RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Feb 2026Clear ×
Daprv1.17.0Orchestration & ManagementFeb 27, 2026

A broad feature release adds workflow, component, API, authentication, tracing, configuration, CLI, and observability capabilities, alongside defect fixes and dependency updates. It also deprecates the alpha Bulk PubSub APIs and alpha application callback and includes security fixes.

Action needed (9)

  • securityGo cryptography dependency updates

    The x/(net/sync/crypto) dependencies are bumped, and dvsekhvalnov/jose2go is pinned.

  • securityGo vulnerability fix

    A vulnerability in Go is fixed.

  • securityRoot-only UID check

    The UID check now checks only the root UID.

  • securityHTTP path matching and invocation auto-registration

    HTTP path matching is fixed to address a cardinality leak, and invocation auto-registration is supported.

  • securityThe golang.org/x/crypto dependency, updated

    The golang.org/x/crypto dependency is bumped.

  • securityThe github.com/docker/docker dependency, updated

    The github.com/docker/docker dependency is bumped.

  • securitySecurity fixes

    Security fixes ship in the release.

  • securityThe github.com/coreos/go-oidc/v3 dependency, updated

    The github.com/coreos/go-oidc/v3 dependency is bumped.

  • securityNATS vulnerability fix

    A vulnerability in NATS is fixed.

Check if affected (3)

  • securityPlacement authorization for Dapr actor types

    Applies if you use Placement.

  • securityCloudflare worker vulnerability fix

    Applies if you use the Cloudflare worker.

  • breakingScheduler resources removed from the Helm chart

    Applies if you use the Helm chart.

Plan ahead (2)

  • deprecatedAlpha Bulk PubSub APIs and app callback deprecation

    Applies if you use /v1.0-alpha1/publish/bulk/<pubsub-name>/<topic>, BulkPublishEventAlpha1, or OnBulkTopicEventAlpha1.

  • deprecatedThe OnBulkTopicEventAlpha1 callback, deprecated

    Applies if you use OnBulkTopicEventAlpha1.

Source
Open Policy Agent (OPA)v1.14.0SecurityFeb 26, 2026

This release adds runtime and API capabilities, changes supported behavior and output, and corrects several defects. It also updates dependencies, including a fix for GHSA-9h8m-3fm2-qjrq.

Action needed (1)

  • securityhighThe go.opentelemetry.io dependencies, updated for GHSA-9h8m-3fm2-qjrq

    The go.opentelemetry.io dependencies include the fix for GHSA-9h8m-3fm2-qjrq.

Check if affected (1)

  • breakingThe --h2c flag with Unix domain socket support

    Applies if you use --h2c with unix domain socket (UDS).

Source
cert-managerv1.18.6SecurityFeb 24, 2026

cert-manager v1.18.6 is a patch release focused on fixing reported vulnerabilities, including CVE-2025-68121, through a Go toolchain bump. CVE-2026-24051 is explicitly stated not to affect cert-manager.

Action needed (2)

  • securitycriticalCVE-2025-68121 vulnerability fix

    The v1.18.6 patch release fixes reported vulnerabilities, most notably CVE-2025-68121, in cert-manager.

  • securitycriticalGo toolchain bump for CVE-2025-68121

    The Go toolchain is bumped in cert-manager v1.18.6 to address CVE-2025-68121.

Source
cert-managerv1.19.4SecurityFeb 24, 2026

cert-manager v1.19.4 is a patch release focused on reported vulnerabilities and dependency updates. It includes fixes for CVE-2026-24051, CVE-2025-68121, and GO-2026-4394.

Action needed (3)

  • securitycriticalThe go dependency update

    The go dependency is bumped in cert-manager v1.19.4 to address CVE-2025-68121.

  • securityhighcert-manager v1.19.4 vulnerability fixes

    cert-manager v1.19.4 is a patch release addressing reported vulnerabilities, including CVE-2026-24051 and CVE-2025-68121.

  • securityhighThe otel SDK dependency update

    The otel SDK dependency is bumped in cert-manager v1.19.4 to address GO-2026-4394.

