A maintenance release with fixes to cri-api, kubeadm etcd handling, and kubelet logging. It also updates the Go toolchain used to build Kubernetes to 1.25.12.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with kubeadm and kubelet behavior corrections, a changed kubeadm timeout default, and a deferred Kubelet deprecation removal. It also includes a toolchain dependency update and no identified security advisories.
Plan ahead (1)
deprecated
Kubeletconfigurations flagsdeprecation removal timelineremoval planned in 1.38Applies if you configure
Kubelet'sconfigurations flags.
A feature and maintenance release that adds scanning, reporting, export, MCP, vulnerability-adaptor, and policy capabilities while correcting air-gapped, exception, scan, SARIF, and image-scan behavior. deploy-library now uses the embedded VAP bundle by default.
Check if affected (1)
breakingThe deploy-library bundle source
Applies if you use
deploy-library.
A maintenance release fixes pipeline validation so $(results. references are accepted in Pipeline task parameters. Nothing else described requires operator attention.
This release includes a security-related default change in TLS key exchange. The change affects deployments that use TLS key exchange.
Check if affected (1)
securityPost-Quantum Cryptography as the default for TLS key exchange
Applies when TLS key exchange is used.
This release tightens Gateway API and service-port handling and corrects tracing identity construction. It also updates dependencies and shipped components, with no security advisories or explicitly described vulnerabilities.
Action needed (1)
breakingUndefined service port requests disallowed
The
destinationcomponent now disallows requests to service ports that are not defined.
Check if affected (1)
breakingGateway API checks during
HelminstallationApplies when you use
Helm.
A maintenance release that corrects runtime, workflow, actor, metrics, component, and sidecar defects. It adds Kafka configuration and health-check capabilities and includes two security-related dependency upgrades.
Action needed (3)
securitymedium
github.updated for CVE-2025-69725com/go-chi/chi/v5 github.is updated to v5.2.4, which resolves CVE-2025-69725.com/go-chi/chi/v5 securitymedium
go.andmongodb. org/mongo-driver github.updatescom/dapr/components-contrib go.is updated to v1.17.7, and themongodb. org/mongo-driver github.dependency is bumped to v1.18.3. The change carries advisory CVE-2026-2303.com/dapr/components-contrib breakingConflict errors for workflow instance IDs
Create requests for workflow instance IDs are rejected with a conflict error that names the blocking child workflow.
An experimental feature release adds guest, CLI, template, VM-driver, and device capabilities. It also changes the Windows default driver and socket_vmnet access constraint, removes a host dependency, and updates nerdctl.
Check if affected (3)
breakingThe default VM driver, from
wsl2toqemuApplies if you do not configure the VM driver.
breakingThe
socket_vmnetaccess constraintApplies if you use
socket_vmnet.breakingThe
almalinux-kittentemplate, moved toexperimental/Applies if you use
almalinux-kitten.
This release adds configuration and feature-gate capabilities, corrects defects, changes histogram bucket values, and introduces the configstorage module. It also removes or deprecates API symbols, with no security issues or advisories identified.
Check if affected (1)
breakingThe
BalancerNamefunction, removedApplies if you use
BalancerName.
Plan ahead (1)
deprecatedThe
WithForceUnmarshaleroption, deprecatedApplies if you use
WithForceUnmarshaler.
This release restores a previously missing permission and updates the CAPI, Go, cert-manager, and etcd dependencies. No security advisories or security-specific fixes are disclosed.
Source ↗This release restores delete permission on secrets and updates the CAPI dependency and Go toolchain version. No security advisories or operator actions are specified.
Source ↗This release combines new cost data and collection capabilities with operational updates. Endpoint access defaults change, and the release includes corrections across pricing, pagination, request handling, providers, and serialization.
Check if affected (1)
breakingEndpoint defaults, deactivated without an admin token
Applies if you use endpoints without setting an admin token.
A feature and maintenance release with authorization tightening, credential handling fixes, and validation improvements. It also adds capabilities across Helm, CUE, workflows, registries, and dependency management.
Check if affected (3)
securityRestricted access to
vela-system definitionsApplies if you use
vela-system definitions.securityCredential redaction for Terraform module remote URLs
Applies if you configure
Terraform module remote URLs.breakingUndeclared parameter validation for application definitions
Applies if you use
application definitions.
A release with backend compatibility removals, forced migrations, new configuration and CLI capabilities, and correctness fixes across storage, extensions, and related components. It does not disclose security advisories or security-specific flaws.
