RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jun 2026Clear ×
OpenCostv1.120.4ObservabilityJun 25, 2026

OpenCost v1.120.4 is a maintenance release with operator-facing fixes and updates to configuration, tooling, provider integrations, and runtime behavior. No security advisories or explicit security vulnerabilities are disclosed.

Source
Fluentdv1.19.3ObservabilityJun 25, 2026

A maintenance release with bug fixes, behavior changes, and two operator-visible default changes. It also updates a runtime dependency and tightens validation and payload handling; no security vulnerability or advisory is explicitly identified.

Check if affected (2)

  • breakingThe in_monitor_agent visibility default

    Applies if in_monitor_agent runs.

  • breakingThe in_debug_agent local-machine default

    Applies if in_debug_agent runs.

Source
OpenTelemetryv0.155.0ObservabilityJun 23, 2026

A release that removes stabilized feature gates, updates processor metric names, and changes service configuration APIs. It also adds schema and metadata tooling capabilities and fixes generator defects.

Check if affected (9)

  • breakingThe confightp.framedSnappy feature gate, removed

    Applies if you use confightp.framedSnappy.

  • breakingThe configoptional.AddEnabledField feature gate, removed

    Applies if you use configoptional.AddEnabledField.

  • breakingThe confmap.newExpandedValueSanitizer feature gate, removed

    Applies if you use confmap.newExpandedValueSanitizer.

  • + 6 more on the release page

Plan ahead (1)

  • deprecatedService configuration API deprecations

    Applies if you use service.Settings.CollectorConf or extensioncapabilities.ConfigWatcher.

Source
Prometheusv3.5.4ObservabilityJun 17, 2026

A security-focused release fixes a secret-exposure flaw and updates dependencies for reported advisories. Container images are also published to the GitHub Container Registry at ghcr.io.

Action needed (2)

  • securitycriticalGo and OpenTelemetry dependency updates

    Prometheus updates golang.org/x/net to v0.55.0 and OpenTelemetry to v1.43.0. The dependency updates address GO-2026-5026, GO-2026-4918, and GO-2026-4985.

  • securityPatched UI dependencies

    The Prometheus UI updates react-router-dom, vitest, vite, and postcss to patched versions that resolve reported security advisories.

Check if affected (1)

  • securityPlaintext secret exposure through /-/config

    Applies if you use the /-/config endpoint.

Source
Litmus3.30.0ObservabilityJun 17, 2026

Litmus 3.30.0 adds installation charts and an exposed metrics port, while correcting GraphQL configuration and experiment creation behavior. It also tightens an RBAC operation and updates Docker base images and Go dependencies.

Source
Chaos Meshv2.8.3ObservabilityJun 10, 2026

A security-focused maintenance release includes undisclosed container-image CVE fixes and updates image components. It also corrects NetworkChaos recovery for targets in CrashLoopBackOff by falling back to the sandbox (pause) container PID for network namespace operations.

Action needed (2)

  • securityGo toolchain and containerd upgrades

    The Go toolchain (1.25.11) and containerd (1.7.32) were upgraded in the container images.

  • securitymemStress rebuild and headless JRE for chaos-daemon

    The memStress helper was rebuilt with the modern Go toolchain (v0.3.1), and the chaos-daemon image switched to a headless JRE.

Source
OpenTelemetryv0.154.0ObservabilityJun 8, 2026

This release adds configuration options, changes how the --skip-get-modules flag handles go.mod, and extends numeric validator handling in generated config structs. It also fixes a nil-pointer panic during sending_queue::batch unmarshalling.

Source
Cortexv1.21.1ObservabilityJun 5, 2026

A maintenance release with operator-facing security fixes and configuration changes across ingestion, distribution, and status pages. It also includes fixes for request handling, authentication, configuration exposure, gossip limits, and client and runtime panics.

Check if affected (3)

  • securityStored XSS protection in Alertmanager and Store Gateway status pages

    Applies if you run Alertmanager or Store Gateway.

  • securityWrappedHistogram native histogram size limit

    Applies if you use native histograms.

  • breakingDecompressed gzip output limit for ParseProtoReader and OTLP ingestion

    Applies if you use the OTLP ingestion path.

Source
Jaegerv2.19.0ObservabilityJun 3, 2026

This release adds API and storage capabilities, updates API query naming and defaults, and includes correctness fixes. No security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingThe searchdepth default in the trace-summaries endpoint

    The default for searchdepth changed in the trace-summaries endpoint.

Source
Browse by month