A maintenance release with ordinary bug fixes across agent, chart, controller, and OpenAPI components. No security advisories or operator actions are identified.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release focused on operator-facing defect corrections across Karmada components. It addresses certificate rotation approval, upgrade rendering, and graceful eviction handling.
Source ↗A maintenance release focused on operator-facing bug fixes in cluster management and upgrade paths. It addresses issues that could affect certificate rotation, chart rendering, and workload evacuation.
Source ↗A maintenance release with correctness fixes for dynamic keys in status., an option to disable status validation, and apply-once resource reconciliation and applied-resource tracking. It also updates a debug webhook script for setup tooling.
Jaeger v2.17.0 contains bug fixes, performance improvements, and new or expanded experimental capabilities. It also changes query and configuration behavior. No security advisories or explicitly security-related flaws are disclosed.
Source ↗A maintenance release with a security-relevant gRPC dependency upgrade, Pulsar Avro and JSON schema handling corrections, and a Scheduler cluster recovery fix. It also adds raw payload topic metadata and updates Avro payload conversion and CloudEvents schema registration.
Action needed (1)
securitycriticalThe
google.dependency and CVE-2026-33186 resolutiongolang. org/grpc The affected
google.dependency is upgraded to a version that resolves CVE-2026-33186. The fix ships in this release.golang. org/grpc
Check if affected (2)
breakingRejected
rawPayload=truepublishing to CloudEvents-wrapped topicsApplies if
rawPayloadis set for a CloudEvents-wrapped topic.breakingStructural validation for
.topicsjsonschema Applies if you configure
..jsonschema
A release that narrows supported environments and installation paths while adding storage, attestation, GPU, API, signature, and image-handling capabilities. It also updates guest and image handling, including sealed-secret signatures, cosign signatures with newlines, in-memory LUKS headers, and improved Vault/OpenBao support.
Check if affected (5)
breakingGo support in
CDHremovedApplies if you use
CDH.breaking
Canonical TDX Tech previewsupport removedApplies if you use
Canonical TDX Tech preview.breakingUbuntu version requirement
Applies if you use
Ubuntu 24.or04. 4 (linux-image-generic-hwe-24. 04) 25..10 - + 2 more on the release page
Plan ahead (1)
deprecated
packer imagessupport, planned for removalremoval date not announcedApplies if you use
packer images.
A maintenance release with operator-facing bug fixes in job pod handling, resource snapshots, GPU resources, and scheduler snapshot cloning. It also contains an update with no stated operator-facing impact.
Source ↗A maintenance release with two operator-facing defect fixes: virt-handler now restarts its domain-notify server after an unexpected exit, and VMExport handles long PVC names.
OPA v1.15.1 is a patch release that corrects a backwards-incompatible v1/logging. interface change from v1.15.0. The fix concerns Go module users with custom Logger implementations; binary and Docker image behavior is unchanged.
This is a patch release for Backstage with one new TablePagination API prop and two correctness fixes. The changes concern pagination labeling, relative link resolution, and entity relation cards.
cert-manager v1.20.1 contains bug corrections and a security-related dependency update. The gRPC vulnerability details are limited to the scanner reports, which state that it does not affect cert-manager.
Action needed (1)
securityThe
google.dependency updategolang. org/grpc The
google.dependency is bumped in cert-manager v1.20.1 to address a vulnerability reported by scanners. The report states that the vulnerability does not affect cert-manager.golang. org/grpc
A maintenance release with operator-relevant fixes to application normalization and cached installation IDs. The remaining release note content does not describe additional product changes.
Source ↗A release with operator-facing compatibility changes, including feature removals, aligned chart and application versions, GHCR-only chart distribution, and a changed CRD conversion-webhook default. It also updates dependencies and the Python interpreter to resolve CVEs, with additional defect fixes and new service and architecture capabilities.
Action needed (1)
securityDependency and Python interpreter updates for CVE fixes
Many dependencies and the Python interpreter were updated to resolve CVEs.
Check if affected (6)
breakingCustom error responses and header-case mangling, removed
Applies if you use Ambassador Edge Stack's custom error responses or header-case mangling features.
breakingHelm chart and Emissary version alignment
Applies if you use the Helm chart.
breakingGHCR-only Helm chart distribution
Applies if you use Emissary's Helm charts.
- + 3 more on the release page
OPA v1.15.0 adds pluggable logging and AWS web-identity signing support, changes the custom HTTPAuthPlugin lifecycle contract, and adds TLS certificate reread configuration. It also includes correctness fixes and dependency updates; no security advisories or vulnerability disclosures are stated.
Check if affected (1)
breakingCustom
HTTPAuthPluginlifecycle contractApplies if you use custom
HTTPAuthPluginimplementations.
Dapr v1.17.3 is a maintenance release with two dependency upgrades that resolve reported CVEs. It also includes correctness fixes for actor and service responses, placement dissemination, reconnect behavior, Scheduler participation, metrics, and Windows sidecar startup.
