# RATATOSK

CNCFリリースノートの毎日のAI分析: 互換性の変更、セキュリティパッチ、そして何をすべきか。

検索とフィルター（プロジェクト・カテゴリ・期間）はウェブUIで利用できます: https://ratatosk.io/ja/releases

## 最近のリリース
- [Linkerd edge-26.8.3](https://ratatosk.io/ja/releases/linkerd/edge-26.8.3) — A maintenance release focused primarily on dependency version updates across the project. The Linkerd proxy is updated to v2.366.0, with no security advisories or operator-enforced breaking changes described. (2026-08-21)
- [Crossplane v1.20.12](https://ratatosk.io/ja/releases/crossplane/v1.20.12) — A maintenance release with security-related dependency and toolchain updates, along with routine dependency and runtime version changes. No advisory identifiers are stated. (2026-08-21) [action 5]
- [Crossplane v2.2.5](https://ratatosk.io/ja/releases/crossplane/v2.2.5) — A maintenance release corrects binary checksum generation and deletion-protection indexing, and updates dependencies for upstream CVE fixes. The changes affect release verification, webhook deletion checks, and the dependency set shipped with the release. (2026-08-21) [action 1]
- [Crossplane v2.3.5](https://ratatosk.io/ja/releases/crossplane/v2.3.5) — A maintenance release corrects binary checksum handling and the `Usage` index key, alongside updates to security-sensitive and build dependencies. The dependency changes require the new release, with no operator configuration migration stated. (2026-08-21) [action 4]
- [SPIRE v1.15.3](https://ratatosk.io/ja/releases/spire/v1.15.3) — This release adds attestors, plugins, configuration options, and CLI/API capabilities. It also updates dependencies and includes behavior changes and defect fixes, with no security advisories or explicitly described vulnerabilities. (2026-08-21)
- [hami v2.10.0](https://ratatosk.io/ja/releases/hami/v2.10.0) — A substantial operator-focused maintenance release with broad bug and behavior fixes, alongside new scheduling, device, configuration, and observability capabilities. It also updates security-relevant dependencies and the runtime/toolchain while removing obsolete functionality that may affect compatibility and configuration. (2026-08-21) [action 3, check 7]
- [Rook v1.20.6](https://ratatosk.io/ja/releases/rook/v1.20.6) — A maintenance release with a Ceph security advisory, a disabled Rook manager module, and clearer CephX fallback errors. Users of Ceph are advised to upgrade, while CephX key fallback failures now report the actual error. (2026-08-20) [check 2]
- [Rook v1.19.10](https://ratatosk.io/ja/releases/rook/v1.19.10) — A maintenance release with a security-driven Ceph upgrade recommendation and a disabled Rook manager module. It also adds or changes CephCluster and CephX error-reporting behavior. (2026-08-20) [action 1, check 1]
- [Crossplane v2.4.0](https://ratatosk.io/ja/releases/crossplane/v2.4.0) — A release with breaking operational changes, new runtime behavior, and correctness fixes. It also updates the Go toolchain and dependencies for security fixes, including changes that affect CLI publication, package operation, and resource deletion. (2026-08-20) [action 15, check 4, plan 1]
- [Kubernetes v1.36.4](https://ratatosk.io/ja/releases/kubernetes/v1.36.4) — A maintenance release with correctness fixes and a security-related dependency update. The dependency update is recorded in the manifest and has no standalone operator impact. (2026-08-20) [action 1]
- [Kyverno v1.19.0](https://ratatosk.io/ja/releases/kyverno/v1.19.0) — A substantial operator-facing release with new CLI, Helm, and policy capabilities alongside fixes and dependency updates. It also changes existing behavior through security fixes, deprecations, removals, and stricter constraints that may require review before upgrading. (2026-08-20) [action 7, check 6, plan 1]
- [Strimzi 1.2.0](https://ratatosk.io/ja/releases/strimzi/1.2.0) — This release removes legacy CRD API versions and resource state metrics, and changes defaults for token mounting, feature gates, and container security contexts. It also adds Kafka and configuration capabilities and updates shipped dependencies. (2026-08-20) [action 2, check 3]
