RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Open Policy Agent (OPA)v1.13.0SecurityJan 29, 2026

OPA v1.13.0 adds a Decision Logger upload mode and a Rego built-in while broadening built-in input support. It also includes runtime and compiler fixes, performance work, and dependency updates; no security advisories or vulnerabilities are disclosed.

Source
Linkerdedge-26.1.4Networking & MessagingJan 29, 2026

This release adds proxy support for the P256+SHA512 and P384+SHA512 cryptographic signature algorithms. It also updates the proxy and several build and development dependencies. No security advisory or explicitly exploitable vulnerability is disclosed.

Source
Longhornv1.11.0Storage & DataJan 29, 2026

A substantial feature and maintenance release with V2 Data Engine changes, new capabilities, dependency updates, numerous fixes, and hotfix image replacements. It also deprecates V2 Backing Image functionality and includes a fix for an SPDK v25.05 CVE issue without a disclosed advisory identifier.

Action needed (1)

  • securityThe SPDK v25.05 CVE issue fix

    The CVE issue in SPDK v25.05 is fixed in this release.

Check if affected (7)

  • breakingThe longhornio/longhorn-instance-manager:v1.11.0 image replacement

    Applies if you use longhornio/longhorn-instance-manager:v1.11.0.

  • breakingThe longhornio/longhorn-manager:v1.11.0 image replacement

    Applies if you use longhornio/longhorn-manager:v1.11.0.

  • breakingBackupstore-related settings removal

    Applies if you configure backupstore related settings.

  • + 4 more on the release page

Plan ahead (2)

  • deprecatedBacking Image for the V2 Data Engine deprecationremoval planned in v1.12.0

    Applies if you use Backing Image and the V2 Data Engine.

  • deprecatedV2 Backing Image Feature deprecation

    Applies if you use the V2 Backing Image Feature.

Source
OpenFGAv1.11.3SecurityJan 28, 2026

This release adds configuration and observability capabilities while changing throttling and metric behavior. It also fixes correctness defects, including a described improper policy enforcement issue.

Action needed (2)

  • securitymediumThe CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9 policy enforcement fix

    The release fixes improper policy enforcement associated with CVE-2026-24851 and GHSA-jq9f-gm9w-rwm9.

  • breakingThe custom grpc_code metric label, removed

    The custom grpc_prometheus fork is replaced with go-grpc-middleware's provider, and the custom grpc_code label is removed from the metric.

Source
Knativeknative-v1.19.9Orchestration & ManagementJan 28, 2026

A release with a breaking observability change that replaces OpenCensus support with OpenTelemetry. It also fixes sub-second precision in metric reporting.

Check if affected (1)

  • breakingOpenCensus support removed in favor of OpenTelemetry

    Applies if you use OpenCensus.

Source
Falco0.43.0SecurityJan 28, 2026

A maintenance release that removes source-config-path output from release builds, deprecates several userspace interfaces, and rotates the package-signing key. It also includes correctness fixes, dependency updates, and an image-size reduction.

Check if affected (2)

  • breakingSource config path output in release builds

    Applies if you use debug builds.

  • breakingGPG signing key for DEB/RPM packages, rotated

    Applies if you use DEB/RPM packages.

Plan ahead (4)

  • deprecatedThe --gvisor-generate-config CLI option, deprecated

    Applies if you use --gvisor-generate-config.

  • deprecatedThe legacy eBPF probe, deprecated

    Applies if you use the legacy eBPF probe.

  • deprecatedThe gVisor engine, deprecated

    Applies if you use the gVisor engine.

  • + 1 more on the release page
Source
Longhornv1.10.2Storage & DataJan 28, 2026

A maintenance release includes a hotfixed operator image, a security-relevant DNS query correction, and fixes across volume, replica, CSI, and management paths. It also adds namespace inheritance for longhorn-share-manager in FastFailover mode.

Check if affected (2)

  • securityThe instance-manager DNS query behavior

    Applies if you do not use a hard or solid state disk.

