RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jul 2026Clear ×
Kubernetesv1.35.7Kubernetes CoreJul 22, 2026

A maintenance release with fixes to cri-api, kubeadm etcd handling, and kubelet logging. It also updates the Go toolchain used to build Kubernetes to 1.25.12.

Source
Kubernetesv1.34.10Kubernetes CoreJul 22, 2026

A maintenance release with kubeadm and kubelet behavior corrections, a changed kubeadm timeout default, and a deferred Kubelet deprecation removal. It also includes a toolchain dependency update and no identified security advisories.

Plan ahead (1)

  • deprecatedKubelet configurations flags deprecation removal timelineremoval planned in 1.38

    Applies if you configure Kubelet's configurations flags.

Source
Kubescapev4.0.11SecurityJul 22, 2026

A feature and maintenance release that adds scanning, reporting, export, MCP, vulnerability-adaptor, and policy capabilities while correcting air-gapped, exception, scan, SARIF, and image-scan behavior. deploy-library now uses the embedded VAP bundle by default.

Check if affected (1)

  • breakingThe deploy-library bundle source

    Applies if you use deploy-library.

Source
Tektonv1.14.1CI/CD & App DeliveryJul 22, 2026

A maintenance release fixes pipeline validation so $(results.*) references are accepted in Pipeline task parameters. Nothing else described requires operator attention.

Source
gRPCv1.83.0Networking & MessagingJul 22, 2026

This release includes a security-related default change in TLS key exchange. The change affects deployments that use TLS key exchange.

Check if affected (1)

  • securityPost-Quantum Cryptography as the default for TLS key exchange

    Applies when TLS key exchange is used.

Source
Linkerdedge-26.7.1Networking & MessagingJul 21, 2026

This release tightens Gateway API and service-port handling and corrects tracing identity construction. It also updates dependencies and shipped components, with no security advisories or explicitly described vulnerabilities.

Action needed (1)

  • breakingUndefined service port requests disallowed

    The destination component now disallows requests to service ports that are not defined.

Check if affected (1)

  • breakingGateway API checks during Helm installation

    Applies when you use Helm.

Source
Daprv1.18.2Orchestration & ManagementJul 21, 2026

A maintenance release that corrects runtime, workflow, actor, metrics, component, and sidecar defects. It adds Kafka configuration and health-check capabilities and includes two security-related dependency upgrades.

Action needed (3)

  • securitymediumgithub.com/go-chi/chi/v5 updated for CVE-2025-69725

    github.com/go-chi/chi/v5 is updated to v5.2.4, which resolves CVE-2025-69725.

  • securitymediumgo.mongodb.org/mongo-driver and github.com/dapr/components-contrib updates

    go.mongodb.org/mongo-driver is updated to v1.17.7, and the github.com/dapr/components-contrib dependency is bumped to v1.18.3. The change carries advisory CVE-2026-2303.

  • breakingConflict errors for workflow instance IDs

    Create requests for workflow instance IDs are rejected with a conflict error that names the blocking child workflow.

Source
Limav2.2.0Kubernetes CoreJul 21, 2026

An experimental feature release adds guest, CLI, template, VM-driver, and device capabilities. It also changes the Windows default driver and socket_vmnet access constraint, removes a host dependency, and updates nerdctl.

Check if affected (3)

  • breakingThe default VM driver, from wsl2 to qemu

    Applies if you do not configure the VM driver.

  • breakingThe socket_vmnet access constraint

    Applies if you use socket_vmnet.

  • breakingThe almalinux-kitten template, moved to experimental/

    Applies if you use almalinux-kitten.

Source
OpenTelemetryv0.157.0ObservabilityJul 21, 2026

This release adds configuration and feature-gate capabilities, corrects defects, changes histogram bucket values, and introduces the configstorage module. It also removes or deprecates API symbols, with no security issues or advisories identified.

Check if affected (1)

  • breakingThe BalancerName function, removed

    Applies if you use BalancerName.

