Karmada v1.16.3 contains operator-facing defect corrections and a base-image dependency update. No security advisories or security-specific fixes are disclosed.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
Karmada v1.15.6 is a maintenance release focused on operator-relevant bug fixes in scheduling, controller behavior, and resource quota handling. It also updates the Alpine base image from alpine:3. to alpine:3..
This is a maintenance release for Karmada with corrections across operator components and an updated Alpine base image. No security advisories or security-specific fixes are disclosed.
Source ↗A feature and maintenance release adds workload affinity and anti-affinity scheduling, operator and API capabilities, and Helm encryption at rest. It also includes controller and scheduler fixes, dependency and image updates, and deprecations and removals.
Check if affected (4)
breaking
namespacevalidation forspec.resourceSelectors Applies if you use
PropagationPolicyorOverridePolicy.breakingStricter
GroupByLabelKeyvalidation inWorkloadAffinityApplies if you configure
GroupByLabelKeyinWorkloadAffinity.breakingUpdated default Kubernetes and
ETCDimagesApplicability is not stated in the release notes.
- + 1 more on the release page
Plan ahead (3)
deprecatedThe
--cluster-lease-durationflag, deprecatedremoval date not announcedApplies if you use
--cluster-lease-duration.deprecatedThe
--cluster-lease-renew-interval-fractionflag, deprecatedremoval date not announcedApplies if you use
--cluster-lease-renew-interval-fraction.deprecated
Etcd.inLocal. InitImage Karmada Init Configuration, deprecatedremoval date not announcedApplies if you configure
Etcd.inLocal. InitImage Karmada Init Configuration.
A broad feature release adds workflow, component, API, authentication, tracing, configuration, CLI, and observability capabilities, alongside defect fixes and dependency updates. It also deprecates the alpha Bulk PubSub APIs and alpha application callback and includes security fixes.
Action needed (9)
securityGo cryptography dependency updates
The
x/(net/sync/crypto)dependencies are bumped, anddvsekhvalnov/jose2gois pinned.security
Govulnerability fixA vulnerability in
Gois fixed.securityRoot-only UID check
The UID check now checks only the root UID.
securityHTTP path matching and invocation auto-registration
HTTP path matching is fixed to address a cardinality leak, and invocation auto-registration is supported.
securityThe
golang.dependency, updatedorg/x/crypto The
golang.dependency is bumped.org/x/crypto securityThe
github.dependency, updatedcom/docker/docker The
github.dependency is bumped.com/docker/docker securitySecurity fixes
Security fixes ship in the release.
securityThe
github.dependency, updatedcom/coreos/go-oidc/v3 The
github.dependency is bumped.com/coreos/go-oidc/v3 securityNATS vulnerability fix
A vulnerability in NATS is fixed.
Check if affected (3)
security
Placementauthorization for Dapr actor typesApplies if you use
Placement.securityCloudflare worker vulnerability fix
Applies if you use the Cloudflare worker.
breakingScheduler resources removed from the Helm chart
Applies if you use the Helm chart.
Plan ahead (2)
deprecatedAlpha Bulk PubSub APIs and app callback deprecation
Applies if you use
/v1.,0-alpha1/publish/bulk/<pubsub-name>/<topic> BulkPublishEventAlpha1, orOnBulkTopicEventAlpha1.deprecatedThe
OnBulkTopicEventAlpha1callback, deprecatedApplies if you use
OnBulkTopicEventAlpha1.
Flux v2.8.1 is a maintenance release focused on operator-relevant defect fixes and updates to Flux dependencies and components. No security advisories are disclosed.
Source ↗A maintenance release with security fixes in backup restore behavior, along with routine bug fixes, a Go toolchain dependency update, and a performance improvement. The backup changes affect manifest-based external decompression and protection against path traversal during restores.
Check if affected (2)
securitycriticalBackup restore path traversal protection
Applies if you use backup storage.
securityhighManifest-based external decompression default, changed
Applies if you use an external decompressor command and do not pass
--external-decompressor-use-manifest.
A security-focused maintenance release with changes to backup and restore behavior, bug fixes, and additional hardening. Backup MANIFEST handling now requires explicit opt-in for compressor commands, and restore blocks path traversal through MANIFEST files.
Check if affected (2)
securityLoading compressor commands from
MANIFEST, opt-inApplies if you use
--external-decompressor-use-manifest.securityPath traversal through backup
MANIFESTon restore blockedApplies if
backupengineruns.
