RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Kyvernov1.16.4SecurityApr 23, 2026

A security-fix release with fixes for multiple CVEs and updates to affected dependencies. It also changes the default HTTP behavior and restricts configmap access for namespaced policies.

Action needed (12)

  • securitycriticalCVE-2025-68121 fix

    This release fixes CVE-2025-68121.

  • securitycriticalCVE-2026-33186 fix

    This release fixes CVE-2026-33186.

  • securityhighCVE-2026-24051 fix

    This release fixes CVE-2026-24051 in the 1.16 release line.

  • securityhighThe github.com/docker/cli dependency update

    The github.com/docker/cli dependency is updated to resolve CVE-2025-15558.

  • securityhighCVE-2025-66564 fix

    This release resolves CVE-2025-66564.

  • securitymediumThe sigstore/rekor dependency update to v1.5.1

    The sigstore/rekor dependency is updated to v1.5.1 to fix CVE-2026-23831.

  • securitymediumThe go-tuf/v2 dependency update to v2.3.1

    The go-tuf/v2 dependency is updated to v2.3.1 to address CVE-2026-23992.

  • securitymediumCVE-2026-22772 fix

    This release fixes CVE-2026-22772.

  • securitymediumThe go-tuf/v2 dependency update to v2.4.1

    The go-tuf/v2 dependency is updated to v2.4.1 to patch CVE-2026-24686.

  • securitylowCVE-2026-1229 fix

    This release fixes CVE-2026-1229 in the 1.16 release line.

  • securitylowCVE-2026-26958 fix

    This release fixes CVE-2026-26958.

  • securityStandard library CVE fixes

    This release fixes standard library CVEs.

Check if affected (3)

  • securitycriticalHTTP disabled by default in namespaced policies

    Applies if you configure namespaced policies.

  • securityCVE fixes for go < 1.25.8

    Applies if you depend on go < 1.25.8.

  • breakingRestricted configmap access for namespaced policies

    Applies if you configure namespaced policies.

Source
Kyvernov1.17.2SecurityApr 23, 2026

A maintenance release with multiple correctness fixes and security fixes, including changes for several CVEs and standard library CVEs. Operators should account for the changed HTTP default and narrower configmap access in addition to the security fixes.

Action needed (6)

  • securitycriticalCVE-2026-33186 correction

    The release fixes CVE-2026-33186.

  • securityhighCVE-2026-24051 correction

    The release fixes CVE-2026-24051 in the 1.17 release line.

  • securityhighCVE-2026-34986 correction

    The release fixes CVE-2026-34986.

  • securitylowCVE-2026-1229 correction

    The release fixes CVE-2026-1229.

  • securityCVES 2026-15558 correction

    The release includes the CVES 2026-15558 fix for 1.17.

  • securityGo version update

    The Go version was bumped to fix standard library CVEs.

Check if affected (2)

  • securitycriticalHTTP default for namespaced policies

    Applies if you configure namespaced policies.

  • breakingConfigmap access for namespaced policies

    Applies if you configure namespaced policies.

Source
Buildpacksv0.40.3CI/CD & App DeliveryApr 22, 2026

This release contains a change to the lifecycle version used by builders created with the pack CLI. The recorded change is not included in the item list because no change entry was provided.

Source
Kubernetesv1.36.0Kubernetes CoreApr 22, 2026

A broad operator-significant release with API, configuration, CLI default, scheduling, runtime, feature-gate, metric, and dependency changes. Upgrade review and testing matter for users of removed or deprecated interfaces, changed defaults, custom scheduler integrations, CRDs, audit logging, and affected metrics.

Action needed (11)

  • breakingStrictIPCIDRValidation enabled by default

    The StrictIPCIDRValidation feature gate in kube-apiserver is enabled by default.

  • breakingThe default debug profile, changed to general

    The default debug profile changes from legacy to general.

  • breakingWatchCacheInitializationPostStartHook enabled by default

    The WatchCacheInitializationPostStartHook feature gate is enabled by default.

  • breakingKubeletPSI graduation to GA

    The KubeletPSI feature graduated to GA and is enabled by default.

  • breakingRelaxedServiceNameValidation at beta, enabled by default

    The RelaxedServiceNameValidation feature gate graduated to beta and is enabled by default.

