# 4.15.68 Created: 2026-08-20 07:14:05 +0000 UTC Image Digest: `sha256:7603840b85b8ae287a0f72a7cc090d333e67912a40fe53ccb750019073e1aeb4` ## Changes from 4.15.39 ### Components * Kubernetes upgraded from 1.28.14 to 1.28.15 * Red Hat Enterprise Linux CoreOS upgraded from 415.92.202411201723-0 to 415.92.202608180329-0 ### Removed images * ovirt-csi-driver * ovirt-csi-driver-operator * ovirt-machine-controllers ### Rebuilt images without code change * [agent-installer-utils](https://github.com/openshift/agent-installer-utils) git [33b7d855](https://github.com/openshift/agent-installer-utils/commit/33b7d855fdebd24a972f32dafafd29e40b117e46) `sha256:c1c2ca6dd20fe6401e487bd9a6d5d798eb18a8e2537e3a8693f6b21fceca2cf3` * [alibaba-cloud-controller-manager](https://github.com/openshift/cloud-provider-alibaba-cloud) git [abf4fa96](https://github.com/openshift/cloud-provider-alibaba-cloud/commit/abf4fa96550caf09e788b66fc06f1df802768397) `sha256:af198e5f859c25c3fc15d015e85ead183e6d248c7ddd315e6e3655c462850cda` * [alibaba-disk-csi-driver-operator](https://github.com/openshift/alibaba-disk-csi-driver-operator) git [41b367ae](https://github.com/openshift/alibaba-disk-csi-driver-operator/commit/41b367ae3bb6de9292539c0ecd98c81c5edc8294) `sha256:7d07b1fa855a7c3d0940298ad49bfee8b1e8d25d8333f47474e38a5b67eeeefd` * [alibaba-machine-controllers](https://github.com/openshift/cluster-api-provider-alibaba) git [f7f5eed8](https://github.com/openshift/cluster-api-provider-alibaba/commit/f7f5eed811b33b9beee1ed6a34f956449fbf7fc7) `sha256:f373d401b0b941c3df747b00845df4d70980f5d881e799b696c4123920834dba` * [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [adccbd5c](https://github.com/openshift/apiserver-network-proxy/commit/adccbd5c16daecfe861fa530acdcbba5ec682a3a) `sha256:086f864ddf87b1569943a57c124db17f12ff68758eb4ee162d53c07fc60d8104` * [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws) git [fd77d92c](https://github.com/openshift/cloud-provider-aws/commit/fd77d92ced47559dadf53fb8c97d1cbeb64dde8c) `sha256:de21f01cf2cab3a95397112fdc8255ccbfbcbf28af3a9a9ec9d67956c237fe59` * [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [7043c1cc](https://github.com/openshift/aws-ebs-csi-driver/commit/7043c1cca6e17dd3c90006140f6361cf0e776d69) `sha256:0ca6341069948df46aff6e64be724962001fb7edb6fc5fb4720477adcc33ae1b` * [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [13385034](https://github.com/openshift/aws-pod-identity-webhook/commit/13385034ec9a843a6b40f8b3aec9966ada785115) `sha256:5a7caae8a840ecb4d21a07b5157d1f88c346ccdb02fc4558974f256622e42f2e` * [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver) git [dcb7e1c7](https://github.com/openshift/azure-disk-csi-driver/commit/dcb7e1c7d239ab5a26d70d7abcff1eb97b634b8d) `sha256:313c3dc6fefe57ef95ffadd23459079582d432248931141337f2d0fc47c2f442` * [azure-disk-csi-driver-operator](https://github.com/openshift/azure-disk-csi-driver-operator) git [160cf624](https://github.com/openshift/azure-disk-csi-driver-operator/commit/160cf624a88f500de7a1f79e6dd9384bb7d17842) `sha256:622cceba0290cf6066e4f26ca8b884b1f19fc5b7acc4601ef11c5479713f32ac` * [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg) git [1fbb2c0c](https://github.com/openshift/baremetal-runtimecfg/commit/1fbb2c0c1e6af304a673d5ac43803d4bb5dca95c) `sha256:3aedbcc485bc7478c756d76fc5edbe933660877362a849256656b344f80a7ce5` * [cli](https://github.com/openshift/oc) git [82316376](https://github.com/openshift/oc/commit/82316376e25f6453b58258df6bf1e11ec4abb670) `sha256:9d90d863a358f0284d3b5757144ccf51874adec1b4046737fecd18bab32a198b` * [cli-artifacts](https://github.com/openshift/oc) git [82316376](https://github.com/openshift/oc/commit/82316376e25f6453b58258df6bf1e11ec4abb670) `sha256:b2dd7899b63a81066cf862fcac75f4c72fa97a6a450c67d386b2c129cfefbc4b` * [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller) git [6864da06](https://github.com/openshift/cloud-network-config-controller/commit/6864da0642026d6004df171539fa9fd5bcb6c2df) `sha256:0132b55fd9ecd2dde16091658cf54726d4103c8511bae677383fef4d0c64589e` * [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator) git [7aaa40eb](https://github.com/openshift/cluster-authentication-operator/commit/7aaa40eb28afdae8c5994b672b33cd4be31cc7d1) `sha256:4c8a1bb7ac7c0315d86541444309a6fdfadff6f60f79a6cc539c8637e42d0963` * [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator) git [8425d88b](https://github.com/openshift/cluster-autoscaler-operator/commit/8425d88b5bedd5d22acfb0f6c0edf929ec401288) `sha256:10c3189d7de1a23e6e78883fe6661da1681e8cdfa73d6a756896a435c4ed8214` * [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [0849c462](https://github.com/openshift/cluster-bootstrap/commit/0849c462de13b9a5765b9a8c882acb9e6e8bf39e) `sha256:dca605adedad9ee390bcaac765f9fecf3a04d74dff01c5a310a23ba2aa60b88b` * [cluster-capi-controllers](https://github.com/openshift/cluster-api) git [2053e13c](https://github.com/openshift/cluster-api/commit/2053e13cb0fda9188e9b685db83c1e1f492e6efa) `sha256:9dbe509807694f58cabf0a889153d76459234389299c25c14fcea839b1d52822` * [cluster-config-api](https://github.com/openshift/api) git [0a58f8c3](https://github.com/openshift/api/commit/0a58f8c30a8c309baaa4aecd05580039b4d3888b) `sha256:6e4859d0496b6b61a1f9b86fc0ecf1937eadc7c9ff8c429ec53cb02fbc189e5f` * [cluster-config-operator](https://github.com/openshift/cluster-config-operator) git [0b4c69fd](https://github.com/openshift/cluster-config-operator/commit/0b4c69fd7e282b9037cbb2b6e2d09c96bcc29818) `sha256:00188e0658418ee73497bcb2db808b0b0a6e43fce3621fd8c382afbd69f58ee8` * [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator) git [65dbb12b](https://github.com/openshift/cluster-csi-snapshot-controller-operator/commit/65dbb12b710b7126f662f5f7f2d8272f9f6868cc) `sha256:38bcabf5d84e3eecfb8a0ecf15a74afec32c672b4fdac0902bd930b45c333516` * [cluster-kube-cluster-api-operator](https://github.com/openshift/cluster-api-operator) git [128d8e08](https://github.com/openshift/cluster-api-operator/commit/128d8e08c48e2002c416e84d0dec816bf5999c7e) `sha256:15eb0800e15f377c7cdbce1dac15d8117249e917d4cdd148ade0e294542656cc` * [cluster-platform-operators-manager](https://github.com/openshift/platform-operators) git [37a0a919](https://github.com/openshift/platform-operators/commit/37a0a919b1032f7affa49b756eda4762d77751d5) `sha256:7b236e13635eb74d6f29b15cf5201ac8643b2aa6cc6a039cf3bd786a028a2872` * [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller) git [cc48f315](https://github.com/openshift/cluster-policy-controller/commit/cc48f3152213bfe6e42fdd82f760246e862d208f) `sha256:1f750eea5c8b40bd4271120d26e51a6a20f4118af52160f17d9c1b9d53cd9269` * [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [802233d8](https://github.com/openshift/cluster-update-keys/commit/802233d84243d3eeceef50a29579501e94ebbf26) `sha256:8be7f51dad8626a44022d738a35af7528cb8b22bca0c5a7301c33fd7babbe0da` * [configmap-reloader](https://github.com/openshift/configmap-reload) git [617398f5](https://github.com/openshift/configmap-reload/commit/617398f581faadbad2c7ded993bfa3169a87b6ab) `sha256:ee7fb9c613e03e881942adcf6011ab2ebee9587d47f88a91ae2a7da784a4cd75` * [csi-driver-shared-resource](https://github.com/openshift/csi-driver-shared-resource) git [260a085a](https://github.com/openshift/csi-driver-shared-resource/commit/260a085ae25606bba7a94cdfed88f67265905ba9) `sha256:ca536df1234be34c4e39b1bf20f8e284dea95985d00f02fb4533a7bc36999712` * [csi-driver-shared-resource-operator](https://github.com/openshift/csi-driver-shared-resource-operator) git [8d017b7f](https://github.com/openshift/csi-driver-shared-resource-operator/commit/8d017b7f19f0226dfd4fc7933271939c550d180f) `sha256:6c4da56ce79775919d09393c36217b3f2b063effed26876dab35d51e0b8eda0b` * [csi-driver-shared-resource-webhook](https://github.com/openshift/csi-driver-shared-resource) git [260a085a](https://github.com/openshift/csi-driver-shared-resource/commit/260a085ae25606bba7a94cdfed88f67265905ba9) `sha256:5ccfba8569f38a01a6febd6b1f9e0382d15a21d25cf23f08cc0620d68465d3bc` * [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [f806f266](https://github.com/openshift/csi-external-attacher/commit/f806f266600fbc0db4d072e4d041fc80e28deee7) `sha256:7de8711bd104ca296846a8669d33bfdc068256e2df3aa27cb4c3f9a25f6e58f8` * [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [ce5a1a33](https://github.com/openshift/csi-external-provisioner/commit/ce5a1a33fadf10bba0c90510c09dfc879dcfec87) `sha256:efbfb2b2419065d3d10b9f2eaedad080fd471b1f6ca58682dea992995f26993c` * [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [3b4236d3](https://github.com/openshift/csi-external-resizer/commit/3b4236d382e4593ca41ecc6f394775be467b1a0d) `sha256:23f61dba81195aa0850aa05b1031f03aaa6466c6b00c42542de6eaf4152504b3` * [csi-external-snapshotter](https://github.com/openshift/csi-external-snapshotter) git [4f2955c7](https://github.com/openshift/csi-external-snapshotter/commit/4f2955c7c90cd150f9dfae782148d0fa8eba7342) `sha256:3070d4a4ac9d406210bb4fb07afcadba4dbaddb888c928a2899cd69c8ddc4a7d` * [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe) git [240bb8c0](https://github.com/openshift/csi-livenessprobe/commit/240bb8c0c7b24d0b18831be4ace39bcbc8d599e3) `sha256:2ed2179a8833c676ead61a1bf2c60f2a46887ab1a48b559dcc96a8f23beab323` * [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [9005584e](https://github.com/openshift/csi-node-driver-registrar/commit/9005584ee45c4d3158e383870aafa5d78a03b141) `sha256:a91504ee3735f1707324515bfb7d8d0b6f8fb23ce16981120bf0ada477c25e25` * [csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter) git [4f2955c7](https://github.com/openshift/csi-external-snapshotter/commit/4f2955c7c90cd150f9dfae782148d0fa8eba7342) `sha256:329022a6973f38361304447469c9bea12a59f92cc9eb6afbfb1c3382194bb9bf` * [csi-snapshot-validation-webhook](https://github.com/openshift/csi-external-snapshotter) git [4f2955c7](https://github.com/openshift/csi-external-snapshotter/commit/4f2955c7c90cd150f9dfae782148d0fa8eba7342) `sha256:a69b1e766d5787281ec3d4d3cb4838b1a8992c71e3312aafe26e55e8d1d39262` * [deployer](https://github.com/openshift/oc) git [82316376](https://github.com/openshift/oc/commit/82316376e25f6453b58258df6bf1e11ec4abb670) `sha256:e566acacd9610db6558eda985965b052f206e4e0d67873eed72e5df243e85b31` * [driver-toolkit](https://github.com/openshift/driver-toolkit) git [7a448c2e](https://github.com/openshift/driver-toolkit/commit/7a448c2ee026c772e293dd344da587493c859f82) `sha256:6c2519c34c724051006bcc63c8337fd96a4544eddbed23ebe85461b1036d899d` * [egress-router-cni](https://github.com/openshift/egress-router-cni) git [f8ec690b](https://github.com/openshift/egress-router-cni/commit/f8ec690bc12a13ec7c9c45f0e3696ad02e143581) `sha256:00b461c15e998d4d4cf137f1a44f8180ec95b7fa327acd92d279125fc899487b` * [etcd](https://github.com/openshift/etcd) git [a7005ef1](https://github.com/openshift/etcd/commit/a7005ef1eae85eec6c59411860538169cea182fd) `sha256:23be17d1d269a7f8520ee73be752c4a1c2dadad05318aabe95c79e4fc35f4890` * [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp) git [fc50272a](https://github.com/openshift/cloud-provider-gcp/commit/fc50272ac32348a96455688c470bf256b1042825) `sha256:7721b04e071fe34d7d2f09426756e7b17dc02598fe160f46d36817c7ccf9bf64` * [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm) git [cc0d5415](https://github.com/openshift/cloud-provider-ibm/commit/cc0d54159c5d626aaa91eef94a92a80b3d1a3870) `sha256:7eeeffd1e82ff2e48ee9e702b0e216303ad65fca083f7bb2892ec4e4403f8256` * [k8s-prometheus-adapter](https://github.com/openshift/k8s-prometheus-adapter) git [34e20193](https://github.com/openshift/k8s-prometheus-adapter/commit/34e201936898455995cd60c6699c6329a696f288) `sha256:6547bfa8b58cff3fc73cfa02887cd10c7d13f3609390e7bb5627064f3df0a079` * [keepalived-ipfailover](https://github.com/openshift/images) git [87c23b5a](https://github.com/openshift/images/commit/87c23b5aa611556ff5013822c7779e6c7551a0f0) `sha256:a9326d0abdfa477f39ba493f7d53f0c33a9b09d86152ee7162f0a6911f92beaf` * [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server) git [bcbf241c](https://github.com/openshift/kubernetes-metrics-server/commit/bcbf241cece8ef455be32a910f1570bae827b4a1) `sha256:cac338ca4b90c8c5f8e1418401ac629edc71f1bb7105904594e116fb4244b200` * [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [9308e7f2](https://github.com/openshift/kube-rbac-proxy/commit/9308e7f2a6d984fa7b8ddc125524d7b7356f92ce) `sha256:11d95cfa44633fe822fec1ac24a6ddd16af6035d85125daad9fb9d8bdedbf938` * [kube-state-metrics](https://github.com/openshift/kube-state-metrics) git [037b59c2](https://github.com/openshift/kube-state-metrics/commit/037b59c265454c599dfb0829a856e14b1ab07896) `sha256:4d1f7e30e0797223848a22223228ceb68978aeaac8bf7afb42aa7c5ed0f6820d` * machine-os-content `sha256:c4d82e60bb1cbf39f8ae96731e9ea8611134055769376966a40514defbf20db9` * [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [b377b4b5](https://github.com/openshift/multus-networkpolicy/commit/b377b4b5fd3029cd5cabc773ca6223cabd6b2af7) `sha256:473f90988421d4c45cc3678426c90032a45237f1b575862f8b6f822f304ecb8b` * [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [1ccafc34](https://github.com/openshift/route-override-cni/commit/1ccafc340ca1147abb42c7ad8dda1f23ba4eb1ee) `sha256:57557e1f2386208c3213c1352361d5a121bddca5579bc998edde446b86ad73ad` * [network-interface-bond-cni](https://github.com/openshift/bond-cni) git [f91decaa](https://github.com/openshift/bond-cni/commit/f91decaa10cfa233c9e680c96ec7ae642e30a03c) `sha256:8e7599a22054f7742e039c914b8a50a32855d3941ab5fb8a5323599b068c71d5` * [network-tools](https://github.com/openshift/network-tools) git [17536c8d](https://github.com/openshift/network-tools/commit/17536c8dff76d50efb604187ba763020bd084771) `sha256:1dd63cedfc15a91348b7b5ab8e70c723c81d8674587301325e3d028c3eee871b` * [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [040d4e01](https://github.com/openshift/cloud-provider-nutanix/commit/040d4e016058c188d2ba0a7575054ee44b94af9e) `sha256:db458b2dd5fb264f33f00b008921a0d28237c05e55866e7d7addeadbdede1e9b` * [oauth-server](https://github.com/openshift/oauth-server) git [c055dbb9](https://github.com/openshift/oauth-server/commit/c055dbb9a84e04575ade106e9a43cc638a8aeaef) `sha256:d262c2f60f20cec8676aa31083c39b898169dc484b30cfc3722c853d2650d5ec` * [olm-catalogd](https://github.com/openshift/operator-framework-catalogd) git [035d3835](https://github.com/openshift/operator-framework-catalogd/commit/035d3835e581bee8ba59ec8919b43c8d7ce4ecfd) `sha256:2dabd5b36a2e6b37668f9b9dddbe6cb19dcae9eaa081144cfa2d3c14dd53417b` * [olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller) git [303b954f](https://github.com/openshift/operator-framework-operator-controller/commit/303b954fa5a92e810aebbe55ab8fafe8dbc06c58) `sha256:7ce0b4538c54a4a6982858774517e82382fae876ccb32406472e1955cff3ae05` * [olm-rukpak](https://github.com/openshift/operator-framework-rukpak) git [5b09cd44](https://github.com/openshift/operator-framework-rukpak/commit/5b09cd44e9ca7b2ec91fd6f906ac4612636277e3) `sha256:b674332beb42548317d10be65974fceaad696af721e76eebc6267f486e998aaf` * [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [1915f645](https://github.com/openshift/openshift-state-metrics/commit/1915f64591a18c11138d10c00c50b3f5cff632ce) `sha256:76ac9e41b89c346830a770a0de394ab97c3c3e0caa7258cd3ac3ec3392d00cfa` * [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack) git [232472ea](https://github.com/openshift/cluster-api-provider-openstack/commit/232472ea527aa86764d93e77dc67b0c7db9cc050) `sha256:a8dfa17de5dc8600d2950e2cd0f4146448b65cc4ec75848def01bcf01f95d0a4` * [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver) git [38bee567](https://github.com/openshift/ibm-powervs-block-csi-driver/commit/38bee567a703d3d5ab2ca6e1e047eea8e799c3c5) `sha256:7d2594ba65e3b5b225b736c95cd270486966b00f61cbc78e87bfbea87410a3e6` * [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs) git [1d6a7ed9](https://github.com/openshift/cloud-provider-powervs/commit/1d6a7ed991427b1c8048b0b44b706228e5c2a001) `sha256:69b8fee257de3dc11e4851d539db7ef724d7f3448628f15b5d687262a750af0f` * [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [f3f1f5d1](https://github.com/openshift/prom-label-proxy/commit/f3f1f5d1161df6c25a0e1d04218dfc6447782ab4) `sha256:418c3a5c91bd8f7e5c76c1486262b1728f73b88f92eed55e55b47f19b5900a78` * [prometheus-config-reloader](https://github.com/openshift/prometheus-operator) git [902436ac](https://github.com/openshift/prometheus-operator/commit/902436ac6a8eec8f2f3f8b91f519a3d319924833) `sha256:f226c48717a83261e1b40ad80fb6dfd5b8c2fc80b9955707bae7fa852a6a1ebd` * [prometheus-node-exporter](https://github.com/openshift/node_exporter) git [aed837c3](https://github.com/openshift/node_exporter/commit/aed837c322b6eb54d88956acada07b5b390b5c25) `sha256:abce6b5067bd71e1a678ed80a73781dda7f5767c3973c957e89206f651eac328` * [prometheus-operator](https://github.com/openshift/prometheus-operator) git [902436ac](https://github.com/openshift/prometheus-operator/commit/902436ac6a8eec8f2f3f8b91f519a3d319924833) `sha256:2642748154b010090da05bcf13b18556d253932516d044ab6601a65099f37d31` * [prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator) git [902436ac](https://github.com/openshift/prometheus-operator/commit/902436ac6a8eec8f2f3f8b91f519a3d319924833) `sha256:60e6c86dfc7195b858e2c950f25209166b94e7d09e7c7455c8ac264cfc6c8829` * rhel-coreos `sha256:737f32dbab1ca79436cd333dc1efff8125e4b74d498213a0a450aad410b2600c` * rhel-coreos-extensions `sha256:cf2eb3d971880d3d4291c2cc853df8e898a8d5c8edb5f5631718a73c145139fc` * [telemeter](https://github.com/openshift/telemeter) git [14489f7d](https://github.com/openshift/telemeter/commit/14489f7dc656175e11a3ef962fcbcd113b3651a9) `sha256:a354e2662aa6a328a67c6a800162e4b5a36ed2e967b4fb6bda44f3cba88da0e9` * [thanos](https://github.com/openshift/thanos) git [66161ad4](https://github.com/openshift/thanos/commit/66161ad4e03e5593f5a3a33aaaffbcd41555d62a) `sha256:c18c76ff37a88defec4d8b29e4ad32ae5296cee5cf01c05a9ef637decffcc687` * [tools](https://github.com/openshift/oc) git [82316376](https://github.com/openshift/oc/commit/82316376e25f6453b58258df6bf1e11ec4abb670) `sha256:522b0f5e015e0e76dcf4d7799451cd1d1dd39b9cc89280dc5e4062356d972b68` ### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/b7cfbf8fa8d25329ab1e4e46571e4c4bbdfdc1b2) * [OCPBUGS-58633](https://issues.redhat.com/browse/OCPBUGS-58633), [OCPBUGS-58638](https://issues.redhat.com/browse/OCPBUGS-58638): Bump glog to v1.2.5 in release-4.15 (#7905) [#7905](https://github.com/openshift/assisted-service/pull/7905) * [OCPBUGS-54402](https://issues.redhat.com/browse/OCPBUGS-54402): Bump go-jwt to 4.5.2 to fix CVE-30204 (#7487) [#7487](https://github.com/openshift/assisted-service/pull/7487) * [OCPBUGS-46940](https://issues.redhat.com/browse/OCPBUGS-46940): OCPBUGS-46185: Bump golang.org/x/net to 0.33.0 (#7199) [#7199](https://github.com/openshift/assisted-service/pull/7199) * [Full changelog](https://github.com/openshift/assisted-service/compare/59ec11581b77fb1e03e153f7399ccc2e97e8c0bf...b7cfbf8fa8d25329ab1e4e46571e4c4bbdfdc1b2) ### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/f0b1275e58633382222af71a6cac527e6f8cec24) * [OCPBUGS-58643](https://issues.redhat.com/browse/OCPBUGS-58643): Bump github.com/golang/glog pkg version to 1.2.4 (#1189) [#1189](https://github.com/openshift/assisted-installer/pull/1189) * [OCPBUGS-53714](https://issues.redhat.com/browse/OCPBUGS-53714): Bump jwt to 4.5.2 in release-4.15 (#1092) [#1092](https://github.com/openshift/assisted-installer/pull/1092) * Bump golang.org/x/net to 0.33.0 (#1011) [#1011](https://github.com/openshift/assisted-installer/pull/1011) * [Full changelog](https://github.com/openshift/assisted-installer/compare/fde2b2eace2f7ceaedc1ac63f0da77f21cfd78f7...f0b1275e58633382222af71a6cac527e6f8cec24) ### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/051696d004b70c305a2feb80fe6ea4f35f7a1b09) * run go mod tidy / vendor [#1020](https://github.com/openshift/assisted-installer-agent/pull/1020) * And 3 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/366295f2cba23d0e7e1a61b384e226f707ff56a6...051696d004b70c305a2feb80fe6ea4f35f7a1b09) ### [alibaba-cloud-csi-driver](https://github.com/openshift/alibaba-cloud-csi-driver/tree/4fb95a28e02d9f080ca41caa209896c1c5f9a563) * [OCPBUGS-67910](https://issues.redhat.com/browse/OCPBUGS-67910): Bump github.com/sirupsen/logrus to v1.8.3 [#47](https://github.com/openshift/alibaba-cloud-csi-driver/pull/47) * [Full changelog](https://github.com/openshift/alibaba-cloud-csi-driver/compare/be4888d3dc176b9801364981fbb34d831f6d6ffe...4fb95a28e02d9f080ca41caa209896c1c5f9a563) ### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/5c673e1d6207e934a4e27da1ef165ddf03bf6a1a) * [OCPBUGS-78228](https://issues.redhat.com/browse/OCPBUGS-78228): [release-4.15] hermetic 4.15 [#592](https://github.com/openshift/cluster-api-provider-aws/pull/592) * [OCPBUGS-61943](https://issues.redhat.com/browse/OCPBUGS-61943): UPSTREAM <carry>: revert: Only tag NetworkInterfaces in RunInstances if IAM Allows It [#573](https://github.com/openshift/cluster-api-provider-aws/pull/573) * [OCPBUGS-58668](https://issues.redhat.com/browse/OCPBUGS-58668), [OCPBUGS-58673](https://issues.redhat.com/browse/OCPBUGS-58673): bump github.com/golang/glog to v1.2.5 [#562](https://github.com/openshift/cluster-api-provider-aws/pull/562) * [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/7f00d2cde7a40b8438c5e0d5e64a4d15a035883a...5c673e1d6207e934a4e27da1ef165ddf03bf6a1a) ### [aws-ebs-csi-driver-operator](https://github.com/openshift/csi-operator/tree/242c3b9ba85478220ecf75a0a91d5c061615029c) * [OCPBUGS-67913](https://issues.redhat.com/browse/OCPBUGS-67913): Bumped logrus to 1.9.3 [#492](https://github.com/openshift/csi-operator/pull/492) * [Full changelog](https://github.com/openshift/csi-operator/compare/2a2b9dd109ba9d4abce11411c96787b21887f929...242c3b9ba85478220ecf75a0a91d5c061615029c) ### [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws/tree/fb9a59a0f7636ffece8cc585f5ab8844e67cd198) * [OCPBUGS-63141](https://issues.redhat.com/browse/OCPBUGS-63141): client: re-use a single file for building the session instead of randomly named files [#153](https://github.com/openshift/machine-api-provider-aws/pull/153) * [OCPBUGS-63141](https://issues.redhat.com/browse/OCPBUGS-63141): revert: client: re-use a single file for building the session instead of randomly named files [#150](https://github.com/openshift/machine-api-provider-aws/pull/150) * [OCPBUGS-63141](https://issues.redhat.com/browse/OCPBUGS-63141): client: re-use a single file for building the session instead of randomly named files [#143](https://github.com/openshift/machine-api-provider-aws/pull/143) * [OCPBUGS-47680](https://issues.redhat.com/browse/OCPBUGS-47680): fix Associate*IpAddress flag on launch EC2 [#122](https://github.com/openshift/machine-api-provider-aws/pull/122) * [Full changelog](https://github.com/openshift/machine-api-provider-aws/compare/0129b1e3e6cf8d142dbff58d6f25ec9d42b0d382...fb9a59a0f7636ffece8cc585f5ab8844e67cd198) ### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/5638728df093f0daccd559842aa5f527495146b6) * [OCPBUGS-79916](https://issues.redhat.com/browse/OCPBUGS-79916), [OCPBUGS-85634](https://issues.redhat.com/browse/OCPBUGS-85634), [OCPBUGS-85637](https://issues.redhat.com/browse/OCPBUGS-85637): Bump google.golang.org/grpc to v1.79.3 [#187](https://github.com/openshift/cloud-provider-azure/pull/187) * [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/0d799a261f70bbdf546d911f5f8b59e2c324bd16...5638728df093f0daccd559842aa5f527495146b6) ### [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure/tree/7896f4a94ae32cf038daa77e255ec207832c1081) * [OCPBUGS-78177](https://issues.redhat.com/browse/OCPBUGS-78177): [release-4.15] update go mod dependency for konflux [#365](https://github.com/openshift/cluster-api-provider-azure/pull/365) * [Full changelog](https://github.com/openshift/cluster-api-provider-azure/compare/44832d2da09778d7ff4d2413c9e10852f330a55d...7896f4a94ae32cf038daa77e255ec207832c1081) ### [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver/tree/23df7785cd9a0ad41470d02336b6ec510248984d) * [OCPBUGS-79874](https://issues.redhat.com/browse/OCPBUGS-79874): Bump google.golang.org/grpc to v1.79.3 [#131](https://github.com/openshift/azure-file-csi-driver/pull/131) * [ART-13080](https://issues.redhat.com/browse/ART-13080): Regenerate go.mod to fix build failure [#94](https://github.com/openshift/azure-file-csi-driver/pull/94) * [Full changelog](https://github.com/openshift/azure-file-csi-driver/compare/bcf919dc0467f84192758155aac4976df5054da6...23df7785cd9a0ad41470d02336b6ec510248984d) ### [azure-file-csi-driver-operator](https://github.com/openshift/azure-file-csi-driver-operator/tree/ef087772a9ed3299d776c28be78f8017762bcd08) * [OCPBUGS-67918](https://issues.redhat.com/browse/OCPBUGS-67918): Bump github.com/sirupsen/logrus to v1.9.3 [#113](https://github.com/openshift/azure-file-csi-driver-operator/pull/113) * [OCPBUGS-60544](https://issues.redhat.com/browse/OCPBUGS-60544): add tag matching to Azure File storage class [#110](https://github.com/openshift/azure-file-csi-driver-operator/pull/110) * [Full changelog](https://github.com/openshift/azure-file-csi-driver-operator/compare/367c4e45899033f7fb7494c0004b83157b6723aa...ef087772a9ed3299d776c28be78f8017762bcd08) ### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/9f1015edb8cb141cd6aaff2de7894f32336719c8) * [OCPBUGS-56657](https://issues.redhat.com/browse/OCPBUGS-56657): Fix failure when attempting to modify immutable availabilitySet [#150](https://github.com/openshift/machine-api-provider-azure/pull/150) * [OCPBUGS-53226](https://issues.redhat.com/browse/OCPBUGS-53226): dynamically setting the amount of fault domains [#134](https://github.com/openshift/machine-api-provider-azure/pull/134) * [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/615b457bcfa1a40e7900585154952aac8194bed4...9f1015edb8cb141cd6aaff2de7894f32336719c8) ### [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity/tree/5db478a9876556666b10f135487a2fd9f82e8653) * [OCPBUGS-53794](https://issues.redhat.com/browse/OCPBUGS-53794): github.com/golang-jwt/jwt/v4 v4.5.2 [#34](https://github.com/openshift/azure-workload-identity/pull/34) * [Full changelog](https://github.com/openshift/azure-workload-identity/compare/2333b7fae0592ae26d77cbac49ce23e7fbaa00b1...5db478a9876556666b10f135487a2fd9f82e8653) ### [baremetal-installer, installer, installer-altinfra, installer-artifacts](https://github.com/openshift/installer/tree/83c823bf5cb70c42dcbbc93306a570759ac6aaf8) * [OCPBUGS-79036](https://issues.redhat.com/browse/OCPBUGS-79036): Azure UPI ARM template: use storageAccountId [#10418](https://github.com/openshift/installer/pull/10418) * [OCPBUGS-76929](https://issues.redhat.com/browse/OCPBUGS-76929): terraform/provider/google: Fixing GCP inconsistencies present with the service account creation [#10316](https://github.com/openshift/installer/pull/10316) * [OCPBUGS-42554](https://issues.redhat.com/browse/OCPBUGS-42554): only allow a single network in failure domain topology [#9060](https://github.com/openshift/installer/pull/9060) * [OCPBUGS-62849](https://issues.redhat.com/browse/OCPBUGS-62849): Release 4.15 bump terraform provider azurerm [#10007](https://github.com/openshift/installer/pull/10007) * [OCPBUGS-62410](https://issues.redhat.com/browse/OCPBUGS-62410): Make swift containers removal not fatal for UPI. [#9978](https://github.com/openshift/installer/pull/9978) * [OCPBUGS-60497](https://issues.redhat.com/browse/OCPBUGS-60497): update resolv.conf every time on bootstrap node [#9885](https://github.com/openshift/installer/pull/9885) * [OCPBUGS-39416](https://issues.redhat.com/browse/OCPBUGS-39416): OpenStack: Install CI dependencies from rpm [#9103](https://github.com/openshift/installer/pull/9103) * [OCPBUGS-54353](https://issues.redhat.com/browse/OCPBUGS-54353): aws/edge/byovpc: tag edge subnets with shared value [#9612](https://github.com/openshift/installer/pull/9612) * [OCPBUGS-54367](https://issues.redhat.com/browse/OCPBUGS-54367): IBMCloud: Move to IBM TF openshift fork [#9614](https://github.com/openshift/installer/pull/9614) * [OCPBUGS-45961](https://issues.redhat.com/browse/OCPBUGS-45961): Update upi references to api-internal [#9298](https://github.com/openshift/installer/pull/9298) * [OCPBUGS-50994](https://issues.redhat.com/browse/OCPBUGS-50994): Bump terraform-provider-google version to v5.37.0 to fix consistent issues during cluster creation [#9509](https://github.com/openshift/installer/pull/9509) * [OCPBUGS-41815](https://issues.redhat.com/browse/OCPBUGS-41815): Validate MTU for custom network [#9294](https://github.com/openshift/installer/pull/9294) * [OCPBUGS-28706](https://issues.redhat.com/browse/OCPBUGS-28706): [azure] update tested x86 instance type on 4.15 [#7966](https://github.com/openshift/installer/pull/7966) * [OCPBUGS-47716](https://issues.redhat.com/browse/OCPBUGS-47716): [release-4.15] Power VS: Create region-zone-sysType hierarchy [#9340](https://github.com/openshift/installer/pull/9340) * [OCPBUGS-44259](https://issues.redhat.com/browse/OCPBUGS-44259): IBMCloud: Ignore failed VPC regions [#9183](https://github.com/openshift/installer/pull/9183) * [ARO-12457](https://issues.redhat.com/browse/ARO-12457): Include bootstrap docker config file in go module [#9260](https://github.com/openshift/installer/pull/9260) * [OCPBUGS-45207](https://issues.redhat.com/browse/OCPBUGS-45207): add chrony.conf file when additional NTP sources are configured [#9251](https://github.com/openshift/installer/pull/9251) * [CORS-3753](https://issues.redhat.com/browse/CORS-3753): Allow mocking of the Azure client everywhere [#9221](https://github.com/openshift/installer/pull/9221) * And 1 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/installer/compare/4caaa383b8dfa4853d1962a966a430da27417423...83c823bf5cb70c42dcbbc93306a570759ac6aaf8) ### [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal/tree/abd5d24efd670cfb719757c0d5af3409ee3c0058) * [OCPBUGS-78100](https://issues.redhat.com/browse/OCPBUGS-78100): [release-4.15] fix vendor/ for hermetic migration [#244](https://github.com/openshift/cluster-api-provider-baremetal/pull/244) * [OCPBUGS-46641](https://issues.redhat.com/browse/OCPBUGS-46641): Bump x/net to 0.33.0 [#227](https://github.com/openshift/cluster-api-provider-baremetal/pull/227) * [Full changelog](https://github.com/openshift/cluster-api-provider-baremetal/compare/73a72cc821224eb7ad0fad25d3bcc8272658238b...abd5d24efd670cfb719757c0d5af3409ee3c0058) ### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/880ee0500b561ac9d0dc70d88c3f2fdfa4c7edee) * [OCPBUGS-53336](https://issues.redhat.com/browse/OCPBUGS-53336): BMO can expose any secret via BMCEventSubscription CRD [#408](https://github.com/openshift/baremetal-operator/pull/408) * [Full changelog](https://github.com/openshift/baremetal-operator/compare/62a7d56e20785c3f4cf02cb2511270a7aa32deea...880ee0500b561ac9d0dc70d88c3f2fdfa4c7edee) ### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/cffd42537ac64a3936a12de001db938d0904126e) * [OCPBUGS-60974](https://issues.redhat.com/browse/OCPBUGS-60974): ccoctl: aws to use proper issuer url on subsequent runs [#910](https://github.com/openshift/cloud-credential-operator/pull/910) * [OCPBUGS-58678](https://issues.redhat.com/browse/OCPBUGS-58678): github.com/golang/glog v1.2.5 [#894](https://github.com/openshift/cloud-credential-operator/pull/894) * [OCPBUGS-53417](https://issues.redhat.com/browse/OCPBUGS-53417): github.com/golang/glog v1.2.4 [#844](https://github.com/openshift/cloud-credential-operator/pull/844) * [OCPBUGS-53818](https://issues.redhat.com/browse/OCPBUGS-53818): update github.com/golang-jwt/jwt [#840](https://github.com/openshift/cloud-credential-operator/pull/840) * [OCPBUGS-51540](https://issues.redhat.com/browse/OCPBUGS-51540): Ignore SNYK-GOLANG-GOLANGORGXOAUTH2JWS-8749594 due to not being affected [#833](https://github.com/openshift/cloud-credential-operator/pull/833) * [OCPBUGS-47068](https://issues.redhat.com/browse/OCPBUGS-47068): golang.org/x/net v0.33.0 [#806](https://github.com/openshift/cloud-credential-operator/pull/806) * [OCPBUGS-45940](https://issues.redhat.com/browse/OCPBUGS-45940): Add AWS region to aws-pod-identity-webhook [#802](https://github.com/openshift/cloud-credential-operator/pull/802) * [OCPBUGS-45008](https://issues.redhat.com/browse/OCPBUGS-45008): Add retry to ccoctl gcp create functions [#795](https://github.com/openshift/cloud-credential-operator/pull/795) * [OCPBUGS-45003](https://issues.redhat.com/browse/OCPBUGS-45003): github.com/golang-jwt/jwt/v4 v4.5.1 [#784](https://github.com/openshift/cloud-credential-operator/pull/784) * [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/60b3edb85025c66c2962fdb31c800afd484c8ba1...cffd42537ac64a3936a12de001db938d0904126e) ### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/89149896bc6a3d02ebf117c61d5e9ea50ad73129) * [OCPBUGS-45149](https://issues.redhat.com/browse/OCPBUGS-45149): [release-4.15] VPA: Update OWNERS file [#326](https://github.com/openshift/kubernetes-autoscaler/pull/326) * [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/e78ea20540f3f445f7417cf4fe138738f3a4143a...89149896bc6a3d02ebf117c61d5e9ea50ad73129) ### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/9508bd334d661b6e8e76d452082f9a6f822a7739) * [OCPBUGS-77448](https://issues.redhat.com/browse/OCPBUGS-77448): Bump github.com/go-errors/errors to v1.5.1 [#563](https://github.com/openshift/cluster-baremetal-operator/pull/563) * [OCPBUGS-44046](https://issues.redhat.com/browse/OCPBUGS-44046): SCC-pinning for metal3-baremetal-operator [#454](https://github.com/openshift/cluster-baremetal-operator/pull/454) * [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/934c2181e98f11c1a2629bd34d4a09e61323ffd6...9508bd334d661b6e8e76d452082f9a6f822a7739) ### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/e5aeca52d0a0739f1a87f39c9e5d4fa3592370ea) * NO-JIRA: Allow sustaining engineering to self serve dependency updates [#561](https://github.com/openshift/cluster-capi-operator/pull/561) * [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/203435ef87a2bed13fc43db893deb8bee1dff97f...e5aeca52d0a0739f1a87f39c9e5d4fa3592370ea) ### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/445ccbfe8aba60c99931701d7728ae7ee012eba8) * [OCPBUGS-63169](https://issues.redhat.com/browse/OCPBUGS-63169): ccm: disable unused secure-serving port and webhook [#424](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/424) * [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/56181136d91dff7bac4aa5acb2c1461381ac6e34...445ccbfe8aba60c99931701d7728ae7ee012eba8) ### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/e1b692b1e9552db95c17f6a03b41d258237ab480) * [OCPBUGS-45839](https://issues.redhat.com/browse/OCPBUGS-45839): relax validation on delete and if failureDomains not configured [#336](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/336) * [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/c03231f93a4630b94d86dde98688f357777c14b6...e1b692b1e9552db95c17f6a03b41d258237ab480) ### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/73aa60d1fd4e86aed93d67ddac62586ecbb70644) * [OCPBUGS-52499](https://issues.redhat.com/browse/OCPBUGS-52499): [release-4.15] Add runbook_url for CoreDNSErrorsHigh [#432](https://github.com/openshift/cluster-dns-operator/pull/432) * [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/49290d7db2194df73dfaeb1e719580dabf166690...73aa60d1fd4e86aed93d67ddac62586ecbb70644) ### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/f1569c6cc1c4e98ee538433416165542acf600a9) * [OCPBUGS-67931](https://issues.redhat.com/browse/OCPBUGS-67931): Update logrus to 1.9.3 to address CVE-2025-65637 [#1547](https://github.com/openshift/cluster-etcd-operator/pull/1547) * [OCPBUGS-53506](https://issues.redhat.com/browse/OCPBUGS-53506): fix CVE-2025-30204 [#1404](https://github.com/openshift/cluster-etcd-operator/pull/1404) * [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/b72a596d1f588da8eca821f28f286dfd609691d1...f1569c6cc1c4e98ee538433416165542acf600a9) ### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/8558f479e1cfc437a898bdf895bfdbd7ae5fb070) * [OCPBUGS-67932](https://issues.redhat.com/browse/OCPBUGS-67932): Bump logrus to 1.9.1 [#1289](https://github.com/openshift/cluster-image-registry-operator/pull/1289) * [OCPBUGS-53866](https://issues.redhat.com/browse/OCPBUGS-53866): bump github.com/golang-jwt/jwt [#1220](https://github.com/openshift/cluster-image-registry-operator/pull/1220) * [OCPBUGS-51596](https://issues.redhat.com/browse/OCPBUGS-51596): bump golang.org/x/oauth2 [#1211](https://github.com/openshift/cluster-image-registry-operator/pull/1211) * [OCPBUGS-51264](https://issues.redhat.com/browse/OCPBUGS-51264): ensure that storage names don't end in dashes [#1183](https://github.com/openshift/cluster-image-registry-operator/pull/1183) * [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/6776f554e8b0664f6e7f54abc4a2c03f42a2a378...8558f479e1cfc437a898bdf895bfdbd7ae5fb070) ### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/06d213a748af01d9c94de4dc823e945e1138af2a) * [OCPBUGS-86712](https://issues.redhat.com/browse/OCPBUGS-86712): Add configuration override for X-SSL strip [#1491](https://github.com/openshift/cluster-ingress-operator/pull/1491) * [OCPBUGS-49392](https://issues.redhat.com/browse/OCPBUGS-49392): Block Upgrades in release 4.15 for CA-Signed Certs Using SHA1 [#1172](https://github.com/openshift/cluster-ingress-operator/pull/1172) * [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/9e0d092565a4589dbcbafb7b1212651afa6d36fa...06d213a748af01d9c94de4dc823e945e1138af2a) ### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/9e3f9ec8a3c1c42643af78c61e984d077a692da2) * [OCPBUGS-67937](https://issues.redhat.com/browse/OCPBUGS-67937): CVE-2025-65637 openshift4/ose-cluster-kube-apiserver-rhel9-operator: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [openshift-4.15.z] [#2044](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2044) * [OCPBUGS-50661](https://issues.redhat.com/browse/OCPBUGS-50661): Increase waitForFallbackDegradedConditionTimeout [#1806](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1806) * [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/aabc7863cdbd76f8909a10fbc1be53b032e4ec31...9e3f9ec8a3c1c42643af78c61e984d077a692da2) ### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/4c1078415f28ca8b9ea051f1a505bee61763ea3c) * [OCPBUGS-67987](https://issues.redhat.com/browse/OCPBUGS-67987): CVE-2025-65637 openshift4/ose-kube-proxy-rhel9: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [openshift-4.15.z] [#910](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/910) * [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/ee8cf52558df0862f9927dbc7275fbe6cc1a1e5f...4c1078415f28ca8b9ea051f1a505bee61763ea3c) ### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/183510ee50bb135bfe685bf40b3a7d6aecad27fe) * [CNTRLPLANE-2843](https://issues.redhat.com/browse/CNTRLPLANE-2843): chore: update OWNERS [#625](https://github.com/openshift/cluster-kube-scheduler-operator/pull/625) * [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/f054dfaf189b43b262c11ef7f97038c79592c796...183510ee50bb135bfe685bf40b3a7d6aecad27fe) ### [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/tree/acf9540b9d87be60f2bee90d38e06eac674a3e20) * [OCPBUGS-67942](https://issues.redhat.com/browse/OCPBUGS-67942): Bump github.com/sirupsen/logrus to v1.9.1 [#145](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/145) * [Full changelog](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/compare/e76cea5f52bd5a125d051c6a0da4127a4dae6700...acf9540b9d87be60f2bee90d38e06eac674a3e20) ### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/863813ecd7b4c1416e76120896add365c492a59e) * [OCPBUGS-46034](https://issues.redhat.com/browse/OCPBUGS-46034): Ensure trailing dots on DNS names do not block serving cert auth [#258](https://github.com/openshift/cluster-machine-approver/pull/258) * [OCPBUGS-46034](https://issues.redhat.com/browse/OCPBUGS-46034): Client internal DNS checks should ignore trailing dot [#252](https://github.com/openshift/cluster-machine-approver/pull/252) * [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/6a809ce320324a3f841c7ac992cc77eafe1d97d7...863813ecd7b4c1416e76120896add365c492a59e) ### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/93b9d9424899b6215c1915c21ffe4bece71f7ebf) * [OCPBUGS-66047](https://issues.redhat.com/browse/OCPBUGS-66047): test: remove image registry e2e tests [#2757](https://github.com/openshift/cluster-monitoring-operator/pull/2757) * [OCPBUGS-46570](https://issues.redhat.com/browse/OCPBUGS-46570): Add new metrics for OpenShift logging telemetry [#2541](https://github.com/openshift/cluster-monitoring-operator/pull/2541) * [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/2eb5a2c888b61fdbf80a238c3ff13787f989b7b2...93b9d9424899b6215c1915c21ffe4bece71f7ebf) ### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/aaa0f93307493501fbad73002311b7d65005387e) * [OCPBUGS-84183](https://issues.redhat.com/browse/OCPBUGS-84183): fix(hypershift): use net.JoinHostPort for URL construction [#2995](https://github.com/openshift/cluster-network-operator/pull/2995) * [OCPBUGS-62980](https://issues.redhat.com/browse/OCPBUGS-62980): Update CNO reviewers/approvers [#2817](https://github.com/openshift/cluster-network-operator/pull/2817) * [OCPBUGS-56649](https://issues.redhat.com/browse/OCPBUGS-56649): Fix live migration with feature migration configured explicitly [#2715](https://github.com/openshift/cluster-network-operator/pull/2715) * [OCPBUGS-36688](https://issues.redhat.com/browse/OCPBUGS-36688), [OCPBUGS-43099](https://issues.redhat.com/browse/OCPBUGS-43099): Unexpected Behavior During Cluster Upgrade for the ovn-ipsec-host pods [#2658](https://github.com/openshift/cluster-network-operator/pull/2658) * [OCPBUGS-53282](https://issues.redhat.com/browse/OCPBUGS-53282): Not update status.migration of the network.config CR to empty [#2669](https://github.com/openshift/cluster-network-operator/pull/2669) * [Release 4.15] OCPBUGS-51208: Use applyconfigurations for updating network.oprerator status [#2653](https://github.com/openshift/cluster-network-operator/pull/2653) * [OCPBUGS-47633](https://issues.redhat.com/browse/OCPBUGS-47633): Prevent live migration process from flapping between step-2 and step-3 [#2609](https://github.com/openshift/cluster-network-operator/pull/2609) * [OCPBUGS-45890](https://issues.redhat.com/browse/OCPBUGS-45890): Pass transit_switch_subnet options in ovnkube-node pod [#2587](https://github.com/openshift/cluster-network-operator/pull/2587) * [OCPBUGS-43716](https://issues.redhat.com/browse/OCPBUGS-43716): Skip including default crypto policies to avoid authby issue [#2599](https://github.com/openshift/cluster-network-operator/pull/2599) * [OCPBUGS-46149](https://issues.redhat.com/browse/OCPBUGS-46149): Remove ip xfrm state when IPsec is disabled [#2596](https://github.com/openshift/cluster-network-operator/pull/2596) * [OCPBUGS-43605](https://issues.redhat.com/browse/OCPBUGS-43605): OCPBUGS-42244: Exporting environment varialbe NODE_CNI for live migration [#2539](https://github.com/openshift/cluster-network-operator/pull/2539) * [OCPBUGS-44973](https://issues.redhat.com/browse/OCPBUGS-44973), [SDN-5436](https://issues.redhat.com/browse/SDN-5436): Provide support for user owned IPsec machine configs [#2576](https://github.com/openshift/cluster-network-operator/pull/2576) * [Full changelog](https://github.com/openshift/cluster-network-operator/compare/7b8459dc88657a44785995a4c0cc88403a95954d...aaa0f93307493501fbad73002311b7d65005387e) ### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/e828bd93defc0cc9c3fcf799d9715b95b2c03f79) * e2e:performance: decode to valid kubeletconfig object (#1275) [#1275](https://github.com/openshift/cluster-node-tuning-operator/pull/1275) * Fix context deadlines in ExecCommandOnPod() (#1265) [#1265](https://github.com/openshift/cluster-node-tuning-operator/pull/1265) * [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/4010bec15ab232b10d847df430b72913c8e66573...e828bd93defc0cc9c3fcf799d9715b95b2c03f79) ### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/0a6713150279776bada78c64717c2a8af0dce16b) * [OCPBUGS-86345](https://issues.redhat.com/browse/OCPBUGS-86345): Update grpc-go to v1.64.1-sec.1 to fix CVE-2026-33186 [#208](https://github.com/openshift/cluster-olm-operator/pull/208) * [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/a7ba89874970cd10765e1d0753405e32fb357d84...0a6713150279776bada78c64717c2a8af0dce16b) ### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/031c048d17690cf5601addfe7de3eb6b067fabbd) * [OCPBUGS-67946](https://issues.redhat.com/browse/OCPBUGS-67946): CVE-2025-65637 - Bump github.com/sirupsen/logrus from v1.9.0 to v1.9.3 [release-4.15] [#655](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/655) * [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/078c81f6e3e39675e8b1edd864e1ddf72472bb73...031c048d17690cf5601addfe7de3eb6b067fabbd) ### [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator/tree/1ae0ba75cfdb910990437ab2898690b9e3f8f94a) * [OCPBUGS-48832](https://issues.redhat.com/browse/OCPBUGS-48832): Add new team members to the OWNERS file [#379](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/379) * [Full changelog](https://github.com/openshift/cluster-openshift-controller-manager-operator/compare/68e8bcd5c5df5072d5eefb8abd9c9ecab289adf4...1ae0ba75cfdb910990437ab2898690b9e3f8f94a) ### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/a01ebb5009c7dd0f0adcd0647660797fb5f3aa74) * [OCPBUGS-63517](https://issues.redhat.com/browse/OCPBUGS-63517): references to github.com/sclorg/django-ex.git now also refer to the branch [#660](https://github.com/openshift/cluster-samples-operator/pull/660) * [OCPBUGS-55475](https://issues.redhat.com/browse/OCPBUGS-55475): Adding mutex to func createSamples on handler.go [#634](https://github.com/openshift/cluster-samples-operator/pull/634) * [OCPBUGS-54481](https://issues.redhat.com/browse/OCPBUGS-54481): add rhdmalone to owners [#623](https://github.com/openshift/cluster-samples-operator/pull/623) * [OCPBUGS-49369](https://issues.redhat.com/browse/OCPBUGS-49369): add shannon and aroyoredhat as owners [#597](https://github.com/openshift/cluster-samples-operator/pull/597) * [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/dac17316605b5dbdc0b12f84af7ff3aa41e8f577...a01ebb5009c7dd0f0adcd0647660797fb5f3aa74) ### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/d9bee3eaafae6fc37e8286bb04011cad1fd1dbc5) * [OCPBUGS-87726](https://issues.redhat.com/browse/OCPBUGS-87726): remove oVirt code from CSO 4.15 [#710](https://github.com/openshift/cluster-storage-operator/pull/710) * [OCPBUGS-67955](https://issues.redhat.com/browse/OCPBUGS-67955): bump github.com/sirupsen/logrus to v1.9.3 [#654](https://github.com/openshift/cluster-storage-operator/pull/654) * [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/4c2b89d6a00e5a0c300b61dbad2a9e289c404e98...d9bee3eaafae6fc37e8286bb04011cad1fd1dbc5) ### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/2cb8ce9ef5c3311be9f1ea266356f1ce95bec1d1) * [OCPBUGS-50591](https://issues.redhat.com/browse/OCPBUGS-50591): Set `openshift.io/required-scc`: privileged annotation in `version` pods [#1152](https://github.com/openshift/cluster-version-operator/pull/1152) * [OCPBUGS-45330](https://issues.redhat.com/browse/OCPBUGS-45330): deps: bump golang.org/x/net to 0.31.0 [#1119](https://github.com/openshift/cluster-version-operator/pull/1119) * [Full changelog](https://github.com/openshift/cluster-version-operator/compare/fbb41e8d40fd3753fb44cffe68189b717356c564...2cb8ce9ef5c3311be9f1ea266356f1ce95bec1d1) ### [console](https://github.com/openshift/console/tree/e7d7a6129f7e003bdb91215c99a9643f3211eef7) * [OCPBUGS-87983](https://issues.redhat.com/browse/OCPBUGS-87983): [release-4.15] shell-quote: Arbitrary code execution via command injection due to unescaped line terminators [#16598](https://github.com/openshift/console/pull/16598) * [OCPBUGS-77117](https://issues.redhat.com/browse/OCPBUGS-77117): [release-4.15] CVE-2026-26996 Bump minimatch library [#16347](https://github.com/openshift/console/pull/16347) * Fix for OCPBUGS-81596: CVE-2026-4800 [#16567](https://github.com/openshift/console/pull/16567) * [OCPBUGS-88366](https://issues.redhat.com/browse/OCPBUGS-88366), [OCPBUGS-88379](https://issues.redhat.com/browse/OCPBUGS-88379), [OCPBUGS-88395](https://issues.redhat.com/browse/OCPBUGS-88395), [OCPBUGS-88402](https://issues.redhat.com/browse/OCPBUGS-88402), [OCPBUGS-88415](https://issues.redhat.com/browse/OCPBUGS-88415), [OCPBUGS-88427](https://issues.redhat.com/browse/OCPBUGS-88427), [OCPBUGS-88445](https://issues.redhat.com/browse/OCPBUGS-88445): CVE-2026-44495 [#16611](https://github.com/openshift/console/pull/16611) * [OCPBUGS-79436](https://issues.redhat.com/browse/OCPBUGS-79436): CVE-2026-29063 Bump immutable [#16328](https://github.com/openshift/console/pull/16328) * NO-JIRA: enable multi-architecture yarn builds [#16425](https://github.com/openshift/console/pull/16425) * [OCPBUGS-83298](https://issues.redhat.com/browse/OCPBUGS-83298): [release-4.15] openshift4/ose-console: Axios: Remote Code Execution via Prototype Pollution escalation [#16302](https://github.com/openshift/console/pull/16302) * [OCPBUGS-76575](https://issues.redhat.com/browse/OCPBUGS-76575): Bump axios [#16033](https://github.com/openshift/console/pull/16033) * [CONSOLE-5011](https://issues.redhat.com/browse/CONSOLE-5011): migrate to yarn berry [#16081](https://github.com/openshift/console/pull/16081) * NO-JIRA: Bump builder image to v29 [#15992](https://github.com/openshift/console/pull/15992) * [OCPBUGS-74443](https://issues.redhat.com/browse/OCPBUGS-74443): Bump lodash to latest [#15970](https://github.com/openshift/console/pull/15970) * [OCPBUGS-69767](https://issues.redhat.com/browse/OCPBUGS-69767): Disallowed Pipelines-plugin Pipelines navigation section [#15864](https://github.com/openshift/console/pull/15864) * [OCPBUGS-65822](https://issues.redhat.com/browse/OCPBUGS-65822): Remove required flag from 'console.flag/model' pipelines-plugin extension [#15749](https://github.com/openshift/console/pull/15749) * [OCPBUGS-65601](https://issues.redhat.com/browse/OCPBUGS-65601): `/auth/error?error=missing_state&error_type=auth` is showing blank page [#15727](https://github.com/openshift/console/pull/15727) * [OCPBUGS-44159](https://issues.redhat.com/browse/OCPBUGS-44159): bump dompurify to latest [#15592](https://github.com/openshift/console/pull/15592) * [OCPBUGS-60672](https://issues.redhat.com/browse/OCPBUGS-60672): Secret key with binary file changes when edited via Console [#15422](https://github.com/openshift/console/pull/15422) * [OCPBUGS-59997](https://issues.redhat.com/browse/OCPBUGS-59997): Remove the devconsole backend common internet proxy and replace it with dedicated ones [#15359](https://github.com/openshift/console/pull/15359) * [OCPBUGS-59564](https://issues.redhat.com/browse/OCPBUGS-59564): Add flags in console static plugin for all the components of this epic [#15306](https://github.com/openshift/console/pull/15306) * [OCPBUGS-60029](https://issues.redhat.com/browse/OCPBUGS-60029): fix bug where / in console.tab/horizontalNav href brea… [#15353](https://github.com/openshift/console/pull/15353) * [OCPBUGS-57521](https://issues.redhat.com/browse/OCPBUGS-57521): Debug pod logs are not accessible when debugging a node via OpenShift Console [#15181](https://github.com/openshift/console/pull/15181) * [OCPBUGS-58223](https://issues.redhat.com/browse/OCPBUGS-58223): Fix TypeError Cannot read properties of null (reading 'metadata') [#15221](https://github.com/openshift/console/pull/15221) * [OCPBUGS-57097](https://issues.redhat.com/browse/OCPBUGS-57097): Add all files to `vendor` regardless of gitignore [#15134](https://github.com/openshift/console/pull/15134) * [OCPBUGS-45257](https://issues.redhat.com/browse/OCPBUGS-45257): Enabling topology e2e tests on CI [#14721](https://github.com/openshift/console/pull/14721) * [OCPBUGS-55733](https://issues.redhat.com/browse/OCPBUGS-55733): fix bug where operator appears twice [#15021](https://github.com/openshift/console/pull/15021) * [OCPBUGS-55174](https://issues.redhat.com/browse/OCPBUGS-55174): Add missing pipelines plugin name to known plugins [#14982](https://github.com/openshift/console/pull/14982) * [OCPBUGS-54673](https://issues.redhat.com/browse/OCPBUGS-54673): Added token to proxy header [#14943](https://github.com/openshift/console/pull/14943) * [OCPBUGS-54252](https://issues.redhat.com/browse/OCPBUGS-54252): Update the monitoring topic used by the console team [#14904](https://github.com/openshift/console/pull/14904) * [OCPBUGS-53138](https://issues.redhat.com/browse/OCPBUGS-53138): fix run time error when no completed version exists [#14879](https://github.com/openshift/console/pull/14879) * [OCPBUGS-53055](https://issues.redhat.com/browse/OCPBUGS-53055): Show Observe section without PROMETHEUS and MONITORING flags [#14867](https://github.com/openshift/console/pull/14867) * [OCPBUGS-52344](https://issues.redhat.com/browse/OCPBUGS-52344): fix alert rule link [#14828](https://github.com/openshift/console/pull/14828) * [OCPBUGS-51332](https://issues.redhat.com/browse/OCPBUGS-51332): Do not pass CSV name to operand list page when an exen… [#14800](https://github.com/openshift/console/pull/14800) * [OCPBUGS-49849](https://issues.redhat.com/browse/OCPBUGS-49849): include external labels so silenced alerts not displayed in notifications [#14718](https://github.com/openshift/console/pull/14718) * [OCPBUGS-48593](https://issues.redhat.com/browse/OCPBUGS-48593): ReRun of Resolver based PipelineRuns fails from UI [#14689](https://github.com/openshift/console/pull/14689) * [OCPBUGS-48592](https://issues.redhat.com/browse/OCPBUGS-48592): ImagePullSecret getting duplicated when editing DeploymentConfig in Form View [#14688](https://github.com/openshift/console/pull/14688) * [OCPBUGS-48048](https://issues.redhat.com/browse/OCPBUGS-48048): Update vendor imports to include all PatternFly components [#14662](https://github.com/openshift/console/pull/14662) * [OCPBUGS-47646](https://issues.redhat.com/browse/OCPBUGS-47646): fix table combination [#14649](https://github.com/openshift/console/pull/14649) * [OCPBUGS-46430](https://issues.redhat.com/browse/OCPBUGS-46430): Plugins that use very old PF4 dropdown or menu components with grouped items have bullets and padding that needs to be removed. [#14626](https://github.com/openshift/console/pull/14626) * [OCPBUGS-45950](https://issues.redhat.com/browse/OCPBUGS-45950): Unable to remove finally tasks in pipeline builder mode [#14606](https://github.com/openshift/console/pull/14606) * [OCPBUGS-46389](https://issues.redhat.com/browse/OCPBUGS-46389): use TaskRuns results.tekton.dev/record annotation to get the logs [#14622](https://github.com/openshift/console/pull/14622) * [OCPBUGS-45248](https://issues.redhat.com/browse/OCPBUGS-45248): Remove ClusterTask dependency in console from Pipelines 1.17 [#14564](https://github.com/openshift/console/pull/14564) * [OCPBUGS-44979](https://issues.redhat.com/browse/OCPBUGS-44979): Don't request user settings configmap if no user has been loaded. [#14534](https://github.com/openshift/console/pull/14534) * [OCPBUGS-37397](https://issues.redhat.com/browse/OCPBUGS-37397): RWOP accessMode is not available on OpenShift console UI [#14078](https://github.com/openshift/console/pull/14078) * [OCPBUGS-44998](https://issues.redhat.com/browse/OCPBUGS-44998): Add IBM Block Storage CSI driver support for RWX [#14536](https://github.com/openshift/console/pull/14536) * [OCPBUGS-44738](https://issues.redhat.com/browse/OCPBUGS-44738): Add flag to hide the pipelines-plugin pipeline builder extensions [#14513](https://github.com/openshift/console/pull/14513) * [Full changelog](https://github.com/openshift/console/compare/8e9e4015d859afb4219ae4c770a258fdf8aca565...e7d7a6129f7e003bdb91215c99a9643f3211eef7) ### [console-operator](https://github.com/openshift/console-operator/tree/62e16389f77d5f4b9dfab6a9e902f69bfce2ae0d) * [OCPBUGS-77993](https://issues.redhat.com/browse/OCPBUGS-77993): [release-4.15] hermetic 4.15 [#1130](https://github.com/openshift/console-operator/pull/1130) * [OCPBUGS-77993](https://issues.redhat.com/browse/OCPBUGS-77993): [release-4.15] NO-JIRA: update go mod dependency for konflux [#1116](https://github.com/openshift/console-operator/pull/1116) * [OCPBUGS-46482](https://issues.redhat.com/browse/OCPBUGS-46482): Dont disable console when authConfig type is set to None [#953](https://github.com/openshift/console-operator/pull/953) * [Full changelog](https://github.com/openshift/console-operator/compare/5d7ebcddf5a58d44ba37d63b149b06d6fc5ae1d8...62e16389f77d5f4b9dfab6a9e902f69bfce2ae0d) ### [container-networking-plugins](https://github.com/openshift/containernetworking-plugins/tree/ffce799a1d110ae86e2f86052e3f930020782fb4) * [OCPBUGS-85668](https://issues.redhat.com/browse/OCPBUGS-85668): CI Build root image tag sync with ART [#233](https://github.com/openshift/containernetworking-plugins/pull/233) * [OCPBUGS-55948](https://issues.redhat.com/browse/OCPBUGS-55948): Check error returned by ipv6 SettleAddresses [#190](https://github.com/openshift/containernetworking-plugins/pull/190) * [OCPBUGS-37732](https://issues.redhat.com/browse/OCPBUGS-37732): Update owners [#167](https://github.com/openshift/containernetworking-plugins/pull/167) * [Full changelog](https://github.com/openshift/containernetworking-plugins/compare/401d35070f2d1d4db3f08ffe183b8262754b7287...ffce799a1d110ae86e2f86052e3f930020782fb4) ### [coredns](https://github.com/openshift/coredns/tree/d3a19e6731ea414a520cfad85c11634f4824c895) * [OCPBUGS-77512](https://issues.redhat.com/browse/OCPBUGS-77512): Modify .gitignore to not exclude vendor build folders [#169](https://github.com/openshift/coredns/pull/169) * [Full changelog](https://github.com/openshift/coredns/compare/1326282c9e158078634be4261b75ded247d233d7...d3a19e6731ea414a520cfad85c11634f4824c895) ### [csi-driver-manila, openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/cacadb5f282c92a9f8ca290a6d101182a55d957b) * [OCPBUGS-79905](https://issues.redhat.com/browse/OCPBUGS-79905): Bump google.golang.org/grpc [#398](https://github.com/openshift/cloud-provider-openstack/pull/398) * [OCPBUGS-67958](https://issues.redhat.com/browse/OCPBUGS-67958): fix CVE-2025-65637 [#362](https://github.com/openshift/cloud-provider-openstack/pull/362) * [OCPBUGS-58885](https://issues.redhat.com/browse/OCPBUGS-58885): CARRY: don't ignore json files [#342](https://github.com/openshift/cloud-provider-openstack/pull/342) * [OCPBUGS-43375](https://issues.redhat.com/browse/OCPBUGS-43375): Merge https://github.com/kubernetes/cloud-provider-openstack:release-1.28 into release-4.15 [#297](https://github.com/openshift/cloud-provider-openstack/pull/297) * [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/6ab1226a552376801e1f5712e3189a27729a23ed...cacadb5f282c92a9f8ca290a6d101182a55d957b) ### [csi-driver-manila-operator](https://github.com/openshift/csi-driver-manila-operator/tree/0b072d27aceb3e2589c962530a02b2de450d5f08) * [OCPBUGS-67959](https://issues.redhat.com/browse/OCPBUGS-67959): Bump logrus [#252](https://github.com/openshift/csi-driver-manila-operator/pull/252) * [Full changelog](https://github.com/openshift/csi-driver-manila-operator/compare/9bcf382eb68d3dd13a553dce41822d24da3870d0...0b072d27aceb3e2589c962530a02b2de450d5f08) ### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/f55d6f0de700a7d30634a870d5cc5ccb0fc24f98) * [OCPBUGS-84930](https://issues.redhat.com/browse/OCPBUGS-84930): Replace google.golang.org/grpc with github.com/openshift-sustaining/grpc-go v1.64.1-sec.1 to avoid go version bump and fix CVE-2026-33186 [#183](https://github.com/openshift/csi-driver-nfs/pull/183) * [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/d032dc1050b58a965e6bb9f923baef6d3c95538e...f55d6f0de700a7d30634a870d5cc5ccb0fc24f98) ### [docker-builder](https://github.com/openshift/builder/tree/5c5fbe01beb8eb7a82fde14efff6385fed88e72a) * [OCPBUGS-65960](https://issues.redhat.com/browse/OCPBUGS-65960): BuildConfig inline Dockerfile fails with heredoc syntax [#491](https://github.com/openshift/builder/pull/491) * [OCPBUGS-58141](https://issues.redhat.com/browse/OCPBUGS-58141): S2I build cpu limits observed by assemble are limited to 1 cpu [#477](https://github.com/openshift/builder/pull/477) * [OCPBUGS-42917](https://issues.redhat.com/browse/OCPBUGS-42917), [OCPBUGS-43294](https://issues.redhat.com/browse/OCPBUGS-43294): Bump buildah to 1.33.12 [#442](https://github.com/openshift/builder/pull/442) * [OCPBUGS-43188](https://issues.redhat.com/browse/OCPBUGS-43188): runc library bump to 1.1.12 [#436](https://github.com/openshift/builder/pull/436) * [OCPBUGS-48298](https://issues.redhat.com/browse/OCPBUGS-48298): skipping some unit tests to avoid failures as they are duplicate [#428](https://github.com/openshift/builder/pull/428) * [OCPBUGS-48281](https://issues.redhat.com/browse/OCPBUGS-48281): Add team members to the OWNERS file [#427](https://github.com/openshift/builder/pull/427) * [Full changelog](https://github.com/openshift/builder/compare/160e7cacc7ab7a6664e4c574b78139a29ace9cd3...5c5fbe01beb8eb7a82fde14efff6385fed88e72a) ### [docker-registry](https://github.com/openshift/image-registry/tree/89c03ea33937f22ce59a0b4faff51cff8c237176) * [OCPBUGS-53650](https://issues.redhat.com/browse/OCPBUGS-53650): bump jwt and oauth dependencies [#433](https://github.com/openshift/image-registry/pull/433) * [Full changelog](https://github.com/openshift/image-registry/compare/b9de67d83c9f850ed42317495b7b340109b3c9ac...89c03ea33937f22ce59a0b4faff51cff8c237176) ### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/3a2055f00aa0b2c1960b13639b10603a613eac85) * [OCPBUGS-78281](https://issues.redhat.com/browse/OCPBUGS-78281): [release-4.15] update go mod dependency for konflux [#268](https://github.com/openshift/cluster-api-provider-gcp/pull/268) * [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/bad54034ed075b24ee8962661e78cfbd84a7dd0a...3a2055f00aa0b2c1960b13639b10603a613eac85) ### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/ebf48aea8055ab0996f110d262f4225e4200cd35) * [OCPBUGS-79899](https://issues.redhat.com/browse/OCPBUGS-79899): Address CVE-2026-33186 [#175](https://github.com/openshift/machine-api-provider-gcp/pull/175) * [OCPBUGS-79899](https://issues.redhat.com/browse/OCPBUGS-79899): Fix setup-envtest GCS 401 by downloading binaries directly [#177](https://github.com/openshift/machine-api-provider-gcp/pull/177) * [OCPBUGS-55410](https://issues.redhat.com/browse/OCPBUGS-55410), [OCPBUGS-55411](https://issues.redhat.com/browse/OCPBUGS-55411): Disable shielded VMs for non-UEFI disks [#117](https://github.com/openshift/machine-api-provider-gcp/pull/117) * [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/b15daaf5836910277b7154a006800505f018aa5a...ebf48aea8055ab0996f110d262f4225e4200cd35) ### [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver/tree/9016f437233494ce9b224bb1adae6f6e0ac7e102) * [OCPBUGS-67973](https://issues.redhat.com/browse/OCPBUGS-67973): Update logrus to v1.9.3 [#93](https://github.com/openshift/gcp-pd-csi-driver/pull/93) * [Full changelog](https://github.com/openshift/gcp-pd-csi-driver/compare/856ee3e23802cd341619cc4fc3181cf6ebbbd548...9016f437233494ce9b224bb1adae6f6e0ac7e102) ### [gcp-pd-csi-driver-operator](https://github.com/openshift/gcp-pd-csi-driver-operator/tree/7cec5854d50298a19ae85290fbdbde5a3de6c898) * [OCPBUGS-67971](https://issues.redhat.com/browse/OCPBUGS-67971): bump github.com/sirupsen/logrus to v1.9.3 [#161](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/161) * [Full changelog](https://github.com/openshift/gcp-pd-csi-driver-operator/compare/3b91ee310c8a7394ceb2d4de6a51dd18a3800312...7cec5854d50298a19ae85290fbdbde5a3de6c898) ### [haproxy-router](https://github.com/openshift/router/tree/cd8a009efd84c29c462f67dfe20a2a7d12dc577b) * [OCPBUGS-86712](https://issues.redhat.com/browse/OCPBUGS-86712): Strip X-SSL-* headers for plain HTTP [#806](https://github.com/openshift/router/pull/806) * [OCPBUGS-49392](https://issues.redhat.com/browse/OCPBUGS-49392): Block Upgrades for CA-Signed Certs Using SHA1 [#641](https://github.com/openshift/router/pull/641) * [Full changelog](https://github.com/openshift/router/compare/dc38fbd84dfbed3a897f2d36b469d0ccfd1ecda3...cd8a009efd84c29c462f67dfe20a2a7d12dc577b) ### [hyperkube, pod](https://github.com/openshift/kubernetes/tree/5cb2ef48f2e7e6cd14abc5e7a5ee90cd25f0d744) * [OCPBUGS-67902](https://issues.redhat.com/browse/OCPBUGS-67902), [OCPBUGS-67977](https://issues.redhat.com/browse/OCPBUGS-67977): CVE-2025-65637 - bump github.com/sirupsen/logrus to v1.9.3 [4.15] [#2583](https://github.com/openshift/kubernetes/pull/2583) * [OCPBUGS-74300](https://issues.redhat.com/browse/OCPBUGS-74300): Skip E2e: attach on previously attached volumes should work [#2569](https://github.com/openshift/kubernetes/pull/2569) * [OCPBUGS-59147](https://issues.redhat.com/browse/OCPBUGS-59147): UPSTREAM: 130047: adjusting loopback certificate validity in kube-apiserver [#2358](https://github.com/openshift/kubernetes/pull/2358) * [OCPBUGS-59147](https://issues.redhat.com/browse/OCPBUGS-59147): UPSTREAM: <carry>: disable some legacy cloud provider Azure tests [#2359](https://github.com/openshift/kubernetes/pull/2359) * [OCPBUGS-52183](https://issues.redhat.com/browse/OCPBUGS-52183): UPSTREAM: <carry>: kubelet/cm: fix bug where kubelet restarts from missing cpuset cgroup [#2227](https://github.com/openshift/kubernetes/pull/2227) * [OCPBUGS-53139](https://issues.redhat.com/browse/OCPBUGS-53139): UPSTREAM: 129180: prevent unnecessary resolving of iscsi/fc devices to dm [#2244](https://github.com/openshift/kubernetes/pull/2244) * [OCPBUGS-44514](https://issues.redhat.com/browse/OCPBUGS-44514): Bump k8s api to 1.28.15 [#2132](https://github.com/openshift/kubernetes/pull/2132) * [Full changelog](https://github.com/openshift/kubernetes/compare/502c5ce31170c64d2cb97884b450aea9b63eb2e8...5cb2ef48f2e7e6cd14abc5e7a5ee90cd25f0d744) ### [hypershift](https://github.com/openshift/hypershift/tree/78af170b990b7f57c31498d234b7e5325d23106e) * [release 4.15] Fix OCPBUGS-99080: CVE-2026-16242 konnectivity agent auth [#9130](https://github.com/openshift/hypershift/pull/9130) * [OCPBUGS-84183](https://issues.redhat.com/browse/OCPBUGS-84183): fix(cno): use brackets only for IPv6 in server URL [#8308](https://github.com/openshift/hypershift/pull/8308) * [OCPBUGS-74670](https://issues.redhat.com/browse/OCPBUGS-74670), [OCPBUGS-74671](https://issues.redhat.com/browse/OCPBUGS-74671): Support proxy authentication when user/pass is included in URL [#7606](https://github.com/openshift/hypershift/pull/7606) * [CNTRLPLANE-1266](https://issues.redhat.com/browse/CNTRLPLANE-1266): Drop extinct mce-2.5 pipeline [#6655](https://github.com/openshift/hypershift/pull/6655) * [CNTRLPLANE-1232](https://issues.redhat.com/browse/CNTRLPLANE-1232): Move CPO pipeline to hermetic builds [#6601](https://github.com/openshift/hypershift/pull/6601) * [OCPBUGS-58506](https://issues.redhat.com/browse/OCPBUGS-58506): [release-4.15] Add missing service network DNS entries to KAS cert [#6394](https://github.com/openshift/hypershift/pull/6394) * [OCPBUGS-57553](https://issues.redhat.com/browse/OCPBUGS-57553): Add proxy variables for the MCD Pod [#6293](https://github.com/openshift/hypershift/pull/6293) * [OCPBUGS-57121](https://issues.redhat.com/browse/OCPBUGS-57121): Add validation to avoid conflicts between KubeAPIServer and NamedCertificates SANs [#6231](https://github.com/openshift/hypershift/pull/6231) * [OCPBUGS-46467](https://issues.redhat.com/browse/OCPBUGS-46467): Consistently look up and dial cloud API hostnames [#5300](https://github.com/openshift/hypershift/pull/5300) * [OCPBUGS-52590](https://issues.redhat.com/browse/OCPBUGS-52590): Honor proxy vars in the util insecure http client [#5791](https://github.com/openshift/hypershift/pull/5791) * [CNTRLPLANE-920](https://issues.redhat.com/browse/CNTRLPLANE-920): Konflux build pipeline service account migration [#6086](https://github.com/openshift/hypershift/pull/6086) * [CNTRLPLANE-920](https://issues.redhat.com/browse/CNTRLPLANE-920): Konflux build pipeline service account migration [#6081](https://github.com/openshift/hypershift/pull/6081) * [OCPBUGS-55266](https://issues.redhat.com/browse/OCPBUGS-55266): [release-4.15] Add konnectivity-proxy sidecar to openshift-oauth-apiserver [#6070](https://github.com/openshift/hypershift/pull/6070) * [OCPBUGS-51800](https://issues.redhat.com/browse/OCPBUGS-51800): Fix golang crypto dependency go.mod replacement [#5995](https://github.com/openshift/hypershift/pull/5995) * [OCPBUGS-53898](https://issues.redhat.com/browse/OCPBUGS-53898): bump golang-jwt v4 and v5 [#5908](https://github.com/openshift/hypershift/pull/5908) * Red Hat Konflux update control-plane-operator-4-15 [#5955](https://github.com/openshift/hypershift/pull/5955) * [ART-11792](https://issues.redhat.com/browse/ART-11792): update go mod dependency for konflux [#5923](https://github.com/openshift/hypershift/pull/5923) * [OCPBUGS-51729](https://issues.redhat.com/browse/OCPBUGS-51729), [OCPBUGS-51800](https://issues.redhat.com/browse/OCPBUGS-51800): Bump dependencies to OCP fork in backports [#5902](https://github.com/openshift/hypershift/pull/5902) * [OCPBUGS-50867](https://issues.redhat.com/browse/OCPBUGS-50867): Prevent IgnitionServer from flooding the API server with patch requests [#5633](https://github.com/openshift/hypershift/pull/5633) * [OCPBUGS-52992](https://issues.redhat.com/browse/OCPBUGS-52992): [release-4.15] OCPBUGS-52506: refactor aws identity health check into new controller [#5815](https://github.com/openshift/hypershift/pull/5815) * [OCPBUGS-52896](https://issues.redhat.com/browse/OCPBUGS-52896): Make managed-trust-bundle optional [#5813](https://github.com/openshift/hypershift/pull/5813) * [OCPBUGS-50699](https://issues.redhat.com/browse/OCPBUGS-50699): add region to AWS creds passed to operators managed by CPO [#5669](https://github.com/openshift/hypershift/pull/5669) * NO-JIRA: chore(deps): update dependency mkdocs-material to v9.6.6 [#5729](https://github.com/openshift/hypershift/pull/5729) * [OCPBUGS-51253](https://issues.redhat.com/browse/OCPBUGS-51253): OCPBUGS-50692: Fix IsIPv4 function identifying also addresses instead of CIDRs [#5701](https://github.com/openshift/hypershift/pull/5701) * [OCPBUGS-52172](https://issues.redhat.com/browse/OCPBUGS-52172): [release-4.15] Add HostedCluster additional trustbundles to konnectivity-https-proxy [#5722](https://github.com/openshift/hypershift/pull/5722) * NO-JIRA: chore(deps): update dependency mkdocs-material to v9.6.5 [#5683](https://github.com/openshift/hypershift/pull/5683) * chore(deps): update registry.access.redhat.com/ubi9-minimal docker tag to v9.5-1739420147 [#5624](https://github.com/openshift/hypershift/pull/5624) * NO-JIRA: chore(deps): update dependency mkdocs-material to v9 [#5642](https://github.com/openshift/hypershift/pull/5642) * NO-JIRA: chore(deps): update registry.access.redhat.com/ubi9-minimal docker tag to v9.5-1738816775 [#5576](https://github.com/openshift/hypershift/pull/5576) * NO-JIRA: chore(deps): update konflux references [#5588](https://github.com/openshift/hypershift/pull/5588) * NO-JIRA: Red Hat Konflux update control-plane-operator-4-15 [#5338](https://github.com/openshift/hypershift/pull/5338) * NO-JIRA: chore(deps): update dependency