A maintenance release with operator-facing bug fixes in job pod handling, resource snapshots, GPU resources, and scheduler snapshot cloning. It also contains an update with no stated operator-facing impact.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release with two operator-facing defect fixes: virt-handler now restarts its domain-notify server after an unexpected exit, and VMExport handles long PVC names.
OPA v1.15.1 is a patch release that corrects a backwards-incompatible v1/logging. interface change from v1.15.0. The fix concerns Go module users with custom Logger implementations; binary and Docker image behavior is unchanged.
This is a patch release for Backstage with one new TablePagination API prop and two correctness fixes. The changes concern pagination labeling, relative link resolution, and entity relation cards.
cert-manager v1.20.1 contains bug corrections and a security-related dependency update. The gRPC vulnerability details are limited to the scanner reports, which state that it does not affect cert-manager.
Action needed (1)
securityThe
google.dependency updategolang. org/grpc The
google.dependency is bumped in cert-manager v1.20.1 to address a vulnerability reported by scanners. The report states that the vulnerability does not affect cert-manager.golang. org/grpc
A maintenance release with operator-relevant fixes to application normalization and cached installation IDs. The remaining release note content does not describe additional product changes.
Source ↗A release with operator-facing compatibility changes, including feature removals, aligned chart and application versions, GHCR-only chart distribution, and a changed CRD conversion-webhook default. It also updates dependencies and the Python interpreter to resolve CVEs, with additional defect fixes and new service and architecture capabilities.
Action needed (1)
securityDependency and Python interpreter updates for CVE fixes
Many dependencies and the Python interpreter were updated to resolve CVEs.
Check if affected (6)
breakingCustom error responses and header-case mangling, removed
Applies if you use Ambassador Edge Stack's custom error responses or header-case mangling features.
breakingHelm chart and Emissary version alignment
Applies if you use the Helm chart.
breakingGHCR-only Helm chart distribution
Applies if you use Emissary's Helm charts.
- + 3 more on the release page
OPA v1.15.0 adds pluggable logging and AWS web-identity signing support, changes the custom HTTPAuthPlugin lifecycle contract, and adds TLS certificate reread configuration. It also includes correctness fixes and dependency updates; no security advisories or vulnerability disclosures are stated.
Check if affected (1)
breakingCustom
HTTPAuthPluginlifecycle contractApplies if you use custom
HTTPAuthPluginimplementations.
Dapr v1.17.3 is a maintenance release with two dependency upgrades that resolve reported CVEs. It also includes correctness fixes for actor and service responses, placement dissemination, reconnect behavior, Scheduler participation, metrics, and Windows sidecar startup.
Action needed (2)
securitycriticalThe
google.dependency, updated for CVE-2026-33186golang. org/grpc The
google.dependency is upgraded in this release to resolve CVE-2026-33186.golang. org/grpc securitymediumThe
golang.dependency, updated for CVE-2026-33809org/x/image This release upgrades
golang.from v0.25.0 to v0.38.0, resolving CVE-2026-33809.org/x/image
This release adds TLS, certificate, xDS, and C++ credential capabilities, and changes EventEngine defaults and support. It also corrects an OpenBSD sizing defect and changes RR and WRR connection behavior.
Check if affected (1)
breaking
EventEnginedefaults and fork supportApplies if you use Python or Ruby.
This release updates the Go toolchain and corrects Scheduler and container defects. The recorded Scheduler and Windows fixes require only an upgrade, with no operator configuration changes stated.
Action needed (1)
securityThe
Goversion, updated to 1.25.8Dapr v1.16.11 updates the
Gotoolchain from 1.25.7 to 1.25.8.
This maintenance release includes a security mitigation for CVE-2026-33186 in grpc-go. It also contains ordinary fixes to application behavior and the user interface.
Action needed (1)
securitycritical
grpc-goCVE-2026-33186 mitigationA mitigation for CVE-2026-33186 in
grpc-goships in therelease-3.line.2
Argo CD v3.1.13 focuses on release artifact provenance and maintenance, with a security mitigation, a UI correction, and a dependency update. Container images are signed, and qualifying container images and CLI binaries receive SLSA Level 3 provenance.
