RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

May 2026Clear ×
Fluxv2.8.7CI/CD & App DeliveryMay 12, 2026

Flux v2.8.7 includes a security update to the go-git dependency alongside toolkit component updates. The go-git update addresses CVE-2026-45022 and GHSA-389r-gv7p-r3rp.

Action needed (1)

  • securityhighThe go-git dependency update to v5.19.0

    The go-git dependency is updated to v5.19.0, which fixes CVE-2026-45022 and addresses GHSA-389r-gv7p-r3rp. This update ships in Flux v2.8.7.

Source
Open Policy Agent (OPA)v1.16.2SecurityMay 12, 2026

OPA v1.16.2 is a security-focused maintenance release. It updates the Go version used to build OPA binaries and images to 1.26.3 to address vulnerabilities.

Action needed (1)

  • securityThe Go build version, updated to 1.26.3

    The version of Go used to build OPA binaries and images is updated to 1.26.3 to address vulnerabilities.

Source
Flatcar Container Linuxstable-4593.2.1Provisioning & RuntimeMay 11, 2026

This is a security-focused Flatcar release with disclosed Linux security fixes. It also updates the Linux and ca-certificates dependencies.

Action needed (1)

  • securitycriticalLinux security updates, including CVE-2026-31733

    Linux receives security updates in Flatcar stable-4593.2.1, including CVE-2026-31733 and the other disclosed Linux advisories listed for this change.

Source
metal3-iov0.13.0Provisioning & RuntimeMay 8, 2026

This release removes the iRMC driver and legacy vbmctl entrypoint, deprecates BMH.Spec.Firmware, and changes defaults and constraints. It also adds HostClaim and vbmctl capabilities, corrects bugs, and updates dependencies.

Action needed (1)

  • breakingManager TLS default set to unset

    The manager TLS default is set back to unset in this release.

Check if affected (3)

  • breakingThe iRMC driver, removed

    Applies if you use the iRMC driver.

  • breakingPreprovisioningImage required for deprovisioning

    Applies if cleaning is enabled.

  • breakingThe legacy vbmctl entrypoint, removed

    Applies if you use the legacy vbmctl entrypoint.

Plan ahead (1)

  • deprecatedThe BMH.Spec.Firmware field, deprecated

    Applies if you configure BMH.Spec.Firmware.

Source
Vitessv23.0.4Storage & DataMay 7, 2026

A maintenance release with bug fixes, compatibility and behavior changes, operational improvements, metric updates, and two Go dependency upgrades. It includes no disclosed security advisories or explicitly security-related fixes.

Action needed (2)

  • breakingUnqualified * rejection after commas in SELECT lists

    vtgate now rejects an unqualified * after a comma in a SELECT list. The change ships in this release.

  • breakingBare * restriction in the sqlparser grammar

    sqlparser now enforces the restriction on bare * in its grammar. The change ships in this release.

Check if affected (1)

  • breakingEmergencyReparentShard replication-stop error validation

    Applies if you use EmergencyReparentShard.

Source
Harborv2.15.1Storage & DataMay 6, 2026

Harbor v2.15.1 is a maintenance release with defect corrections, behavior changes, and dependency and base-image updates. It also updates photon packages to fix CVEs.

Action needed (1)

  • securityphoton packages CVE fixes

    The photon packages are updated to fix CVEs in Harbor v2.15.1.

Source
Argov3.4.1CI/CD & App DeliveryMay 6, 2026

A broad maintenance and feature release with correctness, performance, dependency, and operator-facing changes. Operators should review the cluster-version annotation format and changed defaults, while dependency updates include Kubernetes and Helm changes; no explicitly disclosed exploitable vulnerability or security advisory is identified.

Action needed (4)

  • securityThe k8s.io/kubernetes module, updated to v1.34.2

    The k8s.io/kubernetes module is updated to v1.34.2 as a security-related dependency update.

  • securityThe helm dependency, updated to 3.19.4

    The helm dependency is updated to 3.19.4 due to a CVE.

  • breakinggRPC service config DNS TXT lookups, disabled by default

    gRPC service config DNS TXT lookups are disabled by default.

  • breakingThe appset resource status count, defaulted to 5000

    The default appset resource status count is changed to 5000.

Check if affected (2)

  • breakingThe --client flag in the Helm version command, removed

    Applies if you use --client.

