RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

cert-managerv1.18.6SecurityFeb 24, 2026

cert-manager v1.18.6 is a patch release focused on fixing reported vulnerabilities, including CVE-2025-68121, through a Go toolchain bump. CVE-2026-24051 is explicitly stated not to affect cert-manager.

Action needed (2)

  • securitycriticalCVE-2025-68121 vulnerability fix

    The v1.18.6 patch release fixes reported vulnerabilities, most notably CVE-2025-68121, in cert-manager.

  • securitycriticalGo toolchain bump for CVE-2025-68121

    The Go toolchain is bumped in cert-manager v1.18.6 to address CVE-2025-68121.

Source
cert-managerv1.19.4SecurityFeb 24, 2026

cert-manager v1.19.4 is a patch release focused on reported vulnerabilities and dependency updates. It includes fixes for CVE-2026-24051, CVE-2025-68121, and GO-2026-4394.

Action needed (3)

  • securitycriticalThe go dependency update

    The go dependency is bumped in cert-manager v1.19.4 to address CVE-2025-68121.

  • securityhighcert-manager v1.19.4 vulnerability fixes

    cert-manager v1.19.4 is a patch release addressing reported vulnerabilities, including CVE-2026-24051 and CVE-2025-68121.

  • securityhighThe otel SDK dependency update

    The otel SDK dependency is bumped in cert-manager v1.19.4 to address GO-2026-4394.

Source
Fluxv2.8.0CI/CD & App DeliveryFeb 24, 2026

Flux v2.8.0 expands capabilities across controllers, notifications, the CLI, and artifact handling while also including fixes and dependency updates. It removes the deprecated API versions v1beta2 and v2beta2 from CRDs and changes Kubernetes compatibility requirements, so users of those APIs or affected Kubernetes versions are the main audience.

Check if affected (1)

  • breakingThe Flux APIs v1beta2 and v2beta2, removed from CRDs

    Applies if you use the Flux APIs v1beta2 or v2beta2 in CRDs.

Source
Knativeknative-v1.20.3Orchestration & ManagementFeb 24, 2026

This release rebuilds the prior Knative release with Go v1.25.7. No operator-facing feature or configuration change is described.

Source
Knativeknative-v1.21.1Orchestration & ManagementFeb 24, 2026

Knative v1.21.1 announces a future change to secure pod defaults, while the v1.21 default remains unchanged. The prior release was rebuilt with v1.25.7.

Source
Backstagev1.48.2CI/CD & App DeliveryFeb 24, 2026

This release restores two scaffolder alpha API exports, changes search behavior on first navigation, and updates @microsoft/api-extractor to correct a compatibility defect.

Source
OpenFGAv1.11.6SecurityFeb 23, 2026

This release changes the default ListObjects pipeline and narrows the requirements for read-only container deployments. It updates grpc-health-probe to address CVE-2025-68121, while the grpc-gateway client migration remains internal-only.

Action needed (1)

  • securitycriticalThe grpc-health-probe dependency update for CVE-2025-68121

    The grpc-health-probe dependency is updated to v0.4.45 to address CVE-2025-68121.

Check if affected (1)

  • breakingInternal HTTP-to-gRPC communication over UDS

    Applies if you use --read-only.

Source
KubeVirtv1.7.1Orchestration & ManagementFeb 23, 2026

KubeVirt v1.7.1 is a maintenance release focused on correctness fixes, dependency updates, and expanded compatibility. It also adds a metric and alert for ephemeral hotplug volumes.

Source
Argov3.3.2CI/CD & App DeliveryFeb 22, 2026

This release fixes the client-side apply migration issue reported in versions 3.3.0 and 3.3.1. No security advisories are disclosed.

Action needed (1)

  • breakingClient-side apply migration failure

    The failed to perform client-side apply migration issue present in versions 3.3.0 and 3.3.1 is fixed in this release.

