RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

May 2026Clear ×
Karmadav1.18.0Orchestration & ManagementMay 30, 2026

A feature and maintenance release that adds overflow scheduling and scheduling overcommit protection, along with API, default, constraint, metric, and flag changes. It also includes a security-related alpine base-image update and numerous defect corrections.

Action needed (1)

  • securityThe alpine base image update

    The alpine base image has changed from alpine:3.23.3 to alpine:3.23.4 to address security concerns.

Check if affected (9)

  • breakingThe overflowAffinities field

    Applies if you configure overflowAffinities.

  • breakingStricter clusterTolerations operator validation

    Applies if you set spec.placement.clusterTolerations with Lt or Gt.

  • breakingThe operator's default verbosity level

    Applies if you run the operator.

  • + 6 more on the release page
Source
OpenCostv1.120.3ObservabilityMay 29, 2026

A maintenance release with dependency updates, correctness fixes, and new cloud and query capabilities. Configuration and output behavior also change, along with a Go dependency upgrade for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.

Action needed (1)

  • securityhighGo dependency upgrades for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986

    Go dependencies are upgraded for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.

Check if affected (1)

  • breakingThe MCP_SERVER_ENABLED default is false

    Applies if you do not configure MCP_SERVER_ENABLED.

Source
Confidential Containersv0.21.0SecurityMay 29, 2026

A release with Trustee, KBS, attestation, and platform-support changes, plus a security advisory fix. It also deprecates several CAA components and images planned for removal in 0.22.

Action needed (1)

  • securityGHSA-84rc-2q4r-45pc advisory fix

    The release patches GHSA-84rc-2q4r-45pc in the guest components.

Plan ahead (4)

  • deprecatedpacker-built CAA podvm image deprecationdeprecated since 0.17 · removal planned in 0.22

    Applies if you use the packer-built CAA podvm image.

  • deprecatedCAA docker provider deprecationdeprecated since 0.20 · removal planned in 0.22

    Applies if you use the CAA docker provider.

  • deprecatedFedora-based mkosi-built CAA podvm image deprecationdeprecated since 0.20 · removal planned in 0.22

    Applies if you use the Fedora-based mkosi-built CAA podvm image.

  • + 1 more on the release page
Source
Kubescapev4.0.9SecurityMay 29, 2026

A broad maintenance release with correctness fixes, new CLI and reporting capabilities, anonymization updates, a performance improvement, added validation, and dependency refreshes. It also includes security fixes alongside changes to output and push defaults.

Action needed (3)

  • securityDependency updates for security advisories

    Dependencies are updated to address security advisories.

  • securityEnvFrom clearing in container data removal

    removeContainersData now clears EnvFrom to prevent secret name leakage.

  • securityEnv[].ValueFrom clearing in container data removal

    removeContainersData and removeEphemeralContainersData now clear Env[].ValueFrom.

Check if affected (3)

  • security/v1/results access control hardening

    Applies if you use /v1/results.

  • breakingThe pdf/html output default changed to file output

    Applies if you use pdf/html output.

  • breakingThe push default changed to opt-in

    Applies if you use push.

Source
Contourv1.33.5Networking & MessagingMay 28, 2026

A maintenance release with a security fix for invalid HTTPProxy configurations and an update to golang.org/x/net. It also updates the Go toolchain to 1.25.10 and is tested against Kubernetes 1.32 through 1.34.

Action needed (1)

  • securitycriticalgolang.org/x/net updated to v0.55.0, CVE-2026-39821

    Contour v1.33.5 updates golang.org/x/net to v0.55.0. The change addresses CVE-2026-39821.

Check if affected (1)

  • securitymediumInvalid HTTPProxy configuration rejected, GHSA-g3xr-5w5j-w4q4

    Applies if you configure HTTPProxy with a fallback certificate and enable JWT verification.

Source
OpenFGAv1.16.1SecurityMay 28, 2026

OpenFGA v1.16.1 includes a third-party dependency update for multiple CVEs in the Go standard library. It also corrects defects in the experimental weighted_graph_check behavior.

