RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Istio1.29.0Networking & MessagingFeb 16, 2026

This release adds operator-visible capabilities and changes several runtime defaults. Ambient mesh behavior, debug endpoint authorization, metrics compression, and istiod memory and circuit-breaker behavior receive particular attention.

Action needed (1)

  • breakingAutomatic GOMEMLIMIT setting for istiod

    istiod now automatically sets GOMEMLIMIT to 90% of its memory limits through the automemlimit library. This reduces the risk of OOM kills while maintaining performance.

Check if affected (4)

  • breakingDefault iptables reconciliation

    Applies when the istio-cni DaemonSet is upgraded.

  • breakingDefault debug endpoint authorization

    Applies to debug endpoints on port 15014.

  • breakingDefault HTTP compression for Envoy metrics

    Applies to Envoy metrics at the Prometheus stats endpoint based on client Accept-Header values.

  • + 1 more on the release page
Source
Ciliumv1.18.7Networking & MessagingFeb 13, 2026

A maintenance release combining an operator-facing configuration adjustment with bug fixes and routine dependency and image refreshes. No security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingExclusion of topology.kubernetes.io labels from security labels by default

    The default security-label handling in this release excludes topology.kubernetes.io labels from security labels.

Source
etcdv3.6.8Kubernetes CoreFeb 13, 2026

A maintenance release postpones removal of one flag and reverses another flag's deprecation. It also includes dependency and toolchain updates addressing named security advisories.

Action needed (2)

Plan ahead (1)

  • deprecatedThe --max-snapshots flag, removal postponedremoval planned in v3.8

    Applies if you use --max-snapshots.

Source
etcdv3.5.27Kubernetes CoreFeb 13, 2026

A maintenance release that changes the Go toolchain used to compile binaries. It also includes fixes for three named CVEs and their corresponding GHSA advisories.

Action needed (1)

Source
Daprv1.16.9Orchestration & ManagementFeb 12, 2026

This release includes a Go toolchain dependency upgrade and a corrected Pulsar PubSub subscription-metadata defect. A regression test verifies that metadata is applied to consumer options.

Action needed (1)

  • securityhighThe Go toolchain upgrade to 1.24.13

    Dapr v1.16.9 upgrades Go to 1.24.13. The upgrade addresses advisories GO-2026-4340 and GO-2026-4341.

Source
OpenFGAv1.11.5SecurityFeb 11, 2026

This release includes an operator-facing toolchain update. The change addresses CVE-2025-68121 in OpenFGA v1.11.5.

Action needed (1)

  • securitycriticalThe Go toolchain, updated to 1.25.7

    The Go toolchain is updated to 1.25.7 in OpenFGA v1.11.5 to address CVE-2025-68121.

Source
OpenFGAv1.11.4SecurityFeb 10, 2026

OpenFGA v1.11.4 fixes a planner regression in specific scenarios and updates the OpenTelemetry SDK. The SDK change addresses a disclosed issue affecting earlier versions.

Action needed (1)

  • securityThe otel/sdk dependency at v1.40.0

    The otel/sdk dependency is upgraded to v1.40.0 in OpenFGA v1.11.4 to address the issue identified as SNYK-GOLANG-GOOPENTELEMETRYIOOTELSDKRESOURCE-15182758 in earlier versions.

Source
Istio1.27.6Networking & MessagingFeb 10, 2026

This release includes security safeguards for gateway resource creation and pod specification rendering, along with stricter authorization for debug endpoints. It also adds a Helm configuration field and corrects a TLS configuration mapping.

Action needed (1)

  • securityResource annotation validation

    Resource annotation validation now rejects newline and control characters that could inject containers into pod specifications through template rendering.

Check if affected (2)

  • securityGateway deployment controller resource validation

    Applies if the gateway deployment controller runs.

  • breakingNamespace-based authorization for debug endpoints

    Applies if you use debug endpoints on port 15014.

Source
Keycloak26.5.3SecurityFeb 10, 2026

A maintenance release focused on security fixes, with additional ordinary bug corrections. It also includes startup-memory corrections and a removal related to that area.

