RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Feb 2026Clear ×
KubeVelav1.10.7CI/CD & App DeliveryFeb 18, 2026

A correctness fix clears removed components from Application status. Deleted components are filtered from status fields, and status arrays are updated when components are removed from the spec.

Source
Open Policy Agent (OPA)v1.13.2SecurityFeb 18, 2026

OPA v1.13.2 updates the Go version used to build its binaries and images. The release includes the Go standard library fix for GO-2026-4337.

Action needed (1)

  • securitycriticalGo 1.25.7 build dependency

    OPA binaries and images are now built with Go 1.25.7. The Go standard library in that version contains a fix for GO-2026-4337.

Source
Litmus3.26.0ObservabilityFeb 18, 2026

Litmus 3.26.0 is a maintenance release focused on operator-visible corrections to UI layout behavior and image-registry validation. Other release-note material concerns headings, duplicate detail, or development and build-only changes.

Source
Crossplanev2.2.0Orchestration & ManagementFeb 17, 2026

A release with breaking changes to package installation and package-cache side-loading, alongside new operator capabilities and ordinary defect corrections. It also includes security-tagged dependency updates, but no advisory identifiers or vulnerability details are provided.

Action needed (7)

  • securitySecurity update for golang.org/x/crypto

    The golang.org/x/crypto module was updated to v0.45.0 as a security update.

  • securitySecurity update for github.com/go-chi/chi/v5

    The github.com/go-chi/chi/v5 module was updated to v5.2.4 as a security update.

  • securitySecurity update for github.com/sigstore/cosign/v3

    The github.com/sigstore/cosign/v3 module was updated to v3.0.4 as a security update.

  • securitySecurity update for github.com/theupdateframework/go-tuf/v2

    The github.com/theupdateframework/go-tuf/v2 module was updated to v2.4.1 as a security update.

  • securitySecurity update for github.com/sigstore/rekor

    The github.com/sigstore/rekor module was updated to v1.5.0 as a security update.

  • securitySecurity update for github.com/sigstore/sigstore

    The github.com/sigstore/sigstore module was updated to v1.10.4 as a security update.

  • securitySecurity update for github.com/quic-go/quic-go

    The github.com/quic-go/quic-go module was updated to v0.57.0 as a security update.

Check if affected (2)

  • breakingInput CRD installation from Function packages

    Applies if you use Function packages and Input CRDs.

  • breakingPackage cache structure

    Applicability is not stated in the release notes.

Source
Linkerdedge-26.2.1Networking & MessagingFeb 17, 2026

This release focuses on dependency and component upgrades. It adds no new operator capabilities or stated security changes, and it requires no setup changes beyond upgrading.

Source
Backstagev1.48.0CI/CD & App DeliveryFeb 17, 2026

A release with breaking API and configuration changes alongside new frontend and catalog capabilities. Operators and plugin authors should review renamed catalog extension imports, rejected cross-plugin API overrides, removed configuration and extension-point behaviors, and the module federation default.

Check if affected (7)

  • breakingStable catalogProcessingExtensionPoint export

    Applies if you use catalogProcessingExtensionPoint when providing custom processors and entity providers into the catalog.

  • breakingRejected CatalogApi and ErrorApi overrides

    Applicability is not stated in the release notes.

  • breakingRemoved auth.experimentalDynamicClientRegistration.tokenExpiration

    Applies if you configure auth.experimentalDynamicClientRegistration.tokenExpiration.

  • + 4 more on the release page

Plan ahead (2)

  • deprecatedDeprecated IconComponent type

    Applies if you use IconComponent.

  • deprecatedDeprecated items prop

    Applies if you use the items prop.

Source
Ciliumv1.19.1Networking & MessagingFeb 17, 2026

Cilium v1.19.1 contains routine bug fixes, performance improvements, and dependency and image updates. The available release information does not identify security advisories or explicitly described security flaws.

Source
Istio1.28.4Networking & MessagingFeb 16, 2026

A maintenance release focused on security fixes, validation, and authorization changes across Istio control-plane and endpoint handling. It also includes operator-facing capability changes and corrections for other defects.