Action needed (1)

  • securityThe grpc-health-probe dependency update

    grpc-health-probe is updated to v0.4.50 to address multiple CVEs in the Go standard library.

Source
Argov3.3.11CI/CD & App DeliveryMay 28, 2026

Argo CD v3.3.11 contains bug fixes and a UI dependency update addressing CVE-2026-41240. The release concerns deployments using the affected UI dependency.

Action needed (1)

  • securitymediumThe redoc/dompurify dependency, updated to v3.4.0

    The /ui dependency redoc/dompurify is updated to v3.4.0 to address CVE-2026-41240.

Source
Rookv1.19.6Storage & DataMay 27, 2026

This release includes a security-related dependency update in CI. The change affects builds that use golang.org/x/net.

Action needed (1)

  • securitycriticalThe golang.org/x/net dependency, updated to v0.55.0

    CI updates golang.org/x/net from its previous version to v0.55.0 to fix GO-2026-5026.

Source
Flatcar Container Linuxlts-4081.3.8Provisioning & RuntimeMay 27, 2026

This Flatcar LTS release contains Linux security fixes identified by CVEs, plus ca-certificates and Linux component updates. It is most relevant to deployments tracking the lts-4081.3.8 release.

Action needed (1)

  • securitycriticalLinux security fixes for CVE-2026-43316

    Linux receives security fixes associated with the listed CVEs, including CVE-2026-43316. The update ships in Flatcar LTS lts-4081.3.8.

Source
Crossplanev2.3.1Orchestration & ManagementMay 22, 2026

A maintenance release includes dependency updates and security fixes in golang.org/x/crypto. The fixes cover SSH, SSH agent, and known-hosts behavior.

Action needed (1)

  • securitygolang.org/x/crypto updated to v0.52.0

    The release updates the golang.org/x/crypto module to v0.52.0.

Check if affected (13)

  • securitycriticalUnenforced invoking key constraints in golang.org/x/crypto/ssh/agent

    Applies if you use golang.org/x/crypto/ssh/agent.

  • securitycriticalDropped invoking agent constraints in golang.org/x/crypto/ssh/agent

    Applies if you use golang.org/x/crypto/ssh/agent.

  • securitycriticalServer deadlock on unexpected responses in golang.org/x/crypto/ssh

    Applies if you use golang.org/x/crypto/ssh.

  • + 10 more on the release page
Source
Crossplanev1.20.8Orchestration & ManagementMay 22, 2026

Crossplane v1.20.8 is a dependency and toolchain maintenance release. It updates several modules and the Go version, with the recorded dependency changes addressing security fixes, and also bumps crossplane-runtime to v1.20.8.

Action needed (7)

  • securityThe github.com/docker/cli module, updated to v29.2.0+incompatible

    The github.com/docker/cli module is updated to v29.2.0+incompatible in the release-1.20 branch.

  • securityThe golang.org/x/net module, updated to v0.53.0

    The golang.org/x/net module is updated to v0.53.0 in the release-1.20 branch.

  • securityThe github.com/in-toto/in-toto-golang module, updated to v0.11.0

    The github.com/in-toto/in-toto-golang module is updated to v0.11.0 in the release-1.20 branch.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.19.0

    The github.com/go-git/go-git/v5 module is updated to v5.19.0 in the release-1.20 branch.

  • securityThe Go toolchain, updated to 1.25.10

    Go is updated to 1.25.10 to fix standard-library CVEs in the release-1.20 branch.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.19.1

    The github.com/go-git/go-git/v5 module is updated again, to v5.19.1, in the release-1.20 branch.

  • securityThe golang.org/x/crypto module, updated to v0.52.0

    The golang.org/x/crypto module is updated to v0.52.0 in the release-1.20 branch.

Source
Crossplanev2.1.6Orchestration & ManagementMay 22, 2026

A security-focused maintenance release updates Go and several dependencies, including a fix for an HTTP/2 transport infinite-loop vulnerability. The Go and dependency version increases require upgrading; no configuration migration or deprecation is announced.

