RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Thanosv0.41.0ObservabilityFeb 12, 2026

This release combines performance improvements, bug fixes, and new configuration capabilities with a shuffle-sharding behavior change in Receive. It also upgrades Prometheus, deprecates a flag, and makes native histogram ingestion always enabled.

Check if affected (1)

  • breakingReceive shuffle sharding now uses consistent hashing

    Applies if you use Receive.

Source
OpenFGAv1.11.5SecurityFeb 11, 2026

This release includes an operator-facing toolchain update. The change addresses CVE-2025-68121 in OpenFGA v1.11.5.

Action needed (1)

  • securitycriticalThe Go toolchain, updated to 1.25.7

    The Go toolchain is updated to 1.25.7 in OpenFGA v1.11.5 to address CVE-2025-68121.

Source
Vitessv23.0.2Storage & DataFeb 10, 2026

Vitess v23.0.2 is a maintenance release focused on defect corrections and a Go toolchain dependency update. The release also includes a performance-related change in query execution.

Source
Kubernetesv1.32.12Kubernetes CoreFeb 10, 2026

A maintenance release with correctness fixes in device allocation and kubeadm behavior, plus a Go toolchain update. The changes address scheduling races, etcd learner promotion, argument ordering, and Node patch retries.

Source
Kubernetesv1.33.8Kubernetes CoreFeb 10, 2026

A maintenance release corrects operator-relevant behavior across scheduling, kubeadm, logging, and Windows networking. Kubernetes is now built using Go 1.24.12, and no security advisories or security-specific fixes are disclosed.

Source
Kubernetesv1.34.4Kubernetes CoreFeb 10, 2026

A maintenance release focused on correctness fixes and regression repairs across Kubernetes components. It also updates the Go toolchain and changes kubeadm retry behavior.

Source
Kubernetesv1.35.1Kubernetes CoreFeb 10, 2026

A maintenance release with numerous correctness fixes and an enforced feature-gate default change. It also updates the Go toolchain and hnslib dependency, with no disclosed security advisories.

Check if affected (1)

  • breakingThe SchedulerAsyncAPICalls feature gate, disabled by default

    Applies if you use the SchedulerAsyncAPICalls feature gate.

Source
OpenFGAv1.11.4SecurityFeb 10, 2026

OpenFGA v1.11.4 fixes a planner regression in specific scenarios and updates the OpenTelemetry SDK. The SDK change addresses a disclosed issue affecting earlier versions.

Action needed (1)

  • securityThe otel/sdk dependency at v1.40.0

    The otel/sdk dependency is upgraded to v1.40.0 in OpenFGA v1.11.4 to address the issue identified as SNYK-GOLANG-GOOPENTELEMETRYIOOTELSDKRESOURCE-15182758 in earlier versions.

Source
Istio1.27.6Networking & MessagingFeb 10, 2026

This release includes security safeguards for gateway resource creation and pod specification rendering, along with stricter authorization for debug endpoints. It also adds a Helm configuration field and corrects a TLS configuration mapping.

Action needed (1)

  • securityResource annotation validation

    Resource annotation validation now rejects newline and control characters that could inject containers into pod specifications through template rendering.

Check if affected (2)

  • securityGateway deployment controller resource validation

    Applies if the gateway deployment controller runs.

  • breakingNamespace-based authorization for debug endpoints

    Applies if you use debug endpoints on port 15014.

Source
Keycloak26.5.3SecurityFeb 10, 2026

A maintenance release focused on security fixes, with additional ordinary bug corrections. It also includes startup-memory corrections and a removal related to that area.

Action needed (4)

  • securityhighCVE-2026-1609, disabled users obtaining tokens through the JWT Authorization Grant

    Keycloak 26.5.3 fixes an issue where disabled users could still obtain tokens through the JWT Authorization Grant.

  • securityhighCVE-2026-1529, forged invitation JWT enabling cross-organization self-registration

    Keycloak 26.5.3 fixes an issue where a forged invitation JWT could enable self-registration across organizations.

  • securityhighCVE-2026-1486, authentication through disabled identity providers

    Keycloak 26.5.3 fixes a logic bypass in the JWT Authorization Grant that allowed authentication through disabled identity providers.

  • securitymediumCVE-2025-14778, incorrect ownership checks in /uma-policy/

    Keycloak 26.5.3 fixes incorrect ownership checks in the /uma-policy/ endpoint.

Source
OpenCostv1.119.2ObservabilityFeb 9, 2026

OpenCost v1.119.2 contains operator-facing fixes, configuration and cloud-integration changes, logging updates, and third-party dependency upgrades. No security advisories or explicit vulnerability disclosures are present.