This maintenance release updates the Kubernetes build toolchain to Go 1.25.7.
Source ↗A maintenance release updates the Kubernetes build toolchain to Go 1.24.13. The recorded change concerns how Kubernetes is built, with no operator-facing feature change described.
Source ↗A maintenance release updates the Go toolchain used to build Kubernetes to Go 1.24.13. Nothing else in the release requires operator attention.
Source ↗A maintenance release updates the Go toolchain used to build Kubernetes to Go 1.24.13. Nothing else here needs operator attention.
Source ↗This release adds runtime and API capabilities, changes supported behavior and output, and corrects several defects. It also updates dependencies, including a fix for GHSA-9h8m-3fm2-qjrq.
Action needed (1)
securityhighThe
go.dependencies, updated for GHSA-9h8m-3fm2-qjrqopentelemetry. io The
go.dependencies include the fix for GHSA-9h8m-3fm2-qjrq.opentelemetry. io
Check if affected (1)
breakingThe
--h2cflag with Unix domain socket supportApplies if you use
--h2cwith unix domain socket (UDS).
Version v1.48.3 is a correctness-fix release for Backstage. It fixes MUI module resolution by correcting the @mui/material/styles shared dependency key and fixes entity page tab groups so they follow the configured ordering.
This release adds Prometheus capabilities and image/build options, changes defaults and outputs, improves performance, and fixes correctness defects. No security advisories or explicitly described vulnerabilities are present.
Check if affected (1)
breakingExpanded alert annotations hidden by default
Applies if you use the UI on the
/alertspage.
OpenKruise v1.8.3 includes a constraint change for probe host configuration. Existing configurations that rely on previously accepted host values may require changes.
Check if affected (1)
breakingThe probe
hostfield, restrictedApplies if your probe configurations use the
hostfield.
A focused release change restricts the host field in probes. The section heading carries no operator-facing change.
Check if affected (1)
breakingProbe
hostfield restrictionApplies if
hostis configured.
This release includes operator-facing behavior and API updates, along with default, image, and dependency changes. It also contains an internal build-tooling update and fixes for storage and gateway handling.
Check if affected (1)
breakingDefault gateway topology spread constraints for
nvmeofApplies if you use
nvmeof.
cert-manager v1. is a patch release focused on fixing reported vulnerabilities, including CVE-2025-68121, through a Go toolchain bump. CVE-2026-24051 is explicitly stated not to affect cert-manager.
Action needed (2)
securitycriticalCVE-2025-68121 vulnerability fix
The
v1.patch release fixes reported vulnerabilities, most notably CVE-2025-68121, in cert-manager.18. 6 securitycritical
Gotoolchain bump for CVE-2025-68121The
Gotoolchain is bumped in cert-managerv1.to address CVE-2025-68121.18. 6
cert-manager v1.19.4 is a patch release focused on reported vulnerabilities and dependency updates. It includes fixes for CVE-2026-24051, CVE-2025-68121, and GO-2026-4394.
Action needed (3)
securitycriticalThe
godependency updateThe
godependency is bumped in cert-manager v1.19.4 to address CVE-2025-68121.securityhighcert-manager v1.19.4 vulnerability fixes
cert-manager v1.19.4 is a patch release addressing reported vulnerabilities, including CVE-2026-24051 and CVE-2025-68121.
securityhighThe
otel SDKdependency updateThe
otel SDKdependency is bumped in cert-manager v1.19.4 to addressGO-2026-4394.
Flux v2.8.0 expands capabilities across controllers, notifications, the CLI, and artifact handling while also including fixes and dependency updates. It removes the deprecated API versions v1beta2 and v2beta2 from CRDs and changes Kubernetes compatibility requirements, so users of those APIs or affected Kubernetes versions are the main audience.
Check if affected (1)
breakingThe Flux APIs
v1beta2andv2beta2, removed fromCRDsApplies if you use the Flux APIs
v1beta2orv2beta2inCRDs.
This release rebuilds the prior Knative release with Go v1.25.7. No operator-facing feature or configuration change is described.
Source ↗Knative v1.21.1 announces a future change to secure pod defaults, while the v1.21 default remains unchanged. The prior release was rebuilt with v1.25.7.
Source ↗This release restores two scaffolder alpha API exports, changes search behavior on first navigation, and updates @microsoft/api-extractor to correct a compatibility defect.
