RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Feb 2026Clear ×
Karmadav1.16.3Orchestration & ManagementFeb 28, 2026

Karmada v1.16.3 contains operator-facing defect corrections and a base-image dependency update. No security advisories or security-specific fixes are disclosed.

Source
Karmadav1.15.6Orchestration & ManagementFeb 28, 2026

Karmada v1.15.6 is a maintenance release focused on operator-relevant bug fixes in scheduling, controller behavior, and resource quota handling. It also updates the Alpine base image from alpine:3.23.2 to alpine:3.23.3.

Source
Karmadav1.14.10Orchestration & ManagementFeb 28, 2026

This is a maintenance release for Karmada with corrections across operator components and an updated Alpine base image. No security advisories or security-specific fixes are disclosed.

Source
Karmadav1.17.0Orchestration & ManagementFeb 28, 2026

A feature and maintenance release adds workload affinity and anti-affinity scheduling, operator and API capabilities, and Helm encryption at rest. It also includes controller and scheduler fixes, dependency and image updates, and deprecations and removals.

Check if affected (4)

  • breakingnamespace validation for spec.resourceSelectors

    Applies if you use PropagationPolicy or OverridePolicy.

  • breakingStricter GroupByLabelKey validation in WorkloadAffinity

    Applies if you configure GroupByLabelKey in WorkloadAffinity.

  • breakingUpdated default Kubernetes and ETCD images

    Applicability is not stated in the release notes.

  • + 1 more on the release page

Plan ahead (3)

  • deprecatedThe --cluster-lease-duration flag, deprecatedremoval date not announced

    Applies if you use --cluster-lease-duration.

  • deprecatedThe --cluster-lease-renew-interval-fraction flag, deprecatedremoval date not announced

    Applies if you use --cluster-lease-renew-interval-fraction.

  • deprecatedEtcd.Local.InitImage in Karmada Init Configuration, deprecatedremoval date not announced

    Applies if you configure Etcd.Local.InitImage in Karmada Init Configuration.

Source
Daprv1.17.0Orchestration & ManagementFeb 27, 2026

A broad feature release adds workflow, component, API, authentication, tracing, configuration, CLI, and observability capabilities, alongside defect fixes and dependency updates. It also deprecates the alpha Bulk PubSub APIs and alpha application callback and includes security fixes.

Action needed (9)

  • securityGo cryptography dependency updates

    The x/(net/sync/crypto) dependencies are bumped, and dvsekhvalnov/jose2go is pinned.

  • securityGo vulnerability fix

    A vulnerability in Go is fixed.

  • securityRoot-only UID check

    The UID check now checks only the root UID.

  • securityHTTP path matching and invocation auto-registration

    HTTP path matching is fixed to address a cardinality leak, and invocation auto-registration is supported.

  • securityThe golang.org/x/crypto dependency, updated

    The golang.org/x/crypto dependency is bumped.

  • securityThe github.com/docker/docker dependency, updated

    The github.com/docker/docker dependency is bumped.

  • securitySecurity fixes

    Security fixes ship in the release.

  • securityThe github.com/coreos/go-oidc/v3 dependency, updated

    The github.com/coreos/go-oidc/v3 dependency is bumped.

  • securityNATS vulnerability fix

    A vulnerability in NATS is fixed.

Check if affected (3)

  • securityPlacement authorization for Dapr actor types

    Applies if you use Placement.

  • securityCloudflare worker vulnerability fix

    Applies if you use the Cloudflare worker.

  • breakingScheduler resources removed from the Helm chart

    Applies if you use the Helm chart.

Plan ahead (2)

  • deprecatedAlpha Bulk PubSub APIs and app callback deprecation

    Applies if you use /v1.0-alpha1/publish/bulk/<pubsub-name>/<topic>, BulkPublishEventAlpha1, or OnBulkTopicEventAlpha1.

  • deprecatedThe OnBulkTopicEventAlpha1 callback, deprecated

    Applies if you use OnBulkTopicEventAlpha1.

Source
Fluxv2.8.1CI/CD & App DeliveryFeb 27, 2026

Flux v2.8.1 is a maintenance release focused on operator-relevant defect fixes and updates to Flux dependencies and components. No security advisories are disclosed.

Source
Vitessv22.0.4Storage & DataFeb 27, 2026

A maintenance release with security fixes in backup restore behavior, along with routine bug fixes, a Go toolchain dependency update, and a performance improvement. The backup changes affect manifest-based external decompression and protection against path traversal during restores.

Check if affected (2)

  • securitycriticalBackup restore path traversal protection

    Applies if you use backup storage.

  • securityhighManifest-based external decompression default, changed

    Applies if you use an external decompressor command and do not pass --external-decompressor-use-manifest.

Source
Vitessv23.0.3Storage & DataFeb 27, 2026

A security-focused maintenance release with changes to backup and restore behavior, bug fixes, and additional hardening. Backup MANIFEST handling now requires explicit opt-in for compressor commands, and restore blocks path traversal through MANIFEST files.

