RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Fluxv2.9.1CI/CD & App DeliveryJul 7, 2026

Flux v2.9.1 is a maintenance release focused on defect fixes, dependency and component updates, and a performance improvement. It includes changes across controller behavior and build and decryption paths, with no security advisories disclosed.

Source
OpenTelemetryv0.156.0ObservabilityJul 7, 2026

OpenTelemetry v0.156.0 adds mdatagen and memory-limiter capabilities, changes generated configuration APIs, and corrects runtime and API defects. No security advisories or security-specific fixes are disclosed.

Source
OpenKruisev1.9.1CI/CD & App DeliveryJul 4, 2026

OpenKruise v1.9.1 is a maintenance release focused on an operator-facing defect in Kubernetes server version parsing. The fix addresses a controller panic involving certain GKE and EKS version strings.

Source
k8gbv0.20.0Kubernetes CoreJul 3, 2026

k8gb v0.20.0 centers on ZoneDelegation-based DNS management, with TLSRoute and annotation support alongside changes to defaults and naming. The release also includes defect fixes and dependency updates, and no security advisories or vulnerabilities are identified.

Check if affected (4)

  • breakingThe Bootstrap service, removed

    Applies if your configuration uses the Bootstrap service.

  • breakingThe dynamicZones setting, removed

    Applies if your configuration uses dynamicZones.

  • breakingThe doFinalize default, set to false

    Applies if you use doFinalize in ZoneDelegation finalization.

  • + 1 more on the release page
Source
Limav2.1.4Kubernetes CoreJul 3, 2026

Lima v2.1.4 contains behavior fixes, FreeBSD template and general template updates, a nerdctl update from v2.3.3 to v2.3.4, and a change to the JSON network-list output. No security advisories or security-specific fixes are disclosed.

Source
CRI-Ov1.35.5Kubernetes CoreJul 2, 2026

CRI-O v1.35.5 includes an operator-facing correctness fix for container status ImageRef values after a CRI-O restart. It also updates CPU injection and gomaxprocs handling to account for workload partitioning and reduce potential Go scheduler throttling.

Source
gRPCv1.82.0Networking & MessagingJul 2, 2026

A feature and maintenance release that adds and changes capabilities across Core, PHP, Python, and Ruby, corrects runtime defects, and upgrades protobuf dependencies. The Python 1.82.0 package was removed from PyPI.

Check if affected (1)

  • breakinggRPC Python release 1.82.0, yanked from PyPI

    Applies if you use gRPC Python release 1.82.0.

Source
Harborv2.15.2Storage & DataJul 2, 2026

A maintenance release with a forced internal PostgreSQL major-version upgrade, a redis to valkey cache backend replacement, dependency and component updates, and defect corrections. Token and blob-mount validation is hardened.

Action needed (1)

  • securityToken and blob-mount source validation

    Blob-mount source projects are validated, and tokens without iat are rejected.

Check if affected (2)

  • breakingThe bundled PostgreSQL version, upgraded

    Applies if you use PostgreSQL.

  • breakingThe cache backend, changed from redis to valkey

    Applies if you use redis.

Source
CRI-Ov1.36.2Kubernetes CoreJul 2, 2026

This release has no detailed changes available for display. The remaining release-note entry describes an operator-facing performance behavior update involving the gomaxprocs hook and CPU allocation.

Source
CRI-Ov1.34.10Kubernetes CoreJul 2, 2026

CRI-O v1.34.10 is an operator-facing maintenance release with bug fixes in CPU allocation and container status reporting. It adjusts CPU handling to reduce scheduler throttling and preserves the ImageRef value across CRI-O restarts. No security advisories are identified.

Source
etcdv3.6.13Kubernetes CoreJul 1, 2026

A maintenance release with authentication and certificate-revocation enforcement fixes, Go toolchain and dependency updates, and a new v2 deprecation option. The security-related changes include fixes and dependency updates associated with the listed advisories.

Action needed (2)

  • securityhighgo.opentelemetry.io/otel dependencies, updated to v1.43.0

    The go.opentelemetry.io/otel and go.opentelemetry.io/otel/sdk dependencies are updated from v1.40.0 to v1.43.0. The updates address CVE-2026-29181 and CVE-2026-39883.

  • securityhighgolang.org/x/crypto, updated to v0.52.0

    The golang.org/x/crypto dependency is updated to v0.52.0. The change is associated with CVE-2026-39828, CVE-2026-39835, CVE-2026-46597, and CVE-2026-46598.