Source
OpenFGAv1.11.6SecurityFeb 23, 2026

This release changes the default ListObjects pipeline and narrows the requirements for read-only container deployments. It updates grpc-health-probe to address CVE-2025-68121, while the grpc-gateway client migration remains internal-only.

Action needed (1)

  • securitycriticalThe grpc-health-probe dependency update for CVE-2025-68121

    The grpc-health-probe dependency is updated to v0.4.45 to address CVE-2025-68121.

Check if affected (1)

  • breakingInternal HTTP-to-gRPC communication over UDS

    Applies if you use --read-only.

Source
Argov3.3.2CI/CD & App DeliveryFeb 22, 2026

This release fixes the client-side apply migration issue reported in versions 3.3.0 and 3.3.1. No security advisories are disclosed.

Action needed (1)

  • breakingClient-side apply migration failure

    The failed to perform client-side apply migration issue present in versions 3.3.0 and 3.3.1 is fixed in this release.

Source
k8gbv0.18.1Kubernetes CoreFeb 21, 2026

v0.18.1 is a dependency update release. It includes an update to coredns-plugin for the latest security fixes, alongside other dependency version changes.

Action needed (1)

  • securityThe coredns-plugin dependency, updated for security fixes

    The coredns-plugin dependency is updated to include the latest security fixes in v0.18.1.

Source
Keycloak26.5.4SecurityFeb 20, 2026

A maintenance release with five disclosed security fixes, one new capability, and ten corrected bugs. It contains no operator prerequisites or dependency-manifest entries.

Action needed (2)

  • securitymediumCVE-2026-0707, authorization header parsing

    This release corrects authorization header parsing that could bypass security controls.

  • securitylowCVE-2025-5416, keycloak-core environment information disclosure

    This release fixes environment information disclosure in keycloak-core.

Check if affected (4)

Source
Kyvernov1.17.1SecurityFeb 19, 2026

This release includes a security fix for CVE-2025-68121, along with defect corrections and dependency updates. It also changes operator-facing defaults and configuration documentation, including a default that now uses a duration string.

Action needed (1)

  • securitycriticalCVE-2025-68121 security fix

    CVE-2025-68121 is fixed in this release.

Check if affected (1)

  • breakingDefault value and Helm values documentation format change

    Applicability is not stated in the release notes.

Source
Strimzi0.50.1Networking & MessagingFeb 19, 2026

A maintenance release with two security fixes and a deprecated KafkaUser API field that requires migration. It also includes API conversion fixes, broker certificate output changes, and dependency and container image updates.

Action needed (1)

Plan ahead (1)

  • deprecatedThe .spec.authorization.acls[]operation field is deprecated

    Applies if you configure .spec.authorization.acls[]operation.

Source
Open Policy Agent (OPA)v1.13.2SecurityFeb 18, 2026

OPA v1.13.2 updates the Go version used to build its binaries and images. The release includes the Go standard library fix for GO-2026-4337.

Action needed (1)

  • securitycriticalGo 1.25.7 build dependency

    OPA binaries and images are now built with Go 1.25.7. The Go standard library in that version contains a fix for GO-2026-4337.

Source
Crossplanev2.2.0Orchestration & ManagementFeb 17, 2026

A release with breaking changes to package installation and package-cache side-loading, alongside new operator capabilities and ordinary defect corrections. It also includes security-tagged dependency updates, but no advisory identifiers or vulnerability details are provided.

Action needed (7)

  • securitySecurity update for golang.org/x/crypto

    The golang.org/x/crypto module was updated to v0.45.0 as a security update.

  • securitySecurity update for github.com/go-chi/chi/v5

    The github.com/go-chi/chi/v5 module was updated to v5.2.4 as a security update.

  • securitySecurity update for github.com/sigstore/cosign/v3

    The github.com/sigstore/cosign/v3 module was updated to v3.0.4 as a security update.

  • securitySecurity update for github.com/theupdateframework/go-tuf/v2

    The github.com/theupdateframework/go-tuf/v2 module was updated to v2.4.1 as a security update.