Action needed (1)

  • securityhighCVE-2025-61732 cgo comment parsing flaw

    This release fixes a discrepancy between Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary.

Check if affected (4)

  • securitycriticalCVE-2025-68121 TLS session resumption validation

    Applies if you use Config.Clone with mutations or Config.GetConfigForClient.

  • securityGateway deployment controller resource validation

    Applies if the gateway deployment controller runs.

  • securityResource annotation validation against container injection

    Applies if you configure resource annotations.

  • + 1 more on the release page
Source
Istio1.27.7Networking & MessagingFeb 16, 2026

A security release addressing two vulnerabilities in cgo comment parsing and crypto/tls session resumption. The fixes are relevant to deployments using the affected Go functionality.

Action needed (2)

  • securitycriticalCVE-2025-68121 session resumption vulnerability correction

    CVE-2025-68121 corrects a crypto/tls session resumption flaw that could let resumed handshakes succeed after ClientCAs or RootCAs changed between the initial and resumed handshake.

  • securityhighCVE-2025-61732 code-smuggling vulnerability correction

    CVE-2025-61732 addresses a discrepancy in Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary.

Source
Istio1.29.0Networking & MessagingFeb 16, 2026

A broad release adds operator-visible capabilities across ambient networking, telemetry, Gateway API, and traffic management, while changing several defaults. The most consequential operational changes affect ambient mesh DNS and iptables behavior, debug endpoint authorization, Envoy metrics compression, and istiod memory and circuit-breaker handling.

Action needed (1)

  • breakingAutomatic GOMEMLIMIT setting for istiod

    istiod now automatically sets GOMEMLIMIT to 90% of its memory limits through the automemlimit library. The change ships in 1.29.0.

Check if affected (4)

  • breakingDefault-enabled iptables reconciliation

    Applies when the istio-cni DaemonSet is upgraded.

  • breakingDefault authorization for debug endpoints

    Applies if you use debug endpoints on port 15014.

  • breakingDefault HTTP compression for Envoy metrics

    Applies if you use Envoy metrics at the Prometheus stats endpoint based on client Accept-Header values.

  • + 1 more on the release page
Source
Ciliumv1.18.7Networking & MessagingFeb 13, 2026

A maintenance release combining an operator-facing configuration adjustment with bug fixes and routine dependency and image refreshes. No security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingExclusion of topology.kubernetes.io labels from security labels by default

    The default security-label handling in this release excludes topology.kubernetes.io labels from security labels.

Source
Ciliumv1.17.13Networking & MessagingFeb 13, 2026

This release is focused on dependency and container image maintenance, including a runtime dependency addition and updated installation image digests. No security issues or operator configuration changes are disclosed.

Source
etcdv3.6.8Kubernetes CoreFeb 13, 2026

A maintenance release postpones removal of one flag and reverses another flag's deprecation. It also includes dependency and toolchain updates addressing named security advisories.

Action needed (2)

Plan ahead (1)

  • deprecatedThe --max-snapshots flag, removal postponedremoval planned in v3.8

    Applies if you use --max-snapshots.

Source
etcdv3.5.27Kubernetes CoreFeb 13, 2026

A maintenance release that changes the Go toolchain used to compile binaries. It also includes fixes for three named CVEs and their corresponding GHSA advisories.

Action needed (1)

Source
Daprv1.16.9Orchestration & ManagementFeb 12, 2026

This release includes a Go toolchain dependency upgrade and a corrected Pulsar PubSub subscription-metadata defect. A regression test verifies that metadata is applied to consumer options.

Action needed (1)

  • securityhighThe Go toolchain upgrade to 1.24.13

    Dapr v1.16.9 upgrades Go to 1.24.13. The upgrade addresses advisories GO-2026-4340 and GO-2026-4341.

Source
Kubescapev4.0.1SecurityFeb 12, 2026

A maintenance release contains an operator-facing correctness fix for the isRuleKubescapeVersionCompatible bug with version 4.0.0. The remaining note entries are headings, test changes, or merge metadata.

