Argo v3.2.9 is a maintenance release with defect corrections and dependency updates. It also documents a known limitation, so teams should review the release notes if they rely on the affected behavior.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A release with a breaking configuration-schema replacement, a repo startup correctness fix, and a React Aria dependency update. It changes configuration values used by existing extensions and blueprints and updates React Aria to v1.17.0 with monopackage imports.
Check if affected (1)
breakingConfiguration schema values replaced
Applies if you use existing extensions and blueprints.
A maintenance release updates the Go build toolchain and dependency versions, with fixes for upgrade and runtime defects. The changes include a Kubernetes build with Go 1.25.9 and fixes for apiserver startup during upgrades and kube-proxy nftables support.
Source ↗A maintenance release that updates the Go toolchain and dependency versions in the dependency manifest. It also fixes two correctness regressions, with no security advisories or operator actions identified.
Source ↗A maintenance release with the Go 1.25.9 toolchain and several correctness fixes. It changes the default for StatefulSet parallel pod management and includes fixes for kubelet restarts, apiserver audit-log latency annotations, and kube-proxy nftables support.
Check if affected (1)
breakingDefault for
MaxUnavailableStatefulSetApplies if you do not enable
MaxUnavailableStatefulSet.
Cilium v1.19.3 combines operator-relevant bug fixes with configuration and CLI additions, along with dependency and image updates. The release is relevant to deployments using the affected functionality and to users tracking dependency changes.
Action needed (1)
securityThe
github.module updatecom/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 in the v1.19.3 release. The update is marked as security-related.com/go-jose/go-jose/v4
Cilium v1.18.9 contains correctness fixes and dependency updates. It also includes security-related changes, including an injection-prevention fix and a security-tagged module update.
Action needed (2)
securityRegex dollar-sign escaping for injection prevention
Regex handling now escapes the
$character to prevent injection. The fix ships in Cilium v1.18.9.securityThe
github.dependency updatecom/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 in Cilium v1.18.9. The release note marks this dependency update as security-related.com/go-jose/go-jose/v4
Cilium v1.17.15 is a maintenance release with bug fixes, dependency and image updates, EKS API server hardening, and BPF behavior changes. No security advisory or explicit vulnerability is disclosed.
Source ↗This release contains no operator-facing change details. No specific flags, fields, resources, or other release behavior are described.
Source ↗This release note contains only section headings and no operator-facing change details. No specific changes are described for flagd/v0.15.4.
Source ↗Linkerd edge-26.4.3 adds a proxy environment override annotation and updates the bundled proxy and several dependencies. No disclosed security advisories are listed for this release.
Source ↗Keycloak 26.6.1 is a maintenance release with two described security fixes in the core. It also contains dependency updates, an enhancement, and bug fixes.
Action needed (2)
securitymediumCVE-2026-4366, blind server-side request forgery via HTTP redirect handling
Keycloak 26.6.1 fixes blind server-side request forgery through HTTP redirect handling in
core.securitylowCVE-2026-4633, user enumeration via identity-first login
Keycloak 26.6.1 fixes user enumeration through identity-first login in
core.
Dapr v1.16.13 includes a security-relevant Go dependency update and correctness fixes. The release also changes scheduler reliability and Pulsar pub/sub processing behavior.
Action needed (1)
securityThe
Goversion updateThe
Goversion is updated from1.to25. 8 1.in v1.16.13.25. 9
Check if affected (1)
breaking
processModeinitialization validationApplies if you configure
processMode.
A maintenance release with several defect fixes, including prevention of stale configuration leakage and a frontend base-image update to address a Python vulnerability. It also includes fixes for workflow event handling, branding, and experiment image-registry behavior.
Action needed (2)
securityStale configuration across probes of the same type
Stale configuration no longer leaks across multiple probes of the same type.
securityFrontend base image updated to
ubi9The frontend base image is updated to
ubi9to resolve a Python vulnerability.
This release combines an operator defect correction with changes to operator capabilities, configuration, and dependency or image versions. It contains no security advisories or explicitly described security fixes.
Action needed (1)
breakingThe default
COSIsidecar image version, updatedThe default version of the
COSIsidecar image is updated in the COSI component.
This release contains an operator-facing bug fix in OpenFGA. The recorded note tail refers to delimiter handling in the experimental weighted_graph_check and added validation in v2Check.
Core v0.15.3 combines new feature work with bug fixes. Its changes include metadata support in kubernetes_sync and support for a single entry in the fractional operator.
This release contains no described operator-facing changes. No release note details indicate a change that would affect operator use of flagd.
