)

  • breakingAutomatic startup for overlaybd sysext services

    Applies if you use the overlaybd sysext.

Source
wasmCloudv2.0.5Orchestration & ManagementApr 24, 2026

This release adds the Val map type, Linux glibc GPU builds, and updates to wasmtime and its rustls dependency. It also corrects pooling allocator probing and includes a security update for rustls-webpki.

Action needed (1)

  • securityrustls-webpki security update, RUSTSEC-2026-0049

    The release includes a security update for rustls-webpki, addressing RUSTSEC-2026-0049.

Source
Crossplanev1.20.7Orchestration & ManagementApr 24, 2026

This release updates the Go toolchain in Crossplane to 1.25.9. The change addresses undisclosed standard-library CVEs.

Action needed (1)

  • securityThe Go toolchain, updated to 1.25.9

    Crossplane v1.20.7 updates the Go toolchain to 1.25.9. The update addresses undisclosed standard-library CVEs.

Source
Envoyv1.38.0Networking & MessagingApr 23, 2026

A release with breaking configuration and flag changes, many new extension and protocol capabilities, and fixes for security, correctness, and observability. The recorded additions include module and filter extension APIs, MCP and A2A protocol support, OpenSSL builds, new formatters and metrics, and expanded streaming and TLS capabilities.

Action needed (1)

  • securityhighnghttp2 **CVE-2026-27135** patch

    The nghttp2 **CVE-2026-27135** patch is included.

Check if affected (6)

  • securityURL encoding for query_parameter_mutations values

    Applies if you configure query_parameter_mutations.

  • securityRBAC concatenation-based bypass prevention

    Applies if RBAC runs.

  • breakingExplicit max_early_data_bytes configuration

    Applies if you configure upstream_connect_mode with a value other than IMMEDIATE and do not configure max_early_data_bytes.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe enforce_rsa_key_usage option, deprecatedremoval date not announced

    Applies if you configure enforce_rsa_key_usage.

Source
Kyvernov1.16.4SecurityApr 23, 2026

A security-fix release with fixes for multiple CVEs and updates to affected dependencies. It also changes the default HTTP behavior and restricts configmap access for namespaced policies.

Action needed (12)

  • securitycriticalCVE-2025-68121 fix

    This release fixes CVE-2025-68121.

  • securitycriticalCVE-2026-33186 fix

    This release fixes CVE-2026-33186.

  • securityhighCVE-2026-24051 fix

    This release fixes CVE-2026-24051 in the 1.16 release line.

  • securityhighThe github.com/docker/cli dependency update

    The github.com/docker/cli dependency is updated to resolve CVE-2025-15558.

  • securityhighCVE-2025-66564 fix

    This release resolves CVE-2025-66564.

  • securitymediumThe sigstore/rekor dependency update to v1.5.1

    The sigstore/rekor dependency is updated to v1.5.1 to fix CVE-2026-23831.

  • securitymediumThe go-tuf/v2 dependency update to v2.3.1

    The go-tuf/v2 dependency is updated to v2.3.1 to address CVE-2026-23992.

  • securitymediumCVE-2026-22772 fix

    This release fixes CVE-2026-22772.

  • securitymediumThe go-tuf/v2 dependency update to v2.4.1

    The go-tuf/v2 dependency is updated to v2.4.1 to patch CVE-2026-24686.

  • securitylowCVE-2026-1229 fix

    This release fixes CVE-2026-1229 in the 1.16 release line.

  • securitylowCVE-2026-26958 fix

    This release fixes CVE-2026-26958.

  • securityStandard library CVE fixes

    This release fixes standard library CVEs.

Check if affected (3)

  • securitycriticalHTTP disabled by default in namespaced policies

    Applies if you configure namespaced policies.

  • securityCVE fixes for go < 1.25.8

    Applies if you depend on go < 1.25.8.

  • breakingRestricted configmap access for namespaced policies

    Applies if you configure namespaced policies.

Source
Kyvernov1.17.2SecurityApr 23, 2026

A maintenance release with multiple correctness fixes and security fixes, including changes for several CVEs and standard library CVEs. Operators should account for the changed HTTP default and narrower configmap access in addition to the security fixes.

