RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Jul 2026Clear ×
Helmv3.21.3Kubernetes CoreJul 9, 2026

This release includes a security-related dependency cleanup and a dependency update. The github.com/containerd/containerd dependency moves from 1.7.32 to 1.7.33.

Action needed (1)

  • securityThe containerd v1 dependency, removed

    The containerd v1 dependency is removed in Helm v3.21.3 to resolve govulncheck CVEs associated with 037733e7d51b08e30a0233bd546c345ab3ea3bba.

Source
Helmv4.2.3Kubernetes CoreJul 9, 2026

A maintenance release updates golang.org/x/crypto from 0.53.0 to 0.54.0. It also contains release-navigation text and a generic upgrade recommendation.

Source
SPIREv1.15.2SecurityJul 9, 2026

A feature and behavior release that adds operator-facing configuration and integration options while changing supported inputs and runtime behavior. It also includes a dependency migration for disclosed CVEs and deprecates no existing operator feature.

Action needed (2)

  • securityMigration from github.com/docker/docker to github.com/moby/moby

    Dependencies from github.com/docker/docker were migrated to their github.com/moby/moby equivalents to resolve CVEs. The migration ships in this release.

  • breakingRPC metrics from agent health check loopback calls

    Agent health check loopback calls no longer emit RPC metrics. This reduces metrics noise in the agent.

Check if affected (1)

  • breakingJWT-SVID serving by the delegated API

    Applies if you use the delegated API for admin or downstream entries.

Source
Argov3.4.5CI/CD & App DeliveryJul 9, 2026

v3.4.5 is a maintenance release focused on correctness fixes and dependency updates. No security advisory or vulnerability is disclosed.

Source
Flatcar Container Linuxstable-4593.2.4Provisioning & RuntimeJul 9, 2026

This Flatcar release is a security update focused on fixes for disclosed Linux vulnerabilities. It also updates the Linux and ca-certificates dependencies.

Action needed (1)

Source
Flatcar Container Linuxlts-4081.3.9Provisioning & RuntimeJul 9, 2026

This Flatcar release is a security update with fixes for Linux issues identified by CVE advisories. It also updates Linux and ca-certificates.

Action needed (1)

Source
Prometheusv3.5.5ObservabilityJul 9, 2026

Prometheus v3.5.5 includes a Go 1.25.12 toolchain change and a disclosed security fix in the UI. The security fix concerns the sanitize-html dependency and CVE-2026-53606.

Action needed (1)

  • securitymediumThe sanitize-html dependency update for CVE-2026-53606

    The Prometheus UI updates sanitize-html to v2.17.5 to fix CVE-2026-53606.

Source
Keycloak26.7.0SecurityJul 9, 2026

A substantial operator-focused release that adds and promotes APIs, feature gates, administration capabilities, and deployment options. It also includes deprecations and removals, along with fixes for account takeover, log injection and audit forgery, key-attestation bypass, QR-code dimension denial of service, and four CVE-identified vulnerabilities.

Action needed (1)

  • securityPre-account takeover attack exposure

    The release corrects an issue that provided room for pre-account takeover attacks.

Check if affected (19)

Plan ahead (4)

  • deprecatedThe V1 API, deprecated

    Applies if you use V1.

  • deprecatedThe Require Discoverable Credential option, deprecated

    Applies if you configure the Require Discoverable Credential option.

  • deprecatedThe Twitter IDP implementation, deprecated

    Applies if you use the Twitter IDP implementation.

  • + 1 more on the release page
Source
TiKVv8.5.7Storage & DataJul 9, 2026

A feature and maintenance release with new configuration and resource-management capabilities, plus corrections for invalid timestamp handling, memory use, and stability. It also upgrades vulnerable third-party dependencies and aligns compatibility fixes with upstream.

Action needed (1)

  • securityThird-party dependency upgrades for TiKV 8.5

    TiKV 8.5 upgrades vulnerable third-party dependencies and aligns the required compatibility fixes with upstream.

Check if affected (1)

  • breakingInvalid max_ts updates rejected by default

    Applies if you do not set storage.max-ts.action-on-invalid-update.

Source
cert-managerv1.21.0SecurityJul 8, 2026

A feature and maintenance release with operator-facing RBAC, Helm, API, and feature-gate changes, alongside new capabilities and defect corrections. It includes changes to configuration, permissions, certificate issuance, and integrations.

Check if affected (5)

  • securitycert-manager-edit aggregate ClusterRole permission removal, GHSA-8rvj-mm4h-c258

    Applies if you use the cert-manager-edit aggregate ClusterRole.

  • breakingObjectReference API removal

    Applies if you use ObjectReference in an API.

  • breakingPrometheus ServiceMonitor and PodMonitor Helm value removal

    Applies if you configure any of prometheus.servicemonitor.targetPort, prometheus.servicemonitor.path, or prometheus.podmonitor.path.