  • breakingThe backing-image-manager:v1.10.2 image, replaced with backing-image-manager:v1.10.2-hotfix-1

    Applies if you use backing-image-manager:v1.10.2.

Source
Kyvernov1.15.3SecurityJan 27, 2026

A maintenance release with security-related fixes for the Go toolchain and cross-namespace access through apiCall. It also contains ordinary defect fixes and capability or behavior changes.

Action needed (1)

  • securityThe go version update for standard library CVEs

    The go version is updated to fix standard library CVEs in this release.

Check if affected (1)

  • securityCross-namespace access through apiCall prevented

    Applies if you use apiCall.

Source
NATSv2.12.4Networking & MessagingJan 27, 2026

NATS v2.12.4 is a maintenance release focused on correctness across JetStream, configuration, storage, clustering, and consumer behavior. It also updates the Go toolchain and adds TLS certificate expiry information to the varz monitoring endpoint; no security advisories or explicitly described security flaws are included.

Source
NATSv2.11.12Networking & MessagingJan 27, 2026

NATS v2.11.12 is a maintenance release with WebSocket and monitoring configuration and output additions, along with JetStream and MQTT behavior and performance improvements. It also corrects a broad range of correctness issues; no security advisories or explicitly described security vulnerabilities are identified.

Source
Knativeknative-v1.21.0Orchestration & ManagementJan 27, 2026

A focused operator-facing release combining feature, compatibility, metrics, and defect fixes. The broader changelog is largely dependency housekeeping rather than additional operational changes.

Check if affected (3)

  • breakingThe kn.queueproxy.app.duration metric, renamed

    Applies if you use kn.queueproxy.app.duration.

  • breakingThe kn.queueproxy.depth metric, renamed

    Applies if you use kn.queueproxy.depth.

  • breakingService traffic ownership validation

    Applicability is not stated in the release notes.

Source
Knativeknative-v1.20.2Orchestration & ManagementJan 27, 2026

A maintenance release adds the AllowRootBounded secure-pod-defaults setting and fixes sub-second precision in metric reporting. The OpenCensus removal predates this release.

Source
Kyvernov1.16.3SecurityJan 27, 2026

A release with operator-facing policy behavior changes. It includes namespace-based failure-action overrides, a context size limit, and tighter cross-namespace access controls for apiCall.

Source
Daprv1.16.8Orchestration & ManagementJan 26, 2026

A maintenance release with two operator-relevant defect corrections. It makes issuer_url optional when configuring the client and corrects mutex handling by using write locks.

Source
Keycloak26.5.2SecurityJan 23, 2026

Keycloak 26.5.2 is a maintenance release with security fixes alongside ordinary bug fixes and enhancements. The security updates affect third-party dependencies and Keycloak's token issuance logic.

Action needed (3)

  • securitymediumCVE-2025-67735 in netty-codec-http

    CVE-2025-67735 addresses request smuggling via CRLF injection in netty-codec-http. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-66560 in io.quarkus/quarkus-rest

    CVE-2025-66560 addresses the Quarkus REST worker thread exhaustion vulnerability in io.quarkus/quarkus-rest. The fix ships in Keycloak 26.5.2.

  • securitymediumCVE-2025-14559 in keycloak-services

    CVE-2025-14559 addresses a business logic flaw in keycloak-services that allowed unauthorized token issuance for disabled users. The fix ships in Keycloak 26.5.2.

Source
Confidential Containersv0.18.0SecurityJan 23, 2026

A release that removes or deprecates several operator-facing components while adding capabilities and changing supported formats and behavior. It also updates shipped platform components, including Trustee, image-rs, guest kernels, and OVMF.

Check if affected (2)

  • breakingProcess-based confidential computing via enclave-cc, removed

    Applies if you use enclave-cc.

  • breakingExperimental Secure Comms mode, removed from the Cloud API Adaptor

    Applies if you configure Secure Comms mode.

