RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Argov3.5.1CI/CD & App DeliveryAug 12, 2026

This release contains routine correctness fixes and a security fix in the server. The security change concerns users of the SSD CLI.

Action needed (1)

  • securitySSD CLI secret-mask spoofing prevention

    The server prevents secret-mask spoofing in the SSD CLI. This fix ships in Argo CD v3.5.1.

Source
Argov3.4.7CI/CD & App DeliveryAug 12, 2026

A maintenance release with correctness fixes, a server-side secret-mask spoofing fix, and a third-party dependency update. Ordinary fixes and the dependency update require no operator action, while upgrading addresses the security fix.

Action needed (1)

  • securitySSD CLI secret-mask spoofing prevention

    The server now prevents secret-mask spoofing in the SSD CLI. This fix ships in the 3.4 release line.

Source
Argov3.3.14CI/CD & App DeliveryAug 12, 2026

A maintenance release with fixes for secret masking and pprof endpoint configuration, alongside dependency updates for two listed CVEs. The secret-handling fixes and dependency updates are addressed by upgrading, while the remaining defect fixes require no operator action.

Action needed (2)

  • securityhighThe /ui brace-expansion dependency update for CVE-2026-69152

    The /ui dependency brace-expansion is updated to 2.1.4 and 1.1.18 for CVE-2026-69152.

  • securitymediumThe DOMPurify dependency update for CVE-2026-49978

    The DOMPurify dependency is updated to 3.4.7 for CVE-2026-49978.

Check if affected (2)

  • securitySSD CLI secret mask spoofing prevention

    Applies if you use SSD CLI.

  • securitySecret hiding in the last-applied-configuration annotation

    Applies if you configure last-applied-configuration.

Source
CubeFSv3.6.0Storage & DataAug 12, 2026

A feature and maintenance release with expanded metadata, migration, storage-pool, learner, self-healing, proximity-read, and RocksDB capabilities. Operators need to follow the stated upgrade order and prerequisites; the release also contains corrective fixes, with no security advisories or explicit security flaws disclosed.

Source
Kubescapev4.0.12SecurityAug 12, 2026

A corrective and performance-focused release with operator-visible default and constraint changes, deprecated flag removal, and dependency vulnerability fixes. It also expands scanning, output, registry, and MCP capabilities.

Action needed (3)

  • securityBatch dependency vulnerability fixes

    Batch 1 and 2 dependency vulnerability fixes are included in this release.

  • breakingRegoV1 evaluation and v0 compatibility shim removal

    Rego evaluation now uses RegoV1 and drops the v0 compatibility shim in this release.

  • breakingLoopback-only constraint

    A loopback-only constraint is applied in this release.

Check if affected (3)

  • breakingOpt-in pprof debug server

    Applies if you enable the pprof debug server.

  • breaking--frameworks default set to all

    Applies if you do not configure --frameworks.

  • breakingDeprecated flags removal

    Applies if you configure deprecated flags.

Source
wasmCloudv2.7.0Orchestration & ManagementAug 11, 2026

wasmCloud v2.7.0 adds runtime, networking, plugin, TLS, and chart capabilities while correcting runtime and Helm/chart defects. It also changes defaults and updates dependencies.

Action needed (1)

  • breakingDefault-enabled implements and maps

    implements and maps are enabled by default in wasmCloud v2.7.0.

Source
OpenKruisev1.8.5CI/CD & App DeliveryAug 10, 2026

OpenKruise v1.8.5 corrects nodeimage TTL cleanup so setting completionPolicy.ttlSecondsAfterFinished does not delete the job itself. It adds the default-ttlseconds-for-always-nodeimage flag for kruise-controller-manager to control nodeimage data TTL.

Source
Buildpacksv0.40.9CI/CD & App DeliveryAug 9, 2026

This release updates dependencies associated with published security advisories. Builders created with the pack CLI from this release contain lifecycle v0.21.0 by default.

Action needed (3)

  • securityhighThe github.com/go-git/go-git/v5 dependency update

    github.com/go-git/go-git/v5 updates from v5.19.1 to v5.19.2 in buildpacks v0.40.9. The release note cites GHSA-hc8v-wwc9-vgxm.

  • securitymediumThe go.opentelemetry.io/otel dependency update

    go.opentelemetry.io/otel updates from v1.43.0 to v1.44.0 in buildpacks v0.40.9. The release note cites GO-2026-5158 and CVE-2026-41178 for a baggage header that was not length-capped.

