This release includes operator-visible defect corrections and an image-build behavior change alongside dependency updates for security fixes. Upgrading incorporates the security fixes in the dependency updates, while the remaining changes require no setup action.
Action needed (7)
securityThe
github.module update tocom/sigstore/rekor v1.5. 2 Crossplane v2.3.4 updates the
github.module tocom/sigstore/rekor v1.for security fixes.5. 2 securityThe
github.module update tocom/sigstore/cosign/v3 v3.0. 6 Crossplane v2.3.4 updates the
github.module tocom/sigstore/cosign/v3 v3.for security fixes.0. 6 securityThe
github.module update tocom/sigstore/timestamp-authority/v2 v2.1. 0 Crossplane v2.3.4 updates the
github.module tocom/sigstore/timestamp-authority/v2 v2.for security fixes.1. 0 securityThe
github.module update tocom/sigstore/sigstore-go v1.2. 0 Crossplane v2.3.4 updates the
github.module tocom/sigstore/sigstore-go v1.for security fixes.2. 0 securityCombined security dependency updates
Crossplane v2.3.4 includes combined security updates for
grpc,golang., andorg/x/net golang..org/x/text securityThe
golang.module update toorg/x/text v0.39. 0 Crossplane v2.3.4 updates the
golang.module toorg/x/text v0.for security fixes.39. 0 securityThe
golang.module update toorg/x/net v0.56. 0 Crossplane v2.3.4 updates the
golang.module toorg/x/net v0.for security fixes.56. 0