Plan ahead (2)

  • breakingThe CoCo operator, deprecated, with Helm chart installation

    Applies if you use the CoCo operator.

  • deprecatedpacker guest images, deprecated in favor of mkosiremoval date not announced

    Applies if you use packer images.

Source
Dragonflyv2.4.1Storage & DataJan 23, 2026

A maintenance release that removes deprecated preheat API endpoints and fixes unauthenticated access to the Dragonfly manager job API. Both changes affect users of the corresponding APIs.

Check if affected (2)

  • securityDragonfly manager job API unauthenticated access fix

    Applies if you use Dragonfly manager job API.

  • breakingDeprecated preheat API endpoints removed

    Applies if you use deprecated preheat API endpoints.

Source
Linkerdedge-26.1.3Networking & MessagingJan 23, 2026

This release adds the inbound_http_statuses_total and inbound_grpc_statuses_total metrics for inbound HTTP and gRPC traffic. It also updates multiple dependencies and the proxy component to version v2.337.0; no security advisories or security-specific fixes are disclosed.

Source
Kubescapev3.0.48SecurityJan 22, 2026

Kubescape v3.0.48 is a maintenance release with metrics and reporting additions, workload-scan and panic fixes, and dependency updates. The release concerns users of the affected metrics, reporting, scanning, configuration, and signing components.

Source
Argov3.2.6CI/CD & App DeliveryJan 22, 2026

Argo CD v3.2.6 is a maintenance release with operator-facing bug fixes and a dependency update. The remaining release-note entries are headings or documentation and release metadata rather than distinct operator-facing changes.

Source
Prometheusv3.5.1ObservabilityJan 22, 2026

Prometheus v3.5.1 contains dependency and toolchain version updates without code changes. The recorded release metadata does not describe security-related changes or operator actions beyond upgrading.

Source
Helmv3.20.0Kubernetes CoreJan 21, 2026

A maintenance release with dependency and toolchain updates, several defect corrections, and a new repository timeout flag. The pkg/registry login option for passing TLS configuration in memory has been removed.

Action needed (1)

  • breakingThe pkg/registry in-memory TLS configuration login option, removed

    The pkg/registry login option for passing TLS configuration in memory is reverted and does not ship in this release.

Source
Helmv4.1.0Kubernetes CoreJan 21, 2026

Helm v4.1.0 adds CLI and SDK capabilities and changes waiting and dependency behavior. It also corrects several defects and updates dependencies, with no security advisories or explicitly described vulnerabilities in the release information.

Source
Daprv1.16.7Orchestration & ManagementJan 20, 2026

Dapr v1.16.7 contains operator-facing bug fixes. It updates tracing for raw payload publishes, corrects file-based OAuth configuration with oauth2CredentialsFile, and fixes HTTPEndpoint initialization when only a root CA is configured.

Source
Rookv1.19.0Storage & DataJan 20, 2026

A breaking release changes supported Kubernetes versions and configuration behavior and removes automatic CSI client creation in external mode. It also adds storage features, reconciliation improvements, and operational changes including experimental NVMe-oF support, block volume statistics, encryption settings, and improved fencing and logging.

Check if affected (4)

  • breakingSupported Kubernetes versions

    Applies if you run Kubernetes v1.30 through v1.35.

  • breakingactiveStandby behavior in the CephFilesystem CRD

    Applies if activeStandby is set to false.

  • breakingCeph image settings in the rook-ceph-cluster chart

    Applies if you use the rook-ceph-cluster chart.

  • + 1 more on the release page
Source
Istio1.28.3Networking & MessagingJan 20, 2026

This release adds a Helm configuration field for custom service selector labels during revision-based migrations. It also fixes correctness issues in ambient mode, remote-cluster informer recovery, NFT operations, and pod deletion.

Source
hamiv2.8.0AI & MLJan 20, 2026

Release v2.8.0 adds capabilities and metrics, corrects multiple defects, and updates dependencies. The nvidia-mig-parted upgrade addresses security issues.

