RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Helmv3.20.2Kubernetes CoreApr 9, 2026

A security maintenance release corrects a Helm Chart extraction defect tied to GHSA-hr2v-4r36-88hr. The changelog also contains a duplicate mention of this advisory-backed fix.

Check if affected (1)

  • securitymediumGHSA-hr2v-4r36-88hr: Helm Chart extraction output directory collapse

    Applies if you use Helm Chart extraction.

Source
Linkerdedge-26.4.2Networking & MessagingApr 9, 2026

This Linkerd edge release, edge-26.4.2, updates dependencies and components across the project. The release notes contain no explicit security advisories or security claims.

Source
OpenFeaturecore/v0.15.2CI/CD & App DeliveryApr 9, 2026

This release contains two security updates whose affected vulnerabilities are not identified. It also adds experimental incremental updates for gRPC synchronization.

Action needed (1)

  • securityThe vulnerability-updates security update

    OpenFeature Core v0.15.2 includes a security update for vulnerability-updates.

Source
OpenFeatureflagd-proxy/v0.9.4CI/CD & App DeliveryApr 9, 2026

This release contains security updates for flagd-proxy/v0.9.4. The available notes do not identify the affected vulnerabilities or describe their scope.

Action needed (2)

  • securityThe vulnerability-updates entry for issue #1933

    The vulnerability-updates entry records a security update for flagd-proxy/v0.9.4, tracked in issue #1933. The notes do not describe the affected vulnerability.

  • securityThe vulnerability-updates entry for issue #1934

    The vulnerability-updates entry records a security update for flagd-proxy/v0.9.4, tracked in issue #1934. The notes do not describe the affected vulnerability.

Source
OpenFeatureflagd/v0.15.2CI/CD & App DeliveryApr 9, 2026

flagd v0.15.2 includes two undisclosed security updates and a new experimental gRPC incremental-update capability. The experimental addition concerns deployments that use gRPC synchronization.

Action needed (2)

  • securityThe vulnerability-updates security update for issue #1933

    flagd v0.15.2 includes the vulnerability-updates security update linked to issue #1933.

  • securityThe vulnerability-updates security update for issue #1934

    flagd v0.15.2 includes the vulnerability-updates security update linked to issue #1934.

Source
Helmv4.1.4Kubernetes CoreApr 9, 2026

A maintenance release with security fixes affecting Helm plugins. It also changes plugin-load error handling in the CLI and getter paths.

Action needed (1)

  • securitymediumGHSA-hr2v-4r36-88hr security fix

    GHSA-hr2v-4r36-88hr is addressed in this release.

Check if affected (2)

  • securityhighPlugin verification when .prov is missing

    Applies if you use plugins.

  • securityhighPlugin metadata version path traversal

    Applies if you use plugins.

Source
SPIREv1.14.5SecurityApr 8, 2026

This release updates the Go dependency and toolchain to address multiple disclosed CVEs. It concerns deployments that rely on the release's bundled Go version.

Action needed (1)

Source
SPIREv1.13.5SecurityApr 8, 2026

This release updates the Go dependency to address multiple disclosed CVEs. It concerns deployments that receive their Go runtime or builds from this release.

Action needed (1)

Source
Open Policy Agent (OPA)v1.15.2SecurityApr 8, 2026

This release updates the Go toolchain used to build OPA binaries and images. It also includes multiple security fixes in that Go version.

Action needed (1)

  • securityThe Go toolchain, updated to 1.26.2

    The Go version used to build OPA binaries and images is updated to 1.26.2. This Go version contains multiple security fixes.

Source
Keycloak26.6.0SecurityApr 8, 2026

A substantial operator-facing feature and maintenance release adds new capabilities, configuration and deployment options, performance improvements, and many bug fixes. It also changes selected defaults, deprecates Token Exchange v1, and includes security and correctness fixes for authorization, identity and URL handling, SCIM, anti-phishing checks, and UMA token validation.

Action needed (6)

  • securitySeparate password and OTP brute force protection

    Password and OTP brute force protection are now separate by default to prevent OTP bypass attacks.

  • securityResourceAdminManager URL construction validation

    URL construction in ResourceAdminManager is validated against matrix parameter injection.

  • securityClient retrieval anti-ID phishing check

    Client retrieval now includes the missing anti-ID phishing check.

  • breakingZero-downtime patch releases enabled by default

    Zero-downtime patch releases are now promoted to supported and enabled by default.

  • breaking--truststore-kubernetes-enabled enabled by default

    The behavior controlled by --truststore-kubernetes-enabled is enabled by default.

  • breakingTen-second default not-before validation

    The default not-before validation period is now 10 seconds instead of 0.

Check if affected (7)

  • securityWorkflows admin permission boundaries

    Applies if you use Workflows.

  • securityOrganizations login IdP alias disclosure

    Applies if you use Organizations.

  • securitySCIM PUT body ID override protection

    Applies if you use SCIM.

  • + 4 more on the release page

Plan ahead (1)

  • deprecatedToken Exchange v1 deprecation

    Applies if you use Token Exchange v1.

