RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

hamiv2.10.0AI & MLYesterdayAug 21, 2026

A substantial operator-focused maintenance release with broad bug and behavior fixes, alongside new scheduling, device, configuration, and observability capabilities. It also updates security-relevant dependencies and the runtime/toolchain while removing obsolete functionality that may affect compatibility and configuration.

Action needed (3)

  • securitytensorflow/tensorflow upgraded to 2.21.0rc0-gpu

    The tensorflow/tensorflow dependency is upgraded from 2.20.0rc0-gpu to 2.21.0rc0-gpu.

  • securitytensorflow/tensorflow upgraded to 2.21.0rc1-gpu

    The tensorflow/tensorflow dependency is upgraded from 2.21.0rc0-gpu to 2.21.0rc1-gpu.

  • securitygolang security upgrade

    The golang runtime is upgraded to address a security issue.

Check if affected (7)

  • breakingDRA components removed from the HAMi main chart

    Applies if you use DRA components in the HAMi main chart.

  • breakingWebhook denial of privileged containers

    Applies if you use the webhook.

  • breakingDeprecated scheduler policy configmap removed

    Applies if you configure the deprecated scheduler policy configmap.

  • + 4 more on the release page
Source
KServev0.20.0AI & MLAug 6, 2026

This release adds new inference-service, storage, runtime, routing, and deployment capabilities, alongside correctness fixes and dependency updates. Operators should review the Starlette security update, changed defaults, and narrower readiness behavior.

Action needed (2)

  • securitymediumstarlette dependency update for CVE-2026-48710

    The starlette dependency is bumped to >=1.0.1 for CVE-2026-48710.

  • breakingStandard default alignment with the llm-d optimized baseline

    The standard default is aligned with the llm-d optimized baseline.

Check if affected (7)

  • breakinglora-affinity-scorer default for LoRA adapters

    Applies if you use LoRA adapters.

  • breakingLLMInferenceServiceConfig deletion-prevention finalizer

    Applies if you use LLMInferenceServiceConfig.

  • breakingendpointPickerRef default EPP port

    Applies if you configure endpointPickerRef and do not configure port.

  • + 4 more on the release page
Source
KServev0.19.0AI & MLJun 14, 2026

A release with operator-facing additions and fixes, including new LLMInferenceService capabilities and status observability. It also updates dependencies and images and includes security-related fixes.

Action needed (1)

  • securityhighazure-core pinned for CVE-2026-21226

    The azure-core dependency is pinned to >=1.38.0 to address CVE-2026-21226.

Check if affected (3)

  • securityvllm setup and pillow dependency fixes

    Applies if you depend on vllm or pillow.

  • breakingIncorrect CRDs removed from llmisvc-crd

    Applies if you use llmisvc-crd.

  • breakingHelm imagePullPolicy defaults

    Applies if you use Helm.

Source
hamiv2.9.0AI & MLMay 19, 2026

A feature and maintenance release that adds HAMi-core, Ascend and vNPU virtualization, DRA, CDI, monitoring, metrics, deployment, and debugging capabilities. It also includes scheduling, allocation, device, chart, and compatibility fixes, security updates, dependency upgrades, and removal of a deprecated scheduler policy ConfigMap.

Action needed (3)

  • securityThe tensorflow/tensorflow dependency, upgraded

    The tensorflow/tensorflow dependency was upgraded from 2.20.0rc0-gpu to 2.21.0rc0-gpu in this release.

  • securityThe tensorflow/tensorflow dependency, upgraded again

    The tensorflow/tensorflow dependency was upgraded from 2.21.0rc0-gpu to 2.21.0rc1-gpu in this release.

  • securityThe golang dependency, upgraded

    The golang dependency was upgraded for a security issue in this release.

Check if affected (3)

  • breakingThe deprecated scheduler policy configmap, removed

    Applies if you configure scheduler policy configmap.

