RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

OpenFGAv1.18.0SecurityJun 17, 2026

v1.18.0 is a security-focused release with authentication hardening and stricter configuration validation. MySQL deployments have migration and maintenance-window requirements, while OIDC deployments have required issuer and audience settings.

Check if affected (3)

  • securitymediumMySQL schema migrations 008

    Applies if you use the MySQL backend.

  • securityConstant-time preshared key authentication

    Applies if you use preshared key authentication.

  • securityRequired OIDC issuer and audience configuration

    Applies if authn.method is set to oidc.

Source
Rookv1.20.1Storage & DataJun 16, 2026

A release with operator-facing configuration and behavior changes, including a new default and cleanup of stale resources. It also includes dependency and feature updates, with no security advisory disclosed.

Check if affected (2)

  • breakingStale MDS and RGW pdbs removed

    Applies if you configure MDS and RGW pdbs.

  • breakingcsi-addons disabled by default

    Applies if you enable csi-addons.

Source
Rookv1.19.7Storage & DataJun 16, 2026

This release updates the default Ceph version and changes operational handling for Helm ownership, stale PDB cleanup, OSD device classes, and post-upgrade releases. It contains no disclosed security advisories.

Check if affected (2)

  • breakingDefault Ceph version 19.2.4

    Applies if you use Ceph.

  • breakingStale MDS and RGW PDB cleanup

    Applicability is not stated in the release notes.

Source
Backstagev1.52.0CI/CD & App DeliveryJun 16, 2026

A broad feature and maintenance release with breaking configuration and API evolution across catalog, scaffolder, TechDocs, frontend, actions, and Kubernetes capabilities. It also includes correctness, performance, reliability, and security-related dependency updates, with migration attention needed for renamed or deprecated settings and APIs.

Action needed (2)

  • securityThe infinispan dependency upgrade

    infinispan was upgraded from ^0.12.0 to ^0.13.0 to address known vulnerabilities.

  • breakingThe unused json-schema runtime dependency, removed

    The unused json-schema runtime dependency has been removed.

Check if affected (7)

  • breakingThe catalog.stitchingStrategy.mode: 'immediate' setting, removed

    Applies if you configure catalog.stitchingStrategy.mode.

  • breakingComboboxProps as a union type

    Applies if you use ComboboxProps.

  • breakingThe default /kubernetes page, removed

    Applies if you use /kubernetes.

  • + 4 more on the release page

Plan ahead (9)

  • deprecatedTop-level Combobox input state props, deprecated

    Applies if you use plain-array options.

  • deprecatedPrevious tokens, deprecatedremoval date not announced

    Applicability is not stated in the release notes.

  • deprecatedThe single-module runCliModule helper, deprecated

    Applies if you use runCliModule.

  • + 6 more on the release page
Source
KubeVirtv1.8.4Orchestration & ManagementJun 16, 2026

KubeVirt v1.8.4 adds observability coverage, changes node-labeller CPU feature handling, and fixes a virt-handler resource leak. It also updates a dependency to address CVE-2026-35469 and GHSA-pc3f-x583-g7j2.

Action needed (1)

  • securityhighThe github.com/moby/spdystream dependency, upgraded for CVE-2026-35469

    github.com/moby/spdystream is upgraded from v0.5.0 to v0.5.1 in KubeVirt v1.8.4 to address CVE-2026-35469 and GHSA-pc3f-x583-g7j2.

Source
Ciliumv1.19.5Networking & MessagingJun 16, 2026

A maintenance-focused release with correctness fixes, dependency updates, operator troubleshooting improvements, and a security fix for a namespace-bypass issue. It also removes obsolete Helm settings, so configurations using those values need review.

Check if affected (3)

  • securityWildcard namespace bypass for selectorless ipBlock rules, fixed

    Applies if you configure ipBlock.

  • breakingThe loadBalancer.standalone Helm option, removed

    Applies if you configure loadBalancer.standalone.

  • breakingThe l2podAnnouncements.interface Helm value, replaced by l2podAnnouncements.interfacePattern

    Applies if you configure l2podAnnouncements.interface and enable L2 pod announcements.

Source
Ciliumv1.18.11Networking & MessagingJun 16, 2026

Cilium v1.18.11 is a maintenance release with operator-relevant bug fixes and expanded information reporting for troubleshooting commands. It also updates dependencies, container images, and the proxy version, with no security advisories or explicitly described security flaws.

Source
Ciliumv1.17.17Networking & MessagingJun 16, 2026

Cilium v1.17.17 updates troubleshooting information, Helm chart configurability, proxy and dependency versions, and installation image digests. It also fixes retries for CiliumNode Get errors in multipool.