- [Rook v1.19.9](https://ratatosk.io/ja/releases/rook/v1.19.9) — A maintenance release with security guidance for `CVE-2025–30156` and updates across Ceph authentication, core behavior, Multus networking, and the Ceph base image. The release also includes a workaround for a Ceph authentication rotation race. (2026-08-19) [action 1]
- [Rook v1.20.5](https://ratatosk.io/ja/releases/rook/v1.20.5) — A security-focused release with an advisory requiring Rook and Ceph upgrades. It also adds support for the new cephx key type, changes external version validation to ignore Ceph commit IDs, and fixes monitor registration in the v1 failover path. (2026-08-19) [check 1]
- [Keycloak 26.7.2](https://ratatosk.io/ja/releases/keycloak/26.7.2) — A maintenance release with disclosed security fixes, a cleartext vault-keystore password correction, a Quarkus dependency upgrade, and other bug corrections. The fixes cover account and permission flows, secret handling, and runtime dependencies. (2026-08-19) [action 2, check 6]
- [CoreDNS v1.14.7](https://ratatosk.io/ja/releases/coredns/v1.14.7) — A maintenance release with a Go toolchain update that includes disclosed CVE fixes, an ACL-check bypass correction, and changes to operator-visible defaults. It also adds features and corrects defects across the DNS server. (2026-08-19) [action 1, check 3]
- [Backstage v1.54.0](https://ratatosk.io/ja/releases/backstage/v1.54.0) — A broad release with dependency updates, breaking changes to commands, authentication patterns, and connection APIs, plus new AWS connection support and updates across the catalog, scaffolder, search, and UI. It also includes Kubernetes plugin security fixes and an undisclosed security announcement. (2026-08-18) [action 2, check 16, plan 3]
- [Cilium v1.20.1](https://ratatosk.io/ja/releases/cilium/v1.20.1) — A maintenance release with numerous operator-facing bug fixes and behavior corrections, alongside dependency and image updates. It also introduces a decoder-memory limit and fixes a CIDR policy bypass that could cause traffic drops after an agent restart. (2026-08-18) [check 1]
- [Cilium v1.19.7](https://ratatosk.io/ja/releases/cilium/v1.19.7) — A maintenance release with bug fixes, diagnostic improvements, dependency and image updates, and improved DNS request validation. It contains no security advisories or explicitly described vulnerabilities. (2026-08-18)
- [Cilium v1.18.13](https://ratatosk.io/ja/releases/cilium/v1.18.13) — A maintenance release that adds host-firewall protocol support, corrects networking and stability defects, and changes runtime behavior and observability. It also updates dependencies and container images, including a gRPC security fix with no disclosed vulnerability. (2026-08-18) [action 1]
- [Prometheus v3.14.0](https://ratatosk.io/ja/releases/prometheus/v3.14.0) — A maintenance release with an API deprecation, operator-visible removals and default changes, new capabilities, performance improvements, and correctness fixes across discovery, PromQL, TSDB, and other components. No security advisories or explicitly described security vulnerabilities are included. (2026-08-18) [action 1, check 1, plan 1]
- [Chaos Mesh v2.8.4](https://ratatosk.io/ja/releases/chaos-mesh/v2.8.4) — A maintenance release with fixes to operator-visible Dashboard behavior and Helm chart rendering. The changes address Dashboard serving, workflow schedule details, authentication, token controls, and extra-object template rendering. (2026-08-18)
- [OpenTelemetry v0.159.0](https://ratatosk.io/ja/releases/opentelemetry/v0.159.0) — A release that adds exporter queue batching controls, changes exporter and scraper metric behavior, and updates public API field shapes. Schema-based configuration migrations are also included, with no security advisories or security fixes disclosed. (2026-08-17) [check 2]
- [Open Policy Agent (OPA) v1.19.1](https://ratatosk.io/ja/releases/opa/v1.19.1) — A security-focused maintenance release updates the Go build dependency to `1.26.6` and addresses standard-library vulnerabilities used by OPA's HTTP handler and crypto builtins. Operators building their own binaries or images control the Go version used in those builds. (2026-08-17) [action 1]
