RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Argov3.2.9CI/CD & App DeliveryApr 16, 2026

Argo v3.2.9 is a maintenance release with defect corrections and dependency updates. It also documents a known limitation, so teams should review the release notes if they rely on the affected behavior.

Source
Backstagev1.50.1CI/CD & App DeliveryApr 15, 2026

A release with a breaking configuration-schema replacement, a repo startup correctness fix, and a React Aria dependency update. It changes configuration values used by existing extensions and blueprints and updates React Aria to v1.17.0 with monopackage imports.

Check if affected (1)

  • breakingConfiguration schema values replaced

    Applies if you use existing extensions and blueprints.

Source
Kubernetesv1.33.11Kubernetes CoreApr 15, 2026

A maintenance release updates the Go build toolchain and dependency versions, with fixes for upgrade and runtime defects. The changes include a Kubernetes build with Go 1.25.9 and fixes for apiserver startup during upgrades and kube-proxy nftables support.

Source
Kubernetesv1.34.7Kubernetes CoreApr 15, 2026

A maintenance release that updates the Go toolchain and dependency versions in the dependency manifest. It also fixes two correctness regressions, with no security advisories or operator actions identified.

Source
Kubernetesv1.35.4Kubernetes CoreApr 15, 2026

A maintenance release with the Go 1.25.9 toolchain and several correctness fixes. It changes the default for StatefulSet parallel pod management and includes fixes for kubelet restarts, apiserver audit-log latency annotations, and kube-proxy nftables support.

Check if affected (1)

  • breakingDefault for MaxUnavailableStatefulSet

    Applies if you do not enable MaxUnavailableStatefulSet.

Source
Ciliumv1.19.3Networking & MessagingApr 15, 2026

Cilium v1.19.3 combines operator-relevant bug fixes with configuration and CLI additions, along with dependency and image updates. The release is relevant to deployments using the affected functionality and to users tracking dependency changes.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 module update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in the v1.19.3 release. The update is marked as security-related.

Source
Ciliumv1.18.9Networking & MessagingApr 15, 2026

Cilium v1.18.9 contains correctness fixes and dependency updates. It also includes security-related changes, including an injection-prevention fix and a security-tagged module update.

Action needed (2)

  • securityRegex dollar-sign escaping for injection prevention

    Regex handling now escapes the $ character to prevent injection. The fix ships in Cilium v1.18.9.

  • securityThe github.com/go-jose/go-jose/v4 dependency update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in Cilium v1.18.9. The release note marks this dependency update as security-related.

Source
Ciliumv1.17.15Networking & MessagingApr 15, 2026

Cilium v1.17.15 is a maintenance release with bug fixes, dependency and image updates, EKS API server hardening, and BPF behavior changes. No security advisory or explicit vulnerability is disclosed.

Source
OpenFeaturecore/v0.15.4CI/CD & App DeliveryApr 15, 2026

This release contains no operator-facing change details. No specific flags, fields, resources, or other release behavior are described.

Source
OpenFeatureflagd/v0.15.4CI/CD & App DeliveryApr 15, 2026

This release note contains only section headings and no operator-facing change details. No specific changes are described for flagd/v0.15.4.

Source
Linkerdedge-26.4.3Networking & MessagingApr 15, 2026

Linkerd edge-26.4.3 adds a proxy environment override annotation and updates the bundled proxy and several dependencies. No disclosed security advisories are listed for this release.

Source
Keycloak26.6.1SecurityApr 15, 2026

Keycloak 26.6.1 is a maintenance release with two described security fixes in the core. It also contains dependency updates, an enhancement, and bug fixes.

Action needed (2)

  • securitymediumCVE-2026-4366, blind server-side request forgery via HTTP redirect handling

    Keycloak 26.6.1 fixes blind server-side request forgery through HTTP redirect handling in core.

  • securitylowCVE-2026-4633, user enumeration via identity-first login

    Keycloak 26.6.1 fixes user enumeration through identity-first login in core.

