Cilium v1.17.18 contains ordinary correctness fixes, a new BYOCNI loopback capability, and dependency and image updates. No security advisories or operator actions are identified.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
This release corrects overly small timeouts in the Receiver's Shipper component. The available release information does not include a recorded change item to describe in more detail.
Source ↗Istio 1.29.6 is a correctness-focused maintenance release. The fixes address ambient traffic draining, HBONE capability propagation, ambient CNI responsiveness, Istiod memory use, and cross-network traffic through east-west gateways.
Source ↗Istio 1.30.3 is a maintenance release focused on operator-facing updates, performance work, and defect corrections. The listed release material includes fixes across certificate rotation, ambient mode, waypoint routing, multicluster behavior, and Istiod scalability.
Source ↗A feature and behavior release that adds Windows and device-management capabilities, changes edge database and node-querying behavior, and updates the Kubernetes dependency. Device status retrieval now uses the new DeviceStatus CRD.
Check if affected (1)
breakingThe
DeviceStatus CRDfor device status retrievalApplies if you use the
DeviceStatus CRD.
KubeEdge v1.22.2 combines defect corrections with new operator-facing capabilities, Beehive restart-policy support, device-model API changes, and an upgrade to Kubernetes v1.31.12. No security advisories or security-specific fixes are disclosed.
Source ↗This release combines correctness fixes with changes to node-job behavior, operator capabilities, and command workflows. It introduces configuration updates for edge nodes, which are disabled by default and require an EdgeCore restart; no security advisories are identified.
Check if affected (6)
breakingThe v1alpha2
NodeUpgradeJobandImagePrePullJobdefaultsApplies if you use
NodeUpgradeJoborImagePrePullJob.breakingNode-job switching constraint
Applies if you use
NodeUpgradeJoborImagePrePullJob.breakingThe
taskManagernode-job module, disabled by defaultApplies if
EdgeCoreis running.- + 3 more on the release page
Plan ahead (1)
deprecatedThe v1alpha1
NodeUpgradeJobandImagePrePullJobjobs, deprecatedApplies if you use
NodeUpgradeJoborImagePrePullJob.
Release 3.31.0 contains a dependency update addressing vulnerabilities in graphql/server. It also includes correctness fixes across probes, GraphQL, authentication, infrastructure, and experiment handling.
Action needed (1)
securityDependencies in
graphql/serverupdatedDependencies in
graphql/serverare updated to fix vulnerabilities. The update ships in Release 3.31.0.
KServe v0.18.1 is a maintenance release with a Helm chart defect fix identified in the release metadata. No individual change details are available here.
Source ↗A broad release with operator-facing changes across configuration, protocols, extensions, networking, and observability. Security fixes address multiple identified CVEs and a GHSA, while changed defaults, stricter input validation, and removed functionality may affect existing deployments.
Check if affected (11)
securityhigh
HTTP/2header limits and flood protectionApplies if you use
HTTP/2.securityhigh
HTTP/3QPACK andcontent-lengthsecurity fixesApplies if you use
HTTP/3.securityhighAdditional protocol, parser, formatter, and decompression security fixes
Applies if you use DNS query validation, JSON nesting limits, PROXY protocol TLV, the formatter, TCP StatsD, TLS SAN, or Zstd decompression.
- + 8 more on the release page
A substantial mixed feature and maintenance release adds backend, frontend, catalog, authentication, webhook, and TechDocs capabilities alongside dependency updates and defect fixes. It also includes operator-visible changes to APIs, configuration validation, OpenAPI tooling, and MCP transport behavior; no security advisories or security-specific fixes are disclosed.
Action needed (1)
breakingOpenAPI breaking change detection with
oasdiff@useoptic/opticand@useoptic/openapi-utilitieshave been replaced withoasdifffor OpenAPI breaking change detection.
Check if affected (12)
breakingSchema loading rejects invalid imports
Applicability is not stated in the release notes.
breakingThe
package schema openapi initandrepo schema openapi testcommands, removedApplies if you use
package schema openapi initorrepo schema openapi test.breakingMutually exclusive
userGroupMember.andpath user.configurationfilter Applies if you configure both
userGroupMember.andpath user..filter - + 9 more on the release page
Plan ahead (3)
deprecatedOpaque entity header extension point deprecation
Applies if you use the opaque entity header extension point.
deprecatedDynamic Client Registration deprecation warning
Applies if you enable Dynamic Client Registration.
deprecatedStable
auth.configurationclientIdMetadataDocuments Applies if you configure
auth.orclientIdMetadataDocuments auth..experimentalClientIdMetadataDocuments
A maintenance release rebuilds the pack on Go 1.25.12 to address two disclosed standard library security issues. It also updates several dependencies and includes a newer default lifecycle version.
