RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

KubeEdgev1.23.1Provisioning & RuntimeJul 15, 2026

A feature and behavior release that adds Windows and device-management capabilities, changes edge database and node-querying behavior, and updates the Kubernetes dependency. Device status retrieval now uses the new DeviceStatus CRD.

Check if affected (1)

  • breakingThe DeviceStatus CRD for device status retrieval

    Applies if you use the DeviceStatus CRD.

Source
KubeEdgev1.21.2Provisioning & RuntimeJul 15, 2026

This release combines correctness fixes with changes to node-job behavior, operator capabilities, and command workflows. It introduces configuration updates for edge nodes, which are disabled by default and require an EdgeCore restart; no security advisories are identified.

Check if affected (6)

  • breakingThe v1alpha2 NodeUpgradeJob and ImagePrePullJob defaults

    Applies if you use NodeUpgradeJob or ImagePrePullJob.

  • breakingNode-job switching constraint

    Applies if you use NodeUpgradeJob or ImagePrePullJob.

  • breakingThe taskManager node-job module, disabled by default

    Applies if EdgeCore is running.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe v1alpha1 NodeUpgradeJob and ImagePrePullJob jobs, deprecated

    Applies if you use NodeUpgradeJob or ImagePrePullJob.

Source
Envoyv1.39.0Networking & MessagingJul 14, 2026

A broad release with operator-facing changes across configuration, protocols, extensions, networking, and observability. Security fixes address multiple identified CVEs and a GHSA, while changed defaults, stricter input validation, and removed functionality may affect existing deployments.

Check if affected (11)

  • securityhighHTTP/2 header limits and flood protection

    Applies if you use HTTP/2.

  • securityhighHTTP/3 QPACK and content-length security fixes

    Applies if you use HTTP/3.

  • securityhighAdditional protocol, parser, formatter, and decompression security fixes

    Applies if you use DNS query validation, JSON nesting limits, PROXY protocol TLV, the formatter, TCP StatsD, TLS SAN, or Zstd decompression.

  • + 8 more on the release page
Source
Backstagev1.53.0CI/CD & App DeliveryJul 14, 2026

A substantial mixed feature and maintenance release adds backend, frontend, catalog, authentication, webhook, and TechDocs capabilities alongside dependency updates and defect fixes. It also includes operator-visible changes to APIs, configuration validation, OpenAPI tooling, and MCP transport behavior; no security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingOpenAPI breaking change detection with oasdiff

    @useoptic/optic and @useoptic/openapi-utilities have been replaced with oasdiff for OpenAPI breaking change detection.

Check if affected (12)

  • breakingSchema loading rejects invalid imports

    Applicability is not stated in the release notes.

  • breakingThe package schema openapi init and repo schema openapi test commands, removed

    Applies if you use package schema openapi init or repo schema openapi test.

  • breakingMutually exclusive userGroupMember.path and user.filter configuration

    Applies if you configure both userGroupMember.path and user.filter.

  • + 9 more on the release page

Plan ahead (3)

  • deprecatedOpaque entity header extension point deprecation

    Applies if you use the opaque entity header extension point.

  • deprecatedDynamic Client Registration deprecation warning

    Applies if you enable Dynamic Client Registration.

  • deprecatedStable auth.clientIdMetadataDocuments configuration

    Applies if you configure auth.clientIdMetadataDocuments or auth.experimentalClientIdMetadataDocuments.

Source
CoreDNSv1.14.5Kubernetes CoreJul 10, 2026

A release with operator-visible behavior corrections, new capabilities, configuration changes, and updated defaults. The changes span CoreDNS core behavior and multiple plugins, with no security advisories or explicitly described vulnerabilities.

Action needed (1)

  • breakingGo TLS defaults in core

    The core component uses Go TLS defaults in this release.

Check if affected (1)

  • breakingDefault truncate amount for bare truncate

    Applies if you configure truncate.

