RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Keycloak26.5.1SecurityJan 14, 2026

Keycloak 26.5.1 is a maintenance release with a security fix in the Organization feature. It also contains correctness fixes, a performance improvement, and changes to HTTP responses and realm administration.

Check if affected (1)

  • securityThe Organization feature account-name exposure fix

    Applies if you use the Organization feature.

Source
Linkerdedge-26.1.2Networking & MessagingJan 14, 2026

A maintenance release with dependency and component updates plus a correctness fix in the policy controller. Resource watches now log and skip events that cannot be deserialized so the watch can continue.

Source
Ciliumv1.18.6Networking & MessagingJan 13, 2026

A maintenance release with fixes for networking, policy, proxy, gateway API, and endpoint handling, plus dependency, image, and OCI publishing updates. The Cilium Preflight check no longer includes Envoy Configmaps.

Action needed (1)

  • breakingCilium Preflight check no longer includes Envoy Configmaps

    The Cilium Preflight check no longer includes Envoy Configmaps. This change ships in v1.18.6.

Source
Rookv1.18.9Storage & DataJan 13, 2026

Rook v1.18.9 includes operator-facing behavior changes, new configuration capabilities, a corrected CSI behavior, and expanded CRD validation. No security advisories are disclosed.

Source
Envoyv1.37.0Networking & MessagingJan 13, 2026

This release adds dynamic-module, filter, routing, observability, and certificate capabilities, along with fixes and performance improvements across HTTP, networking, and protocol handling. It also changes HTTP reset behavior, removes runtime guards and legacy code paths, and deprecates the OpenTelemetry access log common_config field.

Action needed (1)

  • breakingRuntime guards and legacy code paths removed

    Multiple runtime guards and legacy code paths are removed in this release.

Check if affected (2)

  • breakingDefault HTTP reset code changed

    Applicability is not stated in the release notes.

  • breakingDefault upstream protocol error reset handling changed

    Applicability is not stated in the release notes.

Plan ahead (1)

  • deprecatedOpenTelemetry access log common_config field deprecated

    Applies if you configure common_config.

Source
Dragonflyv2.4.0Storage & DataJan 12, 2026

Dragonfly v2.4.0 adds scheduling, transfer, preheating, download, and configuration capabilities. It also improves performance and fixes several correctness issues, with no security advisories or explicitly described security flaws present.

Source
Daprv1.16.6Orchestration & ManagementJan 9, 2026

A maintenance release focused on operator-visible correctness and runtime behavior. It tightens UID checks and startup and sidecar-injection reporting, including success metrics only when an actual patch is generated.

Source
Kyvernov1.16.2SecurityJan 9, 2026

A maintenance release with a corrected metric compatibility issue, changes to performance and metric output, and a cleanup-controller fix. It also includes cherry-pick pointers and release-management updates.

Source
Linkerdedge-26.1.1Networking & MessagingJan 9, 2026

Linkerd edge-26.1.1 contains dependency, toolchain, CI action, and proxy version updates. No security advisories or operator-facing functional changes are disclosed.

Source
CoreDNSv1.14.0Kubernetes CoreJan 8, 2026

A maintenance release with a new regex length constraint, correctness fixes, and plugin capability and behavior changes. It does not disclose a security advisory or explicitly exploitable vulnerability.

Action needed (1)

  • breakingThe core regex length limit

    core adds a length limit for regular expressions.

Source
Prometheusv3.9.0ObservabilityJan 7, 2026

This release updates histogram collection and TSDB behavior while adding capabilities across the API, PromQL, storage, and UI. It also includes fixes for query handling, storage validation, receivers, and interface behavior.

Action needed (1)

  • breakingA 10,000-set limit for the TSDB status endpoint

    The TSDB status endpoint now limits responses to a maximum of 10,000 sets of statistics.

Check if affected (1)

  • breakingThe native-histogram feature flag has no effect

    Applies if you set scrape_native_histograms to collect Native Histogram samples from exporters.

Source
OpenCostv1.119.1ObservabilityJan 6, 2026

OpenCost v1.119.1 contains a panic fix and changes to custom-cost configuration behavior. The release also includes internal notes whose details are not described here, with no security advisories identified.

