RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

OpenFeatureflagd/v0.15.5CI/CD & App DeliveryApr 30, 2026

flagd/v0.15.5 is a maintenance release with operator-facing corrections and a value update. No security advisories or explicit security issues are identified.

Source
Argov3.3.9CI/CD & App DeliveryApr 30, 2026

v3.3.9 is a maintenance release with a disclosed security fix and a go version update to resolve CVEs. It also includes bug fixes in the release.

Action needed (2)

  • securitycriticalGHSA-3v3m-wc6v-x4x3 security fix

    This release fixes the vulnerability identified by GHSA-3v3m-wc6v-x4x3.

  • securityThe go version update for CVE resolution

    The go version is bumped to resolve CVEs in v3.3.9.

Source
Argov3.2.11CI/CD & App DeliveryApr 30, 2026

Version v3.2.11 includes a disclosed security fix and additional correctness and dependency updates. The security fix is the release change that concerns users evaluating whether to upgrade.

Action needed (1)

  • securitycriticalSecurity fix for GHSA-3v3m-wc6v-x4x3

    Version v3.2.11 contains a security fix for the vulnerability identified by GHSA-3v3m-wc6v-x4x3.

Source
Backstagev1.50.4CI/CD & App DeliveryApr 29, 2026

A security maintenance release with fixes affecting three Backstage catalog packages. The affected packages are @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, and @backstage/plugin-catalog-unprocessed-entities.

Check if affected (1)

  • securitySecurity fixes for Backstage catalog packages

    Applies if you use any of @backstage/plugin-catalog-backend-module-unprocessed, @backstage/plugin-catalog-unprocessed-entities-common version, or @backstage/plugin-catalog-unprocessed-entities.

Source
Microcks1.14.0CI/CD & App DeliveryApr 29, 2026

Microcks 1.14.0 adds asynchronous request and tracing support, corrects operation-method handling, and updates shipped dependencies. The release concerns deployments or integrations that use these capabilities or depend on the updated platform components.

Source
Buildpacksv0.40.3CI/CD & App DeliveryApr 22, 2026

This release contains a change to the lifecycle version used by builders created with the pack CLI. The recorded change is not included in the item list because no change entry was provided.

Source
Backstagev1.50.3CI/CD & App DeliveryApr 22, 2026

This is a maintenance release for Backstage with ordinary correctness fixes. It addresses home page widget interactions, facets endpoint performance under filters or permissions, and external links under a non-root base path.

Source
Argov3.3.8CI/CD & App DeliveryApr 21, 2026

Argo v3.3.8 is a patch release focused on operator-relevant bug fixes, including a changed default for the ApplicationSet resource status count. No security advisories or security-specific fixes are disclosed.

Source
Argov3.2.10CI/CD & App DeliveryApr 21, 2026

Argo CD v3.2.10 contains operator-relevant bug fixes. The remaining release-note content does not describe a distinct operator-facing change.

Source
Argov3.1.15CI/CD & App DeliveryApr 21, 2026

Argo v3.1.15 is a focused bug-fix release for operator behavior. The listed fixes affect refresh behavior and application-controller synchronization, while the other release material covers installation, documentation, headings, or release metadata.

Source
Fluxv2.8.6CI/CD & App DeliveryApr 21, 2026

This is an operator-focused maintenance release with fixes and configuration constraints across controllers. It also adds a feature gate and updates dependency and toolkit components.

Check if affected (1)

  • breakingRequired audience field on the GCR Receiver secret

    Applies if you configure the audience field on the GCR Receiver secret.

Source
Backstagev1.50.2CI/CD & App DeliveryApr 18, 2026

This release combines a new TechDocs sidebar styling capability with dependency updates and constraints. It also corrects an active tab indicator issue in Backstage UI.

Action needed (1)

  • breakingReact Aria dependency ranges constrained to patch-only updates

    React Aria dependency ranges are limited to patch-only updates in Backstage v1.50.2.

