A maintenance release with operator-relevant fixes for chart upgrades, recovered-cluster resource watching, scheduling, and cluster readiness handling. The remaining release-note entries are headings without standalone operator-facing changes.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
Karmada v1.16.6 is a maintenance release with operator-focused bug fixes. The note tail indicates fixes in cluster resource watching, scheduling under resource pressure, and transient cluster client failures, with no disclosed security advisories or security-specific fixes.
Source ↗A maintenance release with fixes in karmada-search and karmada-controller-manager. It addresses delayed watch updates for recovered clusters and transient cluster-client failures during credential rotation.
A feature and maintenance release that adds overflow scheduling and scheduling overcommit protection, along with API, default, constraint, metric, and flag changes. It also includes a security-related alpine base-image update and numerous defect corrections.
Action needed (1)
securityThe
alpinebase image updateThe
alpinebase image has changed fromalpine:3.to23. 3 alpine:3.to address security concerns.23. 4
Check if affected (9)
breakingThe
overflowAffinitiesfieldApplies if you configure
overflowAffinities.breakingStricter
clusterTolerationsoperator validationApplies if you set
spec.withplacement. clusterTolerations LtorGt.breakingThe operator's default verbosity level
Applies if you run the operator.
- + 6 more on the release page
A maintenance release corrects a workflow retentioner defect and constrains forwarded-host handling during Sentry OIDC discovery. The discovery change affects deployments that use Sentry OIDC.
Check if affected (1)
securityConstrained
X-Forwarded-Hostuse during Sentry OIDC discoveryApplies if you use Sentry OIDC.
A maintenance release includes dependency updates and security fixes in golang.. The fixes cover SSH, SSH agent, and known-hosts behavior.
Action needed (1)
security
golang.updated toorg/x/crypto v0.52. 0 The release updates the
golang.module toorg/x/crypto v0..52. 0
Check if affected (13)
securitycriticalUnenforced invoking key constraints in
golang.org/x/crypto/ssh/agent Applies if you use
golang..org/x/crypto/ssh/agent securitycriticalDropped invoking agent constraints in
golang.org/x/crypto/ssh/agent Applies if you use
golang..org/x/crypto/ssh/agent securitycriticalServer deadlock on unexpected responses in
golang.org/x/crypto/ssh Applies if you use
golang..org/x/crypto/ssh - + 10 more on the release page
Crossplane v1.20.8 is a dependency and toolchain maintenance release. It updates several modules and the Go version, with the recorded dependency changes addressing security fixes, and also bumps crossplane-runtime to v1..
Action needed (7)
securityThe
github.module, updated tocom/docker/cli v29.2. 0+incompatible The
github.module is updated tocom/docker/cli v29.in the2. 0+incompatible release-1.branch.20 securityThe
golang.module, updated toorg/x/net v0.53. 0 The
golang.module is updated toorg/x/net v0.in the53. 0 release-1.branch.20 securityThe
github.module, updated tocom/in-toto/in-toto-golang v0.11. 0 The
github.module is updated tocom/in-toto/in-toto-golang v0.in the11. 0 release-1.branch.20 securityThe
github.module, updated tocom/go-git/go-git/v5 v5.19. 0 The
github.module is updated tocom/go-git/go-git/v5 v5.in the19. 0 release-1.branch.20 securityThe
Gotoolchain, updated to1.25. 10 Gois updated to1.to fix standard-library CVEs in the25. 10 release-1.branch.20 securityThe
github.module, updated tocom/go-git/go-git/v5 v5.19. 1 The
github.module is updated again, tocom/go-git/go-git/v5 v5., in the19. 1 release-1.branch.20 securityThe
golang.module, updated toorg/x/crypto v0.52. 0 The
golang.module is updated toorg/x/crypto v0.in the52. 0 release-1.branch.20
A security-focused maintenance release updates Go and several dependencies, including a fix for an HTTP/2 transport infinite-loop vulnerability. The Go and dependency version increases require upgrading; no configuration migration or deprecation is announced.
