This maintenance release updates the Kubernetes build toolchain to Go 1.25.7.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release updates the Kubernetes build toolchain to Go 1.24.13. The recorded change concerns how Kubernetes is built, with no operator-facing feature change described.
Source ↗A maintenance release updates the Go toolchain used to build Kubernetes to Go 1.24.13. Nothing else in the release requires operator attention.
Source ↗A maintenance release updates the Go toolchain used to build Kubernetes to Go 1.24.13. Nothing else here needs operator attention.
Source ↗v0.18.1 is a dependency update release. It includes an update to coredns-plugin for the latest security fixes, alongside other dependency version changes.
Action needed (1)
securityThe
coredns-plugindependency, updated for security fixesThe
coredns-plugindependency is updated to include the latest security fixes in v0.18.1.
A maintenance release postpones removal of one flag and reverses another flag's deprecation. It also includes dependency and toolchain updates addressing named security advisories.
Action needed (2)
securityhighThe
gotoolchain, updated to 1.24.13Binaries are compiled using
go 1.. The toolchain update addresses CVE-2025-61726, CVE-2025-61731, CVE-2025-61732, GHSA-8jvr-vh7g-f8gx, GHSA-gm9r-q53w-2gh4, and GHSA-xvqr-69v8-f3gv.24. 13 securitymediumThe
golang.dependency, updated to 0.45.0org/x/crypto golang.is updated to 0.45.0 to address CVE-2025-47914 and CVE-2025-58181.org/x/crypto
Plan ahead (1)
deprecatedThe
--max-snapshotsflag, removal postponedremoval planned in v3.8Applies if you use
--max-snapshots.
A maintenance release that changes the Go toolchain used to compile binaries. It also includes fixes for three named CVEs and their corresponding GHSA advisories.
Action needed (1)
securityhighGo 1.24.13 toolchain for compiled binaries
Binaries are compiled with Go 1.24.13. This release includes fixes for CVE-2025-61726, CVE-2025-61731, and CVE-2025-61732, with corresponding advisories GHSA-gm9r-q53w-2gh4,
GHSA-xvqr-69v8-f3gv4, and GHSA-8jvr-vh7g-f8gx.
A maintenance release updates the Go dependency and toolchain to go 1.. It addresses three CVEs and their corresponding GitHub advisories.
Action needed (1)
securityhighGo 1.24.13 dependency and toolchain update
The Go dependency and toolchain update to
go 1.addresses CVE-2025-61726, CVE-2025-61731, and CVE-2025-61732, along with GHSA-8jvr-vh7g-f8gx, GHSA-gm9r-q53w-2gh4, and GHSA-xvqr-69v8-f3gv.24. 13
A maintenance release with correctness fixes in device allocation and kubeadm behavior, plus a Go toolchain update. The changes address scheduling races, etcd learner promotion, argument ordering, and Node patch retries.
Source ↗A maintenance release corrects operator-relevant behavior across scheduling, kubeadm, logging, and Windows networking. Kubernetes is now built using Go 1.24.12, and no security advisories or security-specific fixes are disclosed.
Source ↗A maintenance release focused on correctness fixes and regression repairs across Kubernetes components. It also updates the Go toolchain and changes kubeadm retry behavior.
Source ↗A maintenance release with numerous correctness fixes and an enforced feature-gate default change. It also updates the Go toolchain and hnslib dependency, with no disclosed security advisories.
Check if affected (1)
breakingThe
SchedulerAsyncAPICallsfeature gate, disabled by defaultApplies if you use the
SchedulerAsyncAPICallsfeature gate.
Helm v4.1.1 is a correctness-fix release. The recorded note tail points to fixes for waiting context options, failed-resource handling in kstatus, resource matching behavior, and nil elements during slice copying.
Source ↗k8gb v0.18.0 adds runtime filtering and a Prometheus metric, and corrects several GSLB and DNS behaviors. It also updates dependencies and packaging and adds support features, while CI-only security-pipeline and workflow changes are not operator-facing security fixes.
Source ↗This release contains an operator-facing bug fix for container SELinux labeling. Systemd and init containers now respect a user-specified SELinux label.
Source ↗A maintenance release includes a fix for high performance hook IRQ SMP affinity handling during late container deletion. The fix prevents IRQ SMP affinity for other containers from being changed incorrectly.
Source ↗This release contains no described operator-facing changes. No recorded release-note items indicate changes to configuration, interfaces, or operational behavior.
Source ↗