Source
Thanosv0.41.0ObservabilityFeb 12, 2026

This release combines performance improvements, bug fixes, and new configuration capabilities with a shuffle-sharding behavior change in Receive. It also upgrades Prometheus, deprecates a flag, and makes native histogram ingestion always enabled.

Check if affected (1)

  • breakingReceive shuffle sharding now uses consistent hashing

    Applies if you use Receive.

Source
OpenFGAv1.11.5SecurityFeb 11, 2026

This release includes an operator-facing toolchain update. The change addresses CVE-2025-68121 in OpenFGA v1.11.5.

Action needed (1)

  • securitycriticalThe Go toolchain, updated to 1.25.7

    The Go toolchain is updated to 1.25.7 in OpenFGA v1.11.5 to address CVE-2025-68121.

Source
Vitessv23.0.2Storage & DataFeb 10, 2026

Vitess v23.0.2 is a maintenance release focused on defect corrections and a Go toolchain dependency update. The release also includes a performance-related change in query execution.

Source
Kubernetesv1.32.12Kubernetes CoreFeb 10, 2026

A maintenance release with correctness fixes in device allocation and kubeadm behavior, plus a Go toolchain update. The changes address scheduling races, etcd learner promotion, argument ordering, and Node patch retries.

Source
Kubernetesv1.33.8Kubernetes CoreFeb 10, 2026

A maintenance release corrects operator-relevant behavior across scheduling, kubeadm, logging, and Windows networking. Kubernetes is now built using Go 1.24.12, and no security advisories or security-specific fixes are disclosed.

Source
Kubernetesv1.34.4Kubernetes CoreFeb 10, 2026

A maintenance release focused on correctness fixes and regression repairs across Kubernetes components. It also updates the Go toolchain and changes kubeadm retry behavior.

Source
Kubernetesv1.35.1Kubernetes CoreFeb 10, 2026

A maintenance release with numerous correctness fixes and an enforced feature-gate default change. It also updates the Go toolchain and hnslib dependency, with no disclosed security advisories.

Check if affected (1)

  • breakingThe SchedulerAsyncAPICalls feature gate, disabled by default

    Applies if you use the SchedulerAsyncAPICalls feature gate.

Source
OpenFGAv1.11.4SecurityFeb 10, 2026

OpenFGA v1.11.4 fixes a planner regression in specific scenarios and updates the OpenTelemetry SDK. The SDK change addresses a disclosed issue affecting earlier versions.

Action needed (1)

  • securityThe otel/sdk dependency at v1.40.0

    The otel/sdk dependency is upgraded to v1.40.0 in OpenFGA v1.11.4 to address the issue identified as SNYK-GOLANG-GOOPENTELEMETRYIOOTELSDKRESOURCE-15182758 in earlier versions.

Source
Istio1.27.6Networking & MessagingFeb 10, 2026

This release includes security safeguards for gateway resource creation and pod specification rendering, along with stricter authorization for debug endpoints. It also adds a Helm configuration field and corrects a TLS configuration mapping.

Action needed (1)

  • securityResource annotation validation

    Resource annotation validation now rejects newline and control characters that could inject containers into pod specifications through template rendering.

Check if affected (2)

  • securityGateway deployment controller resource validation

    Applies if the gateway deployment controller runs.

  • breakingNamespace-based authorization for debug endpoints

    Applies if you use debug endpoints on port 15014.

Source
Keycloak26.5.3SecurityFeb 10, 2026

A maintenance release focused on security fixes, with additional ordinary bug corrections. It also includes startup-memory corrections and a removal related to that area.

Action needed (4)

  • securityhighCVE-2026-1609, disabled users obtaining tokens through the JWT Authorization Grant

    Keycloak 26.5.3 fixes an issue where disabled users could still obtain tokens through the JWT Authorization Grant.

  • securityhighCVE-2026-1529, forged invitation JWT enabling cross-organization self-registration

    Keycloak 26.5.3 fixes an issue where a forged invitation JWT could enable self-registration across organizations.

  • securityhighCVE-2026-1486, authentication through disabled identity providers

    Keycloak 26.5.3 fixes a logic bypass in the JWT Authorization Grant that allowed authentication through disabled identity providers.

