Crossplane v2.3.4

v2.3.4
Changed 1
  • Container images are now built with buildGoModule instead of gomod2nix to enable vulnerability scanning by standard tooling
Fixed 3
  • Usage controller now checks all owner references instead of only the first one, preventing repeated owner updates for composed Usages that trigger unnecessary composition reconciliation
  • crossplane render command no longer overwrites the input XR's UID when one is already set
  • crossplane render command now validates observed resources before proceeding with the render
Security 7
  • Update grpc to fix upstream CVEs
  • Update golang.org/x/net to v0.56.0 to fix upstream CVEs
  • Update golang.org/x/text to v0.39.0 to fix upstream CVEs
  • Update github.com/sigstore/cosign/v3 to v3.0.6 to fix upstream CVEs
  • Update github.com/sigstore/rekor to v1.5.2 to fix upstream CVEs
  • Update github.com/sigstore/timestamp-authority/v2 to v2.1.0 to fix upstream CVEs
  • Update github.com/sigstore/sigstore-go to v1.2.0 to fix upstream CVEs

v2.3.4 is a patch release scoped to fixing issues reported by users of Crossplane v2.3 and fixing security related issues in Crossplane and its dependencies.

🎉 Highlights

  • Fixed repeated owner updates for composed Usages (#7597, originally #7591): The Usage controller only checked the first ownerReference when deciding whether the spec.by resource already owned the Usage. A Usage created by a Composition already has the composite as its first owner, so spec.by ended up as a later owner and the controller issued an unnecessary update on every reconciliation — repeatedly re-triggering composition reconciliation and eventually opening the XR circuit breaker. It now checks all owner references.
  • crossplane render fixes (#7599, originally #7544): render no longer overwrites the input XR's UID when one is already set, and now validates observed resources before proceeding with the render.
  • Vulnerability-scannable images (#7574): Container images are now built with buildGoModule (replacing gomod2nix), so published images can be scanned by standard vulnerability tooling.
  • Dependency security updates: Bumps grpc / golang.org/x/net / golang.org/x/text (#7618, #7614, #7615) and the sigstore stack — cosign (#7559), rekor (#7560), timestamp-authority (#7570), sigstore-go (#7583) — to pick up upstream CVE fixes. See ## What's Changed for the full list.
What's Changed

Full Changelog: https://github.com/crossplane/crossplane/compare/v2.3.3...v2.3.4

View original

Upgraded? How did it go?

Discussion