OPA v1.13.1 is a defect-fix release. It addresses a correctness issue in array. when processing single-item arrays.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
OPA v1.13.0 adds a Decision Logger upload mode and a Rego built-in while broadening built-in input support. It also includes runtime and compiler fixes, performance work, and dependency updates; no security advisories or vulnerabilities are disclosed.
Source ↗This release adds configuration and observability capabilities while changing throttling and metric behavior. It also fixes correctness defects, including a described improper policy enforcement issue.
Action needed (2)
securitymediumThe CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9 policy enforcement fix
The release fixes improper policy enforcement associated with CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9.
breakingThe custom
grpc_codemetric label, removedThe custom
grpc_prometheusfork is replaced withgo-grpc-middleware's provider, and the customgrpc_codelabel is removed from the metric.
A maintenance release that removes source-config-path output from release builds, deprecates several userspace interfaces, and rotates the package-signing key. It also includes correctness fixes, dependency updates, and an image-size reduction.
Check if affected (2)
breakingSource config path output in release builds
Applies if you use debug builds.
breakingGPG signing key for DEB/RPM packages, rotated
Applies if you use DEB/RPM packages.
Plan ahead (4)
deprecatedThe
--gvisor-generate-configCLI option, deprecatedApplies if you use
--gvisor-generate-config.deprecatedThe legacy eBPF probe, deprecated
Applies if you use the legacy eBPF probe.
deprecatedThe gVisor engine, deprecated
Applies if you use the gVisor engine.
- + 1 more on the release page
A maintenance release with security-related fixes for the Go toolchain and cross-namespace access through apiCall. It also contains ordinary defect fixes and capability or behavior changes.
Action needed (1)
securityThe
goversion update for standard library CVEsThe
goversion is updated to fix standard library CVEs in this release.
Check if affected (1)
securityCross-namespace access through
apiCallpreventedApplies if you use
apiCall.
A release with operator-facing policy behavior changes. It includes namespace-based failure-action overrides, a context size limit, and tighter cross-namespace access controls for apiCall.
Keycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.
Action needed (3)
securitymediumCVE-2025-67735 in
netty-codec-httpCVE-2025-67735 addresses request smuggling via CRLF injection in
netty-codec-http. The fix ships in Keycloak 26.5.2.securitymediumCVE-2025-66560 in
io.quarkus/quarkus-rest CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in
io.. The fix ships in Keycloak 26.5.2.quarkus/quarkus-rest securitymediumCVE-2025-14559 in
keycloak-servicesCVE-2025-14559 addresses a business logic flaw in
keycloak-servicesthat allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.
A release that removes or deprecates several operator-facing components while adding capabilities and changing supported formats and behavior. It also updates shipped platform components, including Trustee, image-rs, guest kernels, and OVMF.
Check if affected (2)
breakingProcess-based confidential computing via
enclave-cc, removedApplies if you use
enclave-cc.breakingExperimental
Secure Comms mode, removed from the Cloud API AdaptorApplies if you configure
Secure Comms mode.
Plan ahead (2)
breakingThe
CoCo operator, deprecated, withHelm chartinstallationApplies if you use the
CoCo operator.deprecated
packerguest images, deprecated in favor ofmkosiremoval date not announcedApplies if you use
packer images.
Kubescape v3.0.48 is a maintenance release with metrics and reporting additions, workload-scan and panic fixes, and dependency updates. The release concerns users of the affected metrics, reporting, scanning, configuration, and signing components.
Source ↗Cloud Custodian 0.9.49.0 adds AWS and Azure resource support and expands policy filtering. It also changes behavior for several AWS resources, updates dependencies, and changes how c7n-left handles HCL errors. No security advisories or security-specific fixes are disclosed.
Source ↗A maintenance release focused on startup behavior, key disposal, JWT-SVID caching, and metric representation. It affects SPIRE Server on Windows, the aws_kms KeyManager plugin, cache handling, and the uptime_in_ms gauge.
A maintenance release with fixes for configuration values that were misinterpreted or incorrectly assigned during reconfiguration. It addresses discovery polling intervals and decision log reporting buffer sizing, with no security issue or additional operator action stated.
Source ↗A maintenance release with a security fix for the Organization feature, along with correctness fixes, a performance improvement, and updates to HTTP responses and realm administration. Existing working setups are not otherwise described as needing manual changes.
Check if affected (1)
securityOrganization account-name handling
Applies if you enable the
organizationsfeature.
A maintenance release with a corrected metric compatibility issue, changes to performance and metric output, and a cleanup-controller fix. It also includes cherry-pick pointers and release-management updates.
Source ↗OPA v1.12.2 adds a public TemplateString copy method and corrects defects in template-string AST handling and serialization. The changes affect template-string copying, escaped-brace serialization, reference safety, and variable names in template errors.
A substantial feature and maintenance release adds operator capabilities including workflows, JWT authorization grants, organization invitations, OpenTelemetry export, and Windows services. It also updates Quarkus and fixes correctness issues, while changing supported database versions and addressing a vulnerability in brute force detection settings.
Check if affected (2)
securityBrute force detection settings vulnerability, corrected
Applies if you configure brute force detection settings.
breaking
PostgreSQL 13.support removalx Applies if you depend on
PostgreSQL 13..x
Plan ahead (1)
deprecatedFine-Grained Admin Permissions v1, deprecated
Applies if you enable
admin/fine-grained-permissions.