Action needed (1)
securitycritical
grpc-goCVE-2026-33186 mitigationThe release includes a mitigation for CVE-2026-33186 in
grpc-gofor release-3.1.
Argo CD v3.3.5 is a maintenance release with six operator-relevant bug fixes and an update to the google. dependency from 1.77.0 to 1.79.3. No security advisories or security-specific fixes are disclosed.
A maintenance release deprecates and removes install., updates the Go toolchain and JSON-RPC dependency, and corrects dashboard and webhook issues. It also includes vulnerability fixes in Go and UI packages.
Action needed (2)
securityGo package updates for vulnerability fixes
Go packages are upgraded to fix vulnerabilities.
securityUI package updates for vulnerability fixes
UI packages are upgraded to fix vulnerabilities.
Check if affected (1)
breakingThe
install.installer, removedsh Applies if you use
install..sh
Plan ahead (1)
deprecatedThe
install.installer, deprecatedsh Applies if you use
install..sh
Rook v1.19.3 contains operational behavior changes, dependency updates, and new configuration capabilities. The release note also includes changes to storage, exporter, object store, and CSI components, but no explicit security advisories or security flaws are disclosed.
Source ↗A maintenance release with an RBAC grant removal, behavioral fixes, and new CephNFS API fields. It also updates exporter and OSD handling, including log collection, reconciliation, cancellation, encrypted OSD key rotation, and container selection.
Check if affected (1)
breakingThe
nodes/proxyRBAC grant, removedApplies if you use
nodes/proxy.
A broad operator-facing feature and maintenance release with API and behavior changes, dependency updates, deprecations, and removals. Monitoring and configuration changes include recording-rule and feature-gate updates, alongside scheduling and security-related behavior changes; no security advisories are reported.
Check if affected (7)
breakingNetwork attachment definition get permissions in the
virt-controllerClusterRole, removedApplicability is not stated in the release notes.
breakingStop requests for paused VMIs, rejected
Applies if you run paused VMIs.
breakingThe
EnableVirtioFsConfigVolumesfeature, graduated to GAApplies if you use the
EnableVirtioFsConfigVolumesfeature gate.- + 4 more on the release page
Plan ahead (4)
deprecatedThe
DisableMDEVConfigurationfeature gate, deprecatedremoval date not announcedApplies if you use the
DisableMDEVConfigurationfeature gate.deprecatedThe
kubevirt_vmi_migration_data_total_bytesmetric, deprecatedApplies if you use the
kubevirt_vmi_migration_data_total_bytesmetric.deprecatedThe
MultiArchitecturefeature gate, deprecatedApplies if you use the
MultiArchitecturefeature gate.- + 1 more on the release page
A maintenance release with multiple security fixes, tighter JWT and MQTT-related enforcement, and dependency manifest updates. It also includes correctness fixes and improvements across networking, monitoring, clustering, and JetStream.
Action needed (1)
breakingJWT size limit
JWTs now have a
1MBsize limit.
Check if affected (13)
securityhighMQTT security fixes
Applies if you use
MQTT.securityhighLeafnode security fix
Applies if you use
leafnodes.securityhighCommand-line credential security fix
Applies if you provide credentials on the command line.
- + 10 more on the release page
A maintenance release with multiple disclosed security fixes, correctness fixes, stricter validation and permission constraints, and dependency and toolchain updates. It also includes fixes across MQTT, JetStream, leafnodes, WebSockets, monitoring, and clustering.
Action needed (1)
breakingThe
JWTsize limitJWTs now have a 1MB size limit.
Check if affected (11)
securityhighCVE-2026-33216, CVE-2026-33217, and CVE-2026-33215 fixes for MQTT systems
Applies if you use MQTT.
securityhighCVE-2026-33218 fix for leafnodes
Applies if you use leafnodes.
securityhighCVE-2026-33247 fix for command-line credentials
Applies if you configure credentials on the command line.
- + 8 more on the release page
A maintenance release fixes a disclosed security vulnerability in Check requests with conditions and caching enabled, which could return incorrect cached results. The fix addresses the interaction between conditional checks and caching.
Check if affected (1)
securitymediumCVE-2026-33729 and GHSA-h6c8-cww8-35hf fixed
Applies if
Checkrequests use conditions and caching is enabled.
