RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jun 2026Clear ×
KubeVirtv1.7.4Orchestration & ManagementJun 3, 2026

KubeVirt v1.7.4 includes correctness fixes and behavior changes affecting PCI topology and IPv6 migration. It also updates the gRPC dependency to address CVE-2026-33186.

Action needed (1)

  • securitycriticalThe google.golang.org/grpc dependency update for CVE-2026-33186

    KubeVirt v1.7.4 updates google.golang.org/grpc to version 1.79.3 to remediate CVE-2026-33186.

Source
KubeVirtv1.6.6Orchestration & ManagementJun 3, 2026

KubeVirt v1.6.6 includes a dependency update for CVE-2026-33186. The recorded change affects the gRPC dependency shipped with this release.

Action needed (1)

  • securitycriticalgoogle.golang.org/grpc update for CVE-2026-33186

    KubeVirt v1.6.6 bumps google.golang.org/grpc to remediate CVE-2026-33186.

Source
Jaegerv2.19.0ObservabilityJun 3, 2026

This release adds API and storage capabilities, updates API query naming and defaults, and includes correctness fixes. No security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingThe searchdepth default in the trace-summaries endpoint

    The default for searchdepth changed in the trace-summaries endpoint.

Source
wasmCloudv2.3.0Orchestration & ManagementJun 3, 2026

Version v2.3.0 adds workload configuration and telemetry capabilities while correcting wash and runtime defects. It also changes RBAC scope support and updates dependencies, including security patches and reported advisory fixes.

Action needed (2)

  • securityThe wasmtime 44.0.2 security patch

    The release updates wasmtime to 44.0.2 as a security patch.

  • securityReported dependency security advisories

    The dependency set includes patches for reported security advisories.

Source
CRI-Ov1.36.1Kubernetes CoreJun 3, 2026

A maintenance release fixes container status ImageRef changes after CRI-O restarts and reduces debug-log verbosity for List* RPC calls. No other operator-facing changes are described.

Source
CRI-Ov1.33.13Kubernetes CoreJun 3, 2026

A maintenance release fixes a race condition where cri-o reports exitCode 255 when a container exits fast. Nothing else here needs operator attention.

Source
containerdv2.1.8Kubernetes CoreJun 2, 2026

containerd v2.1.8 includes a disclosed security correction identified by CVE-2026-46680 and GHSA-fqw6-gf59-qr4w. The release also contains operator-facing runtime and snapshotter changes in its broader changelog.

Action needed (1)

  • securityhighCVE-2026-46680 security correction

    containerd v2.1.8 includes a correction for CVE-2026-46680, associated with GHSA-fqw6-gf59-qr4w.

Source
Rookv1.20.0Storage & DataJun 2, 2026

A breaking release for CSI configuration also changes unused CRUSH rule handling and supported Kubernetes versions. It adds storage and object-store capabilities, including SSE-S3 with Vault Agent authentication, object-store account management, and encrypted OSD disk expansion.

Check if affected (2)

  • breakingCeph CSI operator for driver settings

    Applies if you configure CSI driver settings.

  • breakingROOK_DELETE_UNUSED_CRUSH_RULES default

    Applies if the Ceph mgr is running.

Source
OpenFGAv1.17.0SecurityJun 2, 2026

OpenFGA v1.17.0 adds configurable trace sampling and changes cache key generation. The release concerns deployments that configure tracing or depend on cache key behavior.

Action needed (1)

  • securityTLV-based cache key generation

    OpenFGA v1.17.0 redesigns cache key generation with TLV binary encoding, removing collision risk from string concatenation. It also adds per-process hash seeding to prevent hash-flooding attacks.

Source
NATSv2.14.2Networking & MessagingJun 2, 2026

This release adds an API capability and updates the Go toolchain. It also contains correctness and performance fixes across protocol handling, monitoring, clustering, and stream and consumer operations.

Source
NATSv2.12.10Networking & MessagingJun 2, 2026

NATS v2.12.10 combines a new client API capability with correctness fixes across protocol handling, monitoring, clustering, and storage. It also changes stream and consumer constraints and scale-down behavior, removes a filestore check, and updates the Go toolchain.

Source
Longhornv1.12.0Storage & DataJun 2, 2026

A broad maintenance and feature release combines bug fixes with new capabilities, configuration options, and platform support. It also changes defaults, tightens operational constraints, and removes V2 Backing Images.

Check if affected (5)

  • breakingV2 Backing Images removal

    Applies if you use V2 Backing Images.

  • breakingThe data-engine-cpu-mask default, changed

    Applies if you do not configure data-engine-cpu-mask.

  • breakingLive migration constraint for older CLI API versions

    Applies if you use an engine image with a CLI API version older than 12.

  • + 2 more on the release page
Source
Knativeknative-v1.22.1Orchestration & ManagementJun 2, 2026

This release contains dependency upgrades with embedded correctness fixes. The recorded changes do not include item-level details beyond those upgrades.

