Crossplane
v2.2.5Orchestration & Management2026年8月21日
運用者向けには、配布物の検証や削除保護に関する不具合修正と、依存関係のセキュリティ更新が含まれます。依存関係の更新では、上流のCVE修正が取り込まれています。
要対応 (1)
security依存関係のセキュリティ更新
上流のCVE修正を取り込むため、
cel-go(#7760)、golang.(org/x/mod #7742)、sigstore-go(#7677)、go-git(#7724)を更新しました。脆弱性のある依存関係をまとめて更新する変更(#7649)も含まれます。さらに、独自のセキュリティ依存関係更新を含むcrossplane-runtimeをv2.(2. 4 #7766)へ更新しました。
その他の記録済み変更 2 件すべてfixes 2
fixes (2)
- * **Correct
crankchecksums foramd64binaries (#7665, originally #7660):** The published.files forsha256 linux_amd64binaries had not matched the binaries themselves sincev2., so any install script or Dockerfile that verified the2. 0 amd64checksum failed. Checksums are now calculated after Nix strips the binary, and the release workflow verifies them before uploading. Fixes #7467. - * **Unambiguous
Usageindex key (#7629, originally #7508):** The deletion protection webhook indexedUsageresources by joining API group, kind, name, and namespace with.. Since groups and names can contain.themselves, two distinct resources could collapse to the same key, causing the webhook to block a deletion that should have been allowed. The key now joins with/, which cannot appear in any of those fields.
Crossplaneをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。