  • securitySecurity update for github.com/sigstore/rekor

    The github.com/sigstore/rekor module was updated to v1.5.0 as a security update.

  • securitySecurity update for github.com/sigstore/sigstore

    The github.com/sigstore/sigstore module was updated to v1.10.4 as a security update.

  • securitySecurity update for github.com/quic-go/quic-go

    The github.com/quic-go/quic-go module was updated to v0.57.0 as a security update.

Check if affected (2)

  • breakingInput CRD installation from Function packages

    Applies if you use Function packages and Input CRDs.

  • breakingPackage cache structure

    Applicability is not stated in the release notes.

Source
Istio1.28.4Networking & MessagingFeb 16, 2026

A maintenance release focused on security fixes, validation, and authorization changes across Istio control-plane and endpoint handling. It also includes operator-facing capability changes and corrections for other defects.

Action needed (1)

  • securityhighCVE-2025-61732 cgo comment parsing flaw

    This release fixes a discrepancy between Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary.

Check if affected (4)

  • securitycriticalCVE-2025-68121 TLS session resumption validation

    Applies if you use Config.Clone with mutations or Config.GetConfigForClient.

  • securityGateway deployment controller resource validation

    Applies if the gateway deployment controller runs.

  • securityResource annotation validation against container injection

    Applies if you configure resource annotations.

  • + 1 more on the release page
Source
Istio1.27.7Networking & MessagingFeb 16, 2026

A security release addressing two vulnerabilities in cgo comment parsing and crypto/tls session resumption. The fixes are relevant to deployments using the affected Go functionality.

Action needed (2)

  • securitycriticalCVE-2025-68121 session resumption vulnerability correction

    CVE-2025-68121 corrects a crypto/tls session resumption flaw that could let resumed handshakes succeed after ClientCAs or RootCAs changed between the initial and resumed handshake.

  • securityhighCVE-2025-61732 code-smuggling vulnerability correction

    CVE-2025-61732 addresses a discrepancy in Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary.

Source
Istio1.29.0Networking & MessagingFeb 16, 2026

This release adds operator-visible capabilities and changes several runtime defaults. Ambient mesh behavior, debug endpoint authorization, metrics compression, and istiod memory and circuit-breaker behavior receive particular attention.

Action needed (1)

  • breakingAutomatic GOMEMLIMIT setting for istiod

    istiod now automatically sets GOMEMLIMIT to 90% of its memory limits through the automemlimit library. This reduces the risk of OOM kills while maintaining performance.

Check if affected (4)

  • breakingDefault iptables reconciliation

    Applies when the istio-cni DaemonSet is upgraded.

  • breakingDefault debug endpoint authorization

    Applies to debug endpoints on port 15014.

  • breakingDefault HTTP compression for Envoy metrics

    Applies to Envoy metrics at the Prometheus stats endpoint based on client Accept-Header values.

  • + 1 more on the release page
Source
Ciliumv1.18.7Networking & MessagingFeb 13, 2026

A maintenance release combining an operator-facing configuration adjustment with bug fixes and routine dependency and image refreshes. No security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingExclusion of topology.kubernetes.io labels from security labels by default

    The default security-label handling in this release excludes topology.kubernetes.io labels from security labels.

Source
etcdv3.6.8Kubernetes CoreFeb 13, 2026

A maintenance release postpones removal of one flag and reverses another flag's deprecation. It also includes dependency and toolchain updates addressing named security advisories.

Action needed (2)

Plan ahead (1)

  • deprecatedThe --max-snapshots flag, removal postponedremoval planned in v3.8

    Applies if you use --max-snapshots.

Source
etcdv3.5.27Kubernetes CoreFeb 13, 2026

A maintenance release that changes the Go toolchain used to compile binaries. It also includes fixes for three named CVEs and their corresponding GHSA advisories.

Action needed (1)

Source
Daprv1.16.9Orchestration & ManagementFeb 12, 2026

This release includes a Go toolchain dependency upgrade and a corrected Pulsar PubSub subscription-metadata defect. A regression test verifies that metadata is applied to consumer options.

