RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: KubeVelaClear ×
KubeVelav1.11.0CI/CD & App DeliveryJul 20, 2026

A release with operator-facing authorization and credential-handling fixes, alongside new Helm, CUE, and workflow capabilities. It also adds validation improvements and dependency updates.

Check if affected (3)

  • securityExplicit authorization for vela-system definitions

    Applies if you use vela-system definitions.

    Namespace administrators cannot access vela-system definitions without explicit permissions.

  • securityCredential redaction for Terraform module remote URLs

    Applies if you configure Terraform module remote URLs.

    Credentials embedded in Terraform module remote URLs are no longer logged or persisted.

  • breakingUndeclared parameter validation in application definitions

    Applies if you use application definitions.

    Application definitions now validate undeclared parameters.

Source
KubeVelav1.10.9CI/CD & App DeliveryJun 30, 2026

A maintenance release with a security fix for unbounded reads in the Terraform remote configuration loader and a correctness fix for CUE imports in status details. It also adds repository ownership metadata.

Check if affected (1)

  • securityUnbounded read prevention in the Terraform remote configuration loader

    Applies if you use the Terraform remote configuration loader.

    The Terraform remote configuration loader now prevents unbounded reads. This fix addresses GHSA-fmgp-q6jx-gg3x.

Source
KubeVelav1.9.14CI/CD & App DeliveryJun 30, 2026

This release includes a security correction for an unbounded-read denial-of-service condition in the Terraform remote configuration loader. The fix is backported to release-1.9 and concerns deployments that use this loader.

Check if affected (1)

  • securityTerraform remote configuration loader DoS fix (GHSA-fmgp-q6jx-gg3x)

    Applies if you use the Terraform remote configuration loader.

    The release-1.9 backport prevents unbounded reads with a shallow-depth-1 clone, a 2-minute fetch timeout, 64 MiB and file-count caps, regular-file and in-cache-path validation, symlink rejection, cache invalidation when the URL changes, and cleanup after rejected reads. The fix ships in v1.9.14.

Source
Browse by month