Source
Backstagev1.49.5CI/CD & App DeliveryApr 17, 2026

This release narrows the allowed React Aria dependency range to prevent unintended breaking updates. The version heading itself carries no operator-facing change.

Source
Backstagev1.47.4CI/CD & App DeliveryApr 17, 2026

This release changes the dependency range for React Aria dependencies to prevent unintended breaking changes from minor-version updates. The release version is not stated as increasing.

Source
Backstagev1.46.7CI/CD & App DeliveryApr 17, 2026

This release has no operator-facing change. Its dependency constraints narrow the React Aria version range to avoid breaking updates from minor releases.

Source
Backstagev1.45.6CI/CD & App DeliveryApr 17, 2026

This release updates the React Aria dependency version constraint to prevent breaking changes from entering through minor updates. It carries no operator-facing change.

Source
Argov3.3.7CI/CD & App DeliveryApr 16, 2026

Argo v3.3.7 is a maintenance release with ordinary bug fixes, performance improvements, and dependency updates. It also documents a known application-reconciliation issue that remains unresolved. No security vulnerability or operator action beyond upgrading is identified.

Source
Argov3.1.14CI/CD & App DeliveryApr 16, 2026

Argo v3.1.14 includes an application refresh defect correction and a fast-xml-parser dependency update in the UI. No security advisories or mandatory operator actions are disclosed.

Source
Argov3.2.9CI/CD & App DeliveryApr 16, 2026

Argo v3.2.9 is a maintenance release with defect corrections and dependency updates. It also documents a known limitation, so teams should review the release notes if they rely on the affected behavior.

Source
Backstagev1.50.1CI/CD & App DeliveryApr 15, 2026

A release with a breaking configuration-schema replacement, a repo startup correctness fix, and a React Aria dependency update. It changes configuration values used by existing extensions and blueprints and updates React Aria to v1.17.0 with monopackage imports.

Check if affected (1)

  • breakingConfiguration schema values replaced

    Applies if you use existing extensions and blueprints.

Source
OpenFeaturecore/v0.15.4CI/CD & App DeliveryApr 15, 2026

This release contains no operator-facing change details. No specific flags, fields, resources, or other release behavior are described.

Source
OpenFeatureflagd/v0.15.4CI/CD & App DeliveryApr 15, 2026

This release note contains only section headings and no operator-facing change details. No specific changes are described for flagd/v0.15.4.

Source
OpenFeaturecore/v0.15.3CI/CD & App DeliveryApr 14, 2026

Core v0.15.3 combines new feature work with bug fixes. Its changes include metadata support in kubernetes_sync and support for a single entry in the fractional operator.

Source
OpenFeatureflagd/v0.15.3CI/CD & App DeliveryApr 14, 2026

This release contains no described operator-facing changes. No release note details indicate a change that would affect operator use of flagd.

Source
Backstagev1.50.0CI/CD & App DeliveryApr 14, 2026

A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the .well-known/oauth-protected-resource URL, and includes broad correctness and dependency updates.

Action needed (4)

  • securityhighThe glob and rollup dependencies, upgraded

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions. rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe glob dependency, upgraded to v13

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.

  • securityThe rollup dependency, upgraded to v4.59+

    rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe .well-known/oauth-protected-resource URL

    The .well-known/oauth-protected-resource resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.

Check if affected (22)

  • breakingThe auth.omitIdentityTokenOwnershipClaim setting

    Applies if you do not configure auth.omitIdentityTokenOwnershipClaim.

  • breakingThe SignInResolverFactoryOptions type parameters

    Applies if you use SignInResolverFactoryOptions.

  • breakingThe catalog permission exports, removed

    Applies if you use CatalogPermissionRuleInput, CatalogPermissionExtensionPoint, or catalogPermissionExtensionPoint.

  • + 19 more on the release page

Plan ahead (6)

  • deprecatedThe show and showModal compatibility implementation, deprecated

    Applies if you use show or showModal.

  • deprecatedThe auth.omitIdentityTokenOwnershipClaim setting, deprecatedremoval date not announced

    Applies if you configure auth.omitIdentityTokenOwnershipClaim.

