RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jun 2026Clear ×
wasmCloudv2.5.0Orchestration & ManagementJun 30, 2026

Version v2.5.0 adds runtime and WIT/API capabilities and includes correctness and dependency updates. The release also enables wasip3 by default and includes a quinn-proto fix for RUSTSEC-2026-0185.

Action needed (1)

  • securityhighThe quinn-proto security fix

    The quinn-proto dependency fix ships in wasmCloud v2.5.0 and addresses RUSTSEC-2026-0185.

Check if affected (1)

  • breakingDefault wasip3 enablement with wasmtime 46

    Applies if your workloads use wasip3.

Source
Karmadav1.18.1Orchestration & ManagementJun 30, 2026

This release updates the Alpine base image and fixes a Helm chart TLS certificate issue. The Helm fix applies to deployments that use a custom namespace, while the base image change addresses security concerns.

Action needed (1)

  • securityThe alpine base image, upgraded

    The alpine base image is promoted from alpine:3.23.4 to alpine:3.24.1 to address security concerns.

Source
Karmadav1.17.4Orchestration & ManagementJun 30, 2026

Karmada v1.17.4 updates its Alpine base image to address security concerns. The release also fixes a Helm chart TLS certificate SAN mismatch when deploying to a custom namespace.

Action needed (1)

  • securityThe alpine base image, updated to alpine:3.24.1

    The alpine base image is updated from alpine:3.23.4 to alpine:3.24.1 to address security concerns. The update ships in Karmada v1.17.4.

Source
Karmadav1.16.7Orchestration & ManagementJun 30, 2026

Karmada v1.16.7 updates its Alpine base image for security concerns and includes a Helm chart fix for TLS certificate SANs in custom namespaces. The release affects deployments that use the updated image or the affected Helm chart configuration.

Action needed (1)

  • securityThe alpine base image, updated

    The base image alpine is promoted from alpine:3.23.4 to alpine:3.24.1 to address security concerns.

Source
Crossplanev2.3.3Orchestration & ManagementJun 22, 2026

Crossplane v2.3.3 is a maintenance release with security fixes delivered through dependency and toolchain updates. It also corrects namespace handling for injected resource references in crossplane render, so rendered output matches reconciler behavior for cluster-scoped XRs.

Action needed (2)

  • securityPackage signature verification TOCTOU fix, GHSA-mf7q-r4rv-jv94

    The package signature verification TOCTOU flaw identified by GHSA-mf7q-r4rv-jv94 is fixed through the crossplane-runtime v2.3.3 dependency bump. The affected code moved from crossplane to crossplane-runtime during the v2.3 milestone, so this fix ships through that dependency in Crossplane v2.3.3.

  • securityGo 1.25.11, golang.org/x/net, and golang.org/x/sys updates

    The release-2.3 branch bumps Go to 1.25.11 and updates golang.org/x/net and golang.org/x/sys for CVE-related security fixes.

Source
Crossplanev2.2.3Orchestration & ManagementJun 22, 2026

This release includes a security fix for package signature verification and updates to dependencies. It concerns deployments affected by the disclosed package-signature-verification flaw or by the updated dependency versions.

Action needed (1)

  • securitycriticalPackage signature verification TOCTOU fix, GHSA-wfqx-gjrf-g28r

    Crossplane v2.2.3 fixes the package signature verification TOCTOU issue identified by GHSA-wfqx-gjrf-g28r.

Source
Crossplanev2.1.7Orchestration & ManagementJun 22, 2026

Crossplane v2.1.7 is a maintenance release with dependency and Go toolchain updates. The changes affect the software components shipped with this release.

Action needed (3)

  • securityThe github.com/quic-go/quic-go module update

    The github.com/quic-go/quic-go module is updated to v0.59.1 in Crossplane v2.1.7.

  • securityThe golang.org/x/net module update

    The golang.org/x/net module is updated to v0.55.0 in Crossplane v2.1.7.

  • securityThe Go toolchain at 1.25.11

    The Go toolchain is bumped to 1.25.11 in Crossplane v2.1.7.

Source
Crossplanev1.20.10Orchestration & ManagementJun 22, 2026

A dependency maintenance release with security updates to the Go toolchain and MongoDB driver, alongside routine dependency bumps. Cosign and Docker remediation items were not applied and remain limitations.

Action needed (2)

  • securityhighThe Go toolchain, updated to 1.25.11

    The Go toolchain is updated to 1.25.11, the latest Go 1.25 security patch. The change addresses CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507.

