RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jul 2026Clear ×
Thanosv0.42.4ObservabilityJul 30, 2026

Thanos v0.42.4 contains no described operator-facing changes in the supplied release information. The available note is a duplicate mention.

Source
Prometheusv3.13.2ObservabilityJul 30, 2026

Prometheus v3.13.2 updates dependencies for two disclosed vulnerabilities and includes related transitive dependency upgrades. It also fixes a PromQL SIGBUS crash when the data disk is full.

Action needed (2)

  • securityhighgolang.org/x/text update for CVE-2026-56852

    golang.org/x/text updates from v0.38.0 to v0.39.0 in Prometheus v3.13.2 for CVE-2026-56852.

  • securityhighgoogle.golang.org/grpc update for GHSA-hrxh-6v49-42gf

    google.golang.org/grpc updates from v1.81.1 to v1.82.1 in Prometheus v3.13.2 for GHSA-hrxh-6v49-42gf.

Source
Thanosv0.42.3ObservabilityJul 29, 2026

This release contains a receive shutdown regression correction. Blocks are uploaded before TSDB shutdown completes, preserving upload behavior during shutdown.

Source
OpenTelemetryv0.157.0ObservabilityJul 21, 2026

This release adds configuration and feature-gate capabilities, corrects defects, changes histogram bucket values, and introduces the configstorage module. It also removes or deprecates API symbols, with no security issues or advisories identified.

Check if affected (1)

  • breakingThe BalancerName function, removed

    Applies if you use BalancerName.

Plan ahead (1)

  • deprecatedThe WithForceUnmarshaler option, deprecated

    Applies if you use WithForceUnmarshaler.

Source
OpenCostv1.121.0ObservabilityJul 20, 2026

This release combines new cost data and collection capabilities with operational updates. Endpoint access defaults change, and the release includes corrections across pricing, pagination, request handling, providers, and serialization.

Check if affected (1)

  • breakingEndpoint defaults, deactivated without an admin token

    Applies if you use endpoints without setting an admin token.

Source
Jaegerv2.20.0ObservabilityJul 20, 2026

A release with backend compatibility removals, forced migrations, new configuration and CLI capabilities, and correctness fixes across storage, extensions, and related components. It does not disclose security advisories or security-specific flaws.

Action needed (1)

  • breakingTemplate creation through esclient

    Template creation moves to esclient, and legacy mapping rendering is retired.

Check if affected (3)

  • breakingSupport for elasticsearch v6, removed

    Applies if you use elasticsearch v6.

  • breakingThe jaegermcp extension, merged into jaegerquery

    Applies if you use the jaegermcp extension.

  • breakingExpired stable feature gates, removed

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedThe legacy flag, deprecated

    Applies if you use legacy flag.

Source
Thanosv0.42.1ObservabilityJul 16, 2026

A maintenance release corrects overly small timeouts in the Receiver's Shipper component. The change is recorded in the release notes as "receive: bump timeouts".

Source
Litmus3.31.0ObservabilityJul 15, 2026

Release 3.31.0 contains a dependency update addressing vulnerabilities in graphql/server. It also includes correctness fixes across probes, GraphQL, authentication, infrastructure, and experiment handling.

Action needed (1)

  • securityDependencies in graphql/server updated

    Dependencies in graphql/server are updated to fix vulnerabilities. The update ships in Release 3.31.0.

Source
Prometheusv3.13.1ObservabilityJul 10, 2026

A maintenance release fixes a TSDB head-chunk cache defect. After head-chunk truncation, range queries no longer receive samples from the wrong chunk or spurious not-found errors.

Source
Prometheusv3.5.5ObservabilityJul 9, 2026

Prometheus v3.5.5 includes a Go 1.25.12 toolchain change and a disclosed security fix in the UI. The security fix concerns the sanitize-html dependency and CVE-2026-53606.

Action needed (1)

  • securitymediumThe sanitize-html dependency update for CVE-2026-53606

    The Prometheus UI updates sanitize-html to v2.17.5 to fix CVE-2026-53606.

Source
Thanosv0.42.0ObservabilityJul 8, 2026

A release with security corrections, breaking configuration removals, and an output-field rename that may require operator or log-collector changes. It also adds TLS and cache configuration, query and tracing changes, and defect fixes across several Thanos components.

Action needed (1)

  • securitycriticalthanos-community/grpc-go fork update for CVE-2026-33186

    The thanos-community/grpc-go fork is bumped to fix CVE-2026-33186, an authorization bypass via malformed :path headers.

Check if affected (4)

  • securityReceive tenant ID validation

    Applies if you run Receive.

  • breakingQuery-Frontend time_taken field renamed to time_taken_ms

    Applies if you run Query-Frontend.

  • breaking--shipper.ignore-unequal-block-size flag removed

    Applies if you configure --shipper.ignore-unequal-block-size.

  • + 1 more on the release page
Source
OpenTelemetryv0.156.0ObservabilityJul 7, 2026

OpenTelemetry v0.156.0 adds mdatagen and memory-limiter capabilities, changes generated configuration APIs, and corrects runtime and API defects. No security advisories or security-specific fixes are disclosed.

Source
Prometheusv3.13.0ObservabilityJul 1, 2026

A long-term support release with security-related dependency updates, PromQL changes, new APIs and configuration controls, and bug fixes. It also replaces a shipped license artifact and includes performance improvements.

Action needed (2)

  • securitycriticalThe sanitize-html dependency update

    The UI updates sanitize-html to address a cross-site scripting vulnerability, identified as CVE-2026-44990.

  • breakingThe third-party license artifact

    Third-party npm dependency licenses are embedded in the Prometheus binary and served at /assets/third-party-licenses.txt. This replaces the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images.

Check if affected (2)

  • securitymediumRedirect credential forwarding

    Applies if you use scraping, remote read/write, alerting, or service discovery.

  • breakingPromQL duration-expression function names

    Applies if you enable experimental-duration-expr and use min() and max().

Source
Browse by month