Action needed (1)

  • securityThe nvidia-mig-parted dependency, upgraded to v0.12.2

    HAMi v2.8.0 upgrades the nvidia-mig-parted dependency to v0.12.2 to address security issues.

Source
Strimzi0.50.0Networking & MessagingJan 18, 2026

Strimzi 0.50.0 includes Java 21 adoption for the operators, with compatibility exceptions for several modules. It also changes connector plugin version configuration, so existing settings that use the rejected option are affected.

Check if affected (1)

  • breakingThe connector.plugin.version option, forbidden in connector configurations

    Applies if you use connector.plugin.version in KafkaConnect or KafkaMirrorMaker2 connector configuration.

Source
Volcanov1.12.3Orchestration & ManagementJan 18, 2026

A maintenance release with operator-facing bug fixes and a new HCCL rank job plugin. Changes cover scheduling, admission permissions, resource validation, job plugins, metrics, and pod handling; no security advisories or flaws are disclosed.

Source
Cloud Custodian0.9.49.0SecurityJan 16, 2026

Cloud Custodian 0.9.49.0 adds AWS and Azure resource support and expands policy filtering. It also changes behavior for several AWS resources, updates dependencies, and changes how c7n-left handles HCL errors. No security advisories or security-specific fixes are disclosed.

Source
Litmus3.25.0ObservabilityJan 16, 2026

This release adds installation and setup artifacts and fixes defects in RBAC permissions, portal refresh behavior, and experiment-name handling. No security advisories or security-specific flaws are disclosed.

Source
CoreDNSv1.14.1Kubernetes CoreJan 16, 2026

A security-focused maintenance release addresses disclosed Go vulnerabilities and improves proxy connection-pool performance. It also adds the forward plugin's max_idle_conns parameter, which defaults to 0 for an unbounded pool.

Action needed (1)

  • securityhighCVE-2025-68119 fix

    The release also addresses CVE-2025-68119, which affects the stated Go versions.

Check if affected (1)

  • securitycriticalGo security vulnerability fixes

    Applicability is not stated in the release notes.

Source
SPIREv1.14.1SecurityJan 15, 2026

A maintenance release focused on startup behavior, key disposal, JWT-SVID caching, and metric representation. It affects SPIRE Server on Windows, the aws_kms KeyManager plugin, cache handling, and the uptime_in_ms gauge.

Source
TiKVv8.5.5Storage & DataJan 15, 2026

TiKV v8.5.5 adds graceful shutdown and related configuration while changing how flow control interacts with RocksDB compaction thresholds. It also improves performance and resource behavior and fixes correctness issues in replication, metrics, recovery, snapshots, and Raft behavior; no security advisories or explicitly described vulnerabilities are present.

Source
Harborv2.14.2Storage & DataJan 15, 2026

Harbor v2.14.2 includes dependency and component updates alongside corrections to user-facing behavior. No security advisories or explicitly described vulnerabilities are present.

Source
Harborv2.13.4Storage & DataJan 15, 2026

Harbor v2.13.4 fixes an ORM mapping defect and updates Trivy-related components and base images. No security advisory or operator migration is described for this release.

Source
Helmv3.19.5Kubernetes CoreJan 15, 2026

A maintenance release with fixes for warnings caused by removing subchart values and for release suspension when helm uninstall --keep-history is used. No security changes are disclosed.

Source
Helmv4.0.5Kubernetes CoreJan 14, 2026

Helm v4.0.5 is a correctness-fix release covering commands, plugins, dependency handling, watching, rollback, and SDK environment handling. The release also includes a new SDK environment exposure change.

Source
Open Policy Agent (OPA)v1.12.3SecurityJan 14, 2026

A maintenance release with fixes for configuration values that were misinterpreted or incorrectly assigned during reconfiguration. It addresses discovery polling intervals and decision log reporting buffer sizing, with no security issue or additional operator action stated.

Source
← NewerOlder →
Browse by month