mkdocs-mermaid2-plugin to v0.6.0 [#5589](https://github.com/openshift/hypershift/pull/5589) * NO-JIRA: chore(deps): update squidfunk/mkdocs-material docker tag to v9.6.3 [#5586](https://github.com/openshift/hypershift/pull/5586) * NO-JIRA: chore(deps): update squidfunk/mkdocs-material docker tag to v9.6.2 [#5577](https://github.com/openshift/hypershift/pull/5577) * [OCPBUGS-49668](https://issues.redhat.com/browse/OCPBUGS-49668): fix overwriting PKI operator HCP conditions [#5512](https://github.com/openshift/hypershift/pull/5512) * NO-JIRA: chore(deps): update registry.access.redhat.com/ubi9/go-toolset docker tag to v9.5-1737480393 [#5486](https://github.com/openshift/hypershift/pull/5486) * NO-JIRA: chore(deps): update konflux references (release-4.15) [#5480](https://github.com/openshift/hypershift/pull/5480) * NO-JIRA: Update squidfunk/mkdocs-material Docker tag to v9.5.50 (release-4.15) [#5434](https://github.com/openshift/hypershift/pull/5434) * NO-JIRA: Update dependency mkdocs-material to v8.5.11 (release-4.15) [#5429](https://github.com/openshift/hypershift/pull/5429) * NO-JIRA: chore(deps): update konflux references (release-4.15) [#5425](https://github.com/openshift/hypershift/pull/5425) * NO-JIRA: chore(deps): update konflux references (release-4.15) [#5386](https://github.com/openshift/hypershift/pull/5386) * NO-JIRA: chore(deps): update registry.access.redhat.com/ubi9/go-toolset docker tag to v9.5-1736729788 (release-4.15) - abandoned [#5380](https://github.com/openshift/hypershift/pull/5380) * NO-JIRA: chore(deps): update registry.access.redhat.com/ubi9-minimal docker tag to v9.5-1736404155 (release-4.15) [#5379](https://github.com/openshift/hypershift/pull/5379) * NO-JIRA: Update squidfunk/mkdocs-material Docker tag to v9.5.49 (release-4.15) [#5385](https://github.com/openshift/hypershift/pull/5385) * NO-JIRA: [release-4.15] Bump golang.org/x/crypto and golang.org/x/net [#5371](https://github.com/openshift/hypershift/pull/5371) * NO-JIRA: chore(deps): update registry.access.redhat.com/ubi9/go-toolset docker tag to v9.5-1734626445 (release-4.15) - abandoned [#5344](https://github.com/openshift/hypershift/pull/5344) * NO-JIRA: chore(deps): update registry.access.redhat.com/ubi9-minimal docker tag to v9.5-1734497536 (release-4.15) [#5343](https://github.com/openshift/hypershift/pull/5343) * [OCPBUGS-46075](https://issues.redhat.com/browse/OCPBUGS-46075): Do not send traffic to local audit-webhook through konnectivity [#5274](https://github.com/openshift/hypershift/pull/5274) * NO-JIRA: Update dependency mkdocs-glightbox to v0.4.0 (release-4.15) [#5327](https://github.com/openshift/hypershift/pull/5327) * NO-JIRA: Update Konflux references (release-4.15) [#5326](https://github.com/openshift/hypershift/pull/5326) * [OCPBUGS-47545](https://issues.redhat.com/browse/OCPBUGS-47545): Separate CPO containerfiles [#5334](https://github.com/openshift/hypershift/pull/5334) * NO-JIRA: chore(deps): update dependency mkdocs to v1.6.1 (release-4.15) [#5292](https://github.com/openshift/hypershift/pull/5292) * NO-JIRA: chore(deps): update konflux references (release-4.15) [#5291](https://github.com/openshift/hypershift/pull/5291) * NO-JIRA: chore(deps): update konflux references (release-4.15) [#5251](https://github.com/openshift/hypershift/pull/5251) * [OCPBUGS-44522](https://issues.redhat.com/browse/OCPBUGS-44522): Add network policies for konnectivity server and ignition server proxy [#5120](https://github.com/openshift/hypershift/pull/5120) * [OCPBUGS-43931](https://issues.redhat.com/browse/OCPBUGS-43931): Return the right tagReference on Catalogs ImageStream [#5187](https://github.com/openshift/hypershift/pull/5187) * NO-JIRA: Update squidfunk/mkdocs-material Docker tag to v9.5.47 (release-4.15) [#5210](https://github.com/openshift/hypershift/pull/5210) * NO-JIRA: chore(deps): update konflux references (release-4.15) [#5208](https://github.com/openshift/hypershift/pull/5208) * NO-JIRA: chore(deps): update squidfunk/mkdocs-material docker tag to v9.5.46 (release-4.15) [#5190](https://github.com/openshift/hypershift/pull/5190) * NO-JIRA: chore(deps): update konflux references to 7779f9e (release-4.15) [#5182](https://github.com/openshift/hypershift/pull/5182) * [OCPBUGS-44278](https://issues.redhat.com/browse/OCPBUGS-44278): Configure OAuth https proxy to dial cloud endpoints directly [#5068](https://github.com/openshift/hypershift/pull/5068) * [Full changelog](https://github.com/openshift/hypershift/compare/ff2600ab1d4ff8f5b6a860b5e9f9e9b38724e667...78af170b990b7f57c31498d234b7e5325d23106e) ### [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver/tree/5b58d112224287f6d6491b0143c73d37817cb3fd) * [OCPBUGS-79893](https://issues.redhat.com/browse/OCPBUGS-79893): Bump google.golang.org/grpc to v1.79.3 [#148](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/148) * [OCPBUGS-77211](https://issues.redhat.com/browse/OCPBUGS-77211): [release-4.15] standardize build paths [#125](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/125) * [OCPBUGS-58739](https://issues.redhat.com/browse/OCPBUGS-58739): bump github.com/golang/glog to version v1.2.4 [#107](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/107) * [OCPBUGS-56064](https://issues.redhat.com/browse/OCPBUGS-56064): tech debt: rework vendor patches [#92](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/92) * [OCPBUGS-53906](https://issues.redhat.com/browse/OCPBUGS-53906): bump github.com/golang-jwt/jwt/v4 to v4.5.2 [#85](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/85) * [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver/compare/81877ac81f4c59eebcfaa1653ef2bb6ed2283d1d...5b58d112224287f6d6491b0143c73d37817cb3fd) ### [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/tree/b039b8e368063df3ef5985600250515680f7fa25) * [OCPBUGS-67980](https://issues.redhat.com/browse/OCPBUGS-67980), [OCPBUGS-67981](https://issues.redhat.com/browse/OCPBUGS-67981): bump github.com/sirupsen/logrus to v1.9.3 [#165](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/165) * [OCPBUGS-59775](https://issues.redhat.com/browse/OCPBUGS-59775): [IBM VPC] set offlineExpansion to false in e2e test manifest [#150](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/150) * [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/compare/1c5b0f9fd714a3df22f6f0273aa8479bd37bbe18...b039b8e368063df3ef5985600250515680f7fa25) ### [ibm-vpc-node-label-updater](https://github.com/openshift/ibm-vpc-node-label-updater/tree/9b13bd4c73e7fa58c109dc3e3b9221773cd7e0e3) * [OCPBUGS-56064](https://issues.redhat.com/browse/OCPBUGS-56064): tech debt: rework vendor patches [#49](https://github.com/openshift/ibm-vpc-node-label-updater/pull/49) * [OCPBUGS-53538](https://issues.redhat.com/browse/OCPBUGS-53538): bump github.com/golang-jwt/jwt/v4 to v4.5.2 [#45](https://github.com/openshift/ibm-vpc-node-label-updater/pull/45) * [Full changelog](https://github.com/openshift/ibm-vpc-node-label-updater/compare/5d72ced58e4ff3c4d4ad02f181578755dfa0312a...9b13bd4c73e7fa58c109dc3e3b9221773cd7e0e3) ### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/bdc981bde680b3a1bc3a80a2c2cfd1c7b2c110e8) * [OCPBUGS-67289](https://issues.redhat.com/browse/OCPBUGS-67289): [release-4.15] Fix incomplete vendor/ [#137](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/137) * [OCPBUGS-51814](https://issues.redhat.com/browse/OCPBUGS-51814): CVE-2025-22869 Update golang.org/x/crypto to patched OpenShift fork [#122](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/122) * [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/b934c68cd083ea3abb65faf463cb6ab5383e5d7d...bdc981bde680b3a1bc3a80a2c2cfd1c7b2c110e8) ### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/6846b9a79e2f2dfc39061fe7625202db30a9a6b4) * [OCPBUGS-36084](https://issues.redhat.com/browse/OCPBUGS-36084): Bump dependency for CVE [#54](https://github.com/openshift/machine-api-provider-ibmcloud/pull/54) * [OCPBUGS-43675](https://issues.redhat.com/browse/OCPBUGS-43675): IBMCloud: Handle pagination for subnets [#48](https://github.com/openshift/machine-api-provider-ibmcloud/pull/48) * [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/6b0b8ea7b16d407fd012ef134b1f9a65ed0bc3a1...6846b9a79e2f2dfc39061fe7625202db30a9a6b4) ### [insights-operator](https://github.com/openshift/insights-operator/tree/975bba9802ebd6c0f1e52117584b82c38831eda8) * Ignore previous status when disabling alerts (#1060) [#1060](https://github.com/openshift/insights-operator/pull/1060) * [OCPBUGS-45204](https://issues.redhat.com/browse/OCPBUGS-45204): LokiStack gatherer (#1057) [#1057](https://github.com/openshift/insights-operator/pull/1057) * [OCPBUGS-45044](https://issues.redhat.com/browse/OCPBUGS-45044): insightsoperator.operator.openshift.io resource is create-only (#1056) [#1056](https://github.com/openshift/insights-operator/pull/1056) * [Full changelog](https://github.com/openshift/insights-operator/compare/692e90c04ac4546949eb4a537d88bb1b4801f6cb...975bba9802ebd6c0f1e52117584b82c38831eda8) ### [ironic](https://github.com/openshift/ironic-image/tree/943b1100380f2d3d02d524bbff2a8553cdde2718) * [OCPBUGS-69784](https://issues.redhat.com/browse/OCPBUGS-69784): Bump eventlet version to 0.33.1-7 [#764](https://github.com/openshift/ironic-image/pull/764) * [OCPBUGS-48148](https://issues.redhat.com/browse/OCPBUGS-48148), [OCPBUGS-48597](https://issues.redhat.com/browse/OCPBUGS-48597): Bump jinja2 to 3.0.1-6.el9.2 [#624](https://github.com/openshift/ironic-image/pull/624) * [Full changelog](https://github.com/openshift/ironic-image/compare/6603bcfdfbb9b0a8a35cf4d14ec45480fce9efde...943b1100380f2d3d02d524bbff2a8553cdde2718) ### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/7b3d8c155e6b8e3cb79e525f1db2dd8d905bef8c) * [OCPBUGS-95071](https://issues.redhat.com/browse/OCPBUGS-95071): Replace individual package removal with a single rpm -e loop [#289](https://github.com/openshift/ironic-agent-image/pull/289) * [OCPBUGS-95071](https://issues.redhat.com/browse/OCPBUGS-95071): Replace dnf remove with rpm -e to prevent dependency removal [#277](https://github.com/openshift/ironic-agent-image/pull/277) * [OCPBUGS-69782](https://issues.redhat.com/browse/OCPBUGS-69782): Bump eventlet version to 0.33.1-7 [#233](https://github.com/openshift/ironic-agent-image/pull/233) * [Full changelog](https://github.com/openshift/ironic-agent-image/compare/d339f3ffb3bbf9879037c1f3d88303880dcb3068...7b3d8c155e6b8e3cb79e525f1db2dd8d905bef8c) ### [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader/tree/705a69ae94d273a2975ce19aa8fdd74b193e7a7c) * [OCPBUGS-87172](https://issues.redhat.com/browse/OCPBUGS-87172): CI build root image tag and go version in go.mod sync with ART 4.15 [#121](https://github.com/openshift/ironic-rhcos-downloader/pull/121) * [Full changelog](https://github.com/openshift/ironic-rhcos-downloader/compare/bcbcd95b6209afc8248b34c55294686dbd3831a3...705a69ae94d273a2975ce19aa8fdd74b193e7a7c) ### [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager/tree/989bcb4f50a98c741f3c9c02c2f0fb118be216c8) * [OCPBUGS-49836](https://issues.redhat.com/browse/OCPBUGS-49836): Fix subnet validation [#49](https://github.com/openshift/ironic-static-ip-manager/pull/49) * [Full changelog](https://github.com/openshift/ironic-static-ip-manager/compare/472000211344be4a5e9581820e94895144cf2bfc...989bcb4f50a98c741f3c9c02c2f0fb118be216c8) ### [kube-proxy, sdn](https://github.com/openshift/sdn/tree/53680a50f8ca7bbcfa6c258c557c765fa6f8471a) * [OCPBUGS-54868](https://issues.redhat.com/browse/OCPBUGS-54868): Handle `openshift-host-network` namespace as special when it modifies [#654](https://github.com/openshift/sdn/pull/654) * [OCPBUGS-46576](https://issues.redhat.com/browse/OCPBUGS-46576): Get rid of deps.diff so it doesn't keep causing problems [4.15] [#646](https://github.com/openshift/sdn/pull/646) * [OCPBUGS-45955](https://issues.redhat.com/browse/OCPBUGS-45955): Stop checking ruleVersion [4.16] [#644](https://github.com/openshift/sdn/pull/644) * [OCPBUGS-43605](https://issues.redhat.com/browse/OCPBUGS-43605): backport fix for network policy during live migration [#642](https://github.com/openshift/sdn/pull/642) * [Full changelog](https://github.com/openshift/sdn/compare/f371b5be76a71a7f55f2e0b674f09a7f2ec5f5bf...53680a50f8ca7bbcfa6c258c557c765fa6f8471a) ### [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator/tree/a6a9ab1a765ea5bf5815e6b15a5a39840a03bb3e) * NO-JIRA: Add DOWNSTREAM_OWNERS (release 4-15). [#228](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/228) * [Full changelog](https://github.com/openshift/kubernetes-kube-storage-version-migrator/compare/e8749689edb8e7fea42eca5f2b67c3187192cdeb...a6a9ab1a765ea5bf5815e6b15a5a39840a03bb3e) ### [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt/tree/379c50d50b7158efd554b8ff69bea6a2a443e1a8) * [OCPBUGS-95081](https://issues.redhat.com/browse/OCPBUGS-95081): OWNERS: Update component to Cloud Compute / KubeVirt Provider [#83](https://github.com/openshift/cloud-provider-kubevirt/pull/83) * [Full changelog](https://github.com/openshift/cloud-provider-kubevirt/compare/dbaf9ea1edd5a953606a80cb45f723c934a73ded...379c50d50b7158efd554b8ff69bea6a2a443e1a8) ### [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver/tree/ebe618a56a660c5b4199aa51fc06933129024cbb) * [OCPBUGS-83658](https://issues.redhat.com/browse/OCPBUGS-83658): Bump google.golang.org/grpc to v1.79.3 [#103](https://github.com/openshift/kubevirt-csi-driver/pull/103) * fix for OCPBUGS-58587: CVE-2024-45339 openshift4/kubevirt-csi-driver [#69](https://github.com/openshift/kubevirt-csi-driver/pull/69) * [Full changelog](https://github.com/openshift/kubevirt-csi-driver/compare/d3bdbce4b08eb05eea70be77f4ecf33e351ce4d3...ebe618a56a660c5b4199aa51fc06933129024cbb) ### [libvirt-machine-controllers](https://github.com/openshift/cluster-api-provider-libvirt/tree/416999a8de40238abc7be3b24e54857f8e5e97e6) * [OCPBUGS-77197](https://issues.redhat.com/browse/OCPBUGS-77197): Fix incomplete vendor [#303](https://github.com/openshift/cluster-api-provider-libvirt/pull/303) * [OCPBUGS-26506](https://issues.redhat.com/browse/OCPBUGS-26506): Updating ose-libvirt-machine-controllers-container image to be consistent with ART for 4.15 [#282](https://github.com/openshift/cluster-api-provider-libvirt/pull/282) * [Full