RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jun 2026Clear ×Project: VitessClear ×
Vitessv24.0.2Storage & DataJun 24, 2026

A bug-fix release with two security fixes, along with routine correctness fixes and Go toolchain dependency updates. The security changes affect users of the static grpc auth plugin or twopcz handler; the release also updates Go to go1.26.3 and go1.26.4.

Check if affected (2)

  • securityConstant-time password comparison in the static grpc auth plugin

    Applies if you use the static grpc auth plugin.

    The static grpc auth plugin now uses a constant-time password comparison. This security fix ships in release-24.0.

  • securityEscaping of reflected form values in the twopcz handler

    Applies if you use the twopcz handler.

    The twopcz handler now escapes reflected form values. This security fix ships in release-24.0.

Source
Browse by month