RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Prometheusv3.14.0ObservabilityAug 18, 2026

A maintenance release with an API deprecation, operator-visible removals and default changes, new capabilities, performance improvements, and correctness fixes across discovery, PromQL, TSDB, and other components. No security advisories or explicitly described security vulnerabilities are included.

Action needed (1)

  • breakingDefault support for PromQL duration expressions

    Duration expressions are enabled by default in PromQL. The promql-duration-expr feature flag is now a no-op.

Check if affected (1)

  • breakingThe __meta_hetzner_datacenter label, removed

    Applies if you use hcloud targets.

Plan ahead (1)

  • deprecatedThe stats query parameter, deprecated for other valuesremoval date not announced

    Applies if you set stats to a value other than true or all.

Source
OpenTelemetryv0.159.0ObservabilityAug 17, 2026

A release that adds exporter queue batching controls, changes exporter and scraper metric behavior, and updates public API field shapes. Schema-based configuration migrations are also included, with no security advisories or security fixes disclosed.

Check if affected (2)

  • breakingThe confighttp.ServerConfig field shape in Config

    Applies if you use extension/zpages.

  • breakingThe configauth.Config field shape in AuthConfig

    Applies if you use configauth.Config.

Source
OpenTelemetryv0.158.0ObservabilityAug 4, 2026

OpenTelemetry v0.158.0 adds a replacement processor and configuration-schema capabilities, along with changes to component maturity and several defect corrections. It also removes the pkg/xconfmap validation API in favor of symbols in confmap.

Check if affected (1)

  • breakingThe pkg/xconfmap validation symbols, renamed

    Applies if you use pkg/xconfmap's Validator or Validate symbols.

Source
OpenTelemetryv0.157.0ObservabilityJul 21, 2026

This release adds configuration and feature-gate capabilities, corrects defects, changes histogram bucket values, and introduces the configstorage module. It also removes or deprecates API symbols, with no security issues or advisories identified.

Check if affected (1)

  • breakingThe BalancerName function, removed

    Applies if you use BalancerName.

Plan ahead (1)

  • deprecatedThe WithForceUnmarshaler option, deprecated

    Applies if you use WithForceUnmarshaler.

Source
OpenCostv1.121.0ObservabilityJul 20, 2026

This release combines new cost data and collection capabilities with operational updates. Endpoint access defaults change, and the release includes corrections across pricing, pagination, request handling, providers, and serialization.

Check if affected (1)

  • breakingEndpoint defaults, deactivated without an admin token

    Applies if you use endpoints without setting an admin token.

Source
Jaegerv2.20.0ObservabilityJul 20, 2026

A release with backend compatibility removals, forced migrations, new configuration and CLI capabilities, and correctness fixes across storage, extensions, and related components. It does not disclose security advisories or security-specific flaws.

Action needed (1)

  • breakingTemplate creation through esclient

    Template creation moves to esclient, and legacy mapping rendering is retired.

Check if affected (3)

  • breakingSupport for elasticsearch v6, removed

    Applies if you use elasticsearch v6.

  • breakingThe jaegermcp extension, merged into jaegerquery

    Applies if you use the jaegermcp extension.

  • breakingExpired stable feature gates, removed

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedThe legacy flag, deprecated

    Applies if you use legacy flag.

Source
Thanosv0.42.0ObservabilityJul 8, 2026

A release with security corrections, breaking configuration removals, and an output-field rename that may require operator or log-collector changes. It also adds TLS and cache configuration, query and tracing changes, and defect fixes across several Thanos components.

Action needed (1)

  • securitycriticalthanos-community/grpc-go fork update for CVE-2026-33186

    The thanos-community/grpc-go fork is bumped to fix CVE-2026-33186, an authorization bypass via malformed :path headers.

Check if affected (4)

  • securityReceive tenant ID validation

    Applies if you run Receive.

  • breakingQuery-Frontend time_taken field renamed to time_taken_ms

    Applies if you run Query-Frontend.

  • breaking--shipper.ignore-unequal-block-size flag removed

    Applies if you configure --shipper.ignore-unequal-block-size.