  • breakingThe cluster-version annotation format, renamed

    Applies if you use Application Sets with Cluster Generators and configure argocd.argoproj.io/auto-label-cluster-info.

Source
CRI-Ov1.36.0Kubernetes CoreMay 5, 2026

CRI-O v1.36.0 is a substantive operator-facing feature and maintenance release with runtime and operational changes. It also includes a security update to spdystream and a broad dependency refresh.

Action needed (1)

  • securityhighThe spdystream dependency update for CVE-2026-35469

    CRI-O v1.36.0 updates the spdystream dependency to fix CVE-2026-35469.

Source
Confidential Containersv0.20.0SecurityMay 5, 2026

Confidential Containers v0.20.0 combines operator-visible capability and compatibility updates with deprecations of several image and provider paths. It also includes a security fix identified by GHSA-q49m-57vm-c8cc.

Action needed (1)

  • securityhighGHSA-q49m-57vm-c8cc security fix

    The release includes a fix for the security issue identified by GHSA-q49m-57vm-c8cc.

Plan ahead (3)

  • deprecatedThe Docker CAA provider, deprecatedremoval date not announced

    Applies if you use the Docker CAA provider.

  • breakingThe Fedora-based mkosi CAA podvm image, deprecatedremoval date not announced

    Applies if you use the Fedora-based mkosi CAA podvm image.

  • deprecatedSupport for packer images, deprecatedremoval date not announced

    Applies if you use packer images.

Source
CRI-Ov1.35.3Kubernetes CoreMay 5, 2026

A maintenance release that adds a runtime metric and a GOMAXPROCS configuration field, fixes two runtime defects, and reverts CNI monitoring after node bootstrapping regressions. It also updates the spdystream dependency to address CVE-2026-35469.

Action needed (2)

  • securityhighThe spdystream dependency update for CVE-2026-35469

    The spdystream dependency is updated to address CVE-2026-35469. The update ships in this release.

  • breakingCRI-O CNI monitoring, reverted

    CRI-O reverts CNI monitoring because it caused node bootstrapping regressions. The change ships in this release.

Source
CRI-Ov1.34.8Kubernetes CoreMay 5, 2026

CRI-O v1.34.8 includes a security-relevant dependency update and adds operator-facing observability and configuration capabilities. The dependency update is the release change that requires upgrading, while the other additions concern optional setup or informational use.

Action needed (1)

  • securityhighCVE-2026-35469 fix in the spdystream dependency

    CRI-O v1.34.8 updates the spdystream dependency to fix CVE-2026-35469.

Source
CRI-Ov1.33.12Kubernetes CoreMay 5, 2026

CRI-O v1.33.12 includes a security fix for a disclosed vulnerability in the spdystream dependency. It also adds the min_injected_gomaxprocs configuration field for controlling the floor of injected GOMAXPROCS values.

Action needed (1)

  • securityhighCVE-2026-35469 fix in the spdystream dependency

    CVE-2026-35469 is fixed by updating the spdystream dependency in CRI-O v1.33.12.

Source
wasmCloudv2.0.6Orchestration & ManagementMay 1, 2026

A maintenance release with correctness fixes for HTTP errors, NATS subscription readiness, and WorkloadDeployment readiness, plus dependency and toolchain updates. It removes canary-v2 now that canary exists and includes dependency cleanup.

Action needed (1)

  • breakingThe canary-v2 option, removed

    canary-v2 is removed now that canary exists. The removal ships in this release.

Source
etcdv3.6.11Kubernetes CoreMay 1, 2026

A maintenance release with a correctness fix, an RBAC authorization bypass fix, and a security-related dependency update for GO-2026-4962. It also records Go 1.25.9 as the toolchain used to build the binaries.

Action needed (1)

  • securitymediumgolang.org/x/image update for GO-2026-4962

    The release updates golang.org/x/image to v0.39.0 to resolve GO-2026-4962.

Check if affected (1)

  • securityRBAC authorization bypass in nested Put requests

    Applies if you use RBAC.

Source
etcdv3.5.30Kubernetes CoreMay 1, 2026

A maintenance release with a security fix for an RBAC authorization bypass in transaction handling. It also includes an ordinary correctness fix and a Go toolchain dependency update.

Action needed (1)

  • securityRBAC authorization bypass in nested etcd transactions

    The release fixes an RBAC authorization bypass that allowed read access through PrevKv or lease attachment in Put requests nested in etcd transactions. The fix ships in this release.

Source
← Newer
Browse by month