A maintenance release with operator-relevant fixes for chart upgrades, recovered-cluster resource watching, scheduling, and cluster readiness handling. The remaining release-note entries are headings without standalone operator-facing changes.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
Karmada v1.16.6 is a maintenance release with operator-focused bug fixes. The note tail indicates fixes in cluster resource watching, scheduling under resource pressure, and transient cluster client failures, with no disclosed security advisories or security-specific fixes.
Source ↗A maintenance release with fixes in karmada-search and karmada-controller-manager. It addresses delayed watch updates for recovered clusters and transient cluster-client failures during credential rotation.
A feature and maintenance release that adds overflow scheduling and scheduling overcommit protection, along with API, default, constraint, metric, and flag changes. It also includes a security-related alpine base-image update and numerous defect corrections.
Action needed (1)
securityThe
alpinebase image updateThe
alpinebase image has changed fromalpine:3.to23. 3 alpine:3.to address security concerns.23. 4
Check if affected (9)
breakingThe
overflowAffinitiesfieldApplies if you configure
overflowAffinities.breakingStricter
clusterTolerationsoperator validationApplies if you set
spec.withplacement. clusterTolerations LtorGt.breakingThe operator's default verbosity level
Applies if you run the operator.
- + 6 more on the release page
This Linkerd release contains dependency version updates. No functional or security changes are stated, and the dependency updates are applied as part of the release without operator setup changes.
Source ↗A maintenance release includes a fix for a panic when sync processes an S3 URI with a query string.
A maintenance release fixes a panic when an s3 URI contains a query string. No security advisory or setup change is indicated.
A maintenance release with dependency updates, correctness fixes, and new cloud and query capabilities. Configuration and output behavior also change, along with a Go dependency upgrade for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.
Action needed (1)
securityhighGo dependency upgrades for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986
Go dependencies are upgraded for GHSA-xmrv-pmrh-hhx2 and CVE-2026-34986.
Check if affected (1)
breakingThe
MCP_SERVER_ENABLEDdefault isfalseApplies if you do not configure
MCP_SERVER_ENABLED.
A maintenance release focused on corrected defects in data access and repository integrations, plus runtime dependency packaging behavior. The release heading contains no additional operator-facing change details.
Source ↗A release with Trustee, KBS, attestation, and platform-support changes, plus a security advisory fix. It also deprecates several CAA components and images planned for removal in 0.22.
Action needed (1)
securityGHSA-84rc-2q4r-45pc advisory fix
The release patches GHSA-84rc-2q4r-45pc in the guest components.
Plan ahead (4)
deprecated
packer-built CAA podvm imagedeprecationdeprecated since 0.17 · removal planned in 0.22Applies if you use the
packer-built CAA podvm image.deprecated
CAA docker providerdeprecationdeprecated since 0.20 · removal planned in 0.22Applies if you use the
CAA docker provider.deprecated
Fedora-based mkosi-built CAA podvm imagedeprecationdeprecated since 0.20 · removal planned in 0.22Applies if you use the
Fedora-based mkosi-built CAA podvm image.- + 1 more on the release page
This release updates dependencies and component versions across Linkerd. It also corrects resource labels in policy-k8s outbound indexer logs.
Source ↗grpc v1.81.0 fixes three correctness issues and changes the default state of the error_flatten experiment. It also includes an internal SSL implementation change with no stated operator impact.
A broad maintenance release with correctness fixes, new CLI and reporting capabilities, anonymization updates, a performance improvement, added validation, and dependency refreshes. It also includes security fixes alongside changes to output and push defaults.
Action needed (3)
securityDependency updates for security advisories
Dependencies are updated to address security advisories.
security
EnvFromclearing in container data removalremoveContainersDatanow clearsEnvFromto prevent secret name leakage.security
Env[].clearing in container data removalValueFrom removeContainersDataandremoveEphemeralContainersDatanow clearEnv[]..ValueFrom
Check if affected (3)
security
/v1/resultsaccess control hardeningApplies if you use
/v1/results.breakingThe
pdf/html outputdefault changed to file outputApplies if you use
pdf/html output.breakingThe
pushdefault changed to opt-inApplies if you use
push.