Plan ahead (1)

  • deprecatedThe WithForceUnmarshaler option, deprecated

    Applies if you use WithForceUnmarshaler.

Source
metal3-iov0.13.2Provisioning & RuntimeJul 21, 2026

This release restores a previously missing permission and updates the CAPI, Go, cert-manager, and etcd dependencies. No security advisories or security-specific fixes are disclosed.

Source
metal3-iov0.12.6Provisioning & RuntimeJul 21, 2026

This release restores delete permission on secrets and updates the CAPI dependency and Go toolchain version. No security advisories or operator actions are specified.

Source
OpenCostv1.121.0ObservabilityJul 20, 2026

This release combines new cost data and collection capabilities with operational updates. Endpoint access defaults change, and the release includes corrections across pricing, pagination, request handling, providers, and serialization.

Check if affected (1)

  • breakingEndpoint defaults, deactivated without an admin token

    Applies if you use endpoints without setting an admin token.

Source
KubeVelav1.11.0CI/CD & App DeliveryJul 20, 2026

A feature and maintenance release with authorization tightening, credential handling fixes, and validation improvements. It also adds capabilities across Helm, CUE, workflows, registries, and dependency management.

Check if affected (3)

  • securityRestricted access to vela-system definitions

    Applies if you use vela-system definitions.

  • securityCredential redaction for Terraform module remote URLs

    Applies if you configure Terraform module remote URLs.

  • breakingUndeclared parameter validation for application definitions

    Applies if you use application definitions.

Source
Jaegerv2.20.0ObservabilityJul 20, 2026

A release with backend compatibility removals, forced migrations, new configuration and CLI capabilities, and correctness fixes across storage, extensions, and related components. It does not disclose security advisories or security-specific flaws.

Action needed (1)

  • breakingTemplate creation through esclient

    Template creation moves to esclient, and legacy mapping rendering is retired.

Check if affected (3)

  • breakingSupport for elasticsearch v6, removed

    Applies if you use elasticsearch v6.

  • breakingThe jaegermcp extension, merged into jaegerquery

    Applies if you use the jaegermcp extension.

  • breakingExpired stable feature gates, removed

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedThe legacy flag, deprecated

    Applies if you use legacy flag.

Source
Ciliumv1.19.6Networking & MessagingJul 16, 2026

A maintenance release with numerous correctness fixes, Gateway API and telemetry additions, dependency and image updates, and internal behavior changes. No security advisories or explicitly described vulnerabilities are present.

Check if affected (1)

  • breakingHelm handling of hostFirewall.enabled disablement

    Applies when you use Helm to disable hostFirewall.enabled, toggling it from true to false.

Source
Ciliumv1.18.12Networking & MessagingJul 16, 2026

Cilium v1.18.12 adds Gateway access-log configuration and BYOCNI loopback support. It also fixes policy, startup, Gateway validation, IPAM, and metric-label defects, while updating shipped images and dependencies; no security advisories or security-specific flaws are disclosed.

Source
Ciliumv1.17.18Networking & MessagingJul 16, 2026

Cilium v1.17.18 contains ordinary correctness fixes, a new BYOCNI loopback capability, and dependency and image updates. No security advisories or operator actions are identified.

Source
Thanosv0.42.1ObservabilityJul 16, 2026

A maintenance release corrects overly small timeouts in the Receiver's Shipper component. The change is recorded in the release notes as "receive: bump timeouts".

Source
Istio1.29.6Networking & MessagingJul 16, 2026

Istio 1.29.6 is a correctness-focused maintenance release. The fixes address ambient traffic draining, HBONE capability propagation, ambient CNI responsiveness, Istiod memory use, and cross-network traffic through east-west gateways.

Source
Istio1.30.3Networking & MessagingJul 16, 2026

Istio 1.30.3 is a maintenance release focused on operator-facing updates, performance work, and defect corrections. The listed release material includes fixes across certificate rotation, ambient mode, waypoint routing, multicluster behavior, and Istiod scalability.