Source
containerdv2.3.3Kubernetes CoreJul 10, 2026

A maintenance release with an enforced CRI constraint, aligned erofs defaults, correctness and behavior fixes, and dependency updates. It contains no security advisories or explicitly described vulnerabilities.

Check if affected (2)

  • breakingThe CreateContainer constraint for stopped sandboxes

    Applies if you use CreateContainer when the sandbox is not running.

  • breakingThe erofs default mkfs block size

    Applies if you use erofs across platforms.

Source
containerdv2.2.6Kubernetes CoreJul 9, 2026

A maintenance release with CRI and image-distribution fixes. The CRI constraint on CreateContainer requests may require action, while the other fixes take effect through the upgrade.

Action needed (1)

  • breakingCreateContainer rejection for stopped sandboxes

    The CRI now rejects CreateContainer requests when the sandbox is not running. This constraint ships in containerd v2.2.6.

Source
SPIREv1.15.2SecurityJul 9, 2026

A feature and behavior release that adds operator-facing configuration and integration options while changing supported inputs and runtime behavior. It also includes a dependency migration for disclosed CVEs and deprecates no existing operator feature.

Action needed (2)

  • securityMigration from github.com/docker/docker to github.com/moby/moby

    Dependencies from github.com/docker/docker were migrated to their github.com/moby/moby equivalents to resolve CVEs. The migration ships in this release.

  • breakingRPC metrics from agent health check loopback calls

    Agent health check loopback calls no longer emit RPC metrics. This reduces metrics noise in the agent.

Check if affected (1)

  • breakingJWT-SVID serving by the delegated API

    Applies if you use the delegated API for admin or downstream entries.

Source
Keycloak26.7.0SecurityJul 9, 2026

A substantial operator-focused release that adds and promotes APIs, feature gates, administration capabilities, and deployment options. It also includes deprecations and removals, along with fixes for account takeover, log injection and audit forgery, key-attestation bypass, QR-code dimension denial of service, and four CVE-identified vulnerabilities.

Action needed (1)

  • securityPre-account takeover attack exposure

    The release corrects an issue that provided room for pre-account takeover attacks.

Check if affected (19)

Plan ahead (4)

  • deprecatedThe V1 API, deprecated

    Applies if you use V1.

  • deprecatedThe Require Discoverable Credential option, deprecated

    Applies if you configure the Require Discoverable Credential option.

  • deprecatedThe Twitter IDP implementation, deprecated

    Applies if you use the Twitter IDP implementation.

  • + 1 more on the release page
Source
TiKVv8.5.7Storage & DataJul 9, 2026

A feature and maintenance release with new configuration and resource-management capabilities, plus corrections for invalid timestamp handling, memory use, and stability. It also upgrades vulnerable third-party dependencies and aligns compatibility fixes with upstream.

Action needed (1)

  • securityThird-party dependency upgrades for TiKV 8.5

    TiKV 8.5 upgrades vulnerable third-party dependencies and aligns the required compatibility fixes with upstream.

Check if affected (1)

  • breakingInvalid max_ts updates rejected by default

    Applies if you do not set storage.max-ts.action-on-invalid-update.

Source
cert-managerv1.21.0SecurityJul 8, 2026

A feature and maintenance release with operator-facing RBAC, Helm, API, and feature-gate changes, alongside new capabilities and defect corrections. It includes changes to configuration, permissions, certificate issuance, and integrations.

Check if affected (5)

  • securitycert-manager-edit aggregate ClusterRole permission removal, GHSA-8rvj-mm4h-c258

    Applies if you use the cert-manager-edit aggregate ClusterRole.

  • breakingObjectReference API removal

    Applies if you use ObjectReference in an API.

  • breakingPrometheus ServiceMonitor and PodMonitor Helm value removal

    Applies if you configure any of prometheus.servicemonitor.targetPort, prometheus.servicemonitor.path, or prometheus.podmonitor.path.