- [Dapr v1.16.19](https://ratatosk.io/ja/releases/dapr/v1.16.19) — A maintenance release with an operator-relevant correctness fix. The remaining note concerns SPIFFE SVID authentication context passed to operation calls. (2026-08-15)
- [OpenFeature core/v0.16.2](https://ratatosk.io/ja/releases/openfeature/core%2Fv0.16.2) — A maintenance release with ordinary bug fixes across the project. No operator action is required beyond upgrading. (2026-08-14)
- [OpenFeature flagd-proxy/v0.9.8](https://ratatosk.io/ja/releases/openfeature/flagd-proxy%2Fv0.9.8) — A maintenance release for flagd-proxy resolves open Dependabot security alerts. The sync server also receives a gRPC keepalive enforcement policy update. (2026-08-14) [action 1]
- [OpenFeature flagd/v0.16.2](https://ratatosk.io/ja/releases/openfeature/flagd%2Fv0.16.2) — A maintenance release focused on bug fixes in eventing, eventstream connections, and evaluation metrics recording. The recorded fixes do not indicate any operator action beyond upgrading. (2026-08-14)
- [Dapr v1.18.3](https://ratatosk.io/ja/releases/dapr/v1.18.3) — A maintenance release with operator-facing correctness fixes, runtime behavior changes, a new configuration flag, and cron parser updates backed by a dependency change. It contains no security advisories or explicitly described vulnerabilities. (2026-08-14)
- [Linkerd edge-26.8.2](https://ratatosk.io/ja/releases/linkerd/edge-26.8.2) — A maintenance release with routine dependency updates, a destination informer correction, and policy-controller behavior changes. It also expands Kubernetes and Gateway API support, with no disclosed security advisories or security-specific fixes. (2026-08-14)
- [Longhorn v1.12.1](https://ratatosk.io/ja/releases/longhorn/v1.12.1) — A release with breaking behavior for legacy V2 linked-clone volumes, a Kubernetes v1.25 minimum, and stronger default network controls, including expanded mTLS enforcement. It also adds V2 data engine capabilities and metrics while correcting defects across V2 operations, backups, expansion, and infrastructure. (2026-08-14) [check 6, plan 1]
- [Rook v1.20.4](https://ratatosk.io/ja/releases/rook/v1.20.4) — A maintenance release with operator-facing behavior changes, compatibility improvements, and defect corrections. No security advisories or explicitly security-related fixes are mentioned. (2026-08-13)
- [Flatcar Container Linux lts-4081.3.10](https://ratatosk.io/ja/releases/flatcar/lts-4081.3.10) — A maintenance release with Linux security fixes identified by CVEs. It also updates the Linux and `ca-certificates` dependencies. (2026-08-13) [action 1]
- [Flatcar Container Linux stable-4593.2.5](https://ratatosk.io/ja/releases/flatcar/stable-4593.2.5) — A security-focused release with Linux and OpenSSH fixes identified by CVE advisories. It also updates versions of Linux, ca-certificates, and OpenSSH. (2026-08-13) [action 2]
- [Helm v4.2.4](https://ratatosk.io/ja/releases/helm/v4.2.4) — A maintenance release with correctness fixes and dependency updates tied to GO advisories. The changes affect Helm users through both general fixes and updated Go dependencies. (2026-08-13) [action 2]
- [Contour v1.33.6](https://ratatosk.io/ja/releases/contour/v1.33.6) — A maintenance release with a security fix for an external authorization bypass and dependency updates for CVE fixes. It also updates the tested Kubernetes range to 1.32 through 1.34, Go to 1.25.12, and Envoy to v1.38.3. (2026-08-12) [action 1, check 1]
- [containerd v2.2.7](https://ratatosk.io/ja/releases/containerd/v2.2.7) — A container runtime and CRI release that changes checkpoint-restore defaults and lifecycle, adds CRIU and Windows log-scrubbing configuration, and expands runtime support. It also includes fixes for CRI environment handling and mount-manager activation, plus dependency manifest updates that are not operator-facing. (2026-08-12) [check 3, plan 1]