Action needed (6)

  • securitycriticalCVE-2026-33186 correction

    The release fixes CVE-2026-33186.

  • securityhighCVE-2026-24051 correction

    The release fixes CVE-2026-24051 in the 1.17 release line.

  • securityhighCVE-2026-34986 correction

    The release fixes CVE-2026-34986.

  • securitylowCVE-2026-1229 correction

    The release fixes CVE-2026-1229.

  • securityCVES 2026-15558 correction

    The release includes the CVES 2026-15558 fix for 1.17.

  • securityGo version update

    The Go version was bumped to fix standard library CVEs.

Check if affected (2)

  • securitycriticalHTTP default for namespaced policies

    Applies if you configure namespaced policies.

  • breakingConfigmap access for namespaced policies

    Applies if you configure namespaced policies.

Source
CoreDNSv1.14.3Kubernetes CoreApr 22, 2026

A maintenance release that adds operator-facing options and transport, plugin, and protocol support while correcting defects. It is built with Go 1.26.2, which contains fixes for disclosed CVEs; other changes concern operators using the affected features or behaviors.

Action needed (1)

Check if affected (1)

  • breakingOversized DoH GET query parameter rejection

    Applies if you use DoH.

Source
cert-managerv1.19.5SecurityApr 21, 2026

This release contains security-related updates to Go dependencies and the Go toolchain. It concerns deployments that rely on the affected dependencies or the bundled Go toolchain.

Action needed (2)

  • securityGo dependencies with reported vulnerabilities updated

    Go dependencies with reported vulnerabilities are updated in cert-manager v1.19.5.

  • securityThe go toolchain updated to 1.25.8

    The go toolchain is updated to 1.25.8 in cert-manager v1.19.5 to address reported vulnerabilities.

Source
Contourv1.32.5Networking & MessagingApr 20, 2026

Contour v1.32.5 fixes a Lua code injection vulnerability and upgrades Envoy to v1.34.14. The release also includes an informational Kubernetes compatibility update.

Action needed (1)

  • securityhighCVE-2026-41246 Lua code injection vulnerability fixed

    This release fixes CVE-2026-41246 and GHSA-x4mj-7f9g-29h4, a Lua code injection vulnerability affecting cookieRewritePolicies[].pathRewrite.value.

Source
Crossplanev2.2.1Orchestration & ManagementApr 20, 2026

Crossplane v2.2.1 includes security-focused dependency updates and a move to Go 1.25.9. It also corrects operator-facing behavior around dependency upgrades with ImageConfig prefix rewrites and resource selectors, and bumps Crossplane Runtime to v2.2.1.

Action needed (10)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    Crossplane v2.2.1 updates the github.com/cloudflare/circl module to v1.6.3 as a security dependency change.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    Crossplane v2.2.1 updates the go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module to v1.43.0 as a security dependency change.

  • securityThe github.com/go-jose/go-jose/v4 module, updated to v4.1.4

    Crossplane v2.2.1 updates the github.com/go-jose/go-jose/v4 module to v4.1.4 as a security dependency change.

  • securityThe github.com/sigstore/cosign/v3 module, updated to v3.0.5

    Crossplane v2.2.1 updates the github.com/sigstore/cosign/v3 module to v3.0.5 as a security dependency change.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    Crossplane v2.2.1 updates the github.com/go-git/go-git/v5 module to v5.17.1 as a security dependency change.

  • securityThe github.com/docker/cli module, updated to v29.2.0+incompatible

    Crossplane v2.2.1 updates the github.com/docker/cli module to v29.2.0+incompatible as a security dependency change.

  • securityGo 1.25.9

    Crossplane v2.2.1 updates Go to 1.25.9 as a security dependency change.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    Crossplane v2.2.1 updates the github.com/moby/spdystream module to v0.5.1 as a security dependency change.

  • securityThe github.com/sigstore/timestamp-authority/v2 module, updated to v2.0.6

    Crossplane v2.2.1 updates the github.com/sigstore/timestamp-authority/v2 module to v2.0.6 as a security dependency change.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    Crossplane v2.2.1 updates the github.com/go-git/go-git/v5 module to v5.18.0 as a security dependency change.