Source ↗A substantial feature and maintenance release with API, UI, plugin, authentication-token, catalog, scaffolder, frontend, and SCM changes. It also updates vulnerable glob and rollup dependencies, fixes the . URL, and includes broad correctness and dependency updates.
Action needed (4)
securityhighThe
globandrollupdependencies, upgradedThe
globdependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.rollupwas upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.securityThe
globdependency, upgraded to v13The
globdependency was upgraded from v7, v8, and v11 to v13 to address security vulnerabilities in older versions.securityThe
rollupdependency, upgraded to v4.59+rollupwas upgraded from v4.27 to v4.59+ to fix the path traversal vulnerability identified by GHSA-mw96-cpmx-2vgc.securityThe
.URLwell-known/oauth-protected-resource The
.resource URL was fixed to comply with RFC 9728 Section 7.3. Dynamic resource paths are enabled.well-known/oauth-protected-resource
Check if affected (22)
breakingThe
auth.settingomitIdentityTokenOwnershipClaim Applies if you do not configure
auth..omitIdentityTokenOwnershipClaim breakingThe
SignInResolverFactoryOptionstype parametersApplies if you use
SignInResolverFactoryOptions.breakingThe catalog permission exports, removed
Applies if you use
CatalogPermissionRuleInput,CatalogPermissionExtensionPoint, orcatalogPermissionExtensionPoint.- + 19 more on the release page
Plan ahead (6)
deprecatedThe
showandshowModalcompatibility implementation, deprecatedApplies if you use
showorshowModal.deprecatedThe
auth.setting, deprecatedremoval date not announcedomitIdentityTokenOwnershipClaim Applies if you configure
auth..omitIdentityTokenOwnershipClaim deprecatedThe
config.callback format, deprecatedschema Applies if you use
config..schema - + 3 more on the release page
containerd v2.2.3 includes a disclosed security-related update to spdystream, alongside correctness, runtime, extraction, and dependency/toolchain changes. The recorded advisory is CVE-2026-35469.
Action needed (1)
securityhigh
spdystreamdependency update for CVE-2026-35469The
spdystreamdependency is updated in containerd v2.2.3 in connection with CVE-2026-35469.
containerd v2.0.8 is a maintenance release with security fixes, a CNI restart correction, and dependency and toolchain updates. The security changes concern spdystream and credential handling in CRI pod events.
Action needed (1)
securityhighThe
spdystreamupdate for CVE-2026-35469The
spdystreamsecurity update for CVE-2026-35469 ships in containerd v2.0.8.
Check if affected (1)
securityCredential sanitization before
gRPCreturnsApplies if you use pod events through the
Container Runtime Interface (CRI).
A maintenance release with fixes across CRI, runtime, image distribution, and security-sensitive paths. It also updates dependencies and toolchains, including a spdystream security update and a fix for credential leakage.
Action needed (2)
securityhighCVE-2026-35469 and GHSA-pc3f-x583-g7j2
The release includes CVE-2026-35469 and GHSA-pc3f-x583-g7j2, related to the
spdystreamsecurity fix.securityhigh
github.v0.5.1 updatecom/moby/spdystream The release updates
github.to v0.5.1. The update carries fixes associated with CVE-2026-35469 and GHSA-pc3f-x583-g7j2.com/moby/spdystream
Check if affected (1)
securityCredential sanitization before
gRPCreturnsApplies if pod events are used.
containerd v1.7.31 is a maintenance release with a disclosed security fix in spdystream, alongside dependency, toolchain, correctness, and behavior updates. The spdystream fix requires upgrading; the other changes matter when affected behaviors or versions are in use.
Action needed (1)
securityhighThe
spdystreamCVE-2026-35469 fixcontainerd v1.7.31 includes the
spdystreamfix for CVE-2026-35469 and GHSA-pc3f-x583-g7j2.
Check if affected (1)
securitySanitized gRPC errors in pod events
Applies if you use pod events.
A maintenance release with a dependency and toolchain update, configuration constraint changes, performance improvements, and correctness fixes. It also fixes an ACL permission bypass along with issues affecting leaf connections, streams, storage, and client authentication.
Check if affected (3)
securityQueue subscription enforcement of ACL
denypatternsApplies if you use queue subscriptions and configure non-queue ACL
denypatterns.breakingThe
no_auth_userconfiguration field, restricted to client connectionsApplies if you configure
no_auth_user.breakingDuplicate
INFOpermission updates for solicited leaf connectionsApplies if you use solicited leaf connections.