Action needed (1)

  • securityhighThe Go toolchain upgrade to 1.24.13

    Dapr v1.16.9 upgrades Go to 1.24.13. The upgrade addresses advisories GO-2026-4340 and GO-2026-4341.

Source
OpenFGAv1.11.5SecurityFeb 11, 2026

This release includes an operator-facing toolchain update. The change addresses CVE-2025-68121 in OpenFGA v1.11.5.

Action needed (1)

  • securitycriticalThe Go toolchain, updated to 1.25.7

    The Go toolchain is updated to 1.25.7 in OpenFGA v1.11.5 to address CVE-2025-68121.

Source
OpenFGAv1.11.4SecurityFeb 10, 2026

OpenFGA v1.11.4 fixes a planner regression in specific scenarios and updates the OpenTelemetry SDK. The SDK change addresses a disclosed issue affecting earlier versions.

Action needed (1)

  • securityThe otel/sdk dependency at v1.40.0

    The otel/sdk dependency is upgraded to v1.40.0 in OpenFGA v1.11.4 to address the issue identified as SNYK-GOLANG-GOOPENTELEMETRYIOOTELSDKRESOURCE-15182758 in earlier versions.

Source
Istio1.27.6Networking & MessagingFeb 10, 2026

This release includes security safeguards for gateway resource creation and pod specification rendering, along with stricter authorization for debug endpoints. It also adds a Helm configuration field and corrects a TLS configuration mapping.

Action needed (1)

  • securityResource annotation validation

    Resource annotation validation now rejects newline and control characters that could inject containers into pod specifications through template rendering.

Check if affected (2)

  • securityGateway deployment controller resource validation

    Applies if the gateway deployment controller runs.

  • breakingNamespace-based authorization for debug endpoints

    Applies if you use debug endpoints on port 15014.

Source
Keycloak26.5.3SecurityFeb 10, 2026

A maintenance release focused on security fixes, with additional ordinary bug corrections. It also includes startup-memory corrections and a removal related to that area.

Action needed (4)

  • securityhighCVE-2026-1609, disabled users obtaining tokens through the JWT Authorization Grant

    Keycloak 26.5.3 fixes an issue where disabled users could still obtain tokens through the JWT Authorization Grant.

  • securityhighCVE-2026-1529, forged invitation JWT enabling cross-organization self-registration

    Keycloak 26.5.3 fixes an issue where a forged invitation JWT could enable self-registration across organizations.

  • securityhighCVE-2026-1486, authentication through disabled identity providers

    Keycloak 26.5.3 fixes a logic bypass in the JWT Authorization Grant that allowed authentication through disabled identity providers.

  • securitymediumCVE-2025-14778, incorrect ownership checks in /uma-policy/

    Keycloak 26.5.3 fixes incorrect ownership checks in the /uma-policy/ endpoint.

Source
Jaegerv2.15.1ObservabilityFeb 9, 2026

This release removes a deprecated v1 adapter wrapper and changes the default span kind in API v3 operations. The remaining release notes do not describe distinct operator-facing changes.

Action needed (1)

  • breakingDeprecated protofromtraces wrapper removal

    The deprecated protofromtraces wrapper has been removed from v1adapter.

Source
Rookv1.19.1Storage & DataFeb 5, 2026

A maintenance release with operator-facing removals, default and behavior changes, new CRD fields, expanded configuration support, and dependency updates. No security advisory is disclosed.

Action needed (1)

  • breakingNodes/proxy RBAC enablement removal

    The unnecessary nodes/proxy RBAC enablement is removed.

Check if affected (2)

  • breakingDefault Ceph image pull policy

    Applies if you do not configure ceph image pull policy.

  • breakingAutomated node fencing code removal

    Applies if automated node fencing runs.

Source
wasmCloudv1.9.2Orchestration & ManagementFeb 4, 2026

This release changes NATS connection authentication and the component spec feature. Dependency and OCI image base updates are also included.

Action needed (1)

  • breakingThe component spec feature, removed

    The component spec feature is removed in this release.

