OPA v1.13.1 is a defect-fix release. It addresses a correctness issue in array. when processing single-item arrays.
Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
OPA v1.13.0 adds a Decision Logger upload mode and a Rego built-in while broadening built-in input support. It also includes runtime and compiler fixes, performance work, and dependency updates; no security advisories or vulnerabilities are disclosed.
Source ↗This release adds proxy support for the P256+SHA512 and P384+SHA512 cryptographic signature algorithms. It also updates the proxy and several build and development dependencies. No security advisory or explicitly exploitable vulnerability is disclosed.
A substantial feature and maintenance release with V2 Data Engine changes, new capabilities, dependency updates, numerous fixes, and hotfix image replacements. It also deprecates V2 Backing Image functionality and includes a fix for an SPDK v25.05 CVE issue without a disclosed advisory identifier.
Action needed (1)
securityThe
SPDK v25.CVE issue fix05 The CVE issue in
SPDK v25.is fixed in this release.05
Check if affected (7)
breakingThe
longhornio/longhorn-instance-manager:v1.image replacement11. 0 Applies if you use
longhornio/longhorn-instance-manager:v1..11. 0 breakingThe
longhornio/longhorn-manager:v1.image replacement11. 0 Applies if you use
longhornio/longhorn-manager:v1..11. 0 breakingBackupstore-related settings removal
Applies if you configure backupstore related settings.
- + 4 more on the release page
Plan ahead (2)
deprecatedBacking Image for the V2 Data Engine deprecationremoval planned in v1.12.0
Applies if you use Backing Image and the V2 Data Engine.
deprecatedV2 Backing Image Feature deprecation
Applies if you use the V2 Backing Image Feature.
This release adds configuration and observability capabilities while changing throttling and metric behavior. It also fixes correctness defects, including a described improper policy enforcement issue.
Action needed (2)
securitymediumThe CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9 policy enforcement fix
The release fixes improper policy enforcement associated with CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9.
breakingThe custom
grpc_codemetric label, removedThe custom
grpc_prometheusfork is replaced withgo-grpc-middleware's provider, and the customgrpc_codelabel is removed from the metric.
A release with a breaking observability change that replaces OpenCensus support with OpenTelemetry. It also fixes sub-second precision in metric reporting.
Check if affected (1)
breaking
OpenCensussupport removed in favor ofOpenTelemetryApplies if you use
OpenCensus.
A maintenance release that removes source-config-path output from release builds, deprecates several userspace interfaces, and rotates the package-signing key. It also includes correctness fixes, dependency updates, and an image-size reduction.
Check if affected (2)
breakingSource config path output in release builds
Applies if you use debug builds.
breakingGPG signing key for DEB/RPM packages, rotated
Applies if you use DEB/RPM packages.
Plan ahead (4)
deprecatedThe
--gvisor-generate-configCLI option, deprecatedApplies if you use
--gvisor-generate-config.deprecatedThe legacy eBPF probe, deprecated
Applies if you use the legacy eBPF probe.
deprecatedThe gVisor engine, deprecated
Applies if you use the gVisor engine.
- + 1 more on the release page
A maintenance release includes a hotfixed operator image, a security-relevant DNS query correction, and fixes across volume, replica, CSI, and management paths. It also adds namespace inheritance for longhorn-share-manager in FastFailover mode.
Check if affected (2)
securityThe
instance-managerDNS query behaviorApplies if you do not use a hard or solid state disk.
breakingThe
backing-image-manager:v1.image, replaced with10. 2 backing-image-manager:v1.10. 2-hotfix-1 Applies if you use
backing-image-manager:v1..10. 2
A maintenance release with security-related fixes for the Go toolchain and cross-namespace access through apiCall. It also contains ordinary defect fixes and capability or behavior changes.
Action needed (1)
securityThe
goversion update for standard library CVEsThe
goversion is updated to fix standard library CVEs in this release.
Check if affected (1)
securityCross-namespace access through
apiCallpreventedApplies if you use
apiCall.
NATS v2.12.4 is a maintenance release focused on correctness across JetStream, configuration, storage, clustering, and consumer behavior. It also updates the Go toolchain and adds TLS certificate expiry information to the varz monitoring endpoint; no security advisories or explicitly described security flaws are included.