  • securityThe go.mongodb.org/mongo-driver module, updated to v1.17.7

    The go.mongodb.org/mongo-driver module is updated to v1.17.7 with a security update.

Source
wasmCloudv2.4.0Orchestration & ManagementJun 17, 2026

wasmCloud v2.4.0 adds operator capabilities and configuration options while correcting runtime and tooling behavior. It also changes supported platform behavior and updates dependencies associated with Rust security advisories, so platform-specific users and deployments using the affected crates are most directly concerned.

Action needed (1)

  • securityThe postgres crates, updated for Rust security advisories

    The postgres crates are updated for RUSTSEC-2026-0178, RUSTSEC-2026-1079, and RUSTSEC-2026-0180. This dependency update ships in wasmCloud v2.4.0.

Check if affected (1)

  • breakingwebgpu disabled for s390

    Applicability is not stated in the release notes.

Source
KubeVirtv1.8.4Orchestration & ManagementJun 16, 2026

KubeVirt v1.8.4 adds observability coverage, changes node-labeller CPU feature handling, and fixes a virt-handler resource leak. It also updates a dependency to address CVE-2026-35469 and GHSA-pc3f-x583-g7j2.

Action needed (1)

  • securityhighThe github.com/moby/spdystream dependency, upgraded for CVE-2026-35469

    github.com/moby/spdystream is upgraded from v0.5.0 to v0.5.1 in KubeVirt v1.8.4 to address CVE-2026-35469 and GHSA-pc3f-x583-g7j2.

Source
Daprv1.18.0Orchestration & ManagementJun 10, 2026

A substantial operator-facing release adds workflow and MCP capabilities alongside control-plane, API, component, and lifecycle changes. It also includes security fixes, dependency and default updates, and compatibility constraints that affect upgrade planning and configuration review.

Action needed (8)

  • securitymediumThe golang.org/x/image dependency update for GO-2026-4962

    golang.org/x/image is updated to v0.39.0 for GO-2026-4962.

  • securityThe durabletask-go and pgx dependency updates

    durabletask-go is updated to v0.12.1, and pgx is updated as part of the vulnerability fixes.

  • breakingThe WorkflowsRemoteActivityReminder default, enabled

    WorkflowsRemoteActivityReminder is enabled by default. Cross-app workflow activity results are delivered through Scheduler reminders unless the setting is changed.

  • breakingThe HotReload default, enabled

    HotReload is enabled by default for Components, Subscriptions, MCPServers, Configurations, HTTPEndpoints, Resiliencies, and WorkflowAccessPolicies.

  • breakingSidecar probe defaults

    Sidecar probe defaults now give liveness more time before a kubelet restart, at about 230 seconds, while readiness responds more quickly.

  • breakingThe HotReload default, enabled in v1.18

    HotReload is enabled by default in v1.18.

  • breakingLiveness and readiness probe defaults

    The default liveness probe is widened, and the readiness probe default is tightened.

  • breakingChanged sidecar probe defaults

    Sidecar probe defaults now set liveness to be more lenient, at about 230 seconds before a kubelet restart, and readiness to be tighter, at about 3 seconds for the control plane and 5 seconds for daprd.

Check if affected (6)

  • securityService invocation path traversal ACL bypass fix

    Applies if you use service invocation.

  • breakingThe MCPServerResource and WorkflowAccessPolicy feature gates, removed

    Applies if you configure the MCPServerResource or WorkflowAccessPolicy feature gates.

  • breakingThe Sentry Ed25519 workload identity key rollback constraint

    Applicability is not stated in the release notes.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe ScheduleJobAlpha1 alpha RPCs, deprecated

    Applies if you use ScheduleJobAlpha1.

Source
Crossplanev1.20.9Orchestration & ManagementJun 5, 2026

This Crossplane release combines dependency maintenance with a new CLI check for upgrade readiness. The check scans a live v1.x control plane for features removed or changed in Crossplane v2 and reports what would break before an upgrade.

Action needed (1)

  • securityThe golang.org/x/net module, updated to v0.55.0

    The golang.org/x/net module is updated to v0.55.0 in Crossplane v1.20.9. The release note marks this dependency update as security-related, but does not identify a specific vulnerability.