Action needed (4)

  • securityhighCVE-2026-1609, disabled users obtaining tokens through the JWT Authorization Grant

    Keycloak 26.5.3 fixes an issue where disabled users could still obtain tokens through the JWT Authorization Grant.

  • securityhighCVE-2026-1529, forged invitation JWT enabling cross-organization self-registration

    Keycloak 26.5.3 fixes an issue where a forged invitation JWT could enable self-registration across organizations.

  • securityhighCVE-2026-1486, authentication through disabled identity providers

    Keycloak 26.5.3 fixes a logic bypass in the JWT Authorization Grant that allowed authentication through disabled identity providers.

  • securitymediumCVE-2025-14778, incorrect ownership checks in /uma-policy/

    Keycloak 26.5.3 fixes incorrect ownership checks in the /uma-policy/ endpoint.

Source
Jaegerv2.15.1ObservabilityFeb 9, 2026

This release removes a deprecated v1 adapter wrapper and changes the default span kind in API v3 operations. The remaining release notes do not describe distinct operator-facing changes.

Action needed (1)

  • breakingDeprecated protofromtraces wrapper removal

    The deprecated protofromtraces wrapper has been removed from v1adapter.

Source
Rookv1.19.1Storage & DataFeb 5, 2026

A maintenance release with operator-facing removals, default and behavior changes, new CRD fields, expanded configuration support, and dependency updates. No security advisory is disclosed.

Action needed (1)

  • breakingNodes/proxy RBAC enablement removal

    The unnecessary nodes/proxy RBAC enablement is removed.

Check if affected (2)

  • breakingDefault Ceph image pull policy

    Applies if you do not configure ceph image pull policy.

  • breakingAutomated node fencing code removal

    Applies if automated node fencing runs.

Source
wasmCloudv1.9.2Orchestration & ManagementFeb 4, 2026

This release changes NATS connection authentication and the component spec feature. Dependency and OCI image base updates are also included.

Action needed (1)

  • breakingThe component spec feature, removed

    The component spec feature is removed in this release.

Source
Vitessv23.0.1Storage & DataFeb 4, 2026

Vitess v23.0.1 is a maintenance release focused on bug fixes and behavior corrections. It also adds CLI and TabletManager capabilities and updates dependencies.

Action needed (1)

  • securityThe golang.org/x/crypto dependency, updated

    Vitess v23.0.1 updates golang.org/x/crypto from 0.42.0 to 0.45.0.

Source
Kubescapev4.0.0SecurityFeb 4, 2026

Kubescape v4.0.0 expands operator capabilities while changing sensing architecture and scan output behavior. It also updates a dependency, improves scan performance, and includes a fix for version handling and injection.

Action needed (1)

  • securityVersion handling and injection fix

    The release fixes version handling and injection in Kubescape v4.0.0.

Source
Ciliumv1.19.0Networking & MessagingFeb 4, 2026

A substantial operator-facing feature and maintenance release with new DNS proxy, installation, configuration, API, metric, and datapath capabilities. It also changes defaults and compatibility requirements, removes deprecated interfaces, migrates BGP APIs, and updates security-related dependencies.

Action needed (15)

  • securityThe github.com/containerd/containerd dependency, updated

    The github.com/containerd/containerd module is updated to v1.7.29.

  • securityThe github.com/go-viper/mapstructure/v2 dependency, updated

    The github.com/go-viper/mapstructure/v2 module is updated to v2.4.0.

  • securityThe github.com/docker/docker dependency, updated

    The github.com/docker/docker module is updated to v28.3.3+incompatible.

  • securityThe golang.org/x/crypto dependency, updated

    The golang.org/x/crypto module is updated to v0.45.0.

  • securityThe helm.sh/helm/v3 dependency, updated to v3.18.4

    The helm.sh/helm/v3 module is updated to v3.18.4.

  • securityThe helm.sh/helm/v3 dependency, updated to v3.18.5

    The helm.sh/helm/v3 module is updated to v3.18.5.

  • breakingThe plpmtud default, set to blackhole

    The default plpmtud mode is now blackhole (blackhole-detected).

  • breakingThe AddressScopeMax default, set to 254

    The default AddressScopeMax is changed to 254, the host scope, for GKE metadata server and HCP use cases. The related setting is --local-max-addr-scope.