This release updates the Go toolchain and corrects authorization, leafnode, and WebSocket behavior. Configuration rules for no_auth_user and duplicate leaf permission updates are narrower, so affected existing setups may require review.
Check if affected (2)
breakingThe
no_auth_userconnection scope restrictionApplies if you configure
no_auth_user.breakingThe
INFOpermission update restrictionApplies if you use solicited leaf connections.
TiKV v8.5.6 adds auto-compaction configuration and changes compaction and cleanup behavior. It also corrects several issues affecting reads, transactions, memory use, indexes, and cluster operations. No security-specific fixes or advisories are identified.
Source ↗This release adds Kubernetes-native service routing and related CRD fields, changes Helm behavior, fixes a NATS subscriber initialization race, and retires the runtime-gateway path. Operators using the deprecated gateway configuration need to account for the routing change and removed chart behavior.
Action needed (1)
breakingThe default chart tag is removed
The default tag is removed, so the chart uses
chart.'syaml appVersion.
Check if affected (1)
breakingNative Kubernetes Service routing replaces
runtime-gatewayApplies if you use
runtime-gateway.
Plan ahead (1)
deprecatedThe Helm
gatewaysection is deprecatedApplies if you configure
gateway.
A maintenance release with dependency updates, defect corrections, expanded compatibility, and new integrations and configuration capabilities. An existing configuration source is replaced, so affected operators need to update their configuration.
Action needed (1)
breakingProvider configuration replaced by
cloud-integration.json The provider config is no longer used, and configuration is read from
cloud-integration.instead. Operators using the replaced configuration source need to update their configuration.json
A maintenance release adds Helm v4 server-side apply support and includes numerous correctness fixes. The WASM decompression size-limit change affects inputs that were previously accepted and may require operator review.
Action needed (1)
breakingThe gzip decompression size limit for WASM binaries
A size limit is now enforced on gzip-decompressed WASM binaries fetched over HTTP.
Istio 1.28.6 is a maintenance release with operator-facing additions and defect corrections. It includes updates related to Helm integration, authentication controls, Gateway API handling, ambient networking, and runtime behavior.
Source ↗Release v3. fixes stored XSS in the Prometheus web UI and changes Consul service-discovery filtering. The Consul updates add health_filter support and correct how filter parameters are applied to the Health API.
Check if affected (1)
securitymediumStored XSS fix in the Prometheus web UI, CVE-2026-40179
Applies if you use the Prometheus web UI.
Prometheus v3.5.2 fixes a stored XSS vulnerability in the Prometheus web UI. The release also includes a regex performance improvement.
Check if affected (1)
securitymediumStored XSS fix in the Prometheus web UI
Applies if crafted metric names or label values can reach the Prometheus web UI.
OpenTelemetry v0.150.0 combines a dependency update with bug fixes relevant to operators. The release addresses behavior in exporter, profile, and configuration handling.
Source ↗cert-manager v1.20.2 fixes invalid Helm YAML generation and updates Go to 1.. It also includes a security-related update to Go dependencies with reported vulnerabilities.
Action needed (1)
securityGo dependency updates
Go dependencies with reported vulnerabilities were updated in cert-manager v1.20.2. No advisory identifier is provided for this update.
Envoy v1.37.2 is a maintenance release focused on operator-relevant correctness fixes. The notes identify no security advisories or operator action beyond upgrading.
Source ↗Envoy v1.36.6 is a maintenance release with fixes for dynamic module buffering, internal redirect request handling, and Docker release images. The recorded issues concern incomplete request or response bodies, request hangs after buffer overflow, and release image updates.
Source ↗A maintenance release adds server shutdown-timeout configuration and performance improvements in object listing and cache key generation. It also corrects an AuthZEN discovery security issue and replaces a vulnerable test dependency.
Check if affected (2)
securityAuthZEN discovery metadata endpoint URLs
Applies if
authzen.is configured.baseURL securityThe
github.test dependency, replaced with Mobycom/docker/docker Applies if tests run.
This release contains operator-relevant correctness fixes across messaging, workflows, HTTP proxying, placement, and scheduling. It also updates the Go toolchain across the repository and its Docker images.
Action needed (1)
securityThe Go toolchain, updated to 1.25.9
The Go toolchain was upgraded from 1.25.8 to 1.25.9 across all modules and Docker images in the repository.
Envoy v1.35.10 is a maintenance release with an operator-facing defect correction. The recorded release note points to an update or fix for Docker release images.
Source ↗This release contains an operator-facing correction to the Docker release images. No individual change details are available beyond that release-note heading.
Source ↗