  • securityThe github.com/klauspost/compress dependency update

    github.com/klauspost/compress updates from v1.18.6 to v1.18.7 in buildpacks v0.40.9. The release note cites GO-2026-5841 and GHSA-259r-337f-4rfw for an out-of-bounds read in s2.

Source
Fluxv2.9.4CI/CD & App DeliveryAug 7, 2026

A maintenance release with correctness fixes that narrow some existing configuration constraints. It also adds CLI repository migration support and updates dependencies; no explicit security advisory or vulnerability is disclosed.

Check if affected (3)

  • breakingThe image-automation-controller refspec constraint

    Applies if you configure refspecs.

  • breakingGCS static authentication limited to service account keys

    Applies if you configure GCS static authentication.

  • breakingThe allow-webhooks network policy restriction

    Applies if you configure allow-webhooks.

Source
Daprv1.17.12Orchestration & ManagementAug 6, 2026

This release contains a security-related build toolchain update and an input-binding startup fix. The probe timeout is configurable for applications with slow startup.

Action needed (1)

  • securityThe Go toolchain version, updated to 1.26.5

    The Go version used to build Dapr is updated from 1.26.4 to 1.26.5 across the runtime, build tooling, and container images.

Source
KServev0.20.0AI & MLAug 6, 2026

This release adds new inference-service, storage, runtime, routing, and deployment capabilities, alongside correctness fixes and dependency updates. Operators should review the Starlette security update, changed defaults, and narrower readiness behavior.

Action needed (2)

  • securitymediumstarlette dependency update for CVE-2026-48710

    The starlette dependency is bumped to >=1.0.1 for CVE-2026-48710.

  • breakingStandard default alignment with the llm-d optimized baseline

    The standard default is aligned with the llm-d optimized baseline.

Check if affected (7)

  • breakinglora-affinity-scorer default for LoRA adapters

    Applies if you use LoRA adapters.

  • breakingLLMInferenceServiceConfig deletion-prevention finalizer

    Applies if you use LLMInferenceServiceConfig.

  • breakingendpointPickerRef default EPP port

    Applies if you configure endpointPickerRef and do not configure port.

  • + 4 more on the release page
Source
Keycloak26.7.1SecurityAug 5, 2026

A maintenance release with security fixes and additional bug fixes. The security fixes require upgrading, and the ordinary bug fixes require no operator action beyond upgrading.

Check if affected (12)

Source
Microcks1.15.0CI/CD & App DeliveryAug 5, 2026

Version 1.15.0 adds authentication, TLS, GraphQL, configuration, and UI capabilities, alongside fixes for correctness defects. It also updates shipped container and frontend dependencies, with no disclosed security advisories or security-specific fixes.

Source
OpenCostv1.121.1ObservabilityAug 5, 2026

OpenCost v1.121.1 adds opt-in Athena query-result reuse configuration and NAT gateway cost metrics to OpenCost scrapes, and updates the Kubernetes dependency to k8s.io/apimachinery 0.36.3. Athena result reuse applies only to query engine v3, has no effect on v2 workgroups, and AWS limits MaxAgeInMinutes to 10080 minutes. No security advisories or security fixes are disclosed.

Source
OpenTelemetryv0.158.0ObservabilityAug 4, 2026

OpenTelemetry v0.158.0 adds a replacement processor and configuration-schema capabilities, along with changes to component maturity and several defect corrections. It also removes the pkg/xconfmap validation API in favor of symbols in confmap.

Check if affected (1)

  • breakingThe pkg/xconfmap validation symbols, renamed

    Applies if you use pkg/xconfmap's Validator or Validate symbols.

Source
Argov3.5.0CI/CD & App DeliveryAug 4, 2026

A maintenance release focused on operator-facing bug fixes, with additional feature and configuration work. It also includes dependency updates, including a UI dependency update for CVE-2026-41240.

Action needed (3)

  • securitymediumThe redoc/dompurify dependency update for CVE-2026-41240

    The UI dependency redoc/dompurify is bumped to v3.4.0 to fix CVE-2026-41240.

  • securityThe formidable dependency update

    The formidable dependency is updated to v2.1.3.

  • breakingThe auto-sync toggle removal from the app top bar

    The auto-sync toggle is removed from the app top bar.

Check if affected (1)

  • breakingThe theme default changed to auto

    Applies if theme is not configured.

