RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Apr 2026Clear ×
OpenFeaturecore/v0.15.5CI/CD & App DeliveryApr 30, 2026

OpenFeature core/v0.15.5 is a maintenance release with operator-relevant corrections and a security-related dependency update. The security announcement does not identify a specific advisory in the release text.

Action needed (1)

  • securityOpen Dependabot security alerts resolved

    Open Dependabot security alerts were resolved in the OpenFeature core release.

Source
OpenFeatureflagd-proxy/v0.9.5CI/CD & App DeliveryApr 30, 2026

This release resolves open Dependabot security alerts in the flagd proxy. The release note does not identify which vulnerabilities or dependencies were fixed.

Action needed (1)

  • securityDependabot security alerts resolved

    The flagd-proxy/v0.9.5 release resolves open Dependabot security alerts. The release note does not identify the affected dependencies or vulnerabilities.

Source
Argov3.3.9CI/CD & App DeliveryApr 30, 2026

v3.3.9 is a maintenance release with a disclosed security fix and a go version update to resolve CVEs. It also includes bug fixes in the release.

Action needed (2)

  • securitycriticalGHSA-3v3m-wc6v-x4x3 security fix

    This release fixes the vulnerability identified by GHSA-3v3m-wc6v-x4x3.

  • securityThe go version update for CVE resolution

    The go version is bumped to resolve CVEs in v3.3.9.

Source
Argov3.2.11CI/CD & App DeliveryApr 30, 2026

Version v3.2.11 includes a disclosed security fix and additional correctness and dependency updates. The security fix is the release change that concerns users evaluating whether to upgrade.

Action needed (1)

  • securitycriticalSecurity fix for GHSA-3v3m-wc6v-x4x3

    Version v3.2.11 contains a security fix for the vulnerability identified by GHSA-3v3m-wc6v-x4x3.

Source
Backstagev1.50.4CI/CD & App DeliveryApr 29, 2026

A security maintenance release with fixes affecting three Backstage catalog packages. The affected packages are @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, and @backstage/plugin-catalog-unprocessed-entities.

Check if affected (1)

  • securitySecurity fixes for Backstage catalog packages

    Applies if you use any of @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, or @backstage/plugin-catalog-unprocessed-entities.

Source
Backstagev1.50.0CI/CD & App DeliveryApr 14, 2026

A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the .well-known/oauth-protected-resource URL, and includes broad correctness and dependency updates.

Action needed (4)

  • securityhighThe glob and rollup dependencies, upgraded

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions. rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe glob dependency, upgraded to v13

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.

  • securityThe rollup dependency, upgraded to v4.59+

    rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe .well-known/oauth-protected-resource URL

    The .well-known/oauth-protected-resource resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.

Check if affected (22)

  • breakingThe auth.omitIdentityTokenOwnershipClaim setting

    Applies if you do not configure auth.omitIdentityTokenOwnershipClaim.

  • breakingThe SignInResolverFactoryOptions type parameters

    Applies if you use SignInResolverFactoryOptions.

  • breakingThe catalog permission exports, removed

    Applies if you use CatalogPermissionRuleInput, CatalogPermissionExtensionPoint, or catalogPermissionExtensionPoint.

  • + 19 more on the release page

Plan ahead (6)

  • deprecatedThe show and showModal compatibility implementation, deprecated

    Applies if you use show or showModal.

  • deprecatedThe auth.omitIdentityTokenOwnershipClaim setting, deprecatedremoval date not announced

    Applies if you configure auth.omitIdentityTokenOwnershipClaim.

  • deprecatedThe config.schema callback format, deprecated

    Applies if you use config.schema.

  • + 3 more on the release page
Source
OpenFeaturecore/v0.15.2CI/CD & App DeliveryApr 9, 2026

This release contains two security updates whose affected vulnerabilities are not identified. It also adds experimental incremental updates for gRPC synchronization.

Action needed (1)

  • securityThe vulnerability-updates security update

    OpenFeature Core v0.15.2 includes a security update for vulnerability-updates.

Source
OpenFeatureflagd-proxy/v0.9.4CI/CD & App DeliveryApr 9, 2026

This release contains security updates for flagd-proxy/v0.9.4. The available notes do not identify the affected vulnerabilities or describe their scope.

Action needed (2)

  • securityThe vulnerability-updates entry for issue #1933

    The vulnerability-updates entry records a security update for flagd-proxy/v0.9.4, tracked in issue #1933. The notes do not describe the affected vulnerability.

  • securityThe vulnerability-updates entry for issue #1934

    The vulnerability-updates entry records a security update for flagd-proxy/v0.9.4, tracked in issue #1934. The notes do not describe the affected vulnerability.

Source
OpenFeatureflagd/v0.15.2CI/CD & App DeliveryApr 9, 2026

flagd v0.15.2 includes two undisclosed security updates and a new experimental gRPC incremental-update capability. The experimental addition concerns deployments that use gRPC synchronization.

Action needed (2)

  • securityThe vulnerability-updates security update for issue #1933

    flagd v0.15.2 includes the vulnerability-updates security update linked to issue #1933.

  • securityThe vulnerability-updates security update for issue #1934

    flagd v0.15.2 includes the vulnerability-updates security update linked to issue #1934.

Source
OpenFeaturecore/v0.15.1CI/CD & App DeliveryApr 7, 2026

Release 0.15.1 fixes a memory leak caused by unbounded metrics cardinality and updates a dependency for an undisclosed security fix. The dependency update ships in the core v0.15.1 release.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 dependency update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 for a security fix. This change ships in core v0.15.1.

Source
OpenFeatureflagd-proxy/v0.9.3CI/CD & App DeliveryApr 7, 2026

This release includes a security update to the github.com/go-jose/go-jose/v4 dependency. The release note does not disclose the nature of the vulnerability.

Action needed (1)

  • securitygithub.com/go-jose/go-jose/v4 updated to v4.1.4

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in flagd-proxy v0.9.3 as a security fix. The note does not disclose the nature of the vulnerability.

Source
OpenFeatureflagd/v0.15.1CI/CD & App DeliveryApr 7, 2026

This release fixes RPC flag defaulting, metrics-server process handling, and unbounded metrics cardinality. It also updates a dependency for an undisclosed security fix, which is the main consideration for users evaluating the release.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 dependency, updated to v4.1.4

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in flagd/v0.15.1 for an undisclosed security fix.

Source
Browse by month