Tekton v1.6.4 contains no operator-facing product changes. The release information covers installation, attestation, verification instructions, and empty section headings.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
Tekton v1.9.5 is a dependency maintenance release. The recorded changes update dependency groups and k8s.; the remaining release-note sections contain no operator-facing changes.
This release focuses on builder configuration and registry issue documentation. It changes the lifecycle version included in builders, corrects the yank registry issue body, and updates the suggested Heroku builder image.
Source ↗OpenKruise v1.9.0 adds operator-facing capabilities, upgrades several APIs to v1beta1, and tightens validation for numerical maxUnavailable and maxSurge values. It also includes multiple correctness fixes, with no security advisories or vulnerabilities disclosed.
Check if affected (2)
breakingKruise APIs upgraded to
v1beta1Applies if your manifests use the listed Kruise APIs at
v1alpha1.breakingNumerical string values for
maxUnavailableandmaxSurgerejectedApplies if you configure numerical string values for
maxUnavailableormaxSurge.
This release focuses on correctness fixes in Argo CD. All Argo CD container images are signed by cosign, and provenance is generated for container images and CLI binaries that meet SLSA Level 3 specifications. No security advisory is disclosed.
Source ↗Argo CD v3.3.12 is a maintenance release containing operator-relevant bug fixes. No security advisories or setup-breaking changes are disclosed.
Source ↗A broad feature and maintenance release with breaking configuration and API evolution across catalog, scaffolder, TechDocs, frontend, actions, and Kubernetes capabilities. It also includes correctness, performance, reliability, and security-related dependency updates, with migration attention needed for renamed or deprecated settings and APIs.
Action needed (2)
securityThe
infinispandependency upgradeinfinispanwas upgraded from^0.to12. 0 ^0.to address known vulnerabilities.13. 0 breakingThe unused
json-schemaruntime dependency, removedThe unused
json-schemaruntime dependency has been removed.
Check if affected (7)
breakingThe
catalog.setting, removedstitchingStrategy. mode: 'immediate' Applies if you configure
catalog..stitchingStrategy. mode breaking
ComboboxPropsas a union typeApplies if you use
ComboboxProps.breakingThe default
/kubernetespage, removedApplies if you use
/kubernetes.- + 4 more on the release page
Plan ahead (9)
deprecatedTop-level
Comboboxinput state props, deprecatedApplies if you use plain-array
options.deprecatedPrevious tokens, deprecatedremoval date not announced
Applicability is not stated in the release notes.
deprecatedThe single-module
runCliModulehelper, deprecatedApplies if you use
runCliModule.- + 6 more on the release page
A maintenance release with defect corrections and a behavior change affecting implicit resource settings for internal containers. No security advisories are disclosed.
Check if affected (1)
breakingDefault resource requirements for internal containers are removed
Applies if you do not set
default-container-resource-requirements.
A maintenance release with several correctness fixes and multiple dependency updates. Resolver behavior is narrowed so that only StepActions, Tasks, and Pipelines can be resolved, which requires review for users of Tekton Resolvers.
Check if affected (1)
breakingTekton Resolver object restrictions
Applies if you use
Tekton Resolvers.
Tekton v1.10.3 contains no operator-facing product changes in the supplied release information. The release information instead contains no recorded changes to describe.
Source ↗A maintenance release with correctness fixes, a security-relevant dependency update, resolver compatibility constraints, metric behavior changes, and additional dependency upgrades. The changes include a restriction on the object types handled by Tekton Resolvers and an update to gRPC.
Action needed (1)
securitycritical
google.updated to 1.79.3 for CVE-2026-33186golang. org/grpc The
google.dependency is updated from 1.77.0 to 1.79.3 to fix CVE-2026-33186, an authorization bypass caused by a missing leading slash in thegolang. org/grpc :pathheader.
Check if affected (1)
breakingTekton Resolvers, limited to supported object types
Applies if you use the
Resolver API.
Tekton v1.6.3 contains resolver validation and behavior corrections, along with fixes affecting cross-architecture execution and metrics. It also updates dependencies, including a gRPC change for CVE-2026-33186, so resolver users and dependency-sensitive deployments should review the release.
