Crossplane v2.2.4

v2.2.4
Changed 1
  • Container images are now built with buildGoModule instead of gomod2nix to support standard vulnerability scanning tools
Fixed 1
  • Usage controller now checks all owner references instead of only the first one to prevent repeated owner updates for composed Usages
Security 5
  • Updated github.com/sigstore/rekor to v1.5.2 to pick up upstream CVE fixes
  • Updated github.com/sigstore/cosign/v3 to v3.0.6 to pick up upstream CVE fixes
  • Updated github.com/sigstore/timestamp-authority/v2 to v2.1.0 to pick up upstream CVE fixes
  • Updated github.com/sigstore/sigstore-go to v1.2.0 to pick up upstream CVE fixes
  • Updated grpc, golang.org/x/net, and golang.org/x/text to pick up upstream CVE fixes

v2.2.4 is a patch release scoped to fixing issues reported by users of Crossplane v2.2 and fixing security related issues in Crossplane and its dependencies.

🎉 Highlights

  • Fixed repeated owner updates for composed Usages (#7596, originally #7591): The Usage controller only checked the first ownerReference when deciding whether the spec.by resource already owned the Usage. A Usage created by a Composition already has the composite as its first owner, so spec.by ended up as a later owner and the controller issued an unnecessary update on every reconciliation — repeatedly re-triggering composition reconciliation and eventually opening the XR circuit breaker. It now checks all owner references.
  • Vulnerability-scannable images (#7575): Container images are now built with buildGoModule (replacing gomod2nix), so published images can be scanned by standard vulnerability tooling.
  • Dependency security updates: Bumps grpc / golang.org/x/net / golang.org/x/text (#7619) and the sigstore stack — cosign (#7558), rekor (#7557), timestamp-authority (#7569), sigstore-go (#7582) — to pick up upstream CVE fixes. See ## What's Changed for the full list.
What's Changed

Full Changelog: https://github.com/crossplane/crossplane/compare/v2.2.3...v2.2.4

View original

Upgraded? How did it go?

Discussion