Check if affected (1)
securityhigh
Go1.25.12 standard library rebuild for GO-2026-4970 and GO-2026-5856Applies if you use
1..25. 11 -> 1. 25. 12
Flux v2.9.2 includes an operator-relevant regression fix for Kustomizations whose openapi. points to a URL, along with dependency and toolkit component updates. CRD description corrections are documentation-only.
wasmCloud v2.5.2 adds asynchronous PostgreSQL support and WIT and wkg configuration resolution. It also improves HTTP recognition and default capability backend handling, while including dependency and internal tooling updates.
Source ↗Dapr v1.16.17 fixes Scheduler handling for actor reminder and job names and actor IDs that were accepted at the API edge but rejected by stricter DNS-1123 validation. It also corrects the related validation error and actor metadata handling, with no operator action required beyond upgrading.
Source ↗Prometheus v3.13.1 is a focused bug-fix release. It corrects a TSDB head-chunk cache defect that could affect range-query results after head-chunk truncation.
Source ↗This release changes dependency composition and CoreDNS behavior. It adds a forward plugin directive and expands secondary-plugin zone support, while also addressing a non-64-bit build defect through a dependency adjustment.
A maintenance release with operator-relevant fixes and behavior changes, plus security work in the 1.18 release line. It includes namespace-boundary enforcement for generators and security dependency updates.
Action needed (1)
securitySecurity dependency updates
Security dependency updates from #16340 are backported to
release-1..18
Check if affected (1)
securityNamespace-boundary enforcement in
generator.apply() Applies if you use
generator..apply()
A release with operator-visible behavior corrections, new capabilities, configuration changes, and updated defaults. The changes span CoreDNS core behavior and multiple plugins, with no security advisories or explicitly described vulnerabilities.
Action needed (1)
breakingGo TLS defaults in
coreThe
corecomponent uses Go TLS defaults in this release.
Check if affected (1)
breakingDefault truncate amount for bare
truncateApplies if you configure
truncate.
A maintenance release with an enforced CRI constraint, aligned erofs defaults, correctness and behavior fixes, and dependency updates. It contains no security advisories or explicitly described vulnerabilities.
Check if affected (2)
breakingThe
CreateContainerconstraint for stopped sandboxesApplies if you use
CreateContainerwhen the sandbox is not running.breakingThe
erofsdefault mkfs block sizeApplies if you use
erofsacross platforms.
A maintenance release with CRI and image-distribution fixes. The CRI constraint on CreateContainer requests may require action, while the other fixes take effect through the upgrade.
Action needed (1)
breaking
CreateContainerrejection for stopped sandboxesThe CRI now rejects
CreateContainerrequests when the sandbox is not running. This constraint ships in containerd v2.2.6.
containerd v2.0.11 fixes content storage pollution by limiting the fallback used during reference resolution. It also updates the Go toolchain to 1.26.5 and 1.25.12.
Source ↗containerd v1.7.34 fixes a CRI event-loss defect and updates the Go toolchain. It also upgrades several golang. dependencies.
This release includes a security-related dependency cleanup and a dependency update. The github. dependency moves from 1. to 1..
Action needed (1)
securityThe
containerd v1dependency, removedThe
containerd v1dependency is removed in Helmv3.to resolve govulncheck CVEs associated with21. 3 037733e7d51b08e30a0233bd546c345ab3ea3bba.
Helm v4.2.3 is a maintenance release that updates the third-party dependency golang. from 0.53.0 to 0.54.0. The remaining release content concerns release navigation and a general upgrade recommendation.
A feature and behavior release that adds operator-facing configuration and integration options while changing supported inputs and runtime behavior. It also includes a dependency migration for disclosed CVEs and deprecates no existing operator feature.
