Karmada v1.16.3 contains operator-facing defect corrections and a base-image dependency update. No security advisories or security-specific fixes are disclosed.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
Karmada v1.15.6 is a maintenance release focused on operator-relevant bug fixes in scheduling, controller behavior, and resource quota handling. It also updates the Alpine base image from alpine:3. to alpine:3..
This is a maintenance release for Karmada with corrections across operator components and an updated Alpine base image. No security advisories or security-specific fixes are disclosed.
Source ↗A feature and maintenance release adds workload affinity and anti-affinity scheduling, operator and API capabilities, and Helm encryption at rest. It also includes controller and scheduler fixes, dependency and image updates, and deprecations and removals.
Check if affected (4)
breaking
namespacevalidation forspec.resourceSelectors Applies if you use
PropagationPolicyorOverridePolicy.breakingStricter
GroupByLabelKeyvalidation inWorkloadAffinityApplies if you configure
GroupByLabelKeyinWorkloadAffinity.breakingUpdated default Kubernetes and
ETCDimagesApplicability is not stated in the release notes.
- + 1 more on the release page
Plan ahead (3)
deprecatedThe
--cluster-lease-durationflag, deprecatedremoval date not announcedApplies if you use
--cluster-lease-duration.deprecatedThe
--cluster-lease-renew-interval-fractionflag, deprecatedremoval date not announcedApplies if you use
--cluster-lease-renew-interval-fraction.deprecated
Etcd.inLocal. InitImage Karmada Init Configuration, deprecatedremoval date not announcedApplies if you configure
Etcd.inLocal. InitImage Karmada Init Configuration.
A broad feature release adds workflow, component, API, authentication, tracing, configuration, CLI, and observability capabilities, alongside defect fixes and dependency updates. It also deprecates the alpha Bulk PubSub APIs and alpha application callback and includes security fixes.
Action needed (9)
securityGo cryptography dependency updates
The
x/(net/sync/crypto)dependencies are bumped, anddvsekhvalnov/jose2gois pinned.security
Govulnerability fixA vulnerability in
Gois fixed.securityRoot-only UID check
The UID check now checks only the root UID.
securityHTTP path matching and invocation auto-registration
HTTP path matching is fixed to address a cardinality leak, and invocation auto-registration is supported.
securityThe
golang.dependency, updatedorg/x/crypto The
golang.dependency is bumped.org/x/crypto securityThe
github.dependency, updatedcom/docker/docker The
github.dependency is bumped.com/docker/docker securitySecurity fixes
Security fixes ship in the release.
securityThe
github.dependency, updatedcom/coreos/go-oidc/v3 The
github.dependency is bumped.com/coreos/go-oidc/v3 securityNATS vulnerability fix
A vulnerability in NATS is fixed.
Check if affected (3)
security
Placementauthorization for Dapr actor typesApplies if you use
Placement.securityCloudflare worker vulnerability fix
Applies if you use the Cloudflare worker.
breakingScheduler resources removed from the Helm chart
Applies if you use the Helm chart.
Plan ahead (2)
deprecatedAlpha Bulk PubSub APIs and app callback deprecation
Applies if you use
/v1.,0-alpha1/publish/bulk/<pubsub-name>/<topic> BulkPublishEventAlpha1, orOnBulkTopicEventAlpha1.deprecatedThe
OnBulkTopicEventAlpha1callback, deprecatedApplies if you use
OnBulkTopicEventAlpha1.
This release rebuilds the prior Knative release with Go v1.25.7. No operator-facing feature or configuration change is described.
Source ↗Knative v1.21.1 announces a future change to secure pod defaults, while the v1.21 default remains unchanged. The prior release was rebuilt with v1.25.7.
Source ↗KubeVirt v1.7.1 is a maintenance release focused on correctness fixes, dependency updates, and expanded compatibility. It also adds a metric and alert for ephemeral hotplug volumes.
Source ↗A release with breaking changes to package installation and package-cache side-loading, alongside new operator capabilities and ordinary defect corrections. It also includes security-tagged dependency updates, but no advisory identifiers or vulnerability details are provided.
