A maintenance release with ordinary bug fixes across the project. No operator action is required beyond upgrading.
Source ↗Releases
AI-analyzed release notes for CNCF graduated and incubating projects.
A maintenance release for flagd-proxy resolves open Dependabot security alerts. The sync server also receives a gRPC keepalive enforcement policy update.
Action needed (1)
securityOpen Dependabot security alerts resolved
Open Dependabot security alerts are resolved in flagd-proxy v0.9.8.
A maintenance release focused on bug fixes in eventing, eventstream connections, and evaluation metrics recording. The recorded fixes do not indicate any operator action beyond upgrading.
Source ↗This release combines ordinary bug fixes with security-related updates. It also improves blob/HTTP synchronization, with no announced operator-facing removals, deprecations, or default changes.
Action needed (2)
securityThe
google.module update to v1.82.1golang. org/grpc The
google.module is updated to v1.82.1 in core v0.16.1.golang. org/grpc securityThe
vulnerability-updatesupdatevulnerability-updatesis updated in core v0.16.1.
A maintenance release with a bug-fix heading, a new server timeout setting, dependency updates, and security-related updates. The google. update requires upgrading.
Action needed (2)
securityThe
google.module, updated to v1.82.1golang. org/grpc The
google.module is updated to v1.82.1 as a security-related dependency change.golang. org/grpc securityThe
vulnerability-updatesdependency updateThe release updates
vulnerability-updatesas a security-related dependency change.
flagd/v0. combines bug fixes with security dependency updates and a configurable sync-server capability. The security notes do not include advisory identifiers or flaw details, while the sync-server changes include server timeouts and configurable gRPC keepalive enforcement.
Action needed (3)
securitySecurity dependency updates
Security dependencies are updated in
flagd/v0..16. 1 securityThe
google.module updategolang. org/grpc The
google.module is updated togolang. org/grpc v1.in82. 1 flagd/v0..16. 1 securityVulnerability updates
Vulnerability updates are included in
flagd/v0.as a security change.16. 1
Core v0.16.0 changes disabled-flag evaluations from returning an error to succeeding with reason DISABLED; resolved values remain unchanged and still use the caller-provided default. The compatibility change affects consumers that inspect reason or errorCode, call flagd directly over gRPC or OFREP, or import core/pkg/model.
flagd v0.16.0 changes evaluation of disabled flags. Disabled flags now resolve successfully with reason=DISABLED instead of returning a FLAG_DISABLED error.
This release contains an operator-facing bug fix. The documented fix addresses a panic when an S3 URI includes a query string.
Source ↗This release contains an operator-facing bug fix for flagd. It addresses a panic when an S3 URI includes a query string.
Source ↗This release is labeled as containing new features, but the supplied release note does not describe a specific operator-facing change. No detailed feature behavior or affected component is stated.
Source ↗This release adds support for custom headers in the OpenFeature flagd proxy. The recorded changes do not include a specific implementation item for this release.
Source ↗This release adds support for custom headers in flagd. The remaining release-note entry is a heading without a recorded change detail.
Source ↗This release contains no described operator-facing changes. No release-note details are provided for this version.
Source ↗OpenFeature core/v0.15.5 is a maintenance release with operator-relevant corrections and a security-related dependency update. The security announcement does not identify a specific advisory in the release text.
Action needed (1)
securityOpen Dependabot security alerts resolved
Open Dependabot security alerts were resolved in the OpenFeature core release.
This release resolves open Dependabot security alerts in the flagd proxy. The release note does not identify which vulnerabilities or dependencies were fixed.
Action needed (1)
securityDependabot security alerts resolved
The
flagd-proxy/v0.release resolves open Dependabot security alerts. The release note does not identify the affected dependencies or vulnerabilities.9. 5
flagd/v0.15.5 is a maintenance release with operator-facing corrections and a value update. No security advisories or explicit security issues are identified.
Source ↗This release contains no operator-facing change details. No specific flags, fields, resources, or other release behavior are described.
Source ↗This release note contains only section headings and no operator-facing change details. No specific changes are described for flagd/v0.15.4.
Source ↗Core v0.15.3 combines new feature work with bug fixes. Its changes include metadata support in kubernetes_sync and support for a single entry in the fractional operator.
This release contains no described operator-facing changes. No release note details indicate a change that would affect operator use of flagd.
Source ↗This release contains two security updates whose affected vulnerabilities are not identified. It also adds experimental incremental updates for gRPC synchronization.
Action needed (1)
securityThe
vulnerability-updatessecurity updateOpenFeature Core v0.15.2 includes a security update for
vulnerability-updates.
This release contains security updates for flagd-proxy/v0.. The available notes do not identify the affected vulnerabilities or describe their scope.
Action needed (2)
securityThe
vulnerability-updatesentry for issue#1933The
vulnerability-updatesentry records a security update forflagd-proxy/v0., tracked in issue9. 4 #1933. The notes do not describe the affected vulnerability.securityThe
vulnerability-updatesentry for issue#1934The
vulnerability-updatesentry records a security update forflagd-proxy/v0., tracked in issue9. 4 #1934. The notes do not describe the affected vulnerability.
flagd v0.15.2 includes two undisclosed security updates and a new experimental gRPC incremental-update capability. The experimental addition concerns deployments that use gRPC synchronization.
Action needed (2)
securityThe
vulnerability-updatessecurity update for issue#1933flagd v0.15.2 includes the
vulnerability-updatessecurity update linked to issue#1933.securityThe
vulnerability-updatessecurity update for issue#1934flagd v0.15.2 includes the
vulnerability-updatessecurity update linked to issue#1934.
Release 0.15.1 fixes a memory leak caused by unbounded metrics cardinality and updates a dependency for an undisclosed security fix. The dependency update ships in the core v0.15.1 release.
Action needed (1)
securityThe
github.dependency updatecom/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 for a security fix. This change ships in core v0.15.1.com/go-jose/go-jose/v4
This release includes a security update to the github. dependency. The release note does not disclose the nature of the vulnerability.
Action needed (1)
security
github.updated to v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 in flagd-proxy v0.9.3 as a security fix. The note does not disclose the nature of the vulnerability.com/go-jose/go-jose/v4
This release fixes RPC flag defaulting, metrics-server process handling, and unbounded metrics cardinality. It also updates a dependency for an undisclosed security fix, which is the main consideration for users evaluating the release.
Action needed (1)
securityThe
github.dependency, updated to v4.1.4com/go-jose/go-jose/v4 The
github.module is updated to v4.1.4 incom/go-jose/go-jose/v4 flagd/v0.for an undisclosed security fix.15. 1
This release changes fractional bucketing behavior in flagd. The provided release information does not describe the operator setup affected by the change.
Source ↗A fractional bucketing update changes pseudorandom assignments without changing the API. Consistent assignments require all providers to be updated.
Check if affected (1)
breakingFractional pseudorandom bucketing assignments
Applies if you use providers.
Fractional bucketing improvements in flagd/v0.15.0 change fractional pseudorandom assignments while leaving the API unchanged. Consistent assignments require all providers to be updated.