Action needed (2)
securityMigration from
github.tocom/docker/docker github.com/moby/moby Dependencies from
github.were migrated to theircom/docker/docker github.equivalents to resolve CVEs. The migration ships in this release.com/moby/moby breakingRPC metrics from agent health check loopback calls
Agent health check loopback calls no longer emit RPC metrics. This reduces metrics noise in the agent.
Check if affected (1)
breakingJWT-SVID serving by the delegated API
Applies if you use the delegated API for admin or downstream entries.
v3.4.5 is a maintenance release focused on correctness fixes and dependency updates. No security advisory or vulnerability is disclosed.
Source ↗This Flatcar release is a security update focused on fixes for disclosed Linux vulnerabilities. It also updates the Linux and ca-certificates dependencies.
Action needed (1)
securitycritical
Linuxsecurity fixes for disclosed CVEsThe
Linuxpackage carries fixes associated with CVE-2026-46242, CVE-2026-52908, CVE-2026-52910, CVE-2026-52917, CVE-2026-52924, CVE-2026-52929, CVE-2026-52930, CVE-2026-52935, CVE-2026-52939, CVE-2026-52942, CVE-2026-52946, CVE-2026-52947, CVE-2026-52948, CVE-2026-53131, CVE-2026-53132, CVE-2026-53133, CVE-2026-53134, CVE-2026-53135, CVE-2026-53136, CVE-2026-53137, CVE-2026-53138, CVE-2026-53140, CVE-2026-53143, CVE-2026-53144, CVE-2026-53146, CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150, CVE-2026-53152, CVE-2026-53154, CVE-2026-53156, CVE-2026-53158, CVE-2026-53159, CVE-2026-53160, CVE-2026-53161, CVE-2026-53168, CVE-2026-53175, CVE-2026-53176, CVE-2026-53177, CVE-2026-53180, CVE-2026-53181, CVE-2026-53182, CVE-2026-53183, CVE-2026-53184, CVE-2026-53185, CVE-2026-53186, CVE-2026-53189, CVE-2026-53190, CVE-2026-53191, CVE-2026-53192, CVE-2026-53193, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53198, CVE-2026-53199, CVE-2026-53202, CVE-2026-53203, CVE-2026-53205, CVE-2026-53207, CVE-2026-53208, CVE-2026-53209, CVE-2026-53210, CVE-2026-53212, CVE-2026-53213, CVE-2026-53214, CVE-2026-53215, CVE-2026-53216, CVE-2026-53217, CVE-2026-53218, CVE-2026-53219, CVE-2026-53220, CVE-2026-53221, CVE-2026-53223, CVE-2026-53225, CVE-2026-53227, CVE-2026-53228, CVE-2026-53229, CVE-2026-53230, CVE-2026-53233, CVE-2026-53234, CVE-2026-53235, CVE-2026-53236, CVE-2026-53237, CVE-2026-53238, CVE-2026-53239, CVE-2026-53241, CVE-2026-53242, CVE-2026-53245, CVE-2026-53247, CVE-2026-53249, CVE-2026-53251, CVE-2026-53252, CVE-2026-53253, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53261, CVE-2026-53262, CVE-2026-53263, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53271, CVE-2026-53272, CVE-2026-53273, CVE-2026-53274, CVE-2026-53275, CVE-2026-53328, CVE-2026-53329, CVE-2026-53331, CVE-2026-53332, CVE-2026-53336, CVE-2026-53337, CVE-2026-53339, CVE-2026-53343, CVE-2026-53345, CVE-2026-53346, CVE-2026-53347, CVE-2026-53349, CVE-2026-53350, CVE-2026-53352, CVE-2026-53353, CVE-2026-53354, CVE-2026-53355, CVE-2026-53356, CVE-2026-53359, CVE-2026-53361, CVE-2026-53362. The fixes ship in Flatcarstable-4593..2. 4
This Flatcar release is a security update with fixes for Linux issues identified by CVE advisories. It also updates Linux and ca-certificates.