Source
KubeEdgev1.23.1Provisioning & RuntimeJul 15, 2026

A feature and behavior release that adds Windows and device-management capabilities, changes edge database and node-querying behavior, and updates the Kubernetes dependency. Device status retrieval now uses the new DeviceStatus CRD.

Check if affected (1)

  • breakingThe DeviceStatus CRD for device status retrieval

    Applies if you use the DeviceStatus CRD.

Source
KubeEdgev1.22.2Provisioning & RuntimeJul 15, 2026

KubeEdge v1.22.2 combines defect corrections with new operator-facing capabilities, Beehive restart-policy support, device-model API changes, and an upgrade to Kubernetes v1.31.12. No security advisories or security-specific fixes are disclosed.

Source
KubeEdgev1.21.2Provisioning & RuntimeJul 15, 2026

This release combines correctness fixes with changes to node-job behavior, operator capabilities, and command workflows. It introduces configuration updates for edge nodes, which are disabled by default and require an EdgeCore restart; no security advisories are identified.

Check if affected (6)

  • breakingThe v1alpha2 NodeUpgradeJob and ImagePrePullJob defaults

    Applies if you use NodeUpgradeJob or ImagePrePullJob.

  • breakingNode-job switching constraint

    Applies if you use NodeUpgradeJob or ImagePrePullJob.

  • breakingThe taskManager node-job module, disabled by default

    Applies if EdgeCore is running.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe v1alpha1 NodeUpgradeJob and ImagePrePullJob jobs, deprecated

    Applies if you use NodeUpgradeJob or ImagePrePullJob.

Source
Litmus3.31.0ObservabilityJul 15, 2026

Release 3.31.0 contains a dependency update addressing vulnerabilities in graphql/server. It also includes correctness fixes across probes, GraphQL, authentication, infrastructure, and experiment handling.

Action needed (1)

  • securityDependencies in graphql/server updated

    Dependencies in graphql/server are updated to fix vulnerabilities. The update ships in Release 3.31.0.

Source
Envoyv1.39.0Networking & MessagingJul 14, 2026

A broad release with operator-facing changes across configuration, protocols, extensions, networking, and observability. Security fixes address multiple identified CVEs and a GHSA, while changed defaults, stricter input validation, and removed functionality may affect existing deployments.

Check if affected (11)

  • securityhighHTTP/2 header limits and flood protection

    Applies if you use HTTP/2.

  • securityhighHTTP/3 QPACK and content-length security fixes

    Applies if you use HTTP/3.

  • securityhighAdditional protocol, parser, formatter, and decompression security fixes

    Applies if you use DNS query validation, JSON nesting limits, PROXY protocol TLV, the formatter, TCP StatsD, TLS SAN, or Zstd decompression.

  • + 8 more on the release page
Source
Backstagev1.53.0CI/CD & App DeliveryJul 14, 2026

A substantial mixed feature and maintenance release adds backend, frontend, catalog, authentication, webhook, and TechDocs capabilities alongside dependency updates and defect fixes. It also includes operator-visible changes to APIs, configuration validation, OpenAPI tooling, and MCP transport behavior; no security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingOpenAPI breaking change detection with oasdiff

    @useoptic/optic and @useoptic/openapi-utilities have been replaced with oasdiff for OpenAPI breaking change detection.

Check if affected (12)

  • breakingSchema loading rejects invalid imports

    Applicability is not stated in the release notes.

  • breakingThe package schema openapi init and repo schema openapi test commands, removed

    Applies if you use package schema openapi init or repo schema openapi test.

  • breakingMutually exclusive userGroupMember.path and user.filter configuration

    Applies if you configure both userGroupMember.path and user.filter.

  • + 9 more on the release page

Plan ahead (3)

  • deprecatedOpaque entity header extension point deprecation

    Applies if you use the opaque entity header extension point.

  • deprecatedDynamic Client Registration deprecation warning

    Applies if you enable Dynamic Client Registration.

  • deprecatedStable auth.clientIdMetadataDocuments configuration

    Applies if you configure auth.clientIdMetadataDocuments or auth.experimentalClientIdMetadataDocuments.

