# Crossplane v2.2.5

> Orchestration & Management · 2026-08-21

A maintenance release corrects binary checksum generation and deletion-protection indexing, and updates dependencies for upstream CVE fixes. The changes affect release verification, webhook deletion checks, and the dependency set shipped with the release.

## Action needed
- **[security]** Dependency security updates
  - The release updates `cel-go`, `golang.org/x/mod`, `sigstore-go`, and `go-git`, along with a combined set of vulnerable dependency updates, to pick up upstream CVE fixes. It also bumps `crossplane-runtime` to `v2.2.4`, which carries its own security dependency updates.

## Other recorded changes
- 2 (defect_corrected 2)

[Full analysis](https://ratatosk.io/en/releases/crossplane/v2.2.5)

[Original release notes](https://github.com/crossplane/crossplane/releases/tag/v2.2.5)
