Crossplane
v2.3.5Orchestration & Management2026년 8월 21일
체크섬과 `Usage` 인덱스 결함을 바로잡고, 보안에 관련된 의존성과 빌드 의존성을 변경했습니다. 보안 의존성 업데이트를 적용하려면 업그레이드가 필요하며, 운영자 설정 마이그레이션은 명시되지 않았습니다.
조치 필요 (4)
security
golang.의존성 업데이트org/x/mod 보안 관련 의존성인
golang.가 업데이트되었습니다.org/x/mod security
github.v1.2.1 업데이트com/sigstore/sigstore-go 보안 관련 의존성
github.가 v1.2.1로 업데이트되었습니다.com/sigstore/sigstore-go security
github.v0.30.0 업데이트com/google/cel-go 보안 관련 의존성
github.가 v0.30.0으로 업데이트되었습니다.com/google/cel-go security
crossplane-runtimev2.3.4 업데이트crossplane-runtime이 v2.3.4로 업데이트되었습니다.
그 외 기록된 변경 4건 전체fixes 2 · value changes 2
fixes (2)
- **Correct
crankchecksums foramd64binaries (#7666, originally #7660):** The published.files forsha256 linux_amd64binaries had not matched the binaries themselves sincev2., so any install script or Dockerfile that verified the2. 0 amd64checksum failed. Checksums are now calculated after Nix strips the binary, and the release workflow verifies them before uploading. Fixes #7467. - **Unambiguous
Usageindex key (#7630, originally #7508):** The deletion protection webhook indexedUsageresources by joining API group, kind, name, and namespace with.. Since groups and names can contain.themselves, two distinct resources could collapse to the same key, causing the webhook to block a deletion that should have been allowed. The key now joins with/, which cannot appear in any of those fields.
value changes (2)
- [Backport release-2.3] build: point docker-client at docker_29 in the nix overlay
- [Backport release-2.3] build: bump pinned nixpkgs channel from nixos-25.11 to nixos-26.05
Crossplane 스택에 추가
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.