Tekton v1.15.0 adds configurable behavior, corrects defects across controllers and runtime components, and updates project dependencies. No security advisories or explicitly described vulnerabilities are present.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with bug fixes and dependency updates. The form-data update in /ui addresses CVE-2026-12143.
Action needed (1)
securityhighThe
form-datadependency update for CVE-2026-12143The
form-datadependency is updated to version 4.0.6 in/uito address CVE-2026-12143.
This is a bug-fix release for Argo CD v3.4.6. The release notes mention corrections to application behavior and integrations, with no security advisories or explicit security vulnerabilities stated.
Source ↗This release contains an operator-facing defect correction. The remaining release-note content consists of headings, installation guidance, or attestation instructions rather than additional software changes.
Source ↗Nothing here needs operator attention.
Source ↗This release combines ordinary bug fixes with security-related updates. It also improves blob/HTTP synchronization, with no announced operator-facing removals, deprecations, or default changes.
Action needed (2)
securityThe
google.module update to v1.82.1golang. org/grpc The
google.module is updated to v1.82.1 in core v0.16.1.golang. org/grpc securityThe
vulnerability-updatesupdatevulnerability-updatesis updated in core v0.16.1.
A maintenance release with a bug-fix heading, a new server timeout setting, dependency updates, and security-related updates. The google. update requires upgrading.
Action needed (2)
securityThe
google.module, updated to v1.82.1golang. org/grpc The
google.module is updated to v1.82.1 as a security-related dependency change.golang. org/grpc securityThe
vulnerability-updatesdependency updateThe release updates
vulnerability-updatesas a security-related dependency change.
flagd/v0. combines bug fixes with security dependency updates and a configurable sync-server capability. The security notes do not include advisory identifiers or flaw details, while the sync-server changes include server timeouts and configurable gRPC keepalive enforcement.
Action needed (3)
securitySecurity dependency updates
Security dependencies are updated in
flagd/v0..16. 1 securityThe
google.module updategolang. org/grpc The
google.module is updated togolang. org/grpc v1.in82. 1 flagd/v0..16. 1 securityVulnerability updates
Vulnerability updates are included in
flagd/v0.as a security change.16. 1
Flux v2.9.3 is a maintenance release with correctness fixes, updated dependencies, and a newly included component in the OCI artifact. No security advisories are disclosed.
Source ↗A maintenance release fixes pipeline validation so $(results. references are accepted in Pipeline task parameters. Nothing else described requires operator attention.
A feature and maintenance release with authorization tightening, credential handling fixes, and validation improvements. It also adds capabilities across Helm, CUE, workflows, registries, and dependency management.
Check if affected (3)
securityRestricted access to
vela-system definitionsApplies if you use
vela-system definitions.securityCredential redaction for Terraform module remote URLs
Applies if you configure
Terraform module remote URLs.breakingUndeclared parameter validation for application definitions
Applies if you use
application definitions.
A substantial mixed feature and maintenance release adds backend, frontend, catalog, authentication, webhook, and TechDocs capabilities alongside dependency updates and defect fixes. It also includes operator-visible changes to APIs, configuration validation, OpenAPI tooling, and MCP transport behavior; no security advisories or security-specific fixes are disclosed.
Action needed (1)
breakingOpenAPI breaking change detection with
oasdiff@useoptic/opticand@useoptic/openapi-utilitieshave been replaced withoasdifffor OpenAPI breaking change detection.
Check if affected (12)
breakingSchema loading rejects invalid imports
Applicability is not stated in the release notes.
breakingThe
package schema openapi initandrepo schema openapi testcommands, removedApplies if you use
package schema openapi initorrepo schema openapi test.breakingMutually exclusive
userGroupMember.andpath user.configurationfilter Applies if you configure both
userGroupMember.andpath user..filter - + 9 more on the release page
Plan ahead (3)
deprecatedOpaque entity header extension point deprecation
Applies if you use the opaque entity header extension point.
deprecatedDynamic Client Registration deprecation warning
Applies if you enable Dynamic Client Registration.
deprecatedStable
auth.configurationclientIdMetadataDocuments Applies if you configure
auth.orclientIdMetadataDocuments auth..experimentalClientIdMetadataDocuments
A maintenance release rebuilds the pack on Go 1.25.12 to address two disclosed standard library security issues. It also updates several dependencies and includes a newer default lifecycle version.
Check if affected (1)
securityhigh
Go1.25.12 standard library rebuild for GO-2026-4970 and GO-2026-5856Applies if you use
1..25. 11 -> 1. 25. 12
Flux v2.9.2 includes an operator-relevant regression fix for Kustomizations whose openapi. points to a URL, along with dependency and toolkit component updates. CRD description corrections are documentation-only.
v3.4.5 is a maintenance release focused on correctness fixes and dependency updates. No security advisory or vulnerability is disclosed.
Source ↗This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.
Action needed (1)
security
Go1.25.10 dependency updateGois updated to1.for CVE remediation in this release.25. 10
Tekton v1.9.6 contains dependency updates for CVE remediation. The release affects Go and two golang. packages, with no specific advisory identifiers or vulnerability details in the note.
Action needed (3)
security
Go1.25.10 updateGois updated to1.for CVE remediation in v1.9.6.25. 10 security
golang.v0.52.0 updateorg/x/crypto golang.is updated toorg/x/crypto v0.for CVE remediation in v1.9.6.52. 0 security
golang.v0.55.0 updateorg/x/net golang.is updated toorg/x/net v0.for CVE remediation in v1.9.6.55. 0
Nothing here needs operator attention.
Source ↗Flux v2.9.1 is a maintenance release focused on defect fixes, dependency and component updates, and a performance improvement. It includes changes across controller behavior and build and decryption paths, with no security advisories disclosed.
Source ↗OpenKruise v1.9.1 is a maintenance release focused on an operator-facing defect in Kubernetes server version parsing. The fix addresses a controller panic involving certain GKE and EKS version strings.
Source ↗