RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Backstagev1.54.0CI/CD & App DeliveryAug 18, 2026

A broad release with dependency updates, breaking changes to commands, authentication patterns, and connection APIs, plus new AWS connection support and updates across the catalog, scaffolder, search, and UI. It also includes Kubernetes plugin security fixes and an undisclosed security announcement.

Action needed (2)

  • breakingStrict TypeScript configuration schema validation

    Package preparation now validates TypeScript configuration schemas strictly before publishing.

  • breakingPortable configuration schemas for root connection types

    Connection types now use portable configuration schemas as the source of root connection types.

Check if affected (16)

  • securityKubernetes plugin security fixes

    Applies if you use the Kubernetes plugin.

  • breakingBackend connection APIs, removed from package exports

    Applies if you use connectionsServiceRef, connectionsServiceFactory, DefaultConnectionsService, declareConnection, RootConnection, or AnyRootConnection.

  • breakingNode.js snapshots in generated backend Dockerfiles

    Applies if you configure generated backend Dockerfiles.

  • + 13 more on the release page

Plan ahead (3)

  • deprecatedThe plugin-web-library template, updated to toastApiRef

    Applies if you use the plugin-web-library template.

  • deprecatedZod v3 schemas, deprecated

    Applies if you depend on Zod v3 schemas.

  • deprecatedThe catalog.providers.backstageOpenapi.plugins option, deprecated

    Applies if you configure catalog.providers.backstageOpenapi.plugins.

Source
OpenFeatureflagd-proxy/v0.9.8CI/CD & App DeliveryAug 14, 2026

A maintenance release for flagd-proxy resolves open Dependabot security alerts. The sync server also receives a gRPC keepalive enforcement policy update.

Action needed (1)

  • securityOpen Dependabot security alerts resolved

    Open Dependabot security alerts are resolved in flagd-proxy v0.9.8.

Source
OpenFeatureflagd/v0.16.2CI/CD & App DeliveryAug 14, 2026

A maintenance release focused on bug fixes in eventing, eventstream connections, and evaluation metrics recording. The recorded fixes do not indicate any operator action beyond upgrading.

Source
Argov3.5.1CI/CD & App DeliveryAug 12, 2026

This release contains routine correctness fixes and a security fix in the server. The security change concerns users of the SSD CLI.

Action needed (1)

  • securitySSD CLI secret-mask spoofing prevention

    The server prevents secret-mask spoofing in the SSD CLI. This fix ships in Argo CD v3.5.1.

Source
Argov3.4.7CI/CD & App DeliveryAug 12, 2026

A maintenance release with correctness fixes, a server-side secret-mask spoofing fix, and a third-party dependency update. Ordinary fixes and the dependency update require no operator action, while upgrading addresses the security fix.

Action needed (1)

  • securitySSD CLI secret-mask spoofing prevention

    The server now prevents secret-mask spoofing in the SSD CLI. This fix ships in the 3.4 release line.

Source
Argov3.3.14CI/CD & App DeliveryAug 12, 2026

A maintenance release with fixes for secret masking and pprof endpoint configuration, alongside dependency updates for two listed CVEs. The secret-handling fixes and dependency updates are addressed by upgrading, while the remaining defect fixes require no operator action.

Action needed (2)

  • securityhighThe /ui brace-expansion dependency update for CVE-2026-69152

    The /ui dependency brace-expansion is updated to 2.1.4 and 1.1.18 for CVE-2026-69152.

  • securitymediumThe DOMPurify dependency update for CVE-2026-49978

    The DOMPurify dependency is updated to 3.4.7 for CVE-2026-49978.

Check if affected (2)

  • securitySSD CLI secret mask spoofing prevention

    Applies if you use SSD CLI.

  • securitySecret hiding in the last-applied-configuration annotation

    Applies if you configure last-applied-configuration.

Source
OpenKruisev1.8.5CI/CD & App DeliveryAug 10, 2026

OpenKruise v1.8.5 corrects nodeimage TTL cleanup so setting completionPolicy.ttlSecondsAfterFinished does not delete the job itself. It adds the default-ttlseconds-for-always-nodeimage flag for kruise-controller-manager to control nodeimage data TTL.

Source
Buildpacksv0.40.9CI/CD & App DeliveryAug 9, 2026

This release updates dependencies associated with published security advisories. Builders created with the pack CLI from this release contain lifecycle v0.21.0 by default.

