flagd/v0.15.5 is a maintenance release with operator-facing corrections and a value update. No security advisories or explicit security issues are identified.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
v3.3.9 is a maintenance release with a disclosed security fix and a go version update to resolve CVEs. It also includes bug fixes in the release.
Action needed (2)
securitycriticalGHSA-3v3m-wc6v-x4x3 security fix
This release fixes the vulnerability identified by GHSA-3v3m-wc6v-x4x3.
securityThe
goversion update for CVE resolutionThe
goversion is bumped to resolve CVEs in v3.3.9.
Version v3. includes a disclosed security fix and additional correctness and dependency updates. The security fix is the release change that concerns users evaluating whether to upgrade.
Action needed (1)
securitycriticalSecurity fix for GHSA-3v3m-wc6v-x4x3
Version
v3.contains a security fix for the vulnerability identified by GHSA-3v3m-wc6v-x4x3.2. 11
A security maintenance release with fixes affecting three Backstage catalog packages. The affected packages are @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, and @backstage/plugin-catalog-unprocessed-entities.
Check if affected (1)
securitySecurity fixes for Backstage catalog packages
Applies if you use any of
@backstage/plugin-catalog-backend-module-unprocessed,@backstage/plugin-catalog-unprocessed-entities-common version, or@backstage/plugin-catalog-unprocessed-entities.
Microcks 1.14.0 adds asynchronous request and tracing support, corrects operation-method handling, and updates shipped dependencies. The release concerns deployments or integrations that use these capabilities or depend on the updated platform components.
Source ↗This release contains a change to the lifecycle version used by builders created with the pack CLI. The recorded change is not included in the item list because no change entry was provided.
Source ↗This is a maintenance release for Backstage with ordinary correctness fixes. It addresses home page widget interactions, facets endpoint performance under filters or permissions, and external links under a non-root base path.
Source ↗Argo v3.3.8 is a patch release focused on operator-relevant bug fixes, including a changed default for the ApplicationSet resource status count. No security advisories or security-specific fixes are disclosed.
Source ↗Argo CD v3.2.10 contains operator-relevant bug fixes. The remaining release-note content does not describe a distinct operator-facing change.
Source ↗Argo v3.1.15 is a focused bug-fix release for operator behavior. The listed fixes affect refresh behavior and application-controller synchronization, while the other release material covers installation, documentation, headings, or release metadata.
Source ↗This is an operator-focused maintenance release with fixes and configuration constraints across controllers. It also adds a feature gate and updates dependency and toolkit components.
Check if affected (1)
breakingRequired
audiencefield on the GCR Receiver secretApplies if you configure the
audiencefield on the GCR Receiver secret.
This release combines a new TechDocs sidebar styling capability with dependency updates and constraints. It also corrects an active tab indicator issue in Backstage UI.
Action needed (1)
breaking
React Ariadependency ranges constrained to patch-only updatesReact Ariadependency ranges are limited to patch-only updates in Backstage v1.50.2.
This release narrows the allowed React Aria dependency range to prevent unintended breaking updates. The version heading itself carries no operator-facing change.
Source ↗This release changes the dependency range for React Aria dependencies to prevent unintended breaking changes from minor-version updates. The release version is not stated as increasing.
Source ↗This release tightens the React Aria dependency range to avoid unintended breaking minor updates. It has no operator-facing change.
Source ↗This release has no operator-facing change. Its dependency constraints narrow the React Aria version range to avoid breaking updates from minor releases.
Source ↗This release updates the React Aria dependency version constraint to prevent breaking changes from entering through minor updates. It carries no operator-facing change.
Source ↗Argo v3.3.7 is a maintenance release with ordinary bug fixes, performance improvements, and dependency updates. It also documents a known application-reconciliation issue that remains unresolved. No security vulnerability or operator action beyond upgrading is identified.
Source ↗This release upgrades the deprecated tar v6 dependency to tar v7. The release heading carries no operator-facing change.
This release upgrades the deprecated tar dependency from v6 to v7. No security issue or operator action is identified.
This release updates the deprecated tar dependency from v6 to v7. No security issue is stated.
This release updates the deprecated tar dependency from v6 to v7. It has no recorded operator-facing changes.
Argo v3.1.14 includes an application refresh defect correction and a fast-xml-parser dependency update in the UI. No security advisories or mandatory operator actions are disclosed.
Argo v3.2.9 is a maintenance release with defect corrections and dependency updates. It also documents a known limitation, so teams should review the release notes if they rely on the affected behavior.
Source ↗A release with a breaking configuration-schema replacement, a repo startup correctness fix, and a React Aria dependency update. It changes configuration values used by existing extensions and blueprints and updates React Aria to v1.17.0 with monopackage imports.
