This release fixes issues for SREs watching stability and regressions.
✓ No known CVEs patched in this version
Topics
+6 more
Affected surfaces
Summary
AI summaryUpdates π Bug Fixes ci, π Subtasks version, and π Build across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Handle `,`, `;`, and `:` in filenames, throwing at creation if file name does not respect regex. Handle `,`, `;`, and `:` in filenames, throwing at creation if file name does not respect regex. Source: granite4.1:8b-q6_K@2026-05-19 Confidence: low |
β |
| Feature | Medium |
Validate filenames to allow `,`, `;`, and `:` while rejecting nonβmatching regex names at creation. Validate filenames to allow `,`, `;`, and `:` while rejecting nonβmatching regex names at creation. Source: granite4.1:30b@2026-05-19-audit Confidence: low |
β |
| Bugfix | Medium |
Replace GH_PERSONAL_TOKEN with GitHub App installation tokens in CI. Replace GH_PERSONAL_TOKEN with GitHub App installation tokens in CI. Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
β |
| Bugfix | Medium |
Do not render Service when only workerGroups are enabled in Helm. Do not render Service when only workerGroups are enabled in Helm. Source: granite4.1:8b-q6_K@2026-05-19 Confidence: high |
β |
| Bugfix | Medium |
ParenTransversalGuard now handles encoded characters in storage. ParenTransversalGuard now handles encoded characters in storage. Source: granite4.1:8b-q6_K@2026-05-19 Confidence: low |
β |
Full changelog
Changelog
π Subtasks
version
- 0f19f95 update to version '1.3.18'
π Bug Fixes
ci
- 310aaf1 replace GH_PERSONAL_TOKEN with GitHub App installation tokens (#16044), closes #16044
helm
- 57a8b0e do not render Service when only workerGroups are enabled (#16032), closes #16032
storage
- c0e5499 parenTransversalGuard was not handling encoded characters
global
- bbf381b handle
,,;and:in filename and throw at creation if file doesnt respect regex name (#16084), closes #14224 #16084
π Build
- ae12df9 setup tags develocity on this release branch
Contributors
We'd like to thank the following people for their contributions:
GitHub, PERREYMOND Gilles, Roman Acevedo, YannC, YannC., brian-mulier-p, github-actions[bot]
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About kestra
Event Driven Orchestration & Scheduling Platform for Mission Critical Applications
Beta — feedback welcome: [email protected]