OpenCost v1.121.1 adds opt-in Athena query-result reuse configuration and NAT gateway cost metrics to OpenCost scrapes, and updates the Kubernetes dependency to k8s. 0.36.3. Athena result reuse applies only to query engine v3, has no effect on v2 workgroups, and AWS limits MaxAgeInMinutes to 10080 minutes. No security advisories or security fixes are disclosed.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This release combines new cost data and collection capabilities with operational updates. Endpoint access defaults change, and the release includes corrections across pricing, pagination, request handling, providers, and serialization.
Check if affected (1)
breakingEndpoint defaults, deactivated without an admin token
Applies if you use endpoints without setting an admin token.
Endpoints are deactivated by default unless an admin token is set. This change ships in OpenCost v1.121.0.
OpenCost v1.120.4 is a maintenance release with operator-facing fixes and updates to configuration, tooling, provider integrations, and runtime behavior. No security advisories or explicit security vulnerabilities are disclosed.
Source ↗A maintenance release with dependency updates, correctness fixes, and new cloud and query capabilities. Configuration and output behavior also change, along with a Go dependency upgrade for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.
Action needed (1)
securityhighGo dependency upgrades for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986
Go dependencies are upgraded for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.
Check if affected (1)
breakingThe
MCP_SERVER_ENABLEDdefault isfalseApplies if you do not configure
MCP_SERVER_ENABLED.The MCP server is now opt-in, with
MCP_SERVER_ENABLEDdefaulting tofalse.
A maintenance release with dependency updates, operator-visible configuration and behavior changes, new integrations and capabilities, and correctness fixes. It also includes an explicitly disclosed security-related Go dependency upgrade.
Action needed (1)
securityhighGo dependency upgrades for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986
Go dependencies were upgraded to address GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.
Check if affected (2)
breakingThe
provider configsource, changedApplies if you configure
provider config.The configuration behavior reads from
cloud-integration.instead of usingjson provider config.breakingThe
MCP_SERVER_ENABLEDdefault, changed tofalseApplies if you use the MCP server.
The
MCP_SERVER_ENABLEDsetting now defaults tofalse, making the MCP server opt-in by default.
A maintenance release with a dependency update, correctness fixes, and new operator-facing capabilities. The MCP server now requires explicit opt-in when MCP_SERVER_ENABLED is not configured.
Check if affected (1)
breakingThe
MCP_SERVER_ENABLEDdefault, changed tofalseApplies if
MCP_SERVER_ENABLEDis not configured.The MCP server now defaults
MCP_SERVER_ENABLEDtofalse, making it opt-in by default.
A maintenance release with dependency updates, defect corrections, expanded compatibility, and new integrations and configuration capabilities. An existing configuration source is replaced, so affected operators need to update their configuration.
Action needed (1)
breakingProvider configuration replaced by
cloud-integration.json The provider config is no longer used, and configuration is read from
cloud-integration.instead. Operators using the replaced configuration source need to update their configuration.json
OpenCost v1.119.2 contains operator-facing fixes, configuration and cloud-integration changes, logging updates, and third-party dependency upgrades. No security advisories or explicit vulnerability disclosures are present.
Source ↗OpenCost v1.119.1 contains a panic fix and changes to custom-cost configuration behavior. The release also includes internal notes whose details are not described here, with no security advisories identified.
Source ↗