  • + 2 more on the release page

Plan ahead (2)

  • deprecatedGateway API controller configuration fields

    Applies if you configure any of enableGatewayAPI, enableGatewayAPIListenerSet, gatewayAPI.enabled, or gatewayAPI.enableListenerSet.

  • deprecatedServerSideApply feature gate deprecation

Source
etcdv3.7.0Kubernetes CoreJul 8, 2026

A maintenance release with security fixes, an authentication correction, and dependency and toolchain updates. The security-related changes address CRL enforcement and golang.org/x/crypto.

Action needed (1)

Check if affected (1)

  • securityCRL enforcement bypass on the gRPC listener, fixed

    Applies if you configure --listen-client-http-urls.

Source
Thanosv0.42.0ObservabilityJul 8, 2026

A release with security corrections, breaking configuration removals, and an output-field rename that may require operator or log-collector changes. It also adds TLS and cache configuration, query and tracing changes, and defect fixes across several Thanos components.

Action needed (1)

  • securitycriticalthanos-community/grpc-go fork update for CVE-2026-33186

    The thanos-community/grpc-go fork is bumped to fix CVE-2026-33186, an authorization bypass via malformed :path headers.

Check if affected (4)

  • securityReceive tenant ID validation

    Applies if you run Receive.

  • breakingQuery-Frontend time_taken field renamed to time_taken_ms

    Applies if you run Query-Frontend.

  • breaking--shipper.ignore-unequal-block-size flag removed

    Applies if you configure --shipper.ignore-unequal-block-size.

  • + 1 more on the release page
Source
gRPCv1.82.1Networking & MessagingJul 8, 2026

A dependency maintenance release raises Python's minimum supported protobuf version from 6.33.5 to 7.35.1. It contains no other operator-facing changes.

Check if affected (1)

  • breakingPython protobuf dependency lower bound update

    Applies if you use Python.

Source
Tektonv1.6.5CI/CD & App DeliveryJul 8, 2026

This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.

Action needed (1)

  • securityGo 1.25.10 dependency update

    Go is updated to 1.25.10 for CVE remediation in this release.

Source
Tektonv1.9.6CI/CD & App DeliveryJul 8, 2026

Tekton v1.9.6 contains dependency updates for CVE remediation. The release affects Go and two golang.org packages, with no specific advisory identifiers or vulnerability details in the note.

Action needed (3)

  • securityGo 1.25.10 update

    Go is updated to 1.25.10 for CVE remediation in v1.9.6.

  • securitygolang.org/x/crypto v0.52.0 update

    golang.org/x/crypto is updated to v0.52.0 for CVE remediation in v1.9.6.

  • securitygolang.org/x/net v0.55.0 update

    golang.org/x/net is updated to v0.55.0 for CVE remediation in v1.9.6.

Source
Rookv1.20.2Storage & DataJul 7, 2026

Rook v1.20.2 includes dependency updates, behavioral changes, and fixes across Ceph, CSI, core, security, and storage operations. The release also tightens the manager NetworkPolicy to ingress-only; no vulnerability or advisory is disclosed.

Source
Fluxv2.9.1CI/CD & App DeliveryJul 7, 2026

Flux v2.9.1 is a maintenance release focused on defect fixes, dependency and component updates, and a performance improvement. It includes changes across controller behavior and build and decryption paths, with no security advisories disclosed.

Source
OpenTelemetryv0.156.0ObservabilityJul 7, 2026

OpenTelemetry v0.156.0 adds mdatagen and memory-limiter capabilities, changes generated configuration APIs, and corrects runtime and API defects. No security advisories or security-specific fixes are disclosed.

Source
OpenKruisev1.9.1CI/CD & App DeliveryJul 4, 2026

OpenKruise v1.9.1 is a maintenance release focused on an operator-facing defect in Kubernetes server version parsing. The fix addresses a controller panic involving certain GKE and EKS version strings.

Source
k8gbv0.20.0Kubernetes CoreJul 3, 2026

k8gb v0.20.0 centers on ZoneDelegation-based DNS management, with TLSRoute and annotation support alongside changes to defaults and naming. The release also includes defect fixes and dependency updates, and no security advisories or vulnerabilities are identified.

Check if affected (4)

  • breakingThe Bootstrap service, removed

    Applies if your configuration uses the Bootstrap service.

  • breakingThe dynamicZones setting, removed

    Applies if your configuration uses dynamicZones.

  • breakingThe doFinalize default, set to false

    Applies if you use doFinalize in ZoneDelegation finalization.

  • + 1 more on the release page
Source
Limav2.1.4Kubernetes CoreJul 3, 2026

Lima v2.1.4 contains behavior fixes, FreeBSD template and general template updates, a nerdctl update from v2.3.3 to v2.3.4, and a change to the JSON network-list output. No security advisories or security-specific fixes are disclosed.

Source
Open Policy Agent (OPA)v1.18.2SecurityJul 2, 2026

A patch release fixes a formatting regression in opa fmt introduced in v1.18.0. It restores behavior where existing newlines in single-item collections determine whether policies are formatted on one line or across multiple lines.