Source
Vitessv23.0.1Storage & DataFeb 4, 2026

Vitess v23.0.1 is a maintenance release focused on bug fixes and behavior corrections. It also adds CLI and TabletManager capabilities and updates dependencies.

Action needed (1)

  • securityThe golang.org/x/crypto dependency, updated

    Vitess v23.0.1 updates golang.org/x/crypto from 0.42.0 to 0.45.0.

Source
Kubescapev4.0.0SecurityFeb 4, 2026

Kubescape v4.0.0 expands operator capabilities while changing sensing architecture and scan output behavior. It also updates a dependency, improves scan performance, and includes a fix for version handling and injection.

Action needed (1)

  • securityVersion handling and injection fix

    The release fixes version handling and injection in Kubescape v4.0.0.

Source
Ciliumv1.19.0Networking & MessagingFeb 4, 2026

A substantial operator-facing feature and maintenance release with new DNS proxy, installation, configuration, API, metric, and datapath capabilities. It also changes defaults and compatibility requirements, removes deprecated interfaces, migrates BGP APIs, and updates security-related dependencies.

Action needed (15)

  • securityThe github.com/containerd/containerd dependency, updated

    The github.com/containerd/containerd module is updated to v1.7.29.

  • securityThe github.com/go-viper/mapstructure/v2 dependency, updated

    The github.com/go-viper/mapstructure/v2 module is updated to v2.4.0.

  • securityThe github.com/docker/docker dependency, updated

    The github.com/docker/docker module is updated to v28.3.3+incompatible.

  • securityThe golang.org/x/crypto dependency, updated

    The golang.org/x/crypto module is updated to v0.45.0.

  • securityThe helm.sh/helm/v3 dependency, updated to v3.18.4

    The helm.sh/helm/v3 module is updated to v3.18.4.

  • securityThe helm.sh/helm/v3 dependency, updated to v3.18.5

    The helm.sh/helm/v3 module is updated to v3.18.5.

  • breakingThe plpmtud default, set to blackhole

    The default plpmtud mode is now blackhole (blackhole-detected).

  • breakingThe AddressScopeMax default, set to 254

    The default AddressScopeMax is changed to 254, the host scope, for GKE metadata server and HCP use cases. The related setting is --local-max-addr-scope.

  • breakingThe tls authMode default, set to migration

    tls authMode is set to migration by default.

  • breakingThe CNI deletion timeout, reduced to 1.5 seconds

    The CNI deletion timeout is reduced to 1.5 seconds.

  • breakingThe policy-default-local-cluster default

    policy-default-local-cluster is now set by default.

  • breakingHost firewall bypass, disabled by default

    Host firewall bypass is disabled by default.

  • breakingFQDN match pattern sanitization

    FQDN match pattern sanitization is refactored and tightened.

  • breakingEncrypted traffic forwarding via cilium_host, removed

    Forwarding encrypted traffic via cilium_host has been removed.

  • breakingCNI configuration in the container image, removed

    The CNI configuration is no longer installed in the container image.

Check if affected (30)

  • breakingLocal-cluster default for network policy selectors

    Applies if you do not set cluster in network policy selectors.

  • breakingThe CiliumBGPPeeringPolicy v1 API, removed

    Applies if you use CiliumBGPPeeringPolicy.

  • breakingMutual Authentication, disabled by default

    Applies if you enable Mutual Authentication.

  • + 27 more on the release page

Plan ahead (7)

  • deprecated--enable-ipsec-encrypted-overlay, deprecatedremoval date not announced

    Applies if you use --enable-ipsec-encrypted-overlay.

  • deprecatedKafka match fields and ToRequires and FromRequires, deprecated

    Applies if you use ToRequires or FromRequires.

  • deprecatedTLS certificate and key Helm values, deprecated

    Applies if you pass TLS certificates or keys in Helm values.

  • + 4 more on the release page
Source
Crossplanev2.1.4Orchestration & ManagementFeb 3, 2026

Crossplane v2.1.4 is a maintenance release with security-related dependency updates. It also includes corrections for shared transitive dependency upgrades, so the release concerns operators tracking dependency and security fixes.