Action needed (7)
securitySecurity update for
golang.org/x/crypto The
golang.module was updated toorg/x/crypto v0.as a security update.45. 0 securitySecurity update for
github.com/go-chi/chi/v5 The
github.module was updated tocom/go-chi/chi/v5 v5.as a security update.2. 4 securitySecurity update for
github.com/sigstore/cosign/v3 The
github.module was updated tocom/sigstore/cosign/v3 v3.as a security update.0. 4 securitySecurity update for
github.com/theupdateframework/go-tuf/v2 The
github.module was updated tocom/theupdateframework/go-tuf/v2 v2.as a security update.4. 1 securitySecurity update for
github.com/sigstore/rekor The
github.module was updated tocom/sigstore/rekor v1.as a security update.5. 0 securitySecurity update for
github.com/sigstore/sigstore The
github.module was updated tocom/sigstore/sigstore v1.as a security update.10. 4 securitySecurity update for
github.com/quic-go/quic-go The
github.module was updated tocom/quic-go/quic-go v0.as a security update.57. 0
Check if affected (2)
breakingInput CRD installation from Function packages
Applies if you use
Functionpackages andInput CRDs.breakingPackage cache structure
Applicability is not stated in the release notes.
A maintenance release with fixes for job scheduling and SubJob recovery behavior. No operator action is required beyond upgrading.
Source ↗This release includes a Go toolchain dependency upgrade and a corrected Pulsar PubSub subscription-metadata defect. A regression test verifies that metadata is applied to consumer options.
Action needed (1)
securityhighThe
Gotoolchain upgrade to1.24. 13 Dapr
v1.upgrades16. 9 Goto1.. The upgrade addresses advisories24. 13 GO-2026-4340andGO-2026-4341.
This release contains no described operator-facing changes. The available release note content consists only of headings and a duplicated release-bot entry.
Source ↗This release changes NATS connection authentication and the component spec feature. Dependency and OCI image base updates are also included.
Action needed (1)
breakingThe component spec feature, removed
The component spec feature is removed in this release.
Crossplane v2.1.4 is a maintenance release with security-related dependency updates. It also includes corrections for shared transitive dependency upgrades, so the release concerns operators tracking dependency and security fixes.
Action needed (4)
securityThe
github.module, updated tocom/quic-go/quic-go v0.57. 0 The release updates the
github.module tocom/quic-go/quic-go v0.as a security-related dependency change.57. 0 security
sigstoredependency updates for CVEsThe release updates
sigstoredependencies to fix CVEs.securityThe
github.module, updated tocom/theupdateframework/go-tuf/v2 v2.4. 1 The release updates the
github.module tocom/theupdateframework/go-tuf/v2 v2.as a security-related dependency change.4. 1 securityThe
github.module, updated tocom/go-chi/chi/v5 v5.2. 4 The release updates the
github.module tocom/go-chi/chi/v5 v5.as a security-related dependency change.2. 4
This release updates a security-related dependency and corrects shared transitive dependency upgrades. It also fixes propagation of composite identity through nested XR trees.
Action needed (1)
securityThe
github.dependency, updated tocom/theupdateframework/go-tuf/v2 v2.4. 1 The
github.module is updated tocom/theupdateframework/go-tuf/v2 v2.in the4. 1 release-2.branch.0
Crossplane v1.20.5 is a maintenance release focused on dependency updates. It includes a security-related update to sigstore dependencies and addresses a defect in shared transitive dependency upgrades.
Action needed (1)
securityThe
sigstoredependencies, updated for CVE fixesThe
release-1.branch updates20 sigstoredependencies to fix CVEs.
A feature and maintenance release that adds scaler and authentication capabilities, updates scaler behavior and status reporting, and corrects several defects. It also replaces a deprecated dependency and removes the NATS Streaming scaler.
Check if affected (1)
breakingThe NATS Streaming scaler, removed
Applies if you use the NATS Streaming scaler.