RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Helmv3.21.1Kubernetes CoreJun 12, 2026

Helm v3.21.1 includes dependency and toolchain updates alongside fixes for correctness issues. The disclosed dependency update affects releases using golang.org/x/net.

Action needed (1)

  • securitycriticalThe golang.org/x/net dependency, updated for GO-2026-5026

    Helm v3.21.1 bumps golang.org/x/net to v0.55.0 to address GO-2026-5026.

Source
Kubernetesv1.36.2Kubernetes CoreJun 12, 2026

A maintenance release with Go 1.26.4 build updates and correctness and performance fixes across scheduling, kubelet volume handling, suspended Jobs, Secret data, endpoint processing, and kubeadm dry-run certificate copying. No security advisories are disclosed.

Source
Kubernetesv1.35.6Kubernetes CoreJun 12, 2026

A maintenance release with correctness and performance fixes, along with an updated Go toolchain dependency. The recorded notes do not disclose security advisories or security-specific flaws.

Source
Kubernetesv1.34.9Kubernetes CoreJun 12, 2026

A maintenance release with a Go toolchain dependency update and fixes for operator-facing defects. The fixes cover endpoint handling, CSI volume republishing, Secret-sourced binary environment values, and kubeadm certificate dry runs.

Source
Kubernetesv1.33.13Kubernetes CoreJun 12, 2026

A maintenance release updates the Go build dependency to Go 1.25.11 and fixes a panic in the endpoint controller when processing services with an empty IPFamilies field. The remaining release-note entries are section headings without operator-facing changes.

Source
CoreDNSv1.14.4Kubernetes CoreJun 9, 2026

A release with new plugin capabilities, stricter validation, DNS and cache behavior changes, expanded platform support, and malformed-input handling fixes. The HTTP/3 request header limit is narrowed for DoH3.

Check if affected (1)

  • breakingBound DoH3 HTTP/3 request header size

    Applies if you use DoH3.

Source
CRI-Ov1.35.4Kubernetes CoreJun 3, 2026

This release contains no operator-facing changes in the provided release information. There are no recorded updates to assess for CRI-O v1.35.4.

Source
CRI-Ov1.36.1Kubernetes CoreJun 3, 2026

This release contains operator-facing corrections to container status image references and to debug logging for List* RPC calls. The recorded changes address a correctness issue after CRI-O restarts and reduce log verbosity to improve performance.

Source
CRI-Ov1.33.13Kubernetes CoreJun 3, 2026

This cri-o release, v1.33.13, contains a documented operator-facing correctness fix. The fix addresses a race condition that could cause cri-o to report exit code 255 when a container exits quickly.

Source
containerdv2.1.8Kubernetes CoreJun 2, 2026

containerd v2.1.8 includes a disclosed security correction identified by CVE-2026-46680 and GHSA-fqw6-gf59-qr4w. The release also contains operator-facing runtime and snapshotter changes in its broader changelog.

Action needed (1)

  • securityhighCVE-2026-46680 security correction

    containerd v2.1.8 includes a correction for CVE-2026-46680, associated with GHSA-fqw6-gf59-qr4w.

Source
etcdv3.6.12Kubernetes CoreJun 1, 2026

A maintenance release with server and tooling fixes, an expanded maintenance-status access rule, and a Go toolchain dependency update. The documented fixes concern operators who depend on the prior maintenance restriction or the corrected server and build behavior.

Source
etcdv3.5.31Kubernetes CoreJun 1, 2026

A maintenance release with correctness fixes and dependency updates. The golang.org/x/crypto update addresses GO-2026-5026.

Action needed (1)

  • securitycriticalThe golang.org/x/crypto dependency update for GO-2026-5026

    The golang.org/x/crypto dependency is updated to v0.52.0 to address GO-2026-5026.

Source
etcdv3.4.45Kubernetes CoreJun 1, 2026

A maintenance release that ends support for the v3.4 line and updates the Go toolchain used to compile binaries. No further patches will be issued for v3.4.

Plan ahead (1)

  • deprecatedThe v3.4 line, end of support

Source
Limav2.1.2Kubernetes CoreJun 1, 2026

A feature and maintenance release with CLI and template changes, QEMU behavior updates, and fixes across drivers, hostagent, shell, and guest support. It also includes a deprecation, while no security advisories or explicitly described vulnerabilities are present.