NATS v2.11.12 is a maintenance release with WebSocket and monitoring configuration and output additions, along with JetStream and MQTT behavior and performance improvements. It also corrects a broad range of correctness issues; no security advisories or explicitly described security vulnerabilities are identified.
Source ↗A focused operator-facing release combining feature, compatibility, metrics, and defect fixes. The broader changelog is largely dependency housekeeping rather than additional operational changes.
Check if affected (3)
breakingThe
kn.metric, renamedqueueproxy. app. duration Applies if you use
kn..queueproxy. app. duration breakingThe
kn.metric, renamedqueueproxy. depth Applies if you use
kn..queueproxy. depth breakingService traffic ownership validation
Applicability is not stated in the release notes.
A maintenance release adds the AllowRootBounded secure-pod-defaults setting and fixes sub-second precision in metric reporting. The OpenCensus removal predates this release.
A release with operator-facing policy behavior changes. It includes namespace-based failure-action overrides, a context size limit, and tighter cross-namespace access controls for apiCall.
A maintenance release with two operator-relevant defect corrections. It makes issuer_url optional when configuring the client and corrects mutex handling by using write locks.
Keycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.
Action needed (3)
securitymediumCVE-2025-67735 in
netty-codec-httpCVE-2025-67735 addresses request smuggling via CRLF injection in
netty-codec-http. The fix ships in Keycloak 26.5.2.securitymediumCVE-2025-66560 in
io.quarkus/quarkus-rest CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in
io.. The fix ships in Keycloak 26.5.2.quarkus/quarkus-rest securitymediumCVE-2025-14559 in
keycloak-servicesCVE-2025-14559 addresses a business logic flaw in
keycloak-servicesthat allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.
A release that removes or deprecates several operator-facing components while adding capabilities and changing supported formats and behavior. It also updates shipped platform components, including Trustee, image-rs, guest kernels, and OVMF.
Check if affected (2)
breakingProcess-based confidential computing via
enclave-cc, removedApplies if you use
enclave-cc.breakingExperimental
Secure Comms mode, removed from the Cloud API AdaptorApplies if you configure
Secure Comms mode.
Plan ahead (2)
breakingThe
CoCo operator, deprecated, withHelm chartinstallationApplies if you use the
CoCo operator.deprecated
packerguest images, deprecated in favor ofmkosiremoval date not announcedApplies if you use
packer images.
A maintenance release that removes deprecated preheat API endpoints and fixes unauthenticated access to the Dragonfly manager job API. Both changes affect users of the corresponding APIs.
Check if affected (2)
securityDragonfly manager job API unauthenticated access fix
Applies if you use
Dragonfly manager job API.breakingDeprecated preheat API endpoints removed
Applies if you use
deprecated preheat API endpoints.
This release adds the inbound_http_statuses_total and inbound_grpc_statuses_total metrics for inbound HTTP and gRPC traffic. It also updates multiple dependencies and the proxy component to version v2.; no security advisories or security-specific fixes are disclosed.
Kubescape v3.0.48 is a maintenance release with metrics and reporting additions, workload-scan and panic fixes, and dependency updates. The release concerns users of the affected metrics, reporting, scanning, configuration, and signing components.
Source ↗Argo CD v3.2.6 is a maintenance release with operator-facing bug fixes and a dependency update. The remaining release-note entries are headings or documentation and release metadata rather than distinct operator-facing changes.
Source ↗Prometheus v3.5.1 contains dependency and toolchain version updates without code changes. The recorded release metadata does not describe security-related changes or operator actions beyond upgrading.
Source ↗A maintenance release with dependency and toolchain updates, several defect corrections, and a new repository timeout flag. The pkg/registry login option for passing TLS configuration in memory has been removed.
Action needed (1)
breakingThe
pkg/registryin-memory TLS configuration login option, removedThe
pkg/registrylogin option for passing TLS configuration in memory is reverted and does not ship in this release.
Helm v4.1.0 adds CLI and SDK capabilities and changes waiting and dependency behavior. It also corrects several defects and updates dependencies, with no security advisories or explicitly described vulnerabilities in the release information.
