RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Sep 2026Clear ×
cert-managerv1.21.2SecuritySep 11, 2026

A maintenance release focused on correctness and data-exposure fixes. It also includes security-related dependency updates and a stricter default for namespaced Vault authentication.

Action needed (6)

  • securityACME server response body limit

    ACME server response bodies are capped at 16 MiB to prevent unbounded-body denial-of-service conditions.

  • securityChallenge.status.reason response disclosure fix

    The ACME HTTP-01 self-check no longer copies the fetched response body into Challenge.status.reason. This prevents internal response contents reached through redirects from being disclosed.

  • securityGo 1.26.6

    The release upgrades Go to 1.26.6, which includes security fixes in the Go command and several standard library packages.

  • securitygoogle.golang.org/grpc v1.83.2

    The release updates google.golang.org/grpc to v1.83.2 to fix reported security vulnerabilities.

  • securitygolang.org/x/crypto v0.56.0

    The release updates golang.org/x/crypto to v0.56.0 to fix reported security vulnerabilities.

  • breakingValidation for converted AdmissionReview requests

    Validation now also applies to equivalent-converted AdmissionReview requests on non-v1 API versions. These requests could previously bypass validation.

Check if affected (1)

  • breakingNamespaced Vault issuer ambient credentials default

    Applies if you use a namespaced Issuer with Vault AWS IAM authentication.

Source
Kyvernov1.19.1SecuritySep 10, 2026

A security-focused maintenance release with dependency updates and fixes for policy and egress behavior. It also includes correctness changes, deprecation warning enforcement, and a narrowed policy constraint that may require operator changes.

Action needed (2)

  • securitycriticalGo and x/net updates for CVE-2026-39821

    The release updates Go to 1.26.6 and x/net to resolve CVE-2026-39821.

  • securityhighGo update for CVE-2026-56853

    The release updates Go to address CVE-2026-56853.

Check if affected (3)

  • securityPolicyException scope bypass fix for GHSA-5cjf-wwfg-pj4c

    Applies if you use the PolicyException CRD.

  • securityapiCall.service egress blocklist bypass fix

    Applies if you configure apiCall.service egress.

  • breakingglobalContext constraint in namespaced policies

    Applies if you use globalContext in namespaced policies.

Source
Cloud Custodian0.9.52.0SecuritySep 3, 2026

A broad multi-cloud release adds resource integrations, filters, and policy actions across AWS, Azure, and GCP, alongside correctness fixes and dependency updates. Operators should also review the LDAP input handling improvement and the behavior changes affecting existing configurations.

Check if affected (3)

  • breakingThe Status field, replaced by State

    Applies if you configure Status.

  • breakingThe SCM basic auth method, replaced by an Entra ID bearer token

    Applies if you use SCM basic auth.

  • breakingThe cloud-run label mutation fields, restricted to the schema

    Applies if you use cloud-run.

Source
Kubescapev4.0.13SecuritySep 2, 2026

A broad feature release expands scanning, policy, reporting, remediation, notifications, telemetry, integrations, and output capabilities. It also includes security hardening and stricter scan constraints, alongside many correctness and runtime fixes.

Action needed (2)

  • securityGo dependency security vulnerabilities

    Dependabot fixes security vulnerabilities in Go dependencies shipped with the release.

  • securitygosec SAST findings

    The release remediates gosec SAST findings in the Go codebase.

Check if affected (10)

  • securityGrafeas filtering through resourceURL

    Applies if you run imagescan.

  • breakingClient-supplied account and accessKey in scan requests

    Applies if you use scan requests.

  • breakingHard validation for --include-controls

    Applies if you configure --include-controls.

  • + 7 more on the release page

Plan ahead (1)

  • deprecatedThe --fail-threshold flag, hidden and deprecated

    Applies if you configure --fail-threshold.

Source
Browse by month