Action needed (4)

  • securityThe github.com/quic-go/quic-go module, updated to v0.57.0

    The release updates the github.com/quic-go/quic-go module to v0.57.0 as a security-related dependency change.

  • securitysigstore dependency updates for CVEs

    The release updates sigstore dependencies to fix CVEs.

  • securityThe github.com/theupdateframework/go-tuf/v2 module, updated to v2.4.1

    The release updates the github.com/theupdateframework/go-tuf/v2 module to v2.4.1 as a security-related dependency change.

  • securityThe github.com/go-chi/chi/v5 module, updated to v5.2.4

    The release updates the github.com/go-chi/chi/v5 module to v5.2.4 as a security-related dependency change.

Source
Crossplanev2.0.7Orchestration & ManagementFeb 3, 2026

This release updates a security-related dependency and corrects shared transitive dependency upgrades. It also fixes propagation of composite identity through nested XR trees.

Action needed (1)

  • securityThe github.com/theupdateframework/go-tuf/v2 dependency, updated to v2.4.1

    The github.com/theupdateframework/go-tuf/v2 module is updated to v2.4.1 in the release-2.0 branch.

Source
Crossplanev1.20.5Orchestration & ManagementFeb 3, 2026

Crossplane v1.20.5 is a maintenance release focused on dependency updates. It includes a security-related update to sigstore dependencies and addresses a defect in shared transitive dependency upgrades.

Action needed (1)

  • securityThe sigstore dependencies, updated for CVE fixes

    The release-1.20 branch updates sigstore dependencies to fix CVEs.

Source
Backstagev1.46.5CI/CD & App DeliveryFeb 2, 2026

This is a maintenance release with security fixes backported from v1.47.3. The fixes affect operators using the v1.46.5 release line.

Action needed (1)

  • securityBackported security fixes from v1.47.3

    This release contains backported security fixes from v1.47.3.

Source
cert-managerv1.18.5SecurityFeb 2, 2026

cert-manager v1.18.5 contains a security fix for GHSA-gx3x-vq4p-mhhv alongside other bug fixes. It also adds IPv6 HTTP-01 support and updates the Go toolchain.

Action needed (1)

  • securitymediumGHSA-gx3x-vq4p-mhhv denial-of-service fix

    cert-manager v1.18.5 fixes the denial-of-service issue identified by GHSA-gx3x-vq4p-mhhv. The release contains three bug fixes in total.

Source
Kyvernov1.17.0SecurityFeb 2, 2026

A substantial feature and maintenance release adds CEL and policy capabilities while correcting controller and API defects. It also includes security fixes, including a kubectl image update for CVEs, along with dependency and integration changes.

Action needed (2)

  • securitySecurity vulnerabilities addressed

    Security vulnerabilities are addressed in this release.

  • securityUpdated kubectl image for CVE fixes

    The kubectl image is updated to address CVEs in this release.

Check if affected (2)

  • breakingRestricted resource access in namespaced CEL policy types

    Applies if you use namespaced CEL policy types.

  • breakingOpt-in VAP/MAP reporting

    Applies if you use VAP/MAP reporting.

Source
Argov3.3.0CI/CD & App DeliveryFeb 2, 2026

Argo v3.3.0 is a substantial feature and maintenance release with changes across synchronization, health, hydration, diff and apply behavior, the UI, and resource operations. It also updates core dependencies and removes an app controller flag.

Action needed (3)

  • securityThe k8s.io/kubernetes module, updated to v1.34.2

    The k8s.io/kubernetes module is updated to v1.34.2 in Argo v3.3.0.

  • securityHelm 3.19.4

    Helm is updated to 3.19.4 in Argo v3.3.0.

  • securityRedis, updated to the latest stable release

    Redis is updated to the latest stable release in Argo v3.3.0.

Check if affected (1)

  • breakingThe --self-heal-backoff-cooldown-seconds flag, removed

    Applies if your app controller configuration uses --self-heal-backoff-cooldown-seconds.

Source
Browse by month