Skip to content

Platform Engineering

IaC, container orchestration, service mesh, and internal developer platforms.

Subscribe
← Releases
Upgrade now
doco-cd v0.90.1 Security relevant
Auth RBAC

OCI security fix

Upgrade now
coder v2.32.5 Security relevant
Dependencies

CVE patches for crypto & net

Upgrade now
Concourse v8.2.3 Security relevant
Auth

Open‑redirect CVE fix

v8.2.2 (10d) CVE fix + bug fixes
Review required
flux2 v2.8.8 Security relevant
Dependencies

CVE fixes, controller reliability, Helm update

Review required
zot v2.1.17 Security relevant
Auth RBAC

OIDC logout + CEL access control

patches CVE-2026-33634
Open
Upgrade now
liquibase v5.0.3 Security relevant
Auth

generate-changelog sanitization fix

Upgrade now
coder v2.30.8 Security relevant
Dependencies RCE / SSRF

CVE security fixes + Azure hardening

patches GHSA-686c-7vgv-v3fx patches GHSA-6x44-w3xg-hqqf
Open
v2.24.5 (21d) Azure identity hardening
v2.29.13 (21d) Security fixes + Go upgrade
v2.31.12 (21d) CVE security fixes
v2.32.2 (21d) CVE-2026-33814 fix
v2.33.3 (21d) CVE fixes
Upgrade now
woodpecker v3.14.1 Security relevant
Auth

agent_id spoof prevention

Splunk Security Content v5.27.0 Security relevant
⚠ Upgrade required
  • Final release for ESCU v5.x; starting with ESCU v6.0, content will be validated, packaged, and published using new internal tooling instead of contentctl.
Security fixes
  • CVE-2026-31431 – Linux Auditd Copy Fail Privilege Escalation detection added to identify unprivileged users writing controlled data to page cache and escalating to root.
Notable features
  • Cisco Secure Access Analytics analytic story using firewall telemetry
  • Expanded Windows threat detection analytics covering PowerShell abuse, process injection, privilege escalation, cloud/Azure activity, RMM tools, and C2 frameworks
kestra v1.3.14 Security relevant
Security fixes
  • Patched vulnerable frontend dependencies (#15661)
pocket-id v2.6.0 Security relevant
Security fixes
  • Fixed access token renewal bypassing important checks
  • Blocked callback URLs with javascript: and data: protocols
Notable features
  • Admins can now revoke user passkeys
  • Added auth method claim (amr) to OIDC tokens
  • Added TLS support for HTTP/2 server
kurtosis 1.18.0 Security relevant
Security fixes
  • CVE-2026-33186 — grpc-go authz bypass patch in CLI and enclave-manager
Notable features
  • shm size ulimits adjustments for GPU environments
semaphore v2.17.36 Security relevant
Security fixes
  • LDAP filter injection vulnerability
vteamcity-mcp-v2.6.1 (1mo) axios upgrade fixes SSRF
Websoft9 2.2.16 Security relevant
Security fixes
  • CVE-2026-33186 — security vulnerability fixed in upgrade
  • CVE-2026-1229 — security vulnerability fixed in upgrades
  • CVE-2026-33747 — security vulnerability fixed in deployment upgrade
Notable features
  • Upgrade Moodle to version 5.1.3
  • Upgrade apphub to 0.2.7 and fix FastAPI compatibility issue
  • Upgrade deployment to 2.40.0
helm v3.20.2 Security relevant
Security fixes
  • GHSA-hr2v-4r36-88hr: Chart extraction path traversal via dot-segment in Chart.yaml
coder v2.31.9 Security relevant
Security fixes
  • dep: High and critical security vulnerabilities in dependencies
Notable features
  • Performance optimization: cap count queries and use native UUID operations for audit and connection logs
Sealed Secrets v0.36.2 Security relevant
⚠ Upgrade required
  • Release notes reference RELEASE-NOTES.md for important upgrade information from previous releases
Security fixes
  • Bumped golang.org/x/crypto from 0.48.0 to 0.49.0 (cryptographic library update with potential security implications)
helm v4.1.4 Security relevant
Security fixes
  • GHSA-hr2v-4r36-88hr: Chart extraction path traversal
  • GHSA-q5jf-9vfq-h4h7: Plugin verification fails open when .prov missing
  • GHSA-vmx8-mqv2-9gmg: Plugin metadata path traversal
kestra v1.0.35 Security relevant
Security fixes
  • Fixed SQL injection vulnerabilities in label search
v1.3.7 (2mo) Fixed SQL injection, validated AI Copilot
dagu v2.3.9 Security relevant
Security fixes
  • Dependency vulnerabilities fixed
ArgoCD v3.2.8 Security relevant
Security fixes
  • CVE-2026-33186 grpc-go mitigation

Beta — feedback welcome: [email protected]