Source
Daprv1.16.13Orchestration & ManagementApr 15, 2026

Dapr v1.16.13 includes a security-relevant Go dependency update and correctness fixes. The release also changes scheduler reliability and Pulsar pub/sub processing behavior.

Action needed (1)

  • securityThe Go version update

    The Go version is updated from 1.25.8 to 1.25.9 in v1.16.13.

Check if affected (1)

  • breakingprocessMode initialization validation

    Applies if you configure processMode.

Source
Litmus3.28.0ObservabilityApr 15, 2026

A maintenance release with several defect fixes, including prevention of stale configuration leakage and a frontend base-image update to address a Python vulnerability. It also includes fixes for workflow event handling, branding, and experiment image-registry behavior.

Action needed (2)

  • securityStale configuration across probes of the same type

    Stale configuration no longer leaks across multiple probes of the same type.

  • securityFrontend base image updated to ubi9

    The frontend base image is updated to ubi9 to resolve a Python vulnerability.

Source
Rookv1.19.4Storage & DataApr 14, 2026

This release combines an operator defect correction with changes to operator capabilities, configuration, and dependency or image versions. It contains no security advisories or explicitly described security fixes.

Action needed (1)

  • breakingThe default COSI sidecar image version, updated

    The default version of the COSI sidecar image is updated in the COSI component.

Source
OpenFGAv1.14.2SecurityApr 14, 2026

This release contains an operator-facing bug fix in OpenFGA. The recorded note tail refers to delimiter handling in the experimental weighted_graph_check and added validation in v2Check.

Source
OpenFeaturecore/v0.15.3CI/CD & App DeliveryApr 14, 2026

Core v0.15.3 combines new feature work with bug fixes. Its changes include metadata support in kubernetes_sync and support for a single entry in the fractional operator.

Source
OpenFeatureflagd/v0.15.3CI/CD & App DeliveryApr 14, 2026

This release contains no described operator-facing changes. No release note details indicate a change that would affect operator use of flagd.

Source
Backstagev1.50.0CI/CD & App DeliveryApr 14, 2026

A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the .well-known/oauth-protected-resource URL, and includes broad correctness and dependency updates.

Action needed (4)

  • securityhighThe glob and rollup dependencies, upgraded

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions. rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe glob dependency, upgraded to v13

    The glob dependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.

  • securityThe rollup dependency, upgraded to v4.59+

    rollup was upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.

  • securityThe .well-known/oauth-protected-resource URL

    The .well-known/oauth-protected-resource resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.

Check if affected (22)

  • breakingThe auth.omitIdentityTokenOwnershipClaim setting

    Applies if you do not configure auth.omitIdentityTokenOwnershipClaim.

  • breakingThe SignInResolverFactoryOptions type parameters

    Applies if you use SignInResolverFactoryOptions.

  • breakingThe catalog permission exports, removed

    Applies if you use CatalogPermissionRuleInput, CatalogPermissionExtensionPoint, or catalogPermissionExtensionPoint.

  • + 19 more on the release page

Plan ahead (6)

  • deprecatedThe show and showModal compatibility implementation, deprecated

    Applies if you use show or showModal.

  • deprecatedThe auth.omitIdentityTokenOwnershipClaim setting, deprecatedremoval date not announced

    Applies if you configure auth.omitIdentityTokenOwnershipClaim.

  • deprecatedThe config.schema callback format, deprecated

    Applies if you use config.schema.

  • + 3 more on the release page
Source
containerdv2.2.3Kubernetes CoreApr 14, 2026

containerd v2.2.3 includes a disclosed security-related update to spdystream, alongside correctness, runtime, extraction, and dependency/toolchain changes. The recorded advisory is CVE-2026-35469.

Action needed (1)

  • securityhighspdystream dependency update for CVE-2026-35469

    The spdystream dependency is updated in containerd v2.2.3 in connection with CVE-2026-35469.

