RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Feb 2026Clear ×
Daprv1.17.0Orchestration & ManagementFeb 27, 2026

A broad feature release adds workflow, component, API, authentication, tracing, configuration, CLI, and observability capabilities, alongside defect fixes and dependency updates. It also deprecates the alpha Bulk PubSub APIs and alpha application callback and includes security fixes.

Action needed (9)

  • securityGo cryptography dependency updates

    The x/(net/sync/crypto) dependencies are bumped, and dvsekhvalnov/jose2go is pinned.

  • securityGo vulnerability fix

    A vulnerability in Go is fixed.

  • securityRoot-only UID check

    The UID check now checks only the root UID.

  • securityHTTP path matching and invocation auto-registration

    HTTP path matching is fixed to address a cardinality leak, and invocation auto-registration is supported.

  • securityThe golang.org/x/crypto dependency, updated

    The golang.org/x/crypto dependency is bumped.

  • securityThe github.com/docker/docker dependency, updated

    The github.com/docker/docker dependency is bumped.

  • securitySecurity fixes

    Security fixes ship in the release.

  • securityThe github.com/coreos/go-oidc/v3 dependency, updated

    The github.com/coreos/go-oidc/v3 dependency is bumped.

  • securityNATS vulnerability fix

    A vulnerability in NATS is fixed.

Check if affected (3)

  • securityPlacement authorization for Dapr actor types

    Applies if you use Placement.

  • securityCloudflare worker vulnerability fix

    Applies if you use the Cloudflare worker.

  • breakingScheduler resources removed from the Helm chart

    Applies if you use the Helm chart.

Plan ahead (2)

  • deprecatedAlpha Bulk PubSub APIs and app callback deprecation

    Applies if you use /v1.0-alpha1/publish/bulk/<pubsub-name>/<topic>, BulkPublishEventAlpha1, or OnBulkTopicEventAlpha1.

  • deprecatedThe OnBulkTopicEventAlpha1 callback, deprecated

    Applies if you use OnBulkTopicEventAlpha1.

Source
Crossplanev2.2.0Orchestration & ManagementFeb 17, 2026

A release with breaking changes to package installation and package-cache side-loading, alongside new operator capabilities and ordinary defect corrections. It also includes security-tagged dependency updates, but no advisory identifiers or vulnerability details are provided.

Action needed (7)

  • securitySecurity update for golang.org/x/crypto

    The golang.org/x/crypto module was updated to v0.45.0 as a security update.

  • securitySecurity update for github.com/go-chi/chi/v5

    The github.com/go-chi/chi/v5 module was updated to v5.2.4 as a security update.

  • securitySecurity update for github.com/sigstore/cosign/v3

    The github.com/sigstore/cosign/v3 module was updated to v3.0.4 as a security update.

  • securitySecurity update for github.com/theupdateframework/go-tuf/v2

    The github.com/theupdateframework/go-tuf/v2 module was updated to v2.4.1 as a security update.

  • securitySecurity update for github.com/sigstore/rekor

    The github.com/sigstore/rekor module was updated to v1.5.0 as a security update.

  • securitySecurity update for github.com/sigstore/sigstore

    The github.com/sigstore/sigstore module was updated to v1.10.4 as a security update.

  • securitySecurity update for github.com/quic-go/quic-go

    The github.com/quic-go/quic-go module was updated to v0.57.0 as a security update.

Check if affected (2)

  • breakingInput CRD installation from Function packages

    Applies if you use Function packages and Input CRDs.

  • breakingPackage cache structure

    Applicability is not stated in the release notes.

Source
Daprv1.16.9Orchestration & ManagementFeb 12, 2026

This release includes a Go toolchain dependency upgrade and a corrected Pulsar PubSub subscription-metadata defect. A regression test verifies that metadata is applied to consumer options.

Action needed (1)

  • securityhighThe Go toolchain upgrade to 1.24.13

    Dapr v1.16.9 upgrades Go to 1.24.13. The upgrade addresses advisories GO-2026-4340 and GO-2026-4341.

Source
Crossplanev2.1.4Orchestration & ManagementFeb 3, 2026

Crossplane v2.1.4 is a maintenance release with security-related dependency updates. It also includes corrections for shared transitive dependency upgrades, so the release concerns operators tracking dependency and security fixes.

Action needed (4)

  • securityThe github.com/quic-go/quic-go module, updated to v0.57.0

    The release updates the github.com/quic-go/quic-go module to v0.57.0 as a security-related dependency change.

  • securitysigstore dependency updates for CVEs

    The release updates sigstore dependencies to fix CVEs.

  • securityThe github.com/theupdateframework/go-tuf/v2 module, updated to v2.4.1

    The release updates the github.com/theupdateframework/go-tuf/v2 module to v2.4.1 as a security-related dependency change.

  • securityThe github.com/go-chi/chi/v5 module, updated to v5.2.4

    The release updates the github.com/go-chi/chi/v5 module to v5.2.4 as a security-related dependency change.

Source
Crossplanev2.0.7Orchestration & ManagementFeb 3, 2026

This release updates a security-related dependency and corrects shared transitive dependency upgrades. It also fixes propagation of composite identity through nested XR trees.

Action needed (1)

  • securityThe github.com/theupdateframework/go-tuf/v2 dependency, updated to v2.4.1

    The github.com/theupdateframework/go-tuf/v2 module is updated to v2.4.1 in the release-2.0 branch.

Source
Crossplanev1.20.5Orchestration & ManagementFeb 3, 2026

Crossplane v1.20.5 is a maintenance release focused on dependency updates. It includes a security-related update to sigstore dependencies and addresses a defect in shared transitive dependency upgrades.

Action needed (1)

  • securityThe sigstore dependencies, updated for CVE fixes

    The release-1.20 branch updates sigstore dependencies to fix CVEs.

Source
Browse by month