OpenCost v1.120.4 is a maintenance release with operator-facing fixes and updates to configuration, tooling, provider integrations, and runtime behavior. No security advisories or explicit security vulnerabilities are disclosed.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with bug fixes, behavior changes, and two operator-visible default changes. It also updates a runtime dependency and tightens validation and payload handling; no security vulnerability or advisory is explicitly identified.
Check if affected (2)
breakingThe
in_monitor_agentvisibility defaultApplies if
in_monitor_agentruns.breakingThe
in_debug_agentlocal-machine defaultApplies if
in_debug_agentruns.
A release that removes stabilized feature gates, updates processor metric names, and changes service configuration APIs. It also adds schema and metadata tooling capabilities and fixes generator defects.
Check if affected (9)
breakingThe
confightp.feature gate, removedframedSnappy Applies if you use
confightp..framedSnappy breakingThe
configoptional.feature gate, removedAddEnabledField Applies if you use
configoptional..AddEnabledField breakingThe
confmap.feature gate, removednewExpandedValueSanitizer Applies if you use
confmap..newExpandedValueSanitizer - + 6 more on the release page
Plan ahead (1)
deprecatedService configuration API deprecations
Applies if you use
service.orSettings. CollectorConf extensioncapabilities..ConfigWatcher
A security-focused release fixes a secret-exposure flaw and updates dependencies for reported advisories. Container images are also published to the GitHub Container Registry at ghcr..
Action needed (2)
securitycriticalGo and
OpenTelemetrydependency updatesPrometheus updates
golang.to v0.55.0 andorg/x/net OpenTelemetryto v1.43.0. The dependency updates address GO-2026-5026, GO-2026-4918, and GO-2026-4985.securityPatched UI dependencies
The Prometheus UI updates
react-router-dom,vitest,vite, andpostcssto patched versions that resolve reported security advisories.
Check if affected (1)
securityPlaintext secret exposure through
/-/configApplies if you use the
/-/configendpoint.
Litmus 3.30.0 adds installation charts and an exposed metrics port, while correcting GraphQL configuration and experiment creation behavior. It also tightens an RBAC operation and updates Docker base images and Go dependencies.
Source ↗A security-focused maintenance release includes undisclosed container-image CVE fixes and updates image components. It also corrects NetworkChaos recovery for targets in CrashLoopBackOff by falling back to the sandbox (pause) container PID for network namespace operations.
Action needed (2)
securityGo toolchain and
containerdupgradesThe Go toolchain (1.25.11) and
containerd(1.7.32) were upgraded in the container images.security
memStressrebuild and headless JRE forchaos-daemonThe
memStresshelper was rebuilt with the modern Go toolchain (v0.3.1), and thechaos-daemonimage switched to a headless JRE.
This release adds configuration options, changes how the --skip-get-modules flag handles go., and extends numeric validator handling in generated config structs. It also fixes a nil-pointer panic during sending_queue::batch unmarshalling.
A maintenance release with operator-facing security fixes and configuration changes across ingestion, distribution, and status pages. It also includes fixes for request handling, authentication, configuration exposure, gossip limits, and client and runtime panics.
Check if affected (3)
securityStored XSS protection in
Alertmanagerand Store Gateway status pagesApplies if you run
Alertmanageror Store Gateway.security
WrappedHistogramnative histogram size limitApplies if you use native histograms.
breakingDecompressed gzip output limit for
ParseProtoReaderand OTLP ingestionApplies if you use the OTLP ingestion path.
This release adds API and storage capabilities, updates API query naming and defaults, and includes correctness fixes. No security advisories or security-specific fixes are disclosed.
Action needed (1)
breakingThe
searchdepthdefault in the trace-summaries endpointThe default for
searchdepthchanged in the trace-summaries endpoint.