  • + 1 more on the release page
Source
Prometheusv3.13.0ObservabilityJul 1, 2026

A long-term support release with security-related dependency updates, PromQL changes, new APIs and configuration controls, and bug fixes. It also replaces a shipped license artifact and includes performance improvements.

Action needed (2)

  • securitycriticalThe sanitize-html dependency update

    The UI updates sanitize-html to address a cross-site scripting vulnerability, identified as CVE-2026-44990.

  • breakingThe third-party license artifact

    Third-party npm dependency licenses are embedded in the Prometheus binary and served at /assets/third-party-licenses.txt. This replaces the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images.

Check if affected (2)

  • securitymediumRedirect credential forwarding

    Applies if you use scraping, remote read/write, alerting, or service discovery.

  • breakingPromQL duration-expression function names

    Applies if you enable experimental-duration-expr and use min() and max().

Source
Fluentdv1.19.3ObservabilityJun 25, 2026

A maintenance release with bug fixes, behavior changes, and two operator-visible default changes. It also updates a runtime dependency and tightens validation and payload handling; no security vulnerability or advisory is explicitly identified.

Check if affected (2)

  • breakingThe in_monitor_agent visibility default

    Applies if in_monitor_agent runs.

  • breakingThe in_debug_agent local-machine default

    Applies if in_debug_agent runs.

Source
OpenTelemetryv0.155.0ObservabilityJun 23, 2026

A release that removes stabilized feature gates, updates processor metric names, and changes service configuration APIs. It also adds schema and metadata tooling capabilities and fixes generator defects.

Check if affected (9)

  • breakingThe confightp.framedSnappy feature gate, removed

    Applies if you use confightp.framedSnappy.

  • breakingThe configoptional.AddEnabledField feature gate, removed

    Applies if you use configoptional.AddEnabledField.

  • breakingThe confmap.newExpandedValueSanitizer feature gate, removed

    Applies if you use confmap.newExpandedValueSanitizer.

  • + 6 more on the release page

Plan ahead (1)

  • deprecatedService configuration API deprecations

    Applies if you use service.Settings.CollectorConf or extensioncapabilities.ConfigWatcher.

Source
Cortexv1.21.1ObservabilityJun 5, 2026

A maintenance release with operator-facing security fixes and configuration changes across ingestion, distribution, and status pages. It also includes fixes for request handling, authentication, configuration exposure, gossip limits, and client and runtime panics.

Check if affected (3)

  • securityStored XSS protection in Alertmanager and Store Gateway status pages

    Applies if you run Alertmanager or Store Gateway.

  • securityWrappedHistogram native histogram size limit

    Applies if you use native histograms.

  • breakingDecompressed gzip output limit for ParseProtoReader and OTLP ingestion

    Applies if you use the OTLP ingestion path.

Source
OpenCostv1.120.3ObservabilityMay 29, 2026

A maintenance release with dependency updates, correctness fixes, and new cloud and query capabilities. Configuration and output behavior also change, along with a Go dependency upgrade for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.

Action needed (1)

  • securityhighGo dependency upgrades for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986

    Go dependencies are upgraded for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.

Check if affected (1)

  • breakingThe MCP_SERVER_ENABLED default is false

    Applies if you do not configure MCP_SERVER_ENABLED.

Source
Prometheusv3.12.0ObservabilityMay 28, 2026

A feature and maintenance release with new operator-facing APIs, discovery integrations, feature flags, configuration options, and UI capabilities. It also addresses disclosed security issues, correctness and performance problems, and validation or constraint behavior.

Action needed (1)

  • breakingConcurrent fgprof profile rejection

    The API rejects concurrent fgprof profiles.

Check if affected (3)

  • securityRemote Write decoded-length constraint

    Applies if you use Remote Write.

  • securityPlaintext secret exposure in STACKIT SD

    Applies if you use STACKIT SD.

  • breakingDecompressed body-size limit for OTLP write requests

    Applies if you use OTLP.

Source
OpenTelemetryv0.153.0ObservabilityMay 25, 2026

This release updates configuration and metadata handling, with new schema and configuration capabilities and several API and feature-gate maturity changes. It also fixes Snappy memory corruption and fatal errors.

