RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: ArgoClear ×
Argov3.5.1CI/CD & App DeliveryAug 12, 2026

This release contains routine correctness fixes and a security fix in the server. The security change concerns users of the SSD CLI.

Action needed (1)

  • securitySSD CLI secret-mask spoofing prevention

    The server prevents secret-mask spoofing in the SSD CLI. This fix ships in Argo CD v3.5.1.

Source
Argov3.4.7CI/CD & App DeliveryAug 12, 2026

A maintenance release with correctness fixes, a server-side secret-mask spoofing fix, and a third-party dependency update. Ordinary fixes and the dependency update require no operator action, while upgrading addresses the security fix.

Action needed (1)

  • securitySSD CLI secret-mask spoofing prevention

    The server now prevents secret-mask spoofing in the SSD CLI. This fix ships in the 3.4 release line.

Source
Argov3.3.14CI/CD & App DeliveryAug 12, 2026

A maintenance release with fixes for secret masking and pprof endpoint configuration, alongside dependency updates for two listed CVEs. The secret-handling fixes and dependency updates are addressed by upgrading, while the remaining defect fixes require no operator action.

Action needed (2)

  • securityhighThe /ui brace-expansion dependency update for CVE-2026-69152

    The /ui dependency brace-expansion is updated to 2.1.4 and 1.1.18 for CVE-2026-69152.

  • securitymediumThe DOMPurify dependency update for CVE-2026-49978

    The DOMPurify dependency is updated to 3.4.7 for CVE-2026-49978.

Check if affected (2)

  • securitySSD CLI secret mask spoofing prevention

    Applies if you use SSD CLI.

    The SSD CLI secret mask spoofing fix ships in the server.

  • securitySecret hiding in the last-applied-configuration annotation

    Applies if you configure last-applied-configuration.

    The last-applied-configuration annotation no longer exposes secrets in SSD.

Source
Argov3.5.0CI/CD & App DeliveryAug 4, 2026

A maintenance release focused on operator-facing bug fixes, with additional feature and configuration work. It also includes dependency updates, including a UI dependency update for CVE-2026-41240.

Action needed (3)

  • securitymediumThe redoc/dompurify dependency update for CVE-2026-41240

    The UI dependency redoc/dompurify is bumped to v3.4.0 to fix CVE-2026-41240.

  • securityThe formidable dependency update

    The formidable dependency is updated to v2.1.3.

  • breakingThe auto-sync toggle removal from the app top bar

    The auto-sync toggle is removed from the app top bar.

Check if affected (1)

  • breakingThe theme default changed to auto

    Applies if theme is not configured.

    The default for theme is changed to auto in v3.5.0.

Source
Argov3.3.13CI/CD & App DeliveryJul 31, 2026

A maintenance release with bug fixes and dependency updates. The form-data update in /ui addresses CVE-2026-12143.

Action needed (1)

  • securityhighThe form-data dependency update for CVE-2026-12143

    The form-data dependency is updated to version 4.0.6 in /ui to address CVE-2026-12143.

Source
Argov3.3.11CI/CD & App DeliveryMay 28, 2026

Argo CD v3.3.11 contains bug fixes and a UI dependency update addressing CVE-2026-41240. The release concerns deployments using the affected UI dependency.

Action needed (1)

  • securitymediumThe redoc/dompurify dependency, updated to v3.4.0

    The /ui dependency redoc/dompurify is updated to v3.4.0 to address CVE-2026-41240.

Source
Argov3.3.10CI/CD & App DeliveryMay 12, 2026

This release combines bug fixes with dependency and toolchain updates. The Go update to 1.25.9 addresses CVEs and concerns deployments using this release.

Action needed (1)

  • securityThe Go toolchain, updated to 1.25.9

    The Go toolchain is updated to 1.25.9 on release-3.3 to resolve CVEs.

Source
Argov3.4.1CI/CD & App DeliveryMay 6, 2026

A broad maintenance and feature release with correctness, performance, dependency, and operator-facing changes. Operators should review the cluster-version annotation format and changed defaults, while dependency updates include Kubernetes and Helm changes; no explicitly disclosed exploitable vulnerability or security advisory is identified.