  • breakingRestartAllContainersOnContainerExits at beta, enabled by default

    The RestartAllContainersOnContainerExits feature gate graduated to beta and is enabled by default.

  • breakingSuspended-job feature gates enabled by default

    The MutablePodResourcesForSuspendedJobs and MutableSchedulingDirectivesForSuspendedJobs feature gates are enabled by default.

  • breakingAtomicFIFO informer store updates

    Default informer behavior now updates store state with all objects in a list or relist before invoking individual-item handler methods. This behavior is associated with AtomicFIFO.

  • breakingUnlockWhileProcessing informer behavior

    Informers can now enqueue new watch events while already-queued events are being processed. This behavior is associated with UnlockWhileProcessing.

  • breakingClientsAllowCARotation functionality enabled by default

    This functionality is enabled by default and can be disabled through the ClientsAllowCARotation feature gate.

  • breakingClientsAllowTLSCacheGC functionality enabled by default

    This functionality is enabled by default and can be controlled through the ClientsAllowTLSCacheGC feature gate.

Check if affected (25)

  • breakingThe volume_operation_total_errors metric, renamed

    Applies if you use volume_operation_total_errors.

  • breakingThe git-repo volume plugin, disabled

    Applies if you use the git-repo volume plugin.

  • breakingAllowlistEntry.Name, renamed to AllowlistEntry.Command

    Applies if you configure AllowlistEntry.Name.

  • + 22 more on the release page

Plan ahead (6)

  • deprecatedService .spec.externalIPs deprecation

    Applies if you configure Service .spec.externalIPs.

  • deprecatedDirect access to metav1.FieldsV1.Raw, deprecated

    Applies if you use metav1.FieldsV1.Raw.

  • deprecatedMinNodeScore and MaxNodeScore, deprecated

    Applies if you use MinNodeScore or MaxNodeScore.

  • + 3 more on the release page
Source
Backstagev1.50.3CI/CD & App DeliveryApr 22, 2026

This is a maintenance release for Backstage with ordinary correctness fixes. It addresses home page widget interactions, facets endpoint performance under filters or permissions, and external links under a non-root base path.

Source
metal3-iov0.12.4Provisioning & RuntimeApr 22, 2026

This release fixes an HFC controller error loop, removes unused RBAC permissions, and updates project dependencies. The changes cover controller correctness and routine maintenance, with no stated security advisory.

Action needed (1)

  • breakingUnused permissions in the controller ClusterRole removed

    Unused RBAC permissions are removed from the controller ClusterRole.

Source
metal3-iov0.11.7Provisioning & RuntimeApr 22, 2026

This release removes unused controller permissions and includes fixes and dependency updates. It may concern users tracking HFC controller behavior, CAPI, the Kubernetes group, or the Go build toolchain.

Action needed (1)

  • breakingUnused controller ClusterRole RBAC permissions removed

    Unused RBAC permissions are removed from the controller ClusterRole in this release.

Source
CoreDNSv1.14.3Kubernetes CoreApr 22, 2026

A maintenance release that adds operator-facing options and transport, plugin, and protocol support while correcting defects. It is built with Go 1.26.2, which contains fixes for disclosed CVEs; other changes concern operators using the affected features or behaviors.

Action needed (1)

Check if affected (1)

  • breakingOversized DoH GET query parameter rejection

    Applies if you use DoH.

Source
wasmCloudv2.0.4Orchestration & ManagementApr 21, 2026

wasmCloud v2.0.4 contains operator-facing changes in Helm configuration and TLS handling. The release material also covers WASI support, CLI certificate options, and updates to TLS dependencies.

Source
Argov3.3.8CI/CD & App DeliveryApr 21, 2026

Argo v3.3.8 is a patch release focused on operator-relevant bug fixes, including a changed default for the ApplicationSet resource status count. No security advisories or security-specific fixes are disclosed.

Source
Argov3.2.10CI/CD & App DeliveryApr 21, 2026

Argo CD v3.2.10 contains operator-relevant bug fixes. The remaining release-note content does not describe a distinct operator-facing change.

Source
Argov3.1.15CI/CD & App DeliveryApr 21, 2026

Argo v3.1.15 is a focused bug-fix release for operator behavior. The listed fixes affect refresh behavior and application-controller synchronization, while the other release material covers installation, documentation, headings, or release metadata.