Source
Helmv4.1.1Kubernetes CoreFeb 9, 2026

Helm v4.1.1 is a correctness-fix release. The recorded note tail points to fixes for waiting context options, failed-resource handling in kstatus, resource matching behavior, and nil elements during slice copying.

Source
Jaegerv2.15.1ObservabilityFeb 9, 2026

This release removes a deprecated v1 adapter wrapper and changes the default span kind in API v3 operations. The remaining release notes do not describe distinct operator-facing changes.

Action needed (1)

  • breakingDeprecated protofromtraces wrapper removal

    The deprecated protofromtraces wrapper has been removed from v1adapter.

Source
k8gbv0.18.0Kubernetes CoreFeb 7, 2026

k8gb v0.18.0 adds runtime filtering and a Prometheus metric, and corrects several GSLB and DNS behaviors. It also updates dependencies and packaging and adds support features, while CI-only security-pipeline and workflow changes are not operator-facing security fixes.

Source
Jaegerv2.15.0ObservabilityFeb 6, 2026

Jaeger v2.15.0 introduces a breaking constraint for trace and metric storage configuration. It also adds experimental MCP and ClickHouse capabilities, corrects API behavior, and includes an internal implementation change without direct operator impact.

Check if affected (1)

  • breakingTrace and metric storage configuration backend constraint

    Applies if you configure trace or metric storage with more than one backend type.

Source
Rookv1.19.1Storage & DataFeb 5, 2026

A maintenance release with operator-facing removals, default and behavior changes, new CRD fields, expanded configuration support, and dependency updates. No security advisory is disclosed.

Action needed (1)

  • breakingNodes/proxy RBAC enablement removal

    The unnecessary nodes/proxy RBAC enablement is removed.

Check if affected (2)

  • breakingDefault Ceph image pull policy

    Applies if you do not configure ceph image pull policy.

  • breakingAutomated node fencing code removal

    Applies if automated node fencing runs.

Source
wasmCloudwash-v0.43.0Orchestration & ManagementFeb 4, 2026

This release contains no described operator-facing changes. The available release note content consists only of headings and a duplicated release-bot entry.

Source
wasmCloudv1.9.2Orchestration & ManagementFeb 4, 2026

This release changes NATS connection authentication and the component spec feature. Dependency and OCI image base updates are also included.

Action needed (1)

  • breakingThe component spec feature, removed

    The component spec feature is removed in this release.

Source
Vitessv23.0.1Storage & DataFeb 4, 2026

Vitess v23.0.1 is a maintenance release focused on bug fixes and behavior corrections. It also adds CLI and TabletManager capabilities and updates dependencies.

Action needed (1)

  • securityThe golang.org/x/crypto dependency, updated

    Vitess v23.0.1 updates golang.org/x/crypto from 0.42.0 to 0.45.0.

Source
gRPCv1.78.0Networking & MessagingFeb 4, 2026

A maintenance release with defect fixes and compatibility updates across the language integrations, plus changes to Python packaging and logging.

Source
Kubescapev4.0.0SecurityFeb 4, 2026

Kubescape v4.0.0 expands operator capabilities while changing sensing architecture and scan output behavior. It also updates a dependency, improves scan performance, and includes a fix for version handling and injection.

Action needed (1)

  • securityVersion handling and injection fix

    The release fixes version handling and injection in Kubescape v4.0.0.

Source
Vitessv22.0.3Storage & DataFeb 4, 2026

Vitess v22.0.3 is a maintenance release focused on correctness across query serving, replication, tablet management, and orchestration. It also adds new vtbench credential and DemotePrimary force flags and upgrades the Go toolchain; no security fixes are described.

Source
Ciliumv1.19.0Networking & MessagingFeb 4, 2026

A substantial operator-facing feature and maintenance release with new DNS proxy, installation, configuration, API, metric, and datapath capabilities. It also changes defaults and compatibility requirements, removes deprecated interfaces, migrates BGP APIs, and updates security-related dependencies.

Action needed (15)

  • securityThe github.com/containerd/containerd dependency, updated

    The github.com/containerd/containerd module is updated to v1.7.29.

  • securityThe github.com/go-viper/mapstructure/v2 dependency, updated

    The github.com/go-viper/mapstructure/v2 module is updated to v2.4.0.

  • securityThe github.com/docker/docker dependency, updated

    The github.com/docker/docker module is updated to v28.3.3+incompatible.

  • securityThe golang.org/x/crypto dependency, updated

    The golang.org/x/crypto module is updated to v0.45.0.

