Tekton v1.15.0 adds configurable behavior, corrects defects across controllers and runtime components, and updates project dependencies. No security advisories or explicitly described vulnerabilities are present.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This release contains an operator-facing defect correction. The remaining release-note content consists of headings, installation guidance, or attestation instructions rather than additional software changes.
Source ↗A maintenance release fixes pipeline validation so $(results. references are accepted in Pipeline task parameters. Nothing else described requires operator attention.
This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.
Action needed (1)
security
Go1.25.10 dependency updateGois updated to1.for CVE remediation in this release.25. 10
Tekton v1.9.6 contains dependency updates for CVE remediation. The release affects Go and two golang. packages, with no specific advisory identifiers or vulnerability details in the note.
Action needed (3)
security
Go1.25.10 updateGois updated to1.for CVE remediation in v1.9.6.25. 10 security
golang.v0.52.0 updateorg/x/crypto golang.is updated toorg/x/crypto v0.for CVE remediation in v1.9.6.52. 0 security
golang.v0.55.0 updateorg/x/net golang.is updated toorg/x/net v0.for CVE remediation in v1.9.6.55. 0