Source
Crossplanev2.1.5Orchestration & ManagementApr 20, 2026

Crossplane v2.1.5 combines correctness fixes with dependency and Go toolchain updates. The release includes updated versions of several modules used by Crossplane.

Action needed (10)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    Crossplane v2.1.5 updates the github.com/cloudflare/circl module to v1.6.3.

  • securityThe google.golang.org/grpc module, updated to v1.79.3

    Crossplane v2.1.5 updates the google.golang.org/grpc module to v1.79.3.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    Crossplane v2.1.5 updates the go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module to v1.43.0.

  • securityThe github.com/go-jose/go-jose/v4 module, updated to v4.1.4

    Crossplane v2.1.5 updates the github.com/go-jose/go-jose/v4 module to v4.1.4.

  • securityThe Go toolchain, updated to 1.25.9

    Crossplane v2.1.5 updates the Go toolchain to 1.25.9.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    Crossplane v2.1.5 updates the github.com/go-git/go-git/v5 module to v5.17.1.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    Crossplane v2.1.5 updates the github.com/moby/spdystream module to v0.5.1.

  • securityThe github.com/sigstore/timestamp-authority/v2 module, updated to v2.0.6

    Crossplane v2.1.5 updates the github.com/sigstore/timestamp-authority/v2 module to v2.0.6.

  • securityThe github.com/docker/cli module, updated to v29.2.0+incompatible

    Crossplane v2.1.5 updates the github.com/docker/cli module to v29.2.0+incompatible.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    Crossplane v2.1.5 updates the github.com/go-git/go-git/v5 module to v5.18.0.

Source
Crossplanev2.0.8Orchestration & ManagementApr 20, 2026

Crossplane v2.0.8 corrects two operator-visible defects and updates Go plus several dependencies. The dependency changes are marked for security, but the disclosures identify only the affected components rather than specific advisory IDs.

Action needed (9)

  • securityThe github.com/cloudflare/circl module update

    The github.com/cloudflare/circl module is updated to v1.6.3 in Crossplane v2.0.8.

  • securityThe OTLP HTTP trace exporter module update

    The go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module is updated to v1.43.0 in Crossplane v2.0.8.

  • securityThe github.com/go-jose/go-jose/v4 module update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in Crossplane v2.0.8.

  • securityThe Go version update to 1.25.9

    Go is updated to 1.25.9 in Crossplane v2.0.8.

  • securityThe github.com/go-git/go-git/v5 module update to v5.17.1

    The github.com/go-git/go-git/v5 module is updated to v5.17.1 in Crossplane v2.0.8.

  • securityThe github.com/moby/spdystream module update

    The github.com/moby/spdystream module is updated to v0.5.1 in Crossplane v2.0.8.

  • securityThe github.com/docker/cli module update

    The github.com/docker/cli module is updated to v29.2.0+incompatible in Crossplane v2.0.8.

  • securityThe github.com/sigstore/timestamp-authority/v2 module update

    The github.com/sigstore/timestamp-authority/v2 module is updated to v2.0.6 in Crossplane v2.0.8.

  • securityThe github.com/go-git/go-git/v5 module update to v5.18.0

    The github.com/go-git/go-git/v5 module is updated to v5.18.0 in Crossplane v2.0.8.

Source
Crossplanev1.20.6Orchestration & ManagementApr 20, 2026

Crossplane v1.20.6 is a dependency-focused release with updates to several Go modules, including security-marked changes. It also includes an update to crossplane-runtime v1.20.6.

Action needed (5)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    The github.com/cloudflare/circl module is updated to v1.6.3 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    The go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module is updated to v1.43.0 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    The github.com/go-git/go-git/v5 module is updated to v5.17.1 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    The github.com/moby/spdystream module is updated to v0.5.1 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    The github.com/go-git/go-git/v5 module is updated to v5.18.0 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

Source
Daprv1.15.14Orchestration & ManagementApr 16, 2026

This is a security-focused maintenance release. It corrects a service-invocation ACL mismatch caused by path normalization and updates Go to v1.25.9 for CVE coverage.

Action needed (2)

  • securityNormalized service-invocation ACL and outbound dispatch paths

    The normalized path form is used for both the ACL check and outbound dispatch, removing the mismatch in service invocation.