  • + 2 more on the release page

Plan ahead (2)

  • deprecatedGateway API controller configuration fields

    Applies if you configure any of enableGatewayAPI, enableGatewayAPIListenerSet, gatewayAPI.enabled, or gatewayAPI.enableListenerSet.

  • deprecatedServerSideApply feature gate deprecation

Source
Thanosv0.42.0ObservabilityJul 8, 2026

A release with security corrections, breaking configuration removals, and an output-field rename that may require operator or log-collector changes. It also adds TLS and cache configuration, query and tracing changes, and defect fixes across several Thanos components.

Action needed (1)

  • securitycriticalthanos-community/grpc-go fork update for CVE-2026-33186

    The thanos-community/grpc-go fork is bumped to fix CVE-2026-33186, an authorization bypass via malformed :path headers.

Check if affected (4)

  • securityReceive tenant ID validation

    Applies if you run Receive.

  • breakingQuery-Frontend time_taken field renamed to time_taken_ms

    Applies if you run Query-Frontend.

  • breaking--shipper.ignore-unequal-block-size flag removed

    Applies if you configure --shipper.ignore-unequal-block-size.

  • + 1 more on the release page
Source
gRPCv1.82.1Networking & MessagingJul 8, 2026

A dependency-focused release raises the minimum supported Python protobuf version. The headings contain no operator-facing changes.

Check if affected (1)

  • breakingThe Python protobuf dependency lower bound, raised

    Applies if you use Python.

Source
k8gbv0.20.0Kubernetes CoreJul 3, 2026

k8gb v0.20.0 centers on ZoneDelegation-based DNS management, with TLSRoute and annotation support alongside changes to defaults and naming. The release also includes defect fixes and dependency updates, and no security advisories or vulnerabilities are identified.

Check if affected (4)

  • breakingThe Bootstrap service, removed

    Applies if your configuration uses the Bootstrap service.

  • breakingThe dynamicZones setting, removed

    Applies if your configuration uses dynamicZones.

  • breakingThe doFinalize default, set to false

    Applies if you use doFinalize in ZoneDelegation finalization.

  • + 1 more on the release page
Source
gRPCv1.82.0Networking & MessagingJul 2, 2026

A feature and maintenance release that adds and changes capabilities across Core, PHP, Python, and Ruby, corrects runtime defects, and upgrades protobuf dependencies. The Python 1.82.0 package was removed from PyPI.

Check if affected (1)

  • breakinggRPC Python release 1.82.0, yanked from PyPI

    Applies if you use gRPC Python release 1.82.0.

Source
Harborv2.15.2Storage & DataJul 2, 2026

A maintenance release with a forced internal PostgreSQL major-version upgrade, a redis to valkey cache backend replacement, dependency and component updates, and defect corrections. Token and blob-mount validation is hardened.

Action needed (1)

  • securityToken and blob-mount source validation

    Blob-mount source projects are validated, and tokens without iat are rejected.

Check if affected (2)

  • breakingThe bundled PostgreSQL version, upgraded

    Applies if you use PostgreSQL.

  • breakingThe cache backend, changed from redis to valkey

    Applies if you use redis.

Source
Prometheusv3.13.0ObservabilityJul 1, 2026

A long-term support release with security-related dependency updates, PromQL changes, new APIs and configuration controls, and bug fixes. It also replaces a shipped license artifact and includes performance improvements.

Action needed (2)

  • securitycriticalThe sanitize-html dependency update

    The UI updates sanitize-html to address a cross-site scripting vulnerability, identified as CVE-2026-44990.

  • breakingThe third-party license artifact

    Third-party npm dependency licenses are embedded in the Prometheus binary and served at /assets/third-party-licenses.txt. This replaces the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images.

Check if affected (2)

  • securitymediumRedirect credential forwarding

    Applies if you use scraping, remote read/write, alerting, or service discovery.