Check if affected (1)

  • breakingQEMU 2MB OVMF images dropped by openSUSE

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedThe _LIMA_QEMU_UEFI_IN_BIOS flag, deprecated

    Applies if you configure _LIMA_QEMU_UEFI_IN_BIOS.

Source
containerdv2.2.4Kubernetes CoreMay 20, 2026

A maintenance release with security updates, including a dependency update tied to an advisory. It also includes compatibility and runtime changes across storage, policy, sandbox, validation, and toolchain areas.

Action needed (2)

Source
containerdv2.0.9Kubernetes CoreMay 20, 2026

A maintenance release with a disclosed security fix, a narrower default socket policy, expanded compatibility for volatile mount options and AppArmor, and several correctness fixes. It also includes updates to container event handling, tar extraction, OCI USER validation, sandbox field forwarding, and event topics.

Action needed (1)

Check if affected (1)

  • breakingThe default seccomp socket policy

    Applies if you use seccomp.

Source
containerdv1.7.32Kubernetes CoreMay 20, 2026

containerd v1.7.32 includes a disclosed security advisory alongside correctness and compatibility fixes. The release concerns users assessing security exposure or changes in runtime and configuration behavior.

Action needed (1)

Source
containerdv2.3.1Kubernetes CoreMay 20, 2026

A maintenance release focused on runtime correctness and security, including fixes across snapshotter, storage, and server components. It also contains compatibility changes and updates to the API and Go toolchain.

Action needed (1)

  • securityhighCVE-2026-46680 correction

    The fix for CVE-2026-46680 ships in this release.

Check if affected (1)

  • breakingThe overlayfs "rebase" capability, disabled in user namespaces

    Applies if you use overlayfs and run in a user namespace.

Plan ahead (1)

  • deprecatedTask fields in Runc options, deprecated

    Applies if you configure task fields in Runc options.

Source
containerdapi/v1.11.1Kubernetes CoreMay 20, 2026

This containerd release corrects a defect in sandbox task API endpoints for non-runc runtimes. The recorded release material identifies the fix in the highlights and overview.

Source
Helmv3.21.0Kubernetes CoreMay 14, 2026

Helm v3.21.0 is a maintenance release with dependency updates and fixes to chart and OCI handling. It also includes a security fix in the opentelemetry packages.

Action needed (1)

  • securityThe opentelemetry packages, upgraded for CVE patches

    Helm v3.21.0 upgrades the opentelemetry packages to patch CVEs.

Source
Helmv4.2.0Kubernetes CoreMay 14, 2026

A feature and maintenance release with new template and CLI capabilities, dependency updates, flag deprecations, and numerous correctness fixes. It also includes security fixes for plugin path traversal and GO-2026-4394.

Action needed (1)

  • securityhighgo.opentelemetry.io/otel/sdk update for GO-2026-4394

    Helm v4.2.0 updates go.opentelemetry.io/otel/sdk to v1.40.0 for GO-2026-4394.

Check if affected (1)

  • securityPlugin version path traversal fix

    Applies if you use the Plugin extension.

Plan ahead (1)

  • deprecatedThe --hide-notes and --render-subchart-notes flags, deprecated

    Applies if you use --hide-notes or --render-subchart-notes.

Source
Kubernetesv1.36.1Kubernetes CoreMay 12, 2026

A maintenance release focused on bug and regression corrections across Kubernetes components. The listed changes affect node startup, networking, kube-proxy, kubeadm initialization and joining, kubelet authorization, and etcd health checks.

Source
Kubernetesv1.35.5Kubernetes CoreMay 12, 2026

A maintenance release with operator-facing bug corrections in scheduling, networking, kubeadm, kube-proxy, and metric behavior. No security advisories or security-specific fixes are disclosed.

Source
Kubernetesv1.34.8Kubernetes CoreMay 12, 2026

A maintenance release with correctness fixes in networking, scheduling, kubeadm, and metrics behavior. No security advisories or operator actions are explicitly identified.