Action needed (6)

  • securityThe go.opentelemetry.io/otel module update

    The go.opentelemetry.io/otel module is updated to v1.41.0 in this release.

  • securityThe github.com/in-toto/in-toto-golang module update

    The github.com/in-toto/in-toto-golang module is updated to v0.11.0 in this release.

  • securityThe github.com/go-git/go-git/v5 module update to v5.19.0

    The github.com/go-git/go-git/v5 module is updated to v5.19.0 in this release.

  • securityGo 1.25.10

    Go is updated to 1.25.10 to fix standard library CVEs.

  • securityThe github.com/go-git/go-git/v5 module update to v5.19.1

    The github.com/go-git/go-git/v5 module is updated to v5.19.1 in this release.

  • securityThe golang.org/x/crypto module update

    The golang.org/x/crypto module is updated to v0.52.0 in this release.

Check if affected (1)

  • securityhighThe golang.org/x/net HTTP/2 transport infinite loop

    Applicability is not stated in the release notes.

Source
Crossplanev2.2.2Orchestration & ManagementMay 22, 2026

Crossplane v2.2.2 is a dependency and toolchain maintenance release with security-focused updates. It concerns deployments and builds that rely on the updated Go toolchain and modules.

Action needed (5)

  • securitygithub.com/in-toto/in-toto-golang updated to v0.11.0

    Crossplane v2.2.2 updates the github.com/in-toto/in-toto-golang module to v0.11.0. The update ships in the release-2.2 line.

  • securitygithub.com/go-git/go-git/v5 updated to v5.19.0

    Crossplane v2.2.2 updates the github.com/go-git/go-git/v5 module to v5.19.0. The update ships in the release-2.2 line.

  • securityGo 1.25.10 update for standard-library CVEs

    Crossplane v2.2.2 updates Go to 1.25.10 to fix standard-library CVEs. The toolchain update ships in the release-2.2 line.

  • securitygithub.com/go-git/go-git/v5 updated to v5.19.1

    Crossplane v2.2.2 updates the github.com/go-git/go-git/v5 module to v5.19.1. The update ships in the release-2.2 line.

  • securitygolang.org/x/crypto updated to v0.52.0

    Crossplane v2.2.2 updates the golang.org/x/crypto module to v0.52.0. The update ships in the release-2.2 line.

Source
Crossplanev2.3.0Orchestration & ManagementMay 21, 2026

Crossplane v2.3.0 combines breaking API naming and path changes with new operator capabilities and correctness fixes. It also updates several Go dependencies and the Go toolchain, which matters to API consumers and builds that depend on the affected packages.

Action needed (14)

  • securityThe github.com/cloudflare/circl dependency, updated to v1.6.3

    The github.com/cloudflare/circl module is updated to v1.6.3 in Crossplane v2.3.0.

  • securityThe google.golang.org/grpc dependency, updated to v1.79.3

    The google.golang.org/grpc module is updated to v1.79.3 in Crossplane v2.3.0.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp dependency, updated to v1.43.0

    The go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module is updated to v1.43.0 in Crossplane v2.3.0.

  • securityThe github.com/go-git/go-git/v5 dependency, updated to v5.17.1

    The github.com/go-git/go-git/v5 module is updated to v5.17.1 in Crossplane v2.3.0.

  • securityThe github.com/go-jose/go-jose/v4 dependency, updated to v4.1.4

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in Crossplane v2.3.0.

  • securityThe github.com/sigstore/cosign/v3 dependency, updated to v3.0.5

    The github.com/sigstore/cosign/v3 module is updated to v3.0.5 in Crossplane v2.3.0.

  • securityThe github.com/docker/cli dependency, updated to v29.2.0+incompatible

    The github.com/docker/cli module is updated to v29.2.0+incompatible in Crossplane v2.3.0.

  • securityThe github.com/sigstore/timestamp-authority/v2 dependency, updated to v2.0.6

    The github.com/sigstore/timestamp-authority/v2 module is updated to v2.0.6 in Crossplane v2.3.0.