  • breakingPromQL duration-expression function names

    Applies if you enable experimental-duration-expr and use min() and max().

Source
wasmCloudv2.5.0Orchestration & ManagementJun 30, 2026

Version v2.5.0 adds runtime and WIT/API capabilities and includes correctness and dependency updates. The release also enables wasip3 by default and includes a quinn-proto fix for RUSTSEC-2026-0185.

Action needed (1)

  • securityhighThe quinn-proto security fix

    The quinn-proto dependency fix ships in wasmCloud v2.5.0 and addresses RUSTSEC-2026-0185.

Check if affected (1)

  • breakingDefault wasip3 enablement with wasmtime 46

    Applies if your workloads use wasip3.

Source
Fluxv2.9.0CI/CD & App DeliveryJun 30, 2026

Flux v2.9.0 removes two deprecated API versions and adds CLI and controller capabilities across several Flux resources. It also changes supported Kubernetes versions, corrects defects, and updates project and third-party dependencies.

Check if affected (1)

  • breakingRemoval of deprecated Flux API versions

    Applies if your CRDs use the image.toolkit.fluxcd.io/v1beta2 or notification.toolkit.fluxcd.io/v1beta2 APIs.

Source
Kubescapev4.0.10SecurityJun 30, 2026

This release removes an orphan CRD, adds operator-facing capabilities and output changes, and corrects runtime, validation, reporting, and scan-processing defects. No security advisories or explicitly exploitable vulnerabilities are disclosed.

Check if affected (1)

  • breakingSecurityException CRD removal

    Applies if you use the SecurityException CRD.

Source
NATSv2.14.3Networking & MessagingJun 29, 2026

A maintenance release with a dependency and toolchain update, broad defect corrections, and behavior improvements across authentication, routing, monitoring, clustering, and JetStream. It also removes JSONP monitoring callbacks and addresses MQTT and authorization-related connection and permission handling.

Check if affected (3)

  • securityNats-Trace-Dest publish permission checks for leaf connections

    Applies if you use Leaf connections.

  • securityMQTT subscribe deny rules on retained message and QoS replay paths

    Applies if you use MQTT.

  • breakingThe JSONP callback support in monitoring endpoints, removed

    Applies if you use JSONP callback support.

Source
NATSv2.12.12Networking & MessagingJun 29, 2026

A maintenance release with dependency updates, operational behavior changes, and correctness fixes across General, MQTT, Monitoring, and JetStream. It also removes JSONP callback support from monitoring endpoints.

Check if affected (1)

  • breakingThe JSONP callback support in monitoring endpoints, removed

    Applies if you use JSONP callback support.

Source
Strimzi1.1.0Networking & MessagingJun 27, 2026

This release adds operator-facing configuration and feature capabilities while updating supported Apache Kafka versions and related integrations. It also changes TLS file handling for KafkaBridge and KafkaMirrorMaker2 and renames entity-operator healthcheck ports, so those areas may require attention.

Check if affected (3)

  • breakingSupport for Kafka 4.1.x removed

    Applies if you use Kafka 4.1.x.

  • breakingPEM-based TLS files for KafkaBridge and KafkaMirrorMaker2

    Applies if you use KafkaBridge or KafkaMirrorMaker2 with TLS authentication or a TLS truststore.

  • breakingEntity-operator healthcheck port names

    Applies if you use entity-operator healthcheck ports.

Source
Open Policy Agent (OPA)v1.18.0SecurityJun 25, 2026

A release with a breaking change to the outbound User-Agent value, along with restored automatic GOMAXPROCS handling and new automatic GOMEMLIMIT support. It also improves formatting and coverage behavior, corrects compiler and runtime defects, and updates dependencies.

Check if affected (1)

  • breakingThe User-Agent header format

    Applies if you configure server-side log filters or WAF rules that exact-match the old string.