changelog](https://github.com/openshift/cluster-api-provider-libvirt/compare/1e096cdf1bfd60e9bf5ee6c90585a8f96cc0c09a...416999a8de40238abc7be3b24e54857f8e5e97e6) ### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/d2712ea2ad4c4a93524ae363f617e1e82aa28458) * [OCPBUGS-67989](https://issues.redhat.com/browse/OCPBUGS-67989): bumped logrus to v1.9.3 [#1460](https://github.com/openshift/machine-api-operator/pull/1460) * [OCPBUGS-59861](https://issues.redhat.com/browse/OCPBUGS-59861): Updates GCP CredentialsRequest [#1397](https://github.com/openshift/machine-api-operator/pull/1397) * [OCPBUGS-55410](https://issues.redhat.com/browse/OCPBUGS-55410), [OCPBUGS-55411](https://issues.redhat.com/browse/OCPBUGS-55411): Updates GCP credentials request [#1356](https://github.com/openshift/machine-api-operator/pull/1356) * [OCPBUGS-53251](https://issues.redhat.com/browse/OCPBUGS-53251): add image/read permissions [#1349](https://github.com/openshift/machine-api-operator/pull/1349) * [OCPBUGS-52481](https://issues.redhat.com/browse/OCPBUGS-52481): Drop oVirt support [#1340](https://github.com/openshift/machine-api-operator/pull/1340) * [OCPBUGS-48105](https://issues.redhat.com/browse/OCPBUGS-48105): Vsphere: Handle cloned instance with lost taskID [#1321](https://github.com/openshift/machine-api-operator/pull/1321) * [OCPBUGS-46080](https://issues.redhat.com/browse/OCPBUGS-46080): Ensure deletion annotation takes priority and oldestPolicy can distinguish longer ages [#1314](https://github.com/openshift/machine-api-operator/pull/1314) * [Full changelog](https://github.com/openshift/machine-api-operator/compare/3ab953de1bdc5c1977222011ebc31254d06c98d2...d2712ea2ad4c4a93524ae363f617e1e82aa28458) ### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/1ffa8341fb18365b72398fc4eedffcbe4d423256) * [OCPBUGS-99046](https://issues.redhat.com/browse/OCPBUGS-99046): Remove sensitive ControllerConfig logging [#6318](https://github.com/openshift/machine-config-operator/pull/6318) * [OCPBUGS-77636](https://issues.redhat.com/browse/OCPBUGS-77636): Machine-config controller should not log about non-existent pull-secret changes [#5573](https://github.com/openshift/machine-config-operator/pull/5573) * [OCPBUGS-60214](https://issues.redhat.com/browse/OCPBUGS-60214): [release-4.15] OCPBUGS-53248: Enforce VIPs to be collocated at the same host [#4988](https://github.com/openshift/machine-config-operator/pull/4988) * [OCPBUGS-59737](https://issues.redhat.com/browse/OCPBUGS-59737): Remove MachineConfigNode CRD from manifests [#5188](https://github.com/openshift/machine-config-operator/pull/5188) * [OCPBUGS-48284](https://issues.redhat.com/browse/OCPBUGS-48284): Do not run resolv-prepender from NM dispatcher [#4783](https://github.com/openshift/machine-config-operator/pull/4783) * [OCPBUGS-57340](https://issues.redhat.com/browse/OCPBUGS-57340): Do not enable on-prem-resolv-prepender.path for UPI [#5115](https://github.com/openshift/machine-config-operator/pull/5115) * [OCPBUGS-36688](https://issues.redhat.com/browse/OCPBUGS-36688): Add ipsec connect wait service [#4937](https://github.com/openshift/machine-config-operator/pull/4937) * [OCPBUGS-54206](https://issues.redhat.com/browse/OCPBUGS-54206): Update format verbs for alert logs [#4943](https://github.com/openshift/machine-config-operator/pull/4943) * [OCPBUGS-54176](https://issues.redhat.com/browse/OCPBUGS-54176): Update ObservedGeneration in KubeletConfig [#4944](https://github.com/openshift/machine-config-operator/pull/4944) * [OCPBUGS-43742](https://issues.redhat.com/browse/OCPBUGS-43742): Soften haproxy timeout for kubeapi probe [#4663](https://github.com/openshift/machine-config-operator/pull/4663) * [OCPBUGS-50526](https://issues.redhat.com/browse/OCPBUGS-50526): Add clarification to invalid maxUnavailable alert [#4842](https://github.com/openshift/machine-config-operator/pull/4842) * [OCPBUGS-48583](https://issues.redhat.com/browse/OCPBUGS-48583): trying to wait for sub-contorllers [#4796](https://github.com/openshift/machine-config-operator/pull/4796) * [OCPBUGS-46034](https://issues.redhat.com/browse/OCPBUGS-46034): Remove trailing periods from AWS provided hostnames [#4745](https://github.com/openshift/machine-config-operator/pull/4745) * [OCPBUGS-44565](https://issues.redhat.com/browse/OCPBUGS-44565): Post upgrading from 4.14 to 4.15.36, the observedGeneration count increased tremendously [#4702](https://github.com/openshift/machine-config-operator/pull/4702) * [Full changelog](https://github.com/openshift/machine-config-operator/compare/657ab58b76a99f2e566714bead33674c08ff9301...1ffa8341fb18365b72398fc4eedffcbe4d423256) ### [machine-image-customization-controller](https://github.com/openshift/image-customization-controller/tree/213f5c866a3ae996170f6a28ffb7048327ae66d2) * [OCPBUGS-67983](https://issues.redhat.com/browse/OCPBUGS-67983): [4.15] uplift logrus [#154](https://github.com/openshift/image-customization-controller/pull/154) * [Full changelog](https://github.com/openshift/image-customization-controller/compare/97d87657caab4323f82f9d0958e6d30fc8fd1846...213f5c866a3ae996170f6a28ffb7048327ae66d2) ### [machine-os-images](https://github.com/openshift/machine-os-images/tree/ad1c48fc1654d6e4b8ceb22f500e90ca6eb25230) * [OCPBUGS-87879](https://issues.redhat.com/browse/OCPBUGS-87879): Add support for hermetic builds via Cachi2 prefetched CoreOS ISOs [#103](https://github.com/openshift/machine-os-images/pull/103) * [OCPBUGS-54170](https://issues.redhat.com/browse/OCPBUGS-54170): Change rhcos release browser url [#58](https://github.com/openshift/machine-os-images/pull/58) * [Full changelog](https://github.com/openshift/machine-os-images/compare/9e9c920f985a375536e8d4caafd2d7ed579e27f3...ad1c48fc1654d6e4b8ceb22f500e90ca6eb25230) ### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/f19703f53dbf0943b02d42ec301af453dc7d697b) * [OCPBUGS-74446](https://issues.redhat.com/browse/OCPBUGS-74446): [release-4.15] fix: upgrade lodash to remove vulnerable code [#907](https://github.com/openshift/monitoring-plugin/pull/907) * [OCPBUGS-78493](https://issues.redhat.com/browse/OCPBUGS-78493): fix for CVE-2025-69873 [#850](https://github.com/openshift/monitoring-plugin/pull/850) * [OCPBUGS-44393](https://issues.redhat.com/browse/OCPBUGS-44393): Manual cherry pick cross spawn 4.15 [#277](https://github.com/openshift/monitoring-plugin/pull/277) * [Full changelog](https://github.com/openshift/monitoring-plugin/compare/e40b085a258b5762532875bbd9ce34d1f75a90b4...f19703f53dbf0943b02d42ec301af453dc7d697b) ### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/a2e3c6e5d5dcb6dd059f87a2f5a519482d955c45) * [OCPBUGS-58769](https://issues.redhat.com/browse/OCPBUGS-58769): Update the github.com/golang/glog module to v1.2.4 [#104](https://github.com/openshift/multus-admission-controller/pull/104) * [Full changelog](https://github.com/openshift/multus-admission-controller/compare/9ea52de962dd644573c99b2f9554a6c4dfaacf62...a2e3c6e5d5dcb6dd059f87a2f5a519482d955c45) ### [multus-cni](https://github.com/openshift/multus-cni/tree/d7c59498b60c2a93bfdfe49f2d9ab5c923239b66) * [OCPBUGS-85252](https://issues.redhat.com/browse/OCPBUGS-85252): Fix server url in kubeconfig [#301](https://github.com/openshift/multus-cni/pull/301) * no-issue: [release-4.15] Bump Go to 1.20 and fix CI build root image [#294](https://github.com/openshift/multus-cni/pull/294) * [Full changelog](https://github.com/openshift/multus-cni/compare/05497ad135c629de9b4ffb0a13fb91d58a335d25...d7c59498b60c2a93bfdfe49f2d9ab5c923239b66) ### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/cfa4f975508177d8daee9652ca75fe16f9e5dc27) * [OCPBUGS-55619](https://issues.redhat.com/browse/OCPBUGS-55619): Fixes leftover podref issue [#366](https://github.com/openshift/whereabouts-cni/pull/366) * [Full changelog](https://github.com/openshift/whereabouts-cni/compare/d80fe46e1895698f3d1073ab965c859a89be2a47...cfa4f975508177d8daee9652ca75fe16f9e5dc27) ### [must-gather](https://github.com/openshift/must-gather/tree/0f70f31cc6a01d849fef5262e20f934bf87a91ee) * [OCPBUGS-36371](https://issues.redhat.com/browse/OCPBUGS-36371): Run ppc node collection in parallel [#430](https://github.com/openshift/must-gather/pull/430) * [OCPBUGS-42970](https://issues.redhat.com/browse/OCPBUGS-42970): Collect etcd object count [#456](https://github.com/openshift/must-gather/pull/456) * [OCPBUGS-48083](https://issues.redhat.com/browse/OCPBUGS-48083): Update owners [#474](https://github.com/openshift/must-gather/pull/474) * [OCPBUGS-46451](https://issues.redhat.com/browse/OCPBUGS-46451): Support gathering IPsec data [#471](https://github.com/openshift/must-gather/pull/471) * [Full changelog](https://github.com/openshift/must-gather/compare/48de487eb38d1434440e4fb8164022b2b708332a...0f70f31cc6a01d849fef5262e20f934bf87a91ee) ### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/1b188fa1f7efdda0dafbdd409deed32450017dfc) * [OCPBUGS-58779](https://issues.redhat.com/browse/OCPBUGS-58779): Bump github.com/golang/glog to v1.2.4 (#114) [#114](https://github.com/openshift/network-metrics-daemon/pull/114) * [OCPBUGS-60374](https://issues.redhat.com/browse/OCPBUGS-60374): Replace e2e test image (#126) [#126](https://github.com/openshift/network-metrics-daemon/pull/126) * swtich golint install method (#124) [#124](https://github.com/openshift/network-metrics-daemon/pull/124) * [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/9e21740225af47318a9ed6d03c2eb9ee2aaea883...1b188fa1f7efdda0dafbdd409deed32450017dfc) ### [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix/tree/ec58a6114b305b91d9a476e5f29c98b1a059c2ad) * [OCPBUGS-47264](https://issues.redhat.com/browse/OCPBUGS-47264): fixing CVE-2024-45338 [#117](https://github.com/openshift/machine-api-provider-nutanix/pull/117) * [OCPBUGS-51850](https://issues.redhat.com/browse/OCPBUGS-51850): CVE-2025-22868 [#109](https://github.com/openshift/machine-api-provider-nutanix/pull/109) * [Full changelog](https://github.com/openshift/machine-api-provider-nutanix/compare/8de6f944d35b2fefaf926006aecf8445be4e6149...ec58a6114b305b91d9a476e5f29c98b1a059c2ad) ### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/2a98b2ccd96215b432c018b817d238766613df5d) * [OCPBUGS-74925](https://issues.redhat.com/browse/OCPBUGS-74925): bump kubernetes-apiserver to pick up loopback cert expiration update [#173](https://github.com/openshift/oauth-apiserver/pull/173) * NO-JIRA: (chore): update OWNERS [#175](https://github.com/openshift/oauth-apiserver/pull/175) * [Full changelog](https://github.com/openshift/oauth-apiserver/compare/0e158441dbfdf232d7fea50b7c4eae3023d2cdbb...2a98b2ccd96215b432c018b817d238766613df5d) ### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/d0833dc677a573e14ecd5be3dafeaac03e15aac4) * [OCPBUGS-61447](https://issues.redhat.com/browse/OCPBUGS-61447): Update x/crypto to v0.31.0 [#336](https://github.com/openshift/oauth-proxy/pull/336) * [Full changelog](https://github.com/openshift/oauth-proxy/compare/241a88c47cb01d0e61ff105ceff81ad14fd9ea6e...d0833dc677a573e14ecd5be3dafeaac03e15aac4) ### [oc-mirror](https://github.com/openshift/oc-mirror/tree/18d55d6a096fa9713d9fbd8e9bd35f9c6112706d) * [OCPBUGS-77858](https://issues.redhat.com/browse/OCPBUGS-77858): fix vendor for hermetic 4.15 [#1361](https://github.com/openshift/oc-mirror/pull/1361) * And 2 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/oc-mirror/compare/e91f573c771182f7fd4a2d3513ed49562dee6b38...18d55d6a096fa9713d9fbd8e9bd35f9c6112706d) ### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/e488c1f6be78eef974989890ce99526518d66ec4) * [OCPBUGS-82665](https://issues.redhat.com/browse/OCPBUGS-82665): Address CVE-2026-35469 [#648](https://github.com/openshift/openshift-apiserver/pull/648) * [OCPBUGS-67998](https://issues.redhat.com/browse/OCPBUGS-67998): CVE-2025-65637 - Bump github.com/sirupsen/logrus from v1.9.0 to v1.9.3 [release-4.15] [#611](https://github.com/openshift/openshift-apiserver/pull/611) * [OCPBUGS-74923](https://issues.redhat.com/browse/OCPBUGS-74923): bump kubernetes-apiserver to pick up loopback cert expiration update [#600](https://github.com/openshift/openshift-apiserver/pull/600) * [OCPBUGS-58822](https://issues.redhat.com/browse/OCPBUGS-58822): Fix image reference in TestImageStreamImportQuayIO [#517](https://github.com/openshift/openshift-apiserver/pull/517) * [OCPBUGS-47766](https://issues.redhat.com/browse/OCPBUGS-47766): Pass expected type to deploymentconfig/scale object validation. [#466](https://github.com/openshift/openshift-apiserver/pull/466) * [Full changelog](https://github.com/openshift/openshift-apiserver/compare/08f4c422eed5d9584799244c0d9755708686c0c8...e488c1f6be78eef974989890ce99526518d66ec4) ### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/110a10ad9c720400f87e3428354ccff051b70af3) * [OCPBUGS-57761](https://issues.redhat.com/browse/OCPBUGS-57761): Set node-pullsecrets volume to read-only to protect image pull credentials [#396](https://github.com/openshift/openshift-controller-manager/pull/396) * [OCPBUGS-56474](https://issues.redhat.com/browse/OCPBUGS-56474): Empty proxy variables are causing issues during the build [#383](https://github.com/openshift/openshift-controller-manager/pull/383) * [OCPBUGS-54344](https://issues.redhat.com/browse/OCPBUGS-54344): Unable to look up the service account secrets for build [#370](https://github.com/openshift/openshift-controller-manager/pull/370) * [OCPBUGS-48280](https://issues.redhat.com/browse/OCPBUGS-48280): Add team members to the OWNERS file [#359](https://github.com/openshift/openshift-controller-manager/pull/359) * [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/f2afd434358966ccc09f55d4915d2689ed2cb1b6...110a10ad9c720400f87e3428354ccff051b70af3) ### [openstack-cinder-csi-driver-operator](https://github.com/openshift/openstack-cinder-csi-driver-operator/tree/c44a604df76d9f889e8366387396d2cfdb5a6424) * [OCPBUGS-68000](https://issues.redhat.com/browse/OCPBUGS-68000): CVE-2025-65637 openshift4/ose-openstack-cinder-csi-driver-rhel8-operator: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [openshift-4.15.z] [#192](https://github.com/openshift/openstack-cinder-csi-driver-operator/pull/192) * [Full changelog](https://github.com/openshift/openstack-cinder-csi-driver-operator/compare/d0c24077b4e4ac1e00a6a529a814066cd9b5521c...c44a604df76d9f889e8366387396d2cfdb5a6424) ### [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack/tree/bf81e212f644e7d09a66fd111566e71f0538851e) * [OCPBUGS-78171](https://issues.redhat.com/browse/OCPBUGS-78171): hermetic 