  • securityThe Go toolchain, updated to 1.25.9

    The Go toolchain is updated to 1.25.9 in Crossplane v2.3.0.

  • securityThe github.com/moby/spdystream dependency, updated to v0.5.1

    The github.com/moby/spdystream module is updated to v0.5.1 in Crossplane v2.3.0.

  • securityThe github.com/go-git/go-git/v5 dependency, updated to v5.18.0

    The github.com/go-git/go-git/v5 module is updated to v5.18.0 in Crossplane v2.3.0.

  • securityThe github.com/in-toto/in-toto-golang dependency, updated to v0.11.0

    The github.com/in-toto/in-toto-golang module is updated to v0.11.0 in Crossplane v2.3.0.

  • securityThe golang.org/x/net dependency, updated to v0.53.0

    The golang.org/x/net module is updated to v0.53.0 in Crossplane v2.3.0.

  • securityThe Go toolchain, updated to 1.25.10

    The Go toolchain is updated to 1.25.10 in Crossplane v2.3.0 to fix standard library CVEs.

Check if affected (3)

  • breakingThe Crossplane API dependency path, renamed

    Applies if you build external consumers of Crossplane APIs.

  • breakingThe common API package, moved

    Applies if you use the common APIs from crossplane-runtime.

  • breakingThe v1.Resource* types, renamed

    Applies if you use the old v1.Resource* types.

Source
containerdv2.2.4Kubernetes CoreMay 20, 2026

A maintenance release with security updates, including a dependency update tied to an advisory. It also includes compatibility and runtime changes across storage, policy, sandbox, validation, and toolchain areas.

Action needed (2)

Source
containerdv2.0.9Kubernetes CoreMay 20, 2026

A maintenance release with a disclosed security fix, a narrower default socket policy, expanded compatibility for volatile mount options and AppArmor, and several correctness fixes. It also includes updates to container event handling, tar extraction, OCI USER validation, sandbox field forwarding, and event topics.

Action needed (1)

Check if affected (1)

  • breakingThe default seccomp socket policy

    Applies if you use seccomp.

Source
containerdv1.7.32Kubernetes CoreMay 20, 2026

containerd v1.7.32 includes a disclosed security advisory alongside correctness and compatibility fixes. The release concerns users assessing security exposure or changes in runtime and configuration behavior.

Action needed (1)

Source
containerdv2.3.1Kubernetes CoreMay 20, 2026

A maintenance release focused on runtime correctness and security, including fixes across snapshotter, storage, and server components. It also contains compatibility changes and updates to the API and Go toolchain.

Action needed (1)

  • securityhighCVE-2026-46680 correction

    The fix for CVE-2026-46680 ships in this release.

Check if affected (1)

  • breakingThe overlayfs "rebase" capability, disabled in user namespaces

    Applies if you use overlayfs and run in a user namespace.

Plan ahead (1)

  • deprecatedTask fields in Runc options, deprecated

    Applies if you configure task fields in Runc options.

Source
OpenFGAv1.16.0SecurityMay 20, 2026

Release v1.16.0 adds datastore timeout configuration and additional tracing output. It also fixes defects in experimental weighted_graph_check and OIDC authentication, and updates the Go toolchain for standard-library vulnerability fixes.

Action needed (1)

  • securityThe Go toolchain, updated to 1.26.3

    The toolchain now uses Go version 1.26.3 to address vulnerabilities in the Go standard library. This update ships in v1.16.0.

Source
Backstagev1.51.0CI/CD & App DeliveryMay 19, 2026

A broad release with breaking API removals, changed defaults and constraints, and many new operator-facing capabilities. It also includes performance improvements and an explicitly described dependency security update.

Action needed (2)

  • securityModule Federation packages at v2.3.3

    Module Federation packages were upgraded to v2.3.3 to address known vulnerabilities.

  • breakingThe @remixicon/react version constraint

    The @remixicon/react dependency is limited to versions below 4.9.0 because of a license change.