Source
CRI-Ov1.35.6Kubernetes CoreAug 4, 2026

This release fixes user-namespace UID/GID restoration after CRI-O restart, reduces debug-log verbosity for List* RPC calls, and restores pre-1.34 handling of environment-variable values containing non-UTF-8 data. It also updates or removes dependencies listed in the dependency manifest.

Source
CRI-Ov1.34.11Kubernetes CoreAug 4, 2026

CRI-O v1.34.11 includes a correctness fix that restores prior handling of environment-variable values containing non-UTF-8 data. No detailed change item is provided here.

Source
CRI-Ov1.36.3Kubernetes CoreAug 4, 2026

This cri-o release includes a fix for a disclosed security vulnerability alongside runtime behavior, monitoring configuration, metric, and dependency updates. It is most relevant to deployments affected by the HOME environment-variable issue or the related observability and CNI configuration changes.

Action needed (1)

  • securityhighCVE-2026-15809 HOME environment-variable injection fix

    cri-o v1.36.3 fixes CVE-2026-15809. The vulnerability allowed a bypass of the CVE-2022-4318 fix, enabling /etc/passwd injection through newline characters in the HOME environment variable.

Source
Linkerdedge-26.8.1Networking & MessagingAug 3, 2026

Linkerd edge-26.8.1 updates third-party dependencies and the Linkerd proxy component. No security advisories or operator action are identified for this release.

Source
OpenFGAv1.18.2SecurityAug 3, 2026

A maintenance release with diagnostic logging, experimental cache metric changes, and corrections for weighted-graph and tuple-validation defects. It also updates the Go toolchain and embedded grpc-health-probe in released images.

Action needed (1)

  • securityhighgrpc-health-probe rebuilt at v0.4.53

    The embedded grpc-health-probe is rebuilt with Go 1.26.5 and bumped to v0.4.53 in released images. The update addresses the Go standard library vulnerabilities documented in the Go 1.26.5 release notes, including CVE-2026-39822.

Source
Tektonv1.15.0CI/CD & App DeliveryJul 31, 2026

Tekton v1.15.0 adds configurable behavior, corrects defects across controllers and runtime components, and updates project dependencies. No security advisories or explicitly described vulnerabilities are present.

Source
Argov3.3.13CI/CD & App DeliveryJul 31, 2026

A maintenance release with bug fixes and dependency updates. The form-data update in /ui addresses CVE-2026-12143.

Action needed (1)

  • securityhighThe form-data dependency update for CVE-2026-12143

    The form-data dependency is updated to version 4.0.6 in /ui to address CVE-2026-12143.

Source
Argov3.4.6CI/CD & App DeliveryJul 31, 2026

This is a bug-fix release for Argo CD v3.4.6. The release notes mention corrections to application behavior and integrations, with no security advisories or explicit security vulnerabilities stated.

Source
Karmadav1.18.2Orchestration & ManagementJul 31, 2026

A broad operator-impacting maintenance release with security-related base image updates, API and configuration changes, scheduling capabilities, and deprecations and removals. Operators should review changed defaults and constraints and account for migration work affecting their configurations, APIs, and metrics.

Action needed (2)

  • securityThe alpine base image update

    The alpine base image is updated from alpine:3.23.4 to alpine:3.24.1 to address security concerns.

  • securityThe alpine base image update

    The alpine base image is updated from alpine:3.23.3 to alpine:3.23.4 to address security concerns.

Check if affected (8)

  • breakingThe cluster lease duration flags, removed

    Applies if you configure either --cluster-lease-duration or --cluster-lease-renew-interval-fraction.

  • breakingThe Estimator metric label value, removed

    Applies if you use either estimating_plugin_execution_duration_seconds or estimating_plugin_extension_point_duration_seconds.

  • breakingThe Etcd.Local.InitImage configuration field, removed

    Applies if you configure Etcd.Local.InitImage.

  • + 5 more on the release page

Plan ahead (4)

  • deprecatedThe ReplicaRequirements.resourceRequest field deprecationdeprecated since v1.18.0

    Applies if you use ReplicaRequirements.resourceRequest.

  • deprecatedThe ComponentReplicaRequirements.resourceRequest field deprecationdeprecated since v1.18.0

    Applies if you use ComponentReplicaRequirements.resourceRequest.

  • deprecatedThe NodeClaim.nodeAffinity field deprecationdeprecated since v1.18.0

    Applies if you use NodeClaim.nodeAffinity.

