# Flux v2.9.5 - Product: Flux (https://whatsnew.fyi/product/flux) - Vendor: Flux project - Date: 2026-08-31 - Version: v2.9.5 - Original notes: https://github.com/fluxcd/flux2/releases/tag/v2.9.5 - Permalink: https://whatsnew.fyi/product/flux/releases/v2.9.5 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **changed** — Move helm-controller and source-controller back to upstream Helm v4.2.4, dropping the Flux fork - **fixed** — Validate kubeconfigs from .spec.kubeConfig Secrets, rejecting local file references in certificate-authority, tokenFile, client-certificate and client-key; credentials and certificates must be embedded inline in helm-controller and kustomize-controller - **fixed** — Purge temporary directories at startup in kustomize-controller - **fixed** — Fix panic on negative-length substring expressions in post-build substitution in kustomize-controller and flux CLI - **changed** — Update fluxcd/pkg dependencies, bringing Kubernetes to 1.36.4 across all controllers and the CLI ##### Highlights Flux v2.9.5 is a patch release that moves helm-controller and source-controller back to upstream Helm, now at v4.2.4, dropping the temporary Flux fork. It hardens the handling of kubeconfig Secrets in helm-controller and kustomize-controller, which now reject kubeconfigs referencing files on the local filesystem and require credentials and certificates to be embedded inline. It also stops kustomize-controller from leaving behind the temporary directories of a previous process that exited without running its cleanup, and fixes a crash in post-build substitution where a substring expression with a negative length, e.g. `${VAR:2:-1}`, panicked instead of counting back from the end of the string like Bash does. Across all controllers and the CLI, the fluxcd/pkg dependencies have been updated, bringing Kubernetes to 1.36.4. Users are encouraged to upgrade for the best experience. ℹ️ Please follow the [Upgrade Procedure for Flux v2.7+](https://github.com/fluxcd/flux2/discussions/5572) for a smooth upgrade from Flux v2.6 to the latest version. Fixes: - Validate kubeconfigs from `.spec.kubeConfig` Secrets, rejecting local file references in `certificate-authority`, `tokenFile`, `client-certificate` and `client-key`; credentials and certificates must be embedded inline (helm-controller, kustomize-controller) - Purge temporary directories at startup (kustomize-controller) - Fix panic on negative-length substring expressions in post-build substitution (kustomize-controller, flux CLI) Improvements: - Move back to upstream Helm v4.2.4, dropping the Flux fork (helm-controller, source-controller) - Update fluxcd/pkg dependencies, which bring Kubernetes to 1.36.4 (all controllers, flux CLI) ##### Components changelog - source-controller [v1.9.5](https://github.com/fluxcd/source-controller/blob/v1.9.5/CHANGELOG.md) - source-watcher [v2.2.4](https://github.com/fluxcd/source-watcher/blob/v2.2.4/CHANGELOG.md) - kustomize-controller [v1.9.5](https://github.com/fluxcd/kustomize-controller/blob/v1.9.5/CHANGELOG.md) - helm-controller [v1.6.4](https://github.com/fluxcd/helm-controller/blob/v1.6.4/CHANGELOG.md) - notification-controller [v1.9.4](https://github.com/fluxcd/notification-controller/blob/v1.9.4/CHANGELOG.md) - image-reflector-controller [v1.2.5](https://github.com/fluxcd/image-reflector-controller/blob/v1.2.5/CHANGELOG.md) - image-automation-controller [v1.2.5](https://github.com/fluxcd/image-automation-controller/blob/v1.2.5/CHANGELOG.md) ##### CLI changelog * Update fluxcd/pkg dependencies by @fluxcdbot in https://github.com/fluxcd/flux2/pull/6046 * Update fluxcd/pkg dependencies by @fluxcdbot in https://github.com/fluxcd/flux2/pull/6048 * Update toolkit components by @fluxcdbot in https://github.com/fluxcd/flux2/pull/6049 **Full Changelog**: https://github.com/fluxcd/flux2/compare/v2.9.4...v2.9.5