  • securitymediumCVE-2025-14778, incorrect ownership checks in /uma-policy/

    Keycloak 26.5.3 fixes incorrect ownership checks in the /uma-policy/ endpoint.

Source
OpenCostv1.119.2ObservabilityFeb 9, 2026

OpenCost v1.119.2 contains operator-facing fixes, configuration and cloud-integration changes, logging updates, and third-party dependency upgrades. No security advisories or explicit vulnerability disclosures are present.

Source
Helmv4.1.1Kubernetes CoreFeb 9, 2026

Helm v4.1.1 is a correctness-fix release. The recorded note tail points to fixes for waiting context options, failed-resource handling in kstatus, resource matching behavior, and nil elements during slice copying.

Source
Jaegerv2.15.1ObservabilityFeb 9, 2026

This release removes a deprecated v1 adapter wrapper and changes the default span kind in API v3 operations. The remaining release notes do not describe distinct operator-facing changes.

Action needed (1)

  • breakingDeprecated protofromtraces wrapper removal

    The deprecated protofromtraces wrapper has been removed from v1adapter.

Source
k8gbv0.18.0Kubernetes CoreFeb 7, 2026

k8gb v0.18.0 adds runtime filtering and a Prometheus metric, and corrects several GSLB and DNS behaviors. It also updates dependencies and packaging and adds support features, while CI-only security-pipeline and workflow changes are not operator-facing security fixes.

Source
Jaegerv2.15.0ObservabilityFeb 6, 2026

Jaeger v2.15.0 introduces a breaking constraint for trace and metric storage configuration. It also adds experimental MCP and ClickHouse capabilities, corrects API behavior, and includes an internal implementation change without direct operator impact.

Check if affected (1)

  • breakingTrace and metric storage configuration backend constraint

    Applies if you configure trace or metric storage with more than one backend type.

Source
Rookv1.19.1Storage & DataFeb 5, 2026

A maintenance release with operator-facing removals, default and behavior changes, new CRD fields, expanded configuration support, and dependency updates. No security advisory is disclosed.

Action needed (1)

  • breakingNodes/proxy RBAC enablement removal

    The unnecessary nodes/proxy RBAC enablement is removed.

Check if affected (2)

  • breakingDefault Ceph image pull policy

    Applies if you do not configure ceph image pull policy.

  • breakingAutomated node fencing code removal

    Applies if automated node fencing runs.

Source
wasmCloudwash-v0.43.0Orchestration & ManagementFeb 4, 2026

This release contains no described operator-facing changes. The available release note content consists only of headings and a duplicated release-bot entry.

Source
wasmCloudv1.9.2Orchestration & ManagementFeb 4, 2026

This release changes NATS connection authentication and the component spec feature. Dependency and OCI image base updates are also included.

Action needed (1)

  • breakingThe component spec feature, removed

    The component spec feature is removed in this release.

Source
Vitessv23.0.1Storage & DataFeb 4, 2026

Vitess v23.0.1 is a maintenance release focused on bug fixes and behavior corrections. It also adds CLI and TabletManager capabilities and updates dependencies.

Action needed (1)

  • securityThe golang.org/x/crypto dependency, updated

    Vitess v23.0.1 updates golang.org/x/crypto from 0.42.0 to 0.45.0.

Source
gRPCv1.78.0Networking & MessagingFeb 4, 2026

A maintenance release with defect fixes and compatibility updates across the language integrations, plus changes to Python packaging and logging.

Source
Kubescapev4.0.0SecurityFeb 4, 2026

Kubescape v4.0.0 expands operator capabilities while changing sensing architecture and scan output behavior. It also updates a dependency, improves scan performance, and includes a fix for version handling and injection.

Action needed (1)

  • securityVersion handling and injection fix

    The release fixes version handling and injection in Kubescape v4.0.0.

Source
Vitessv22.0.3Storage & DataFeb 4, 2026

Vitess v22.0.3 is a maintenance release focused on correctness across query serving, replication, tablet management, and orchestration. It also adds new vtbench credential and DemotePrimary force flags and upgrades the Go toolchain; no security fixes are described.

Source
← NewerOlder →
Browse by month