RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: VolcanoClear ×
Volcanov1.15.1Orchestration & ManagementJul 30, 2026

Volcano v1.15.1 is a maintenance release with a dependency update, configuration-format compatibility changes, and correctness fixes. It also includes implementation-only changes with no operator-facing impact.

Action needed (1)

  • securityThe golang.org/x/crypto dependency, upgraded

    Volcano v1.15.1 upgrades golang.org/x/crypto from v0.49.0 to v0.53.0, incorporating upstream SSH security fixes released in v0.52.0.

Source
Volcanov1.14.4Orchestration & ManagementJul 30, 2026

Volcano v1.14.4 is a bug-fix release covering scheduler behavior, nil-pointer panics, job dependency readiness, allocation flow, and Ascend vNPU configuration and resource handling. No security advisories or security-specific flaws are identified.

Source
Volcanov1.14.3Orchestration & ManagementJun 27, 2026

Volcano v1.14.3 is a bug-fix release for operator-relevant scheduling, resource accounting, pod metadata, status handling, and scheduler snapshots. The recorded release data contains no individual change entries to display.

Source
Volcanov1.15.0Orchestration & ManagementJun 1, 2026

A feature and operational-hardening release that adds alpha scheduling capabilities, new scheduler and Helm configuration, and fixes scheduler and integration stability issues. Operators should review Kubernetes and DRA compatibility requirements, the changed DRA default, and the disclosed denial-of-service and Prometheus security fixes.

Action needed (4)

  • securitymediumPrometheus dependency update for GHSA-vffh-x6r8-xx99

    Updates github.com/prometheus/prometheus to address stored XSS advisory GHSA-vffh-x6r8-xx99.

  • securitymediumAdmission webhook request body limits

    The admission webhook now limits request bodies, fixing the denial-of-service risk identified by CVE-2026-44247 and GHSA-8wxp-xxp2-rcgx.

  • breakingDRA scheduling integration default

    DRA scheduling integration is enabled by default.

  • breakingDRA scheduling integration default behavior

    DRA scheduling integration is enabled by default to align with Kubernetes 1.34 and later behavior. Set predicate.DynamicResourceAllocationEnable to false to disable it.

Check if affected (2)

  • breakingOpt-in SchedulingGatesQueueAdmission

    Applies if you enable SchedulingGatesQueueAdmission.

    SchedulingGatesQueueAdmission is opt-in and must be enabled on both the scheduler and webhook-manager.

  • breakingOpt-in gang-aware preemption and reclamation

    Applies if you configure gangPreempt and gangReclaim and do not configure preempt or reclaim.

    Gang-aware preemption and reclamation are opt-in. Configure gangPreempt and gangReclaim explicitly, without using the legacy preempt and reclaim actions in the same scheduler action list.

Source
Volcanov1.12.4Orchestration & ManagementMay 9, 2026

A maintenance release with a security fix for a disclosed denial-of-service vulnerability in the webhook server, plus ordinary scheduling bug fixes. The vulnerability affects webhook servers that accept unbounded HTTP request bodies.

Check if affected (1)

  • securitymediumCVE-2026-44247 in the Volcano webhook server

    Applies if the Volcano webhook server runs.

    This release fixes a denial-of-service vulnerability in the Volcano webhook server caused by unbounded HTTP request body size. A pod with network access to the webhook endpoint could send an arbitrarily large request body and cause the server to be killed by OOM.

Source
Volcanov1.13.3Orchestration & ManagementMay 9, 2026

Volcano v1.13.3 includes a security fix for a denial-of-service vulnerability in the webhook server. It also contains other defect corrections.

Check if affected (1)

  • securitymediumCVE-2026-44247 in the Volcano webhook server

    Applies if a pod can access the Volcano webhook endpoint over the network.

    CVE-2026-44247 fixes an unbounded HTTP request body size issue in the Volcano webhook server. A pod with network access to the webhook endpoint could send an arbitrarily large request body and cause the server to be killed by OOM.

Source
Volcanov1.14.2Orchestration & ManagementMay 9, 2026

A maintenance release fixes a disclosed webhook denial-of-service vulnerability and corrects scheduler, queue, and event-handling defects. It also updates the Kubernetes version used by the webhook-manager image.

Check if affected (1)

  • securitymediumCVE-2026-44247: Webhook server request body handling

    Applies if the Volcano webhook server runs.

    The Volcano webhook server fixes a vulnerability in HTTP request body handling that could let a pod with network access to the webhook endpoint send an arbitrarily large request body and cause an out-of-memory denial of service. The fix ships in the Volcano webhook server.

Source
Volcanov1.13.2Orchestration & ManagementMar 30, 2026

Volcano v1.13.2 is a maintenance release focused on operator-relevant bug fixes. It addresses issues in workload termination and resource or scheduler snapshot handling.

Source
Volcanov1.14.1Orchestration & ManagementFeb 14, 2026

Volcano v1.14.1 is a maintenance release focused on scheduling and recovery fixes. The recorded changes do not include details for individual fixes.

Source
Volcanov1.14.0Orchestration & ManagementJan 31, 2026

Volcano v1.14.0 is a substantial feature and maintenance release with new scheduling, topology, colocation, accelerator, API, and integration capabilities, alongside fixes for correctness and stability issues. No security advisories or explicitly described vulnerabilities are noted.

Source
Volcanov1.12.3Orchestration & ManagementJan 18, 2026

Volcano v1.12.3 is an operator-facing release with scheduler, plugin, validation, metrics, and resource-handling changes. The release notes disclose no security advisories or security flaws.

Source
Browse by month