Tekton v1.15.0 adds configurable behavior, corrects defects across controllers and runtime components, and updates project dependencies. No security advisories or explicitly described vulnerabilities are present.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with bug fixes and dependency updates. The form-data update in /ui addresses CVE-2026-12143.
Action needed (1)
securityhighThe
form-datadependency update for CVE-2026-12143The
form-datadependency is updated to version 4.0.6 in/uito address CVE-2026-12143.
This is a bug-fix release for Argo CD v3.4.6. The release notes mention corrections to application behavior and integrations, with no security advisories or explicit security vulnerabilities stated.
Source ↗A broad operator-impacting maintenance release with security-related base image updates, API and configuration changes, scheduling capabilities, and deprecations and removals. Operators should review changed defaults and constraints and account for migration work affecting their configurations, APIs, and metrics.
Action needed (2)
securityThe
alpinebase image updateThe
alpinebase image is updated fromalpine:3.to23. 4 alpine:3.to address security concerns.24. 1 securityThe
alpinebase image updateThe
alpinebase image is updated fromalpine:3.to23. 3 alpine:3.to address security concerns.23. 4
Check if affected (8)
breakingThe cluster lease duration flags, removed
Applies if you configure either
--cluster-lease-durationor--cluster-lease-renew-interval-fraction.breakingThe
Estimatormetric label value, removedApplies if you use either
estimating_plugin_execution_duration_secondsorestimating_plugin_extension_point_duration_seconds.breakingThe
Etcd.configuration field, removedLocal. InitImage Applies if you configure
Etcd..Local. InitImage - + 5 more on the release page
Plan ahead (4)
deprecatedThe
ReplicaRequirements.field deprecationdeprecated since v1.18.0resourceRequest Applies if you use
ReplicaRequirements..resourceRequest deprecatedThe
ComponentReplicaRequirements.field deprecationdeprecated since v1.18.0resourceRequest Applies if you use
ComponentReplicaRequirements..resourceRequest deprecatedThe
NodeClaim.field deprecationdeprecated since v1.18.0nodeAffinity Applies if you use
NodeClaim..nodeAffinity - + 1 more on the release page
A mixed maintenance and feature release with workload-affinity and anti-affinity support, encryption-at-rest capabilities, bug fixes, and updates to dependencies and default images. It also changes operational defaults and validation while deprecating or removing configuration flags and fields, so compatibility and configuration changes are part of the release.
Action needed (1)
breaking
ControllerPriorityQueuepromotion to beta and default enablementControllerPriorityQueueis promoted to beta and enabled by default.
Check if affected (4)
breakingThe
--etcd-init-imageflag, removed fromkarmadactl initApplies if you use the
--etcd-init-imageflag.breaking
namespacevalidation forspec.resourceSelectors Applies if you use
PropagationPolicyorOverridePolicy.breakingDistinct
GroupByLabelKeyvalues inWorkloadAffinityApplies if you configure
WorkloadAffinity.- + 1 more on the release page
Plan ahead (2)
deprecated
Etcd.deprecationdeprecated since v1.17.0 · removal date not announcedLocal. InitImage Applies if you configure
Etcd.inLocal. InitImage Karmada Init Configuration.deprecatedDeprecation of cluster lease flagsdeprecated since v1.17.0 · removal date not announced
Applies if you use
--cluster-lease-durationor--cluster-lease-renew-interval-fraction.
A mixed maintenance and feature release with bug fixes, new APIs and capabilities, performance and instrumentation improvements, dependency updates, and deprecated field removals. Operators should review the removed fields and the updated dependency, while the release also adds multi-component scheduling, configurable initialization, eviction queue support, and new workload interpreters.
Action needed (1)
securitymediumThe
github.dependency updatecom/vektra/mockery The
github.dependency was bumped to v3.5.5 to address security concerns identified bycom/vektra/mockery GO-2025-3900.
Check if affected (4)
breakingThe external etcd fields
CAData,CertData, andKeyData, removedApplies if you configure
CAData,CertData, orKeyData.breakingThe
initcommand's default component imagesApplies if you run the
initcommand.breakingA 32s default timeout for the member cluster client
Applies if you use the member cluster client.
