Crossplane
v2.3.5Orchestration & Management2026年8月21日
チェックサムと `Usage` インデックスの不具合を修正し、セキュリティ関連の依存関係とビルド依存関係を更新したリリースです。セキュリティ関連の依存関係を利用している場合はアップグレードが必要ですが、オペレーター設定の移行についての記載はありません。
要対応 (4)
security
golang.の更新org/x/mod 依存モジュール
golang.が更新されました。org/x/mod security
github.をcom/sigstore/sigstore-go v1.に更新2. 1 依存モジュール
github.がcom/sigstore/sigstore-go v1.に更新されました。2. 1 security
github.をcom/google/cel-go v0.に更新30. 0 依存モジュール
github.がcom/google/cel-go v0.に更新されました。30. 0 security
crossplane-runtimeをv2.に更新3. 4 crossplane-runtimeがv2.に更新されました。3. 4
その他の記録済み変更 4 件すべてfixes 2 · value changes 2
fixes (2)
- **Correct
crankchecksums foramd64binaries (#7666, originally #7660):** The published.files forsha256 linux_amd64binaries had not matched the binaries themselves sincev2., so any install script or Dockerfile that verified the2. 0 amd64checksum failed. Checksums are now calculated after Nix strips the binary, and the release workflow verifies them before uploading. Fixes #7467. - **Unambiguous
Usageindex key (#7630, originally #7508):** The deletion protection webhook indexedUsageresources by joining API group, kind, name, and namespace with.. Since groups and names can contain.themselves, two distinct resources could collapse to the same key, causing the webhook to block a deletion that should have been allowed. The key now joins with/, which cannot appear in any of those fields.
value changes (2)
- [Backport release-2.3] build: point docker-client at docker_29 in the nix overlay
- [Backport release-2.3] build: bump pinned nixpkgs channel from nixos-25.11 to nixos-26.05
Crossplaneをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。