Source
OpenFeaturecore/v0.15.1CI/CD & App DeliveryApr 7, 2026

Release 0.15.1 fixes a memory leak caused by unbounded metrics cardinality and updates a dependency for an undisclosed security fix. The dependency update ships in the core v0.15.1 release.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 dependency update

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 for a security fix. This change ships in core v0.15.1.

Source
OpenFeatureflagd-proxy/v0.9.3CI/CD & App DeliveryApr 7, 2026

This release includes a security update to the github.com/go-jose/go-jose/v4 dependency. The release note does not disclose the nature of the vulnerability.

Action needed (1)

  • securitygithub.com/go-jose/go-jose/v4 updated to v4.1.4

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in flagd-proxy v0.9.3 as a security fix. The note does not disclose the nature of the vulnerability.

Source
OpenFeatureflagd/v0.15.1CI/CD & App DeliveryApr 7, 2026

This release fixes RPC flag defaulting, metrics-server process handling, and unbounded metrics cardinality. It also updates a dependency for an undisclosed security fix, which is the main consideration for users evaluating the release.

Action needed (1)

  • securityThe github.com/go-jose/go-jose/v4 dependency, updated to v4.1.4

    The github.com/go-jose/go-jose/v4 module is updated to v4.1.4 in flagd/v0.15.1 for an undisclosed security fix.

Source
Fluxv2.8.5CI/CD & App DeliveryApr 7, 2026

Flux v2.8.5 is a maintenance release with bug fixes, clearer error reporting, added verification and authentication configuration, and updated toolkit components. No security advisories or explicitly described security vulnerabilities are present.

Source
Fluxv2.8.4CI/CD & App DeliveryApr 7, 2026

Flux v2.8.4 includes fixes for Windows support and --source validation, along with updates to Flux dependencies. These changes concern users of the affected commands and dependency consumers.

Source
Backstagev1.49.4CI/CD & App DeliveryApr 7, 2026

This is a patch release for Backstage with operator-relevant correctness fixes. The recorded note tail points to fixes for OAuth 2.0 metadata URL handling, the legacy-frontend-plugin template name, and permissions on the scaffolder plugin's /.well-known endpoint.

Source
Istio1.27.9Networking & MessagingApr 7, 2026

Istio 1.27.9 is a defect-fix release focused on operator and networking behavior. The recorded note tail includes fixes for startup handling, authorization matching, gateway restarts, TLS route hostname constraints, and intermittent proxy errors.

Source
OpenFGAv1.14.0SecurityApr 3, 2026

This release adds an operator-facing histogram metric and ListObjects performance improvements, fixes PostgreSQL and ListObjects defects, and addresses improper BatchCheck policy enforcement. Playground users face a breaking authentication constraint, while the built-in Playground and its port settings are deprecated.

Action needed (1)

  • securitymediumBatchCheck policy enforcement fix for CVE-2026-34972

    The issue was fixed where BatchCheck calls with multiple checks for the same tuple could result in improper policy enforcement. The fix addresses CVE-2026-34972 and GHSA-jwvj-g8pc-cx45.

Check if affected (1)

  • breakingPlayground authentication limited to none

    Applies if the Playground runs with preshared key authentication.

Plan ahead (2)

  • deprecatedBuilt-in OpenFGA Playground deprecationremoval date not announced

    Applies if you use the built-in OpenFGA Playground.

  • deprecated--playground-port and OPENFGA_PLAYGROUND_PORT deprecation

    Applies if you configure --playground-port or OPENFGA_PLAYGROUND_PORT.

Source
Limav2.1.1Kubernetes CoreApr 3, 2026

A release with Windows artifacts, broader guest and template configuration support, and changed vz audio handling. It also updates the bundled nerdctl distribution and dependencies, including security updates in BuildKit and CNI plugins that are obtained by upgrading.

Check if affected (1)

  • securityBuildKit and CNI plugins security updates

    Applies if you use BuildKit or CNI plugins.

Source
Linkerdedge-26.4.1Networking & MessagingApr 2, 2026

This Linkerd release includes proxy correctness fixes, operator-visible configuration changes, and added multicluster resources. It also updates dependencies and component versions, with no security advisories or explicitly described vulnerabilities.

Source
Keycloak26.5.7SecurityApr 2, 2026

A security maintenance release fixes seven disclosed vulnerabilities. It also upgrades Quarkus and corrects an error caused by requests without a Host header.

Action needed (1)

  • securitymediumCVE-2026-1002 static handler component cache

    CVE-2026-1002 fixes a flaw in the io.vertx/vertx-core static handler component cache that could deny access to static files.

Check if affected (6)

Source
Prometheusv3.11.0ObservabilityApr 2, 2026

A broad release with new service discovery, PromQL, TSDB, and UI capabilities, alongside performance, dependency, output, and correctness changes. It also deprecates legacy Hetzner discovery labels and corrects TSDB retention-time handling.

Check if affected (1)

  • breakingThe storage.tsdb.retention.time unit handling

    Applies if you configure storage.tsdb.retention.time.