Source
Knativeknative-v1.21.3Orchestration & ManagementJun 2, 2026

A maintenance release with a fix for a non-constant format string error and updates to knative.dev/pkg, knative.dev/networking, and knative.dev/hack. No security advisories or security-specific flaws are identified.

Source
etcdv3.6.12Kubernetes CoreJun 1, 2026

A maintenance release expands maintenance-status access to non-admin users, corrects unexpected learner promotion and data-file-path validation issues, and compiles binaries with Go 1.25.10. The bug fixes require no operator action beyond upgrading, while the access change matters to operators relying on the previous restriction.

Source
etcdv3.5.31Kubernetes CoreJun 1, 2026

A maintenance release with correctness fixes and dependency updates. The golang.org/x/crypto update addresses GO-2026-5026.

Action needed (1)

  • securitycriticalThe golang.org/x/crypto dependency update for GO-2026-5026

    The golang.org/x/crypto dependency is updated to v0.52.0 to address GO-2026-5026.

Source
etcdv3.4.45Kubernetes CoreJun 1, 2026

A maintenance release that ends support for the v3.4 line and updates the Go toolchain used to compile binaries. No further patches will be issued for v3.4.

Plan ahead (1)

  • deprecatedThe v3.4 line, end of support

Source
Daprv1.17.9Orchestration & ManagementJun 1, 2026

This release corrects a workflow retention purge failure for Azure Cosmos DB when the customStatus row is absent. Affected workflows recover automatically after upgrading to v1.17.9, with no manual scheduler intervention required.

Source
OpenFeaturecore/v0.16.0CI/CD & App DeliveryJun 1, 2026

Core v0.16.0 changes disabled-flag evaluations from returning an error to succeeding with reason DISABLED; resolved values remain unchanged and still use the caller-provided default. The compatibility change affects consumers that inspect reason or errorCode, call flagd directly over gRPC or OFREP, or import core/pkg/model.

Source
OpenFeatureflagd/v0.16.0CI/CD & App DeliveryJun 1, 2026

A behavior update changes how disabled flags are evaluated: they now resolve successfully with reason=DISABLED instead of returning a FLAG_DISABLED error. No other operator action is indicated.

Source
KEDAv2.20.0Orchestration & ManagementJun 1, 2026

This release adds scalers, configuration options, metrics, authentication modes, and compatibility improvements. Operators with custom RBAC need to account for the Kubernetes events API migration, and users of removed scaler settings need to update their configurations.

Check if affected (7)

  • securityCredential headers on cross-host redirects and HTTPS downgrades

    Applicability is not stated in the release notes.

  • breakingScaledObject name length validation

    Applies when a ScaledObject name exceeds 63 characters.

  • breakingPositive unprocessedEventThreshold values

    Applies if you configure a non-positive unprocessedEventThreshold.

  • + 4 more on the release page

Plan ahead (1)

  • deprecatedThe buildId, selectAllActive, and selectUnversioned settings, deprecated

    Applies if you configure buildId, selectAllActive, or selectUnversioned.

Source
Limav2.1.2Kubernetes CoreJun 1, 2026

A feature and maintenance release with CLI and template changes, QEMU behavior updates, and fixes across drivers, hostagent, shell, and guest support. It also includes a deprecation, while no security advisories or explicitly described vulnerabilities are present.

Check if affected (1)

  • breakingQEMU 2MB OVMF images dropped by openSUSE

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedThe _LIMA_QEMU_UEFI_IN_BIOS flag, deprecated

    Applies if you configure _LIMA_QEMU_UEFI_IN_BIOS.

Source
Volcanov1.15.0Orchestration & ManagementJun 1, 2026

A feature and operational-hardening release that adds alpha scheduling capabilities, new scheduler and Helm configuration, and fixes scheduler and integration stability issues. Operators should review Kubernetes and DRA compatibility requirements, the changed DRA default, and the disclosed denial-of-service and Prometheus security fixes.

Action needed (4)

  • securitymediumPrometheus dependency update for GHSA-vffh-x6r8-xx99

    Updates github.com/prometheus/prometheus to address stored XSS advisory GHSA-vffh-x6r8-xx99.

  • securitymediumAdmission webhook request body limits

    The admission webhook now limits request bodies, fixing the denial-of-service risk identified by CVE-2026-44247 and GHSA-8wxp-xxp2-rcgx.

  • breakingDRA scheduling integration default

    DRA scheduling integration is enabled by default.

  • breakingDRA scheduling integration default behavior

    DRA scheduling integration is enabled by default to align with Kubernetes 1.34 and later behavior. Set predicate.DynamicResourceAllocationEnable to false to disable it.

Check if affected (2)

  • breakingOpt-in SchedulingGatesQueueAdmission

    Applies if you enable SchedulingGatesQueueAdmission.

  • breakingOpt-in gang-aware preemption and reclamation

    Applies if you configure gangPreempt and gangReclaim and do not configure preempt or reclaim.

Source
← Newer
Browse by month