Check if affected (1)
breakingConfiguration schema values replaced
Applies if you use existing extensions and blueprints.
This release contains no operator-facing change details. No specific flags, fields, resources, or other release behavior are described.
Source ↗This release note contains only section headings and no operator-facing change details. No specific changes are described for flagd/v0.15.4.
Source ↗Core v0.15.3 combines new feature work with bug fixes. Its changes include metadata support in kubernetes_sync and support for a single entry in the fractional operator.
This release contains no described operator-facing changes. No release note details indicate a change that would affect operator use of flagd.
Source ↗A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the . URL, and includes broad correctness and dependency updates.
Action needed (4)
securityhighThe
globandrollupdependencies, upgradedThe
globdependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.rollupwas upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.securityThe
globdependency, upgraded to v13The
globdependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.securityThe
rollupdependency, upgraded to v4.59+rollupwas upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.securityThe
.URLwell-known/oauth-protected-resource The
.resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.well-known/oauth-protected-resource
Check if affected (22)
breakingThe
auth.settingomitIdentityTokenOwnershipClaim Applies if you do not configure
auth..omitIdentityTokenOwnershipClaim breakingThe
SignInResolverFactoryOptionstype parametersApplies if you use
SignInResolverFactoryOptions.breakingThe catalog permission exports, removed
Applies if you use
CatalogPermissionRuleInput,CatalogPermissionExtensionPoint, orcatalogPermissionExtensionPoint.- + 19 more on the release page
Plan ahead (6)
deprecatedThe
showandshowModalcompatibility implementation, deprecatedApplies if you use
showorshowModal.deprecatedThe
auth.setting, deprecatedremoval date not announcedomitIdentityTokenOwnershipClaim Applies if you configure
auth..omitIdentityTokenOwnershipClaim deprecatedThe
config.callback format, deprecatedschema Applies if you use
config..schema - + 3 more on the release page
This release contains two security updates whose affected vulnerabilities are not identified. It also adds experimental incremental updates for gRPC synchronization.
Action needed (1)
securityThe
vulnerability-updatessecurity updateOpenFeature Core v0.15.2 includes a security update for
vulnerability-updates.
This release contains security updates for flagd-proxy/v0.. The available notes do not identify the affected vulnerabilities or describe their scope.
Action needed (2)
securityThe
vulnerability-updatesentry for issue#1933The
vulnerability-updatesentry records a security update forflagd-proxy/v0., tracked in issue9. 4 #1933. The notes do not describe the affected vulnerability.securityThe
vulnerability-updatesentry for issue#1934The
vulnerability-updatesentry records a security update forflagd-proxy/v0., tracked in issue9. 4 #1934. The notes do not describe the affected vulnerability.
flagd v0.15.2 includes two undisclosed security updates and a new experimental gRPC incremental-update capability. The experimental addition concerns deployments that use gRPC synchronization.
Action needed (2)
securityThe
vulnerability-updatessecurity update for issue#1933flagd v0.15.2 includes the
vulnerability-updatessecurity update linked to issue#1933.securityThe
vulnerability-updatessecurity update for issue#1934flagd v0.15.2 includes the
vulnerability-updatessecurity update linked to issue#1934.
Release 0.15.1 fixes a memory leak caused by unbounded metrics cardinality and updates a dependency for an undisclosed security fix. The dependency update ships in the core v0.15.1 release.
Action needed (1)
securityThe
github.dependency updatecom/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 for a security fix. This change ships in core v0.15.1.com/go-jose/go-jose/v4
This release includes a security update to the github. dependency. The release note does not disclose the nature of the vulnerability.
Action needed (1)
security
github.updated to v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 in flagd-proxy v0.9.3 as a security fix. The note does not disclose the nature of the vulnerability.com/go-jose/go-jose/v4
This release fixes RPC flag defaulting, metrics-server process handling, and unbounded metrics cardinality. It also updates a dependency for an undisclosed security fix, which is the main consideration for users evaluating the release.
Action needed (1)
securityThe
github.dependency, updated to v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 incom/go-jose/go-jose/v4 flagd/v0.for an undisclosed security fix.15. 1
Flux v2.8.5 is a maintenance release with bug fixes, clearer error reporting, added verification and authentication configuration, and updated toolkit components. No security advisories or explicitly described security vulnerabilities are present.
Source ↗Flux v2.8.4 includes fixes for Windows support and --source validation, along with updates to Flux dependencies. These changes concern users of the affected commands and dependency consumers.
This is a patch release for Backstage with operator-relevant correctness fixes. The recorded note tail points to fixes for OAuth 2.0 metadata URL handling, the legacy-frontend-plugin template name, and permissions on the scaffolder plugin's /. endpoint.
This release changes fractional bucketing behavior in flagd. The provided release information does not describe the operator setup affected by the change.
Source ↗