  • + 1 more on the release page
Source
Karmadav1.17.5Orchestration & ManagementJul 31, 2026

A mixed maintenance and feature release with workload-affinity and anti-affinity support, encryption-at-rest capabilities, bug fixes, and updates to dependencies and default images. It also changes operational defaults and validation while deprecating or removing configuration flags and fields, so compatibility and configuration changes are part of the release.

Action needed (1)

  • breakingControllerPriorityQueue promotion to beta and default enablement

    ControllerPriorityQueue is promoted to beta and enabled by default.

Check if affected (4)

  • breakingThe --etcd-init-image flag, removed from karmadactl init

    Applies if you use the --etcd-init-image flag.

  • breakingnamespace validation for spec.resourceSelectors

    Applies if you use PropagationPolicy or OverridePolicy.

  • breakingDistinct GroupByLabelKey values in WorkloadAffinity

    Applies if you configure WorkloadAffinity.

  • + 1 more on the release page

Plan ahead (2)

  • deprecatedEtcd.Local.InitImage deprecationdeprecated since v1.17.0 · removal date not announced

    Applies if you configure Etcd.Local.InitImage in Karmada Init Configuration.

  • deprecatedDeprecation of cluster lease flagsdeprecated since v1.17.0 · removal date not announced

    Applies if you use --cluster-lease-duration or --cluster-lease-renew-interval-fraction.

Source
Karmadav1.16.8Orchestration & ManagementJul 31, 2026

A mixed maintenance and feature release with bug fixes, new APIs and capabilities, performance and instrumentation improvements, dependency updates, and deprecated field removals. Operators should review the removed fields and the updated dependency, while the release also adds multi-component scheduling, configurable initialization, eviction queue support, and new workload interpreters.

Action needed (1)

  • securitymediumThe github.com/vektra/mockery dependency update

    The github.com/vektra/mockery dependency was bumped to v3.5.5 to address security concerns identified by GO-2025-3900.

Check if affected (4)

  • breakingThe external etcd fields CAData, CertData, and KeyData, removed

    Applies if you configure CAData, CertData, or KeyData.

  • breakingThe init command's default component images

    Applies if you run the init command.

  • breakingA 32s default timeout for the member cluster client

    Applies if you use the member cluster client.

  • + 1 more on the release page

Plan ahead (2)

  • deprecatedThe --etcd-init-image flag, deprecatedremoval date not announced

    Applies if you use --etcd-init-image.

  • breakingThe Prometheus metric labels cluster and cluster_name, replaced by member_clusterremoval planned in 1.18

    Applies if you use the cluster or cluster_name metric labels.

Source
KEDAv2.20.2Orchestration & ManagementJul 31, 2026

KEDA v2.20.2 contains a new ScaledObject condition alongside correctness, validation, and performance fixes. The release also addresses operator stability and scaler behavior, with no disclosed security advisories or setup changes.

Source
Open Policy Agent (OPA)v1.19.0SecurityJul 30, 2026

A release with a SQL injection fix and a GHSA-linked dependency update, alongside a breaking Rego safety-checking change. It also changes runtime and CLI behavior, adds capabilities, and fixes correctness and performance issues.

Action needed (3)

  • securityhighoras.land/oras-go/v2 update for GHSA-fxhp-mv3v-67qp

    oras.land/oras-go/v2 is updated from 2.6.1 to 2.6.2 to address GHSA-fxhp-mv3v-67qp.

  • breakingReadHeaderTimeout default

    All HTTP servers now set ReadHeaderTimeout to 32s.

  • breakingPartial set and -object rule name conflicts

    The AST rejects partial set and -object rules that share a name.

Check if affected (2)

  • securityCompile API SQL identifier handling

    Applies if you use the Compile API and use a dynamic key.

  • breakingStricter := safety checking

    Applicability is not stated in the release notes.

Source
KubeVirtv1.9.0Orchestration & ManagementJul 30, 2026

A broad operator-facing release with fixes, behavior changes, new capabilities, API and feature-gate maturity changes, deprecations, and component updates. It also includes security updates for CVE-2026-35469, GHSA-pc3f-x583-g7j2, and CVE-2026-33186, along with a symlink-traversal fix and a security dependency update.

Action needed (2)

  • securitycriticalThe grpc dependency, updated

    grpc is updated to 1.79.3 to remediate CVE-2026-33186.

