RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: FluxClear ×
Fluxv2.9.4CI/CD & App DeliveryAug 7, 2026

A maintenance release with correctness fixes that narrow some existing configuration constraints. It also adds CLI repository migration support and updates dependencies; no explicit security advisory or vulnerability is disclosed.

Check if affected (3)

  • breakingThe image-automation-controller refspec constraint

    Applies if you configure refspecs.

    The image-automation-controller disallows force updates and deletions through refspecs.

  • breakingGCS static authentication limited to service account keys

    Applies if you configure GCS static authentication.

    The source-controller limits GCS static authentication to service account keys.

  • breakingThe allow-webhooks network policy restriction

    Applies if you configure allow-webhooks.

    In release/v2.9.x, the allow-webhooks network policy is restricted to the receiver port.

Source
Fluxv2.9.3CI/CD & App DeliveryJul 23, 2026

Flux v2.9.3 is a maintenance release with correctness fixes, updated dependencies, and a newly included component in the OCI artifact. No security advisories are disclosed.

Source
Fluxv2.9.2CI/CD & App DeliveryJul 13, 2026

Flux v2.9.2 includes an operator-relevant regression fix for Kustomizations whose openapi.path points to a URL, along with dependency and toolkit component updates. CRD description corrections are documentation-only.

Source
Fluxv2.9.1CI/CD & App DeliveryJul 7, 2026

Flux v2.9.1 is a maintenance release focused on defect fixes, dependency and component updates, and a performance improvement. It includes changes across controller behavior and build and decryption paths, with no security advisories disclosed.

Source
Fluxv2.9.0CI/CD & App DeliveryJun 30, 2026

Flux v2.9.0 removes two deprecated API versions and adds CLI and controller capabilities across several Flux resources. It also changes supported Kubernetes versions, corrects defects, and updates project and third-party dependencies.

Check if affected (1)

  • breakingRemoval of deprecated Flux API versions

    Applies if your CRDs use the image.toolkit.fluxcd.io/v1beta2 or notification.toolkit.fluxcd.io/v1beta2 APIs.

    The Flux APIs image.toolkit.fluxcd.io/v1beta2 and notification.toolkit.fluxcd.io/v1beta2 have reached end of life and are removed from the CRDs in Flux v2.9.0.

Source
Fluxv2.8.7CI/CD & App DeliveryMay 12, 2026

Flux v2.8.7 includes a security update to the go-git dependency alongside toolkit component updates. The go-git update addresses CVE-2026-45022 and GHSA-389r-gv7p-r3rp.

Action needed (1)

  • securityhighThe go-git dependency update to v5.19.0

    The go-git dependency is updated to v5.19.0, which fixes CVE-2026-45022 and addresses GHSA-389r-gv7p-r3rp. This update ships in Flux v2.8.7.

Source
Fluxv2.8.6CI/CD & App DeliveryApr 21, 2026

This is an operator-focused maintenance release with fixes and configuration constraints across controllers. It also adds a feature gate and updates dependency and toolkit components.

Check if affected (1)

  • breakingRequired audience field on the GCR Receiver secret

    Applies if you configure the audience field on the GCR Receiver secret.

    The audience field is required on the GCR Receiver secret in notification-controller. It will become mandatory in Flux v2.9.

Source
Fluxv2.8.5CI/CD & App DeliveryApr 7, 2026

Flux v2.8.5 is a maintenance release with bug fixes, clearer error reporting, added verification and authentication configuration, and updated toolkit components. No security advisories or explicitly described security vulnerabilities are present.

Source
Fluxv2.8.4CI/CD & App DeliveryApr 7, 2026

Flux v2.8.4 includes fixes for Windows support and --source validation, along with updates to Flux dependencies. These changes concern users of the affected commands and dependency consumers.

Source
Fluxv2.8.2CI/CD & App DeliveryMar 12, 2026

Flux v2.8.2 includes correctness fixes and dependency updates. It also fixes a disclosed TLS-handshake denial-of-service issue in the controller builds.

Action needed (1)

  • securitymediumCVE-2026-27138 TLS-handshake DoS fix

    The TLS-handshake denial-of-service issue identified as CVE-2026-27138 is fixed by building all controllers with Go 1.26.1.

Source
Fluxv2.8.1CI/CD & App DeliveryFeb 27, 2026

Flux v2.8.1 is a maintenance release focused on operator-relevant defect fixes and updates to Flux dependencies and components. No security advisories are disclosed.

Source
Fluxv2.8.0CI/CD & App DeliveryFeb 24, 2026

Flux v2.8.0 expands capabilities across controllers, notifications, the CLI, and artifact handling while also including fixes and dependency updates. It removes the deprecated API versions v1beta2 and v2beta2 from CRDs and changes Kubernetes compatibility requirements, so users of those APIs or affected Kubernetes versions are the main audience.

Check if affected (1)

  • breakingThe Flux APIs v1beta2 and v2beta2, removed from CRDs

    Applies if you use the Flux APIs v1beta2 or v2beta2 in CRDs.

    The deprecated Flux APIs v1beta2 and v2beta2 have reached end of life and are removed from the CRDs in v2.8.0.

Source
Browse by month