Source
CRI-Ov1.35.5Kubernetes CoreJul 2, 2026

CRI-O v1.35.5 includes an operator-facing correctness fix for container status ImageRef values after a CRI-O restart. It also updates CPU injection and gomaxprocs handling to account for workload partitioning and reduce potential Go scheduler throttling.

Source
gRPCv1.82.0Networking & MessagingJul 2, 2026

A feature and maintenance release that adds and changes capabilities across Core, PHP, Python, and Ruby, corrects runtime defects, and upgrades protobuf dependencies. The Python 1.82.0 package was removed from PyPI.

Check if affected (1)

  • breakinggRPC Python release 1.82.0, yanked from PyPI

    Applies if you use gRPC Python release 1.82.0.

Source
Harborv2.15.2Storage & DataJul 2, 2026

A maintenance release with a forced internal PostgreSQL major-version upgrade, a redis to valkey cache backend replacement, dependency and component updates, and defect corrections. Token and blob-mount validation is hardened.

Action needed (1)

  • securityToken and blob-mount source validation

    Blob-mount source projects are validated, and tokens without iat are rejected.

Check if affected (2)

  • breakingThe bundled PostgreSQL version, upgraded

    Applies if you use PostgreSQL.

  • breakingThe cache backend, changed from redis to valkey

    Applies if you use redis.

Source
CRI-Ov1.36.2Kubernetes CoreJul 2, 2026

A performance behavior change updates the gomaxprocs hook to ignore workload partitioning when deciding whether to inject it. The calculation gives containers at least twice their requested number of CPUs to reduce potential Go scheduler throttling.

Source
CRI-Ov1.34.10Kubernetes CoreJul 2, 2026

A maintenance release with fixes for CPU allocation behavior and container status reporting. CPU allocation is corrected to reduce scheduler throttling, and ImageRef remains stable across CRI-O restarts.

Source
etcdv3.6.13Kubernetes CoreJul 1, 2026

A maintenance release with authentication and certificate-revocation enforcement fixes, Go toolchain and dependency updates, and a new v2 deprecation option. The security-related changes include fixes and dependency updates associated with the listed advisories.

Action needed (2)

  • securityhighgo.opentelemetry.io/otel dependencies, updated to v1.43.0

    The go.opentelemetry.io/otel and go.opentelemetry.io/otel/sdk dependencies are updated from v1.40.0 to v1.43.0. The updates address CVE-2026-29181 and CVE-2026-39883.

  • securityhighgolang.org/x/crypto, updated to v0.52.0

    The golang.org/x/crypto dependency is updated to v0.52.0. The change is associated with CVE-2026-39828, CVE-2026-39835, CVE-2026-46597, and CVE-2026-46598.

Check if affected (1)

  • securityCRL enforcement bypass on the gRPC listener, fixed

    Applies if --listen-client-http-urls is configured.

Source
etcdv3.5.32Kubernetes CoreJul 1, 2026

A maintenance release with server configuration, access control, authentication, validation, logging, and dependency updates. Deployments using the affected listener configuration or OpenTelemetry dependencies are directly concerned by the included fixes.

Action needed (1)

  • securityhighOpenTelemetry dependencies updated for CVE-2026-29181 and CVE-2026-39883

    go.opentelemetry.io/otel and go.opentelemetry.io/otel/sdk were updated from v1.40.0 to v1.43.0. The updates address CVE-2026-29181 and CVE-2026-39883.

Check if affected (1)

  • securityCRL enforcement with --listen-client-http-urls

    Applies if --listen-client-http-urls is configured.

Source
Prometheusv3.13.0ObservabilityJul 1, 2026

A long-term support release with security-related dependency updates, PromQL changes, new APIs and configuration controls, and bug fixes. It also replaces a shipped license artifact and includes performance improvements.

Action needed (2)

  • securitycriticalThe sanitize-html dependency update

    The UI updates sanitize-html to address a cross-site scripting vulnerability, identified as CVE-2026-44990.

  • breakingThe third-party license artifact

    Third-party npm dependency licenses are embedded in the Prometheus binary and served at /assets/third-party-licenses.txt. This replaces the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images.

Check if affected (2)

  • securitymediumRedirect credential forwarding

    Applies if you use scraping, remote read/write, alerting, or service discovery.

  • breakingPromQL duration-expression function names

    Applies if you enable experimental-duration-expr and use min() and max().

Source
Longhornv1.11.3Storage & DataJul 1, 2026

Longhorn v1.11.3 is a maintenance release with multiple correctness fixes and new metrics for LONGHORN_DISTRO. It requires Kubernetes v1.34 or later because the CSI external provisioner was upgraded to v6.3.0.

Source
Istio1.28.10Networking & MessagingJul 1, 2026

Istio 1.28.10 contains an operator-relevant correctness fix in the krt controller framework. The available release information does not include a standalone change item for this fix.

Source
← Newer
Browse by month