  • breakingThe tls authMode default, set to migration

    tls authMode is set to migration by default.

  • breakingThe CNI deletion timeout, reduced to 1.5 seconds

    The CNI deletion timeout is reduced to 1.5 seconds.

  • breakingThe policy-default-local-cluster default

    policy-default-local-cluster is now set by default.

  • breakingHost firewall bypass, disabled by default

    Host firewall bypass is disabled by default.

  • breakingFQDN match pattern sanitization

    FQDN match pattern sanitization is refactored and tightened.

  • breakingEncrypted traffic forwarding via cilium_host, removed

    Forwarding encrypted traffic via cilium_host has been removed.

  • breakingCNI configuration in the container image, removed

    The CNI configuration is no longer installed in the container image.

Check if affected (30)

  • breakingLocal-cluster default for network policy selectors

    Applies if you do not set cluster in network policy selectors.

  • breakingThe CiliumBGPPeeringPolicy v1 API, removed

    Applies if you use CiliumBGPPeeringPolicy.

  • breakingMutual Authentication, disabled by default

    Applies if you enable Mutual Authentication.

  • + 27 more on the release page

Plan ahead (7)

  • deprecated--enable-ipsec-encrypted-overlay, deprecatedremoval date not announced

    Applies if you use --enable-ipsec-encrypted-overlay.

  • deprecatedKafka match fields and ToRequires and FromRequires, deprecated

    Applies if you use ToRequires or FromRequires.

  • deprecatedTLS certificate and key Helm values, deprecated

    Applies if you pass TLS certificates or keys in Helm values.

  • + 4 more on the release page
Source
Crossplanev2.1.4Orchestration & ManagementFeb 3, 2026

Crossplane v2.1.4 is a maintenance release with security-related dependency updates. It also includes corrections for shared transitive dependency upgrades, so the release concerns operators tracking dependency and security fixes.

Action needed (4)

  • securityThe github.com/quic-go/quic-go module, updated to v0.57.0

    The release updates the github.com/quic-go/quic-go module to v0.57.0 as a security-related dependency change.

  • securitysigstore dependency updates for CVEs

    The release updates sigstore dependencies to fix CVEs.

  • securityThe github.com/theupdateframework/go-tuf/v2 module, updated to v2.4.1

    The release updates the github.com/theupdateframework/go-tuf/v2 module to v2.4.1 as a security-related dependency change.

  • securityThe github.com/go-chi/chi/v5 module, updated to v5.2.4

    The release updates the github.com/go-chi/chi/v5 module to v5.2.4 as a security-related dependency change.

Source
Crossplanev2.0.7Orchestration & ManagementFeb 3, 2026

This release updates a security-related dependency and corrects shared transitive dependency upgrades. It also fixes propagation of composite identity through nested XR trees.

Action needed (1)

  • securityThe github.com/theupdateframework/go-tuf/v2 dependency, updated to v2.4.1

    The github.com/theupdateframework/go-tuf/v2 module is updated to v2.4.1 in the release-2.0 branch.

Source
Crossplanev1.20.5Orchestration & ManagementFeb 3, 2026

Crossplane v1.20.5 is a maintenance release focused on dependency updates. It includes a security-related update to sigstore dependencies and addresses a defect in shared transitive dependency upgrades.

Action needed (1)

  • securityThe sigstore dependencies, updated for CVE fixes

    The release-1.20 branch updates sigstore dependencies to fix CVEs.

Source
Backstagev1.46.5CI/CD & App DeliveryFeb 2, 2026

This is a maintenance release with security fixes backported from v1.47.3. The fixes affect operators using the v1.46.5 release line.

Action needed (1)

  • securityBackported security fixes from v1.47.3

    This release contains backported security fixes from v1.47.3.

Source
cert-managerv1.18.5SecurityFeb 2, 2026

cert-manager v1.18.5 contains a security fix for GHSA-gx3x-vq4p-mhhv alongside other bug fixes. It also adds IPv6 HTTP-01 support and updates the Go toolchain.

Action needed (1)

  • securitymediumGHSA-gx3x-vq4p-mhhv denial-of-service fix

    cert-manager v1.18.5 fixes the denial-of-service issue identified by GHSA-gx3x-vq4p-mhhv. The release contains three bug fixes in total.

