This is a maintenance release for Argo CD focused on operator-relevant bug fixes. It addresses incorrect behavior in application normalization and cached installation ID handling.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This maintenance release includes a security mitigation for CVE-2026-33186 in grpc-go. It also contains ordinary fixes to application behavior and the user interface.
Action needed (1)
securitycritical
grpc-goCVE-2026-33186 mitigationA mitigation for CVE-2026-33186 in
grpc-goships in therelease-3.line.2
Argo CD v3.1.13 focuses on release artifact provenance and maintenance, with a security mitigation, a UI correction, and a dependency update. Container images are signed, and qualifying container images and CLI binaries receive SLSA Level 3 provenance.
Action needed (1)
securitycritical
grpc-goCVE-2026-33186 mitigationThe release includes a mitigation for CVE-2026-33186 in
grpc-gofor release-3.1.
Argo CD v3.3.5 is a maintenance release with six operator-relevant bug fixes and an update to the google. dependency from 1.77.0 to 1.79.3. No security advisories or security-specific fixes are disclosed.
Argo CD v3.3.4 includes signed container images, a fix that skips token refresh threshold parsing in unrelated components, and an otel-sdk dependency update. The release also contains CI-only work, headings, and installation examples without separately actionable operator impact.
A maintenance release with a compatibility update for cluster version labels and several ordinary defect corrections. The compatibility update concerns Application Sets that fetch clusters based on Kubernetes version.
Check if affected (1)
breakingThe
argocd.format, changedargoproj. io/kubernetes-version Applies if
argocd.andargoproj. io/auto-label-cluster-info argocd.are configured.argoproj. io/kubernetes-version Application Sets with Cluster Generators must use
argocd.with theargoproj. io/kubernetes-version vMajor.format instead of the previousMinor. Patch Major.format when fetching clusters by Kubernetes version. The affected cluster secret usesMinor argocd..argoproj. io/auto-label-cluster-info