- + 1 more on the release page
Plan ahead (2)
deprecatedThe
--etcd-init-imageflag, deprecatedremoval date not announcedApplies if you use
--etcd-init-image.breakingThe Prometheus metric labels
clusterandcluster_name, replaced bymember_clusterremoval planned in 1.18Applies if you use the
clusterorcluster_namemetric labels.
KEDA v2.20.2 contains a new ScaledObject condition alongside correctness, validation, and performance fixes. The release also addresses operator stability and scaler behavior, with no disclosed security advisories or setup changes.
A release with a SQL injection fix and a GHSA-linked dependency update, alongside a breaking Rego safety-checking change. It also changes runtime and CLI behavior, adds capabilities, and fixes correctness and performance issues.
Action needed (3)
securityhigh
oras.update for GHSA-fxhp-mv3v-67qpland/oras-go/v2 oras.is updated fromland/oras-go/v2 2.to6. 1 2.to address GHSA-fxhp-mv3v-67qp.6. 2 breaking
ReadHeaderTimeoutdefaultAll HTTP servers now set
ReadHeaderTimeoutto32s.breakingPartial set and
-objectrule name conflictsThe AST rejects partial set and
-objectrules that share a name.
Check if affected (2)
securityCompile API SQL identifier handling
Applies if you use the Compile API and use a dynamic key.
breakingStricter
:=safety checkingApplicability is not stated in the release notes.
A broad operator-facing release with fixes, behavior changes, new capabilities, API and feature-gate maturity changes, deprecations, and component updates. It also includes security updates for CVE-2026-35469, GHSA-pc3f-x583-g7j2, and CVE-2026-33186, along with a symlink-traversal fix and a security dependency update.
Action needed (2)
securitycriticalThe
grpcdependency, updatedgrpcis updated to 1.79.3 to remediate CVE-2026-33186.securityhighThe
github.dependency, updatedcom/moby/spdystream The
github.dependency is updated from v0.5.0 to v0.5.1 to address CVE-2026-35469 (GHSA-pc3f-x583-g7j2).com/moby/spdystream
Check if affected (9)
breakingStricter network interface binding admission
Applies if you configure network interface bindings.
breakingThe
Templatefeature gate, enabled by defaultApplies if you enable the
Templatefeature gate.breakingThe ephemeral hotplug volume metric and alert, removed
Applies if you use the ephemeral hotplug volume metric.
- + 6 more on the release page
Plan ahead (2)
deprecatedcgroup v1 support, deprecatedremoval date not announced
Applies if you run with cgroup v1 support.
deprecatedLegacy VM creation recording rules and metrics, deprecated
Applies if you use
kubevirt_vm_created_totalorkubevirt_vm_created_by_pod_total.
Thanos v0.42.4 contains no described operator-facing changes in the supplied release information. The available note is a duplicate mention.
Source ↗A maintenance release with dependency and toolchain updates, JetStream performance and configuration improvements, and broad correctness fixes. It also includes authentication and permission fixes.
Check if affected (4)
security
JWTvalidation with whitespace-only permissionsApplies if you use JWT validation.
security
verify_and_mapauthentication with blank passwordsApplies if TLS
verify_and_mapis configured.securityMQTT subscription restriction for
$MQTT.subjects> Applies if you use
MQTT.- + 1 more on the release page
A maintenance release with a Go toolchain update, dependency manifest updates, JetStream performance and configuration changes, and numerous correctness fixes. Authentication fixes address security flaws and require upgrading.
Action needed (1)
breakingThe disk concurrency semaphore, increased to 4096 slots
The disk concurrency semaphore is now set to 4096 slots, up from the previous CPU-scaled count. This performance change ships in v2.12.14.
Check if affected (2)
securityAuthentication checks with
no_auth_userand auth calloutsApplies if you configure
no_auth_userand use auth callouts.securityTLS
verify_and_mapauthentication with blank passwordsApplies if you use TLS and configure
verify_and_map.