A maintenance release corrects a workflow retentioner defect and constrains forwarded-host handling during Sentry OIDC discovery. The discovery change affects deployments that use Sentry OIDC.
Check if affected (1)
securityConstrained
X-Forwarded-Hostuse during Sentry OIDC discoveryApplies if you use Sentry OIDC.
This is a broad operator-focused multi-cloud release with additions and extensions across AWS, Azure, and especially GCP. It also includes defect fixes and dependency updates, with no security advisories or explicit vulnerability disclosures noted.
Check if affected (1)
breakingThe
json-difffilter foraws., removediam-access-key Applies if your policies use the
json-difffilter onaws..iam-access-key
SPIRE v1.15.1 includes a security correction for Azure IMDS node attestation. The release also updates the golang. and golang. dependencies.
Check if affected (1)
securityAzure IMDS node attestation validation
Applies if you use the
azure_imdsserver node attestor plugin.
The release note contains a new-features heading but does not describe a specific operator-facing change.
Source ↗This release adds support for custom headers in the OpenFeature flagd proxy. The recorded changes do not include a specific implementation item for this release.
Source ↗Adds support for custom headers and includes documentation for the change.
Source ↗SPIRE v1.14.7 fixes a security vulnerability in Azure IMDS node attestation. It also updates the Go toolchain to 1.26.3 and updates three dependencies.
Check if affected (1)
securityThe
azure_imdsnode attestor validation is correctedApplies if you use the
azure_imdsserver node attestor plugin.
A maintenance release with a security fix for invalid HTTPProxy configurations and an update to golang.. It also updates the Go toolchain to 1.25.10 and is tested against Kubernetes 1.32 through 1.34.
Action needed (1)
securitycritical
golang.updated to v0.55.0, CVE-2026-39821org/x/net Contour v1.33.5 updates
golang.to v0.55.0. The change addresses CVE-2026-39821.org/x/net
Check if affected (1)
securitymediumInvalid
HTTPProxyconfiguration rejected, GHSA-g3xr-5w5j-w4q4Applies if you configure
HTTPProxywith afallback certificateand enableJWT verification.
A feature and maintenance release with new operator-facing APIs, discovery integrations, feature flags, configuration options, and UI capabilities. It also addresses disclosed security issues, correctness and performance problems, and validation or constraint behavior.
Action needed (1)
breakingConcurrent
fgprofprofile rejectionThe API rejects concurrent
fgprofprofiles.
Check if affected (3)
security
Remote Writedecoded-length constraintApplies if you use
Remote Write.securityPlaintext secret exposure in STACKIT SD
Applies if you use
STACKIT SD.breakingDecompressed body-size limit for OTLP write requests
Applies if you use
OTLP.
OpenFGA v1.16.1 includes a third-party dependency update for multiple CVEs in the Go standard library. It also corrects defects in the experimental weighted_graph_check behavior.
Action needed (1)
securityThe
grpc-health-probedependency updategrpc-health-probeis updated tov0.to address multiple CVEs in the Go standard library.4. 50
OPA v1.17.0 adds improved negation semantics, decision-log rule labels, published schemas, and API capabilities. It also includes correctness and performance improvements, removes two dependencies, and upgrades several others.
Source ↗Argo CD v3.3.11 contains bug fixes and a UI dependency update addressing CVE-2026-41240. The release concerns deployments using the affected UI dependency.
Action needed (1)
securitymediumThe
redoc/dompurifydependency, updated to v3.4.0The
/uidependencyredoc/dompurifyis updated to v3.4.0 to address CVE-2026-41240.
A maintenance release with several correctness fixes across Argo CD and a UI dependency update addressing CVE-2026-41240. The recorded fixes cover CLI, UI, Git, controller startup, and resource handling.