  • breakingThe Helm nvidia.overwriteEnv default

    Applies if you use Helm.

  • breakingHost networking for the device plugin, disabled

    Applies if the device plugin runs.

Source
KServev0.18.0AI & MLApr 29, 2026

A release with operator-facing fixes, new capabilities, API and configuration changes, and dependency updates. It also includes fixes for CVE-2026-32597 in PyJWT and CVE-2026-30922 in pyasn1.

Action needed (3)

  • securityhighCVE-2026-32597 PyJWT validation fix

    PyJWT crit header validation was fixed for CVE-2026-32597.

  • securityhighCVE-2026-30922 pyasn1 fix

    The pyasn1 dependency was updated to address CVE-2026-30922 and its denial-of-service vulnerability.

  • breakingRequired MaxReplicas field

    MaxReplicas is now required and must use the int32 type.

Check if affected (2)

  • breakingRemoval of the scheduler cert-hash restart annotation

    Applies if you configure cert-hash.

  • breakingPYTHONPATH blocked by ISVC and ServingRuntime webhooks

    Applies if you configure PYTHONPATH.

Source
KServev0.17.0AI & MLMar 13, 2026

An operator release with expanded configuration and LLMInferenceService capabilities, plus chart and dependency updates, behavior changes, removals, and defect corrections. It also includes security fixes for operators to review.

Action needed (13)

  • securitycriticalh11 malformed-body fix for CVE-2025-43859

    h11 malformed-body handling associated with CVE-2025-43859 is addressed in this release.

  • securityhighstarlette version 0.49.1

    starlette is pinned to version 0.49.1 to fix CVE-2025-62727 in this release.

  • securityhighlightgbm version 4.6.0

    lightgbm is updated to version 4.6.0 for CVE-2024-43598 in this release.

  • securityhighCVE-2025-66418 decompression-chain fix

    The unbounded number of links in the decompression chain associated with CVE-2025-66418 is addressed in this release.

  • securityhighexpr-lang/expr version v1.17.7

    expr-lang/expr is updated to v1.17.7 to fix CVE-2025-68156 in this release.

  • securityhighcryptography fix for CVE-2026-26007

    The cryptography issue associated with CVE-2026-26007 is addressed in this release.

  • securityhighpython-multipart fix for CVE-2026-24486

    The arbitrary file write issue in python-multipart associated with CVE-2026-24486 is addressed in this release.

  • securitymediumFixes for CVE-2025-22872, CVE-2025-47914, and CVE-2025-58181

    This release addresses CVE-2025-22872, CVE-2025-47914, and CVE-2025-58181.

  • securityhttps.go path traversal prevention

    The path traversal issue in https.go is prevented in this release.

  • securitySeveral CVE fixes

    This release addresses several CVEs.

  • securityAIOHTTP HTTP Parser auto_decompress fix

    The AIOHTTP HTTP Parser auto_decompress feature issue involving zip bombs is addressed in this release.

  • securityextractTarFiles path traversal fix

    The path traversal vulnerability in extractTarFiles is addressed in this release.

  • breakingminio replacement with seaweedfs

    minio is replaced with seaweedfs in this release.

Check if affected (6)

  • breakinginferenceservice CRD cert-manager annotation removal

    Applies if you use the inferenceservice CRD.

  • breakingPython 3.9 support removal

    Applies if you run Python 3.9.

  • breakingDeprecated --disable-log-requests flag removal

    Applies if you configure --disable-log-requests.

  • + 3 more on the release page
Source
hamiv2.8.0AI & MLJan 20, 2026

Release v2.8.0 adds capabilities and metrics, corrects multiple defects, and updates dependencies. The nvidia-mig-parted upgrade addresses security issues.

Action needed (1)

  • securityThe nvidia-mig-parted dependency, upgraded to v0.12.2

    HAMi v2.8.0 upgrades the nvidia-mig-parted dependency to v0.12.2 to address security issues.

Source
Browse by month