Action needed (6)
securityThe
go.module updateopentelemetry. io/otel The
go.module is updated toopentelemetry. io/otel v1.in this release.41. 0 securityThe
github.module updatecom/in-toto/in-toto-golang The
github.module is updated tocom/in-toto/in-toto-golang v0.in this release.11. 0 securityThe
github.module update tocom/go-git/go-git/v5 v5.19. 0 The
github.module is updated tocom/go-git/go-git/v5 v5.in this release.19. 0 security
Go1.25. 10 Gois updated to1.to fix standard library CVEs.25. 10 securityThe
github.module update tocom/go-git/go-git/v5 v5.19. 1 The
github.module is updated tocom/go-git/go-git/v5 v5.in this release.19. 1 securityThe
golang.module updateorg/x/crypto The
golang.module is updated toorg/x/crypto v0.in this release.52. 0
Check if affected (1)
securityhighThe
golang.HTTP/2 transport infinite looporg/x/net Applicability is not stated in the release notes.
Crossplane v2.2.2 is a dependency and toolchain maintenance release with security-focused updates. It concerns deployments and builds that rely on the updated Go toolchain and modules.
Action needed (5)
security
github.updated to v0.11.0com/in-toto/in-toto-golang Crossplane v2.2.2 updates the
github.module to v0.11.0. The update ships in the release-2.2 line.com/in-toto/in-toto-golang security
github.updated to v5.19.0com/go-git/go-git/v5 Crossplane v2.2.2 updates the
github.module to v5.19.0. The update ships in the release-2.2 line.com/go-git/go-git/v5 security
Go1.25.10 update for standard-library CVEsCrossplane v2.2.2 updates
Goto 1.25.10 to fix standard-library CVEs. The toolchain update ships in the release-2.2 line.security
github.updated to v5.19.1com/go-git/go-git/v5 Crossplane v2.2.2 updates the
github.module to v5.19.1. The update ships in the release-2.2 line.com/go-git/go-git/v5 security
golang.updated to v0.52.0org/x/crypto Crossplane v2.2.2 updates the
golang.module to v0.52.0. The update ships in the release-2.2 line.org/x/crypto
This release corrects the runtime operator's generated and Helm RBAC permissions. The fixes cover finalizer updates needed for garbage collection and permissions for resources used by reconcilers; no security advisory or security flaw is disclosed.
Source ↗Crossplane v2.3.0 combines breaking API naming and path changes with new operator capabilities and correctness fixes. It also updates several Go dependencies and the Go toolchain, which matters to API consumers and builds that depend on the affected packages.
Action needed (14)
securityThe
github.dependency, updated to v1.6.3com/cloudflare/circl The
github.module is updated to v1.6.3 in Crossplane v2.3.0.com/cloudflare/circl securityThe
google.dependency, updated to v1.79.3golang. org/grpc The
google.module is updated to v1.79.3 in Crossplane v2.3.0.golang. org/grpc securityThe
go.dependency, updated to v1.43.0opentelemetry. io/otel/exporters/otlp/otlptrace/otlptracehttp The
go.module is updated to v1.43.0 in Crossplane v2.3.0.opentelemetry. io/otel/exporters/otlp/otlptrace/otlptracehttp securityThe
github.dependency, updated to v5.17.1com/go-git/go-git/v5 The
github.module is updated to v5.17.1 in Crossplane v2.3.0.com/go-git/go-git/v5 securityThe
github.dependency, updated to v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 in Crossplane v2.3.0.com/go-jose/go-jose/v4 securityThe
github.dependency, updated to v3.0.5com/sigstore/cosign/v3 The
github.module is updated to v3.0.5 in Crossplane v2.3.0.com/sigstore/cosign/v3 securityThe
github.dependency, updated to v29.2.0+incompatiblecom/docker/cli The
github.module is updated to v29.2.0+incompatible in Crossplane v2.3.0.com/docker/cli securityThe
github.dependency, updated to v2.0.6com/sigstore/timestamp-authority/v2 The
github.module is updated to v2.0.6 in Crossplane v2.3.0.com/sigstore/timestamp-authority/v2 securityThe
