Crossplane
v2.4.1Orchestration & Management2026年9月15日
パッケージリビジョン間の引き継ぎ修正と、依存関係のセキュリティ更新を含むメンテナンスリリースです。gRPCの勧告への対応やツールチェーンの更新も行われています。
要対応 (3)
securityhigh
google.の更新golang. org/grpc google.をgolang. org/grpc v1.へ更新し、上流のCVE修正を取り込みます。gRPCの勧告GHSA-2v4p-qf9q-27wjも対象です。83. 2 securityGo toolchainと依存関係のセキュリティ更新
Go toolchainを
1.へ更新し、上流で修正されたCVEを取り込みます。あわせて26. 7 google.をgolang. org/grpc v1.、83. 2 golang.をorg/x/crypto v0.へ更新し、56. 0 github.をcom/crossplane/crossplane/apis/v2 v2.へ更新、ロックファイルも刷新しています。4. 0 security
golang.の更新org/x/crypto golang.をorg/x/crypto v0.へ更新し、上流で修正されたCVEを取り込みます。Go toolchainは56. 0 1.、26. 7 google.はgolang. org/grpc v1.へ更新され、83. 2 github.の更新とロックファイルの刷新も行われています。com/crossplane/crossplane/apis/v2
その他の記録済み変更 2 件すべてfixes 1 · value changes 1
fixes (1)
- * **Package revisions now take control of established objects from the revision they replace:** An outgoing package revision could fail to relinquish control of the package's CRDs, leaving the incoming revision permanently unhealthy with
cannot establish control of object. The provider's pod would never be created, so that provider could do no work without manual intervention by someone either deleting the stale revision or editing the CRD's owner reference by hand. Package revisions now directly take control from the revision they replace, so the hand-off succeeds without any intervention. Backported in #7821, originally fixed in #7733.
value changes (1)
- * **Dependency security updates:** Bumps the Go toolchain to
1.(#7803),26. 7 google.togolang. org/grpc v1.(#7800, #7826), and83. 2 golang.toorg/x/crypto v0.(#7810) to pick up upstream CVE fixes — including the gRPC advisory [GHSA-2v4p-qf9q-27wj](https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj). Also bumps56. 0 github.tocom/crossplane/crossplane/apis/v2 v2.(#7780) and refreshes the lock file (#7779).4. 0
Crossplaneをスタックに追加
対応が必要なリリースが出たときに、週次メールでお知らせします。 今回のセキュリティパッチも、その一例です。