RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Sep 2026Clear ×
Linkerdedge-26.9.1Networking & MessagingSep 4, 2026

A maintenance release updates the proxy and dependencies, fixes destination behavior, and tightens multicluster credential and Link resource handling. The changes concern proxy, destination, and multicluster components, alongside routine dependency updates.

Action needed (2)

  • breakingCluster credential secrets and the exec auth provider

    Cluster credential secrets created by linkerd multicluster link use the token auth provider. The exec auth provider is disallowed because it is not used or necessary.

  • breakingLink resource lookup scope

    Link resource lookups are restricted to the linkerd-multicluster namespace.

Source
containerdv1.7.35Kubernetes CoreSep 4, 2026

A security-focused maintenance release with fixes for vulnerabilities and changes to image fetching and Windows log handling. Runtime and performance improvements are also included.

Action needed (2)

Check if affected (1)

  • breakingThe ScrubLogs default on Windows

    Applies if you run on Windows.

Source
containerdv2.0.12Kubernetes CoreSep 4, 2026

A security-focused maintenance release fixes two disclosed vulnerabilities, changes the Windows logging default, and hardens registry fetching. It also includes correctness and performance fixes.

Action needed (2)

  • securityCVE-2026-53495 and GHSA-7jxh-36q5-gcqv security fix

    This release fixes the disclosed vulnerability identified by CVE-2026-53495 and GHSA-7jxh-36q5-gcqv.

  • securityGHSA-rp3h-jf77-q9p4 security fix

    This release fixes the disclosed vulnerability identified by GHSA-rp3h-jf77-q9p4.

Check if affected (1)

  • breakingThe ScrubLogs Windows default

    Applies if you run containerd on Windows.

Source
containerdv2.2.8Kubernetes CoreSep 4, 2026

A security and maintenance release with fixes for two security advisories, request hardening, runtime and snapshot correctness, and a small performance improvement. No operator migration requirement is stated.

Action needed (2)

Source
Cloud Custodian0.9.52.0SecuritySep 3, 2026

A broad multi-cloud release adds resource integrations, filters, and policy actions across AWS, Azure, and GCP, alongside correctness fixes and dependency updates. Operators should also review the LDAP input handling improvement and the behavior changes affecting existing configurations.

Check if affected (3)

  • breakingThe Status field, replaced by State

    Applies if you configure Status.

  • breakingThe SCM basic auth method, replaced by an Entra ID bearer token

    Applies if you use SCM basic auth.

  • breakingThe cloud-run label mutation fields, restricted to the schema

    Applies if you use cloud-run.

Source
Mesheryv1.0.69Provisioning & RuntimeSep 3, 2026

A maintenance release focused on correctness fixes across the server, CLI, and UI. It also adds a CLI capability and includes dependency updates, with no stated security changes.

Source
Vitessv24.0.3Storage & DataSep 3, 2026

A narrowly scoped breaking maintenance release removes the VRLog endpoint. Its enabling flag remains as a deprecated no-op until v26.

Check if affected (2)

  • breakingThe /debug/vrlog endpoint, removed

    Applies if you use /debug/vrlog.

  • deprecatedThe --vreplication-enable-http-log flag, deprecated as a no-op

    Applies if you configure --vreplication-enable-http-log.

Source
Vitessv23.0.6Storage & DataSep 3, 2026

A maintenance release with correctness fixes and dependency updates. The /debug/vrlog removal and newly enforced safety limits affect operators using those paths.

Action needed (2)

  • breakingRecursion-depth limit on the streaming recursive CTE path

    A recursion-depth limit is enforced on the streaming recursive CTE path.

  • breakingStored-procedure safety checks on the streaming CALL path

    Stored-procedure safety checks are enforced on the streaming CALL path.

Check if affected (1)

  • breakingThe /debug/vrlog endpoint, removed

    Applies if you use /debug/vrlog.

Plan ahead (1)

  • deprecatedThe --vreplication-enable-http-log flag, deprecatedremoval planned in v26

    Applies if you configure --vreplication-enable-http-log.

Source
Rookv1.20.7Storage & DataSep 2, 2026

A maintenance release with operational behavior improvements, CSI compatibility updates, and new external-cluster and deployment capabilities. It includes CSI 3.17.1 for AES256K compatibility and updates to cluster reconciliation, election handling, security initialization, OSD error reporting, and manager module behavior.

Source
Rookv1.19.11Storage & DataSep 2, 2026

A maintenance release focused on CSI compatibility and small behavioral improvements. It includes an update to Rook for CSI 3.16.3 AES256K compatibility, along with changes to monitor elections, cluster health warnings, the Rook manager module, and device path handling.

Source
OpenTelemetryv0.160.0ObservabilitySep 2, 2026

A maintenance and API-evolution release with client configuration deprecations, a higher Go toolchain requirement, performance improvements, and a breaking resource-creation API signature change. The release also includes compatibility, error-handling, platform support, and component behavior updates.

Check if affected (3)

  • breakingDeprecated fields with keepalive section

    Applicability is not stated in the release notes.

  • breakingGo 1.25.0 support removal

    Applies if you depend on go.

  • breakingtelemetry.Factory.CreateResource and telemetry.CreateResourceFunc return signature

    Applies if you use telemetry.Factory.CreateResource or telemetry.CreateResourceFunc.

Plan ahead (1)

  • deprecatedClient configuration fields deprecated in favor of keepalive

    Applies if you configure any of idle_conn_timeout, max_idle_conns, max_idle_conns_per_host, disable_keep_alives, idle_timeout, or keep_alives_enabled.

Source
k8gbv1.0.0Kubernetes CoreSep 2, 2026

A feature and maintenance release with corrections across ZoneDelegation, CoreDNS, and geotagging behavior. It also adds configuration capabilities and updates project dependencies.

Source
CRI-Ov1.36.5Kubernetes CoreSep 2, 2026

A maintenance release fixes concurrent image-volume mounting and a high-performance hook CPU-set bug. It contains no new operator-facing configuration or compatibility changes.

Source
CRI-Ov1.35.8Kubernetes CoreSep 2, 2026

A release with no stated runtime or operator-behavior changes. It includes guidance for verifying artifact signatures and SBOMs.

Source
Kubescapev4.0.13SecuritySep 2, 2026

A broad feature release expands scanning, policy, reporting, remediation, notifications, telemetry, integrations, and output capabilities. It also includes security hardening and stricter scan constraints, alongside many correctness and runtime fixes.

Action needed (2)

  • securityGo dependency security vulnerabilities

    Dependabot fixes security vulnerabilities in Go dependencies shipped with the release.

  • securitygosec SAST findings

    The release remediates gosec SAST findings in the Go codebase.

Check if affected (10)

  • securityGrafeas filtering through resourceURL

    Applies if you run imagescan.

  • breakingClient-supplied account and accessKey in scan requests

    Applies if you use scan requests.

  • breakingHard validation for --include-controls

    Applies if you configure --include-controls.

  • + 7 more on the release page

Plan ahead (1)

  • deprecatedThe --fail-threshold flag, hidden and deprecated

    Applies if you configure --fail-threshold.

Source
← Newer
Browse by month