securityThe github.com/containerd/containerd dependency, updated
The github.com/containerd/containerd module is updated to v1.7.29.
securityThe github.com/go-viper/mapstructure/v2 dependency, updated
The github.com/go-viper/mapstructure/v2 module is updated to v2.4.0.
securityThe github.com/docker/docker dependency, updated
The github.com/docker/docker module is updated to v28.3.3+incompatible.
securityThe golang.org/x/crypto dependency, updated
The golang.org/x/crypto module is updated to v0.45.0.
securityThe helm.sh/helm/v3 dependency, updated to v3.18.4
The helm.sh/helm/v3 module is updated to v3.18.4.
securityThe helm.sh/helm/v3 dependency, updated to v3.18.5
The helm.sh/helm/v3 module is updated to v3.18.5.
breakingThe plpmtud default, set to blackhole
The default plpmtud mode is now blackhole (blackhole-detected).
breakingThe AddressScopeMax default, set to 254
The default AddressScopeMax is changed to 254, the host scope, for GKE metadata server and HCP use cases. The related setting is --local-max-addr-scope.
breakingThe tls authMode default, set to migration
tls authMode is set to migration by default.
breakingThe CNI deletion timeout, reduced to 1.5 seconds
The CNI deletion timeout is reduced to 1.5 seconds.
breakingThe policy-default-local-cluster default
policy-default-local-cluster is now set by default.
breakingHost firewall bypass, disabled by default
Host firewall bypass is disabled by default.
breakingFQDN match pattern sanitization
FQDN match pattern sanitization is refactored and tightened.
breakingEncrypted traffic forwarding via cilium_host, removed
Forwarding encrypted traffic via cilium_host has been removed.
breakingCNI configuration in the container image, removed
The CNI configuration is no longer installed in the container image.