This release adds proxy support for the P256+SHA512 and P384+SHA512 cryptographic signature algorithms. It also updates the proxy and several build and development dependencies. No security advisory or explicitly exploitable vulnerability is disclosed.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
NATS v2.12.4 is a maintenance release focused on correctness across JetStream, configuration, storage, clustering, and consumer behavior. It also updates the Go toolchain and adds TLS certificate expiry information to the varz monitoring endpoint; no security advisories or explicitly described security flaws are included.
NATS v2.11.12 is a maintenance release with WebSocket and monitoring configuration and output additions, along with JetStream and MQTT behavior and performance improvements. It also corrects a broad range of correctness issues; no security advisories or explicitly described security vulnerabilities are identified.
Source ↗This release adds the inbound_http_statuses_total and inbound_grpc_statuses_total metrics for inbound HTTP and gRPC traffic. It also updates multiple dependencies and the proxy component to version v2.; no security advisories or security-specific fixes are disclosed.
This release adds a Helm configuration field for custom service selector labels during revision-based migrations. It also fixes correctness issues in ambient mode, remote-cluster informer recovery, NFT operations, and pod deletion.
Source ↗Strimzi 0.50.0 includes Java 21 adoption for the operators, with compatibility exceptions for several modules. It also changes connector plugin version configuration, so existing settings that use the rejected option are affected.
Check if affected (1)
breakingThe
connector.option, forbidden in connector configurationsplugin. version Applies if you use
connector.inplugin. version KafkaConnectorKafkaMirrorMaker2connector configuration.
A maintenance release with dependency and component updates plus a correctness fix in the policy controller. Resource watches now log and skip events that cannot be deserialized so the watch can continue.
Source ↗A maintenance release with fixes for networking, policy, proxy, gateway API, and endpoint handling, plus dependency, image, and OCI publishing updates. The Cilium Preflight check no longer includes Envoy Configmaps.
Action needed (1)
breakingCilium Preflight check no longer includes Envoy Configmaps
The
Cilium Preflightcheck no longer includesEnvoy Configmaps. This change ships in v1.18.6.
This release adds dynamic-module, filter, routing, observability, and certificate capabilities, along with fixes and performance improvements across HTTP, networking, and protocol handling. It also changes HTTP reset behavior, removes runtime guards and legacy code paths, and deprecates the OpenTelemetry access log common_config field.
Action needed (1)
breakingRuntime guards and legacy code paths removed
Multiple runtime guards and legacy code paths are removed in this release.
Check if affected (2)
breakingDefault HTTP reset code changed
Applicability is not stated in the release notes.
breakingDefault upstream protocol error reset handling changed
Applicability is not stated in the release notes.
Plan ahead (1)
deprecatedOpenTelemetry access log
common_configfield deprecatedApplies if you configure
common_config.
Linkerd edge-26.1.1 contains dependency, toolchain, CI action, and proxy version updates. No security advisories or operator-facing functional changes are disclosed.
Source ↗