Check if affected (1)

  • securityCRL enforcement bypass on the gRPC listener, fixed

    Applies if --listen-client-http-urls is configured.

Source
etcdv3.5.32Kubernetes CoreJul 1, 2026

A maintenance release with server configuration, access control, authentication, validation, logging, and dependency updates. Deployments using the affected listener configuration or OpenTelemetry dependencies are directly concerned by the included fixes.

Action needed (1)

  • securityhighOpenTelemetry dependencies updated for CVE-2026-29181 and CVE-2026-39883

    go.opentelemetry.io/otel and go.opentelemetry.io/otel/sdk were updated from v1.40.0 to v1.43.0. The updates address CVE-2026-29181 and CVE-2026-39883.

Check if affected (1)

  • securityCRL enforcement with --listen-client-http-urls

    Applies if --listen-client-http-urls is configured.

Source
Prometheusv3.13.0ObservabilityJul 1, 2026

A long-term support release with security-related dependency updates, PromQL changes, new APIs and configuration controls, and bug fixes. It also replaces a shipped license artifact and includes performance improvements.

Action needed (2)

  • securitycriticalThe sanitize-html dependency update

    The UI updates sanitize-html to address a cross-site scripting vulnerability, identified as CVE-2026-44990.

  • breakingThe third-party license artifact

    Third-party npm dependency licenses are embedded in the Prometheus binary and served at /assets/third-party-licenses.txt. This replaces the npm_licenses.tar.bz2 archive previously shipped in release tarballs and container images.

Check if affected (2)

  • securitymediumRedirect credential forwarding

    Applies if you use scraping, remote read/write, alerting, or service discovery.

  • breakingPromQL duration-expression function names

    Applies if you enable experimental-duration-expr and use min() and max().

Source
Longhornv1.11.3Storage & DataJul 1, 2026

Longhorn v1.11.3 is a maintenance release with multiple correctness fixes and new metrics for LONGHORN_DISTRO. It requires Kubernetes v1.34 or later because the CSI external provisioner was upgraded to v6.3.0.

Source
Istio1.28.10Networking & MessagingJul 1, 2026

Istio 1.28.10 contains an operator-relevant correctness fix in the krt controller framework. The available release information does not include a standalone change item for this fix.

Source
wasmCloudv2.5.0Orchestration & ManagementJun 30, 2026

Version v2.5.0 adds runtime and WIT/API capabilities and includes correctness and dependency updates. The release also enables wasip3 by default and includes a quinn-proto fix for RUSTSEC-2026-0185.

Action needed (1)

  • securityhighThe quinn-proto security fix

    The quinn-proto dependency fix ships in wasmCloud v2.5.0 and addresses RUSTSEC-2026-0185.

Check if affected (1)

  • breakingDefault wasip3 enablement with wasmtime 46

    Applies if your workloads use wasip3.

Source
Tektonv1.14.0CI/CD & App DeliveryJun 30, 2026

Release v1.14.0 adds tracing and observability capabilities and broadens ResolutionRequest resolution support. It also includes correctness fixes, a Go security-related update, and shipped dependency updates.

Action needed (1)

  • securityGo 1.26.4 update

    Go is updated to 1.26.4 in v1.14.0 for CVE remediation.

Source
Fluxv2.9.0CI/CD & App DeliveryJun 30, 2026

Flux v2.9.0 removes two deprecated API versions and adds CLI and controller capabilities across several Flux resources. It also changes supported Kubernetes versions, corrects defects, and updates project and third-party dependencies.

Check if affected (1)

  • breakingRemoval of deprecated Flux API versions

    Applies if your CRDs use the image.toolkit.fluxcd.io/v1beta2 or notification.toolkit.fluxcd.io/v1beta2 APIs.

Source
Kubescapev4.0.10SecurityJun 30, 2026

This release removes an orphan CRD, adds operator-facing capabilities and output changes, and corrects runtime, validation, reporting, and scan-processing defects. No security advisories or explicitly exploitable vulnerabilities are disclosed.

Check if affected (1)

  • breakingSecurityException CRD removal

    Applies if you use the SecurityException CRD.

Source
Karmadav1.18.1Orchestration & ManagementJun 30, 2026

This release updates the Alpine base image and fixes a Helm chart TLS certificate issue. The Helm fix applies to deployments that use a custom namespace, while the base image change addresses security concerns.

