A maintenance release focused primarily on dependency version updates across the project. The Linkerd proxy is updated to v2.366.0, with no security advisories or operator-enforced breaking changes described.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with routine dependency updates, a destination informer correction, and policy-controller behavior changes. It also expands Kubernetes and Gateway API support, with no disclosed security advisories or security-specific fixes.
Source ↗Linkerd edge-26.8.1 updates third-party dependencies and the Linkerd proxy component. No security advisories or operator action are identified for this release.
Source ↗Linkerd edge-26.7.2 contains no functional changes. It updates runtime, build, and development dependencies, with no security advisories disclosed or referenced.
Source ↗This release tightens Gateway API and service-port handling and corrects tracing identity construction. It also updates dependencies and shipped components, with no security advisories or explicitly described vulnerabilities.
Action needed (1)
breakingUndefined service port requests disallowed
The
destinationcomponent now disallows requests to service ports that are not defined.
Check if affected (1)
breakingGateway API checks during
HelminstallationApplies when you use
Helm.Installation with
Helmnow checks for theGateway API.
This edge release completes functionality for rate-limit-aware load balancing in Linkerd 2.20. It updates the proxy and several third-party dependencies, with no security advisories or security flaws identified.
Source ↗A release with narrower ExternalWorkloads endpoint behavior, annotation support for upcoming load-balancing features, policy and profile fixes, dependency updates, and new load-biasing functionality. This release is explicitly not recommended in favor of edge-26..
Check if affected (1)
breakingNamespace-restricted
ExternalWorkloadsendpointsApplies if you use
ExternalWorkloads.ExternalWorkloadsnow use only endpoints within their own namespace.
Linkerd edge-26.6.1 fixes an HTTP body size-limit defect and updates several dependencies and the proxy component. No security advisories or security-specific flaws are described.
Source ↗This Linkerd release contains dependency version updates. No functional or security changes are stated, and the dependency updates are applied as part of the release without operator setup changes.
Source ↗This release updates dependencies and component versions across Linkerd. It also corrects resource labels in policy-k8s outbound indexer logs.
Source ↗This Linkerd edge release updates the OpenSSL and tower-http dependencies and ships Linkerd proxy version 2.353.0. No functional changes, security advisories, or operator actions are identified.
Source ↗A release that changes the default sidecar mode and promotes native sidecars to GA. It also fixes correctness issues, adds configurable timestamp handling, addresses eleven disclosed CVEs, and updates numerous dependencies.
Action needed (2)
securityhighEleven disclosed CVEs, fixed
The release fixes eleven disclosed CVEs: CVE-2026-42501, CVE-2026-42499, CVE-2026-39836, CVE-2026-39826, CVE-2026-39825, CVE-2026-39823, CVE-2026-39820, CVE-2026-39819, CVE-2026-39817, CVE-2026-33814, and CVE-2026-33811.
breakingThe
config.default, changedlinkerd. io/proxy-enable-native-sidecar The default sidecar mode changes through
config., making native sidecars the default.linkerd. io/proxy-enable-native-sidecar
This release narrows Kubernetes support to version 1.31 or newer. It also adds multicluster gateway configuration, reduces destination-controller memory usage, corrects namespace-aware service cleanup, and updates third-party dependencies.
Check if affected (1)
breakingMinimum supported
Kubernetesversion, 1.31Applies when your cluster runs
Kubernetesolder than1..31 The minimum supported
Kubernetesversion for this release and future releases is1..31
This Linkerd edge release contains correctness fixes, proxy and proxy-init/CNI updates, and dependency version changes. No security advisories or security-specific flaws are disclosed.
Source ↗Linkerd edge-26.4.3 adds a proxy environment override annotation and updates the bundled proxy and several dependencies. No disclosed security advisories are listed for this release.
Source ↗This Linkerd edge release, edge-26., updates dependencies and components across the project. The release notes contain no explicit security advisories or security claims.
This Linkerd release includes proxy correctness fixes, operator-visible configuration changes, and added multicluster resources. It also updates dependencies and component versions, with no security advisories or explicitly described vulnerabilities.
Source ↗Linkerd edge-26.3.3 fixes a proxy restart defect and updates dependencies and shipped component versions. No security issue or operator configuration change is disclosed.
Source ↗This release narrows Linkerd Viz scraping behavior and adds the inbound_http_request_duration_seconds and inbound_grpc_request_duration_seconds metrics histograms. It also updates dependencies and ships proxy v2.342.0.
Check if affected (1)
breakingLinkerd Viz default scraping configuration
Applies if you use Linkerd Viz.
Linkerd Viz's default scraping configuration now scrapes only
RunningorPendingpods.
This release adds tap authorization support for X-Remote-Extra- headers and introduces inbound HTTP and gRPC response-duration metrics. It also corrects tap authorization and non-mTLS logging behavior, alongside proxy and dependency upgrades. No security advisory or vulnerability is disclosed.
This release focuses on dependency and component upgrades. It adds no new operator capabilities or stated security changes, and it requires no setup changes beyond upgrading.
Source ↗This release adds proxy support for the P256+SHA512 and P384+SHA512 cryptographic signature algorithms. It also updates the proxy and several build and development dependencies. No security advisory or explicitly exploitable vulnerability is disclosed.
This release adds the inbound_http_statuses_total and inbound_grpc_statuses_total metrics for inbound HTTP and gRPC traffic. It also updates multiple dependencies and the proxy component to version v2.; no security advisories or security-specific fixes are disclosed.
This release combines dependency and component version updates with a correctness fix in the policy controller's resource watches. The fix logs resources that cannot be deserialized and skips those events so the watch continues.
Source ↗Linkerd edge-26.1.1 contains dependency, toolchain, CI action, and proxy version updates. No security advisories or operator-facing functional changes are disclosed.
Source ↗