Crossplane
v2.2.6Orchestration & Management2026年9月15日
依存関係の更新で上流の CVE 修正を取り込む、セキュリティ重視のメンテナンスリリースです。パッケージリビジョンの引き継ぎも修正され、置き換え対象のリビジョンから所有権を引き継ぐ処理が手動介入なしで完了します。
要対応 (3)
securityhigh
google.の更新golang. org/grpc google.をgolang. org/grpc v1.に更新し、gRPC の勧告 GHSA-2v4p-qf9q-27wj を含む上流の CVE 修正を取り込みます。83. 2 securityGo toolchain の更新
Go toolchain を
1.に更新し、上流の CVE 修正を取り込みます。ロックファイルも更新されます。26. 7 security
golang.の更新org/x/crypto golang.をorg/x/crypto v0.に更新し、上流の CVE 修正を取り込みます。56. 0
その他の記録済み変更 1 件すべてfixes 1
fixes (1)
- * **Package revisions now take control of established objects from the revision they replace:** An outgoing package revision could fail to relinquish control of the package's CRDs, leaving the incoming revision permanently unhealthy with
cannot establish control of object. The provider's pod would never be created, so that provider could do no work without manual intervention by someone either deleting the stale revision or editing the CRD's owner reference by hand. Package revisions now directly take control from the revision they replace, so the hand-off succeeds without any intervention. Backported in #7828, originally fixed in #7733.
Crossplaneをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。