Source
Fluentdv1.19.3ObservabilityJun 25, 2026

A maintenance release with bug fixes, behavior changes, and two operator-visible default changes. It also updates a runtime dependency and tightens validation and payload handling; no security vulnerability or advisory is explicitly identified.

Check if affected (2)

  • breakingThe in_monitor_agent visibility default

    Applies if in_monitor_agent runs.

  • breakingThe in_debug_agent local-machine default

    Applies if in_debug_agent runs.

Source
Dragonflyv2.5.0Storage & DataJun 25, 2026

v2.5.0 adds operator-facing capabilities and changes download and proxy behavior. Deprecated API surface is removed and correctness issues are fixed; no security advisory is disclosed.

Action needed (1)

  • breakingHealth checks consolidated to /healthy

    Health checks are consolidated to the /healthy endpoint in v2.5.0.

Check if affected (1)

  • breakingDeprecated V1 preheat API endpoints removed

    Applies if you use the deprecated V1 preheat API endpoints.

Source
Istio1.30.2Networking & MessagingJun 24, 2026

A maintenance release with a changed logging default, operator-facing additions and fixes, and a restriction on pilot-agent metric content types. It also includes Envoy security fixes covering denial-of-service, crashes, validation issues, memory exhaustion, and other vulnerabilities.

Action needed (12)

  • securityhighCVE-2026-47220 crash bug fix

    The Envoy security update fixes the crash bug described by CVE-2026-47220.

  • securityhighCVE-2026-48044 memory exhaustion fix

    The Envoy security update fixes the memory exhaustion vulnerability described by CVE-2026-48044.

  • securityhighCVE-2026-48042 JSON nesting-depth limit

    The Envoy security update limits JSON nesting depth to 1000 through envoy.reloadable_features.limit_json_parser_nesting_depth.

  • securitymediumCVE-2026-47692 bug fix

    The Envoy security update fixes the bug described by CVE-2026-47692.

  • securitymediumCVE-2026-47205 use-after-free crash fix

    The Envoy security update fixes the use-after-free crash described by CVE-2026-47205.

  • securitymediumCVE-2026-48090 asynchronous token callback handling

    The Envoy security update fixes a bug where the asynchronous token change callback could be triggered after the filter had been torn down.

  • securitymediumCVE-2026-47778 Subject Alternative Name validation

    The Envoy security update fixes an issue where Envoy could fail to validate the Subject Alternative Name (SAN).

  • securitymediumCVE-2026-47204 crash and use-after-free fix

    The Envoy security update fixes a crash or use-after-free described by CVE-2026-47204.

  • securitymediumCVE-2026-48497 query name length checking

    The Envoy security update fixes sanity checking of the query name length.

  • securitymediumCVE-2026-47775 padding oracle

    The Envoy security update addresses a padding oracle described by CVE-2026-47775.

  • securityGHSA-p7c7-7c47-pwch denial-of-service fix

    The Envoy security update fixes the denial-of-service vulnerability described by GHSA-p7c7-7c47-pwch.

  • breakingWarn-level message logging

    The message is now logged at warn level.

Check if affected (5)

Source
Envoyv1.38.3Networking & MessagingJun 23, 2026

A maintenance release with multiple disclosed security fixes and a security-related Wasmtime dependency update. It also removes the Intel DLB connection-balancer extension from all builds and disables TLS certificate compression by default.

Action needed (16)

  • securityhighThe com_github_wasmtime dependency update

    The Wasmtime dependency com_github_wasmtime was updated to resolve CVE-2026-47261. The update ships in the WebAssembly build.

  • securityhighREQUESTED_SERVER_NAME crash, CVE-2026-47220

    The REQUESTED_SERVER_NAME crash was corrected in Envoy. The change addresses CVE-2026-47220 and GHSA-j9wh-4qfm-wf2v.

  • securityhighzstd RLE zip bomb, CVE-2026-48044

    The zstd RLE zip bomb issue was corrected in Envoy. The change addresses CVE-2026-48044 and GHSA-m3p9-47wh-88wg.