  • securityThe helm.sh/helm/v3 dependency, updated to v3.18.4

    The helm.sh/helm/v3 module is updated to v3.18.4.

  • securityThe helm.sh/helm/v3 dependency, updated to v3.18.5

    The helm.sh/helm/v3 module is updated to v3.18.5.

  • breakingThe plpmtud default, set to blackhole

    The default plpmtud mode is now blackhole (blackhole-detected).

  • breakingThe AddressScopeMax default, set to 254

    The default AddressScopeMax is changed to 254, the host scope, for GKE metadata server and HCP use cases. The related setting is --local-max-addr-scope.

  • breakingThe tls authMode default, set to migration

    tls authMode is set to migration by default.

  • breakingThe CNI deletion timeout, reduced to 1.5 seconds

    The CNI deletion timeout is reduced to 1.5 seconds.

  • breakingThe policy-default-local-cluster default

    policy-default-local-cluster is now set by default.

  • breakingHost firewall bypass, disabled by default

    Host firewall bypass is disabled by default.

  • breakingFQDN match pattern sanitization

    FQDN match pattern sanitization is refactored and tightened.

  • breakingEncrypted traffic forwarding via cilium_host, removed

    Forwarding encrypted traffic via cilium_host has been removed.

  • breakingCNI configuration in the container image, removed

    The CNI configuration is no longer installed in the container image.

Check if affected (30)

  • breakingLocal-cluster default for network policy selectors

    Applies if you do not set cluster in network policy selectors.

  • breakingThe CiliumBGPPeeringPolicy v1 API, removed

    Applies if you use CiliumBGPPeeringPolicy.

  • breakingMutual Authentication, disabled by default

    Applies if you enable Mutual Authentication.

  • + 27 more on the release page

Plan ahead (7)

  • deprecated--enable-ipsec-encrypted-overlay, deprecatedremoval date not announced

    Applies if you use --enable-ipsec-encrypted-overlay.

  • deprecatedKafka match fields and ToRequires and FromRequires, deprecated

    Applies if you use ToRequires or FromRequires.

  • deprecatedTLS certificate and key Helm values, deprecated

    Applies if you pass TLS certificates or keys in Helm values.

  • + 4 more on the release page
Source
CRI-Ov1.32.13Kubernetes CoreFeb 4, 2026

This release contains an operator-facing bug fix for container SELinux labeling. Systemd and init containers now respect a user-specified SELinux label.

Source
Crossplanev2.1.4Orchestration & ManagementFeb 3, 2026

Crossplane v2.1.4 is a maintenance release with security-related dependency updates. It also includes corrections for shared transitive dependency upgrades, so the release concerns operators tracking dependency and security fixes.

Action needed (4)

  • securityThe github.com/quic-go/quic-go module, updated to v0.57.0

    The release updates the github.com/quic-go/quic-go module to v0.57.0 as a security-related dependency change.

  • securitysigstore dependency updates for CVEs

    The release updates sigstore dependencies to fix CVEs.

  • securityThe github.com/theupdateframework/go-tuf/v2 module, updated to v2.4.1

    The release updates the github.com/theupdateframework/go-tuf/v2 module to v2.4.1 as a security-related dependency change.

  • securityThe github.com/go-chi/chi/v5 module, updated to v5.2.4

    The release updates the github.com/go-chi/chi/v5 module to v5.2.4 as a security-related dependency change.

Source
Crossplanev2.0.7Orchestration & ManagementFeb 3, 2026

This release updates a security-related dependency and corrects shared transitive dependency upgrades. It also fixes propagation of composite identity through nested XR trees.

Action needed (1)

  • securityThe github.com/theupdateframework/go-tuf/v2 dependency, updated to v2.4.1

    The github.com/theupdateframework/go-tuf/v2 module is updated to v2.4.1 in the release-2.0 branch.

Source
Crossplanev1.20.5Orchestration & ManagementFeb 3, 2026

Crossplane v1.20.5 is a maintenance release focused on dependency updates. It includes a security-related update to sigstore dependencies and addresses a defect in shared transitive dependency upgrades.

Action needed (1)

  • securityThe sigstore dependencies, updated for CVE fixes

    The release-1.20 branch updates sigstore dependencies to fix CVEs.

Source
CRI-Ov1.34.5Kubernetes CoreFeb 3, 2026

A maintenance release includes a fix for high performance hook IRQ SMP affinity handling during late container deletion. The fix prevents IRQ SMP affinity for other containers from being changed incorrectly.

Source
CRI-Ov1.33.9Kubernetes CoreFeb 3, 2026

This release contains no described operator-facing changes. No recorded release-note items indicate changes to configuration, interfaces, or operational behavior.