Action needed (3)

  • securityhighThe github.com/go-git/go-git/v5 dependency update

    github.com/go-git/go-git/v5 updates from v5.19.1 to v5.19.2 in buildpacks v0.40.9. The release note cites GHSA-hc8v-wwc9-vgxm.

  • securitymediumThe go.opentelemetry.io/otel dependency update

    go.opentelemetry.io/otel updates from v1.43.0 to v1.44.0 in buildpacks v0.40.9. The release note cites GO-2026-5158 and CVE-2026-41178 for a baggage header that was not length-capped.

  • securityThe github.com/klauspost/compress dependency update

    github.com/klauspost/compress updates from v1.18.6 to v1.18.7 in buildpacks v0.40.9. The release note cites GO-2026-5841 and GHSA-259r-337f-4rfw for an out-of-bounds read in s2.

Source
Fluxv2.9.4CI/CD & App DeliveryAug 7, 2026

A maintenance release with correctness fixes that narrow some existing configuration constraints. It also adds CLI repository migration support and updates dependencies; no explicit security advisory or vulnerability is disclosed.

Check if affected (3)

  • breakingThe image-automation-controller refspec constraint

    Applies if you configure refspecs.

  • breakingGCS static authentication limited to service account keys

    Applies if you configure GCS static authentication.

  • breakingThe allow-webhooks network policy restriction

    Applies if you configure allow-webhooks.

Source
Microcks1.15.0CI/CD & App DeliveryAug 5, 2026

Version 1.15.0 adds authentication, TLS, GraphQL, configuration, and UI capabilities, alongside fixes for correctness defects. It also updates shipped container and frontend dependencies, with no disclosed security advisories or security-specific fixes.

Source
Argov3.5.0CI/CD & App DeliveryAug 4, 2026

A maintenance release focused on operator-facing bug fixes, with additional feature and configuration work. It also includes dependency updates, including a UI dependency update for CVE-2026-41240.

Action needed (3)

  • securitymediumThe redoc/dompurify dependency update for CVE-2026-41240

    The UI dependency redoc/dompurify is bumped to v3.4.0 to fix CVE-2026-41240.

  • securityThe formidable dependency update

    The formidable dependency is updated to v2.1.3.

  • breakingThe auto-sync toggle removal from the app top bar

    The auto-sync toggle is removed from the app top bar.

Check if affected (1)

  • breakingThe theme default changed to auto

    Applies if theme is not configured.

Source
Tektonv1.15.0CI/CD & App DeliveryJul 31, 2026

Tekton v1.15.0 adds configurable behavior, corrects defects across controllers and runtime components, and updates project dependencies. No security advisories or explicitly described vulnerabilities are present.

Source
Argov3.3.13CI/CD & App DeliveryJul 31, 2026

A maintenance release with bug fixes and dependency updates. The form-data update in /ui addresses CVE-2026-12143.

Action needed (1)

  • securityhighThe form-data dependency update for CVE-2026-12143

    The form-data dependency is updated to version 4.0.6 in /ui to address CVE-2026-12143.

Source
Argov3.4.6CI/CD & App DeliveryJul 31, 2026

This is a bug-fix release for Argo CD v3.4.6. The release notes mention corrections to application behavior and integrations, with no security advisories or explicit security vulnerabilities stated.

Source
Tektonv1.6.6CI/CD & App DeliveryJul 30, 2026

This release contains an operator-facing defect correction. The remaining release-note content consists of headings, installation guidance, or attestation instructions rather than additional software changes.

Source
Backstagev1.53.1CI/CD & App DeliveryJul 29, 2026

Backstage v1.53.1 contains no operator-facing change details in the available release note. The release note provides only the version heading, so there are no documented changes to assess.

Source
OpenFeaturecore/v0.16.1CI/CD & App DeliveryJul 27, 2026

This release combines ordinary bug fixes with security-related updates. It also improves blob/HTTP synchronization, with no announced operator-facing removals, deprecations, or default changes.

Action needed (2)

  • securityThe google.golang.org/grpc module update to v1.82.1

    The google.golang.org/grpc module is updated to v1.82.1 in core v0.16.1.

  • securityThe vulnerability-updates update

    vulnerability-updates is updated in core v0.16.1.