Action needed (1)

  • securityThe alpine base image, upgraded

    The alpine base image is promoted from alpine:3.23.4 to alpine:3.24.1 to address security concerns.

Source
Karmadav1.17.4Orchestration & ManagementJun 30, 2026

Karmada v1.17.4 updates its Alpine base image to address security concerns. The release also fixes a Helm chart TLS certificate SAN mismatch when deploying to a custom namespace.

Action needed (1)

  • securityThe alpine base image, updated to alpine:3.24.1

    The alpine base image is updated from alpine:3.23.4 to alpine:3.24.1 to address security concerns. The update ships in Karmada v1.17.4.

Source
Karmadav1.16.7Orchestration & ManagementJun 30, 2026

Karmada v1.16.7 updates its Alpine base image for security concerns and includes a Helm chart fix for TLS certificate SANs in custom namespaces. The release affects deployments that use the updated image or the affected Helm chart configuration.

Action needed (1)

  • securityThe alpine base image, updated

    The base image alpine is promoted from alpine:3.23.4 to alpine:3.24.1 to address security concerns.

Source
KubeVelav1.10.9CI/CD & App DeliveryJun 30, 2026

A maintenance release with a security fix for unbounded reads in the Terraform remote configuration loader and a correctness fix for CUE imports in status details. It also adds repository ownership metadata.

Check if affected (1)

  • securityUnbounded read prevention in the Terraform remote configuration loader

    Applies if you use the Terraform remote configuration loader.

Source
KubeVelav1.9.14CI/CD & App DeliveryJun 30, 2026

This release includes a security correction for an unbounded-read denial-of-service condition in the Terraform remote configuration loader. The fix is backported to release-1.9 and concerns deployments that use this loader.

Check if affected (1)

  • securityTerraform remote configuration loader DoS fix (GHSA-fmgp-q6jx-gg3x)

    Applies if you use the Terraform remote configuration loader.

Source
OpenFGAv1.18.1SecurityJun 29, 2026

This release contains an experimental authorization evaluation change and an IP address matching semantics change. The remaining updates are diagnostic or storage-internal and do not require operator action.

Source
NATSv2.14.3Networking & MessagingJun 29, 2026

A maintenance release with a dependency and toolchain update, broad defect corrections, and behavior improvements across authentication, routing, monitoring, clustering, and JetStream. It also removes JSONP monitoring callbacks and addresses MQTT and authorization-related connection and permission handling.

Check if affected (3)

  • securityNats-Trace-Dest publish permission checks for leaf connections

    Applies if you use Leaf connections.

  • securityMQTT subscribe deny rules on retained message and QoS replay paths

    Applies if you use MQTT.

  • breakingThe JSONP callback support in monitoring endpoints, removed

    Applies if you use JSONP callback support.

Source
NATSv2.12.12Networking & MessagingJun 29, 2026

A maintenance release with dependency updates, operational behavior changes, and correctness fixes across General, MQTT, Monitoring, and JetStream. It also removes JSONP callback support from monitoring endpoints.

Check if affected (1)

  • breakingThe JSONP callback support in monitoring endpoints, removed

    Applies if you use JSONP callback support.

Source
Strimzi1.1.0Networking & MessagingJun 27, 2026

This release adds operator-facing configuration and feature capabilities while updating supported Apache Kafka versions and related integrations. It also changes TLS file handling for KafkaBridge and KafkaMirrorMaker2 and renames entity-operator healthcheck ports, so those areas may require attention.

Check if affected (3)

  • breakingSupport for Kafka 4.1.x removed

    Applies if you use Kafka 4.1.x.

  • breakingPEM-based TLS files for KafkaBridge and KafkaMirrorMaker2

    Applies if you use KafkaBridge or KafkaMirrorMaker2 with TLS authentication or a TLS truststore.

  • breakingEntity-operator healthcheck port names

    Applies if you use entity-operator healthcheck ports.

Source
Volcanov1.14.3Orchestration & ManagementJun 27, 2026

Volcano v1.14.3 is a bug-fix release for operator-relevant scheduling, resource accounting, pod metadata, status handling, and scheduler snapshots. The recorded release data contains no individual change entries to display.

Source
Keycloak26.6.4SecurityJun 26, 2026

Version 26.6.4 is a security-focused Keycloak release with fixes for disclosed vulnerabilities. It also upgrades Quarkus to 3.33.2.1, an informational dependency change for operators.