A maintenance release with a configurable TLS addition in the release notes. The secure pod default change is announced for a future release, not this one.
Source ↗A maintenance release with security-related dependency updates and removal of the hostPort setting from example manifests. It also documents compatibility testing with Kubernetes 1.32 through 1.34.
Action needed (2)
securitycritical
google.golang. org/grpc v1.update79. 3 google.is updated togolang. org/grpc v1., which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected by this advisory.79. 3 security
Envoyv1.update35. 9 The
Envoydependency is updated tov1.to address security vulnerabilities.35. 9
Check if affected (1)
breakingRemoval of
hostPort: 8002from example manifestsApplies if you use
hostPortin example manifests.
A maintenance release with updated Envoy and gRPC dependencies, plus a change to the example manifests. It is tested against Kubernetes 1.31 through 1.33.
Action needed (2)
securitycritical
google.updated togolang. org/grpc v1.79. 3 google.is updated togolang. org/grpc v1., which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected.79. 3 security
Envoyupdated tov1.34. 13 Envoyis updated tov1.to address security vulnerabilities and improve stability.34. 13
Check if affected (1)
breaking
hostPort: 8002removed from example manifestsApplies if
hostPort: 8002is configured in example manifests.
A maintenance release contains dependency security updates and an example-manifest cleanup. It also documents testing against Kubernetes 1.30 through 1.32.
Action needed (2)
securitycritical
google.updated to v1.79.3 for CVE-2026-33186golang. org/grpc The release updates
google.to v1.79.3, which addresses CVE-2026-33186 and GHSA-p77j-4mvh-x3m3. Contour is not affected.golang. org/grpc security
Envoyupdated to v1.34.13The release bumps
Envoyto v1.34.13.
Check if affected (1)
breakingEnvoy metrics
hostPort: 8002removed from example manifestsApplies if example manifests use
hostPort: 8002.
This release adds experimental AuthZen 1.0 support and changes observability output for list-objects operations. It also includes fixes for recoverable panics.
Source ↗A maintenance release with operator-relevant bug fixes, new configuration and diagnostic capabilities, and dependency and image updates. Two fixes address security-relevant exposure or policy bypass, and no deprecations or removals are announced.
Check if affected (2)
securityWorld-accessible Envoy admin socket
Applies if
envoyruns.securityIngress policy enforcement for local backends
Applies if you use
ingress policiesandlocal backends.
Cilium v1.18.8 contains one new XDP capability, multiple bug fixes, and dependency and image updates. GKE users should skip this version because of a known regression.
Source ↗A maintenance release with bug fixes, dependency and image updates, improved bugtool output, and a GKE channel fix. The Envoy admin socket fix addresses its world-accessible creation.
Check if affected (1)
securityThe Envoy admin socket's accessibility
Applies if Envoy runs.
This release contains project module maintenance and regenerated protobuf code. Nothing here needs operator attention.
Source ↗wasmCloud v2.0.0 adds operator-facing capabilities, changes CRD locations, updates dependencies, and fixes runtime and CLI behavior. The dependency update addresses the disclosed advisory RUSTSEC-2026-0007.
Action needed (2)
securitymediumLock file update for
RUSTSEC-2026-0007wasmCloud v2.0.0 updates the lock file to address
RUSTSEC-2026-0007.breakingCRD location moved from
templates/crdsto/crdswasmCloud v2.0.0 moves CRDs from
templates/crdsto/crds.
This patch release corrects CIMD redirect URI matching for loopback addresses. No operator configuration change is indicated.
Source ↗A feature and maintenance release that introduces a vendor-neutral API with a user-controlled migration workflow, alongside preview Dynamic Zones support. It also changes Helm and runtime image distribution locations and updates dependencies.
Check if affected (2)
breakingThe
helmrepository, switched to OCIApplies if you use Helm.
breakingThe API group, renamed to
k8gb.io/v1beta1 Applies if you use
k8gb..absa. oss/v1beta1
This release updates supported Kubernetes and pod-security configurations, installation behavior, and bundled component versions. The main operator-facing changes are the Kubernetes 1. requirement and the baseline pod-security enforcement default, alongside fixes and new capabilities.
Action needed (1)
breakingBaseline pod security enforcement
Pod security enforcement changes to the baseline level in this release.