Source
k8gbv0.18.1Kubernetes CoreFeb 21, 2026

v0.18.1 is a dependency update release. It includes an update to coredns-plugin for the latest security fixes, alongside other dependency version changes.

Action needed (1)

  • securityThe coredns-plugin dependency, updated for security fixes

    The coredns-plugin dependency is updated to include the latest security fixes in v0.18.1.

Source
Contourv1.33.2Networking & MessagingFeb 20, 2026

A maintenance release tested against Kubernetes 1.32 through 1.34, with runtime resource tuning and a correction to load balancer status handling. It also updates Go to v1.25.7.

Source
Contourv1.32.3Networking & MessagingFeb 20, 2026

Contour v1.32.3 updates the Go dependency, corrects an HTTPProxy CRD schema defect, and documents the Kubernetes versions tested with the release. No individual change details are available here.

Source
Contourv1.31.4Networking & MessagingFeb 20, 2026

Contour v1.31.4 updates the Go toolchain to v1.24.13 and corrects an HTTPProxy status schema defect that affected load balancer status updates. It is tested against Kubernetes 1.30 through 1.32, and no security advisories are disclosed.

Source
Keycloak26.5.4SecurityFeb 20, 2026

A maintenance release with five disclosed security fixes, one new capability, and ten corrected bugs. It contains no operator prerequisites or dependency-manifest entries.

Action needed (2)

  • securitymediumCVE-2026-0707, authorization header parsing

    This release corrects authorization header parsing that could bypass security controls.

  • securitylowCVE-2025-5416, keycloak-core environment information disclosure

    This release fixes environment information disclosure in keycloak-core.

Check if affected (4)

Source
Kyvernov1.17.1SecurityFeb 19, 2026

This release includes a security fix for CVE-2025-68121, along with defect corrections and dependency updates. It also changes operator-facing defaults and configuration documentation, including a default that now uses a duration string.

Action needed (1)

  • securitycriticalCVE-2025-68121 security fix

    CVE-2025-68121 is fixed in this release.

Check if affected (1)

  • breakingDefault value and Helm values documentation format change

    Applicability is not stated in the release notes.

Source
Fluentdv1.19.2ObservabilityFeb 19, 2026

Fluentd v1.19.2 contains bug fixes, dependency updates, and compatibility improvements. No security advisories or explicitly described security fixes are identified for this release.

Source
Strimzi0.50.1Networking & MessagingFeb 19, 2026

A maintenance release with two security fixes and a deprecated KafkaUser API field that requires migration. It also includes API conversion fixes, broker certificate output changes, and dependency and container image updates.

Action needed (1)

Plan ahead (1)

  • deprecatedThe .spec.authorization.acls[]operation field is deprecated

    Applies if you configure .spec.authorization.acls[]operation.

Source
Kubescapev4.0.2SecurityFeb 18, 2026

A maintenance release upgrades github.com/go-git/go-git/v5 from 5.16.2 to 5.16.5 and corrects runtime version reporting in the release build configuration. The configuration uses .Tag for the runtime version to avoid a confusing message when installing the latest version and running a scan.

Source
Argov3.2.7CI/CD & App DeliveryFeb 18, 2026

Argo CD v3.2.7 is a maintenance release with ordinary bug fixes and a Go dependency update. No security advisory or forced operator action is disclosed.

Source
Argov3.3.1CI/CD & App DeliveryFeb 18, 2026

Argo CD v3.3.1 is a maintenance release with correctness fixes and updates to its Kustomize dependency and Ubuntu base image. Operators of self-managing Argo CD installations should account for the documented upgrade prerequisite.

Source
KubeVelav1.10.7CI/CD & App DeliveryFeb 18, 2026

A correctness fix clears removed components from Application status. Deleted components are filtered from status fields, and status arrays are updated when components are removed from the spec.

Source
Open Policy Agent (OPA)v1.13.2SecurityFeb 18, 2026

OPA v1.13.2 updates the Go version used to build its binaries and images. The release includes the Go standard library fix for GO-2026-4337.