Source
cert-managerv1.19.5SecurityApr 21, 2026

This release contains security-related updates to Go dependencies and the Go toolchain. It concerns deployments that rely on the affected dependencies or the bundled Go toolchain.

Action needed (2)

  • securityGo dependencies with reported vulnerabilities updated

    Go dependencies with reported vulnerabilities are updated in cert-manager v1.19.5.

  • securityThe go toolchain updated to 1.25.8

    The go toolchain is updated to 1.25.8 in cert-manager v1.19.5 to address reported vulnerabilities.

Source
Fluxv2.8.6CI/CD & App DeliveryApr 21, 2026

This is an operator-focused maintenance release with fixes and configuration constraints across controllers. It also adds a feature gate and updates dependency and toolkit components.

Check if affected (1)

  • breakingRequired audience field on the GCR Receiver secret

    Applies if you configure the audience field on the GCR Receiver secret.

Source
KubeVirtv1.8.2Orchestration & ManagementApr 20, 2026

A correctness-focused release also changes backend volume naming and removes permissions from the kubevirt.io:edit RBAC role. The RBAC change requires operator attention.

Action needed (1)

  • breakingThe kubevirt.io:edit RBAC role, with vnc and screenshot permissions removed

    The vnc and screenshot permissions are removed from the kubevirt.io:edit RBAC role in this release.

Source
Contourv1.33.4Networking & MessagingApr 20, 2026

A release with a fix for Lua code injection, a required Envoy version change, and an Envoy dependency update. It is tested against Kubernetes 1.32 through 1.34.

Check if affected (2)

  • securityhighCVE-2026-41246 fix for cookieRewritePolicies[].pathRewrite.value

    Applies if you use HTTPProxy resources.

  • breakingEnvoy 1.35.0 minimum version

    Applies if you depend on Envoy.

Source
Contourv1.32.5Networking & MessagingApr 20, 2026

Contour v1.32.5 fixes a Lua code injection vulnerability and upgrades Envoy to v1.34.14. The release also includes an informational Kubernetes compatibility update.

Action needed (1)

  • securityhighCVE-2026-41246 Lua code injection vulnerability fixed

    This release fixes CVE-2026-41246 and GHSA-x4mj-7f9g-29h4, a Lua code injection vulnerability affecting cookieRewritePolicies[].pathRewrite.value.

Source
Contourv1.31.6Networking & MessagingApr 20, 2026

This release fixes a Lua code injection vulnerability in Contour's Cookie Rewriting feature and updates Envoy to v1.34.14. It is tested against Kubernetes 1.30 through 1.32.

Check if affected (1)

  • securityhighLua code injection fix for CVE-2026-41246

    Applies if you configure cookieRewritePolicies[].pathRewrite.value.

Source
Crossplanev2.2.1Orchestration & ManagementApr 20, 2026

Crossplane v2.2.1 includes security-focused dependency updates and a move to Go 1.25.9. It also corrects operator-facing behavior around dependency upgrades with ImageConfig prefix rewrites and resource selectors, and bumps Crossplane Runtime to v2.2.1.

Action needed (10)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    Crossplane v2.2.1 updates the github.com/cloudflare/circl module to v1.6.3 as a security dependency change.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    Crossplane v2.2.1 updates the go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module to v1.43.0 as a security dependency change.

  • securityThe github.com/go-jose/go-jose/v4 module, updated to v4.1.4

    Crossplane v2.2.1 updates the github.com/go-jose/go-jose/v4 module to v4.1.4 as a security dependency change.

  • securityThe github.com/sigstore/cosign/v3 module, updated to v3.0.5

    Crossplane v2.2.1 updates the github.com/sigstore/cosign/v3 module to v3.0.5 as a security dependency change.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    Crossplane v2.2.1 updates the github.com/go-git/go-git/v5 module to v5.17.1 as a security dependency change.

  • securityThe github.com/docker/cli module, updated to v29.2.0+incompatible

    Crossplane v2.2.1 updates the github.com/docker/cli module to v29.2.0+incompatible as a security dependency change.

  • securityGo 1.25.9

    Crossplane v2.2.1 updates Go to 1.25.9 as a security dependency change.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    Crossplane v2.2.1 updates the github.com/moby/spdystream module to v0.5.1 as a security dependency change.