Check if affected (3)

  • breakingThe pdata.useCustomProtoEncoding feature gate, removed

    Applies if you use pdata.useCustomProtoEncoding.

  • breakingDefault reaggregation_enabled behavior

    Applies if you run cmd/mdatagen.

  • breakingStricter feature_gates validation

    Applies if you configure feature_gates in metadata.yaml.

Source
OpenTelemetryv0.152.1ObservabilityMay 19, 2026

A maintenance release that adds exporter in-flight request monitoring and configuration-validation APIs while correcting runtime and configuration behavior. It also changes Prometheus telemetry defaults for explicitly configured metrics and deprecates older validation APIs.

Check if affected (2)

  • breakingThe max_request_body_size limit for snappy requests

    Applies if you configure max_request_body_size.

  • breakingPrometheus exporter defaults for explicitly configured telemetry

    Applies if you configure the telemetry metrics section.

Plan ahead (1)

  • deprecatedThe xconfmap.Validator and confmap.Validate APIs

    Applies if you use xconfmap.Validator or confmap.Validate.

Source
OpenCostv1.120.2ObservabilityMay 18, 2026

A maintenance release with dependency updates, operator-visible configuration and behavior changes, new integrations and capabilities, and correctness fixes. It also includes an explicitly disclosed security-related Go dependency upgrade.

Action needed (1)

Check if affected (2)

  • breakingThe provider config source, changed

    Applies if you configure provider config.

  • breakingThe MCP_SERVER_ENABLED default, changed to false

    Applies if you use the MCP server.

Source
OpenTelemetryv0.151.0ObservabilityApr 28, 2026

A release with API and configuration contract changes, new capabilities, deprecations, and bug fixes. It includes transport, telemetry, generated configuration, and data-handling updates, with no disclosed security advisories or security-specific fixes.

Check if affected (2)

  • breakingRelative replace paths in generated Collector source

    Applies if you use the generated Collector source.

  • breakingNamed Config.Protocols field

    Applies if you use Config.Protocols.

Plan ahead (1)

  • deprecatedDefaultMetricsBuilderConfig deprecation

    Applies if you use DefaultMetricsBuilderConfig.

Source
OpenCostv1.120.1ObservabilityApr 28, 2026

A maintenance release with a dependency update, correctness fixes, and new operator-facing capabilities. The MCP server now requires explicit opt-in when MCP_SERVER_ENABLED is not configured.

Check if affected (1)

  • breakingThe MCP_SERVER_ENABLED default, changed to false

    Applies if MCP_SERVER_ENABLED is not configured.

Source
Cortexv1.21.0ObservabilityApr 27, 2026

A feature and maintenance release that adds Store Gateway, federation, overrides, caching, metric, and query capabilities while graduating several experimental features. It also changes defaults and configuration names, updates dependencies, and fixes correctness, memory, panic, and data-corruption defects.

Action needed (1)

  • breakingThe blocks storage bucket index default

    Blocks storage now enables the bucket index by default through -blocks-storage.bucket-store.bucket-index.enabled. Disabling it with -blocks-storage.bucket-store.bucket-index.enabled=false is not recommended for production.

Check if affected (1)

  • breakingThe Distributor type and unit label flag

    Applies if you configure either -distributor.enable-type-and-unit-labels or -distributor.otlp.enable-type-and-unit-labels for remote write v2 and OTLP requests.

Plan ahead (3)

  • breakingThe Ruler API flag rename

    Applies if you configure -experimental.ruler.enable-api.

  • breakingThe Alertmanager API flag rename

    Applies if you configure -experimental.alertmanager.enable-api.

  • breakingThe Users Scanner user index update configuration

    Applies if you configure either -*.users-scanner.user-index.cleanup-interval or clean_up_interval.

Source
Prometheusv3.11.0ObservabilityApr 2, 2026

A broad release with new service discovery, PromQL, TSDB, and UI capabilities, alongside performance, dependency, output, and correctness changes. It also deprecates legacy Hetzner discovery labels and corrects TSDB retention-time handling.

Check if affected (1)

  • breakingThe storage.tsdb.retention.time unit handling

    Applies if you configure storage.tsdb.retention.time.

