Skip to content

Platform Engineering

IaC, container orchestration, service mesh, and internal developer platforms.

Subscribe
← Releases
Review required
argo-rollouts v1.9.1 Security relevant

CVE-2026-35469 fix + module updates

Review required
Featbit 5.4.3 Security relevant
Auth RBAC RCE / SSRF

SSRF protection

Upgrade now
GoCD 26.1.0 Security

Security fixes

patches CVE-2022-22965
Open
Upgrade now
semaphore v2.18.19 Security relevant
Auth RBAC

Git URL validation + role fixes

Config change
gitea v1.26.4 Security relevant
Auth

OAuth2 user activation fix

Review required
Loki Mode v7.74.0 Security relevant
Auth RBAC

Trust‑gate hardening

v7.67.0 (1mo) FIX: FALSE-PASS CRITICAL
v7.47.0 (1mo) OIDC RBAC bypass fix
Review required
Jenkins jenkins-2.568 Security relevant

Security fixes

Upgrade now
coder v2.33.7 Security relevant
Dependencies RCE / SSRF

CVE fixes + aibridge header fix

Upgrade now
doco-cd v0.90.1 Security relevant
Auth RBAC

OCI security fix

Upgrade now
coder v2.32.5 Security relevant
Dependencies

CVE patches for crypto & net

Upgrade now
Concourse v8.2.3 Security relevant
Auth

Open‑redirect CVE fix

v8.2.2 (2mo) CVE fix + bug fixes
Review required
flux2 v2.8.8 Security relevant
Dependencies

CVE fixes, controller reliability, Helm update

Review required
zot v2.1.17 Security relevant
Auth RBAC

OIDC logout + CEL access control

patches CVE-2026-33634
Open
Upgrade now
liquibase v5.0.3 Security relevant
Auth

generate-changelog sanitization fix

Upgrade now
coder v2.30.8 Security relevant
Dependencies RCE / SSRF

CVE security fixes + Azure hardening

patches GHSA-686c-7vgv-v3fx patches GHSA-6x44-w3xg-hqqf
Open
v2.24.5 (2mo) Azure identity hardening
v2.29.13 (2mo) Security fixes + Go upgrade
v2.31.12 (2mo) CVE security fixes
v2.32.2 (2mo) CVE-2026-33814 fix
v2.33.3 (2mo) CVE fixes
Upgrade now
woodpecker v3.14.1 Security relevant
Auth

agent_id spoof prevention

Checkov 3.2.527 Security relevant patches CVE-2020-11023 patches CVE-2023-44487
Breaking changes
  • Secrets scanner now reports only the first multiline regex match per file, reverting previous behavior that reported all matches.
Splunk Security Content v5.27.0 Security relevant
⚠ Upgrade required
  • Final release for ESCU v5.x; starting with ESCU v6.0, content will be validated, packaged, and published using new internal tooling instead of contentctl.
Security fixes
  • CVE-2026-31431 – Linux Auditd Copy Fail Privilege Escalation detection added to identify unprivileged users writing controlled data to page cache and escalating to root.
Notable features
  • Cisco Secure Access Analytics analytic story using firewall telemetry
  • Expanded Windows threat detection analytics covering PowerShell abuse, process injection, privilege escalation, cloud/Azure activity, RMM tools, and C2 frameworks
kestra v1.3.14 Security relevant
Security fixes
  • Patched vulnerable frontend dependencies (#15661)
pocket-id v2.6.0 Security relevant
Security fixes
  • Fixed access token renewal bypassing important checks
  • Blocked callback URLs with javascript: and data: protocols
Notable features
  • Admins can now revoke user passkeys
  • Added auth method claim (amr) to OIDC tokens
  • Added TLS support for HTTP/2 server

Beta — feedback welcome: [email protected]