  • securityThe Go dependency, updated to v1.25.9

    The Go dependency is updated to v1.25.9 to address CVEs affecting the 1.24 line.

Source
Daprv1.17.5Orchestration & ManagementApr 16, 2026

This release contains a security fix for service-invocation access-control policy handling. It aligns method-path normalization for ACL checks and outbound dispatch, which concerns operators using these policies.

Action needed (1)

  • securityService-invocation ACL path normalization

    In Dapr v1.17.5, the normalized method path is used for both the service-invocation ACL check and outbound dispatch, eliminating the mismatch that caused the bypass.

Source
Daprv1.16.14Orchestration & ManagementApr 16, 2026

A security-focused release fixes a service-invocation ACL bypass caused by inconsistent path normalization. It also rejects dangerous method-path characters, removes the purell dependency from ACL path handling, and applies additional path cleaning in constructRequest.

Action needed (3)

  • securityConsistent service-invocation method path normalization

    Method paths are normalized at the service invocation edge for HTTP and gRPC public API calls, gRPC internal calls, and proxied calls. The normalized form is used for both the ACL check and outbound dispatch.

  • securityStricter method path validation

    Normalization uses path.Clean to resolve ../ segments and duplicate slashes. Method paths containing #, ?, null bytes, or control characters are rejected.

  • securityThe purell dependency, removed from the ACL path

    The purell dependency has been removed from ACL path handling.

Source
Ciliumv1.19.3Networking & MessagingApr 15, 2026

Cilium v1.19.3 combines operator-relevant bug fixes with configuration and CLI additions, along with dependency and image updates. The release is relevant to deployments using the affected functionality and to users tracking dependency changes.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 module update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in the v1.19.3 release. The update is marked as security-related.

Source
Ciliumv1.18.9Networking & MessagingApr 15, 2026

Cilium v1.18.9 contains correctness fixes and dependency updates. It also includes security-related changes, including an injection-prevention fix and a security-tagged module update.

Action needed (2)

  • securityRegex dollar-sign escaping for injection prevention

    Regex handling now escapes the $ character to prevent injection. The fix ships in Cilium v1.18.9.

  • securityThe github.com/go-jose/go-jose/v4 dependency update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in Cilium v1.18.9. The release note marks this dependency update as security-related.

Source
Keycloak26.6.1SecurityApr 15, 2026

Keycloak 26.6.1 is a maintenance release with two described security fixes in the core. It also contains dependency updates, an enhancement, and bug fixes.

Action needed (2)

  • securitymediumCVE-2026-4366, blind server-side request forgery via HTTP redirect handling

    Keycloak 26.6.1 fixes blind server-side request forgery through HTTP redirect handling in core.

  • securitylowCVE-2026-4633, user enumeration via identity-first login

    Keycloak 26.6.1 fixes user enumeration through identity-first login in core.

Source
Daprv1.16.13Orchestration & ManagementApr 15, 2026

Dapr v1.16.13 includes a security-relevant Go dependency update and correctness fixes. The release also changes scheduler reliability and Pulsar pub/sub processing behavior.

Action needed (1)

  • securityThe Go version update

    The Go version is updated from 1.25.8 to 1.25.9 in v1.16.13.

Check if affected (1)

  • breakingprocessMode initialization validation

    Applies if you configure processMode.

Source
Litmus3.28.0ObservabilityApr 15, 2026

A maintenance release with several defect fixes, including prevention of stale configuration leakage and a frontend base-image update to address a Python vulnerability. It also includes fixes for workflow event handling, branding, and experiment image-registry behavior.

Action needed (2)

  • securityStale configuration across probes of the same type

    Stale configuration no longer leaks across multiple probes of the same type.

  • securityFrontend base image updated to ubi9

    The frontend base image is updated to ubi9 to resolve a Python vulnerability.

Source
Backstagev1.50.0CI/CD & App DeliveryApr 14, 2026

A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the .well-known/oauth-protected-resource URL, and includes broad correctness and dependency updates.

Action needed (4)

  • securityhighThe glob and rollup dependencies, upgraded

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions. rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe glob dependency, upgraded to v13

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.