  • securityhighHighly nested JSON destructor stack overflow, CVE-2026-48042

    The stack overflow in the destructor of highly nested JSON was corrected in Envoy. The change addresses CVE-2026-48042 and GHSA-f24p-rxw2-g6pv.

  • securityhighHTTP/3 to HTTP/1 request smuggling, CVE-2026-48743

    The HTTP/3 to HTTP/1 request smuggling issue involving a headers-only request with a nonzero Content-Length was corrected in Envoy. The change addresses CVE-2026-48743 and GHSA-8phg-2h2q-jgxf.

  • securitymediumAuthz per route crash, CVE-2026-47205

    The Authz per route crash was corrected in Envoy. The change addresses CVE-2026-47205 and GHSA-mvh9-767w-x47j.

  • securitymediumThe ext_proc response issue, CVE-2026-47207

    The ext_proc response handling issue involving one gRPC message was corrected in Envoy. The change addresses CVE-2026-47207 and GHSA-68cv-hq5f-g6xv.

  • securitymediumRouter internal redirects crash, CVE-2026-47221

    The router internal redirects crash was corrected in Envoy. The change addresses CVE-2026-47221 and GHSA-rcff-gw58-pjpr.

  • securitymediumOAuth2 code verifier padding oracle, CVE-2026-47775

    The OAuth2 code verifier padding oracle issue was corrected in Envoy. The change addresses CVE-2026-47775 and GHSA-396h-jpq4-vc7p.

  • securitymediumThe grpc_stats filter segfault, CVE-2026-47204

    The grpc_stats filter segfault on Connect protocol requests to direct_response routes was corrected in Envoy. The change addresses CVE-2026-47204 and GHSA-3jxh-8p6x-7pf6.

  • securitymediumPROXY Protocol v2 skipped TLVs, CVE-2026-47692

    The PROXY Protocol v2 header generator issue involving skipped TLVs and attacker-controlled spillover into the upstream application stream was corrected in Envoy. The change addresses CVE-2026-47692 and GHSA-wh36-hm39-mm3r.

  • securitymediumEmbedded NUL in TLS SAN truncation, CVE-2026-47778

    The embedded NUL issue in TLS SAN truncation that could cause an authorization bypass was corrected in Envoy. The change addresses CVE-2026-47778 and GHSA-f8x4-rw5x-f3r7.

  • securitymediumOAuth2 filter late token completion, CVE-2026-48090

    The OAuth2 filter issue involving late asynchronous token completion after stream teardown was corrected in Envoy. The change addresses CVE-2026-48090 and GHSA-3cj2-c63f-q26f.

  • securitymediumDNS UDP filter abnormal process termination, CVE-2026-48497

    The abnormal process termination in the DNS UDP filter was corrected in Envoy. The change addresses CVE-2026-48497 and GHSA-j6g2-wf95-q66q.

  • securitymediumThe TcpStatsdSink heap buffer overflow, CVE-2026-48706

    The heap buffer overflow in TcpStatsdSink was corrected in Envoy. The change addresses CVE-2026-48706 and GHSA-7q3f-gwg7-j8g4.

  • securityHTTP/3 QPACK blocked decoding, GHSA-p7c7-7c47-pwch

    The HTTP/3 stack issue involving QPACK blocked decoding was corrected in Envoy. The change addresses GHSA-p7c7-7c47-pwch.

Check if affected (2)

  • breakingThe envoy.network.connection_balance.dlb extension removal

    Applies if you use envoy.network.connection_balance.dlb.

  • breakingThe envoy.reloadable_features.tls_certificate_compression_brotli default

    Applies if you do not configure envoy.reloadable_features.tls_certificate_compression_brotli.