Source
OpenFeatureflagd-proxy/v0.9.7CI/CD & App DeliveryJul 27, 2026

A maintenance release with a bug-fix heading, a new server timeout setting, dependency updates, and security-related updates. The google.golang.org/grpc update requires upgrading.

Action needed (2)

  • securityThe google.golang.org/grpc module, updated to v1.82.1

    The google.golang.org/grpc module is updated to v1.82.1 as a security-related dependency change.

  • securityThe vulnerability-updates dependency update

    The release updates vulnerability-updates as a security-related dependency change.

Source
OpenFeatureflagd/v0.16.1CI/CD & App DeliveryJul 27, 2026

flagd/v0.16.1 combines bug fixes with security dependency updates and a configurable sync-server capability. The security notes do not include advisory identifiers or flaw details, while the sync-server changes include server timeouts and configurable gRPC keepalive enforcement.

Action needed (3)

  • securitySecurity dependency updates

    Security dependencies are updated in flagd/v0.16.1.

  • securityThe google.golang.org/grpc module update

    The google.golang.org/grpc module is updated to v1.82.1 in flagd/v0.16.1.

  • securityVulnerability updates

    Vulnerability updates are included in flagd/v0.16.1 as a security change.

Source
Fluxv2.9.3CI/CD & App DeliveryJul 23, 2026

Flux v2.9.3 is a maintenance release with correctness fixes, updated dependencies, and a newly included component in the OCI artifact. No security advisories are disclosed.

Source
Tektonv1.14.1CI/CD & App DeliveryJul 22, 2026

This release contains a pipeline validation defect correction. The recorded change allows result variable references in Pipeline task parameters, while no itemized release changes are provided here.

Source
KubeVelav1.11.0CI/CD & App DeliveryJul 20, 2026

A release with operator-facing authorization and credential-handling fixes, alongside new Helm, CUE, and workflow capabilities. It also adds validation improvements and dependency updates.

Check if affected (3)

  • securityExplicit authorization for vela-system definitions

    Applies if you use vela-system definitions.

  • securityCredential redaction for Terraform module remote URLs

    Applies if you configure Terraform module remote URLs.

  • breakingUndeclared parameter validation in application definitions

    Applies if you use application definitions.

Source
Backstagev1.53.0CI/CD & App DeliveryJul 14, 2026

A substantial mixed feature and maintenance release adds backend, frontend, catalog, authentication, webhook, and TechDocs capabilities alongside dependency updates and defect fixes. It also includes operator-visible changes to APIs, configuration validation, OpenAPI tooling, and MCP transport behavior; no security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingOpenAPI breaking change detection with oasdiff

    @useoptic/optic and @useoptic/openapi-utilities have been replaced with oasdiff for OpenAPI breaking change detection.

Check if affected (12)

  • breakingSchema loading rejects invalid imports

    Applicability is not stated in the release notes.

  • breakingThe package schema openapi init and repo schema openapi test commands, removed

    Applies if you use package schema openapi init or repo schema openapi test.

  • breakingMutually exclusive userGroupMember.path and user.filter configuration

    Applies if you configure both userGroupMember.path and user.filter.

  • + 9 more on the release page

Plan ahead (3)

  • deprecatedOpaque entity header extension point deprecation

    Applies if you use the opaque entity header extension point.

  • deprecatedDynamic Client Registration deprecation warning

    Applies if you enable Dynamic Client Registration.

  • deprecatedStable auth.clientIdMetadataDocuments configuration

    Applies if you configure auth.clientIdMetadataDocuments or auth.experimentalClientIdMetadataDocuments.

Source
Buildpacksv0.40.8CI/CD & App DeliveryJul 13, 2026

A maintenance release rebuilds the pack on Go 1.25.12 to address two disclosed standard library security issues. It also updates several dependencies and includes a newer default lifecycle version.

Check if affected (1)

  • securityhighGo 1.25.12 standard library rebuild for GO-2026-4970 and GO-2026-5856

    Applies if you use 1.25.11 -> 1.25.12.

Source
Fluxv2.9.2CI/CD & App DeliveryJul 13, 2026

Flux v2.9.2 includes an operator-relevant regression fix for Kustomizations whose openapi.path points to a URL, along with dependency and toolkit component updates. CRD description corrections are documentation-only.

Source
Argov3.4.5CI/CD & App DeliveryJul 9, 2026

v3.4.5 is a maintenance release focused on correctness fixes and dependency updates. No security advisory or vulnerability is disclosed.