Source
Flatcar Container Linuxstable-4593.2.3Provisioning & RuntimeJun 16, 2026

This Flatcar release includes multiple Linux vulnerability fixes and updates Linux to 6.12.93. It also adds NVMe/TCP support for storage backends that use NVMe over Fabrics, while the Linux security fixes make the release relevant to systems requiring those updates.

Action needed (1)

Source
Daprv1.18.1Orchestration & ManagementJun 16, 2026

Dapr v1.18.1 is a bug-fix release covering workflow timer cleanup, sidecar shutdown and restart behavior, ContinueAsNew completion handling, operator resynchronization, and Helm CRD schema alignment. No security advisories or security flaws are identified.

Source
Linkerdedge-26.6.2Networking & MessagingJun 16, 2026

A release with narrower ExternalWorkloads endpoint behavior, annotation support for upcoming load-balancing features, policy and profile fixes, dependency updates, and new load-biasing functionality. This release is explicitly not recommended in favor of edge-26.6.3.

Check if affected (1)

  • breakingNamespace-restricted ExternalWorkloads endpoints

    Applies if you use ExternalWorkloads.

Source
Daprv1.17.10Orchestration & ManagementJun 15, 2026

This release corrects a resiliency retry defect in pubsub publish operations. Configured status-code matching is honored when publish errors carry gRPC status codes.

Source
Daprv1.16.16Orchestration & ManagementJun 15, 2026

This release contains operator-relevant defect corrections for Sentry certificate signing interoperability and Helm-based downgrade handling. The fixes cover certificate template and signing request compatibility, plus chart support for downgrade-related storage sizing.

Source
Tektonv1.13.1CI/CD & App DeliveryJun 15, 2026

A maintenance release with defect corrections and a behavior change affecting implicit resource settings for internal containers. No security advisories are disclosed.

Check if affected (1)

  • breakingDefault resource requirements for internal containers are removed

    Applies if you do not set default-container-resource-requirements.

Source
Tektonv1.12.1CI/CD & App DeliveryJun 15, 2026

A maintenance release with several correctness fixes and multiple dependency updates. Resolver behavior is narrowed so that only StepActions, Tasks, and Pipelines can be resolved, which requires review for users of Tekton Resolvers.

Check if affected (1)

  • breakingTekton Resolver object restrictions

    Applies if you use Tekton Resolvers.

Source
Tektonv1.10.3CI/CD & App DeliveryJun 15, 2026

Tekton v1.10.3 contains no operator-facing product changes in the supplied release information. The release information instead contains no recorded changes to describe.

Source
Tektonv1.9.4CI/CD & App DeliveryJun 15, 2026

A maintenance release with correctness fixes, a security-relevant dependency update, resolver compatibility constraints, metric behavior changes, and additional dependency upgrades. The changes include a restriction on the object types handled by Tekton Resolvers and an update to gRPC.

Action needed (1)

  • securitycriticalgoogle.golang.org/grpc updated to 1.79.3 for CVE-2026-33186

    The google.golang.org/grpc dependency is updated from 1.77.0 to 1.79.3 to fix CVE-2026-33186, an authorization bypass caused by a missing leading slash in the :path header.

Check if affected (1)

  • breakingTekton Resolvers, limited to supported object types

    Applies if you use the Resolver API.

Source
Tektonv1.6.3CI/CD & App DeliveryJun 15, 2026

Tekton v1.6.3 contains resolver validation and behavior corrections, along with fixes affecting cross-architecture execution and metrics. It also updates dependencies, including a gRPC change for CVE-2026-33186, so resolver users and dependency-sensitive deployments should review the release.

Action needed (1)

  • securitycriticalThe google.golang.org/grpc dependency fix for CVE-2026-33186

    The google.golang.org/grpc dependency includes a fix for CVE-2026-33186 in v1.6.3.

Check if affected (1)

  • breakingTekton Resolver target restrictions

    Applies if your ResolutionRequest objects use Tekton Resolvers.

Source
Tektonv1.3.5CI/CD & App DeliveryJun 15, 2026

A correctness-focused release fixes resolver behavior and updates dependencies. It also narrows the resolver input contract and changes pod metrics and labels.

Action needed (1)

  • breakingPod label removal

    The pod label is removed in this release.

Check if affected (1)

  • breakingThe Resolver API resolution scope

    Applies if you use custom resolvers and the Resolver API.

Source
Tektonv1.2.1CI/CD & App DeliveryJun 15, 2026

Tekton v1.2.1 contains no operator-facing changes. The release information covers installation and attestation details, with no recorded feature, behavior, or configuration updates.

Source
Kubeflow26.03.1AI & MLJun 15, 2026

A calendar-versioned release with a breaking dashboard upgrade requirement, updated components and dependencies, new defaults, and fixes for deployment and configuration defects. Security hardening is included, but no specific vulnerability or advisory is disclosed.