  • securityThe github.com/sigstore/timestamp-authority/v2 module, updated to v2.0.6

    Crossplane v2.2.1 updates the github.com/sigstore/timestamp-authority/v2 module to v2.0.6 as a security dependency change.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    Crossplane v2.2.1 updates the github.com/go-git/go-git/v5 module to v5.18.0 as a security dependency change.

Source
Crossplanev2.1.5Orchestration & ManagementApr 20, 2026

Crossplane v2.1.5 combines correctness fixes with dependency and Go toolchain updates. The release includes updated versions of several modules used by Crossplane.

Action needed (10)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    Crossplane v2.1.5 updates the github.com/cloudflare/circl module to v1.6.3.

  • securityThe google.golang.org/grpc module, updated to v1.79.3

    Crossplane v2.1.5 updates the google.golang.org/grpc module to v1.79.3.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    Crossplane v2.1.5 updates the go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module to v1.43.0.

  • securityThe github.com/go-jose/go-jose/v4 module, updated to v4.1.4

    Crossplane v2.1.5 updates the github.com/go-jose/go-jose/v4 module to v4.1.4.

  • securityThe Go toolchain, updated to 1.25.9

    Crossplane v2.1.5 updates the Go toolchain to 1.25.9.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    Crossplane v2.1.5 updates the github.com/go-git/go-git/v5 module to v5.17.1.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    Crossplane v2.1.5 updates the github.com/moby/spdystream module to v0.5.1.

  • securityThe github.com/sigstore/timestamp-authority/v2 module, updated to v2.0.6

    Crossplane v2.1.5 updates the github.com/sigstore/timestamp-authority/v2 module to v2.0.6.

  • securityThe github.com/docker/cli module, updated to v29.2.0+incompatible

    Crossplane v2.1.5 updates the github.com/docker/cli module to v29.2.0+incompatible.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    Crossplane v2.1.5 updates the github.com/go-git/go-git/v5 module to v5.18.0.

Source
Crossplanev2.0.8Orchestration & ManagementApr 20, 2026

Crossplane v2.0.8 corrects two operator-visible defects and updates Go plus several dependencies. The dependency changes are marked for security, but the disclosures identify only the affected components rather than specific advisory IDs.

Action needed (9)

  • securityThe github.com/cloudflare/circl module update

    The github.com/cloudflare/circl module is updated to v1.6.3 in Crossplane v2.0.8.

  • securityThe OTLP HTTP trace exporter module update

    The go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module is updated to v1.43.0 in Crossplane v2.0.8.

  • securityThe github.com/go-jose/go-jose/v4 module update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in Crossplane v2.0.8.

  • securityThe Go version update to 1.25.9

    Go is updated to 1.25.9 in Crossplane v2.0.8.

  • securityThe github.com/go-git/go-git/v5 module update to v5.17.1

    The github.com/go-git/go-git/v5 module is updated to v5.17.1 in Crossplane v2.0.8.

  • securityThe github.com/moby/spdystream module update

    The github.com/moby/spdystream module is updated to v0.5.1 in Crossplane v2.0.8.

  • securityThe github.com/docker/cli module update

    The github.com/docker/cli module is updated to v29.2.0+incompatible in Crossplane v2.0.8.

  • securityThe github.com/sigstore/timestamp-authority/v2 module update

    The github.com/sigstore/timestamp-authority/v2 module is updated to v2.0.6 in Crossplane v2.0.8.

  • securityThe github.com/go-git/go-git/v5 module update to v5.18.0

    The github.com/go-git/go-git/v5 module is updated to v5.18.0 in Crossplane v2.0.8.

Source
Crossplanev1.20.6Orchestration & ManagementApr 20, 2026

Crossplane v1.20.6 is a dependency-focused release with updates to several Go modules, including security-marked changes. It also includes an update to crossplane-runtime v1.20.6.

Action needed (5)

  • securityThe github.com/cloudflare/circl module, updated to v1.6.3

    The github.com/cloudflare/circl module is updated to v1.6.3 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module, updated to v1.43.0

    The go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp module is updated to v1.43.0 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.17.1

    The github.com/go-git/go-git/v5 module is updated to v5.17.1 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/moby/spdystream module, updated to v0.5.1

    The github.com/moby/spdystream module is updated to v0.5.1 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

  • securityThe github.com/go-git/go-git/v5 module, updated to v5.18.0

    The github.com/go-git/go-git/v5 module is updated to v5.18.0 in Crossplane v1.20.6. The release note marks this dependency update as security-related.