Source
CRI-Ov1.36.0Kubernetes CoreMay 5, 2026

CRI-O v1.36.0 is a substantive operator-facing feature and maintenance release with runtime and operational changes. It also includes a security update to spdystream and a broad dependency refresh.

Action needed (1)

  • securityhighThe spdystream dependency update for CVE-2026-35469

    CRI-O v1.36.0 updates the spdystream dependency to fix CVE-2026-35469.

Source
CRI-Ov1.35.3Kubernetes CoreMay 5, 2026

A maintenance release that adds a runtime metric and a GOMAXPROCS configuration field, fixes two runtime defects, and reverts CNI monitoring after node bootstrapping regressions. It also updates the spdystream dependency to address CVE-2026-35469.

Action needed (2)

  • securityhighThe spdystream dependency update for CVE-2026-35469

    The spdystream dependency is updated to address CVE-2026-35469. The update ships in this release.

  • breakingCRI-O CNI monitoring, reverted

    CRI-O reverts CNI monitoring because it caused node bootstrapping regressions. The change ships in this release.

Source
CRI-Ov1.34.8Kubernetes CoreMay 5, 2026

CRI-O v1.34.8 includes a security-relevant dependency update and adds operator-facing observability and configuration capabilities. The dependency update is the release change that requires upgrading, while the other additions concern optional setup or informational use.

Action needed (1)

  • securityhighCVE-2026-35469 fix in the spdystream dependency

    CRI-O v1.34.8 updates the spdystream dependency to fix CVE-2026-35469.

Source
CRI-Ov1.33.12Kubernetes CoreMay 5, 2026

CRI-O v1.33.12 includes a security fix for a disclosed vulnerability in the spdystream dependency. It also adds the min_injected_gomaxprocs configuration field for controlling the floor of injected GOMAXPROCS values.

Action needed (1)

  • securityhighCVE-2026-35469 fix in the spdystream dependency

    CVE-2026-35469 is fixed by updating the spdystream dependency in CRI-O v1.33.12.

Source
etcdv3.6.11Kubernetes CoreMay 1, 2026

A maintenance release with a correctness fix, an RBAC authorization bypass fix, and a security-related dependency update for GO-2026-4962. It also records Go 1.25.9 as the toolchain used to build the binaries.

Action needed (1)

  • securitymediumgolang.org/x/image update for GO-2026-4962

    The release updates golang.org/x/image to v0.39.0 to resolve GO-2026-4962.

Check if affected (1)

  • securityRBAC authorization bypass in nested Put requests

    Applies if you use RBAC.

Source
etcdv3.5.30Kubernetes CoreMay 1, 2026

A maintenance release with a security fix for an RBAC authorization bypass in transaction handling. It also includes an ordinary correctness fix and a Go toolchain dependency update.

Action needed (1)

  • securityRBAC authorization bypass in nested etcd transactions

    The release fixes an RBAC authorization bypass that allowed read access through PrevKv or lease attachment in Put requests nested in etcd transactions. The fix ships in this release.

Source
etcdv3.4.44Kubernetes CoreMay 1, 2026

A security maintenance release fixes an RBAC authorization bypass. It also updates the Go toolchain used to compile binaries to go 1.25.9.

Check if affected (1)

  • securityRBAC authorization bypass fix

    Applies if you use RBAC.

Source
containerdv2.3.0Kubernetes CoreApr 30, 2026

A substantial operator-facing release with new capabilities, behavior changes, a compatibility constraint, and a deprecation. It is the first annual LTS release under a Kubernetes-aligned cadence, with support planned for at least two years.

Action needed (1)

  • breakingPlugin names disallow commas

    OCI hook adjustments accumulate owners, and commas are disallowed in plugin names in this release.

Plan ahead (1)

  • deprecatedThe shim.Command API, deprecated

    Applies if you use shim.Command.

Source
containerdapi/v1.11.0Kubernetes CoreApr 30, 2026

This release adds and changes API and runtime capabilities, removes a sandbox metadata field, and updates a dependency. No security advisories or vulnerabilities are disclosed.

Check if affected (1)

  • breakingThe Container sandbox metadata field, removed

    Applies if you use Container in API specs.