Action needed (1)
breakingTemplate creation through
esclientTemplate creation moves to
esclient, and legacy mapping rendering is retired.
Check if affected (3)
breakingSupport for
elasticsearch v6, removedApplies if you use
elasticsearch v6.breakingThe
jaegermcpextension, merged intojaegerqueryApplies if you use the
jaegermcpextension.breakingExpired stable feature gates, removed
Applicability is not stated in the release notes.
Plan ahead (1)
deprecatedThe
legacy flag, deprecatedApplies if you use
legacy flag.
Nothing here needs operator attention.
Source ↗A maintenance release with numerous correctness fixes, Gateway API and telemetry additions, dependency and image updates, and internal behavior changes. No security advisories or explicitly described vulnerabilities are present.
Check if affected (1)
breakingHelm handling of
hostFirewall.disablementenabled Applies when you use Helm to disable
hostFirewall., toggling it from true to false.enabled
Cilium v1.18.12 adds Gateway access-log configuration and BYOCNI loopback support. It also fixes policy, startup, Gateway validation, IPAM, and metric-label defects, while updating shipped images and dependencies; no security advisories or security-specific flaws are disclosed.
Source ↗Cilium v1.17.18 contains ordinary correctness fixes, a new BYOCNI loopback capability, and dependency and image updates. No security advisories or operator actions are identified.
Source ↗A maintenance release corrects overly small timeouts in the Receiver's Shipper component. The change is recorded in the release notes as "receive: bump timeouts".
Source ↗Istio 1.29.6 is a correctness-focused maintenance release. The fixes address ambient traffic draining, HBONE capability propagation, ambient CNI responsiveness, Istiod memory use, and cross-network traffic through east-west gateways.
Source ↗Istio 1.30.3 is a maintenance release focused on operator-facing updates, performance work, and defect corrections. The listed release material includes fixes across certificate rotation, ambient mode, waypoint routing, multicluster behavior, and Istiod scalability.
Source ↗A feature and behavior release that adds Windows and device-management capabilities, changes edge database and node-querying behavior, and updates the Kubernetes dependency. Device status retrieval now uses the new DeviceStatus CRD.
Check if affected (1)
breakingThe
DeviceStatus CRDfor device status retrievalApplies if you use the
DeviceStatus CRD.
KubeEdge v1.22.2 combines defect corrections with new operator-facing capabilities, Beehive restart-policy support, device-model API changes, and an upgrade to Kubernetes v1.31.12. No security advisories or security-specific fixes are disclosed.
Source ↗This release combines correctness fixes with changes to node-job behavior, operator capabilities, and command workflows. It introduces configuration updates for edge nodes, which are disabled by default and require an EdgeCore restart; no security advisories are identified.
Check if affected (6)
breakingThe v1alpha2
NodeUpgradeJobandImagePrePullJobdefaultsApplies if you use
NodeUpgradeJoborImagePrePullJob.breakingNode-job switching constraint
Applies if you use
NodeUpgradeJoborImagePrePullJob.breakingThe
taskManagernode-job module, disabled by defaultApplies if
EdgeCoreis running.- + 3 more on the release page
Plan ahead (1)
deprecatedThe v1alpha1
NodeUpgradeJobandImagePrePullJobjobs, deprecatedApplies if you use
NodeUpgradeJoborImagePrePullJob.
Release 3.31.0 contains a dependency update addressing vulnerabilities in graphql/server. It also includes correctness fixes across probes, GraphQL, authentication, infrastructure, and experiment handling.
Action needed (1)
securityDependencies in
graphql/serverupdatedDependencies in
graphql/serverare updated to fix vulnerabilities. The update ships in Release 3.31.0.
A maintenance release includes a Helm chart defect fix. The available release detail does not identify which chart behavior changed.
Source ↗A broad release with operator-facing changes across configuration, protocols, extensions, networking, and observability. Security fixes address multiple identified CVEs and a GHSA, while changed defaults, stricter input validation, and removed functionality may affect existing deployments.
Check if affected (11)
securityhigh
HTTP/2header limits and flood protectionApplies if you use
HTTP/2.securityhigh
HTTP/3QPACK andcontent-lengthsecurity fixesApplies if you use
HTTP/3.securityhighAdditional protocol, parser, formatter, and decompression security fixes
Applies if you use DNS query validation, JSON nesting limits, PROXY protocol TLV, the formatter, TCP StatsD, TLS SAN, or Zstd decompression.