Check if affected (1)
securitymediumThe
redoc/dompurifydependency, upgraded for CVE-2026-41240Applies if you use
redoc/dompurifyin/ui.
This release includes a security-related dependency update in CI. The change affects builds that use golang..
Action needed (1)
securitycriticalThe
golang.dependency, updated toorg/x/net v0.55. 0 CI updates
golang.from its previous version toorg/x/net v0.to fix55. 0 GO-2026-5026.
Rook v1.18.11 changes OSD installation and liveness probe behavior, corrects CSI priority-class handling, and updates a third-party dependency. No security issue is disclosed.
Source ↗Flatcar stable-4593. is a maintenance release with Linux security fixes. It also updates Linux to 6. and ca-certificates to 3..
Action needed (1)
securitycritical
Linuxsecurity fixesLinuxsecurity fixes for CVE-2024-36476, CVE-2024-39282, CVE-2024-53681, CVE-2024-54031, CVE-2024-57795, CVE-2024-57801, CVE-2024-57802, CVE-2024-57841, CVE-2024-57844, CVE-2024-57857, CVE-2024-57882, CVE-2024-57883, CVE-2024-57884, CVE-2024-57885, CVE-2024-57886, CVE-2024-57887, CVE-2024-57888, CVE-2024-57889, CVE-2024-57890, CVE-2024-57891, CVE-2024-57892, CVE-2024-57893, CVE-2024-57894, CVE-2024-57895, CVE-2024-57896, CVE-2024-57897, CVE-2024-57898, CVE-2024-57899, CVE-2024-57900, CVE-2024-57901, CVE-2024-57902, CVE-2024-57903, CVE-2024-57930, CVE-2024-57931, CVE-2024-57932, CVE-2024-57933, CVE-2024-57934, CVE-2024-57935, CVE-2024-57936, CVE-2024-57937, CVE-2024-57938, CVE-2024-58237, CVE-2025-21629, CVE-2025-21630, CVE-2026-43490, CVE-2026-43492, CVE-2026-43495, CVE-2026-43496, CVE-2026-43497, CVE-2026-43502, CVE-2026-43503, CVE-2026-46300, and CVE-2026-46333 ship in Flatcarstable-4593..2. 2
This Flatcar LTS release contains Linux security fixes identified by CVEs, plus ca-certificates and Linux component updates. It is most relevant to deployments tracking the lts-4081. release.
Action needed (1)
securitycritical
Linuxsecurity fixes for CVE-2026-43316Linuxreceives security fixes associated with the listed CVEs, including CVE-2026-43316. The update ships in Flatcar LTSlts-4081..3. 8
A release that removes several supported engines and outputs and restricts falco-webui access. It also adds rule and configuration capabilities, includes defect fixes and dependency updates, and discloses no security advisory.
Action needed (1)
breakinggRPC server support, removed
gRPC server support is removed in this release.
Check if affected (5)
securityPlugin library path traversal prevention
Applies if you configure the
plugin library path.breakingThe
gRPC output, removedApplies if you use the
gRPC output.breakingThe
gVisor engine, removedApplies if you use the
gVisor engine.- + 2 more on the release page
This release updates configuration and metadata handling, with new schema and configuration capabilities and several API and feature-gate maturity changes. It also fixes Snappy memory corruption and fatal errors.
Check if affected (3)
breakingThe
pdata.feature gate, removeduseCustomProtoEncoding Applies if you use
pdata..useCustomProtoEncoding breakingDefault
reaggregation_enabledbehaviorApplies if you run
cmd/mdatagen.breakingStricter
feature_gatesvalidationApplies if you configure
feature_gatesinmetadata..yaml
A maintenance release includes dependency updates and security fixes in golang.. The fixes cover SSH, SSH agent, and known-hosts behavior.
