RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Mar 2026Clear ×
Confidential Containersv0.19.0SecurityMar 30, 2026

A release that narrows supported environments and installation paths while adding storage, attestation, GPU, API, signature, and image-handling capabilities. It also updates guest and image handling, including sealed-secret signatures, cosign signatures with newlines, in-memory LUKS headers, and improved Vault/OpenBao support.

Check if affected (5)

  • breakingGo support in CDH removed

    Applies if you use CDH.

  • breakingCanonical TDX Tech preview support removed

    Applies if you use Canonical TDX Tech preview.

  • breakingUbuntu version requirement

    Applies if you use Ubuntu 24.04.4 (linux-image-generic-hwe-24.04) or 25.10.

  • + 2 more on the release page

Plan ahead (1)

  • deprecatedpacker images support, planned for removalremoval date not announced

    Applies if you use packer images.

Source
Open Policy Agent (OPA)v1.15.1SecurityMar 30, 2026

OPA v1.15.1 is a patch release that corrects a backwards-incompatible v1/logging.Logger interface change from v1.15.0. The fix concerns Go module users with custom Logger implementations; binary and Docker image behavior is unchanged.

Source
cert-managerv1.20.1SecurityMar 27, 2026

cert-manager v1.20.1 contains bug corrections and a security-related dependency update. The gRPC vulnerability details are limited to the scanner reports, which state that it does not affect cert-manager.

Action needed (1)

  • securityThe google.golang.org/grpc dependency update

    The google.golang.org/grpc dependency is bumped in cert-manager v1.20.1 to address a vulnerability reported by scanners. The report states that the vulnerability does not affect cert-manager.

Source
Open Policy Agent (OPA)v1.15.0SecurityMar 26, 2026

OPA v1.15.0 adds pluggable logging and AWS web-identity signing support, changes the custom HTTPAuthPlugin lifecycle contract, and adds TLS certificate reread configuration. It also includes correctness fixes and dependency updates; no security advisories or vulnerability disclosures are stated.

Check if affected (1)

  • breakingCustom HTTPAuthPlugin lifecycle contract

    Applies if you use custom HTTPAuthPlugin implementations.

Source
OpenFGAv1.13.1SecurityMar 24, 2026

A maintenance release fixes a disclosed security vulnerability in Check requests with conditions and caching enabled, which could return incorrect cached results. The fix addresses the interaction between conditional checks and caching.

Check if affected (1)

Source
OpenFGAv1.13.0SecurityMar 23, 2026

This release adds experimental AuthZen 1.0 support and changes observability output for list-objects operations. It also includes fixes for recoverable panics.

Source
SPIREv1.14.4SecurityMar 19, 2026

This release fixes an agent version-reporting defect during re-attestation or SVID renewal. The recorded release note describes the agent's startup version being replaced by an empty string during that process.

Source
OpenFGAv1.12.1SecurityMar 19, 2026

A maintenance release updates grpc-go to v1.79.3 and grpc-health-probe to v0.4.47. It also corrects OTEL_EXPORTER_OTLP_ENDPOINT handling for URI schemes, including TLS activation for https:// endpoints.

Source
Keycloak26.5.6SecurityMar 19, 2026

A security and maintenance release that fixes disclosed vulnerabilities alongside ordinary bugs. The security fixes require upgrading, while the other fixes require no operator action beyond upgrading.

Check if affected (8)

  • securitymediumCVE-2026-1180, blind SSRF in OIDC Dynamic Client Registration

    Applies if you use OIDC Dynamic Client Registration.

  • securitymediumCVE-2025-14777, Keycloak IDOR in realm client creation and deletion

    Applicability is not stated in the release notes.

  • securitymediumCVE-2026-3121, privilege escalation via manage-clients permission

    Applies if you configure manage-clients permission.

  • + 5 more on the release page
Source
Cloud Custodian0.9.50.0SecurityMar 18, 2026

Cloud Custodian 0.9.50.0 adds operator-facing resources, filters, actions, and configuration options across AWS, Azure, and GCP. It also corrects provider-specific defects and changes existing filtering and policy behavior, with no security advisories or explicit vulnerability fixes described.

Source
SPIREv1.14.3SecurityMar 18, 2026

A maintenance release adds agent version reporting, changes TLS policy behavior, improves performance, and corrects several defects. It also includes security fixes for selector logging and TLS certificate chain validation.

