A maintenance release with correctness fixes for dynamic keys in status., an option to disable status validation, and apply-once resource reconciliation and applied-resource tracking. It also updates a debug webhook script for setup tooling.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This is a patch release for Backstage with one new TablePagination API prop and two correctness fixes. The changes concern pagination labeling, relative link resolution, and entity relation cards.
A maintenance release with operator-relevant fixes to application normalization and cached installation IDs. The remaining release note content does not describe additional product changes.
Source ↗This maintenance release includes a security mitigation for CVE-2026-33186 in grpc-go. It also contains ordinary fixes to application behavior and the user interface.
Action needed (1)
securitycritical
grpc-goCVE-2026-33186 mitigationA mitigation for CVE-2026-33186 in
grpc-goships in therelease-3.line.2
Argo CD v3.1.13 focuses on release artifact provenance and maintenance, with a security mitigation, a UI correction, and a dependency update. Container images are signed, and qualifying container images and CLI binaries receive SLSA Level 3 provenance.
Action needed (1)
securitycritical
grpc-goCVE-2026-33186 mitigationThe release includes a mitigation for CVE-2026-33186 in
grpc-gofor release-3.1.
Argo CD v3.3.5 is a maintenance release with six operator-relevant bug fixes and an update to the google. dependency from 1.77.0 to 1.79.3. No security advisories or security-specific fixes are disclosed.
This patch release corrects CIMD redirect URI matching for loopback addresses. No operator configuration change is indicated.
Source ↗This release contains API and template changes, new DevTools functionality, frontend behavior changes, and defect corrections. No security advisories or security-specific fixes are stated.
Check if affected (1)
breakingThe catalog entity page layout header is disabled
Applies if you use the catalog entity page in the new frontend system.
A breaking compatibility release changes defaults and removes or narrows support across the frontend, CLI, catalog, and integrations. It also introduces new frontend, catalog, scaffolder, CLI, and integration capabilities, while deprecated functionality remains in some areas and requires planning. The release contains no security fixes.
Check if affected (14)
breakingThe New Frontend System as the default for new apps
Applicability is not stated in the release notes.
breakingThe
create-appfrontend selection flagApplies if you use the
--nextflag forcreate-app.breakingDeprecated types and options
Applies if you use deprecated types and options.
- + 11 more on the release page
Plan ahead (7)
deprecatedDeprecated
variant,columns, andtableOptionspropsApplies if you use the
variant,columns, ortableOptionsprops.deprecatedThe
RelatedEntitiesCardcomponentApplies if you use
RelatedEntitiesCard.deprecatedThe
CLI built-in set fallbackApplicability is not stated in the release notes.
- + 4 more on the release page
Flux v2.8.3 fixes a helm-controller templating regression. The release also identifies helm-controller v1.5.3.
Source ↗Argo CD v3.3.4 includes signed container images, a fix that skips token refresh threshold parsing in unrelated components, and an otel-sdk dependency update. The release also contains CI-only work, headings, and installation examples without separately actionable operator impact.
A maintenance release updates builders to include lifecycle v0.21.0 and fixes lifecycle binary selection for amd64. It also adds ubi9, ubi10, and noble as suggested builders.
Source ↗Flux v2.8.2 includes correctness fixes and dependency updates. It also fixes a disclosed TLS-handshake denial-of-service issue in the controller builds.
Action needed (1)
securitymediumCVE-2026-27138 TLS-handshake DoS fix
The TLS-handshake denial-of-service issue identified as CVE-2026-27138 is fixed by building all controllers with
Go 1..26. 1
A security-focused maintenance release fixes undisclosed issues in two Backstage backend plugins. The affected plugins are @backstage/plugin-auth-backend and @backstage/plugin-scaffolder-backend.
Action needed (1)
securitySecurity fixes in two Backstage backend plugins
Security fixes ship in
@backstage/plugin-auth-backendand@backstage/plugin-scaffolder-backend.
A maintenance release with a compatibility update for cluster version labels and several ordinary defect corrections. The compatibility update concerns Application Sets that fetch clusters based on Kubernetes version.
Check if affected (1)
breakingThe
argocd.format, changedargoproj. io/kubernetes-version Applies if
argocd.andargoproj. io/auto-label-cluster-info argocd.are configured.argoproj. io/kubernetes-version
Backstage v1.48.4 is a security-fix release affecting three Backstage packages. Operators using these packages are the audience for this update.
Check if affected (1)
securitySecurity fixes for three Backstage packages
Applies to users of
@backstage/plugin-techdocs-node,@backstage/integration, or@backstage/plugin-scaffolder-backend.