Check if affected (9)

  • securitySpecific defaults for known MCP clients

    Applies if you configure CIMD or DCR.

  • breakingThe NavItemBlueprint API, removed

    Applies if you use NavItemBlueprint.

  • breakingSidebar and legacy nav-item rendering in renderInTestApp

    Applies if you use renderInTestApp.

  • + 6 more on the release page

Plan ahead (4)

  • deprecatedThe PolicyQueryUser.identity field, deprecated

    Applies if you use PolicyQueryUser.identity.

  • deprecatedThe EXPERIMENTAL_formDecorators field, deprecated alias

    Applies if you configure EXPERIMENTAL_formDecorators.

  • deprecatedThe catalog.stitchingStrategy.mode: 'immediate' setting, deprecated

    Applies if you configure catalog.stitchingStrategy.mode.

  • + 1 more on the release page
Source
Keycloak26.6.2SecurityMay 19, 2026

A maintenance release with numerous disclosed security fixes, dependency updates, enhancements, and bug fixes. It also corrects forced object deletion during the operator upgrade path.

Action needed (6)

  • securityhighCVE-2026-33871: HTTP/2 CONTINUATION frame flood denial of service

    The release fixes the HTTP/2 CONTINUATION frame flood denial-of-service issue identified by CVE-2026-33871.

  • securityhighCVE-2026-33870: HTTP request smuggling through chunked extension parsing

    The release corrects the HTTP request smuggling primitive caused by chunked extension quoted-string parsing, identified by CVE-2026-33870.

  • securityhighBouncycastle updates for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598

    The release updates bouncycastle for CVE-2026-0636, CVE-2026-3505, and CVE-2026-5598.

  • securityhighCVE-2026-7504: Redirect URI validation bypass

    The release corrects the redirect URI validation bypass in Keycloak, identified by CVE-2026-7504.

  • securitymediumCVE-2026-5588: Bouncy Castle bcpkix cryptographic algorithm vulnerability

    The release updates the bcpkix modules affected by the broken or risky cryptographic algorithm vulnerability in the Bouncy Castle Crypto Package for Java, identified by CVE-2026-5588.

  • securityPermission and policy call ordering in admin/api

    The release corrects the ordering of permission and policy calls in admin/api that led to exposure of a client ID.

Check if affected (12)

Source
hamiv2.9.0AI & MLMay 19, 2026

A feature and maintenance release that adds HAMi-core, Ascend and vNPU virtualization, DRA, CDI, monitoring, metrics, deployment, and debugging capabilities. It also includes scheduling, allocation, device, chart, and compatibility fixes, security updates, dependency upgrades, and removal of a deprecated scheduler policy ConfigMap.

Action needed (3)

  • securityThe tensorflow/tensorflow dependency, upgraded

    The tensorflow/tensorflow dependency was upgraded from 2.20.0rc0-gpu to 2.21.0rc0-gpu in this release.

  • securityThe tensorflow/tensorflow dependency, upgraded again

    The tensorflow/tensorflow dependency was upgraded from 2.21.0rc0-gpu to 2.21.0rc1-gpu in this release.

  • securityThe golang dependency, upgraded

    The golang dependency was upgraded for a security issue in this release.

Check if affected (3)

  • breakingThe deprecated scheduler policy configmap, removed

    Applies if you configure scheduler policy configmap.

  • breakingThe Helm nvidia.overwriteEnv default

    Applies if you use Helm.

  • breakingHost networking for the device plugin, disabled

    Applies if the device plugin runs.

Source
OpenCostv1.120.2ObservabilityMay 18, 2026

A maintenance release with dependency updates, operator-visible configuration and behavior changes, new integrations and capabilities, and correctness fixes. It also includes an explicitly disclosed security-related Go dependency upgrade.

Action needed (1)

Check if affected (2)

  • breakingThe provider config source, changed

    Applies if you configure provider config.

  • breakingThe MCP_SERVER_ENABLED default, changed to false

    Applies if you use the MCP server.