Source
Buildpacksv0.40.8CI/CD & App DeliveryJul 13, 2026

A maintenance release rebuilds the pack on Go 1.25.12 to address two disclosed standard library security issues. It also updates several dependencies and includes a newer default lifecycle version.

Check if affected (1)

  • securityhighGo 1.25.12 standard library rebuild for GO-2026-4970 and GO-2026-5856

    Applies if you use 1.25.11 -> 1.25.12.

Source
Fluxv2.9.2CI/CD & App DeliveryJul 13, 2026

Flux v2.9.2 includes an operator-relevant regression fix for Kustomizations whose openapi.path points to a URL, along with dependency and toolkit component updates. CRD description corrections are documentation-only.

Source
wasmCloudv2.5.2Orchestration & ManagementJul 10, 2026

wasmCloud v2.5.2 adds asynchronous PostgreSQL support and WIT and wkg configuration resolution. It also improves HTTP recognition and default capability backend handling, while including dependency and internal tooling updates.

Source
Daprv1.16.17Orchestration & ManagementJul 10, 2026

Dapr v1.16.17 fixes Scheduler handling for actor reminder and job names and actor IDs that were accepted at the API edge but rejected by stricter DNS-1123 validation. It also corrects the related validation error and actor metadata handling, with no operator action required beyond upgrading.

Source
Prometheusv3.13.1ObservabilityJul 10, 2026

A maintenance release fixes a TSDB head-chunk cache defect. After head-chunk truncation, range queries no longer receive samples from the wrong chunk or spurious not-found errors.

Source
CoreDNSv1.14.6Kubernetes CoreJul 10, 2026

This release changes dependency composition and CoreDNS behavior. It adds a forward plugin directive and expands secondary-plugin zone support, while also addressing a non-64-bit build defect through a dependency adjustment.

Source
Kyvernov1.18.2SecurityJul 10, 2026

A maintenance release with operator-relevant fixes and behavior changes, plus security work in the 1.18 release line. It includes namespace-boundary enforcement for generators and security dependency updates.

Action needed (1)

  • securitySecurity dependency updates

    Security dependency updates from #16340 are backported to release-1.18.

Check if affected (1)

  • securityNamespace-boundary enforcement in generator.apply()

    Applies if you use generator.apply().

Source
CoreDNSv1.14.5Kubernetes CoreJul 10, 2026

A release with operator-visible behavior corrections, new capabilities, configuration changes, and updated defaults. The changes span CoreDNS core behavior and multiple plugins, with no security advisories or explicitly described vulnerabilities.

Action needed (1)

  • breakingGo TLS defaults in core

    The core component uses Go TLS defaults in this release.

Check if affected (1)

  • breakingDefault truncate amount for bare truncate

    Applies if you configure truncate.

Source
containerdv2.3.3Kubernetes CoreJul 10, 2026

A maintenance release with an enforced CRI constraint, aligned erofs defaults, correctness and behavior fixes, and dependency updates. It contains no security advisories or explicitly described vulnerabilities.

Check if affected (2)

  • breakingThe CreateContainer constraint for stopped sandboxes

    Applies if you use CreateContainer when the sandbox is not running.

  • breakingThe erofs default mkfs block size

    Applies if you use erofs across platforms.

Source
containerdv2.2.6Kubernetes CoreJul 9, 2026

A maintenance release with CRI and image-distribution fixes. The CRI constraint on CreateContainer requests may require action, while the other fixes take effect through the upgrade.

Action needed (1)

  • breakingCreateContainer rejection for stopped sandboxes

    The CRI now rejects CreateContainer requests when the sandbox is not running. This constraint ships in containerd v2.2.6.

Source
containerdv2.0.11Kubernetes CoreJul 9, 2026

A maintenance release fixes content storage pollution caused by fallback during reference resolution. It also updates the Go toolchain to versions 1.26.5 and 1.25.12.

Source
← NewerOlder →
Browse by month