Action needed (8)

  • securityhighCVE-2026-9099, group-admin escalation to realm-admin

    Version 26.6.4 fixes the group-admin escalation to realm-admin identified as CVE-2026-9099 in Keycloak.

  • securityhighCVE-2026-9086, cross-site scripting via URI validation bypass

    Version 26.6.4 fixes the cross-site scripting issue caused by a case-insensitive URI validation bypass identified as CVE-2026-9086 in Keycloak.

  • securityhighCVE-2026-9795, improper scope mapping enforcement

    Version 26.6.4 fixes the privilege escalation caused by improper scope mapping enforcement identified as CVE-2026-9795 in Keycloak.

  • securityhighCVE-2026-9800, policy enforcer URI comparison

    Version 26.6.4 fixes the authorization bypass caused by incorrect URI comparison in the Keycloak policy enforcer, identified as CVE-2026-9800.

  • securityhighCVE-2026-11800, JWT algorithm confusion authentication bypass

    Version 26.6.4 fixes the JWT algorithm confusion authentication bypass identified as CVE-2026-11800 in Keycloak.

  • securitymediumCVE-2026-9083, arbitrary filesystem path probing

    Version 26.6.4 fixes the information disclosure through arbitrary filesystem path probing identified as CVE-2026-9083 in Keycloak.

  • securitymediumCVE-2026-9705, disabled client takeover

    Version 26.6.4 fixes the issue identified as CVE-2026-9705, which allowed disabled clients to be re-enabled and taken over through a registration access token in Keycloak.

  • securitymediumCVE-2026-9799, UMA permission ticket bypass

    Version 26.6.4 fixes the unauthorized resource access caused by a UMA permission ticket bypass identified as CVE-2026-9799 in Keycloak.

Source
Operator Frameworkv1.42.3Orchestration & ManagementJun 26, 2026

This release primarily updates dependencies and base images, including the Ansible operator plugin version. No security advisories or explicitly described vulnerabilities are included.

Source
Backstagev1.52.1CI/CD & App DeliveryJun 26, 2026

Backstage v1.52.1 is a maintenance release focused on operator-facing defect fixes. It addresses scheduler task state during trigger changes and a broken configuration schema in the Kubernetes React plugin.

Source
metal3-iov0.13.1Provisioning & RuntimeJun 26, 2026

Version v0.13.1 contains a correctness fix, a configuration or behavior adjustment, and dependency and toolchain updates. No security advisories or operator actions are disclosed.

Source
Open Policy Agent (OPA)v1.18.0SecurityJun 25, 2026

A release with a breaking change to the outbound User-Agent value, along with restored automatic GOMAXPROCS handling and new automatic GOMEMLIMIT support. It also improves formatting and coverage behavior, corrects compiler and runtime defects, and updates dependencies.

Check if affected (1)

  • breakingThe User-Agent header format

    Applies if you configure server-side log filters or WAF rules that exact-match the old string.

Source
OpenCostv1.120.4ObservabilityJun 25, 2026

OpenCost v1.120.4 is a maintenance release with operator-facing fixes and updates to configuration, tooling, provider integrations, and runtime behavior. No security advisories or explicit security vulnerabilities are disclosed.

Source
cert-managerv1.19.6SecurityJun 25, 2026

cert-manager v1.19.6 changes permissions in the cert-manager-edit aggregate ClusterRole and updates the Go toolchain. Workflows that directly create or modify Challenge or Order resources may require explicit permissions after the release.

Action needed (2)

  • securityhighGo v1.25.11 with fixes for CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507

    Go is updated to v1.25.11 in cert-manager v1.19.6 to fix CVE-2026-27145, CVE-2026-42504, and CVE-2026-42507.

  • securityGo 1.25.10 dependency upgrade

    Go is upgraded to 1.25.10 as part of the dependency updates in cert-manager v1.19.6.

Check if affected (1)

  • securityReduced cert-manager-edit permissions for Challenge and Order creation and updates

    Applies if you use the cert-manager-edit aggregate ClusterRole for workflows that create or modify Challenge or Order resources.

Source
cert-managerv1.20.3SecurityJun 25, 2026

A security-focused patch release removes unsafe ACME permissions and includes fixes for identified CVEs. It also corrects Challenge garbage collection and updates Go dependencies.

Action needed (1)

Check if affected (1)

  • securityThe cert-manager-edit aggregate ClusterRole permissions

    Applicability is not stated in the release notes.

Source
← NewerOlder →
Browse by month