Action needed (2)
securitycriticalThe
google.dependency, updated for CVE-2026-33186golang. org/grpc The
google.dependency is upgraded in this release to resolve CVE-2026-33186.golang. org/grpc securitymediumThe
golang.dependency, updated for CVE-2026-33809org/x/image This release upgrades
golang.from v0.25.0 to v0.38.0, resolving CVE-2026-33809.org/x/image
This release adds TLS, certificate, xDS, and C++ credential capabilities, and changes EventEngine defaults and support. It also corrects an OpenBSD sizing defect and changes RR and WRR connection behavior.
Check if affected (1)
breaking
EventEnginedefaults and fork supportApplies if you use Python or Ruby.
This release updates the Go toolchain and corrects Scheduler and container defects. The recorded Scheduler and Windows fixes require only an upgrade, with no operator configuration changes stated.
Action needed (1)
securityThe
Goversion, updated to 1.25.8Dapr v1.16.11 updates the
Gotoolchain from 1.25.7 to 1.25.8.
This maintenance release includes a security mitigation for CVE-2026-33186 in grpc-go. It also contains ordinary fixes to application behavior and the user interface.
Action needed (1)
securitycritical
grpc-goCVE-2026-33186 mitigationA mitigation for CVE-2026-33186 in
grpc-goships in therelease-3.line.2
Argo CD v3.1.13 focuses on release artifact provenance and maintenance, with a security mitigation, a UI correction, and a dependency update. Container images are signed, and qualifying container images and CLI binaries receive SLSA Level 3 provenance.
Action needed (1)
securitycritical
grpc-goCVE-2026-33186 mitigationThe release includes a mitigation for CVE-2026-33186 in
grpc-gofor release-3.1.
Argo CD v3.3.5 is a maintenance release with six operator-relevant bug fixes and an update to the google. dependency from 1.77.0 to 1.79.3. No security advisories or security-specific fixes are disclosed.
A maintenance release deprecates and removes install., updates the Go toolchain and JSON-RPC dependency, and corrects dashboard and webhook issues. It also includes vulnerability fixes in Go and UI packages.
Action needed (2)
securityGo package updates for vulnerability fixes
Go packages are upgraded to fix vulnerabilities.
securityUI package updates for vulnerability fixes
UI packages are upgraded to fix vulnerabilities.
Check if affected (1)
breakingThe
install.installer, removedsh Applies if you use
install..sh
Plan ahead (1)
deprecatedThe
install.installer, deprecatedsh Applies if you use
install..sh
Rook v1.19.3 contains operational behavior changes, dependency updates, and new configuration capabilities. The release note also includes changes to storage, exporter, object store, and CSI components, but no explicit security advisories or security flaws are disclosed.
Source ↗A maintenance release with an RBAC grant removal, behavioral fixes, and new CephNFS API fields. It also updates exporter and OSD handling, including log collection, reconciliation, cancellation, encrypted OSD key rotation, and container selection.
Check if affected (1)
breakingThe
nodes/proxyRBAC grant, removedApplies if you use
nodes/proxy.
A broad operator-facing feature and maintenance release with API and behavior changes, dependency updates, deprecations, and removals. Monitoring and configuration changes include recording-rule and feature-gate updates, alongside scheduling and security-related behavior changes; no security advisories are reported.
Check if affected (7)
breakingNetwork attachment definition get permissions in the
virt-controllerClusterRole, removedApplicability is not stated in the release notes.
breakingStop requests for paused VMIs, rejected
Applies if you run paused VMIs.
breakingThe
EnableVirtioFsConfigVolumesfeature, graduated to GAApplies if you use the
EnableVirtioFsConfigVolumesfeature gate.- + 4 more on the release page
Plan ahead (4)
deprecatedThe
DisableMDEVConfigurationfeature gate, deprecatedremoval date not announcedApplies if you use the
DisableMDEVConfigurationfeature gate.deprecatedThe
kubevirt_vmi_migration_data_total_bytesmetric, deprecatedApplies if you use the
kubevirt_vmi_migration_data_total_bytesmetric.deprecatedThe
MultiArchitecturefeature gate, deprecatedApplies if you use the
MultiArchitecturefeature gate.- + 1 more on the release page
A maintenance release with multiple security fixes, tighter JWT and MQTT-related enforcement, and dependency manifest updates. It also includes correctness fixes and improvements across networking, monitoring, clustering, and JetStream.
Action needed (1)
breakingJWT size limit
JWTs now have a
1MBsize limit.
Check if affected (13)
securityhighMQTT security fixes
Applies if you use
MQTT.securityhighLeafnode security fix
Applies if you use
leafnodes.securityhighCommand-line credential security fix
Applies if you provide credentials on the command line.