Action needed (2)

  • breakingmodel-registry UI enabled by default

    The model-registry UI is enabled by default in this release.

  • breakingTwo dex replicas without a sticky service

    dex runs two replicas without a sticky service by default in this release.

Check if affected (1)

  • breakingBreaking dashboard upgrade requirement

    Applies if you use the dashboard.

Source
KServev0.19.0AI & MLJun 14, 2026

A release with operator-facing additions and fixes, including new LLMInferenceService capabilities and status observability. It also updates dependencies and images and includes security-related fixes.

Action needed (1)

  • securityhighazure-core pinned for CVE-2026-21226

    The azure-core dependency is pinned to >=1.38.0 to address CVE-2026-21226.

Check if affected (3)

  • securityvllm setup and pillow dependency fixes

    Applies if you depend on vllm or pillow.

  • breakingIncorrect CRDs removed from llmisvc-crd

    Applies if you use llmisvc-crd.

  • breakingHelm imagePullPolicy defaults

    Applies if you use Helm.

Source
Helmv4.2.1Kubernetes CoreJun 12, 2026

Helm v4.2.1 is a maintenance release with correctness fixes and dependency updates. It includes an update to golang.org/x/net that addresses GO-2026-5026.

Action needed (1)

  • securitycriticalThe golang.org/x/net dependency update for GO-2026-5026

    Helm v4.2.1 updates golang.org/x/net to v0.55.0 to address GO-2026-5026.

Source
Helmv3.21.1Kubernetes CoreJun 12, 2026

Helm v3.21.1 includes dependency and toolchain updates alongside fixes for correctness issues. The disclosed dependency update affects releases using golang.org/x/net.

Action needed (1)

  • securitycriticalThe golang.org/x/net dependency, updated for GO-2026-5026

    Helm v3.21.1 bumps golang.org/x/net to v0.55.0 to address GO-2026-5026.

Source
Kubernetesv1.36.2Kubernetes CoreJun 12, 2026

A maintenance release with Go 1.26.4 build updates and correctness and performance fixes across scheduling, kubelet volume handling, suspended Jobs, Secret data, endpoint processing, and kubeadm dry-run certificate copying. No security advisories are disclosed.

Source
Kubernetesv1.35.6Kubernetes CoreJun 12, 2026

A maintenance release with correctness and performance fixes, along with an updated Go toolchain dependency. The recorded notes do not disclose security advisories or security-specific flaws.

Source
Kubernetesv1.34.9Kubernetes CoreJun 12, 2026

A maintenance release with a Go toolchain dependency update and fixes for operator-facing defects. The fixes cover endpoint handling, CSI volume republishing, Secret-sourced binary environment values, and kubeadm certificate dry runs.

Source
Kubernetesv1.33.13Kubernetes CoreJun 12, 2026

A maintenance release updates the Go build dependency to Go 1.25.11 and fixes a panic in the endpoint controller when processing services with an empty IPFamilies field. The remaining release-note entries are section headings without operator-facing changes.

Source
Daprv1.16.15Orchestration & ManagementJun 11, 2026

This release contains a correctness fix for Sentry startup when using Ed25519 or RSA issuer keys. It also includes a dependency version update associated with that fix.

Source
Falco0.44.1SecurityJun 11, 2026

This release adds a capability to disable BPF iterators and fixes multiple BPF-iterator issues through a library dependency update. No security issue is disclosed.

Source
Envoyv1.38.2Networking & MessagingJun 10, 2026

This maintenance release adds HTTP/2 runtime controls and corrects runtime guard override handling. It also announces future removal of the HTTP/2 histogram feature and its runtime guard.

Plan ahead (1)

  • deprecatedFuture removal of envoy.reloadable_features.http2_record_histogramsremoval date not announced

    Applies if envoy.reloadable_features.http2_record_histograms is enabled.

Source
Envoyv1.37.4Networking & MessagingJun 10, 2026

This release adds HTTP/2 header-statistics histograms and a cookie-size limit, and fixes RTDS runtime guard override removal. The HTTP/2 histogram runtime guard is planned for removal in a future Envoy release.

Plan ahead (1)

  • deprecatedThe envoy.reloadable_features.http2_record_histograms histograms and runtime guard, planned for future removalremoval date not announced

    Applies if you use envoy.reloadable_features.http2_record_histograms.

Source
Envoyv1.36.8Networking & MessagingJun 10, 2026

A maintenance release corrects RTDS runtime-guard override behavior and adds opt-in HTTP/2 cookie and header capabilities. The existing HTTP/2 histogram capability and its runtime guard are announced for future removal.

