A maintenance release with improvements to Helm charts, custom resource support, networking, monitoring, and storage behavior. It also includes correctness fixes across scheduling, reconciliation, endpoint handling, account deletion, and logging.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
v1.19.8 is a maintenance release with a security-related dependency update and behavioral improvements. The recorded dependency change updates the vulnerable go text package from v0.37 to a newer version.
Action needed (1)
securityThe
go textpackage, updated from v0.37The
go textpackage is updated from v0.37 to the latest version because v0.37 has a vulnerability. This dependency update ships in v1.19.8.
Dragonfly v2.5.1 adds scheduler and statistics capabilities while correcting runtime and scheduling behavior. It also updates dependencies and changes digest validation to reject non-hex encoded values; no security advisories or explicitly described vulnerabilities are present.
Source ↗A feature and maintenance release with new configuration and resource-management capabilities, plus corrections for invalid timestamp handling, memory use, and stability. It also upgrades vulnerable third-party dependencies and aligns compatibility fixes with upstream.
Action needed (1)
securityThird-party dependency upgrades for TiKV 8.5
TiKV 8.5 upgrades
vulnerable third-party dependenciesand aligns the required compatibility fixes with upstream.
Check if affected (1)
breakingInvalid
max_tsupdates rejected by defaultApplies if you do not set
storage..max-ts. action-on-invalid-update
Rook v1.20.2 includes dependency updates, behavioral changes, and fixes across Ceph, CSI, core, security, and storage operations. The release also tightens the manager NetworkPolicy to ingress-only; no vulnerability or advisory is disclosed.
Source ↗A maintenance release with a forced internal PostgreSQL major-version upgrade, a redis to valkey cache backend replacement, dependency and component updates, and defect corrections. Token and blob-mount validation is hardened.
Action needed (1)
securityToken and blob-mount source validation
Blob-mount source projects are validated, and tokens without
iatare rejected.
Check if affected (2)
breakingThe bundled
PostgreSQLversion, upgradedApplies if you use
PostgreSQL.breakingThe cache backend, changed from
redistovalkeyApplies if you use
redis.
Longhorn v1.11.3 is a maintenance release with multiple correctness fixes and new metrics for LONGHORN_DISTRO. It requires Kubernetes v1.34 or later because the CSI external provisioner was upgraded to v6.3.0.