This release contains an operator-facing correction to the Docker release images. No individual change details are available beyond that release-note heading.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A security maintenance release corrects a Helm Chart extraction defect tied to GHSA-hr2v-4r36-88hr. The changelog also contains a duplicate mention of this advisory-backed fix.
Check if affected (1)
securitymediumGHSA-hr2v-4r36-88hr: Helm Chart extraction output directory collapse
Applies if you use Helm Chart extraction.
A maintenance release with routine dependency updates and the Linkerd proxy updated to v2.348.0. The release notes contain no explicit security advisories or security claims.
Source ↗This release contains two security updates whose affected vulnerabilities are not identified. It also adds experimental incremental updates for gRPC synchronization.
Action needed (1)
securityThe
vulnerability-updatessecurity updateOpenFeature Core v0.15.2 includes a security update for
vulnerability-updates.
This release contains security updates for flagd-proxy/v0.. The available notes do not identify the affected vulnerabilities or describe their scope.
Action needed (2)
securityThe
vulnerability-updatesentry for issue#1933The
vulnerability-updatesentry records a security update forflagd-proxy/v0., tracked in issue9. 4 #1933. The notes do not describe the affected vulnerability.securityThe
vulnerability-updatesentry for issue#1934The
vulnerability-updatesentry records a security update forflagd-proxy/v0., tracked in issue9. 4 #1934. The notes do not describe the affected vulnerability.
This release includes two undisclosed security updates and a new experimental gRPC incremental-update capability. The gRPC capability adds experimental incremental updates to synchronization.
Action needed (2)
securityThe
vulnerability-updatesentry for#1933The
vulnerability-updatesentry associated with issue#1933is updated in this release.securityThe
vulnerability-updatesentry for#1934The
vulnerability-updatesentry associated with issue#1934is updated in this release.
Falco 0.43.1 updates build component versions. The release note discloses no security changes.
Source ↗A maintenance release with security fixes affecting Helm plugins. It also changes plugin-load error handling in the CLI and getter paths.
Action needed (1)
securitymediumGHSA-hr2v-4r36-88hr security fix
GHSA-hr2v-4r36-88hr is addressed in this release.
Check if affected (2)
securityhighPlugin verification when
.is missingprov Applies if you use plugins.
securityhighPlugin metadata version path traversal
Applies if you use plugins.
This release updates the Go dependency and toolchain to address multiple disclosed CVEs. It concerns deployments that rely on the release's bundled Go version.
Action needed (1)
securitycriticalThe
Gotoolchain, updated to1.26. 2 The release updates the
Gotoolchain to1.to address CVE-2026-32282, CVE-2026-32289, CVE-2026-33810, CVE-2026-27144, CVE-2026-27143, CVE-2026-32288, CVE-2026-32283, CVE-2026-27140, and CVE-2026-32281.26. 2
This release updates the Go dependency to address multiple disclosed CVEs. It concerns deployments that receive their Go runtime or builds from this release.
Action needed (1)
securitycriticalThe
Godependency, upgraded to1.25. 9 The release upgrades
Goto1.to address CVE-2026-32282, CVE-2026-32289, CVE-2026-27144, CVE-2026-27143, CVE-2026-32288, CVE-2026-32283, CVE-2026-27140, and CVE-2026-32281. The update ships in this release.25. 9
This release updates the Go toolchain used to build OPA binaries and images. It also includes multiple security fixes in that Go version.
Action needed (1)
securityThe
Gotoolchain, updated to 1.26.2The
Goversion used to build OPA binaries and images is updated to1.. This26. 2 Goversion contains multiple security fixes.
A substantial operator-facing feature and maintenance release adds new capabilities, configuration and deployment options, performance improvements, and many bug fixes. It also changes selected defaults, deprecates Token Exchange v1, and includes security and correctness fixes for authorization, identity and URL handling, SCIM, anti-phishing checks, and UMA token validation.
Action needed (6)
securitySeparate password and OTP brute force protection
Password and OTP brute force protection are now separate by default to prevent OTP bypass attacks.
security
ResourceAdminManagerURL construction validationURL construction in
ResourceAdminManageris validated against matrix parameter injection.securityClient retrieval anti-ID phishing check
Client retrieval now includes the missing anti-ID phishing check.
breaking
Zero-downtime patch releasesenabled by defaultZero-downtime patch releasesare now promoted to supported and enabled by default.breaking
--truststore-kubernetes-enabledenabled by defaultThe behavior controlled by
--truststore-kubernetes-enabledis enabled by default.breakingTen-second default not-before validation
The default not-before validation period is now 10 seconds instead of 0.
Check if affected (7)
security
Workflowsadmin permission boundariesApplies if you use
Workflows.security
Organizationslogin IdP alias disclosureApplies if you use
Organizations.securitySCIM PUT body ID override protection
Applies if you use
SCIM.- + 4 more on the release page
Plan ahead (1)
deprecatedToken Exchange v1 deprecation
Applies if you use
Token Exchange v1.
Release 0.15.1 fixes a memory leak caused by unbounded metrics cardinality and updates a dependency for an undisclosed security fix. The dependency update ships in the core v0.15.1 release.
Action needed (1)
securityThe
github.dependency updatecom/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 for a security fix. This change ships in core v0.15.1.com/go-jose/go-jose/v4
This release includes a security update to the github. dependency. The release note does not disclose the nature of the vulnerability.