Action needed (4)

  • securityThe k8s.io/kubernetes module, updated to v1.34.2

    The k8s.io/kubernetes module is updated to v1.34.2 as a security-related dependency update.

  • securityThe helm dependency, updated to 3.19.4

    The helm dependency is updated to 3.19.4 due to a CVE.

  • breakinggRPC service config DNS TXT lookups, disabled by default

    gRPC service config DNS TXT lookups are disabled by default.

  • breakingThe appset resource status count, defaulted to 5000

    The default appset resource status count is changed to 5000.

Check if affected (2)

  • breakingThe --client flag in the Helm version command, removed

    Applies if you use --client.

    The --client flag is removed from the Helm version command.

  • breakingThe cluster-version annotation format, renamed

    Applies if you use Application Sets with Cluster Generators and configure argocd.argoproj.io/auto-label-cluster-info.

    Application Sets using Cluster Generators and argocd.argoproj.io/auto-label-cluster-info on cluster secrets must use argocd.argoproj.io/kubernetes-version instead. The Kubernetes version format changes from Major.Minor to vMajor.Minor.Patch.

Source
Argov3.3.9CI/CD & App DeliveryApr 30, 2026

v3.3.9 is a maintenance release with a disclosed security fix and a go version update to resolve CVEs. It also includes bug fixes in the release.

Action needed (2)

  • securitycriticalGHSA-3v3m-wc6v-x4x3 security fix

    This release fixes the vulnerability identified by GHSA-3v3m-wc6v-x4x3.

  • securityThe go version update for CVE resolution

    The go version is bumped to resolve CVEs in v3.3.9.

Source
Argov3.2.11CI/CD & App DeliveryApr 30, 2026

Version v3.2.11 includes a disclosed security fix and additional correctness and dependency updates. The security fix is the release change that concerns users evaluating whether to upgrade.

Action needed (1)

  • securitycriticalSecurity fix for GHSA-3v3m-wc6v-x4x3

    Version v3.2.11 contains a security fix for the vulnerability identified by GHSA-3v3m-wc6v-x4x3.

Source
Argov3.2.8CI/CD & App DeliveryMar 26, 2026

This maintenance release includes a security mitigation for CVE-2026-33186 in grpc-go. It also contains ordinary fixes to application behavior and the user interface.

Action needed (1)

  • securitycriticalgrpc-go CVE-2026-33186 mitigation

    A mitigation for CVE-2026-33186 in grpc-go ships in the release-3.2 line.

Source
Argov3.1.13CI/CD & App DeliveryMar 25, 2026

Argo CD v3.1.13 focuses on release artifact provenance and maintenance, with a security mitigation, a UI correction, and a dependency update. Container images are signed, and qualifying container images and CLI binaries receive SLSA Level 3 provenance.

Action needed (1)

  • securitycriticalgrpc-go CVE-2026-33186 mitigation

    The release includes a mitigation for CVE-2026-33186 in grpc-go for release-3.1.

Source
Argov3.3.2CI/CD & App DeliveryFeb 22, 2026

This release fixes the client-side apply migration issue reported in versions 3.3.0 and 3.3.1. No security advisories are disclosed.

Action needed (1)

  • breakingClient-side apply migration failure

    The failed to perform client-side apply migration issue present in versions 3.3.0 and 3.3.1 is fixed in this release.

Source
Argov3.3.0CI/CD & App DeliveryFeb 2, 2026

Argo v3.3.0 is a substantial feature and maintenance release with changes across synchronization, health, hydration, diff and apply behavior, the UI, and resource operations. It also updates core dependencies and removes an app controller flag.

Action needed (3)

  • securityThe k8s.io/kubernetes module, updated to v1.34.2

    The k8s.io/kubernetes module is updated to v1.34.2 in Argo v3.3.0.

  • securityHelm 3.19.4

    Helm is updated to 3.19.4 in Argo v3.3.0.

  • securityRedis, updated to the latest stable release

    Redis is updated to the latest stable release in Argo v3.3.0.

Check if affected (1)

  • breakingThe --self-heal-backoff-cooldown-seconds flag, removed

    Applies if your app controller configuration uses --self-heal-backoff-cooldown-seconds.

    The app controller no longer includes the unnecessary --self-heal-backoff-cooldown-seconds flag.

Source
Browse by month