Source
Istio1.29.3Networking & MessagingMay 18, 2026

A maintenance release adds Gateway API compatibility, analyzer and HBONE tuning capabilities, and fixes certificate, controller, probe, output, and authorization issues. The authorization fixes address cross-namespace configuration access and regex handling in AuthorizationPolicy.

Action needed (1)

  • securityCross-namespace access to istio.io/debug/syncz and istio.io/debug/config_dump

    Authorization is fixed so an authenticated workload cannot enumerate proxies or retrieve configuration dumps for workloads in other namespaces through istio.io/debug/syncz and istio.io/debug/config_dump.

Check if affected (2)

  • securityRegex handling in AuthorizationPolicy identity fields

    Applicability is not stated in the release notes.

  • breakingThe AMBIENT_ENABLE_AWS_BRANCH_ENI_PROBE setting and kubelet health probes

    Applies when ambient mesh pods run on AWS EKS and use Security Groups for Pods (branch ENI).

Source
Istio1.28.7Networking & MessagingMay 18, 2026

A maintenance release that adds Gateway API v1.4.1 support and new diagnostics and configuration controls while fixing several correctness issues. It also includes two described security fixes for XDS debug endpoint authorization and regex handling in AuthorizationPolicy.

Action needed (1)

  • securitySame-namespace authorization for StatusGen XDS debug endpoints

    The StatusGen-served XDS debug endpoints istio.io/debug/syncz and istio.io/debug/config_dump now enforce same-namespace authorization for non-system callers. Authenticated workloads can no longer enumerate proxies or retrieve configuration dumps for workloads in other namespaces.

Check if affected (1)

  • securityEscaped regex metacharacters in AuthorizationPolicy identity fields

    Applies if you configure source.principals or source.namespaces.

Source
Litmus3.29.0ObservabilityMay 18, 2026

Litmus 3.29.0 includes operator-facing changes across dependencies and platform behavior. This release includes a google.golang.org/grpc update to v1.79.3 for CVE-2026-33186.

Action needed (1)

  • securitycriticalThe google.golang.org/grpc dependency, updated for CVE-2026-33186

    The release updates google.golang.org/grpc to v1.79.3. The dependency update addresses CVE-2026-33186 in Litmus 3.29.0.

Source
The Update Framework (TUF)v7.0.0SecurityMay 18, 2026

A release focused on a security fix and API evolution. It tightens the Updater() contract and begins preparation for removal of an existing module.

Action needed (1)

Check if affected (1)

  • breakingThe Updater() bootstrap argument, now required

    Applies if you use Updater().

Plan ahead (1)

  • deprecatedPreparation for removal of securesystemslib.hash

    Applies if you use securesystemslib.hash.

Source
Linkerdedge-26.5.2Networking & MessagingMay 15, 2026

A release that changes the default sidecar mode and promotes native sidecars to GA. It also fixes correctness issues, adds configurable timestamp handling, addresses eleven disclosed CVEs, and updates numerous dependencies.

Action needed (2)

Source
Helmv3.21.0Kubernetes CoreMay 14, 2026

Helm v3.21.0 is a maintenance release with dependency updates and fixes to chart and OCI handling. It also includes a security fix in the opentelemetry packages.

Action needed (1)

  • securityThe opentelemetry packages, upgraded for CVE patches

    Helm v3.21.0 upgrades the opentelemetry packages to patch CVEs.

Source
Helmv4.2.0Kubernetes CoreMay 14, 2026

A feature and maintenance release with new template and CLI capabilities, dependency updates, flag deprecations, and numerous correctness fixes. It also includes security fixes for plugin path traversal and GO-2026-4394.

Action needed (1)

  • securityhighgo.opentelemetry.io/otel/sdk update for GO-2026-4394

    Helm v4.2.0 updates go.opentelemetry.io/otel/sdk to v1.40.0 for GO-2026-4394.

Check if affected (1)

  • securityPlugin version path traversal fix

    Applies if you use the Plugin extension.

Plan ahead (1)

  • deprecatedThe --hide-notes and --render-subchart-notes flags, deprecated

    Applies if you use --hide-notes or --render-subchart-notes.