Check if affected (2)

  • securityLoading compressor commands from MANIFEST, opt-in

    Applies if you use --external-decompressor-use-manifest.

  • securityPath traversal through backup MANIFEST on restore blocked

    Applies if backupengine runs.

Source
Kubernetesv1.32.13Kubernetes CoreFeb 26, 2026

A maintenance release updates the Kubernetes build toolchain to Go 1.24.13. The recorded change concerns how Kubernetes is built, with no operator-facing feature change described.

Source
Open Policy Agent (OPA)v1.14.0SecurityFeb 26, 2026

This release adds runtime and API capabilities, changes supported behavior and output, and corrects several defects. It also updates dependencies, including a fix for GHSA-9h8m-3fm2-qjrq.

Action needed (1)

  • securityhighThe go.opentelemetry.io dependencies, updated for GHSA-9h8m-3fm2-qjrq

    The go.opentelemetry.io dependencies include the fix for GHSA-9h8m-3fm2-qjrq.

Check if affected (1)

  • breakingThe --h2c flag with Unix domain socket support

    Applies if you use --h2c with unix domain socket (UDS).

Source
Backstagev1.48.3CI/CD & App DeliveryFeb 26, 2026

Version v1.48.3 is a correctness-fix release for Backstage. It fixes MUI module resolution by correcting the @mui/material/styles shared dependency key and fixes entity page tab groups so they follow the configured ordering.

Source
Prometheusv3.10.0ObservabilityFeb 26, 2026

This release adds Prometheus capabilities and image/build options, changes defaults and outputs, improves performance, and fixes correctness defects. No security advisories or explicitly described vulnerabilities are present.

Check if affected (1)

  • breakingExpanded alert annotations hidden by default

    Applies if you use the UI on the /alerts page.

Source
OpenKruisev1.8.3CI/CD & App DeliveryFeb 25, 2026

OpenKruise v1.8.3 includes a constraint change for probe host configuration. Existing configurations that rely on previously accepted host values may require changes.

Check if affected (1)

  • breakingThe probe host field, restricted

    Applies if your probe configurations use the host field.

Source
OpenKruisev1.7.5CI/CD & App DeliveryFeb 25, 2026

A focused release change restricts the host field in probes. The section heading carries no operator-facing change.

Check if affected (1)

  • breakingProbe host field restriction

    Applies if host is configured.

Source
Rookv1.19.2Storage & DataFeb 24, 2026

This release includes operator-facing behavior and API updates, along with default, image, and dependency changes. It also contains an internal build-tooling update and fixes for storage and gateway handling.

Check if affected (1)

  • breakingDefault gateway topology spread constraints for nvmeof

    Applies if you use nvmeof.

Source
cert-managerv1.18.6SecurityFeb 24, 2026

cert-manager v1.18.6 is a patch release focused on fixing reported vulnerabilities, including CVE-2025-68121, through a Go toolchain bump. CVE-2026-24051 is explicitly stated not to affect cert-manager.

Action needed (2)

  • securitycriticalCVE-2025-68121 vulnerability fix

    The v1.18.6 patch release fixes reported vulnerabilities, most notably CVE-2025-68121, in cert-manager.

  • securitycriticalGo toolchain bump for CVE-2025-68121

    The Go toolchain is bumped in cert-manager v1.18.6 to address CVE-2025-68121.

Source
cert-managerv1.19.4SecurityFeb 24, 2026

cert-manager v1.19.4 is a patch release focused on reported vulnerabilities and dependency updates. It includes fixes for CVE-2026-24051, CVE-2025-68121, and GO-2026-4394.

Action needed (3)

  • securitycriticalThe go dependency update

    The go dependency is bumped in cert-manager v1.19.4 to address CVE-2025-68121.

  • securityhighcert-manager v1.19.4 vulnerability fixes

    cert-manager v1.19.4 is a patch release addressing reported vulnerabilities, including CVE-2026-24051 and CVE-2025-68121.

  • securityhighThe otel SDK dependency update

    The otel SDK dependency is bumped in cert-manager v1.19.4 to address GO-2026-4394.

Source
Fluxv2.8.0CI/CD & App DeliveryFeb 24, 2026

Flux v2.8.0 expands capabilities across controllers, notifications, the CLI, and artifact handling while also including fixes and dependency updates. It removes the deprecated API versions v1beta2 and v2beta2 from CRDs and changes Kubernetes compatibility requirements, so users of those APIs or affected Kubernetes versions are the main audience.

Check if affected (1)

  • breakingThe Flux APIs v1beta2 and v2beta2, removed from CRDs

    Applies if you use the Flux APIs v1beta2 or v2beta2 in CRDs.

Source
Knativeknative-v1.20.3Orchestration & ManagementFeb 24, 2026

This release rebuilds the prior Knative release with Go v1.25.7. No operator-facing feature or configuration change is described.

Source
Knativeknative-v1.21.1Orchestration & ManagementFeb 24, 2026

Knative v1.21.1 announces a future change to secure pod defaults, while the v1.21 default remains unchanged. The prior release was rebuilt with v1.25.7.

