This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.
Action needed (1)
security
Go1.25.10 dependency updateGois updated to1.for CVE remediation in this release.25. 10
AI-analyzed release notes for CNCF graduated and incubating projects.
This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.
Action needed (1)
securityGo 1.25.10 dependency update
Go is updated to 1. for CVE remediation in this release.
Tekton v1.9.6 contains dependency updates for CVE remediation. The release affects Go and two golang. packages, with no specific advisory identifiers or vulnerability details in the note.
Action needed (3)
securityGo 1.25.10 update
Go is updated to 1. for CVE remediation in v1.9.6.
securitygolang. v0.52.0 update
golang. is updated to v0. for CVE remediation in v1.9.6.
securitygolang. v0.55.0 update
golang. is updated to v0. for CVE remediation in v1.9.6.
A maintenance release with a forced internal PostgreSQL major-version upgrade, a redis to valkey cache backend replacement, dependency and component updates, and defect corrections. Token and blob-mount validation is hardened.
Action needed (1)
securityToken and blob-mount source validation
Blob-mount source projects are validated, and tokens without iat are rejected.
Check if affected (2)
breakingThe bundled PostgreSQL version, upgraded
Applies if you use PostgreSQL.
breakingThe cache backend, changed from redis to valkey
Applies if you use redis.
A maintenance release with authentication and certificate-revocation enforcement fixes, Go toolchain and dependency updates, and a new v2 deprecation option. The security-related changes include fixes and dependency updates associated with the listed advisories.
Action needed (2)
securityhighgo. dependencies, updated to v1.
The go. and go. dependencies are updated from v1. to v1.. The updates address CVE-2026-29181 and CVE-2026-39883.
securityhighgolang., updated to v0.
The golang. dependency is updated to v0.. The change is associated with CVE-2026-39828, CVE-2026-39835, CVE-2026-46597, and CVE-2026-46598.
Check if affected (1)
securityCRL enforcement bypass on the gRPC listener, fixed
Applies if --listen-client-http-urls is configured.
A maintenance release with server configuration, access control, authentication, validation, logging, and dependency updates. Deployments using the affected listener configuration or OpenTelemetry dependencies are directly concerned by the included fixes.
Action needed (1)
securityhighOpenTelemetry dependencies updated for CVE-2026-29181 and CVE-2026-39883
go. and go. were updated from v1. to v1.. The updates address CVE-2026-29181 and CVE-2026-39883.
Check if affected (1)
securityCRL enforcement with --listen-client-http-urls
Applies if --listen-client-http-urls is configured.
A long-term support release with security-related dependency updates, PromQL changes, new APIs and configuration controls, and bug fixes. It also replaces a shipped license artifact and includes performance improvements.
Action needed (2)
securitycriticalThe sanitize-html dependency update
The UI updates sanitize-html to address a cross-site scripting vulnerability, identified as CVE-2026-44990.
breakingThe third-party license artifact
Third-party npm dependency licenses are embedded in the Prometheus binary and served at /assets/third-party-licenses.. This replaces the npm_licenses. archive previously shipped in release tarballs and container images.
Check if affected (2)
securitymediumRedirect credential forwarding
Applies if you use scraping, remote read/write, alerting, or service discovery.
breakingPromQL duration-expression function names
Applies if you enable experimental-duration-expr and use min() and max().