Action needed (1)
security
golang.updated toorg/x/crypto v0.52. 0 The release updates the
golang.module toorg/x/crypto v0..52. 0
Check if affected (13)
securitycriticalUnenforced invoking key constraints in
golang.org/x/crypto/ssh/agent Applies if you use
golang..org/x/crypto/ssh/agent securitycriticalDropped invoking agent constraints in
golang.org/x/crypto/ssh/agent Applies if you use
golang..org/x/crypto/ssh/agent securitycriticalServer deadlock on unexpected responses in
golang.org/x/crypto/ssh Applies if you use
golang..org/x/crypto/ssh - + 10 more on the release page
Crossplane v1.20.8 is a dependency and toolchain maintenance release. It updates several modules and the Go version, with the recorded dependency changes addressing security fixes, and also bumps crossplane-runtime to v1..
Action needed (7)
securityThe
github.module, updated tocom/docker/cli v29.2. 0+incompatible The
github.module is updated tocom/docker/cli v29.in the2. 0+incompatible release-1.branch.20 securityThe
golang.module, updated toorg/x/net v0.53. 0 The
golang.module is updated toorg/x/net v0.in the53. 0 release-1.branch.20 securityThe
github.module, updated tocom/in-toto/in-toto-golang v0.11. 0 The
github.module is updated tocom/in-toto/in-toto-golang v0.in the11. 0 release-1.branch.20 securityThe
github.module, updated tocom/go-git/go-git/v5 v5.19. 0 The
github.module is updated tocom/go-git/go-git/v5 v5.in the19. 0 release-1.branch.20 securityThe
Gotoolchain, updated to1.25. 10 Gois updated to1.to fix standard-library CVEs in the25. 10 release-1.branch.20 securityThe
github.module, updated tocom/go-git/go-git/v5 v5.19. 1 The
github.module is updated again, tocom/go-git/go-git/v5 v5., in the19. 1 release-1.branch.20 securityThe
golang.module, updated toorg/x/crypto v0.52. 0 The
golang.module is updated toorg/x/crypto v0.in the52. 0 release-1.branch.20
This release contains no described operator-facing changes. No release-note details are provided for this version.
Source ↗A security-focused maintenance release updates Go and several dependencies, including a fix for an HTTP/2 transport infinite-loop vulnerability. The Go and dependency version increases require upgrading; no configuration migration or deprecation is announced.
Action needed (6)
securityThe
go.module updateopentelemetry. io/otel The
go.module is updated toopentelemetry. io/otel v1.in this release.41. 0 securityThe
github.module updatecom/in-toto/in-toto-golang The
github.module is updated tocom/in-toto/in-toto-golang v0.in this release.11. 0 securityThe
github.module update tocom/go-git/go-git/v5 v5.19. 0 The
github.module is updated tocom/go-git/go-git/v5 v5.in this release.19. 0 security
Go1.25. 10 Gois updated to1.to fix standard library CVEs.25. 10 securityThe
github.module update tocom/go-git/go-git/v5 v5.19. 1 The
github.module is updated tocom/go-git/go-git/v5 v5.in this release.19. 1 securityThe
golang.module updateorg/x/crypto The
golang.module is updated toorg/x/crypto v0.in this release.52. 0
Check if affected (1)
securityhighThe
golang.HTTP/2 transport infinite looporg/x/net Applicability is not stated in the release notes.
Crossplane v2.2.2 is a dependency and toolchain maintenance release with security-focused updates. It concerns deployments and builds that rely on the updated Go toolchain and modules.
