Crossplane
v2.4.1Orchestration & Management2026년 9월 15일
패키지 리비전 교체 과정의 제어권 인계 문제를 고치고 의존성 보안 업데이트를 반영한 유지 보수 릴리스입니다. 도구 체인과 `gRPC` 관련 권고 사항을 포함해 의존성 버전과 잠금 파일을 갱신했습니다.
조치 필요 (3)
securityhigh
google.보안 버전 갱신golang. org/grpc google.를golang. org/grpc v1.로 올려 상위 프로젝트의83. 2 CVE수정 사항을 반영했습니다. GHSA-2v4p-qf9q-27wj 보안 권고도 반영 대상에 포함됩니다.securityGo 도구 체인
1.갱신26. 7 Go 도구 체인을
1.로 갱신해 상위 프로젝트의26. 7 CVE수정 사항을 반영했습니다.security
golang.보안 버전 갱신org/x/crypto golang.를org/x/crypto v0.으로 갱신해 상위 프로젝트의56. 0 CVE수정 사항을 반영했습니다.
그 외 기록된 변경 2건 전체fixes 1 · value changes 1
fixes (1)
- * **Package revisions now take control of established objects from the revision they replace:** An outgoing package revision could fail to relinquish control of the package's CRDs, leaving the incoming revision permanently unhealthy with
cannot establish control of object. The provider's pod would never be created, so that provider could do no work without manual intervention by someone either deleting the stale revision or editing the CRD's owner reference by hand. Package revisions now directly take control from the revision they replace, so the hand-off succeeds without any intervention. Backported in #7821, originally fixed in #7733.
value changes (1)
- * **Dependency security updates:** Bumps the Go toolchain to
1.(#7803),26. 7 google.togolang. org/grpc v1.(#7800, #7826), and83. 2 golang.toorg/x/crypto v0.(#7810) to pick up upstream CVE fixes — including the gRPC advisory [GHSA-2v4p-qf9q-27wj](https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj). Also bumps56. 0 github.tocom/crossplane/crossplane/apis/v2 v2.(#7780) and refreshes the lock file (#7779).4. 0
Crossplane 스택에 추가
조치가 필요한 릴리스가 나왔을 때 주간 메일로 알려드립니다. 이번 릴리스의 보안 패치 같은 것들입니다.