Source
Ciliumv1.19.4Networking & MessagingMay 13, 2026

A maintenance release with several operator-visible fixes, narrower EndpointSlice watch behavior, Helm configurability, and dependency and image updates. The EndpointSlice filtering change affects configurations that set a service proxy name, while the release also updates the github.com/moby/spdystream dependency.

Action needed (2)

  • securityThe github.com/moby/spdystream module update

    The github.com/moby/spdystream module is updated to v0.5.1.

  • breakingService-label filtering for EndpointSlice watches

    The loadbalancer/reflectors component filters EndpointSlice watches by service labels.

Check if affected (1)

  • breakingLabel filtering for EndpointSlices

    Applies if you set --k8s-service-proxy-name.

Source
Ciliumv1.17.16Networking & MessagingMay 13, 2026

A maintenance release with an enforced policy behavior change, bug fixes, new metrics, and Helm image overrides. It also updates dependencies and container images and refreshes container image manifests.

Action needed (1)

  • securityThe github.com/moby/spdystream dependency update

    The github.com/moby/spdystream module is updated to v0.5.1 in v1.17.16.

Check if affected (1)

  • breakingCiliumLocalRedirectPolicy addressMatcher override behavior

    Applies if you use addressMatcher in CiliumLocalRedirectPolicy and do not enable --enable-lrp-address-matcher-override=true.

Source
Ciliumv1.18.10Networking & MessagingMay 13, 2026

Cilium v1.18.10 contains correctness fixes, Helm support for overriding images, and dependency and image updates. The github.com/moby/spdystream update is marked as a security update, but no advisory identifier is provided.

Action needed (1)

  • securityThe github.com/moby/spdystream module update to v0.5.1

    Cilium v1.18.10 updates the github.com/moby/spdystream module to v0.5.1 as an undisclosed security update.

Source
Argov3.3.10CI/CD & App DeliveryMay 12, 2026

This release combines bug fixes with dependency and toolchain updates. The Go update to 1.25.9 addresses CVEs and concerns deployments using this release.

Action needed (1)

  • securityThe Go toolchain, updated to 1.25.9

    The Go toolchain is updated to 1.25.9 on release-3.3 to resolve CVEs.

Source
Fluxv2.8.7CI/CD & App DeliveryMay 12, 2026

Flux v2.8.7 includes a security update to the go-git dependency alongside toolkit component updates. The go-git update addresses CVE-2026-45022 and GHSA-389r-gv7p-r3rp.

Action needed (1)

  • securityhighThe go-git dependency update to v5.19.0

    The go-git dependency is updated to v5.19.0, which fixes CVE-2026-45022 and addresses GHSA-389r-gv7p-r3rp. This update ships in Flux v2.8.7.

Source
Open Policy Agent (OPA)v1.16.2SecurityMay 12, 2026

OPA v1.16.2 is a security-focused maintenance release. It updates the Go version used to build OPA binaries and images to 1.26.3 to address vulnerabilities.

Action needed (1)

  • securityThe Go build version, updated to 1.26.3

    The version of Go used to build OPA binaries and images is updated to 1.26.3 to address vulnerabilities.

Source
Flatcar Container Linuxstable-4593.2.1Provisioning & RuntimeMay 11, 2026

This is a security-focused Flatcar release with disclosed Linux security fixes. It also updates the Linux and ca-certificates dependencies.

Action needed (1)

  • securitycriticalLinux security updates, including CVE-2026-31733

    Linux receives security updates in Flatcar stable-4593.2.1, including CVE-2026-31733 and the other disclosed Linux advisories listed for this change.

Source
Harborv2.15.1Storage & DataMay 6, 2026

Harbor v2.15.1 is a maintenance release with defect corrections, behavior changes, and dependency and base-image updates. It also updates photon packages to fix CVEs.

Action needed (1)

  • securityphoton packages CVE fixes

    The photon packages are updated to fix CVEs in Harbor v2.15.1.

Source
Older →
Browse by month