Gotoolchain, updated to 1.25.9The
Gotoolchain is updated to 1.25.9 in Crossplane v2.3.0.securityThe
github.dependency, updated to v0.5.1com/moby/spdystream The
github.module is updated to v0.5.1 in Crossplane v2.3.0.com/moby/spdystream securityThe
github.dependency, updated to v5.18.0com/go-git/go-git/v5 The
github.module is updated to v5.18.0 in Crossplane v2.3.0.com/go-git/go-git/v5 securityThe
github.dependency, updated to v0.11.0com/in-toto/in-toto-golang The
github.module is updated to v0.11.0 in Crossplane v2.3.0.com/in-toto/in-toto-golang securityThe
golang.dependency, updated to v0.53.0org/x/net The
golang.module is updated to v0.53.0 in Crossplane v2.3.0.org/x/net securityThe
Gotoolchain, updated to 1.25.10The
Gotoolchain is updated to 1.25.10 in Crossplane v2.3.0 to fix standard library CVEs.
Check if affected (3)
breakingThe Crossplane API dependency path, renamed
Applies if you build external consumers of Crossplane APIs.
breakingThe common API package, moved
Applies if you use the common APIs from
crossplane-runtime.breakingThe
v1.types, renamedResource* Applies if you use the old
v1.types.Resource*
wasmCloud v2.2.0 adds runtime, CLI, routing, API, and interface-publishing capabilities and corrects handling for musl-on-glibc systems. The release notes provided here disclose no security changes or operator actions.
Source ↗Dapr v1.17.7 is a corrective release focused on workflow, scheduler, actor, networking, and pub/sub reliability defects. It also adds workflow payload metrics, changes scheduler defaults, adds a scheduler flag, and updates github..
Check if affected (1)
breakingThe actor
drainOngoingCallTimeoutconstraintApplies if an application supplies an actor
drainOngoingCallTimeoutthat meets or exceeds the daprd-side placement dissemination timeout, which defaults to 30 seconds.
A maintenance release with a security fix for a disclosed denial-of-service vulnerability in the webhook server, plus ordinary scheduling bug fixes. The vulnerability affects webhook servers that accept unbounded HTTP request bodies.
Check if affected (1)
securitymediumCVE-2026-44247 in the
Volcano webhook serverApplies if the
Volcano webhook serverruns.
Volcano v1.13.3 includes a security fix for a denial-of-service vulnerability in the webhook server. It also contains other defect corrections.
Check if affected (1)
securitymediumCVE-2026-44247 in the Volcano webhook server
Applies if a pod can access the Volcano webhook endpoint over the network.
A maintenance release fixes a disclosed webhook denial-of-service vulnerability and corrects scheduler, queue, and event-handling defects. It also updates the Kubernetes version used by the webhook-manager image.
Check if affected (1)
securitymediumCVE-2026-44247: Webhook server request body handling
Applies if the Volcano webhook server runs.
A maintenance release with correctness fixes, dependency updates, and new deployment and plugin capabilities. It also removes the obsolete canary-v2 identifier.
Check if affected (1)
breakingThe
canary-v2canary identifier, removedApplies if you configure
canary-v2.
A maintenance release with corrected HTTP and workload behavior, dependency updates, and toolchain maintenance. It also removes canary-v2 in favor of canary.
Check if affected (1)
breakingThe
canary-v2configuration, removed in favor ofcanaryApplies if you configure
canary-v2.
A maintenance release with correctness fixes for HTTP errors, NATS subscription readiness, and WorkloadDeployment readiness, plus dependency and toolchain updates. It removes canary-v2 now that canary exists and includes dependency cleanup.
Action needed (1)
breakingThe
canary-v2option, removedcanary-v2is removed now thatcanaryexists. The removal ships in this release.