Action needed (5)
security
github.updated to v0.11.0com/in-toto/in-toto-golang Crossplane v2.2.2 updates the
github.module to v0.11.0. The update ships in the release-2.2 line.com/in-toto/in-toto-golang security
github.updated to v5.19.0com/go-git/go-git/v5 Crossplane v2.2.2 updates the
github.module to v5.19.0. The update ships in the release-2.2 line.com/go-git/go-git/v5 security
Go1.25.10 update for standard-library CVEsCrossplane v2.2.2 updates
Goto 1.25.10 to fix standard-library CVEs. The toolchain update ships in the release-2.2 line.security
github.updated to v5.19.1com/go-git/go-git/v5 Crossplane v2.2.2 updates the
github.module to v5.19.1. The update ships in the release-2.2 line.com/go-git/go-git/v5 security
golang.updated to v0.52.0org/x/crypto Crossplane v2.2.2 updates the
golang.module to v0.52.0. The update ships in the release-2.2 line.org/x/crypto
This release corrects the runtime operator's generated and Helm RBAC permissions. The fixes cover finalizer updates needed for garbage collection and permissions for resources used by reconcilers; no security advisory or security flaw is disclosed.
Source ↗Crossplane v2.3.0 combines breaking API naming and path changes with new operator capabilities and correctness fixes. It also updates several Go dependencies and the Go toolchain, which matters to API consumers and builds that depend on the affected packages.
Action needed (14)
securityThe
github.dependency, updated to v1.6.3com/cloudflare/circl The
github.module is updated to v1.6.3 in Crossplane v2.3.0.com/cloudflare/circl securityThe
google.dependency, updated to v1.79.3golang. org/grpc The
google.module is updated to v1.79.3 in Crossplane v2.3.0.golang. org/grpc securityThe
go.dependency, updated to v1.43.0opentelemetry. io/otel/exporters/otlp/otlptrace/otlptracehttp The
go.module is updated to v1.43.0 in Crossplane v2.3.0.opentelemetry. io/otel/exporters/otlp/otlptrace/otlptracehttp securityThe
github.dependency, updated to v5.17.1com/go-git/go-git/v5 The
github.module is updated to v5.17.1 in Crossplane v2.3.0.com/go-git/go-git/v5 securityThe
github.dependency, updated to v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 in Crossplane v2.3.0.com/go-jose/go-jose/v4 securityThe
github.dependency, updated to v3.0.5com/sigstore/cosign/v3 The
github.module is updated to v3.0.5 in Crossplane v2.3.0.com/sigstore/cosign/v3 securityThe
github.dependency, updated to v29.2.0+incompatiblecom/docker/cli The
github.module is updated to v29.2.0+incompatible in Crossplane v2.3.0.com/docker/cli securityThe
github.dependency, updated to v2.0.6com/sigstore/timestamp-authority/v2 The
github.module is updated to v2.0.6 in Crossplane v2.3.0.com/sigstore/timestamp-authority/v2 securityThe
Gotoolchain, updated to 1.25.9The
Gotoolchain is updated to 1.25.9 in Crossplane v2.3.0.securityThe
github.dependency, updated to v0.5.1com/moby/spdystream The
github.module is updated to v0.5.1 in Crossplane v2.3.0.com/moby/spdystream securityThe
github.dependency, updated to v5.18.0com/go-git/go-git/v5 The
github.module is updated to v5.18.0 in Crossplane v2.3.0.com/go-git/go-git/v5 securityThe
github.dependency, updated to v0.11.0com/in-toto/in-toto-golang The
github.module is updated to v0.11.0 in Crossplane v2.3.0.com/in-toto/in-toto-golang securityThe
golang.dependency, updated to v0.53.0org/x/net The
golang.module is updated to v0.53.0 in Crossplane v2.3.0.org/x/net securityThe
Gotoolchain, updated to 1.25.10The
Gotoolchain is updated to 1.25.10 in Crossplane v2.3.0 to fix standard library CVEs.
Check if affected (3)
breakingThe Crossplane API dependency path, renamed
Applies if you build external consumers of Crossplane APIs.
breakingThe common API package, moved
Applies if you use the common APIs from
crossplane-runtime.breakingThe
v1.types, renamedResource* Applies if you use the old
v1.types.Resource*
KServe v0.17.1 is a maintenance release with operator-facing corrections and updated release-version metadata. It includes fixes related to installation scripts and the Helm chart, with no disclosed security advisories or security-specific fixes.
Source ↗