Source
Backstagev1.50.2CI/CD & App DeliveryApr 18, 2026

This release combines a new TechDocs sidebar styling capability with dependency updates and constraints. It also corrects an active tab indicator issue in Backstage UI.

Action needed (1)

  • breakingReact Aria dependency ranges constrained to patch-only updates

    React Aria dependency ranges are limited to patch-only updates in Backstage v1.50.2.

Source
Kubescapev4.0.5SecurityApr 17, 2026

This release contains an operator-facing dependency and toolchain update. The available release information does not specify the affected Go version or dependencies.

Source
Backstagev1.49.5CI/CD & App DeliveryApr 17, 2026

This release narrows the allowed React Aria dependency range to prevent unintended breaking updates. The version heading itself carries no operator-facing change.

Source
Kubescapev4.0.4SecurityApr 17, 2026

Kubescape v4.0.4 contains dependency updates, ordinary correctness improvements, and a logging dependency update. No security advisory or explicitly security-related flaw is disclosed.

Source
Backstagev1.47.4CI/CD & App DeliveryApr 17, 2026

This release changes the dependency range for React Aria dependencies to prevent unintended breaking changes from minor-version updates. The release version is not stated as increasing.

Source
Backstagev1.46.7CI/CD & App DeliveryApr 17, 2026

This release has no operator-facing change. Its dependency constraints narrow the React Aria version range to avoid breaking updates from minor releases.

Source
Backstagev1.45.6CI/CD & App DeliveryApr 17, 2026

This release updates the React Aria dependency version constraint to prevent breaking changes from entering through minor updates. It carries no operator-facing change.

Source
Daprv1.15.14Orchestration & ManagementApr 16, 2026

This is a security-focused maintenance release. It corrects a service-invocation ACL mismatch caused by path normalization and updates Go to v1.25.9 for CVE coverage.

Action needed (2)

  • securityNormalized service-invocation ACL and outbound dispatch paths

    The normalized path form is used for both the ACL check and outbound dispatch, removing the mismatch in service invocation.

  • securityThe Go dependency, updated to v1.25.9

    The Go dependency is updated to v1.25.9 to address CVEs affecting the 1.24 line.

Source
Argov3.3.7CI/CD & App DeliveryApr 16, 2026

Argo v3.3.7 is a maintenance release with ordinary bug fixes, performance improvements, and dependency updates. It also documents a known application-reconciliation issue that remains unresolved. No security vulnerability or operator action beyond upgrading is identified.

Source
Daprv1.17.5Orchestration & ManagementApr 16, 2026

This release contains a security fix for service-invocation access-control policy handling. It aligns method-path normalization for ACL checks and outbound dispatch, which concerns operators using these policies.

Action needed (1)

  • securityService-invocation ACL path normalization

    In Dapr v1.17.5, the normalized method path is used for both the service-invocation ACL check and outbound dispatch, eliminating the mismatch that caused the bypass.

Source
Daprv1.16.14Orchestration & ManagementApr 16, 2026

A security-focused release fixes a service-invocation ACL bypass caused by inconsistent path normalization. It also rejects dangerous method-path characters, removes the purell dependency from ACL path handling, and applies additional path cleaning in constructRequest.

Action needed (3)

  • securityConsistent service-invocation method path normalization

    Method paths are normalized at the service invocation edge for HTTP and gRPC public API calls, gRPC internal calls, and proxied calls. The normalized form is used for both the ACL check and outbound dispatch.

  • securityStricter method path validation

    Normalization uses path.Clean to resolve ../ segments and duplicate slashes. Method paths containing #, ?, null bytes, or control characters are rejected.

  • securityThe purell dependency, removed from the ACL path

    The purell dependency has been removed from ACL path handling.

Source
Argov3.1.14CI/CD & App DeliveryApr 16, 2026

Argo v3.1.14 includes an application refresh defect correction and a fast-xml-parser dependency update in the UI. No security advisories or mandatory operator actions are disclosed.

Source
← NewerOlder →
Browse by month