Prometheus v3.13.2 updates dependencies for two disclosed vulnerabilities and includes related transitive dependency upgrades. It also fixes a PromQL SIGBUS crash when the data disk is full.
Action needed (2)
securityhigh
golang.update for CVE-2026-56852org/x/text golang.updates from v0.38.0 to v0.39.0 in Prometheus v3.13.2 for CVE-2026-56852.org/x/text securityhigh
google.update for GHSA-hrxh-6v49-42gfgolang. org/grpc google.updates from v1.81.1 to v1.82.1 in Prometheus v3.13.2 for GHSA-hrxh-6v49-42gf.golang. org/grpc
This release contains an operator-facing defect correction. The remaining release-note content consists of headings, installation guidance, or attestation instructions rather than additional software changes.
Source ↗A maintenance release with an updated cryptography dependency that incorporates upstream SSH security fixes. It also expands configuration-format support and includes scheduler correctness fixes.
Action needed (1)
securityThe
golang.dependency, upgradedorg/x/crypto The
golang.dependency is upgraded from v0.49.0 to v0.53.0 in the v1.15.1 release branch. The update incorporates upstream SSH security fixes released in v0.52.0.org/x/crypto
Volcano v1.14.4 is a bug-fix release covering scheduler behavior, nil-pointer panics, job dependency readiness, allocation flow, and Ascend vNPU configuration and resource handling. No security advisories or security-specific flaws are identified.
Source ↗Release v2.6.1 renames two operator-facing identifiers. Existing references may need updating to match the new names.
Source ↗Nothing here needs operator attention.
Source ↗cert-manager v1.21.1 is a maintenance release with fixes for regressions and updates to dependencies affected by reported security vulnerabilities. The dependency updates concern all installations, while the regression fixes address controller behavior and require no setup change.
Action needed (4)
securityThe
golang.dependency, updated to v0.40.0org/x/text The
golang.dependency is updated to v0.40.0 to fix a reported security vulnerability.org/x/text securityThe
google.dependency, updated to v1.82.1golang. org/grpc The
google.dependency is updated to v1.82.1 to fix a reported security vulnerability.golang. org/grpc securityThe
github.dependency, updated to v0.29.0com/google/cel-go The
github.dependency is updated to v0.29.0 to fix a reported security vulnerability.com/google/cel-go securityThe
go.dependency, updated to v1.44.0opentelemetry. io/otel The
go.dependency is updated to v1.44.0 to fix a reported security vulnerability.opentelemetry. io/otel
A substantial feature and maintenance release with Gateway API, networking, IPAM, policy, observability, and datapath changes, alongside correctness and performance fixes. Operators should review removed or renamed options, changed defaults and requirements, removed metrics and integrations, and the dependency updates addressing security-related issues.
Action needed (11)
security
google.v1.79.3golang. org/grpc The
google.module is updated to v1.79.3 in the main branch.golang. org/grpc security
google.v1.82.1golang. org/grpc The
google.module is updated to v1.82.1 in the v1.20 branch.golang. org/grpc security
helm.v4.1.4sh/helm/v4 The
helm.module is updated to v4.1.4 in the main branch.sh/helm/v4 security
github.v1.6.3com/cloudflare/circl The
github.module is updated to v1.6.3.com/cloudflare/circl security
github.v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4.com/go-jose/go-jose/v4 security
github.v0.5.1com/moby/spdystream The
github.module is updated to v0.5.1.com/moby/spdystream breaking
cni.CNI configuration versioncustomConf The default CNI configuration version for
cni.changes from 0.3.1 to 1.0.0.customConf breakingCilium operator IPAM metrics removal
The IPAM metrics
cilium_operator_ipam_ipsandcilium_operator_ipam_available_interfacesare removed.breakingDefault CNI configuration version
The default CNI configuration version changes from 0.3.1 to 1.0.0.
breakingNative histogram default
Native histograms are emitted for all histograms by default.
breakingAgent bootstrap metrics removal
Agent bootstrap metrics are removed.
