A maintenance release focused primarily on dependency version updates across the project. The Linkerd proxy is updated to v2.366.0, with no security advisories or operator-enforced breaking changes described.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This release removes legacy CRD API versions and resource state metrics, and changes defaults for token mounting, feature gates, and container security contexts. It also adds Kafka and configuration capabilities and updates shipped dependencies.
Action needed (2)
breakingService Account token mounting
Service Account tokens are no longer auto-mounted into Pods. They are mounted through a volume instead.
breakingThe
ServerSideApplyPhase1feature gate, permanently enabledThe
ServerSideApplyPhase1feature gate has moved to GA and is permanently enabled. It can no longer be disabled.
Check if affected (3)
breakingLegacy CRD API versions, no longer supported
Applies before upgrading to Strimzi 1.0.0 or later if you use the
v1beta2,v1beta1, orv1alpha1APIs.breakingResource state metrics, removed
Applicability is not stated in the release notes.
breakingDefault
securityContextfor operator installationsApplies if you use the Cluster, Topic, and User Operator YAML installation files or the Cluster Operator Helm Chart.
A maintenance release with numerous operator-facing bug fixes and behavior corrections, alongside dependency and image updates. It also introduces a decoder-memory limit and fixes a CIDR policy bypass that could cause traffic drops after an agent restart.
Check if affected (1)
securityThe
endpointCIDR policy bypass, fixedApplicability is not stated in the release notes.
A maintenance release with bug fixes, diagnostic improvements, dependency and image updates, and improved DNS request validation. It contains no security advisories or explicitly described vulnerabilities.
Source ↗A maintenance release that adds host-firewall protocol support, corrects networking and stability defects, and changes runtime behavior and observability. It also updates dependencies and container images, including a gRPC security fix with no disclosed vulnerability.
Action needed (1)
securityThe
google.dependency, updated togolang. org/grpc v1.82. 1 The
google.module is updated togolang. org/grpc v1.in the v1.18 release line. The release note marks this dependency update as a security fix, but does not disclose the vulnerability.82. 1
A maintenance release with routine dependency updates, a destination informer correction, and policy-controller behavior changes. It also expands Kubernetes and Gateway API support, with no disclosed security advisories or security-specific fixes.
Source ↗A maintenance release with a security fix for an external authorization bypass and dependency updates for CVE fixes. It also updates the tested Kubernetes range to 1.32 through 1.34, Go to 1.25.12, and Envoy to v1.38.3.
Action needed (1)
securityDependency updates for CVE fixes
Dependencies were updated to fix CVEs. The updates ship in Contour v1.33.6.
Check if affected (1)
securityExternal authorization bypass with disabled
authPolicyApplies if
authPolicyis not configured.
NATS v2.14.5 updates the Go toolchain and two dependencies, and adds a configurable leafnode dial timeout for high-latency links. It fixes a logger deadlock and a JetStream defect involving idempotent stream creation, with no security advisories or security-specific fixes disclosed.
NATS v2.12.15 updates the Go toolchain and dependency manifests. It also fixes deadlocks in logging and a JetStream data-loss bug related to idempotent stream creation when an offline node catches up from a metalayer snapshot.
Source ↗Linkerd edge-26.8.1 updates third-party dependencies and the Linkerd proxy component. No security advisories or operator action are identified for this release.
Source ↗