This release keeps dependencies and maintenance posture current for teams operating this tool.
✓ No known CVEs patched in this version
Topics
Summary
AI summaryMinor fixes and improvements.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | High |
Container images are signed with cosign and GitHub OIDC. Container images are signed with cosign and GitHub OIDC. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Adds container image support for linux/arm/v7 architecture. Adds container image support for linux/arm/v7 architecture. Source: llm_adapter@2026-07-13 Confidence: high |
— |
| Feature | Low |
Provides container images from docker.io/fluxcd/source-controller:v1.9.3. Provides container images from docker.io/fluxcd/source-controller:v1.9.3. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Provides container images from ghcr.io/fluxcd/source-controller:v1.9.3. Provides container images from ghcr.io/fluxcd/source-controller:v1.9.3. Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
| Feature | Low |
Enables verification of image provenance (SLSA level 3). Enables verification of image provenance (SLSA level 3). Source: granite4.1:30b@2026-07-14-audit Confidence: low |
— |
Full changelog
Changelog
Container images
docker.io/fluxcd/source-controller:v1.9.3ghcr.io/fluxcd/source-controller:v1.9.3
Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Related tools
Beta — feedback welcome: [email protected]