Check if affected (28)
security
tbidtraffic host namespace handlingApplies if you use
tbidtraffic.breakingDocker libnetwork plugin removal
Applies if you use the Docker libnetwork plugin.
breaking
ces-slice-moderemovalApplies if you configure
ces-slice-mode.- + 25 more on the release page
Plan ahead (6)
deprecatedBeta Mutual Auth deprecationremoval date not announced
Applies if you use Mutual Auth.
deprecatedDeprecated address and interface CIDR fields
Applies if you configure
addresses[].orsubnet interfaces[]..cidr deprecatedLocal REST BGP API deprecationremoval date not announced
Applies if you use the local REST BGP APIs.
- + 3 more on the release page
This release contains a receive shutdown regression correction. Blocks are uploaded before TSDB shutdown completes, preserving upload behavior during shutdown.
Source ↗Knative v1.23.0 expands platform support with generic ephemeral volumes, startup-probe validation, and IPv6 handling for autoscaler and activator behavior. It also corrects WebSocket hijack state tracking, with no security advisories or operator actions identified.
Source ↗A feature and maintenance release that adds runtime, plugin, service, component, and pooling capabilities while changing the default NATS behavior. It also includes dependency updates and fixes for runtime and observability defects.
Action needed (1)
breakingThe
NATSconsumer-group defaultNATS now uses consumer groups by default in the release.
A maintenance release with improvements to Helm charts, custom resource support, networking, monitoring, and storage behavior. It also includes correctness fixes across scheduling, reconciliation, endpoint handling, account deletion, and logging.
Source ↗v1.19.8 is a maintenance release with a security-related dependency update and behavioral improvements. The recorded dependency change updates the vulnerable go text package from v0.37 to a newer version.
Action needed (1)
securityThe
go textpackage, updated from v0.37The
go textpackage is updated from v0.37 to the latest version because v0.37 has a vulnerability. This dependency update ships in v1.19.8.
A release with a breaking authentication change and several operator-visible removals, alongside new integrations, APIs, and configuration capabilities. No security fixes or advisory identifiers are disclosed.
Check if affected (6)
breakingKBS client admin-token authentication
Applies if you use the
KBS client.breakingThe
CAA docker provider, removedApplies if you use the
CAA docker provider.breakingThe Fedora-based mkosi-built
CAA podvmimage, removedApplies if you use the Fedora-based mkosi-built
CAA podvmimage.- + 3 more on the release page
This release combines ordinary bug fixes with security-related updates. It also improves blob/HTTP synchronization, with no announced operator-facing removals, deprecations, or default changes.
Action needed (2)
securityThe
google.module update to v1.82.1golang. org/grpc The
google.module is updated to v1.82.1 in core v0.16.1.golang. org/grpc securityThe
vulnerability-updatesupdatevulnerability-updatesis updated in core v0.16.1.
A maintenance release with a bug-fix heading, a new server timeout setting, dependency updates, and security-related updates. The google. update requires upgrading.
Action needed (2)
securityThe
google.module, updated to v1.82.1golang. org/grpc The
google.module is updated to v1.82.1 as a security-related dependency change.golang. org/grpc securityThe
vulnerability-updatesdependency updateThe release updates
vulnerability-updatesas a security-related dependency change.
flagd/v0. combines bug fixes with security dependency updates and a configurable sync-server capability. The security notes do not include advisory identifiers or flaw details, while the sync-server changes include server timeouts and configurable gRPC keepalive enforcement.
Action needed (3)
securitySecurity dependency updates
Security dependencies are updated in
flagd/v0..16. 1 securityThe
google.module updategolang. org/grpc The
google.module is updated togolang. org/grpc v1.in82. 1 flagd/v0..16. 1 securityVulnerability updates
Vulnerability updates are included in
flagd/v0.as a security change.16. 1
Dragonfly v2.5.1 adds scheduler and statistics capabilities while correcting runtime and scheduling behavior. It also updates dependencies and changes digest validation to reject non-hex encoded values; no security advisories or explicitly described vulnerabilities are present.
Source ↗Linkerd edge-26.7.2 contains no functional changes. It updates runtime, build, and development dependencies, with no security advisories disclosed or referenced.