Source
KubeVirtv1.8.3Orchestration & ManagementJun 3, 2026

A maintenance release with a fix for symlink traversal, a gRPC dependency update addressing GHSA-p77j-4mvh-x3m3, and deprecated recording rules. It also contains correctness fixes across VM status reporting, device resource handling, live migration, alerts, and VM operations.

Action needed (2)

  • securitycriticalgoogle.golang.org/grpc update to 1.79.3

    The google.golang.org/grpc dependency is bumped to 1.79.3 to remediate GHSA-p77j-4mvh-x3m3.

  • securitySymlink traversal fix in the VMExport directory handler

    The VMExport directory handler is fixed to prevent symlink traversal.

Plan ahead (1)

  • deprecatedDeprecated kubevirt_vm_created_total and kubevirt_vm_created_by_pod_total recording rules

    Applies if you use kubevirt_vm_created_total or kubevirt_vm_created_by_pod_total.

Source
KubeVirtv1.7.4Orchestration & ManagementJun 3, 2026

KubeVirt v1.7.4 includes correctness fixes and behavior changes affecting PCI topology and IPv6 migration. It also updates the gRPC dependency to address CVE-2026-33186.

Action needed (1)

  • securitycriticalThe google.golang.org/grpc dependency update for CVE-2026-33186

    KubeVirt v1.7.4 updates google.golang.org/grpc to version 1.79.3 to remediate CVE-2026-33186.

Source
KubeVirtv1.6.6Orchestration & ManagementJun 3, 2026

KubeVirt v1.6.6 includes a dependency update for CVE-2026-33186. The recorded change affects the gRPC dependency shipped with this release.

Action needed (1)

  • securitycriticalgoogle.golang.org/grpc update for CVE-2026-33186

    KubeVirt v1.6.6 bumps google.golang.org/grpc to remediate CVE-2026-33186.

Source
wasmCloudv2.3.0Orchestration & ManagementJun 3, 2026

Version v2.3.0 adds workload configuration and telemetry capabilities while correcting wash and runtime defects. It also changes RBAC scope support and updates dependencies, including security patches and reported advisory fixes.

Action needed (2)

  • securityThe wasmtime 44.0.2 security patch

    The release updates wasmtime to 44.0.2 as a security patch.

  • securityReported dependency security advisories

    The dependency set includes patches for reported security advisories.

Source
KEDAv2.20.0Orchestration & ManagementJun 1, 2026

This release adds scalers, configuration options, metrics, authentication modes, and compatibility improvements. Operators with custom RBAC need to account for the Kubernetes events API migration, and users of removed scaler settings need to update their configurations.

Check if affected (7)

  • securityCredential headers on cross-host redirects and HTTPS downgrades

    Applicability is not stated in the release notes.

  • breakingScaledObject name length validation

    Applies when a ScaledObject name exceeds 63 characters.

  • breakingPositive unprocessedEventThreshold values

    Applies if you configure a non-positive unprocessedEventThreshold.

  • + 4 more on the release page

Plan ahead (1)

  • deprecatedThe buildId, selectAllActive, and selectUnversioned settings, deprecated

    Applies if you configure buildId, selectAllActive, or selectUnversioned.

Source
Volcanov1.15.0Orchestration & ManagementJun 1, 2026

A feature and operational-hardening release that adds alpha scheduling capabilities, new scheduler and Helm configuration, and fixes scheduler and integration stability issues. Operators should review Kubernetes and DRA compatibility requirements, the changed DRA default, and the disclosed denial-of-service and Prometheus security fixes.

Action needed (4)

  • securitymediumPrometheus dependency update for GHSA-vffh-x6r8-xx99

    Updates github.com/prometheus/prometheus to address stored XSS advisory GHSA-vffh-x6r8-xx99.

  • securitymediumAdmission webhook request body limits

    The admission webhook now limits request bodies, fixing the denial-of-service risk identified by CVE-2026-44247 and GHSA-8wxp-xxp2-rcgx.

  • breakingDRA scheduling integration default

    DRA scheduling integration is enabled by default.

  • breakingDRA scheduling integration default behavior

    DRA scheduling integration is enabled by default to align with Kubernetes 1.34 and later behavior. Set predicate.DynamicResourceAllocationEnable to false to disable it.

Check if affected (2)

  • breakingOpt-in SchedulingGatesQueueAdmission

    Applies if you enable SchedulingGatesQueueAdmission.

  • breakingOpt-in gang-aware preemption and reclamation

    Applies if you configure gangPreempt and gangReclaim and do not configure preempt or reclaim.

Source
Browse by month