Action needed (1)
securitycriticalThe
google.dependency fix for CVE-2026-33186golang. org/grpc The
google.dependency includes a fix for CVE-2026-33186 in v1.6.3.golang. org/grpc
Check if affected (1)
breakingTekton Resolver target restrictions
Applies if your
ResolutionRequestobjects use Tekton Resolvers.
A correctness-focused release fixes resolver behavior and updates dependencies. It also narrows the resolver input contract and changes pod metrics and labels.
Action needed (1)
breakingPod label removal
The pod label is removed in this release.
Check if affected (1)
breakingThe
Resolver APIresolution scopeApplies if you use custom resolvers and the
Resolver API.
Tekton v1.2.1 contains no operator-facing changes. The release information covers installation and attestation details, with no recorded feature, behavior, or configuration updates.
Source ↗This release contains a documented operator-facing defect fix. The recorded release heading has no actionable change.
Source ↗Core v0.16.0 changes disabled-flag evaluations from returning an error to succeeding with reason DISABLED; resolved values remain unchanged and still use the caller-provided default. The compatibility change affects consumers that inspect reason or errorCode, call flagd directly over gRPC or OFREP, or import core/pkg/model.
flagd v0.16.0 changes evaluation of disabled flags. Disabled flags now resolve successfully with reason=DISABLED instead of returning a FLAG_DISABLED error.
This release contains an operator-facing bug fix. The documented fix addresses a panic when an S3 URI includes a query string.
Source ↗This release contains an operator-facing bug fix for flagd. It addresses a panic when an S3 URI includes a query string.
Source ↗Backstage v1.51.1 is a maintenance release focused on corrected defects and package dependency behavior. The available release information indicates fixes in query handling, GitLab repository retrieval, runtime dependency classification, and Microsoft Graph group-member filtering.
Source ↗This release is labeled as containing new features, but the supplied release note does not describe a specific operator-facing change. No detailed feature behavior or affected component is stated.
Source ↗This release adds support for custom headers in the OpenFeature flagd proxy. The recorded changes do not include a specific implementation item for this release.
Source ↗This release adds support for custom headers in flagd. The remaining release-note entry is a heading without a recorded change detail.
Source ↗Argo CD v3.3.11 contains bug fixes and a UI dependency update addressing CVE-2026-41240. The release concerns deployments using the affected UI dependency.
Action needed (1)
securitymediumThe
redoc/dompurifydependency, updated to v3.4.0The
/uidependencyredoc/dompurifyis updated to v3.4.0 to address CVE-2026-41240.
A maintenance release with several correctness fixes across Argo CD and a UI dependency update addressing CVE-2026-41240. The recorded fixes cover CLI, UI, Git, controller startup, and resource handling.
Check if affected (1)
securitymediumThe
redoc/dompurifydependency, upgraded for CVE-2026-41240Applies if you use
redoc/dompurifyin/ui.
This release contains no described operator-facing changes. No release-note details are provided for this version.
Source ↗Flux v2.8.8 is a maintenance release with defect corrections, expanded compatibility, and dependency updates. It also includes two disclosed security fixes in go-git.
Action needed (1)
securitymediumThe
go-gitsecurity fixes for CVE-2026-45571 and CVE-2026-45570Flux v2.8.8 includes security fixes in
go-gitassociated with CVE-2026-45571, CVE-2026-45570, GHSA-crhj-59gh-8x96, and GHSA-m7cr-m3pv-hgrp.
A broad release with breaking API removals, changed defaults and constraints, and many new operator-facing capabilities. It also includes performance improvements and an explicitly described dependency security update.
Action needed (2)
securityModule Federation packages at
v2.3. 3 Module Federation packages were upgraded to
v2.to address known vulnerabilities.3. 3 breakingThe
@remixicon/reactversion constraintThe
@remixicon/reactdependency is limited to versions below4.because of a license change.9. 0
Check if affected (9)
securitySpecific defaults for known MCP clients
Applies if you configure
CIMDorDCR.breakingThe
NavItemBlueprintAPI, removedApplies if you use
NavItemBlueprint.breakingSidebar and legacy
nav-itemrendering inrenderInTestAppApplies if you use
renderInTestApp.- + 6 more on the release page
Plan ahead (4)
deprecatedThe
PolicyQueryUser.field, deprecatedidentity Applies if you use
PolicyQueryUser..identity deprecatedThe
EXPERIMENTAL_formDecoratorsfield, deprecated aliasApplies if you configure
EXPERIMENTAL_formDecorators.deprecatedThe
catalog.setting, deprecatedstitchingStrategy. mode: 'immediate' Applies if you configure
catalog..stitchingStrategy. mode - + 1 more on the release page
This release updates the lifecycle bundled into newly created builders and corrects trusted-builder inspection. It also adds a trusted Heroku builder, with a future recommendation change announced.
