Rook v1.19.3 contains operational behavior changes, dependency updates, and new configuration capabilities. The release note also includes changes to storage, exporter, object store, and CSI components, but no explicit security advisories or security flaws are disclosed.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with an RBAC grant removal, behavioral fixes, and new CephNFS API fields. It also updates exporter and OSD handling, including log collection, reconciliation, cancellation, encrypted OSD key rotation, and container selection.
Check if affected (1)
breakingThe
nodes/proxyRBAC grant, removedApplies if you use
nodes/proxy.
A feature and compatibility release adds registry, cache, signing, profiling, and configuration capabilities. It changes proxy-cache behavior, removes GCR replication, and includes dependency, base-component, and defect corrections.
Action needed (2)
securityBearer token validation
Harbor rejects bearer tokens issued before project creation.
breakingPort
9443removed from the webhook event checkPort
9443is removed from the Harbor IP used for webhook event checks.
Check if affected (2)
breakingThe
pull-through cacheis replaced byproxy cacheApplies if you use
pull-through cachein Harbor.breaking
GCR replicationremovalApplies if you use
GCR replicationin Harbor.
Longhorn v1.11.1 is a maintenance release with operator-relevant correctness fixes, CSI and V2 engine improvements, and compatibility changes. No security advisories or explicitly security-related flaws are disclosed.
Source ↗Dragonfly v2.4.3 is a dependency maintenance release with updates to five third-party dependencies and d7y.. No security advisory or operator-facing behavior change is described.
Bearer tokens issued before project creation are rejected. The release also updates dependencies and components and removes payload data from the configuration audit log.
Action needed (1)
securityRejection of bearer tokens issued before project creation
The security enforcement rejects bearer tokens issued before project creation.
This release updates base images, dependencies, and Trivy components, and changes the audit-log payload. It also rejects bearer tokens issued before project creation.
Action needed (1)
securityBearer tokens issued before project creation rejected
The security fix rejects bearer tokens issued before project creation.
A feature and maintenance release that expands configuration and scheduler capabilities while changing configuration controls and the priorities type. Dependency versions are updated, and no security advisories or explicitly described vulnerabilities are mentioned.
Action needed (1)
breakingThe
prioritiestype, changed toint32The
prioritiestype changed fromstringtoint32in v2.4.2.
Check if affected (1)
breakingThe
Enableflag, removed fromseedPeerApplies if you configure
Enable.