Action needed (1)
securitycritical
Linuxsecurity fixes for CVE advisoriesLinuxreceives security fixes associated with CVE-2026-46242, CVE-2026-46243, CVE-2026-46244, CVE-2026-46275, CVE-2026-46323, CVE-2026-52908, CVE-2026-52910, CVE-2026-52912, CVE-2026-52913, CVE-2026-52914, CVE-2026-52915, CVE-2026-52916, CVE-2026-52917, CVE-2026-52918, CVE-2026-52919, CVE-2026-52921, CVE-2026-52922, CVE-2026-52923, CVE-2026-52924, CVE-2026-52926, CVE-2026-52927, CVE-2026-52929, CVE-2026-52930, CVE-2026-52931, CVE-2026-52934, CVE-2026-52935, CVE-2026-52939, CVE-2026-52941, CVE-2026-52942, CVE-2026-52943, CVE-2026-52944, CVE-2026-52946, CVE-2026-52947, CVE-2026-52948, CVE-2026-53080, CVE-2026-53131, CVE-2026-53133, CVE-2026-53134, CVE-2026-53135, CVE-2026-53136, CVE-2026-53137, CVE-2026-53143, CVE-2026-53144, CVE-2026-53146, CVE-2026-53147, CVE-2026-53148, CVE-2026-53149, CVE-2026-53150, CVE-2026-53154, CVE-2026-53158, CVE-2026-53159, CVE-2026-53160, CVE-2026-53161, CVE-2026-53168, CVE-2026-53176, CVE-2026-53177, CVE-2026-53181, CVE-2026-53182, CVE-2026-53183, CVE-2026-53184, CVE-2026-53185, CVE-2026-53186, CVE-2026-53189, CVE-2026-53190, CVE-2026-53192, CVE-2026-53194, CVE-2026-53195, CVE-2026-53196, CVE-2026-53198, CVE-2026-53199, CVE-2026-53207, CVE-2026-53208, CVE-2026-53209, CVE-2026-53212, CVE-2026-53213, CVE-2026-53214, CVE-2026-53215, CVE-2026-53216, CVE-2026-53217, CVE-2026-53218, CVE-2026-53219, CVE-2026-53221, CVE-2026-53223, CVE-2026-53225, CVE-2026-53227, CVE-2026-53228, CVE-2026-53230, CVE-2026-53236, CVE-2026-53237, CVE-2026-53238, CVE-2026-53239, CVE-2026-53242, CVE-2026-53245, CVE-2026-53247, CVE-2026-53249, CVE-2026-53252, CVE-2026-53253, CVE-2026-53254, CVE-2026-53255, CVE-2026-53256, CVE-2026-53263, CVE-2026-53264, CVE-2026-53265, CVE-2026-53266, CVE-2026-53267, CVE-2026-53268, CVE-2026-53269, CVE-2026-53270, CVE-2026-53271, CVE-2026-53273, CVE-2026-53274, CVE-2026-53275, CVE-2026-53329, CVE-2026-53331, CVE-2026-53336, CVE-2026-53337, CVE-2026-53339, CVE-2026-53343, CVE-2026-53345, CVE-2026-53347, CVE-2026-53349, CVE-2026-53350, CVE-2026-53352, CVE-2026-53353, CVE-2026-53354, CVE-2026-53355, CVE-2026-53356, CVE-2026-53357, CVE-2026-53358, CVE-2026-53359, CVE-2026-53361, and CVE-2026-53362.
Prometheus v3.5.5 includes a Go 1.25.12 toolchain change and a disclosed security fix in the UI. The security fix concerns the sanitize-html dependency and CVE-2026-53606.
Action needed (1)
securitymediumThe
sanitize-htmldependency update for CVE-2026-53606The Prometheus UI updates
sanitize-htmlto v2.17.5 to fix CVE-2026-53606.
A substantial operator-focused release that adds and promotes APIs, feature gates, administration capabilities, and deployment options. It also includes deprecations and removals, along with fixes for account takeover, log injection and audit forgery, key-attestation bypass, QR-code dimension denial of service, and four CVE-identified vulnerabilities.
Action needed (1)
securityPre-account takeover attack exposure
The release corrects an issue that provided room for pre-account takeover attacks.
Check if affected (19)
securitymediumCVE-2026-9796, admin role rename authorization
Applies if you use
manage-clients.securitymediumCVE-2026-9689, OIDC redirect URI parameter handling
Applies if you use
OIDC.securitymediumCVE-2026-9798, CIBA account lockout
Applies if you run the
CIBAauthentication flow.- + 16 more on the release page
Plan ahead (4)
deprecatedThe
V1API, deprecatedApplies if you use
V1.deprecatedThe
Require Discoverable Credentialoption, deprecatedApplies if you configure the
Require Discoverable Credentialoption.deprecatedThe Twitter IDP implementation, deprecated
Applies if you use the Twitter IDP implementation.