  • securityThe rollup dependency, upgraded to v4.59+

    rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe .well-known/oauth-protected-resource URL

    The .well-known/oauth-protected-resource resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.

Check if affected (22)

  • breakingThe auth.omitIdentityTokenOwnershipClaim setting

    Applies if you do not configure auth.omitIdentityTokenOwnershipClaim.

  • breakingThe SignInResolverFactoryOptions type parameters

    Applies if you use SignInResolverFactoryOptions.

  • breakingThe catalog permission exports, removed

    Applies if you use CatalogPermissionRuleInput, CatalogPermissionExtensionPoint, or catalogPermissionExtensionPoint.

  • + 19 more on the release page

Plan ahead (6)

  • deprecatedThe show and showModal compatibility implementation, deprecated

    Applies if you use show or showModal.

  • deprecatedThe auth.omitIdentityTokenOwnershipClaim setting, deprecatedremoval date not announced

    Applies if you configure auth.omitIdentityTokenOwnershipClaim.

  • deprecatedThe config.schema callback format, deprecated

    Applies if you use config.schema.

  • + 3 more on the release page
Source
containerdv2.2.3Kubernetes CoreApr 14, 2026

containerd v2.2.3 includes a disclosed security-related update to spdystream, alongside correctness, runtime, extraction, and dependency/toolchain changes. The recorded advisory is CVE-2026-35469.

Action needed (1)

  • securityhighspdystream dependency update for CVE-2026-35469

    The spdystream dependency is updated in containerd v2.2.3 in connection with CVE-2026-35469.

Source
containerdv2.0.8Kubernetes CoreApr 14, 2026

containerd v2.0.8 is a maintenance release with security fixes, a CNI restart correction, and dependency and toolchain updates. The security changes concern spdystream and credential handling in CRI pod events.

Action needed (1)

  • securityhighThe spdystream update for CVE-2026-35469

    The spdystream security update for CVE-2026-35469 ships in containerd v2.0.8.

Check if affected (1)

  • securityCredential sanitization before gRPC returns

    Applies if you use pod events through the Container Runtime Interface (CRI).

Source
containerdv2.1.7Kubernetes CoreApr 14, 2026

A maintenance release with fixes across CRI, runtime, image distribution, and security-sensitive paths. It also updates dependencies and toolchains, including a spdystream security update and a fix for credential leakage.

Action needed (2)

  • securityhighCVE-2026-35469 and GHSA-pc3f-x583-g7j2

    The release includes CVE-2026-35469 and GHSA-pc3f-x583-g7j2, related to the spdystream security fix.

  • securityhighgithub.com/moby/spdystream v0.5.1 update

    The release updates github.com/moby/spdystream to v0.5.1. The update carries fixes associated with CVE-2026-35469 and GHSA-pc3f-x583-g7j2.

Check if affected (1)

  • securityCredential sanitization before gRPC returns

    Applies if pod events are used.

Source
containerdv1.7.31Kubernetes CoreApr 14, 2026

containerd v1.7.31 is a maintenance release with a disclosed security fix in spdystream, alongside dependency, toolchain, correctness, and behavior updates. The spdystream fix requires upgrading; the other changes matter when affected behaviors or versions are in use.

Action needed (1)

Check if affected (1)

  • securitySanitized gRPC errors in pod events

    Applies if you use pod events.

Source
cert-managerv1.20.2SecurityApr 11, 2026

cert-manager v1.20.2 fixes invalid Helm YAML generation and updates Go to 1.26.2. It also includes a security-related update to Go dependencies with reported vulnerabilities.

Action needed (1)

  • securityGo dependency updates

    Go dependencies with reported vulnerabilities were updated in cert-manager v1.20.2. No advisory identifier is provided for this update.

Source
Daprv1.17.4Orchestration & ManagementApr 10, 2026

This release contains operator-relevant correctness fixes across messaging, workflows, HTTP proxying, placement, and scheduling. It also updates the Go toolchain across the repository and its Docker images.

Action needed (1)

  • securityThe Go toolchain, updated to 1.25.9

    The Go toolchain was upgraded from 1.25.8 to 1.25.9 across all modules and Docker images in the repository.

Source
Older →
Browse by month