A maintenance release with ordinary bug fixes across agent, chart, controller, and OpenAPI components. No security advisories or operator actions are identified.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release focused on operator-facing defect corrections across Karmada components. It addresses certificate rotation approval, upgrade rendering, and graceful eviction handling.
Source ↗A maintenance release focused on operator-facing bug fixes in cluster management and upgrade paths. It addresses issues that could affect certificate rotation, chart rendering, and workload evacuation.
Source ↗A maintenance release with a security-relevant gRPC dependency upgrade, Pulsar Avro and JSON schema handling corrections, and a Scheduler cluster recovery fix. It also adds raw payload topic metadata and updates Avro payload conversion and CloudEvents schema registration.
Action needed (1)
securitycriticalThe
google.dependency and CVE-2026-33186 resolutiongolang. org/grpc The affected
google.dependency is upgraded to a version that resolves CVE-2026-33186. The fix ships in this release.golang. org/grpc
Check if affected (2)
breakingRejected
rawPayload=truepublishing to CloudEvents-wrapped topicsApplies if
rawPayloadis set for a CloudEvents-wrapped topic.breakingStructural validation for
.topicsjsonschema Applies if you configure
..jsonschema
A maintenance release with operator-facing bug fixes in job pod handling, resource snapshots, GPU resources, and scheduler snapshot cloning. It also contains an update with no stated operator-facing impact.
Source ↗A maintenance release with two operator-facing defect fixes: virt-handler now restarts its domain-notify server after an unexpected exit, and VMExport handles long PVC names.
Dapr v1.17.3 is a maintenance release with two dependency upgrades that resolve reported CVEs. It also includes correctness fixes for actor and service responses, placement dissemination, reconnect behavior, Scheduler participation, metrics, and Windows sidecar startup.
Action needed (2)
securitycriticalThe
google.dependency, updated for CVE-2026-33186golang. org/grpc The
google.dependency is upgraded in this release to resolve CVE-2026-33186.golang. org/grpc securitymediumThe
golang.dependency, updated for CVE-2026-33809org/x/image This release upgrades
golang.from v0.25.0 to v0.38.0, resolving CVE-2026-33809.org/x/image
This release updates the Go toolchain and corrects Scheduler and container defects. The recorded Scheduler and Windows fixes require only an upgrade, with no operator configuration changes stated.
Action needed (1)
securityThe
Goversion, updated to 1.25.8Dapr v1.16.11 updates the
Gotoolchain from 1.25.7 to 1.25.8.
A broad operator-facing feature and maintenance release with API and behavior changes, dependency updates, deprecations, and removals. Monitoring and configuration changes include recording-rule and feature-gate updates, alongside scheduling and security-related behavior changes; no security advisories are reported.
Check if affected (7)
breakingNetwork attachment definition get permissions in the
virt-controllerClusterRole, removedApplicability is not stated in the release notes.
breakingStop requests for paused VMIs, rejected
Applies if you run paused VMIs.
breakingThe
EnableVirtioFsConfigVolumesfeature, graduated to GAApplies if you use the
EnableVirtioFsConfigVolumesfeature gate.- + 4 more on the release page
Plan ahead (4)
deprecatedThe
DisableMDEVConfigurationfeature gate, deprecatedremoval date not announcedApplies if you use the
DisableMDEVConfigurationfeature gate.deprecatedThe
kubevirt_vmi_migration_data_total_bytesmetric, deprecatedApplies if you use the
kubevirt_vmi_migration_data_total_bytesmetric.deprecatedThe
MultiArchitecturefeature gate, deprecatedApplies if you use the
MultiArchitecturefeature gate.- + 1 more on the release page
A maintenance release with a configurable TLS addition in the release notes. The secure pod default change is announced for a future release, not this one.
Source ↗This release contains project module maintenance and regenerated protobuf code. Nothing here needs operator attention.
Source ↗wasmCloud v2.0.0 adds operator-facing capabilities, changes CRD locations, updates dependencies, and fixes runtime and CLI behavior. The dependency update addresses the disclosed advisory RUSTSEC-2026-0007.
Action needed (2)
securitymediumLock file update for
RUSTSEC-2026-0007wasmCloud v2.0.0 updates the lock file to address
RUSTSEC-2026-0007.breakingCRD location moved from
templates/crdsto/crdswasmCloud v2.0.0 moves CRDs from
templates/crdsto/crds.
A maintenance release with disclosed Go standard-library security fixes, a Go toolchain upgrade, and a required manual Configuration CRD update. It also adds RavenDB state-store registration and correctness and performance fixes across pub/sub, scheduling, service invocation, workflows, actors, conversation components, state stores, and Sentry.
Action needed (3)
securityhighGo toolchain upgrade to 1.25.8
The Go toolchain was upgraded from 1.24.13 to 1.25.8 across all modules and Docker images in the repository.
securitymedium
GO-2026-4603and escaped meta content URLshtml/templatenow escapes URLs in meta content attribute actions, addressing potential cross-site scripting via crafted URLs.securitylow
GO-2026-4602andos.root boundariesFileInfo os.can no longer escape from aFileInfo Rootto access files outside the intended directory boundary.
Check if affected (2)
securityhigh
GO-2026-4601and IPv6 host literal parsingApplies if you use
net/url.breaking
ConfigurationstateRetentionPolicyschemaApplies if you configure
stateRetentionPolicy.
A maintenance release updates the google. dependency from 1.78.0 to 1.79.3 and updates the Ansible operator plugin to 1.42.2. Generated-file maintenance and the section heading do not affect operators.
A maintenance release with operator-facing behavior fixes across backup handling, VMI updates, storage migration, and monitoring. It also updates the quiescing status indication used by KubeVirt.
Action needed (1)
breakingThe
QuiesceFailedindication replaced byQuiesceTimeoutThe
QuiesceFailedindication was replaced withQuiesceTimeout.
A maintenance release with a disclosed security fix, an indication rename for Windows VSS handling, and correctness, behavior, and observability updates. Most changes require no operator action beyond upgrading.
Action needed (1)
securityhighCVE-2025-47913 remediation
The release adds a replace directive that points
golang/x/cryptoto the patchedopenshift/golang-cryptomodule to remediate CVE-2025-47913.
Check if affected (2)
breaking
QuiesceFailedindication renamed toQuiesceTimeoutApplies if you use Windows VSS.
breaking
DefaultVirtWebhookClient{QPS,Burst}values alignedApplicability is not stated in the release notes.
This release focuses on dependency maintenance, including a security-related Go update, along with a grace-period behavior change. No operator setup changes are explicitly required beyond upgrading to obtain the security fix.
Action needed (1)
securityGo dependency updates for CVE remediation
The release updates
goand its dependencies to address CVEs. The change ships in operator-framework v1.42.1.
Dapr v1.17.1 is a maintenance release focused on runtime behavior in the operator path. The noted fixes cover workflow cleanup, bulk subscription timing, WASM component registration, and placement dissemination overhead.
Source ↗This release corrects Avro publishing and WASM component registration defects, improves Avro publishing performance, and updates the Go and OpenTelemetry SDK dependencies. The Go update includes security fixes, while the OpenTelemetry update is presented without a disclosed security issue.
Action needed (1)
securityThe
Go 1.update25. 7 Go 1.ships security fixes for the25. 7 gocommand andcrypto/tlspackage, plus compiler andcrypto/x509bug fixes.