Source
Kubernetesv1.36.0Kubernetes CoreApr 22, 2026

A broad operator-significant release with API, configuration, CLI default, scheduling, runtime, feature-gate, metric, and dependency changes. Upgrade review and testing matter for users of removed or deprecated interfaces, changed defaults, custom scheduler integrations, CRDs, audit logging, and affected metrics.

Action needed (11)

  • breakingStrictIPCIDRValidation enabled by default

    The StrictIPCIDRValidation feature gate in kube-apiserver is enabled by default.

  • breakingThe default debug profile, changed to general

    The default debug profile changes from legacy to general.

  • breakingWatchCacheInitializationPostStartHook enabled by default

    The WatchCacheInitializationPostStartHook feature gate is enabled by default.

  • breakingKubeletPSI graduation to GA

    The KubeletPSI feature graduated to GA and is enabled by default.

  • breakingRelaxedServiceNameValidation at beta, enabled by default

    The RelaxedServiceNameValidation feature gate graduated to beta and is enabled by default.

  • breakingRestartAllContainersOnContainerExits at beta, enabled by default

    The RestartAllContainersOnContainerExits feature gate graduated to beta and is enabled by default.

  • breakingSuspended-job feature gates enabled by default

    The MutablePodResourcesForSuspendedJobs and MutableSchedulingDirectivesForSuspendedJobs feature gates are enabled by default.

  • breakingAtomicFIFO informer store updates

    Default informer behavior now updates store state with all objects in a list or relist before invoking individual-item handler methods. This behavior is associated with AtomicFIFO.

  • breakingUnlockWhileProcessing informer behavior

    Informers can now enqueue new watch events while already-queued events are being processed. This behavior is associated with UnlockWhileProcessing.

  • breakingClientsAllowCARotation functionality enabled by default

    This functionality is enabled by default and can be disabled through the ClientsAllowCARotation feature gate.

  • breakingClientsAllowTLSCacheGC functionality enabled by default

    This functionality is enabled by default and can be controlled through the ClientsAllowTLSCacheGC feature gate.

Check if affected (25)

  • breakingThe volume_operation_total_errors metric, renamed

    Applies if you use volume_operation_total_errors.

  • breakingThe git-repo volume plugin, disabled

    Applies if you use the git-repo volume plugin.

  • breakingAllowlistEntry.Name, renamed to AllowlistEntry.Command

    Applies if you configure AllowlistEntry.Name.

  • + 22 more on the release page

Plan ahead (6)

  • deprecatedService .spec.externalIPs deprecation

    Applies if you configure Service .spec.externalIPs.

  • deprecatedDirect access to metav1.FieldsV1.Raw, deprecated

    Applies if you use metav1.FieldsV1.Raw.

  • deprecatedMinNodeScore and MaxNodeScore, deprecated

    Applies if you use MinNodeScore or MaxNodeScore.

  • + 3 more on the release page
Source
CoreDNSv1.14.3Kubernetes CoreApr 22, 2026

A maintenance release that adds operator-facing options and transport, plugin, and protocol support while correcting defects. It is built with Go 1.26.2, which contains fixes for disclosed CVEs; other changes concern operators using the affected features or behaviors.

Action needed (1)

Check if affected (1)

  • breakingOversized DoH GET query parameter rejection

    Applies if you use DoH.

Source
Kubernetesv1.33.11Kubernetes CoreApr 15, 2026

A maintenance release updates the Go build toolchain and dependency versions, with fixes for upgrade and runtime defects. The changes include a Kubernetes build with Go 1.25.9 and fixes for apiserver startup during upgrades and kube-proxy nftables support.

Source
Kubernetesv1.34.7Kubernetes CoreApr 15, 2026

A maintenance release that updates the Go toolchain and dependency versions in the dependency manifest. It also fixes two correctness regressions, with no security advisories or operator actions identified.

Source
Kubernetesv1.35.4Kubernetes CoreApr 15, 2026

A maintenance release with the Go 1.25.9 toolchain and several correctness fixes. It changes the default for StatefulSet parallel pod management and includes fixes for kubelet restarts, apiserver audit-log latency annotations, and kube-proxy nftables support.

Check if affected (1)

  • breakingDefault for MaxUnavailableStatefulSet

    Applies if you do not enable MaxUnavailableStatefulSet.

Source
← NewerOlder →
Browse by month