RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Sep 2026Clear ×
containerdapi/v1.12.0Kubernetes CoreTodaySep 16, 2026

A feature and maintenance release adds runtime and API capabilities while updating dependencies. It also deprecates two interfaces, with no disclosed security changes.

Plan ahead (2)

  • deprecatedcontainerd.io/runtime-allow-mounts shim annotation deprecation

  • deprecatedTask API address and version fields in runc options

Source
Backstagev1.55.0CI/CD & App DeliveryYesterdaySep 15, 2026

A broad feature and maintenance release adds scaffolder recovery and credential controls, TechDocs, notification and streaming capabilities, and Kubernetes and authentication improvements. It also includes dependency and tooling security updates, a security fix, and compatibility changes that affect users of the listed resolvers, catalog integrations, MCP configuration, and task recovery.

Action needed (6)

  • securityModule Federation dependency updates for security

    This release updates the Module Federation dependencies to versions that avoid known security vulnerabilities.

  • securityYarn tooling dependency updates for security

    This release updates the Yarn tooling dependencies to versions that avoid known security vulnerabilities.

  • securityModule Federation security dependency update

    This release updates the Module Federation dependencies to versions that avoid known security vulnerabilities.

  • securityOpenAPI generator tooling security update

    This release updates the OpenAPI generator tooling to avoid known security vulnerabilities.

  • securityOpenAPI generator tooling security update

    This release updates the OpenAPI generator tooling to avoid known security vulnerabilities.

  • breakingLocale-insensitive Unicode casing

    String handling now uses locale-insensitive Unicode casing for consistent results across environments.

Check if affected (6)

  • securityKubernetes catalog cluster locator URL validation

    Applies if you use the catalog cluster locator.

  • securityPull request workspace handling security fix

    Applies if you use pull request workspace handling.

  • breakingGitHub user ID catalog lookup matching

    Applies if you use GitHub user ID catalog lookups.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedGitHub username sign-in resolver deprecation

    Applies if you use the GitHub username sign-in resolver.

Source
wasmCloudv2.9.0Orchestration & ManagementSep 8, 2026

A feature release that adds plugin, runtime, concurrency, and observability capabilities. It also corrects runtime defects and enforces guest-memory limits.

Action needed (1)

  • breakingThe max-guest-memory limit is enforced

    This release enforces the max-guest-memory limit.

Plan ahead (1)

  • deprecatedThe deprecated --enable-meters flag alias

Source
metal3-iov0.14.0Provisioning & RuntimeSep 8, 2026

A feature-rich release with breaking changes, new controllers, and expanded provisioning capabilities. It also includes correctness fixes and broad dependency updates.

Action needed (1)

  • breakingThe separate TryInit call, removed

    Provisioner no longer makes a separate TryInit call in this release.

Plan ahead (1)

  • deprecatedThe BMH Taints field, deprecated

Source
Vitessv23.0.6Storage & DataSep 3, 2026

A maintenance release with correctness fixes and dependency updates. The /debug/vrlog removal and newly enforced safety limits affect operators using those paths.

Action needed (2)

  • breakingRecursion-depth limit on the streaming recursive CTE path

    A recursion-depth limit is enforced on the streaming recursive CTE path.

  • breakingStored-procedure safety checks on the streaming CALL path

    Stored-procedure safety checks are enforced on the streaming CALL path.

Check if affected (1)

  • breakingThe /debug/vrlog endpoint, removed

    Applies if you use /debug/vrlog.

Plan ahead (1)

  • deprecatedThe --vreplication-enable-http-log flag, deprecatedremoval planned in v26

    Applies if you configure --vreplication-enable-http-log.

Source
OpenTelemetryv0.160.0ObservabilitySep 2, 2026

A maintenance and API-evolution release with client configuration deprecations, a higher Go toolchain requirement, performance improvements, and a breaking resource-creation API signature change. The release also includes compatibility, error-handling, platform support, and component behavior updates.

Check if affected (3)

  • breakingDeprecated fields with keepalive section

    Applicability is not stated in the release notes.

  • breakingGo 1.25.0 support removal

    Applies if you depend on go.

  • breakingtelemetry.Factory.CreateResource and telemetry.CreateResourceFunc return signature

    Applies if you use telemetry.Factory.CreateResource or telemetry.CreateResourceFunc.

Plan ahead (1)

  • deprecatedClient configuration fields deprecated in favor of keepalive

    Applies if you configure any of idle_conn_timeout, max_idle_conns, max_idle_conns_per_host, disable_keep_alives, idle_timeout, or keep_alives_enabled.

Source
Kubescapev4.0.13SecuritySep 2, 2026

A broad feature release expands scanning, policy, reporting, remediation, notifications, telemetry, integrations, and output capabilities. It also includes security hardening and stricter scan constraints, alongside many correctness and runtime fixes.

Action needed (2)

  • securityGo dependency security vulnerabilities

    Dependabot fixes security vulnerabilities in Go dependencies shipped with the release.

  • securitygosec SAST findings

    The release remediates gosec SAST findings in the Go codebase.

Check if affected (10)

  • securityGrafeas filtering through resourceURL

    Applies if you run imagescan.

  • breakingClient-supplied account and accessKey in scan requests

    Applies if you use scan requests.

  • breakingHard validation for --include-controls

    Applies if you configure --include-controls.

  • + 7 more on the release page

Plan ahead (1)

  • deprecatedThe --fail-threshold flag, hidden and deprecated

    Applies if you configure --fail-threshold.

Source
Browse by month