- + 8 more on the release page
A substantial mixed feature and maintenance release adds backend, frontend, catalog, authentication, webhook, and TechDocs capabilities alongside dependency updates and defect fixes. It also includes operator-visible changes to APIs, configuration validation, OpenAPI tooling, and MCP transport behavior; no security advisories or security-specific fixes are disclosed.
Action needed (1)
breakingOpenAPI breaking change detection with
oasdiff@useoptic/opticand@useoptic/openapi-utilitieshave been replaced withoasdifffor OpenAPI breaking change detection.
Check if affected (12)
breakingSchema loading rejects invalid imports
Applicability is not stated in the release notes.
breakingThe
package schema openapi initandrepo schema openapi testcommands, removedApplies if you use
package schema openapi initorrepo schema openapi test.breakingMutually exclusive
userGroupMember.andpath user.configurationfilter Applies if you configure both
userGroupMember.andpath user..filter - + 9 more on the release page
Plan ahead (3)
deprecatedOpaque entity header extension point deprecation
Applies if you use the opaque entity header extension point.
deprecatedDynamic Client Registration deprecation warning
Applies if you enable Dynamic Client Registration.
deprecatedStable
auth.configurationclientIdMetadataDocuments Applies if you configure
auth.orclientIdMetadataDocuments auth..experimentalClientIdMetadataDocuments
A maintenance release rebuilds the pack on Go 1.25.12 to address two disclosed standard library security issues. It also updates several dependencies and includes a newer default lifecycle version.
Check if affected (1)
securityhigh
Go1.25.12 standard library rebuild for GO-2026-4970 and GO-2026-5856Applies if you use
1..25. 11 -> 1. 25. 12
Flux v2.9.2 includes an operator-relevant regression fix for Kustomizations whose openapi. points to a URL, along with dependency and toolkit component updates. CRD description corrections are documentation-only.
wasmCloud v2.5.2 adds asynchronous PostgreSQL support and WIT and wkg configuration resolution. It also improves HTTP recognition and default capability backend handling, while including dependency and internal tooling updates.
Source ↗Dapr v1.16.17 fixes Scheduler handling for actor reminder and job names and actor IDs that were accepted at the API edge but rejected by stricter DNS-1123 validation. It also corrects the related validation error and actor metadata handling, with no operator action required beyond upgrading.
Source ↗A maintenance release fixes a TSDB head-chunk cache defect. After head-chunk truncation, range queries no longer receive samples from the wrong chunk or spurious not-found errors.
Source ↗This release changes dependency composition and CoreDNS behavior. It adds a forward plugin directive and expands secondary-plugin zone support, while also addressing a non-64-bit build defect through a dependency adjustment.
A maintenance release with operator-relevant fixes and behavior changes, plus security work in the 1.18 release line. It includes namespace-boundary enforcement for generators and security dependency updates.
Action needed (1)
securitySecurity dependency updates
Security dependency updates from #16340 are backported to
release-1..18
Check if affected (1)
securityNamespace-boundary enforcement in
generator.apply() Applies if you use
generator..apply()
A release with operator-visible behavior corrections, new capabilities, configuration changes, and updated defaults. The changes span CoreDNS core behavior and multiple plugins, with no security advisories or explicitly described vulnerabilities.
Action needed (1)
breakingGo TLS defaults in
coreThe
corecomponent uses Go TLS defaults in this release.
Check if affected (1)
breakingDefault truncate amount for bare
truncateApplies if you configure
truncate.
A maintenance release with an enforced CRI constraint, aligned erofs defaults, correctness and behavior fixes, and dependency updates. It contains no security advisories or explicitly described vulnerabilities.
Check if affected (2)
breakingThe
CreateContainerconstraint for stopped sandboxesApplies if you use
CreateContainerwhen the sandbox is not running.breakingThe
erofsdefault mkfs block sizeApplies if you use
erofsacross platforms.
A maintenance release with CRI and image-distribution fixes. The CRI constraint on CreateContainer requests may require action, while the other fixes take effect through the upgrade.
Action needed (1)
breaking
CreateContainerrejection for stopped sandboxesThe CRI now rejects
CreateContainerrequests when the sandbox is not running. This constraint ships in containerd v2.2.6.
A maintenance release fixes content storage pollution caused by fallback during reference resolution. It also updates the Go toolchain to versions 1.26.5 and 1.25.12.
Source ↗containerd v1.7.34 fixes a CRI event-loss defect and updates the Go toolchain. It also upgrades several golang. dependencies.