✓ No known CVEs patched
This release patches 5 known CVEs
Topics
cloudnative
grafana
logging
prometheus
Affected surfaces
deps
Summary
AI summaryUpdates Bug Fixes, release-3.7.x, and 3.7.4 across a mixed release.
Full changelog
3.7.4 (2026-07-22)
Bug Fixes
- ci: Fix zizmor findings for operator-images in Loki 3.7 (#22820) (abc1186)
- ci: Helm CI warning fix (#22605) (7389428)
- ci: Re-enable docker plugin publishing (#22818) (28f44a8)
- compactor: Fix delete request when using Thanos objstore client with filesystem backend [release-3.7.x] (#22811) (dd6fdb5)
- deps: Update module charm.land/bubbletea/v2 to v2.0.7 (release-3.7.x) (#22768) (e11f935)
- deps: Update module charm.land/lipgloss/v2 to v2.0.4 (release-3.7.x) (#22769) (10213c2)
- deps: Update module github.com/aws/aws-sdk-go-v2/credentials to v1.19.24 (release-3.7.x) (#22776) (3daf198)
- deps: Update module github.com/aws/smithy-go to v1.27.3 (release-3.7.x) (#22795) (1f6a191)
- deps: Update module github.com/baidubce/bce-sdk-go to v0.9.270 (release-3.7.x) (#22783) (103ccd8)
- deps: Update module github.com/coder/quartz to v0.3.1 (release-3.7.x) (#22784) (3509e31)
- deps: Update module github.com/IBM/ibm-cos-sdk-go to v1.14.1 (release-3.7.x) (#22785) (d0abe72)
- deps: Update module github.com/klauspost/compress to v1.18.6 (release-3.7.x) (#22797) (327da7c)
- deps: Update module github.com/pierrec/lz4/v4 to v4.1.27 (release-3.7.x) (#22798) (6b3297f)
- deps: Update module github.com/shirou/gopsutil/v4 to v4.26.5 (release-3.7.x) (#22800) (cb7f17d)
- security/CRITICAL/clients/cmd/fluentd/docker: Update dependency fluentd to v1.19.3 [SECURITY] (release-3.7.x) (#22693) (6d8f1b5)
- security/HIGH/: Bump Go to 1.26.5 to address CVE-2026-39822 and CVE-2026-42505 [SECURITY] (#23393) (b318f28)
- security/HIGH/: Update module github.com/apache/thrift to v0.24.0 [SECURITY] (release-3.7.x) (#22767) (36eb5f7)
- security/UNKNOWN/pkg/push: Update module golang.org/x/net to v0.55.0 [SECURITY] (release-3.7.x) (#22200) (dd7a124)
- security/UNKNOWN/: Update module github.com/containerd/containerd/v2 to v2.0.10 [SECURITY] (release-3.7.x) (#22478) (6fa6165)
- storage: Fix index filename issue with legacy S3 client and
chunk_delimiter(#23165) (0eca83c)
Security Fixes
- Bump Go to 1.26.5 addressing CVE-2026-39822 and CVE-2026-42505
- Update fluentd dependency to v1.19.3 (SECURITY)
- Update Apache Thrift module to v0.24.0 (SECURITY)
- Update containerd/v2 module to v2.0.10 (SECURITY)
- CVE-2026-42505
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]