Source
containerdv2.0.8Kubernetes CoreApr 14, 2026

containerd v2.0.8 is a maintenance release with security fixes, a CNI restart correction, and dependency and toolchain updates. The security changes concern spdystream and credential handling in CRI pod events.

Action needed (1)

  • securityhighThe spdystream update for CVE-2026-35469

    The spdystream security update for CVE-2026-35469 ships in containerd v2.0.8.

Check if affected (1)

  • securityCredential sanitization before gRPC returns

    Applies if you use pod events through the Container Runtime Interface (CRI).

Source
containerdv2.1.7Kubernetes CoreApr 14, 2026

A maintenance release with fixes across CRI, runtime, image distribution, and security-sensitive paths. It also updates dependencies and toolchains, including a spdystream security update and a fix for credential leakage.

Action needed (2)

  • securityhighCVE-2026-35469 and GHSA-pc3f-x583-g7j2

    The release includes CVE-2026-35469 and GHSA-pc3f-x583-g7j2, related to the spdystream security fix.

  • securityhighgithub.com/moby/spdystream v0.5.1 update

    The release updates github.com/moby/spdystream to v0.5.1. The update carries fixes associated with CVE-2026-35469 and GHSA-pc3f-x583-g7j2.

Check if affected (1)

  • securityCredential sanitization before gRPC returns

    Applies if pod events are used.

Source
containerdv1.7.31Kubernetes CoreApr 14, 2026

containerd v1.7.31 is a maintenance release with a disclosed security fix in spdystream, alongside dependency, toolchain, correctness, and behavior updates. The spdystream fix requires upgrading; the other changes matter when affected behaviors or versions are in use.

Action needed (1)

Check if affected (1)

  • securitySanitized gRPC errors in pod events

    Applies if you use pod events.

Source
NATSv2.12.7Networking & MessagingApr 14, 2026

A maintenance release with a dependency and toolchain update, configuration constraint changes, performance improvements, and correctness fixes. It also fixes an ACL permission bypass along with issues affecting leaf connections, streams, storage, and client authentication.

Check if affected (3)

  • securityQueue subscription enforcement of ACL deny patterns

    Applies if you use queue subscriptions and configure non-queue ACL deny patterns.

  • breakingThe no_auth_user configuration field, restricted to client connections

    Applies if you configure no_auth_user.

  • breakingDuplicate INFO permission updates for solicited leaf connections

    Applies if you use solicited leaf connections.

Source
NATSv2.11.16Networking & MessagingApr 14, 2026

This release updates the Go toolchain and corrects authorization, leafnode, and WebSocket behavior. Configuration rules for no_auth_user and duplicate leaf permission updates are narrower, so affected existing setups may require review.

Check if affected (2)

  • breakingThe no_auth_user connection scope restriction

    Applies if you configure no_auth_user.

  • breakingThe INFO permission update restriction

    Applies if you use solicited leaf connections.

Source
TiKVv8.5.6Storage & DataApr 14, 2026

TiKV v8.5.6 adds auto-compaction configuration and changes compaction and cleanup behavior. It also corrects several issues affecting reads, transactions, memory use, indexes, and cluster operations. No security-specific fixes or advisories are identified.

Source
wasmCloudv2.0.3Orchestration & ManagementApr 14, 2026

This release adds Kubernetes-native service routing and related CRD fields, changes Helm behavior, fixes a NATS subscriber initialization race, and retires the runtime-gateway path. Operators using the deprecated gateway configuration need to account for the routing change and removed chart behavior.

Action needed (1)

  • breakingThe default chart tag is removed

    The default tag is removed, so the chart uses chart.yaml's appVersion.

Check if affected (1)

  • breakingNative Kubernetes Service routing replaces runtime-gateway

    Applies if you use runtime-gateway.

Plan ahead (1)

  • deprecatedThe Helm gateway section is deprecated

    Applies if you configure gateway.

Source
OpenCostv1.120.0ObservabilityApr 13, 2026

A maintenance release with dependency updates, defect corrections, expanded compatibility, and new integrations and configuration capabilities. An existing configuration source is replaced, so affected operators need to update their configuration.

