RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Rookv1.20.6Storage & DataAug 20, 2026

A maintenance release with a Ceph security advisory, a disabled Rook manager module, and clearer CephX fallback errors. Users of Ceph are advised to upgrade, while CephX key fallback failures now report the actual error.

Check if affected (2)

  • securityCeph CVE-2025–30156 upgrade advisory

    Applies if you depend on Ceph.

  • breakingThe rook mgr module, disabled

    Applies if you enable the rook mgr module.

Source
Rookv1.19.10Storage & DataAug 20, 2026

A maintenance release with a security-driven Ceph upgrade recommendation and a disabled Rook manager module. It also adds or changes CephCluster and CephX error-reporting behavior.

Action needed (1)

  • breakingThe Rook manager module, disabled

    The Rook manager module is disabled in this release.

Check if affected (1)

  • securityCeph upgrade recommendation for CVE-2025-30156

    Applies if you use Ceph.

Source
Rookv1.20.5Storage & DataAug 19, 2026

A security-focused release with an advisory requiring Rook and Ceph upgrades. It also adds support for the new cephx key type, changes external version validation to ignore Ceph commit IDs, and fixes monitor registration in the v1 failover path.

Check if affected (1)

  • securityCeph CVE-2025–30156 advisory

    Applies if you use Ceph.

Source
Vitessv24.0.2Storage & DataJun 24, 2026

A bug-fix release with two security fixes, along with routine correctness fixes and Go toolchain dependency updates. The security changes affect users of the static grpc auth plugin or twopcz handler; the release also updates Go to go1.26.3 and go1.26.4.

Check if affected (2)

  • securityConstant-time password comparison in the static grpc auth plugin

    Applies if you use the static grpc auth plugin.

  • securityEscaping of reflected form values in the twopcz handler

    Applies if you use the twopcz handler.

Source
Vitessv24.0.0Storage & DataApr 30, 2026

A broad feature and maintenance release adds routing, streaming, tracing, backup and restore, observability, and tablet-management capabilities alongside correctness, performance, and dependency updates. Operators should review changed defaults, backup behavior, removed endpoints and metrics, deprecated features, and security fixes affecting external decompression.

Action needed (3)

  • securityClear-text logging of sensitive information

    The release addresses a code scanning alert about clear-text logging of sensitive information.

  • securityDirectory traversal protection in GetBackups

    The file backup storage GetBackups RPC no longer permits directory traversal paths.

  • breakingStricter VTGate SELECT list validation

    VTGate rejects an unqualified * after a comma in a SELECT list.

Check if affected (12)

  • securityOpt-in compressor commands from MANIFEST

    Applicability is not stated in the release notes.

  • securityExternal decompressor commands from backup MANIFEST

    Applies if you use backup storage.

  • securityBackup MANIFEST path traversal protection

    Applies if backupengine runs.

  • + 9 more on the release page

Plan ahead (4)

  • deprecatedThe glog deprecationremoval planned in v25

    Applies if you use glog.

  • deprecatedThe OpenTracing backend deprecationsremoval planned in v25

    Applies if you use opentracing-jaeger or opentracing-datadog.

  • deprecatedVTOrc Snapshot Topology deprecationremoval planned in v25

    Applies if you configure --snapshot-topology-interval.

  • + 1 more on the release page
Source
Vitessv22.0.4Storage & DataFeb 27, 2026

A maintenance release with security fixes in backup restore behavior, along with routine bug fixes, a Go toolchain dependency update, and a performance improvement. The backup changes affect manifest-based external decompression and protection against path traversal during restores.

Check if affected (2)

  • securitycriticalBackup restore path traversal protection

    Applies if you use backup storage.

  • securityhighManifest-based external decompression default, changed

    Applies if you use an external decompressor command and do not pass --external-decompressor-use-manifest.

Source
Vitessv23.0.3Storage & DataFeb 27, 2026

A security-focused maintenance release with changes to backup and restore behavior, bug fixes, and additional hardening. Backup MANIFEST handling now requires explicit opt-in for compressor commands, and restore blocks path traversal through MANIFEST files.

Check if affected (2)

  • securityLoading compressor commands from MANIFEST, opt-in

    Applies if you use --external-decompressor-use-manifest.

  • securityPath traversal through backup MANIFEST on restore blocked

    Applies if backupengine runs.

Source
Longhornv1.10.2Storage & DataJan 28, 2026

A maintenance release includes a hotfixed operator image, a security-relevant DNS query correction, and fixes across volume, replica, CSI, and management paths. It also adds namespace inheritance for longhorn-share-manager in FastFailover mode.

Check if affected (2)

  • securityThe instance-manager DNS query behavior

    Applies if you do not use a hard or solid state disk.

  • breakingThe backing-image-manager:v1.10.2 image, replaced with backing-image-manager:v1.10.2-hotfix-1

    Applies if you use backing-image-manager:v1.10.2.

Source
Dragonflyv2.4.1Storage & DataJan 23, 2026

A maintenance release that removes deprecated preheat API endpoints and fixes unauthenticated access to the Dragonfly manager job API. Both changes affect users of the corresponding APIs.

Check if affected (2)

  • securityDragonfly manager job API unauthenticated access fix

    Applies if you use Dragonfly manager job API.

  • breakingDeprecated preheat API endpoints removed

    Applies if you use deprecated preheat API endpoints.

Source
Browse by month