OPA v1.12.2 adds a public TemplateString copy method and corrects defects in template-string AST handling and serialization. The changes affect template-string copying, escaped-brace serialization, reference safety, and variable names in template errors.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A substantial feature and maintenance release adds operator capabilities including workflows, JWT authorization grants, organization invitations, OpenTelemetry export, and Windows services. It also updates Quarkus and fixes correctness issues, while changing supported database versions and addressing a vulnerability in brute force detection settings.
Check if affected (2)
securityBrute force detection settings vulnerability, corrected
Applies if you configure brute force detection settings.
breaking
PostgreSQL 13.support removalx Applies if you depend on
PostgreSQL 13..x
Plan ahead (1)
deprecatedFine-Grained Admin Permissions v1, deprecated
Applies if you enable
admin/fine-grained-permissions.
This is a security maintenance release for Notary. It updates the golang-jwt dependency to address CVE-2025-30204.
Action needed (1)
securityhigh
golang-jwtupdate for CVE-2025-30204Notary v1.3.2 updates the
golang-jwtdependency to address CVE-2025-30204.