Plan ahead (2)

  • deprecatedThe __meta_hetzner_datacenter label, deprecatedremoval date not announced

    Applies if you use __meta_hetzner_datacenter.

  • deprecatedThe Hetzner Cloud datacenter location labels, deprecated

    Applies if you use __meta_hetzner_hcloud_datacenter_location or __meta_hetzner_hcloud_datacenter_location_network_zone.

Source
CRI-Ov1.33.11Kubernetes CoreApr 2, 2026

CRI-O v1.33.11 contains no operator-facing changes in the supplied release material. No specific flags, fields, resources, metrics, or advisories are identified for this version.

Source
CRI-Ov1.35.2Kubernetes CoreApr 2, 2026

CRI-O v1.35.2 is an operator-facing maintenance release focused on configuration and runtime behavior. It concerns deployments using artifact stores, pinned images, image pulls, or the affected metrics paths.

Source
CRI-Ov1.34.7Kubernetes CoreApr 2, 2026

CRI-O v1.34.7 contains no operator-facing change details in the release note. There are no specific changes to assess for this release.

Source
wasmCloudv2.0.2Orchestration & ManagementApr 2, 2026

This release adds a Host pod reconciler and winget packaging, upgrades the wasmtime dependency, and changes install-script behavior. The install-script changes apply to both scripts and include fixes for the stable v2 release.

Source
etcdv3.6.10Kubernetes CoreApr 1, 2026

A maintenance release with changes to authorization behavior and an etcdctl endpoint command regression. The recorded release notes also include headings and documentation updates.

Source
etcdv3.5.29Kubernetes CoreApr 1, 2026

A maintenance release with changes to etcdserver access and an etcdctl command regression. The recorded changes do not include item details for this release.

Source
etcdv3.4.43Kubernetes CoreApr 1, 2026

A maintenance release with permission and etcdctl regression fixes. The recorded changes do not include details for individual release-note entries.

Source
OpenFeaturecore/v0.15.0CI/CD & App DeliveryApr 1, 2026

This release changes fractional bucketing behavior in flagd. The provided release information does not describe the operator setup affected by the change.

Source
OpenFeatureflagd/v0.15.0CI/CD & App DeliveryApr 1, 2026

A fractional bucketing update changes pseudorandom assignments without changing the API. Consistent assignments require all providers to be updated.

Check if affected (1)

  • breakingFractional pseudorandom bucketing assignments

    Applies if you use providers.

Source
Karmadav1.16.4Orchestration & ManagementMar 31, 2026

Karmada v1.16.4 is a maintenance release focused on operator-facing defect corrections. It targets reliability in certificate rotation, upgrades, and workload evacuation.

Source
Karmadav1.15.7Orchestration & ManagementMar 31, 2026

Karmada v1.15.7 is a maintenance release focused on operator-facing bug fixes. The release notes emphasize corrections to operational behavior in Karmada components.

Source
KubeVelav1.10.8CI/CD & App DeliveryMar 31, 2026

This release focuses on operator correctness, with changes to status.details handling, an option to disable status validation, and fixes for apply-once resource reconciliation and applied-resource tracking. It also updates the debug webhook script as setup tooling.

Source
Jaegerv2.17.0ObservabilityMar 30, 2026

Jaeger v2.17.0 contains bug fixes, performance improvements, and new or expanded experimental capabilities. It also changes query and configuration behavior. No security advisories or explicitly security-related flaws are disclosed.

Source
Daprv1.16.12Orchestration & ManagementMar 30, 2026

A maintenance release with a security-relevant gRPC dependency upgrade, Pulsar Avro and JSON schema handling corrections, and a Scheduler cluster recovery fix. It also adds raw payload topic metadata and updates Avro payload conversion and CloudEvents schema registration.

Action needed (1)

  • securitycriticalThe google.golang.org/grpc dependency and CVE-2026-33186 resolution

    The affected google.golang.org/grpc dependency is upgraded to a version that resolves CVE-2026-33186. The fix ships in this release.

Check if affected (2)

  • breakingRejected rawPayload=true publishing to CloudEvents-wrapped topics

    Applies if rawPayload is set for a CloudEvents-wrapped topic.

  • breakingStructural validation for .jsonschema topics

    Applies if you configure .jsonschema.

Source
Confidential Containersv0.19.0SecurityMar 30, 2026

A release that narrows supported environments and installation paths while adding storage, attestation, GPU, API, signature, and image-handling capabilities. It also updates guest and image handling, including sealed-secret signatures, cosign signatures with newlines, in-memory LUKS headers, and improved Vault/OpenBao support.

Check if affected (5)

  • breakingGo support in CDH removed

    Applies if you use CDH.

  • breakingCanonical TDX Tech preview support removed

    Applies if you use Canonical TDX Tech preview.

  • breakingUbuntu version requirement

    Applies if you use Ubuntu 24.04.4 (linux-image-generic-hwe-24.04) or 25.10.

  • + 2 more on the release page

Plan ahead (1)

  • deprecatedpacker images support, planned for removalremoval date not announced

    Applies if you use packer images.

Source
← NewerOlder →
Browse by month