This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.
Action needed (1)
security
Go1.25.10 dependency updateGois updated to1.for CVE remediation in this release.25. 10
AI-analyzed release notes for CNCF graduated and incubating projects.
This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.
Action needed (1)
securityGo 1.25.10 dependency update
Go is updated to 1. for CVE remediation in this release.
Tekton v1.9.6 contains dependency updates for CVE remediation. The release affects Go and two golang. packages, with no specific advisory identifiers or vulnerability details in the note.
Action needed (3)
securityGo 1.25.10 update
Go is updated to 1. for CVE remediation in v1.9.6.
securitygolang. v0.52.0 update
golang. is updated to v0. for CVE remediation in v1.9.6.
securitygolang. v0.55.0 update
golang. is updated to v0. for CVE remediation in v1.9.6.
Release v1.14.0 adds tracing and observability capabilities and broadens ResolutionRequest resolution support. It also includes correctness fixes, a Go security-related update, and shipped dependency updates.
Action needed (1)
securityGo 1. update
Go is updated to 1. in v1.14.0 for CVE remediation.
A maintenance release with correctness fixes, a security-relevant dependency update, resolver compatibility constraints, metric behavior changes, and additional dependency upgrades. The changes include a restriction on the object types handled by Tekton Resolvers and an update to gRPC.
Action needed (1)
securitycriticalgoogle. updated to 1.79.3 for CVE-2026-33186
The google. dependency is updated from 1.77.0 to 1.79.3 to fix CVE-2026-33186, an authorization bypass caused by a missing leading slash in the :path header.
Check if affected (1)
breakingTekton Resolvers, limited to supported object types
Applies if you use the Resolver API.
Resolving a non-Tekton object now causes ResolutionRequest to fail. Tekton Resolvers only resolve StepActions, Tasks, and Pipelines; custom resolvers or ResolutionRequest users of the Resolver API for other object types no longer function.
Tekton v1.6.3 contains resolver validation and behavior corrections, along with fixes affecting cross-architecture execution and metrics. It also updates dependencies, including a gRPC change for CVE-2026-33186, so resolver users and dependency-sensitive deployments should review the release.
Action needed (1)
securitycriticalThe google. dependency fix for CVE-2026-33186
The google. dependency includes a fix for CVE-2026-33186 in v1.6.3.
Check if affected (1)
breakingTekton Resolver target restrictions
Applies if your ResolutionRequest objects use Tekton Resolvers.
Tekton Resolvers now permit ResolutionRequest objects to resolve only StepAction, Task, and Pipeline resources. This restriction ships in v1.6.3.