Source
Tektonv1.6.5CI/CD & App DeliveryJul 8, 2026

This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.

Action needed (1)

  • securityGo 1.25.10 dependency update

    Go is updated to 1.25.10 for CVE remediation in this release.

Source
Tektonv1.9.6CI/CD & App DeliveryJul 8, 2026

Tekton v1.9.6 contains dependency updates for CVE remediation. The release affects Go and two golang.org packages, with no specific advisory identifiers or vulnerability details in the note.

Action needed (3)

  • securityGo 1.25.10 update

    Go is updated to 1.25.10 for CVE remediation in v1.9.6.

  • securitygolang.org/x/crypto v0.52.0 update

    golang.org/x/crypto is updated to v0.52.0 for CVE remediation in v1.9.6.

  • securitygolang.org/x/net v0.55.0 update

    golang.org/x/net is updated to v0.55.0 for CVE remediation in v1.9.6.

Source
Artifact Hubv1.23.0CI/CD & App DeliveryJul 7, 2026

Version v1.23.0 contains no recorded changes for artifact-hub. The release note does not identify any project change that requires a user-facing description.

Source
Fluxv2.9.1CI/CD & App DeliveryJul 7, 2026

Flux v2.9.1 is a maintenance release focused on defect fixes, dependency and component updates, and a performance improvement. It includes changes across controller behavior and build and decryption paths, with no security advisories disclosed.

Source
OpenKruisev1.9.1CI/CD & App DeliveryJul 4, 2026

OpenKruise v1.9.1 is a maintenance release focused on an operator-facing defect in Kubernetes server version parsing. The fix addresses a controller panic involving certain GKE and EKS version strings.

Source
Tektonv1.14.0CI/CD & App DeliveryJun 30, 2026

Release v1.14.0 adds tracing and observability capabilities and broadens ResolutionRequest resolution support. It also includes correctness fixes, a Go security-related update, and shipped dependency updates.

Action needed (1)

  • securityGo 1.26.4 update

    Go is updated to 1.26.4 in v1.14.0 for CVE remediation.

Source
Fluxv2.9.0CI/CD & App DeliveryJun 30, 2026

Flux v2.9.0 removes two deprecated API versions and adds CLI and controller capabilities across several Flux resources. It also changes supported Kubernetes versions, corrects defects, and updates project and third-party dependencies.

Check if affected (1)

  • breakingRemoval of deprecated Flux API versions

    Applies if your CRDs use the image.toolkit.fluxcd.io/v1beta2 or notification.toolkit.fluxcd.io/v1beta2 APIs.

Source
KubeVelav1.10.9CI/CD & App DeliveryJun 30, 2026

A maintenance release with a security fix for unbounded reads in the Terraform remote configuration loader and a correctness fix for CUE imports in status details. It also adds repository ownership metadata.

Check if affected (1)

  • securityUnbounded read prevention in the Terraform remote configuration loader

    Applies if you use the Terraform remote configuration loader.

Source
KubeVelav1.9.14CI/CD & App DeliveryJun 30, 2026

This release includes a security correction for an unbounded-read denial-of-service condition in the Terraform remote configuration loader. The fix is backported to release-1.9 and concerns deployments that use this loader.

Check if affected (1)

  • securityTerraform remote configuration loader DoS fix (GHSA-fmgp-q6jx-gg3x)

    Applies if you use the Terraform remote configuration loader.

Source
Backstagev1.52.1CI/CD & App DeliveryJun 26, 2026

Backstage v1.52.1 is a maintenance release focused on operator-facing defect fixes. It addresses scheduler task state during trigger changes and a broken configuration schema in the Kubernetes React plugin.

Source
Tektonv1.0.4CI/CD & App DeliveryJun 23, 2026

This release contains a release pipeline bug fix for automated draft release support. No operator-facing product changes are recorded here.

Source
Tektonv1.12.2CI/CD & App DeliveryJun 23, 2026

Tekton v1.12.2 is a maintenance release with a dependency version update from k8s.io/client-go 0.35.5 to 0.35.6. No distinct operator-facing changes are recorded.

Source
Tektonv1.3.6CI/CD & App DeliveryJun 23, 2026

Tekton v1.3.6 contains dependency update batches, with no functional or security changes described. The release material also includes installation instructions and attestation or verification metadata.

Source
Older →
Browse by month