- [containerd v2.3.4](https://ratatosk.io/ja/releases/containerd/v2.3.4) — A container runtime release with changes to CRI behavior, checkpoint restore handling, and configuration. It also adds CRI capabilities and fixes runtime and snapshotter defects. (2026-08-12) [check 3, plan 1]
- [NATS v2.14.5](https://ratatosk.io/ja/releases/nats/v2.14.5) — NATS v2.14.5 updates the Go toolchain and two dependencies, and adds a configurable `leafnode` dial timeout for high-latency links. It fixes a logger deadlock and a JetStream defect involving idempotent stream creation, with no security advisories or security-specific fixes disclosed. (2026-08-12)
- [NATS v2.12.15](https://ratatosk.io/ja/releases/nats/v2.12.15) — NATS v2.12.15 updates the Go toolchain and dependency manifests. It also fixes deadlocks in logging and a JetStream data-loss bug related to idempotent stream creation when an offline node catches up from a metalayer snapshot. (2026-08-12)
- [Argo v3.5.1](https://ratatosk.io/ja/releases/argo/v3.5.1) — This release contains routine correctness fixes and a security fix in the server. The security change concerns users of the `SSD CLI`. (2026-08-12) [action 1]
- [Argo v3.4.7](https://ratatosk.io/ja/releases/argo/v3.4.7) — A maintenance release with correctness fixes, a server-side secret-mask spoofing fix, and a third-party dependency update. Ordinary fixes and the dependency update require no operator action, while upgrading addresses the security fix. (2026-08-12) [action 1]
- [Argo v3.3.14](https://ratatosk.io/ja/releases/argo/v3.3.14) — A maintenance release with fixes for secret masking and pprof endpoint configuration, alongside dependency updates for two listed CVEs. The secret-handling fixes and dependency updates are addressed by upgrading, while the remaining defect fixes require no operator action. (2026-08-12) [action 2, check 2]
- [CubeFS v3.6.0](https://ratatosk.io/ja/releases/cubefs/v3.6.0) — A feature and maintenance release with expanded metadata, migration, storage-pool, learner, self-healing, proximity-read, and RocksDB capabilities. Operators need to follow the stated upgrade order and prerequisites; the release also contains corrective fixes, with no security advisories or explicit security flaws disclosed. (2026-08-12)
- [Kubescape v4.0.12](https://ratatosk.io/ja/releases/kubescape/v4.0.12) — A corrective and performance-focused release with operator-visible default and constraint changes, deprecated flag removal, and dependency vulnerability fixes. It also expands scanning, output, registry, and MCP capabilities. (2026-08-12) [action 3, check 3]
- [wasmCloud v2.7.0](https://ratatosk.io/ja/releases/wasmcloud/v2.7.0) — wasmCloud v2.7.0 adds runtime, networking, plugin, TLS, and chart capabilities while correcting runtime and Helm/chart defects. It also changes defaults and updates dependencies. (2026-08-11) [action 1]
- [OpenKruise v1.8.5](https://ratatosk.io/ja/releases/openkruise/v1.8.5) — OpenKruise v1.8.5 corrects nodeimage TTL cleanup so setting `completionPolicy.ttlSecondsAfterFinished` does not delete the job itself. It adds the `default-ttlseconds-for-always-nodeimage` flag for `kruise-controller-manager` to control nodeimage data TTL. (2026-08-10)
- [Buildpacks v0.40.9](https://ratatosk.io/ja/releases/buildpacks/v0.40.9) — This release updates dependencies associated with published security advisories. Builders created with the pack CLI from this release contain lifecycle v0.21.0 by default. (2026-08-09) [action 3]
- [Flux v2.9.4](https://ratatosk.io/ja/releases/flux/v2.9.4) — A maintenance release with correctness fixes that narrow some existing configuration constraints. It also adds CLI repository migration support and updates dependencies; no explicit security advisory or vulnerability is disclosed. (2026-08-07) [check 3]
- [Dapr v1.17.12](https://ratatosk.io/ja/releases/dapr/v1.17.12) — This release contains a security-related build toolchain update and an input-binding startup fix. The probe timeout is configurable for applications with slow startup. (2026-08-06) [action 1]
