A maintenance release includes a fix for a panic when sync processes an S3 URI with a query string.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release fixes a panic when an s3 URI contains a query string. No security advisory or setup change is indicated.
A maintenance release focused on corrected defects in data access and repository integrations, plus runtime dependency packaging behavior. The release heading contains no additional operator-facing change details.
Source ↗The release note contains a new-features heading but does not describe a specific operator-facing change.
Source ↗This release adds support for custom headers in the OpenFeature flagd proxy. The recorded changes do not include a specific implementation item for this release.
Source ↗Adds support for custom headers and includes documentation for the change.
Source ↗Argo CD v3.3.11 contains bug fixes and a UI dependency update addressing CVE-2026-41240. The release concerns deployments using the affected UI dependency.
Action needed (1)
securitymediumThe
redoc/dompurifydependency, updated to v3.4.0The
/uidependencyredoc/dompurifyis updated to v3.4.0 to address CVE-2026-41240.
A maintenance release with several correctness fixes across Argo CD and a UI dependency update addressing CVE-2026-41240. The recorded fixes cover CLI, UI, Git, controller startup, and resource handling.
Check if affected (1)
securitymediumThe
redoc/dompurifydependency, upgraded for CVE-2026-41240Applies if you use
redoc/dompurifyin/ui.
This release contains no described operator-facing changes. No release-note details are provided for this version.
Source ↗Flux v2.8.8 is a maintenance release with defect corrections, expanded compatibility, and dependency updates. It also includes two disclosed security fixes in go-git.
Action needed (1)
securitymediumThe
go-gitsecurity fixes for CVE-2026-45571 and CVE-2026-45570Flux v2.8.8 includes security fixes in
go-gitassociated with CVE-2026-45571, CVE-2026-45570, GHSA-crhj-59gh-8x96, and GHSA-m7cr-m3pv-hgrp.
A broad release with breaking API removals, changed defaults and constraints, and many new operator-facing capabilities. It also includes performance improvements and an explicitly described dependency security update.
Action needed (2)
securityModule Federation packages at
v2.3. 3 Module Federation packages were upgraded to
v2.to address known vulnerabilities.3. 3 breakingThe
@remixicon/reactversion constraintThe
@remixicon/reactdependency is limited to versions below4.because of a license change.9. 0
Check if affected (9)
securitySpecific defaults for known MCP clients
Applies if you configure
CIMDorDCR.breakingThe
NavItemBlueprintAPI, removedApplies if you use
NavItemBlueprint.breakingSidebar and legacy
nav-itemrendering inrenderInTestAppApplies if you use
renderInTestApp.- + 6 more on the release page
Plan ahead (4)
deprecatedThe
PolicyQueryUser.field, deprecatedidentity Applies if you use
PolicyQueryUser..identity deprecatedThe
EXPERIMENTAL_formDecoratorsfield, deprecated aliasApplies if you configure
EXPERIMENTAL_formDecorators.deprecatedThe
catalog.setting, deprecatedstitchingStrategy. mode: 'immediate' Applies if you configure
catalog..stitchingStrategy. mode - + 1 more on the release page
This release updates the lifecycle bundled into newly created builders and corrects trusted-builder inspection. It also adds a trusted Heroku builder, with a future recommendation change announced.
Source ↗A maintenance release updates the bundled lifecycle version in pack CLI builders and refreshes Go dependencies. The notes also include upgrade prerequisites.
Source ↗A maintenance release that closes the 3.2 series and marks it as end of life. It also contains an operator-visible bug fix and a dependency update.
Plan ahead (1)
deprecatedThe
3.reaches end of life2 release series Applies if you use the
3..2 release series
This release combines bug fixes with dependency and toolchain updates. The Go update to 1. addresses CVEs and concerns deployments using this release.
Action needed (1)
securityThe
Gotoolchain, updated to1.25. 9 The
Gotoolchain is updated to1.on25. 9 release-3.to resolve CVEs.3
Argo CD v3.4.2 is a maintenance release with bug fixes, dependency updates, and corrected secret handling in server-side diff results. It contains no listed security advisories, and no operator action beyond upgrading is identified.
Source ↗Flux v2. includes a security update to the go-git dependency alongside toolkit component updates. The go-git update addresses CVE-2026-45022 and GHSA-389r-gv7p-r3rp.
Action needed (1)
securityhighThe
go-gitdependency update tov5.19. 0 The
go-gitdependency is updated tov5., which fixes CVE-2026-45022 and addresses GHSA-389r-gv7p-r3rp. This update ships in Flux19. 0 v2..8. 7
A broad maintenance and feature release with correctness, performance, dependency, and operator-facing changes. Operators should review the cluster-version annotation format and changed defaults, while dependency updates include Kubernetes and Helm changes; no explicitly disclosed exploitable vulnerability or security advisory is identified.
Action needed (4)
securityThe
k8s.module, updated toio/kubernetes v1.34. 2 The
k8s.module is updated toio/kubernetes v1.as a security-related dependency update.34. 2 securityThe
helmdependency, updated to3.19. 4 The
helmdependency is updated to3.due to a CVE.19. 4 breakinggRPC service config DNS TXT lookups, disabled by default
gRPC service config DNS TXT lookups are disabled by default.
breakingThe appset resource status count, defaulted to
5000The default appset resource status count is changed to
5000.
Check if affected (2)
breakingThe
--clientflag in the Helm version command, removedApplies if you use
--client.breakingThe cluster-version annotation format, renamed
Applies if you use Application Sets with Cluster Generators and configure
argocd..argoproj. io/auto-label-cluster-info
A maintenance release that ends the 3. series on May 06th 2026, after which it will no longer receive bug fixes or security updates. It also includes a fix for an error when attempting a second delete operation.
Plan ahead (1)
deprecatedThe
3.release series, end of liferemoval planned in May 06th 20261 Applies if you run the
3.release series.1
This release updates the lifecycle bundled into builders and corrects platform-specific builder image fetching for containerd-backed Docker daemons. The remaining release-note material describes headings or duplicate details of the same fix.
Source ↗