Action needed (1)

  • securitycriticalGo 1.25.7 build dependency

    OPA binaries and images are now built with Go 1.25.7. The Go standard library in that version contains a fix for GO-2026-4337.

Source
Litmus3.26.0ObservabilityFeb 18, 2026

Litmus 3.26.0 is a maintenance release focused on operator-visible corrections to UI layout behavior and image-registry validation. Other release-note material concerns headings, duplicate detail, or development and build-only changes.

Source
Crossplanev2.2.0Orchestration & ManagementFeb 17, 2026

A release with breaking changes to package installation and package-cache side-loading, alongside new operator capabilities and ordinary defect corrections. It also includes security-tagged dependency updates, but no advisory identifiers or vulnerability details are provided.

Action needed (7)

  • securitySecurity update for golang.org/x/crypto

    The golang.org/x/crypto module was updated to v0.45.0 as a security update.

  • securitySecurity update for github.com/go-chi/chi/v5

    The github.com/go-chi/chi/v5 module was updated to v5.2.4 as a security update.

  • securitySecurity update for github.com/sigstore/cosign/v3

    The github.com/sigstore/cosign/v3 module was updated to v3.0.4 as a security update.

  • securitySecurity update for github.com/theupdateframework/go-tuf/v2

    The github.com/theupdateframework/go-tuf/v2 module was updated to v2.4.1 as a security update.

  • securitySecurity update for github.com/sigstore/rekor

    The github.com/sigstore/rekor module was updated to v1.5.0 as a security update.

  • securitySecurity update for github.com/sigstore/sigstore

    The github.com/sigstore/sigstore module was updated to v1.10.4 as a security update.

  • securitySecurity update for github.com/quic-go/quic-go

    The github.com/quic-go/quic-go module was updated to v0.57.0 as a security update.

Check if affected (2)

  • breakingInput CRD installation from Function packages

    Applies if you use Function packages and Input CRDs.

  • breakingPackage cache structure

    Applicability is not stated in the release notes.

Source
Linkerdedge-26.2.1Networking & MessagingFeb 17, 2026

This release focuses on dependency and component upgrades. It adds no new operator capabilities or stated security changes, and it requires no setup changes beyond upgrading.

Source
Backstagev1.48.0CI/CD & App DeliveryFeb 17, 2026

A release with breaking API and configuration changes alongside new frontend and catalog capabilities. Operators and plugin authors should review renamed catalog extension imports, rejected cross-plugin API overrides, removed configuration and extension-point behaviors, and the module federation default.

Check if affected (7)

  • breakingStable catalogProcessingExtensionPoint export

    Applies if you use catalogProcessingExtensionPoint when providing custom processors and entity providers into the catalog.

  • breakingRejected CatalogApi and ErrorApi overrides

    Applicability is not stated in the release notes.

  • breakingRemoved auth.experimentalDynamicClientRegistration.tokenExpiration

    Applies if you configure auth.experimentalDynamicClientRegistration.tokenExpiration.

  • + 4 more on the release page

Plan ahead (2)

  • deprecatedDeprecated IconComponent type

    Applies if you use IconComponent.

  • deprecatedDeprecated items prop

    Applies if you use the items prop.

Source
Ciliumv1.19.1Networking & MessagingFeb 17, 2026

Cilium v1.19.1 contains routine bug fixes, performance improvements, and dependency and image updates. The available release information does not identify security advisories or explicitly described security flaws.

Source
Istio1.28.4Networking & MessagingFeb 16, 2026

A maintenance release focused on security fixes, validation, and authorization changes across Istio control-plane and endpoint handling. It also includes operator-facing capability changes and corrections for other defects.

Action needed (1)

  • securityhighCVE-2025-61732 cgo comment parsing flaw

    This release fixes a discrepancy between Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary.

Check if affected (4)

  • securitycriticalCVE-2025-68121 TLS session resumption validation

    Applies if you use Config.Clone with mutations or Config.GetConfigForClient.

