Helm v4.1.1 is a correctness-fix release. The recorded note tail points to fixes for waiting context options, failed-resource handling in kstatus, resource matching behavior, and nil elements during slice copying.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
k8gb v0.18.0 adds runtime filtering and a Prometheus metric, and corrects several GSLB and DNS behaviors. It also updates dependencies and packaging and adds support features, while CI-only security-pipeline and workflow changes are not operator-facing security fixes.
Source ↗This release contains an operator-facing bug fix for container SELinux labeling. Systemd and init containers now respect a user-specified SELinux label.
Source ↗CRI-O v1.34.5 is a maintenance release. The available release information identifies an operator-facing bug fix, but no individual change details are included here.
Source ↗This release contains no described operator-facing changes. No recorded release-note items indicate changes to configuration, interfaces, or operational behavior.
Source ↗A maintenance release with dependency and toolchain updates, several defect corrections, and a new repository timeout flag. The pkg/registry login option for passing TLS configuration in memory has been removed.
Action needed (1)
breakingThe
pkg/registryin-memory TLS configuration login option, removedThe
pkg/registrylogin option for passing TLS configuration in memory is reverted and does not ship in this release.
Helm v4.1.0 adds CLI and SDK capabilities and changes waiting and dependency behavior. It also corrects several defects and updates dependencies, with no security advisories or explicitly described vulnerabilities in the release information.
Source ↗A security-focused maintenance release addresses disclosed Go vulnerabilities and improves proxy connection-pool performance. It also adds the forward plugin's max_idle_conns parameter, which defaults to 0 for an unbounded pool.
Action needed (1)
securityhighCVE-2025-68119 fix
The release also addresses CVE-2025-68119, which affects the stated Go versions.
Check if affected (1)
securitycriticalGo security vulnerability fixes
Applicability is not stated in the release notes.
Helm v3.19.5 is a small operator-focused bug-fix release. No security changes are disclosed.
Source ↗Helm v4.0.5 is a correctness-fix release covering commands, plugins, dependency handling, watching, rollback, and SDK environment handling. The release also includes a new SDK environment exposure change.
Source ↗A maintenance release with a new regex length constraint, correctness fixes, and plugin capability and behavior changes. It does not disclose a security advisory or explicitly exploitable vulnerability.
Action needed (1)
breakingThe
coreregex length limitcoreadds a length limit for regular expressions.
This CRI-O release contains one operator-facing behavior change related to SELinux labels for systemd or init containers. No actionable change details are included here beyond that release-note summary.
Source ↗cri-o v1.34.4 is a correctness-focused maintenance release. It fixes CPU affinity behavior when CPU load balancing is disabled and respects user-specified SELinux labels for systemd or init containers. No security advisories or operator-actionable removals, default changes, or constraint changes are disclosed.
Source ↗