Source ↗Dapr v1.16.7 contains operator-facing bug fixes. It updates tracing for raw payload publishes, corrects file-based OAuth configuration with oauth2CredentialsFile, and fixes HTTPEndpoint initialization when only a root CA is configured.
A breaking release changes supported Kubernetes versions and configuration behavior and removes automatic CSI client creation in external mode. It also adds storage features, reconciliation improvements, and operational changes including experimental NVMe-oF support, block volume statistics, encryption settings, and improved fencing and logging.
Check if affected (4)
breakingSupported Kubernetes versions
Applies if you run Kubernetes
v1.through30 v1..35 breaking
activeStandbybehavior in theCephFilesystemCRDApplies if
activeStandbyis set tofalse.breakingCeph image settings in the
rook-ceph-clusterchartApplies if you use the
rook-ceph-clusterchart.- + 1 more on the release page
This release adds a Helm configuration field for custom service selector labels during revision-based migrations. It also fixes correctness issues in ambient mode, remote-cluster informer recovery, NFT operations, and pod deletion.
Source ↗Release v2.8.0 adds capabilities and metrics, corrects multiple defects, and updates dependencies. The nvidia-mig-parted upgrade addresses security issues.
Action needed (1)
securityThe
nvidia-mig-parteddependency, upgraded tov0.12. 2 HAMi v2.8.0 upgrades the
nvidia-mig-parteddependency tov0.to address security issues.12. 2
Strimzi 0.50.0 includes Java 21 adoption for the operators, with compatibility exceptions for several modules. It also changes connector plugin version configuration, so existing settings that use the rejected option are affected.
Check if affected (1)
breakingThe
connector.option, forbidden in connector configurationsplugin. version Applies if you use
connector.inplugin. version KafkaConnectorKafkaMirrorMaker2connector configuration.
A maintenance release with operator-facing bug fixes and a new HCCL rank job plugin. Changes cover scheduling, admission permissions, resource validation, job plugins, metrics, and pod handling; no security advisories or flaws are disclosed.
Source ↗Cloud Custodian 0.9.49.0 adds AWS and Azure resource support and expands policy filtering. It also changes behavior for several AWS resources, updates dependencies, and changes how c7n-left handles HCL errors. No security advisories or security-specific fixes are disclosed.
Source ↗This release adds installation and setup artifacts and fixes defects in RBAC permissions, portal refresh behavior, and experiment-name handling. No security advisories or security-specific flaws are disclosed.
Source ↗A security-focused maintenance release addresses disclosed Go vulnerabilities and improves proxy connection-pool performance. It also adds the forward plugin's max_idle_conns parameter, which defaults to 0 for an unbounded pool.
Action needed (1)
securityhighCVE-2025-68119 fix
The release also addresses CVE-2025-68119, which affects the stated Go versions.
Check if affected (1)
securitycriticalGo security vulnerability fixes
Applicability is not stated in the release notes.
A maintenance release focused on startup behavior, key disposal, JWT-SVID caching, and metric representation. It affects SPIRE Server on Windows, the aws_kms KeyManager plugin, cache handling, and the uptime_in_ms gauge.
TiKV v8.5.5 adds graceful shutdown and related configuration while changing how flow control interacts with RocksDB compaction thresholds. It also improves performance and resource behavior and fixes correctness issues in replication, metrics, recovery, snapshots, and Raft behavior; no security advisories or explicitly described vulnerabilities are present.
Source ↗Harbor v2.14.2 includes dependency and component updates alongside corrections to user-facing behavior. No security advisories or explicitly described vulnerabilities are present.
Source ↗Harbor v2.13.4 fixes an ORM mapping defect and updates Trivy-related components and base images. No security advisory or operator migration is described for this release.
Source ↗A maintenance release with fixes for warnings caused by removing subchart values and for release suspension when helm uninstall --keep-history is used. No security changes are disclosed.
Helm v4.0.5 is a correctness-fix release covering commands, plugins, dependency handling, watching, rollback, and SDK environment handling. The release also includes a new SDK environment exposure change.
Source ↗A maintenance release with fixes for configuration values that were misinterpreted or incorrectly assigned during reconfiguration. It addresses discovery polling intervals and decision log reporting buffer sizing, with no security issue or additional operator action stated.
Source ↗