  • securityGateway deployment controller resource validation

    Applies if the gateway deployment controller runs.

  • securityResource annotation validation against container injection

    Applies if you configure resource annotations.

  • + 1 more on the release page
Source
Istio1.27.7Networking & MessagingFeb 16, 2026

A security release addressing two vulnerabilities in cgo comment parsing and crypto/tls session resumption. The fixes are relevant to deployments using the affected Go functionality.

Action needed (2)

  • securitycriticalCVE-2025-68121 session resumption vulnerability correction

    CVE-2025-68121 corrects a crypto/tls session resumption flaw that could let resumed handshakes succeed after ClientCAs or RootCAs changed between the initial and resumed handshake.

  • securityhighCVE-2025-61732 code-smuggling vulnerability correction

    CVE-2025-61732 addresses a discrepancy in Go and C/C++ comment parsing that allowed code smuggling into the resulting cgo binary.

Source
Istio1.29.0Networking & MessagingFeb 16, 2026

A broad release adds operator-visible capabilities across ambient networking, telemetry, Gateway API, and traffic management, while changing several defaults. The most consequential operational changes affect ambient mesh DNS and iptables behavior, debug endpoint authorization, Envoy metrics compression, and istiod memory and circuit-breaker handling.

Action needed (1)

  • breakingAutomatic GOMEMLIMIT setting for istiod

    istiod now automatically sets GOMEMLIMIT to 90% of its memory limits through the automemlimit library. The change ships in 1.29.0.

Check if affected (4)

  • breakingDefault-enabled iptables reconciliation

    Applies when the istio-cni DaemonSet is upgraded.

  • breakingDefault authorization for debug endpoints

    Applies if you use debug endpoints on port 15014.

  • breakingDefault HTTP compression for Envoy metrics

    Applies if you use Envoy metrics at the Prometheus stats endpoint based on client Accept-Header values.

  • + 1 more on the release page
Source
Ciliumv1.18.7Networking & MessagingFeb 13, 2026

A maintenance release combining an operator-facing configuration adjustment with bug fixes and routine dependency and image refreshes. No security advisories or security-specific fixes are disclosed.

Action needed (1)

  • breakingExclusion of topology.kubernetes.io labels from security labels by default

    The default security-label handling in this release excludes topology.kubernetes.io labels from security labels.

Source
Ciliumv1.17.13Networking & MessagingFeb 13, 2026

This release is focused on dependency and container image maintenance, including a runtime dependency addition and updated installation image digests. No security issues or operator configuration changes are disclosed.

Source
etcdv3.6.8Kubernetes CoreFeb 13, 2026

A maintenance release postpones removal of one flag and reverses another flag's deprecation. It also includes dependency and toolchain updates addressing named security advisories.

Action needed (2)

Plan ahead (1)

  • deprecatedThe --max-snapshots flag, removal postponedremoval planned in v3.8

    Applies if you use --max-snapshots.

Source
etcdv3.5.27Kubernetes CoreFeb 13, 2026

A maintenance release that changes the Go toolchain used to compile binaries. It also includes fixes for three named CVEs and their corresponding GHSA advisories.

Action needed (1)

Source
Daprv1.16.9Orchestration & ManagementFeb 12, 2026

This release includes a Go toolchain dependency upgrade and a corrected Pulsar PubSub subscription-metadata defect. A regression test verifies that metadata is applied to consumer options.

Action needed (1)

  • securityhighThe Go toolchain upgrade to 1.24.13

    Dapr v1.16.9 upgrades Go to 1.24.13. The upgrade addresses advisories GO-2026-4340 and GO-2026-4341.

Source
Kubescapev4.0.1SecurityFeb 12, 2026

A maintenance release contains an operator-facing correctness fix for the isRuleKubescapeVersionCompatible bug with version 4.0.0. The remaining note entries are headings, test changes, or merge metadata.

Source
← NewerOlder →
Browse by month