Action needed (1)
security
github.updated to v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 in flagd-proxy v0.9.3 as a security fix. The note does not disclose the nature of the vulnerability.com/go-jose/go-jose/v4
This release fixes RPC flag defaulting, metrics-server process handling, and unbounded metrics cardinality. It also updates a dependency for an undisclosed security fix, which is the main consideration for users evaluating the release.
Action needed (1)
securityThe
github.dependency, updated to v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 incom/go-jose/go-jose/v4 flagd/v0.for an undisclosed security fix.15. 1
Flux v2.8.5 is a maintenance release with bug fixes, clearer error reporting, added verification and authentication configuration, and updated toolkit components. No security advisories or explicitly described security vulnerabilities are present.
Source ↗A maintenance release fixes a startup failure in OTLP HTTP tracing when insecure: true is configured.
A maintenance release with fixes for Windows support in flux build ks and flux diff ks, plus corrected --source flag validation in the create kustomization command. It also updates fluxcd/pkg dependencies.
This is a patch release for Backstage with operator-relevant correctness fixes. The recorded note tail points to fixes for OAuth 2.0 metadata URL handling, the legacy-frontend-plugin template name, and permissions on the scaffolder plugin's /. endpoint.
A maintenance release contains fixes for control-plane and networking behavior, including startup compatibility, policy matching, Gateway API routing, and intermittent proxy error logs. Operators using these areas may see changes in behavior.
Source ↗This release adds an operator-facing histogram metric and ListObjects performance improvements, fixes PostgreSQL and ListObjects defects, and addresses improper BatchCheck policy enforcement. Playground users face a breaking authentication constraint, while the built-in Playground and its port settings are deprecated.
Action needed (1)
securitymedium
BatchCheckpolicy enforcement fix for CVE-2026-34972The issue was fixed where
BatchCheckcalls with multiple checks for the same tuple could result in improper policy enforcement. The fix addresses CVE-2026-34972 and GHSA-jwvj-g8pc-cx45.
Check if affected (1)
breaking
Playgroundauthentication limited tononeApplies if the
Playgroundruns withpresharedkey authentication.
Plan ahead (2)
deprecatedBuilt-in OpenFGA Playground deprecationremoval date not announced
Applies if you use the built-in OpenFGA Playground.
deprecated
--playground-portandOPENFGA_PLAYGROUND_PORTdeprecationApplies if you configure
--playground-portorOPENFGA_PLAYGROUND_PORT.
A release with Windows artifacts, broader guest and template configuration support, and changed vz audio handling. It also updates the bundled nerdctl distribution and dependencies, including security updates in BuildKit and CNI plugins that are obtained by upgrading.
Check if affected (1)
security
BuildKitandCNI pluginssecurity updatesApplies if you use
BuildKitorCNI plugins.
This Linkerd release includes proxy correctness fixes, operator-visible configuration changes, and added multicluster resources. It also updates dependencies and component versions, with no security advisories or explicitly described vulnerabilities.
Source ↗A security maintenance release fixes seven disclosed vulnerabilities. It also upgrades Quarkus and corrects an error caused by requests without a Host header.
Action needed (1)
securitymediumCVE-2026-1002 static handler component cache
CVE-2026-1002 fixes a flaw in the
io.static handler component cache that could deny access to static files.vertx/vertx-core
Check if affected (6)
securityhighCVE-2026-4634 scope processing
Applies if you use Scope Processing.
securityhighCVE-2026-4636 UMA policy resource injection
Applies if you use UMA.
securityhighCVE-2026-3872 OIDC redirect URI validation
Applies if you use OIDC.
- + 3 more on the release page
A broad release with new service discovery, PromQL, TSDB, and UI capabilities, alongside performance, dependency, output, and correctness changes. It also deprecates legacy Hetzner discovery labels and corrects TSDB retention-time handling.
Check if affected (1)
breakingThe
storage.unit handlingtsdb. retention. time Applies if you configure
storage..tsdb. retention. time
Plan ahead (2)
deprecatedThe
__meta_hetzner_datacenterlabel, deprecatedremoval date not announcedApplies if you use
__meta_hetzner_datacenter.deprecatedThe Hetzner Cloud datacenter location labels, deprecated
Applies if you use
__meta_hetzner_hcloud_datacenter_locationor__meta_hetzner_hcloud_datacenter_location_network_zone.
Nothing here needs operator attention.
Source ↗A maintenance release with configuration for additional read-only artifact stores and changed image pull behavior. It fixes metric reporting, prevents regular images from entering the OCI artifact store, and applies pinned image configuration consistently.
Source ↗Nothing here needs operator attention.
Source ↗A maintenance release that adds a Host pod reconciler and winget packaging, upgrades the wasmtime dependency, and changes install-script behavior for the stable v2 release.
Source ↗A maintenance release with changes to authorization behavior and an etcdctl endpoint command regression. The recorded release notes also include headings and documentation updates.
A maintenance release that widens access to existing etcdserver operations and corrects an etcdctl endpoint command regression when --cluster is used with authentication enabled.
A maintenance release with a permission constraint adjustment and a fix for an etcdctl regression when authentication is enabled. It also contains documentation and usage instructions.
This release changes fractional bucketing behavior. The release note does not state what operator setup, if any, must change.
Source ↗A fractional bucketing update changes pseudorandom assignments without changing the API. Consistent assignments require all providers to be updated.
Check if affected (1)
breakingFractional pseudorandom bucketing assignments
Applies if you use providers.