Source
Backstagev1.46.5CI/CD & App DeliveryFeb 2, 2026

This is a maintenance release with security fixes backported from v1.47.3. The fixes affect operators using the v1.46.5 release line.

Action needed (1)

  • securityBackported security fixes from v1.47.3

    This release contains backported security fixes from v1.47.3.

Source
Backstagev1.47.3CI/CD & App DeliveryFeb 2, 2026

A security-focused release with fixes for the TechDocs Node plugin. The release is relevant to deployments that use @backstage/plugin-techdocs-node.

Check if affected (1)

  • securitySecurity fixes for @backstage/plugin-techdocs-node

    Applies if you use @backstage/plugin-techdocs-node.

Source
cert-managerv1.18.5SecurityFeb 2, 2026

cert-manager v1.18.5 contains a security fix for GHSA-gx3x-vq4p-mhhv alongside other bug fixes. It also adds IPv6 HTTP-01 support and updates the Go toolchain.

Action needed (1)

  • securitymediumGHSA-gx3x-vq4p-mhhv denial-of-service fix

    cert-manager v1.18.5 fixes the denial-of-service issue identified by GHSA-gx3x-vq4p-mhhv. The release contains three bug fixes in total.

Source
cert-managerv1.19.3SecurityFeb 2, 2026

A maintenance release with a security fix in the cert-manager controller, along with routine bug fixes and a Go toolchain dependency update. The security fix addresses a DNS response handling issue that could cause controller denial of service.

Check if affected (1)

  • securitymediumcert-manager controller DNS response panic fix, GHSA-gx3x-vq4p-mhhv

    Applicability is not stated in the release notes.

Source
Kyvernov1.17.0SecurityFeb 2, 2026

A substantial feature and maintenance release adds CEL and policy capabilities while correcting controller and API defects. It also includes security fixes, including a kubectl image update for CVEs, along with dependency and integration changes.

Action needed (2)

  • securitySecurity vulnerabilities addressed

    Security vulnerabilities are addressed in this release.

  • securityUpdated kubectl image for CVE fixes

    The kubectl image is updated to address CVEs in this release.

Check if affected (2)

  • breakingRestricted resource access in namespaced CEL policy types

    Applies if you use namespaced CEL policy types.

  • breakingOpt-in VAP/MAP reporting

    Applies if you use VAP/MAP reporting.

Source
KEDAv2.19.0Orchestration & ManagementFeb 2, 2026

A feature and maintenance release that adds scaler and authentication capabilities, updates scaler behavior and status reporting, and corrects several defects. It also replaces a deprecated dependency and removes the NATS Streaming scaler.

Check if affected (1)

  • breakingThe NATS Streaming scaler, removed

    Applies if you use the NATS Streaming scaler.

Source
Argov3.3.0CI/CD & App DeliveryFeb 2, 2026

Argo v3.3.0 is a substantial feature and maintenance release with changes across synchronization, health, hydration, diff and apply behavior, the UI, and resource operations. It also updates core dependencies and removes an app controller flag.

Action needed (3)

  • securityThe k8s.io/kubernetes module, updated to v1.34.2

    The k8s.io/kubernetes module is updated to v1.34.2 in Argo v3.3.0.

  • securityHelm 3.19.4

    Helm is updated to 3.19.4 in Argo v3.3.0.

  • securityRedis, updated to the latest stable release

    Redis is updated to the latest stable release in Argo v3.3.0.

Check if affected (1)

  • breakingThe --self-heal-backoff-cooldown-seconds flag, removed

    Applies if your app controller configuration uses --self-heal-backoff-cooldown-seconds.

Source
Karmadav1.16.2Orchestration & ManagementJan 31, 2026

Karmada v1.16.2 is a maintenance release with operator-relevant bug fixes. The remaining release entries are headings without recorded change details.

Source
Karmadav1.15.5Orchestration & ManagementJan 31, 2026

Karmada v1.15.5 is a focused maintenance release with two operator-relevant bug fixes. It contains no described security advisories or security-specific fixes.

Source
Karmadav1.14.9Orchestration & ManagementJan 31, 2026

Karmada v1.14.9 is a maintenance release with an operator-facing bug fix. The recorded change addresses a policy deletion issue involving selectors for non-existent resources.

Source
Volcanov1.14.0Orchestration & ManagementJan 31, 2026

Volcano v1.14.0 is a substantial feature and maintenance release with new scheduling, topology, colocation, accelerator, API, and integration capabilities, alongside fixes for correctness and stability issues. No security advisories or explicitly described vulnerabilities are noted.

Source
← NewerOlder →
Browse by month