Source
Kyvernov1.17.0SecurityFeb 2, 2026

A substantial feature and maintenance release adds CEL and policy capabilities while correcting controller and API defects. It also includes security fixes, including a kubectl image update for CVEs, along with dependency and integration changes.

Action needed (2)

  • securitySecurity vulnerabilities addressed

    Security vulnerabilities are addressed in this release.

  • securityUpdated kubectl image for CVE fixes

    The kubectl image is updated to address CVEs in this release.

Check if affected (2)

  • breakingRestricted resource access in namespaced CEL policy types

    Applies if you use namespaced CEL policy types.

  • breakingOpt-in VAP/MAP reporting

    Applies if you use VAP/MAP reporting.

Source
Argov3.3.0CI/CD & App DeliveryFeb 2, 2026

Argo v3.3.0 is a substantial feature and maintenance release with changes across synchronization, health, hydration, diff and apply behavior, the UI, and resource operations. It also updates core dependencies and removes an app controller flag.

Action needed (3)

  • securityThe k8s.io/kubernetes module, updated to v1.34.2

    The k8s.io/kubernetes module is updated to v1.34.2 in Argo v3.3.0.

  • securityHelm 3.19.4

    Helm is updated to 3.19.4 in Argo v3.3.0.

  • securityRedis, updated to the latest stable release

    Redis is updated to the latest stable release in Argo v3.3.0.

Check if affected (1)

  • breakingThe --self-heal-backoff-cooldown-seconds flag, removed

    Applies if your app controller configuration uses --self-heal-backoff-cooldown-seconds.

Source
Longhornv1.11.0Storage & DataJan 29, 2026

A substantial feature and maintenance release with V2 Data Engine changes, new capabilities, dependency updates, numerous fixes, and hotfix image replacements. It also deprecates V2 Backing Image functionality and includes a fix for an SPDK v25.05 CVE issue without a disclosed advisory identifier.

Action needed (1)

  • securityThe SPDK v25.05 CVE issue fix

    The CVE issue in SPDK v25.05 is fixed in this release.

Check if affected (7)

  • breakingThe longhornio/longhorn-instance-manager:v1.11.0 image replacement

    Applies if you use longhornio/longhorn-instance-manager:v1.11.0.

  • breakingThe longhornio/longhorn-manager:v1.11.0 image replacement

    Applies if you use longhornio/longhorn-manager:v1.11.0.

  • breakingBackupstore-related settings removal

    Applies if you configure backupstore related settings.

  • + 4 more on the release page

Plan ahead (2)

  • deprecatedBacking Image for the V2 Data Engine deprecationremoval planned in v1.12.0

    Applies if you use Backing Image and the V2 Data Engine.

  • deprecatedV2 Backing Image Feature deprecation

    Applies if you use the V2 Backing Image Feature.

Source
OpenFGAv1.11.3SecurityJan 28, 2026

This release adds configuration and observability capabilities while changing throttling and metric behavior. It also fixes correctness defects, including a described improper policy enforcement issue.

Action needed (2)

  • securitymediumThe CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9 policy enforcement fix

    The release fixes improper policy enforcement associated with CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9.

  • breakingThe custom grpc_code metric label, removed

    The custom grpc_prometheus fork is replaced with go-grpc-middleware's provider, and the custom grpc_code label is removed from the metric.

Source
Kyvernov1.15.3SecurityJan 27, 2026

A maintenance release with security-related fixes for the Go toolchain and cross-namespace access through apiCall. It also contains ordinary defect fixes and capability or behavior changes.

Action needed (1)

  • securityThe go version update for standard library CVEs

    The go version is updated to fix standard library CVEs in this release.

Check if affected (1)

  • securityCross-namespace access through apiCall prevented

    Applies if you use apiCall.

Source
Keycloak26.5.2SecurityJan 23, 2026

Keycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.

Action needed (3)

  • securitymediumCVE-2025-67735 in netty-codec-http

    CVE-2025-67735 addresses request smuggling via CRLF injection in netty-codec-http. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-66560 in io.quarkus/quarkus-rest

    CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in io.quarkus/quarkus-rest. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-14559 in keycloak-services

    CVE-2025-14559 addresses a business logic flaw in keycloak-services that allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.

