Crossplane v2. is a maintenance release with security fixes delivered through dependency and toolchain updates. It also corrects namespace handling for injected resource references in crossplane render, so rendered output matches reconciler behavior for cluster-scoped XRs.
Action needed (2)
securityPackage signature verification TOCTOU fix, GHSA-mf7q-r4rv-jv94
The package signature verification TOCTOU flaw identified by GHSA-mf7q-r4rv-jv94 is fixed through the
crossplane-runtimev2.dependency bump. The affected code moved from3. 3 crossplanetocrossplane-runtimeduring thev2.milestone, so this fix ships through that dependency in Crossplane3 v2..3. 3 security
Go1.,25. 11 golang., andorg/x/net golang.updatesorg/x/sys The
release-2.branch bumps3 Goto1.and updates25. 11 golang.andorg/x/net golang.for CVE-related security fixes.org/x/sys