Source
Backstagev1.48.2CI/CD & App DeliveryFeb 24, 2026

This release restores two scaffolder alpha API exports, changes search behavior on first navigation, and updates @microsoft/api-extractor to correct a compatibility defect.

Source
OpenFGAv1.11.6SecurityFeb 23, 2026

This release changes the default ListObjects pipeline and narrows the requirements for read-only container deployments. It updates grpc-health-probe to address CVE-2025-68121, while the grpc-gateway client migration remains internal-only.

Action needed (1)

  • securitycriticalThe grpc-health-probe dependency update for CVE-2025-68121

    The grpc-health-probe dependency is updated to v0.4.45 to address CVE-2025-68121.

Check if affected (1)

  • breakingInternal HTTP-to-gRPC communication over UDS

    Applies if you use --read-only.

Source
KubeVirtv1.7.1Orchestration & ManagementFeb 23, 2026

KubeVirt v1.7.1 is a maintenance release focused on correctness fixes, dependency updates, and expanded compatibility. It also adds a metric and alert for ephemeral hotplug volumes.

Source
Argov3.3.2CI/CD & App DeliveryFeb 22, 2026

This release fixes the client-side apply migration issue reported in versions 3.3.0 and 3.3.1. No security advisories are disclosed.

Action needed (1)

  • breakingClient-side apply migration failure

    The failed to perform client-side apply migration issue present in versions 3.3.0 and 3.3.1 is fixed in this release.

Source
k8gbv0.18.1Kubernetes CoreFeb 21, 2026

v0.18.1 is a dependency update release. It includes an update to coredns-plugin for the latest security fixes, alongside other dependency version changes.

Action needed (1)

  • securityThe coredns-plugin dependency, updated for security fixes

    The coredns-plugin dependency is updated to include the latest security fixes in v0.18.1.

Source
Contourv1.33.2Networking & MessagingFeb 20, 2026

A maintenance release tested against Kubernetes 1.32 through 1.34, with runtime resource tuning and a correction to load balancer status handling. It also updates Go to v1.25.7.

Source
Contourv1.32.3Networking & MessagingFeb 20, 2026

Contour v1.32.3 updates the Go dependency, corrects an HTTPProxy CRD schema defect, and documents the Kubernetes versions tested with the release. No individual change details are available here.

Source
Contourv1.31.4Networking & MessagingFeb 20, 2026

Contour v1.31.4 updates the Go toolchain to v1.24.13 and corrects an HTTPProxy status schema defect that affected load balancer status updates. It is tested against Kubernetes 1.30 through 1.32, and no security advisories are disclosed.

Source
Keycloak26.5.4SecurityFeb 20, 2026

A maintenance release with five disclosed security fixes, one new capability, and ten corrected bugs. It contains no operator prerequisites or dependency-manifest entries.

Action needed (2)

  • securitymediumCVE-2026-0707, authorization header parsing

    This release corrects authorization header parsing that could bypass security controls.

  • securitylowCVE-2025-5416, keycloak-core environment information disclosure

    This release fixes environment information disclosure in keycloak-core.

Check if affected (4)

Source
Kyvernov1.17.1SecurityFeb 19, 2026

This release includes a security fix for CVE-2025-68121, along with defect corrections and dependency updates. It also changes operator-facing defaults and configuration documentation, including a default that now uses a duration string.

Action needed (1)

  • securitycriticalCVE-2025-68121 security fix

    CVE-2025-68121 is fixed in this release.

Check if affected (1)

  • breakingDefault value and Helm values documentation format change

    Applicability is not stated in the release notes.

Source
Fluentdv1.19.2ObservabilityFeb 19, 2026

Fluentd v1.19.2 contains bug fixes, dependency updates, and compatibility improvements. No security advisories or explicitly described security fixes are identified for this release.

Source
Strimzi0.50.1Networking & MessagingFeb 19, 2026

A maintenance release with two security fixes and a deprecated KafkaUser API field that requires migration. It also includes API conversion fixes, broker certificate output changes, and dependency and container image updates.

Action needed (1)

Plan ahead (1)

  • deprecatedThe .spec.authorization.acls[]operation field is deprecated

    Applies if you configure .spec.authorization.acls[]operation.

Source
Kubescapev4.0.2SecurityFeb 18, 2026

A maintenance release upgrades github.com/go-git/go-git/v5 from 5.16.2 to 5.16.5 and corrects runtime version reporting in the release build configuration. The configuration uses .Tag for the runtime version to avoid a confusing message when installing the latest version and running a scan.

Source
Argov3.2.7CI/CD & App DeliveryFeb 18, 2026

Argo CD v3.2.7 is a maintenance release with ordinary bug fixes and a Go dependency update. No security advisory or forced operator action is disclosed.

Source
Argov3.3.1CI/CD & App DeliveryFeb 18, 2026

Argo CD v3.3.1 is a maintenance release with correctness fixes and updates to its Kustomize dependency and Ubuntu base image. Operators of self-managing Argo CD installations should account for the documented upgrade prerequisite.

Source
Older →
Browse by month