Source
Envoyv1.37.5Networking & MessagingJun 23, 2026

A security-focused release with fixes for multiple Envoy components, extensions, protocols, and dependencies. It also disables the broken envoy.network.connection_balance.dlb contrib extension at the Bazel layer for all builds and platforms.

Action needed (1)

  • securityhighcom_github_wasmtime dependency update, CVE-2026-47261

    The com_github_wasmtime dependency was bumped to resolve CVE-2026-47261.

Check if affected (16)

Source
Envoyv1.36.9Networking & MessagingJun 23, 2026

A security-focused release with fixes for crashes, request handling, protocol processing, authentication, and parsing, plus a security-related wasm dependency update. The contrib extension envoy.network.connection_balance.dlb is disabled in all builds.

Action needed (1)

  • securityhighHighly nested JSON destructor stack overflow

    The stack overflow in the destructor of highly nested JSON is corrected in connection with CVE-2026-48042 and GHSA-f24p-rxw2-g6pv.

Check if affected (15)

  • securityhighzstd RLE zip bomb correction

    Applies if you use zstd.

  • securityhighHTTP/3 to HTTP/1 request smuggling

    Applies if you use HTTP/3 and HTTP/1.

  • securityhighcom_github_wasmtime dependency update

    Applies if you use wasm.

  • + 12 more on the release page
Source
Envoyv1.35.13Networking & MessagingJun 23, 2026

A security-focused maintenance release with fixes across filters, protocol handling, request processing, and JSON parsing. It also updates the Wasmtime dependency and disables the contrib extension envoy.network.connection_balance.dlb.

Action needed (1)

  • securityhighHighly nested JSON destructor stack overflow, corrected for CVE-2026-48042

    This release corrects the stack overflow in the destructor of highly nested JSON described by CVE-2026-48042 and GHSA-f24p-rxw2-g6pv.

Check if affected (14)

Source
OpenTelemetryv0.155.0ObservabilityJun 23, 2026

A release that removes stabilized feature gates, updates processor metric names, and changes service configuration APIs. It also adds schema and metadata tooling capabilities and fixes generator defects.

Check if affected (9)

  • breakingThe confightp.framedSnappy feature gate, removed

    Applies if you use confightp.framedSnappy.

  • breakingThe configoptional.AddEnabledField feature gate, removed

    Applies if you use configoptional.AddEnabledField.

  • breakingThe confmap.newExpandedValueSanitizer feature gate, removed

    Applies if you use confmap.newExpandedValueSanitizer.

  • + 6 more on the release page

Plan ahead (1)

  • deprecatedService configuration API deprecations

    Applies if you use service.Settings.CollectorConf or extensioncapabilities.ConfigWatcher.

Source
OpenKruisev1.9.0CI/CD & App DeliveryJun 21, 2026

OpenKruise v1.9.0 adds operator-facing capabilities, upgrades several APIs to v1beta1, and tightens validation for numerical maxUnavailable and maxSurge values. It also includes multiple correctness fixes, with no security advisories or vulnerabilities disclosed.

Check if affected (2)

  • breakingKruise APIs upgraded to v1beta1

    Applies if your manifests use the listed Kruise APIs at v1alpha1.

  • breakingNumerical string values for maxUnavailable and maxSurge rejected

    Applies if you configure numerical string values for maxUnavailable or maxSurge.

Source
Limav2.1.3Kubernetes CoreJun 19, 2026

A maintenance release that changes several defaults, updates dependencies, and fixes multiple security vulnerabilities. It also includes a fallback to scp for remote sources and destinations in auto mode.

Check if affected (5)

  • securitycriticalcontainerd v2.3.2 security fixes

    Applies if you use containerd.

  • securityhighCVE-2026-53657 and GHSA-2j9v-p4xj-cjw2 guest agent socket fix

    Applies if you run a QEMU VM that uses the guest agent socket.

  • breakingcontainerd.user default on non-Linux guests

    Applies if you run non-Linux guests.

