This release includes 1 breaking change for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
Affected surfaces
ReleasePort's take
Moderate signalThe release restricts server‑side path reads to stdio transport in kubectl_apply, kubectl_delete, and Helm chart tools.
Why it matters: Security: mitigates unintended file access across affected Kubernetes tooling with high severity (90).
Summary
AI summaryServer‑side path reads are restricted to the stdio transport in kubectl_apply, kubectl_delete, and Helm chart tools
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Restricts server-side path reads to stdio transport in kubectl_apply, kubectl_delete, and Helm chart tools. Restricts server-side path reads to stdio transport in kubectl_apply, kubectl_delete, and Helm chart tools. Source: llm_adapter@2026-07-18 Confidence: high |
— |
Full changelog
Restrict server-side path reads (filename/valuesFile) to the stdio transport in kubectl_apply, kubectl_delete, and Helm chart tools (#346)
Breaking Changes
- Server‑side path reads (filename/valuesFile) now limited to stdio transport in kubectl_apply, kubectl_delete, and Helm chart tools
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]