Plan ahead (2)

  • deprecatedThe __meta_hetzner_datacenter label, deprecatedremoval date not announced

    Applies if you use __meta_hetzner_datacenter.

  • deprecatedThe Hetzner Cloud datacenter location labels, deprecated

    Applies if you use __meta_hetzner_hcloud_datacenter_location or __meta_hetzner_hcloud_datacenter_location_network_zone.

Source
Chaos Meshv2.8.2ObservabilityMar 25, 2026

A maintenance release deprecates and removes install.sh, updates the Go toolchain and JSON-RPC dependency, and corrects dashboard and webhook issues. It also includes vulnerability fixes in Go and UI packages.

Action needed (2)

  • securityGo package updates for vulnerability fixes

    Go packages are upgraded to fix vulnerabilities.

  • securityUI package updates for vulnerability fixes

    UI packages are upgraded to fix vulnerabilities.

Check if affected (1)

  • breakingThe install.sh installer, removed

    Applies if you use install.sh.

Plan ahead (1)

  • deprecatedThe install.sh installer, deprecated

    Applies if you use install.sh.

Source
Jaegerv2.16.0ObservabilityMar 7, 2026

A release with breaking configuration and API changes, a Go 1.25.7 requirement, new capabilities, and bug and performance fixes. No security advisories or security-specific fixes are identified.

Action needed (1)

  • breakingGo 1.25.7 requirement

    The codebase now requires Go 1.25.7, with Go version consistency enforced across the codebase.

Check if affected (2)

  • breakingLegacy response format of the remote sampling endpoint, removed

    Applies if you use the remote sampling endpoint.

  • breakingtraces.topic renamed to traces.topics

    Applies if you configure traces.topic.

Source
Prometheusv3.10.0ObservabilityFeb 26, 2026

This release adds Prometheus capabilities and image/build options, changes defaults and outputs, improves performance, and fixes correctness defects. No security advisories or explicitly described vulnerabilities are present.

Check if affected (1)

  • breakingExpanded alert annotations hidden by default

    Applies if you use the UI on the /alerts page.

Source
Thanosv0.41.0ObservabilityFeb 12, 2026

This release combines performance improvements, bug fixes, and new configuration capabilities with a shuffle-sharding behavior change in Receive. It also upgrades Prometheus, deprecates a flag, and makes native histogram ingestion always enabled.

Check if affected (1)

  • breakingReceive shuffle sharding now uses consistent hashing

    Applies if you use Receive.

Source
Jaegerv2.15.0ObservabilityFeb 6, 2026

Jaeger v2.15.0 introduces a breaking constraint for trace and metric storage configuration. It also adds experimental MCP and ClickHouse capabilities, corrects API behavior, and includes an internal implementation change without direct operator impact.

Check if affected (1)

  • breakingTrace and metric storage configuration backend constraint

    Applies if you configure trace or metric storage with more than one backend type.

Source
Prometheusv3.9.0ObservabilityJan 7, 2026

This release updates histogram collection and TSDB behavior while adding capabilities across the API, PromQL, storage, and UI. It also includes fixes for query handling, storage validation, receivers, and interface behavior.

Action needed (1)

  • breakingA 10,000-set limit for the TSDB status endpoint

    The TSDB status endpoint now limits responses to a maximum of 10,000 sets of statistics.

Check if affected (1)

  • breakingThe native-histogram feature flag has no effect

    Applies if you set scrape_native_histograms to collect Native Histogram samples from exporters.

Source
Jaegerv2.14.0ObservabilityJan 2, 2026

A release focused on removing legacy v1 components and storage interfaces, while changing configuration and UI defaults. It also adds or expands experimental storage capabilities and includes fixes for storage behavior and dependency API changes.

Check if affected (9)

  • breakingRemaining v1 utilities published as v2.x.x versions

    Applies if you use v1 utilities.

  • breakingThe UI theme selector, enabled by default

    Applies if you use the UI.

  • breakingThe storage/v1/grpc interface, removed

    Applies if you use storage/v1/grpc.

  • + 6 more on the release page
Source
Browse by month