A release with breaking changes to package installation and package-cache side-loading, alongside new operator capabilities and ordinary defect corrections. It also includes security-tagged dependency updates, but no advisory identifiers or vulnerability details are provided.
Action needed (7)
securitySecurity update for
golang.org/x/crypto The
golang.module was updated toorg/x/crypto v0.as a security update.45. 0 securitySecurity update for
github.com/go-chi/chi/v5 The
github.module was updated tocom/go-chi/chi/v5 v5.as a security update.2. 4 securitySecurity update for
github.com/sigstore/cosign/v3 The
github.module was updated tocom/sigstore/cosign/v3 v3.as a security update.0. 4 securitySecurity update for
github.com/theupdateframework/go-tuf/v2 The
github.module was updated tocom/theupdateframework/go-tuf/v2 v2.as a security update.4. 1 securitySecurity update for
github.com/sigstore/rekor The
github.module was updated tocom/sigstore/rekor v1.as a security update.5. 0 securitySecurity update for
github.com/sigstore/sigstore The
github.module was updated tocom/sigstore/sigstore v1.as a security update.10. 4 securitySecurity update for
github.com/quic-go/quic-go The
github.module was updated tocom/quic-go/quic-go v0.as a security update.57. 0
Check if affected (2)
breakingInput CRD installation from Function packages
Applies if you use
Functionpackages andInput CRDs.Input CRDs included in
Functionpackages are no longer installed by the package manager.breakingPackage cache structure
Applicability is not stated in the release notes.
The on-disk structure of the package cache has changed. This breaks the undocumented behavior that allowed packages to be side-loaded into Crossplane.