Action needed (1)

  • securityAgent-level selector logging removal

    Selectors are no longer logged at the agent level to avoid potential leakage of sensitive information.

Check if affected (1)

  • securityServer TCP endpoint TLS session tickets disabled

    Applies if you use the server TCP endpoint.

Source
Kubescapev4.0.3SecurityMar 17, 2026

A maintenance release with an updated OpenTelemetry SDK, a new --grype-db-url option for the Kubescape scan command, and a fix for missing-host handling. The remaining release-note entries are merge, heading, or internal logging changes.

Source
OpenFGAv1.12.0SecurityMar 13, 2026

A maintenance release adds gRPC message-size configuration, changes TLS certificate rotation handling, and updates an experimental default. It also tightens tuple validation, fixes correctness issues, and updates the Go toolchain for disclosed advisories.

Action needed (2)

  • securityhighGo toolchain version 1.25.8

    The Go toolchain is updated to version 1.25.8 to address standard library vulnerabilities identified by GO-2026-4603 and GO-2026-4601.

  • breakingStricter tuple string validation

    Tuple validation now fails when a tuple string contains Unicode control characters or null bytes.

Check if affected (1)

  • breakingThe pipeline_list_objects experimental default

    Applies if you set pipeline_list_objects, set listObjects-pipeline-enabled, or use a custom featureflag client.

Source
cert-managerv1.20.0SecurityMar 10, 2026

This release adds Helm, API, solver, and feature-gate capabilities while changing defaults and accepted behavior. It also corrects bugs and includes security fixes in the cert-manager controller and Go.

Action needed (2)

  • securityhighGo v1.25.5 update for CVE-2025-61727 and CVE-2025-61729

    Go is updated to v1.25.5 to fix CVE-2025-61727 and CVE-2025-61729.

  • breakingIssuer reference kind and group defaults, reverted

    The default issuer reference kind and group values are reverted to the behavior before 0.19.0.

Check if affected (4)

  • securityPotential cert-manager controller panic from cached DNS responses

    Applicability is not stated in the release notes.

  • breakingThe OtherNames feature, enabled by default

    Applies if you use the OtherNames feature.

  • breakingDefault container user and group IDs

    Applies if you do not configure the default container user (UID) or do not configure the default container group (GID).

  • + 1 more on the release page
Source
Open Policy Agent (OPA)v1.14.1SecurityMar 9, 2026

OPA v1.14.1 is a patch release focused on bug fixes and dependency updates. It includes dependency work related to the Go standard library and common package vulnerabilities.

Action needed (1)

  • securityGolang standard library dependency updates

    This patch release collects two bug fixes and dependency updates for the Golang standard library and common package vulnerabilities. The change ships in OPA v1.14.1.

Source
Keycloak26.5.5SecurityMar 5, 2026

This release fixes four disclosed security vulnerabilities involving SAML and identity brokering. The corrections address authentication, identity provider enforcement, broker login, and encrypted assertion handling.

Check if affected (4)

  • securityhighCVE-2026-3047 SAML broker authentication bypass

    Applies if you use SAML broker and configure a disabled SAML client.

  • securityhighCVE-2026-3009 disabled identity provider enforcement

    Applies if you configure Disabled Identity Provider.

  • securityhighCVE-2026-2603 disabled SAML IdP broker login

    Applies if you configure Disabled SAML IdP.

  • + 1 more on the release page
Source
SPIREv1.14.2SecurityMar 3, 2026

Fixes two security vulnerabilities in server node attestor plugins: an SSRF issue and excessive CPU consumption during node attestation. The fixes apply to the http_challenge and x509pop plugins.

Check if affected (2)

  • securityThe http_challenge server node attestor plugin, SSRF issue fixed

    Applies if you use http_challenge.

  • securityThe x509pop server node attestor plugin, CPU-exhaustion issue fixed

    Applies if you use x509pop.

Source
SPIREv1.13.4SecurityMar 3, 2026

A security maintenance release with fixes in server node attestor plugins. The corrected issues affect request handling and resource use during node attestation.

Check if affected (2)

  • securityThe http_challenge server node attestor plugin, SSRF issue corrected

    Applies if you use the http_challenge server node attestor plugin.

  • securityThe x509pop server node attestor plugin, CPU consumption issue corrected

    Applies if you use the x509pop server node attestor plugin.

Source
Browse by month