Harbor v2.13.4 fixes an ORM mapping defect and updates Trivy-related components and base images. No security advisory or operator migration is described for this release.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with fixes for warnings caused by removing subchart values and for release suspension when helm uninstall --keep-history is used. No security changes are disclosed.
Helm v4.0.5 is a correctness-fix release covering commands, plugins, dependency handling, watching, rollback, and SDK environment handling. The release also includes a new SDK environment exposure change.
Source ↗A maintenance release with fixes for configuration values that were misinterpreted or incorrectly assigned during reconfiguration. It addresses discovery polling intervals and decision log reporting buffer sizing, with no security issue or additional operator action stated.
Source ↗Keycloak 26.5.1 is a maintenance release with a security fix in the Organization feature. It also contains correctness fixes, a performance improvement, and changes to HTTP responses and realm administration.
Check if affected (1)
securityThe
Organizationfeature account-name exposure fixApplies if you use the
Organizationfeature.
A maintenance release with dependency and component updates plus a correctness fix in the policy controller. Resource watches now log and skip events that cannot be deserialized so the watch can continue.
Source ↗A maintenance release with fixes for networking, policy, proxy, gateway API, and endpoint handling, plus dependency, image, and OCI publishing updates. The Cilium Preflight check no longer includes Envoy Configmaps.
Action needed (1)
breakingCilium Preflight check no longer includes Envoy Configmaps
The
Cilium Preflightcheck no longer includesEnvoy Configmaps. This change ships in v1.18.6.
Rook v1.18.9 includes operator-facing behavior changes, new configuration capabilities, a corrected CSI behavior, and expanded CRD validation. No security advisories are disclosed.
Source ↗This release adds dynamic-module, filter, routing, observability, and certificate capabilities, along with fixes and performance improvements across HTTP, networking, and protocol handling. It also changes HTTP reset behavior, removes runtime guards and legacy code paths, and deprecates the OpenTelemetry access log common_config field.
Action needed (1)
breakingRuntime guards and legacy code paths removed
Multiple runtime guards and legacy code paths are removed in this release.
Check if affected (2)
breakingDefault HTTP reset code changed
Applicability is not stated in the release notes.
breakingDefault upstream protocol error reset handling changed
Applicability is not stated in the release notes.
Plan ahead (1)
deprecatedOpenTelemetry access log
common_configfield deprecatedApplies if you configure
common_config.
Dragonfly v2.4.0 adds scheduling, transfer, preheating, download, and configuration capabilities. It also improves performance and fixes several correctness issues, with no security advisories or explicitly described security flaws present.
Source ↗A maintenance release focused on operator-visible correctness and runtime behavior. It tightens UID checks and startup and sidecar-injection reporting, including success metrics only when an actual patch is generated.
Source ↗A maintenance release with a corrected metric compatibility issue, changes to performance and metric output, and a cleanup-controller fix. It also includes cherry-pick pointers and release-management updates.
Source ↗Linkerd edge-26.1.1 contains dependency, toolchain, CI action, and proxy version updates. No security advisories or operator-facing functional changes are disclosed.
Source ↗A maintenance release with a new regex length constraint, correctness fixes, and plugin capability and behavior changes. It does not disclose a security advisory or explicitly exploitable vulnerability.
Action needed (1)
breakingThe
coreregex length limitcoreadds a length limit for regular expressions.
Prometheus v3.9.1 is a small bug-fix release. It addresses an Agent startup crash and restores scraping relabel keep and drop rules.
Source ↗This release updates histogram collection and TSDB behavior while adding capabilities across the API, PromQL, storage, and UI. It also includes fixes for query handling, storage validation, receivers, and interface behavior.
Action needed (1)
breakingA 10,000-set limit for the TSDB status endpoint
The TSDB status endpoint now limits responses to a maximum of 10,000 sets of statistics.
Check if affected (1)
breakingThe
native-histogramfeature flag has no effectApplies if you set
scrape_native_histogramsto collect Native Histogram samples from exporters.
OpenCost v1.119.1 contains a panic fix and changes to custom-cost configuration behavior. The release also includes internal notes whose details are not described here, with no security advisories identified.
Source ↗Microcks 1.13.2 adds UI, configuration, tracing, and external data-handling capabilities. It also corrects chart calculations, MCP type reflection, PubSub topic handling, and the container image version.
Source ↗OPA v1.12.2 adds a public TemplateString copy method and corrects defects in template-string AST handling and serialization. The changes affect template-string copying, escaped-brace serialization, reference safety, and variable names in template errors.
A substantial feature and maintenance release adds operator capabilities including workflows, JWT authorization grants, organization invitations, OpenTelemetry export, and Windows services. It also updates Quarkus and fixes correctness issues, while changing supported database versions and addressing a vulnerability in brute force detection settings.
Check if affected (2)
securityBrute force detection settings vulnerability, corrected
Applies if you configure brute force detection settings.
breaking
PostgreSQL 13.support removalx Applies if you depend on
PostgreSQL 13..x
Plan ahead (1)
deprecatedFine-Grained Admin Permissions v1, deprecated
Applies if you enable
admin/fine-grained-permissions.
This CRI-O release contains one operator-facing behavior change related to SELinux labels for systemd or init containers. No actionable change details are included here beyond that release-note summary.
Source ↗cri-o v1.34.4 is a correctness-focused maintenance release. It fixes CPU affinity behavior when CPU load balancing is disabled and respects user-specified SELinux labels for systemd or init containers. No security advisories or operator-actionable removals, default changes, or constraint changes are disclosed.
Source ↗Nothing here needs operator attention.
Source ↗A release focused on removing legacy v1 components and storage interfaces, while changing configuration and UI defaults. It also adds or expands experimental storage capabilities and includes fixes for storage behavior and dependency API changes.
Check if affected (9)
breakingRemaining
v1utilities published asv2.versionsx. x Applies if you use
v1 utilities.breakingThe UI theme selector, enabled by default
Applies if you use the UI.
breakingThe
storage/v1/grpcinterface, removedApplies if you use
storage/v1/grpc.- + 6 more on the release page