This release changes the default ListObjects pipeline and narrows the requirements for read-only container deployments. It updates grpc-health-probe to address CVE-2025-68121, while the grpc-gateway client migration remains internal-only.
Action needed (1)
securitycriticalThe
grpc-health-probedependency update for CVE-2025-68121The
grpc-health-probedependency is updated tov0.to address CVE-2025-68121.4. 45
Check if affected (1)
breakingInternal HTTP-to-gRPC communication over UDS
Applies if you use
--read-only.
KubeVirt v1.7.1 is a maintenance release focused on correctness fixes, dependency updates, and expanded compatibility. It also adds a metric and alert for ephemeral hotplug volumes.
Source ↗This release fixes the client-side apply migration issue reported in versions 3. and 3.. No security advisories are disclosed.
Action needed (1)
breakingClient-side apply migration failure
The
failed to perform client-side apply migrationissue present in versions3.and3. 0 3.is fixed in this release.3. 1
v0.18.1 is a dependency update release. It includes an update to coredns-plugin for the latest security fixes, alongside other dependency version changes.
Action needed (1)
securityThe
coredns-plugindependency, updated for security fixesThe
coredns-plugindependency is updated to include the latest security fixes in v0.18.1.
A maintenance release tested against Kubernetes 1.32 through 1.34, with runtime resource tuning and a correction to load balancer status handling. It also updates Go to v1.25.7.
Source ↗Contour v1.32.3 updates the Go dependency, corrects an HTTPProxy CRD schema defect, and documents the Kubernetes versions tested with the release. No individual change details are available here.
Source ↗Contour v1.31.4 updates the Go toolchain to v1.24.13 and corrects an HTTPProxy status schema defect that affected load balancer status updates. It is tested against Kubernetes 1.30 through 1.32, and no security advisories are disclosed.
Source ↗A maintenance release with five disclosed security fixes, one new capability, and ten corrected bugs. It contains no operator prerequisites or dependency-manifest entries.
Action needed (2)
securitymediumCVE-2026-0707, authorization header parsing
This release corrects authorization header parsing that could bypass security controls.
securitylowCVE-2025-5416,
keycloak-coreenvironment information disclosureThis release fixes environment information disclosure in
keycloak-core.
Check if affected (4)
securitymediumCVE-2026-2575, excessive
SAMLRequestdecompressionApplies if you use SAML.
securitylowCVE-2026-1190, SAML brokering response delay
Applies if you use SAML brokering.
securitylowCVE-2026-2733, disabled client check for Docker Registry Protocol
Applies if you use the Docker Registry Protocol.
- + 1 more on the release page
Nothing here needs operator attention.
Source ↗This release includes a security fix for CVE-2025-68121, along with defect corrections and dependency updates. It also changes operator-facing defaults and configuration documentation, including a default that now uses a duration string.
Action needed (1)
securitycriticalCVE-2025-68121 security fix
CVE-2025-68121 is fixed in this release.
Check if affected (1)
breakingDefault value and Helm values documentation format change
Applicability is not stated in the release notes.
Fluentd v1.19.2 contains bug fixes, dependency updates, and compatibility improvements. No security advisories or explicitly described security fixes are identified for this release.
Source ↗A maintenance release with two security fixes and a deprecated KafkaUser API field that requires migration. It also includes API conversion fixes, broker certificate output changes, and dependency and container image updates.
Action needed (1)
securityhighCVE-2026-27133 and CVE-2026-27134 security fixes
The release includes security fixes for CVE-2026-27133 and CVE-2026-27134.
Plan ahead (1)
deprecatedThe
.field is deprecatedspec. authorization. acls[]operation Applies if you configure
..spec. authorization. acls[]operation
This release contains an operator-facing defect correction. No detailed change entry is available here.
Source ↗A maintenance release upgrades github. from 5.16.2 to 5.16.5 and corrects runtime version reporting in the release build configuration. The configuration uses . for the runtime version to avoid a confusing message when installing the latest version and running a scan.
Argo CD v3.2.7 is a maintenance release with ordinary bug fixes and a Go dependency update. No security advisory or forced operator action is disclosed.
Source ↗Argo CD v3.3.1 is a maintenance release with correctness fixes and updates to its Kustomize dependency and Ubuntu base image. Operators of self-managing Argo CD installations should account for the documented upgrade prerequisite.
Source ↗