Plan ahead (1)

  • deprecatedenvoy.reloadable_features.http2_record_histograms, future removalremoval date not announced

    Applies if you use envoy.reloadable_features.http2_record_histograms.

Source
Daprv1.18.0Orchestration & ManagementJun 10, 2026

A substantial operator-facing release adds workflow and MCP capabilities alongside control-plane, API, component, and lifecycle changes. It also includes security fixes, dependency and default updates, and compatibility constraints that affect upgrade planning and configuration review.

Action needed (8)

  • securitymediumThe golang.org/x/image dependency update for GO-2026-4962

    golang.org/x/image is updated to v0.39.0 for GO-2026-4962.

  • securityThe durabletask-go and pgx dependency updates

    durabletask-go is updated to v0.12.1, and pgx is updated as part of the vulnerability fixes.

  • breakingThe WorkflowsRemoteActivityReminder default, enabled

    WorkflowsRemoteActivityReminder is enabled by default. Cross-app workflow activity results are delivered through Scheduler reminders unless the setting is changed.

  • breakingThe HotReload default, enabled

    HotReload is enabled by default for Components, Subscriptions, MCPServers, Configurations, HTTPEndpoints, Resiliencies, and WorkflowAccessPolicies.

  • breakingSidecar probe defaults

    Sidecar probe defaults now give liveness more time before a kubelet restart, at about 230 seconds, while readiness responds more quickly.

  • breakingThe HotReload default, enabled in v1.18

    HotReload is enabled by default in v1.18.

  • breakingLiveness and readiness probe defaults

    The default liveness probe is widened, and the readiness probe default is tightened.

  • breakingChanged sidecar probe defaults

    Sidecar probe defaults now set liveness to be more lenient, at about 230 seconds before a kubelet restart, and readiness to be tighter, at about 3 seconds for the control plane and 5 seconds for daprd.

Check if affected (6)

  • securityService invocation path traversal ACL bypass fix

    Applies if you use service invocation.

  • breakingThe MCPServerResource and WorkflowAccessPolicy feature gates, removed

    Applies if you configure the MCPServerResource or WorkflowAccessPolicy feature gates.

  • breakingThe Sentry Ed25519 workload identity key rollback constraint

    Applicability is not stated in the release notes.

  • + 3 more on the release page

Plan ahead (1)

  • deprecatedThe ScheduleJobAlpha1 alpha RPCs, deprecated

    Applies if you use ScheduleJobAlpha1.

Source
Envoyv1.35.12Networking & MessagingJun 10, 2026

Envoy v1.35.12 contains an RTDS runtime-guard correction and opt-in HTTP/2 statistics and cookie-size controls. No security advisories or security-specific fixes are disclosed.

Source
Chaos Meshv2.8.3ObservabilityJun 10, 2026

A security-focused maintenance release includes undisclosed container-image CVE fixes and updates image components. It also corrects NetworkChaos recovery for targets in CrashLoopBackOff by falling back to the sandbox (pause) container PID for network namespace operations.

Action needed (2)

  • securityGo toolchain and containerd upgrades

    The Go toolchain (1.25.11) and containerd (1.7.32) were upgraded in the container images.

  • securitymemStress rebuild and headless JRE for chaos-daemon

    The memStress helper was rebuilt with the modern Go toolchain (v0.3.1), and the chaos-daemon image switched to a headless JRE.

Source
Crossplanev2.3.2Orchestration & ManagementJun 9, 2026

Crossplane v2.3.2 changes XR rendering and requirement handling, fixes stable sorting of resource references, and updates the crossplane-runtime dependency. It concerns releases that use these rendering, requirement, sorting, or dependency paths.

Source
NATSv2.12.11Networking & MessagingJun 9, 2026

A feature and behavior release for JetStream and server operations, with new capabilities alongside changed defaults and downgrade constraints. Operators using strict JetStream requests, insecure TLS cipher suites, or new v2.12 features should review the changed behavior; the release also fixes a JetStream regression.

Check if affected (3)

  • breakingInsecure TLS cipher suite default

    Applies if you enable allow_insecure_cipher_suites.

  • breakingJetStream strict mode default

    Applies if you use JetStream.

  • breakingDowngrade compatibility for new v2.12 features

    Applies if you use new v2.12 features.

Source
CoreDNSv1.14.4Kubernetes CoreJun 9, 2026

A release with new plugin capabilities, stricter validation, DNS and cache behavior changes, expanded platform support, and malformed-input handling fixes. The HTTP/3 request header limit is narrowed for DoH3.

Check if affected (1)

  • breakingBound DoH3 HTTP/3 request header size

    Applies if you use DoH3.

Source
← NewerOlder →
Browse by month