Source ↗This release includes a bundled lifecycle version change and updates to Go and other Go dependencies. The remaining release-note entries are headings or upgrade prerequisites.
Source ↗A maintenance release that closes the 3.2 series and marks it as end of life. It also contains an operator-visible bug fix and a dependency update.
Plan ahead (1)
deprecatedThe
3.reaches end of life2 release series Applies if you use the
3..2 release series
This release combines bug fixes with dependency and toolchain updates. The Go update to 1. addresses CVEs and concerns deployments using this release.
Action needed (1)
securityThe
Gotoolchain, updated to1.25. 9 The
Gotoolchain is updated to1.on25. 9 release-3.to resolve CVEs.3
Argo CD v3.4.2 is a maintenance release with bug fixes, dependency updates, and corrected secret handling in server-side diff results. It contains no listed security advisories, and no operator action beyond upgrading is identified.
Source ↗Flux v2. includes a security update to the go-git dependency alongside toolkit component updates. The go-git update addresses CVE-2026-45022 and GHSA-389r-gv7p-r3rp.
Action needed (1)
securityhighThe
go-gitdependency update tov5.19. 0 The
go-gitdependency is updated tov5., which fixes CVE-2026-45022 and addresses GHSA-389r-gv7p-r3rp. This update ships in Flux19. 0 v2..8. 7
A broad maintenance and feature release with correctness, performance, dependency, and operator-facing changes. Operators should review the cluster-version annotation format and changed defaults, while dependency updates include Kubernetes and Helm changes; no explicitly disclosed exploitable vulnerability or security advisory is identified.
Action needed (4)
securityThe
k8s.module, updated toio/kubernetes v1.34. 2 The
k8s.module is updated toio/kubernetes v1.as a security-related dependency update.34. 2 securityThe
helmdependency, updated to3.19. 4 The
helmdependency is updated to3.due to a CVE.19. 4 breakinggRPC service config DNS TXT lookups, disabled by default
gRPC service config DNS TXT lookups are disabled by default.
breakingThe appset resource status count, defaulted to
5000The default appset resource status count is changed to
5000.
Check if affected (2)
breakingThe
--clientflag in the Helm version command, removedApplies if you use
--client.breakingThe cluster-version annotation format, renamed
Applies if you use Application Sets with Cluster Generators and configure
argocd..argoproj. io/auto-label-cluster-info
A maintenance release that ends the 3. series on May 06th 2026, after which it will no longer receive bug fixes or security updates. It also includes a fix for an error when attempting a second delete operation.
Plan ahead (1)
deprecatedThe
3.release series, end of liferemoval planned in May 06th 20261 Applies if you run the
3.release series.1
This release updates the lifecycle bundled into builders and corrects platform-specific builder image fetching for containerd-backed Docker daemons. The remaining release-note material describes headings or duplicate details of the same fix.
Source ↗OpenFeature core/v0.15.5 is a maintenance release with operator-relevant corrections and a security-related dependency update. The security announcement does not identify a specific advisory in the release text.
Action needed (1)
securityOpen Dependabot security alerts resolved
Open Dependabot security alerts were resolved in the OpenFeature core release.
This release resolves open Dependabot security alerts in the flagd proxy. The release note does not identify which vulnerabilities or dependencies were fixed.
Action needed (1)
securityDependabot security alerts resolved
The
flagd-proxy/v0.release resolves open Dependabot security alerts. The release note does not identify the affected dependencies or vulnerabilities.9. 5
flagd/v0.15.5 is a maintenance release with operator-facing corrections and a value update. No security advisories or explicit security issues are identified.
Source ↗