Check if affected (1)
breaking
Kubernetes 1.requirement34+ Applies if you use
Kubernetes1..34+
This release contains API and template changes, new DevTools functionality, frontend behavior changes, and defect corrections. No security advisories or security-specific fixes are stated.
Check if affected (1)
breakingThe catalog entity page layout header is disabled
Applies if you use the catalog entity page in the new frontend system.
A security and maintenance release with authorization-bypass fixes and dependency updates that address reported vulnerabilities. It also includes correctness fixes, with no operator configuration changes or deprecations announced.
Action needed (4)
securitycritical
google.updated togolang. org/grpc 1.79. 3 The release updates
google.togolang. org/grpc 1.to resolve CVE-2026-33186.79. 3 securityhighAuthorization bypasses in multiple APIs, CVE-2026-33413
The etcd server fixes authorization bypasses in multiple APIs. The issue is identified by CVE-2026-33413 and GHSA-q8m4-xhhv-38mg.
securityhigh
go.updated toopentelemetry. io/otel/sdk v1.40. 0 The release updates
go.toopentelemetry. io/otel/sdk v1.. The update addresses40. 0 GO-2026-4394.securityhigh
golang.updated toorg/x/net v0.51. 0 The release updates
golang.toorg/x/net v0.to resolve51. 0 GO-2026-4559.
Check if affected (1)
securitylowRBAC checks for nested etcd transactions, CVE-2026-33343
Applies if you use nested etcd transactions and
RBAC.
A maintenance release with ordinary correctness fixes, disclosed security fixes, and security-related dependency updates. The security changes are addressed by upgrading, and no operator reconfiguration is explicitly required.
Action needed (3)
securitycriticalThe
google.dependency, updated togolang. org/grpc 1.79. 3 The release updates
google.togolang. org/grpc 1.to resolve CVE-2026-33186.79. 3 securityhighThe
go.dependency, updated toopentelemetry. io/otel/sdk v1.40. 0 The release updates
go.toopentelemetry. io/otel/sdk v1.to resolve40. 0 GO-2026-4394.securityhighThe
golang.dependency, updated toorg/x/net v0.51. 0 The release updates
golang.toorg/x/net v0.to resolve51. 0 GO-2026-4559.
Check if affected (2)
securityhighAuthorization bypasses in multiple APIs (CVE-2026-33413)
Applies if you use unauthenticated endpoints.
securitylowNested etcd transaction RBAC authorization checks (CVE-2026-33343)
Applies if you use nested txn ops.
A maintenance release with authorization fixes for unauthenticated APIs and nested transactions. It also updates golang. and google. to address reported issues.
Action needed (4)
securitycritical
google.updated togolang. org/grpc 1.79. 3 The
google.dependency is updated togolang. org/grpc 1.to resolve CVE-2026-33186.79. 3 securityhighAuthorization checks for unauthenticated endpoints
Unauthenticated endpoints in the
etcdserver now have authorization checks. This fixes authorization bypasses in multiple APIs, identified as CVE-2026-33413 and GHSA-q8m4-xhhv-38mg.securityhigh
golang.updated toorg/x/net v0.51. 0 The
golang.dependency is updated toorg/x/net v0.to resolve51. 0 GO-2026-4559.securitylowRBAC checks for nested
etcdtransactionsNested transaction operations in the
etcdserver now enforce authorization checks. This fixes RBAC authorization bypasses in nestedetcdtransactions, identified as CVE-2026-33343 and GHSA-rfx7-8w68-q57q.
A feature and compatibility release adds registry, cache, signing, profiling, and configuration capabilities. It changes proxy-cache behavior, removes GCR replication, and includes dependency, base-component, and defect corrections.
Action needed (2)
securityBearer token validation
Harbor rejects bearer tokens issued before project creation.
breakingPort
9443removed from the webhook event checkPort
9443is removed from the Harbor IP used for webhook event checks.
Check if affected (2)
breakingThe
pull-through cacheis replaced byproxy cacheApplies if you use
pull-through cachein Harbor.breaking
GCR replicationremovalApplies if you use
GCR replicationin Harbor.
This release fixes an agent version-reporting defect during re-attestation or SVID renewal. The recorded release note describes the agent's startup version being replaced by an empty string during that process.
Source ↗