  • securityhighThe github.com/moby/spdystream dependency, updated

    The github.com/moby/spdystream dependency is updated from v0.5.0 to v0.5.1 to address CVE-2026-35469 (GHSA-pc3f-x583-g7j2).

Check if affected (9)

  • breakingStricter network interface binding admission

    Applies if you configure network interface bindings.

  • breakingThe Template feature gate, enabled by default

    Applies if you enable the Template feature gate.

  • breakingThe ephemeral hotplug volume metric and alert, removed

    Applies if you use the ephemeral hotplug volume metric.

  • + 6 more on the release page

Plan ahead (2)

  • deprecatedcgroup v1 support, deprecatedremoval date not announced

    Applies if you run with cgroup v1 support.

  • deprecatedLegacy VM creation recording rules and metrics, deprecated

    Applies if you use kubevirt_vm_created_total or kubevirt_vm_created_by_pod_total.

Source
Thanosv0.42.4ObservabilityJul 30, 2026

Thanos v0.42.4 contains no described operator-facing changes in the supplied release information. The available note is a duplicate mention.

Source
NATSv2.14.4Networking & MessagingJul 30, 2026

A maintenance release with dependency and toolchain updates, JetStream performance and configuration improvements, and broad correctness fixes. It also includes authentication and permission fixes.

Check if affected (4)

  • securityJWT validation with whitespace-only permissions

    Applies if you use JWT validation.

  • securityverify_and_map authentication with blank passwords

    Applies if TLS verify_and_map is configured.

  • securityMQTT subscription restriction for $MQTT.> subjects

    Applies if you use MQTT.

  • + 1 more on the release page
Source
NATSv2.12.14Networking & MessagingJul 30, 2026

A maintenance release with a Go toolchain update, dependency manifest updates, JetStream performance and configuration changes, and numerous correctness fixes. Authentication fixes address security flaws and require upgrading.

Action needed (1)

  • breakingThe disk concurrency semaphore, increased to 4096 slots

    The disk concurrency semaphore is now set to 4096 slots, up from the previous CPU-scaled count. This performance change ships in v2.12.14.

Check if affected (2)

  • securityAuthentication checks with no_auth_user and auth callouts

    Applies if you configure no_auth_user and use auth callouts.

  • securityTLS verify_and_map authentication with blank passwords

    Applies if you use TLS and configure verify_and_map.

Source
Prometheusv3.13.2ObservabilityJul 30, 2026

Prometheus v3.13.2 updates dependencies for two disclosed vulnerabilities and includes related transitive dependency upgrades. It also fixes a PromQL SIGBUS crash when the data disk is full.

Action needed (2)

  • securityhighgolang.org/x/text update for CVE-2026-56852

    golang.org/x/text updates from v0.38.0 to v0.39.0 in Prometheus v3.13.2 for CVE-2026-56852.

  • securityhighgoogle.golang.org/grpc update for GHSA-hrxh-6v49-42gf

    google.golang.org/grpc updates from v1.81.1 to v1.82.1 in Prometheus v3.13.2 for GHSA-hrxh-6v49-42gf.

Source
Tektonv1.6.6CI/CD & App DeliveryJul 30, 2026

This release contains an operator-facing defect correction. The remaining release-note content consists of headings, installation guidance, or attestation instructions rather than additional software changes.

Source
Volcanov1.15.1Orchestration & ManagementJul 30, 2026

Volcano v1.15.1 is a maintenance release with a dependency update, configuration-format compatibility changes, and correctness fixes. It also includes implementation-only changes with no operator-facing impact.

Action needed (1)

  • securityThe golang.org/x/crypto dependency, upgraded

    Volcano v1.15.1 upgrades golang.org/x/crypto from v0.49.0 to v0.53.0, incorporating upstream SSH security fixes released in v0.52.0.

Source
Volcanov1.14.4Orchestration & ManagementJul 30, 2026

Volcano v1.14.4 is a bug-fix release covering scheduler behavior, nil-pointer panics, job dependency readiness, allocation flow, and Ascend vNPU configuration and resource handling. No security advisories or security-specific flaws are identified.

Source
Backstagev1.53.1CI/CD & App DeliveryJul 29, 2026

Backstage v1.53.1 contains no operator-facing change details in the available release note. The release note provides only the version heading, so there are no documented changes to assess.

Source
← NewerOlder →
Browse by month