Source
Microcks1.13.2CI/CD & App DeliveryJan 6, 2026

Microcks 1.13.2 adds UI, configuration, tracing, and external data-handling capabilities. It also corrects chart calculations, MCP type reflection, PubSub topic handling, and the container image version.

Source
Open Policy Agent (OPA)v1.12.2SecurityJan 6, 2026

OPA v1.12.2 adds a public TemplateString copy method and corrects defects in template-string AST handling and serialization. The changes affect template-string copying, escaped-brace serialization, reference safety, and variable names in template errors.

Source
Keycloak26.5.0SecurityJan 6, 2026

A substantial feature and maintenance release adds operator capabilities including workflows, JWT authorization grants, organization invitations, OpenTelemetry export, and Windows services. It also updates Quarkus and fixes correctness issues, while changing supported database versions and addressing a vulnerability in brute force detection settings.

Check if affected (2)

  • securityBrute force detection settings vulnerability, corrected

    Applies if you configure brute force detection settings.

  • breakingPostgreSQL 13.x support removal

    Applies if you depend on PostgreSQL 13.x.

Plan ahead (1)

  • deprecatedFine-Grained Admin Permissions v1, deprecated

    Applies if you enable admin/fine-grained-permissions.

Source
CRI-Ov1.33.8Kubernetes CoreJan 6, 2026

This CRI-O release contains one operator-facing behavior change related to SELinux labels for systemd or init containers. No actionable change details are included here beyond that release-note summary.

Source
CRI-Ov1.34.4Kubernetes CoreJan 6, 2026

cri-o v1.34.4 is a correctness-focused maintenance release. It fixes CPU affinity behavior when CPU load balancing is disabled and respects user-specified SELinux labels for systemd or init containers. No security advisories or operator-actionable removals, default changes, or constraint changes are disclosed.

Source
Jaegerv2.14.0ObservabilityJan 2, 2026

A release focused on removing legacy v1 components and storage interfaces, while changing configuration and UI defaults. It also adds or expands experimental storage capabilities and includes fixes for storage behavior and dependency API changes.

Check if affected (9)

  • breakingRemaining v1 utilities published as v2.x.x versions

    Applies if you use v1 utilities.

  • breakingThe UI theme selector, enabled by default

    Applies if you use the UI.

  • breakingThe storage/v1/grpc interface, removed

    Applies if you use storage/v1/grpc.

  • + 6 more on the release page
Source
CubeFSv3.5.3Storage & DataDec 23, 2025

CubeFS v3.5.3 adds client, FlashNode, remote-cache, and decommissioning capabilities, alongside performance improvements and bug fixes. The release includes an upgrade order that operators should follow, and clients must be newer than v3.2.0.

Source
Fluidv1.0.8Orchestration & ManagementOct 31, 2025

This release combines operator-facing additions with enforced defaults and restrictions, defect fixes, and dependency and image updates. New support includes native sidecar injection, ThinRuntime metadata configuration, and additional storage client types.

Action needed (1)

  • breakingRestricted service account permissions

    Service account permissions are restricted. The sample file samples/juicefs/read_job.yaml is included.

Check if affected (1)

  • breakingRemoval of the redundant SYS_ADMIN capability from runtime engines

    Applies if you use runtime engines.

Source
CloudEvents[email protected]Networking & MessagingJun 17, 2024

This release clarifies the CESQL specification and behavior, including error handling, type casting, whitespace, function results, missing attributes, evaluation order, default zero values, and string comparison. In fail-fast error handling, expressions return the zero value for their return type when they encounter an error.

Source
CloudEvents[email protected]Networking & MessagingFeb 6, 2022

This CloudEvents release updates protocol and binding behavior, including clarifications to headers, formats, and extensions. The header rename concerns integrations that use the Webhook header.

Check if affected (1)

  • breakingThe Webhook-Request-Origin header, renamed to Webhook-Allowed-Origin

    Applies if you use Webhook headers in CloudEvents HTTP bindings.

Source
← Newer
Browse by month