- + 10 more on the release page
A maintenance release with multiple disclosed security fixes, correctness fixes, stricter validation and permission constraints, and dependency and toolchain updates. It also includes fixes across MQTT, JetStream, leafnodes, WebSockets, monitoring, and clustering.
Action needed (1)
breakingThe
JWTsize limitJWTs now have a 1MB size limit.
Check if affected (11)
securityhighCVE-2026-33216, CVE-2026-33217, and CVE-2026-33215 fixes for MQTT systems
Applies if you use MQTT.
securityhighCVE-2026-33218 fix for leafnodes
Applies if you use leafnodes.
securityhighCVE-2026-33247 fix for command-line credentials
Applies if you configure credentials on the command line.
- + 8 more on the release page
A maintenance release fixes a disclosed security vulnerability in Check requests with conditions and caching enabled, which could return incorrect cached results. The fix addresses the interaction between conditional checks and caching.
Check if affected (1)
securitymediumCVE-2026-33729 and GHSA-h6c8-cww8-35hf fixed
Applies if
Checkrequests use conditions and caching is enabled.
A maintenance release with a configurable TLS addition in the release notes. The secure pod default change is announced for a future release, not this one.
Source ↗A maintenance release with security-related dependency updates and removal of the hostPort setting from example manifests. It also documents compatibility testing with Kubernetes 1.32 through 1.34.
Action needed (2)
securitycritical
google.golang. org/grpc v1.update79. 3 google.is updated togolang. org/grpc v1., which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected by this advisory.79. 3 security
Envoyv1.update35. 9 The
Envoydependency is updated tov1.to address security vulnerabilities.35. 9
Check if affected (1)
breakingRemoval of
hostPort: 8002from example manifestsApplies if you use
hostPortin example manifests.
A maintenance release with updated Envoy and gRPC dependencies, plus a change to the example manifests. It is tested against Kubernetes 1.31 through 1.33.
Action needed (2)
securitycritical
google.updated togolang. org/grpc v1.79. 3 google.is updated togolang. org/grpc v1., which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected.79. 3 security
Envoyupdated tov1.34. 13 Envoyis updated tov1.to address security vulnerabilities and improve stability.34. 13
Check if affected (1)
breaking
hostPort: 8002removed from example manifestsApplies if
hostPort: 8002is configured in example manifests.
A maintenance release contains dependency security updates and an example-manifest cleanup. It also documents testing against Kubernetes 1.30 through 1.32.
Action needed (2)
securitycritical
google.updated to v1.79.3 for CVE-2026-33186golang. org/grpc The release updates
google.to v1.79.3, which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected.golang. org/grpc security
Envoyupdated to v1.34.13The release bumps
Envoyto v1.34.13.
Check if affected (1)
breakingEnvoy metrics
hostPort: 8002removed from example manifestsApplies if example manifests use
hostPort: 8002.
This release adds experimental AuthZen 1.0 support and changes observability output for list-objects operations. It also includes fixes for recoverable panics.
Source ↗A maintenance release with operator-relevant bug fixes, new configuration and diagnostic capabilities, and dependency and image updates. Two fixes address security-relevant exposure or policy bypass, and no deprecations or removals are announced.
Check if affected (2)
securityWorld-accessible Envoy admin socket
Applies if
envoyruns.securityIngress policy enforcement for local backends
Applies if you use
ingress policiesandlocal backends.
Cilium v1.18.8 contains one new XDP capability, multiple bug fixes, and dependency and image updates. GKE users should skip this version because of a known regression.
Source ↗A maintenance release with bug fixes, dependency and image updates, improved bugtool output, and a GKE channel fix. The Envoy admin socket fix addresses its world-accessible creation.
Check if affected (1)
securityThe Envoy admin socket's accessibility
Applies if Envoy runs.
This release contains project module maintenance and regenerated protobuf code. Nothing here needs operator attention.
Source ↗wasmCloud v2.0.0 adds operator-facing capabilities, changes CRD locations, updates dependencies, and fixes runtime and CLI behavior. The dependency update addresses the disclosed advisory RUSTSEC-2026-0007.
Action needed (2)
securitymediumLock file update for
RUSTSEC-2026-0007wasmCloud v2.0.0 updates the lock file to address
RUSTSEC-2026-0007.breakingCRD location moved from
templates/crdsto/crdswasmCloud v2.0.0 moves CRDs from
templates/crdsto/crds.
This patch release corrects CIMD redirect URI matching for loopback addresses. No operator configuration change is indicated.
Source ↗A feature and maintenance release that introduces a vendor-neutral API with a user-controlled migration workflow, alongside preview Dynamic Zones support. It also changes Helm and runtime image distribution locations and updates dependencies.
Check if affected (2)
breakingThe
helmrepository, switched to OCIApplies if you use Helm.
breakingThe API group, renamed to
k8gb.io/v1beta1 Applies if you use
k8gb..absa. oss/v1beta1