- + 1 more on the release page
A feature and maintenance release with new configuration and resource-management capabilities, plus corrections for invalid timestamp handling, memory use, and stability. It also upgrades vulnerable third-party dependencies and aligns compatibility fixes with upstream.
Action needed (1)
securityThird-party dependency upgrades for TiKV 8.5
TiKV 8.5 upgrades
vulnerable third-party dependenciesand aligns the required compatibility fixes with upstream.
Check if affected (1)
breakingInvalid
max_tsupdates rejected by defaultApplies if you do not set
storage..max-ts. action-on-invalid-update
A feature and maintenance release with operator-facing RBAC, Helm, API, and feature-gate changes, alongside new capabilities and defect corrections. It includes changes to configuration, permissions, certificate issuance, and integrations.
Check if affected (5)
security
cert-manager-editaggregateClusterRolepermission removal, GHSA-8rvj-mm4h-c258Applies if you use the
cert-manager-editaggregateClusterRole.breaking
ObjectReferenceAPI removalApplies if you use
ObjectReferencein an API.breakingPrometheus ServiceMonitor and PodMonitor Helm value removal
Applies if you configure any of
prometheus.,servicemonitor. targetPort prometheus., orservicemonitor. path prometheus..podmonitor. path - + 2 more on the release page
Plan ahead (2)
deprecatedGateway API controller configuration fields
Applies if you configure any of
enableGatewayAPI,enableGatewayAPIListenerSet,gatewayAPI., orenabled gatewayAPI..enableListenerSet deprecated
ServerSideApplyfeature gate deprecation
A maintenance release with security fixes, an authentication correction, and dependency and toolchain updates. The security-related changes address CRL enforcement and golang..
Action needed (1)
securityhigh
golang.updated toorg/x/crypto v0.52. 0 The release updates
golang.toorg/x/crypto v0.to resolve CVE-2026-46598, CVE-2026-39835, CVE-2026-39828, and CVE-2026-46597.52. 0
Check if affected (1)
securityCRL enforcement bypass on the gRPC listener, fixed
Applies if you configure
--listen-client-http-urls.
A release with security corrections, breaking configuration removals, and an output-field rename that may require operator or log-collector changes. It also adds TLS and cache configuration, query and tracing changes, and defect fixes across several Thanos components.
Action needed (1)
securitycritical
thanos-community/grpc-gofork update for CVE-2026-33186The
thanos-community/grpc-gofork is bumped to fix CVE-2026-33186, an authorization bypass via malformed:pathheaders.
Check if affected (4)
security
Receivetenant ID validationApplies if you run
Receive.breaking
Query-Frontendtime_takenfield renamed totime_taken_msApplies if you run
Query-Frontend.breaking
--shipper.flag removedignore-unequal-block-size Applies if you configure
--shipper..ignore-unequal-block-size - + 1 more on the release page
A dependency-focused release raises the minimum supported Python protobuf version. The headings contain no operator-facing changes.
Check if affected (1)
breakingThe Python
protobufdependency lower bound, raisedApplies if you use Python.
This is a maintenance release centered on a Go dependency update for CVE remediation. The change is operator-facing.
Action needed (1)
security
Go1.25.10 dependency updateGois updated to1.for CVE remediation in this release.25. 10
Tekton v1.9.6 contains dependency updates for CVE remediation. The release affects Go and two golang. packages, with no specific advisory identifiers or vulnerability details in the note.
Action needed (3)
security
Go1.25.10 updateGois updated to1.for CVE remediation in v1.9.6.25. 10 security
golang.v0.52.0 updateorg/x/crypto golang.is updated toorg/x/crypto v0.for CVE remediation in v1.9.6.52. 0 security
golang.v0.55.0 updateorg/x/net golang.is updated toorg/x/net v0.for CVE remediation in v1.9.6.55. 0
Rook v1.20.2 includes dependency updates, behavioral changes, and fixes across Ceph, CSI, core, security, and storage operations. The release also tightens the manager NetworkPolicy to ingress-only; no vulnerability or advisory is disclosed.
Source ↗Version v1.23.0 contains no recorded changes for artifact-hub. The release note does not identify any project change that requires a user-facing description.
Source ↗