  • + 2 more on the release page
Source
containerdv2.2.5Kubernetes CoreJun 18, 2026

A maintenance release with disclosed security fixes, dependency and toolchain updates, and changes to checkpoint and image-processing behavior. User-database reads are bounded in openUserFile, which may reject inputs that previously worked.

Action needed (2)

Source
Strimzi1.0.1Networking & MessagingJun 17, 2026

A release focused on CRD compatibility and Entity Operator watching defaults, with fixes for disclosed security vulnerabilities. It affects deployments using older CRD APIs or configuring cross-namespace watching.

Action needed (2)

Check if affected (2)

  • breakingSupported CRD API versions narrowed

    Applies if you use the v1beta2, v1beta1, or v1alpha1 CRD APIs.

  • breakingEntity Operator cross-namespace watching default

    Applies if you configure STRIMZI_ENTITY_OPERATOR_WATCHED_NAMESPACE_ENABLED or watchedNamespace.

Source
wasmCloudv2.4.0Orchestration & ManagementJun 17, 2026

wasmCloud v2.4.0 adds operator capabilities and configuration options while correcting runtime and tooling behavior. It also changes supported platform behavior and updates dependencies associated with Rust security advisories, so platform-specific users and deployments using the affected crates are most directly concerned.

Action needed (1)

  • securityThe postgres crates, updated for Rust security advisories

    The postgres crates are updated for RUSTSEC-2026-0178, RUSTSEC-2026-1079, and RUSTSEC-2026-0180. This dependency update ships in wasmCloud v2.4.0.

Check if affected (1)

  • breakingwebgpu disabled for s390

    Applicability is not stated in the release notes.

Source
Rookv1.20.1Storage & DataJun 16, 2026

A release with operator-facing configuration and behavior changes, including a new default and cleanup of stale resources. It also includes dependency and feature updates, with no security advisory disclosed.

Check if affected (2)

  • breakingStale MDS and RGW pdbs removed

    Applies if you configure MDS and RGW pdbs.

  • breakingcsi-addons disabled by default

    Applies if you enable csi-addons.

Source
Rookv1.19.7Storage & DataJun 16, 2026

This release updates the default Ceph version and changes operational handling for Helm ownership, stale PDB cleanup, OSD device classes, and post-upgrade releases. It contains no disclosed security advisories.

Check if affected (2)

  • breakingDefault Ceph version 19.2.4

    Applies if you use Ceph.

  • breakingStale MDS and RGW PDB cleanup

    Applicability is not stated in the release notes.

Source
Backstagev1.52.0CI/CD & App DeliveryJun 16, 2026

A broad feature and maintenance release with breaking configuration and API evolution across catalog, scaffolder, TechDocs, frontend, actions, and Kubernetes capabilities. It also includes correctness, performance, reliability, and security-related dependency updates, with migration attention needed for renamed or deprecated settings and APIs.

Action needed (2)

  • securityThe infinispan dependency upgrade

    infinispan was upgraded from ^0.12.0 to ^0.13.0 to address known vulnerabilities.

  • breakingThe unused json-schema runtime dependency, removed

    The unused json-schema runtime dependency has been removed.

Check if affected (7)

  • breakingThe catalog.stitchingStrategy.mode: 'immediate' setting, removed

    Applies if you configure catalog.stitchingStrategy.mode.

  • breakingComboboxProps as a union type

    Applies if you use ComboboxProps.

  • breakingThe default /kubernetes page, removed

    Applies if you use /kubernetes.

  • + 4 more on the release page

Plan ahead (9)

  • deprecatedTop-level Combobox input state props, deprecated

    Applies if you use plain-array options.

  • deprecatedPrevious tokens, deprecatedremoval date not announced

    Applicability is not stated in the release notes.

  • deprecatedThe single-module runCliModule helper, deprecated

    Applies if you use runCliModule.

  • + 6 more on the release page
Source
← NewerOlder →
Browse by month