Source ↗A maintenance release changes server defaults and behavior, fixes correctness issues, and addresses disclosed security issues in watch permissions and google.. It also includes fixes for unbounded peer lease HTTP request reads and nested transaction request handling.
Action needed (3)
securityhighThe
google.dependency updategolang. org/grpc The release updates
google.to versiongolang. org/grpc 1.to address GHSA-hrxh-6v49-42gf.82. 1 breakingThe
snapshotLimitBytedefaultThe release sets a reasonable default value for
snapshotLimitByte.breakingThe client HTTP server
ReadHeaderTimeoutThe client HTTP server now sets
ReadHeaderTimeout.
Check if affected (1)
securityhighWatch responses restricted to authorized keys
Applicability is not stated in the release notes.
A maintenance release with security fixes, dependency updates, and changes to defaults and behavior. The changed snapshotLimitByte default and the security fixes are the main release concerns; other correctness fixes require no setup changes.
Action needed (5)
securitycriticalThe
golang.dependency updateorg/x/net The
golang.dependency is updated from 0.54.0 to 0.55.0 to address CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-42502, CVE-2026-25680, and CVE-2026-42506.org/x/net securityhighAuthorization fix for watch responses, GHSA-xg4h-6gfc-h4m8
An authorization issue is fixed where a user with read permission on one key could receive watch responses for every key starting from that key. This addresses GHSA-xg4h-6gfc-h4m8.
securityhighThe
tlsHandshakeTimeoutsetting fortlsListener, GHSA-6vch-q96h-7gc3The release sets
tlsHandshakeTimeoutfortlsListener. This addresses GHSA-6vch-q96h-7gc3.securityhighThe
google.dependency updategolang. org/grpc The
google.dependency is updated to 1.82.1 to address GHSA-hrxh-6v49-42gf.golang. org/grpc breakingThe
snapshotLimitBytedefault valueThe default value for
snapshotLimitByteis set to a reasonable value in this release.
A maintenance release with correctness and security fixes, timeout behavior changes, and dependency and toolchain updates. It also updates the build toolchain used to compile binaries.
Action needed (5)
securityhighWatch response authorization for key ranges
The watch authorization issue is fixed: a user with read permission on one key could no longer receive watch responses for every key starting from that key. The fix addresses GHSA-xg4h-6gfc-h4m8.
securityhighThe
tlsHandshakeTimeoutsetting fortlsListenerA
tlsHandshakeTimeoutis set fortlsListener. The change addresses GHSA-6vch-q96h-7gc3.securityhighThe
golang.dependency, updated to v0.56.0org/x/net The
golang.dependency is updated to v0.56.0 to addressorg/x/net GO-2026-5942.securityhighThe
golang.dependency, updated to v0.39.0org/x/text The
golang.dependency is updated to v0.39.0 to addressorg/x/text GO-2026-5970.securityhighThe
google.dependency, updated to 1.82.1golang. org/grpc The
google.dependency is updated to 1.82.1 to address GHSA-hrxh-6v49-42gf.golang. org/grpc
Flux v2.9.3 is a maintenance release with correctness fixes, updated dependencies, and a newly included component in the OCI artifact. No security advisories are disclosed.
Source ↗This release includes operator-visible defect corrections and an image-build behavior change alongside dependency updates for security fixes. Upgrading incorporates the security fixes in the dependency updates, while the remaining changes require no setup action.