  • deprecatedThe config.schema callback format, deprecated

    Applies if you use config.schema.

  • + 3 more on the release page
Source
OpenFeaturecore/v0.15.2CI/CD & App DeliveryApr 9, 2026

This release contains two security updates whose affected vulnerabilities are not identified. It also adds experimental incremental updates for gRPC synchronization.

Action needed (1)

  • securityThe vulnerability-updates security update

    OpenFeature Core v0.15.2 includes a security update for vulnerability-updates.

Source
OpenFeatureflagd-proxy/v0.9.4CI/CD & App DeliveryApr 9, 2026

This release contains security updates for flagd-proxy/v0.9.4. The available notes do not identify the affected vulnerabilities or describe their scope.

Action needed (2)

  • securityThe vulnerability-updates entry for issue #1933

    The vulnerability-updates entry records a security update for flagd-proxy/v0.9.4, tracked in issue #1933. The notes do not describe the affected vulnerability.

  • securityThe vulnerability-updates entry for issue #1934

    The vulnerability-updates entry records a security update for flagd-proxy/v0.9.4, tracked in issue #1934. The notes do not describe the affected vulnerability.

Source
OpenFeatureflagd/v0.15.2CI/CD & App DeliveryApr 9, 2026

flagd v0.15.2 includes two undisclosed security updates and a new experimental gRPC incremental-update capability. The experimental addition concerns deployments that use gRPC synchronization.

Action needed (2)

  • securityThe vulnerability-updates security update for issue #1933

    flagd v0.15.2 includes the vulnerability-updates security update linked to issue #1933.

  • securityThe vulnerability-updates security update for issue #1934

    flagd v0.15.2 includes the vulnerability-updates security update linked to issue #1934.

Source
OpenFeaturecore/v0.15.1CI/CD & App DeliveryApr 7, 2026

Release 0.15.1 fixes a memory leak caused by unbounded metrics cardinality and updates a dependency for an undisclosed security fix. The dependency update ships in the core v0.15.1 release.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 dependency update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 for a security fix. This change ships in core v0.15.1.

Source
OpenFeatureflagd-proxy/v0.9.3CI/CD & App DeliveryApr 7, 2026

This release includes a security update to the github.com/go-jose/go-jose/v4 dependency. The release note does not disclose the nature of the vulnerability.

Action needed (1)

  • securitygithub.com/go-jose/go-jose/v4 updated to v4.1.4

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in flagd-proxy v0.9.3 as a security fix. The note does not disclose the nature of the vulnerability.

Source
OpenFeatureflagd/v0.15.1CI/CD & App DeliveryApr 7, 2026

This release fixes RPC flag defaulting, metrics-server process handling, and unbounded metrics cardinality. It also updates a dependency for an undisclosed security fix, which is the main consideration for users evaluating the release.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 dependency, updated to v4.1.4

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in flagd/v0.15.1 for an undisclosed security fix.

Source
Fluxv2.8.5CI/CD & App DeliveryApr 7, 2026

Flux v2.8.5 is a maintenance release with bug fixes, clearer error reporting, added verification and authentication configuration, and updated toolkit components. No security advisories or explicitly described security vulnerabilities are present.

Source
Fluxv2.8.4CI/CD & App DeliveryApr 7, 2026

Flux v2.8.4 includes fixes for Windows support and --source validation, along with updates to Flux dependencies. These changes concern users of the affected commands and dependency consumers.

Source
Backstagev1.49.4CI/CD & App DeliveryApr 7, 2026

This is a patch release for Backstage with operator-relevant correctness fixes. The recorded note tail points to fixes for OAuth 2.0 metadata URL handling, the legacy-frontend-plugin template name, and permissions on the scaffolder plugin's /.well-known endpoint.

Source
OpenFeaturecore/v0.15.0CI/CD & App DeliveryApr 1, 2026

This release changes fractional bucketing behavior in flagd. The provided release information does not describe the operator setup affected by the change.

Source
← NewerOlder →
Browse by month