Source
Helmv3.20.0Kubernetes CoreJan 21, 2026

A maintenance release with dependency and toolchain updates, several defect corrections, and a new repository timeout flag. The pkg/registry login option for passing TLS configuration in memory has been removed.

Action needed (1)

  • breakingThe pkg/registry in-memory TLS configuration login option, removed

    The pkg/registry login option for passing TLS configuration in memory is reverted and does not ship in this release.

Source
hamiv2.8.0AI & MLJan 20, 2026

Release v2.8.0 adds capabilities and metrics, corrects multiple defects, and updates dependencies. The nvidia-mig-parted upgrade addresses security issues.

Action needed (1)

  • securityThe nvidia-mig-parted dependency, upgraded to v0.12.2

    HAMi v2.8.0 upgrades the nvidia-mig-parted dependency to v0.12.2 to address security issues.

Source
CoreDNSv1.14.1Kubernetes CoreJan 16, 2026

A security-focused maintenance release addresses disclosed Go vulnerabilities and improves proxy connection-pool performance. It also adds the forward plugin's max_idle_conns parameter, which defaults to 0 for an unbounded pool.

Action needed (1)

  • securityhighCVE-2025-68119 fix

    The release also addresses CVE-2025-68119, which affects the stated Go versions.

Check if affected (1)

  • securitycriticalGo security vulnerability fixes

    Applicability is not stated in the release notes.

Source
Ciliumv1.18.6Networking & MessagingJan 13, 2026

A maintenance release with fixes for networking, policy, proxy, gateway API, and endpoint handling, plus dependency, image, and OCI publishing updates. The Cilium Preflight check no longer includes Envoy Configmaps.

Action needed (1)

  • breakingCilium Preflight check no longer includes Envoy Configmaps

    The Cilium Preflight check no longer includes Envoy Configmaps. This change ships in v1.18.6.

Source
Envoyv1.37.0Networking & MessagingJan 13, 2026

This release adds dynamic-module, filter, routing, observability, and certificate capabilities, along with fixes and performance improvements across HTTP, networking, and protocol handling. It also changes HTTP reset behavior, removes runtime guards and legacy code paths, and deprecates the OpenTelemetry access log common_config field.

Action needed (1)

  • breakingRuntime guards and legacy code paths removed

    Multiple runtime guards and legacy code paths are removed in this release.

Check if affected (2)

  • breakingDefault HTTP reset code changed

    Applicability is not stated in the release notes.

  • breakingDefault upstream protocol error reset handling changed

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedOpenTelemetry access log common_config field deprecated

    Applies if you configure common_config.

Source
CoreDNSv1.14.0Kubernetes CoreJan 8, 2026

A maintenance release with a new regex length constraint, correctness fixes, and plugin capability and behavior changes. It does not disclose a security advisory or explicitly exploitable vulnerability.

Action needed (1)

  • breakingThe core regex length limit

    core adds a length limit for regular expressions.

Source
Prometheusv3.9.0ObservabilityJan 7, 2026

This release updates histogram collection and TSDB behavior while adding capabilities across the API, PromQL, storage, and UI. It also includes fixes for query handling, storage validation, receivers, and interface behavior.

Action needed (1)

  • breakingA 10,000-set limit for the TSDB status endpoint

    The TSDB status endpoint now limits responses to a maximum of 10,000 sets of statistics.

Check if affected (1)

  • breakingThe native-histogram feature flag has no effect

    Applies if you set scrape_native_histograms to collect Native Histogram samples from exporters.

Source
Fluidv1.0.8Orchestration & ManagementOct 31, 2025

This release combines operator-facing additions with enforced defaults and restrictions, defect fixes, and dependency and image updates. New support includes native sidecar injection, ThinRuntime metadata configuration, and additional storage client types.

Action needed (1)

  • breakingRestricted service account permissions

    Service account permissions are restricted. The sample file samples/juicefs/read_job.yaml is included.

Check if affected (1)

  • breakingRemoval of the redundant SYS_ADMIN capability from runtime engines

    Applies if you use runtime engines.

Source
← Newer
Browse by month