Action needed (7)
securityThe
github.module update tocom/sigstore/rekor v1.5. 2 Crossplane v2.3.4 updates the
github.module tocom/sigstore/rekor v1.for security fixes.5. 2 securityThe
github.module update tocom/sigstore/cosign/v3 v3.0. 6 Crossplane v2.3.4 updates the
github.module tocom/sigstore/cosign/v3 v3.for security fixes.0. 6 securityThe
github.module update tocom/sigstore/timestamp-authority/v2 v2.1. 0 Crossplane v2.3.4 updates the
github.module tocom/sigstore/timestamp-authority/v2 v2.for security fixes.1. 0 securityThe
github.module update tocom/sigstore/sigstore-go v1.2. 0 Crossplane v2.3.4 updates the
github.module tocom/sigstore/sigstore-go v1.for security fixes.2. 0 securityCombined security dependency updates
Crossplane v2.3.4 includes combined security updates for
grpc,golang., andorg/x/net golang..org/x/text securityThe
golang.module update toorg/x/text v0.39. 0 Crossplane v2.3.4 updates the
golang.module toorg/x/text v0.for security fixes.39. 0 securityThe
golang.module update toorg/x/net v0.56. 0 Crossplane v2.3.4 updates the
golang.module toorg/x/net v0.for security fixes.56. 0
Crossplane v2.2.4 fixes a Usage-controller reconciliation defect and changes image builds to use buildGoModule, so published images can be scanned by standard vulnerability tooling. It also includes security-related dependency updates.
Action needed (5)
securityThe
github.module update to v1.5.2com/sigstore/rekor Crossplane v2.2.4 updates the
github.module to v1.5.2.com/sigstore/rekor securityThe
github.module update to v3.0.6com/sigstore/cosign/v3 Crossplane v2.2.4 updates the
github.module to v3.0.6.com/sigstore/cosign/v3 securityThe
github.module update to v2.1.0com/sigstore/timestamp-authority/v2 Crossplane v2.2.4 updates the
github.module to v2.1.0.com/sigstore/timestamp-authority/v2 securityThe
github.module update to v1.2.0com/sigstore/sigstore-go Crossplane v2.2.4 updates the
github.module to v1.2.0.com/sigstore/sigstore-go securityCombined
grpc,x/net, andx/textdependency updatesCrossplane v2.2.4 applies combined security updates to
grpc,x/net, andx/text.
Crossplane v2.1.8 is a maintenance release with several security-related dependency and toolchain updates. It also fixes repeated owner updates for composed Usages by checking all owner references instead of only the first.
Action needed (7)
securityThe
github.module atcom/sigstore/rekor v1.5. 2 The
github.module is updated tocom/sigstore/rekor v1.in Crossplane v2.1.8.5. 2 securityThe
github.module atcom/sigstore/timestamp-authority/v2 v2.1. 0 The
github.module is updated tocom/sigstore/timestamp-authority/v2 v2.in Crossplane v2.1.8.1. 0 securityThe
github.module atcom/sigstore/cosign/v2 v2.6. 3 The
github.module is updated tocom/sigstore/cosign/v2 v2.in Crossplane v2.1.8.6. 3 securityThe
Gotoolchain at1.25. 12 The
Gotoolchain is updated to1.in Crossplane v2.1.8.25. 12 securityThe
github.module atcom/sigstore/sigstore-go v1.2. 0 The
github.module is updated tocom/sigstore/sigstore-go v1.in Crossplane v2.1.8.2. 0 securityCombined
grpc,x/net, andx/textdependency updatesCombined security dependency updates cover
grpc,x/net, andx/textin Crossplane v2.1.8.securityThe
golang.module atorg/x/text v0.39. 0 The
golang.module is updated toorg/x/text v0.in Crossplane v2.1.8.39. 0
A maintenance release fixes repeated owner updates in the Usage controller and includes security-related dependency and toolchain upgrades. It updates the runtime dependency set, Go toolchain, and Alpine base image in the release-1.20 line.
Action needed (4)
securityThe
github.module, updated to v1.5.2com/sigstore/rekor The
github.module is updated to v1.5.2 in the release-1.20 line.com/sigstore/rekor securityThe
Gotoolchain, updated to 1.25.12The
Gotoolchain is updated to 1.25.12 in the release-1.20 line.securityThe
alpineDocker tag, updated to v3.24The
alpineDocker tag is updated to v3.24 in the release-1.20 line.securitySecurity updates for
grpc,x/net, andx/textSecurity updates are applied to
grpc,x/net, andx/textin the release-1.20 line.
A maintenance release with dependency updates and correctness fixes across scheduling, kubelet behavior, server-side apply, and kubeadm. It also includes a Go 1.26.5 build update, with no disclosed security advisories.
Source ↗