Action needed (1)

  • breakingProvider configuration replaced by cloud-integration.json

    The provider config is no longer used, and configuration is read from cloud-integration.json instead. Operators using the replaced configuration source need to update their configuration.

Source
Istio1.29.2Networking & MessagingApr 13, 2026

A maintenance release adds Helm v4 server-side apply support and includes numerous correctness fixes. The WASM decompression size-limit change affects inputs that were previously accepted and may require operator review.

Action needed (1)

  • breakingThe gzip decompression size limit for WASM binaries

    A size limit is now enforced on gzip-decompressed WASM binaries fetched over HTTP.

Source
Istio1.28.6Networking & MessagingApr 13, 2026

Istio 1.28.6 is a maintenance release with operator-facing additions and defect corrections. It includes updates related to Helm integration, authentication controls, Gateway API handling, ambient networking, and runtime behavior.

Source
Prometheusv3.11.2ObservabilityApr 13, 2026

Release v3.11.2 fixes stored XSS in the Prometheus web UI and changes Consul service-discovery filtering. The Consul updates add health_filter support and correct how filter parameters are applied to the Health API.

Check if affected (1)

  • securitymediumStored XSS fix in the Prometheus web UI, CVE-2026-40179

    Applies if you use the Prometheus web UI.

Source
Prometheusv3.5.2ObservabilityApr 13, 2026

Prometheus v3.5.2 fixes a stored XSS vulnerability in the Prometheus web UI. The release also includes a regex performance improvement.

Check if affected (1)

  • securitymediumStored XSS fix in the Prometheus web UI

    Applies if crafted metric names or label values can reach the Prometheus web UI.

Source
cert-managerv1.20.2SecurityApr 11, 2026

cert-manager v1.20.2 fixes invalid Helm YAML generation and updates Go to 1.26.2. It also includes a security-related update to Go dependencies with reported vulnerabilities.

Action needed (1)

  • securityGo dependency updates

    Go dependencies with reported vulnerabilities were updated in cert-manager v1.20.2. No advisory identifier is provided for this update.

Source
Envoyv1.37.2Networking & MessagingApr 10, 2026

Envoy v1.37.2 is a maintenance release focused on operator-relevant correctness fixes. The notes identify no security advisories or operator action beyond upgrading.

Source
Envoyv1.36.6Networking & MessagingApr 10, 2026

Envoy v1.36.6 is a maintenance release with fixes for dynamic module buffering, internal redirect request handling, and Docker release images. The recorded issues concern incomplete request or response bodies, request hangs after buffer overflow, and release image updates.

Source
OpenFGAv1.14.1SecurityApr 10, 2026

A maintenance release adds server shutdown-timeout configuration and performance improvements in object listing and cache key generation. It also corrects an AuthZEN discovery security issue and replaces a vulnerable test dependency.

Check if affected (2)

  • securityAuthZEN discovery metadata endpoint URLs

    Applies if authzen.baseURL is configured.

  • securityThe github.com/docker/docker test dependency, replaced with Moby

    Applies if tests run.

Source
Daprv1.17.4Orchestration & ManagementApr 10, 2026

This release contains operator-relevant correctness fixes across messaging, workflows, HTTP proxying, placement, and scheduling. It also updates the Go toolchain across the repository and its Docker images.

Action needed (1)

  • securityThe Go toolchain, updated to 1.25.9

    The Go toolchain was upgraded from 1.25.8 to 1.25.9 across all modules and Docker images in the repository.

Source
Envoyv1.35.10Networking & MessagingApr 10, 2026

Envoy v1.35.10 is a maintenance release with an operator-facing defect correction. The recorded release note points to an update or fix for Docker release images.

Source
Envoyv1.34.14Networking & MessagingApr 10, 2026

This release contains an operator-facing correction to the Docker release images. No individual change details are available beyond that release-note heading.

Source
← NewerOlder →
Browse by month