4.15 [#164](https://github.com/openshift/machine-api-provider-openstack/pull/164) * [Full changelog](https://github.com/openshift/machine-api-provider-openstack/compare/396a09fffe401679f18e8a7db56c77bbf2dee246...bf81e212f644e7d09a66fd111566e71f0538851e) ### [operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/b7cee7e4946c39704b192e78b34e2b0d621f915b) * [OCPBUGS-79906](https://issues.redhat.com/browse/OCPBUGS-79906), [OCPBUGS-87895](https://issues.redhat.com/browse/OCPBUGS-87895): Fix CVE-2026-33186 with openshift-sustaining/grpc-go v1.64.1-sec.1 [release-4.15] [#1325](https://github.com/openshift/operator-framework-olm/pull/1325) * [OCPBUGS-82056](https://issues.redhat.com/browse/OCPBUGS-82056): Drop github.com/distribution/distribution dep [#1303](https://github.com/openshift/operator-framework-olm/pull/1303) * [OCPBUGS-61466](https://issues.redhat.com/browse/OCPBUGS-61466): [release-4.15] Add NetworkPolicy as a supported kind [#1051](https://github.com/openshift/operator-framework-olm/pull/1051) * [OCPBUGS-61389](https://issues.redhat.com/browse/OCPBUGS-61389): [4.15] e2e stability fixes [#1084](https://github.com/openshift/operator-framework-olm/pull/1084) * [OCPBUGS-57430](https://issues.redhat.com/browse/OCPBUGS-57430): reduce cache expiry frequency [release-4.19] [#1023](https://github.com/openshift/operator-framework-olm/pull/1023) * [OCPBUGS-56463](https://issues.redhat.com/browse/OCPBUGS-56463): fix(olm): improve error logging for missing olm.managed label (#3558) [#1010](https://github.com/openshift/operator-framework-olm/pull/1010) * [OCPBUGS-48662](https://issues.redhat.com/browse/OCPBUGS-48662): Fix concurrent namespace resolution [#948](https://github.com/openshift/operator-framework-olm/pull/948) * [OCPBUGS-48697](https://issues.redhat.com/browse/OCPBUGS-48697): Fix excessive catalog source snapshots cause severe performance regression [#958](https://github.com/openshift/operator-framework-olm/pull/958) * [OCPBUGS-46926](https://issues.redhat.com/browse/OCPBUGS-46926), [OCPBUGS-46933](https://issues.redhat.com/browse/OCPBUGS-46933), [OCPBUGS-47313](https://issues.redhat.com/browse/OCPBUGS-47313): x/net bump to v0.34.0 [release-4.15] [#940](https://github.com/openshift/operator-framework-olm/pull/940) * [OCPBUGS-46479](https://issues.redhat.com/browse/OCPBUGS-46479): CRD upgrade existing CR validation fix [#917](https://github.com/openshift/operator-framework-olm/pull/917) * [Full changelog](https://github.com/openshift/operator-framework-olm/compare/2a0924f9655371f636d16b60e9ae7e49934c5640...b7cee7e4946c39704b192e78b34e2b0d621f915b) ### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/5c7af29b454e253322d8650c7d125c842eca92c8) * [OCPBUGS-68005](https://issues.redhat.com/browse/OCPBUGS-68005): CVE-2025-65637 fixed in logrus v1.9.3+ [#733](https://github.com/operator-framework/operator-marketplace/pull/733) * [OCPBUGS-62221](https://issues.redhat.com/browse/OCPBUGS-62221): Remove Expect func so that the test case can use the retry logic [#672](https://github.com/operator-framework/operator-marketplace/pull/672) * [OCPBUGS-62119](https://issues.redhat.com/browse/OCPBUGS-62119): Update memoryTarget on catalog source pods [#666](https://github.com/operator-framework/operator-marketplace/pull/666) * [OCPBUGS-49428](https://issues.redhat.com/browse/OCPBUGS-49428): Upgrade golang.org/x/net [release-4.15] [#588](https://github.com/operator-framework/operator-marketplace/pull/588) * [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/1f1bc1988527f01b7326f63953aacbd400fd8426...5c7af29b454e253322d8650c7d125c842eca92c8) ### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/871ee75596467e467b6123f66e135b363af14086) * [OCPBUGS-97815](https://issues.redhat.com/browse/OCPBUGS-97815): External gateway: Remove routes for external gateway pods in terminating or not ready state [#3285](https://github.com/openshift/ovn-kubernetes/pull/3285) * [CORENET-6055](https://issues.redhat.com/browse/CORENET-6055), [OCPBUGS-76403](https://issues.redhat.com/browse/OCPBUGS-76403): [release-4.15] Dockerfile: Unpin OVN and consume the latest from FDP [#2974](https://github.com/openshift/ovn-kubernetes/pull/2974) * [OCPBUGS-56660](https://issues.redhat.com/browse/OCPBUGS-56660), [OCPBUGS-58162](https://issues.redhat.com/browse/OCPBUGS-58162): Unpin OVS patch versions #2649 [#2649](https://github.com/openshift/ovn-kubernetes/pull/2649) * [OCPBUGS-56419](https://issues.redhat.com/browse/OCPBUGS-56419): Update to FDP25.A.1 24.03.5-40. [#2573](https://github.com/openshift/ovn-kubernetes/pull/2573) * [OCPBUGS-50583](https://issues.redhat.com/browse/OCPBUGS-50583): Bump OVN to 23.09.6-12 to consume fix for FDP-905 [#2454](https://github.com/openshift/ovn-kubernetes/pull/2454) * [OCPBUGS-53384](https://issues.redhat.com/browse/OCPBUGS-53384): [release-4.15] Dockerfile.base: bump OVS version to 3.3 [#2492](https://github.com/openshift/ovn-kubernetes/pull/2492) * [OCPBUGS-43605](https://issues.redhat.com/browse/OCPBUGS-43605): Add SDN node subnet gateway IP to host-network address_set [#2419](https://github.com/openshift/ovn-kubernetes/pull/2419) * [OCPBUGS-46403](https://issues.redhat.com/browse/OCPBUGS-46403): Add static route to the hairpin masquerade IPs to pod [#2396](https://github.com/openshift/ovn-kubernetes/pull/2396) * [OCPBUGS-47799](https://issues.redhat.com/browse/OCPBUGS-47799): Let OVN-northd bind remote ports [#2407](https://github.com/openshift/ovn-kubernetes/pull/2407) * [OCPBUGS-44708](https://issues.redhat.com/browse/OCPBUGS-44708): Add hybird overlay pod IPs to the namespace address_set [#2399](https://github.com/openshift/ovn-kubernetes/pull/2399) * [OCPBUGS-45097](https://issues.redhat.com/browse/OCPBUGS-45097): pin libreswan to 4.6-3.el9_0.3 [#2374](https://github.com/openshift/ovn-kubernetes/pull/2374) * [OCPBUGS-44782](https://issues.redhat.com/browse/OCPBUGS-44782): Bump ovs to 3.1.0-137 [#2359](https://github.com/openshift/ovn-kubernetes/pull/2359) * [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/0d35785ab8c4fccea85a0d2e6dc49fe1da2d11cd...871ee75596467e467b6123f66e135b363af14086) ### [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/tree/766c2e6af74efa696364cef21c2b9915ed886e42) * [OCPBUGS-68006](https://issues.redhat.com/browse/OCPBUGS-68006): Fix CVE-2025-65637 by bumping logrus to v1.9.1 [#99](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/99) * [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/compare/a3729dcb75a7da8c9ee7466da5de07e2f1fe5951...766c2e6af74efa696364cef21c2b9915ed886e42) ### [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs/tree/5c68b044b7fc3e70e39f6d67e4df440d8206d929) * [OCPBUGS-61702](https://issues.redhat.com/browse/OCPBUGS-61702): Use OS_GIT_VERSION in Makefile when found (for Konflux builds) [#128](https://github.com/openshift/machine-api-provider-powervs/pull/128) * [OCPBUGS-54753](https://issues.redhat.com/browse/OCPBUGS-54753): Fix for CVE-2024-51744 in github.com/golang-jwt/jwt/v4 in release-4.15 [#115](https://github.com/openshift/machine-api-provider-powervs/pull/115) * [Full changelog](https://github.com/openshift/machine-api-provider-powervs/compare/4121cfc4304dcbb698993a388368f4025ab9c24a...5c68b044b7fc3e70e39f6d67e4df440d8206d929) ### [prometheus](https://github.com/openshift/prometheus/tree/f5ef2c4a07c3ef1ca3d152d46312cdc10728bd82) * [OCPBUGS-88592](https://issues.redhat.com/browse/OCPBUGS-88592): remote: validate snappy decoded length before allocation in read endpoint [#352](https://github.com/openshift/prometheus/pull/352) * [OCPBUGS-79907](https://issues.redhat.com/browse/OCPBUGS-79907): Bump google.golang.org/grpc [#322](https://github.com/openshift/prometheus/pull/322) * [OCPBUGS-56740](https://issues.redhat.com/browse/OCPBUGS-56740): BACKPORT: fix promtool analyze block shows metric name with 0 cardinality [#256](https://github.com/openshift/prometheus/pull/256) * [OCPBUGS-43669](https://issues.redhat.com/browse/OCPBUGS-43669): fix(discovery): Handle cache.DeletedFinalStateUnknown in node informers' DeleteFunc [#233](https://github.com/openshift/prometheus/pull/233) * [Full changelog](https://github.com/openshift/prometheus/compare/6828e4464c45f239a89c7965233c2fef49c6b1fb...f5ef2c4a07c3ef1ca3d152d46312cdc10728bd82) ### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/683f4f217cdfa0f8847844f57ef961bb307c32d0) * [OCPBUGS-100359](https://issues.redhat.com/browse/OCPBUGS-100359): Set testdata CA expiry to 20 years from issue date (#4112) [#153](https://github.com/openshift/prometheus-alertmanager/pull/153) * [OCPBUGS-77058](https://issues.redhat.com/browse/OCPBUGS-77058): Include go-verify-deps expected files in gitignore [#117](https://github.com/openshift/prometheus-alertmanager/pull/117) * [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/870ade52a6097bc55cec29c1a9cc028967c5d23c...683f4f217cdfa0f8847844f57ef961bb307c32d0) ### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/eb7ed133e99c6ed6c31ca89c3a056e688c593378) * [OCPBUGS-86882](https://issues.redhat.com/browse/OCPBUGS-86882): [release-4.15] bump google.golang.org/grpc to v1.64.1-sec.1 [#93](https://github.com/openshift/route-controller-manager/pull/93) * [Full changelog](https://github.com/openshift/route-controller-manager/compare/c5cc7a73705e4086759e2a36811b055b7716def4...eb7ed133e99c6ed6c31ca89c3a056e688c593378) ### [service-ca-operator](https://github.com/openshift/service-ca-operator/tree/57a122c2a6c6a2fe0c6ab11946859c435cf593b9) * [OCPBUGS-68019](https://issues.redhat.com/browse/OCPBUGS-68019): update logrus to v1.9.1 [#321](https://github.com/openshift/service-ca-operator/pull/321) * [Full changelog](https://github.com/openshift/service-ca-operator/compare/19f312e96bb4e5b7da9f61ea4cab202b227a60c6...57a122c2a6c6a2fe0c6ab11946859c435cf593b9) ### [tests](https://github.com/openshift/origin/tree/8acddbb71da35dcc067d5009b72ad5917674faf9) * [OCPBUGS-74300](https://issues.redhat.com/browse/OCPBUGS-74300): Skip E2e: attach on previously attached volumes should work [#30725](https://github.com/openshift/origin/pull/30725) * [OCPBUGS-66329](https://issues.redhat.com/browse/OCPBUGS-66329): Replace RunHostCmd with Exec function to censor bearer token being exposed [#30528](https://github.com/openshift/origin/pull/30528) * [OCPBUGS-57335](https://issues.redhat.com/browse/OCPBUGS-57335): Fix regex parser for censoring private key [#29913](https://github.com/openshift/origin/pull/29913) * [OCPBUGS-61229](https://issues.redhat.com/browse/OCPBUGS-61229): images/tests: Remove rteval [#30207](https://github.com/openshift/origin/pull/30207) * [OCPBUGS-57136](https://issues.redhat.com/browse/OCPBUGS-57136): aws/edge: prevent test using unschedulable nodes [#29897](https://github.com/openshift/origin/pull/29897) * [OCPBUGS-55477](https://issues.redhat.com/browse/OCPBUGS-55477): support provider type external [#29739](https://github.com/openshift/origin/pull/29739) * NO-JIRA: Sync OWNERS from main branch [#29856](https://github.com/openshift/origin/pull/29856) * [OCPBUGS-55695](https://issues.redhat.com/browse/OCPBUGS-55695): [build] Ensure Git Clone Does Not Run Privileged [#29752](https://github.com/openshift/origin/pull/29752) * [OCPBUGS-54769](https://issues.redhat.com/browse/OCPBUGS-54769): Fix egress firewall tests by updating the URL from docs.openshift.com to redhat.com [#29664](https://github.com/openshift/origin/pull/29664) * [OCPBUGS-52582](https://issues.redhat.com/browse/OCPBUGS-52582): Use payload pullspec for image info test [#29590](https://github.com/openshift/origin/pull/29590) * [OCPBUGS-41614](https://issues.redhat.com/browse/OCPBUGS-41614): Disable:Broken for [sig-builds][Feature:Builds][Slow] can use private repositories as build input build using an HTTP token should be able to clone source code via an HTTP token [#29502](https://github.com/openshift/origin/pull/29502) * [OCPBUGS-49647](https://issues.redhat.com/browse/OCPBUGS-49647): Fixing build s2i ruby test data inline with latest ruby version(>=3.0) [#29503](https://github.com/openshift/origin/pull/29503) * [OCPBUGS-48749](https://issues.redhat.com/browse/OCPBUGS-48749): Add/remove team members to the OWNERS file for Builds [#29551](https://github.com/openshift/origin/pull/29551) * [Full changelog](https://github.com/openshift/origin/compare/1ec96648894ae137d5d976aed612e203e2eb8184...8acddbb71da35dcc067d5009b72ad5917674faf9) ### [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere/tree/429abecf805b4a6876c576f3f1c572866e23f235) * [OCPBUGS-78030](https://issues.redhat.com/browse/OCPBUGS-78030): hermetic migration 4.15 [#108](https://github.com/openshift/cloud-provider-vsphere/pull/108) * [Full changelog](https://github.com/openshift/cloud-provider-vsphere/compare/81ad52ad7bcf37b225bc50a6e6150ca0572057b7...429abecf805b4a6876c576f3f1c572866e23f235) ### [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere/tree/c0212e3276d0270d369d306317026a87d727d180) * [OCPBUGS-78021](https://issues.redhat.com/browse/OCPBUGS-78021): hermetic migration 4.15 [#87](https://github.com/openshift/cluster-api-provider-vsphere/pull/87) * [OCPBUGS-61654](https://issues.redhat.com/browse/OCPBUGS-61654): Fix unit tests [#73](https://github.com/openshift/cluster-api-provider-vsphere/pull/73) * [Full changelog](https://github.com/openshift/cluster-api-provider-vsphere/compare/5611168658586d68b5a92c77c07304694fc2cc64...c0212e3276d0270d369d306317026a87d727d180) ### [vsphere-csi-driver, vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver/tree/6ff97bb1441a4edf2ccf451a6c63c206e9cf61d6) * [OCPBUGS-86873](https://issues.redhat.com/browse/OCPBUGS-86873): Bump google.golang.org/grpc [#183](https://github.com/openshift/vmware-vsphere-csi-driver/pull/183) * [OCPBUGS-68022](https://issues.redhat.com/browse/OCPBUGS-68022): CVE-2025-65637: Bump github.com/sirupsen/logrus to v1.8.3 [#159](https://github.com/openshift/vmware-vsphere-csi-driver/pull/159) * [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver/compare/4b15e93bd578484c4bfb1c124fa655c451bbd1ca...6ff97bb1441a4edf2ccf451a6c63c206e9cf61d6) ### [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator/tree/cb86a71f40db49e599591fd59a70ffc56a7fa99f) * [OCPBUGS-68020](https://issues.redhat.com/browse/OCPBUGS-68020), [OCPBUGS-68024](https://issues.redhat.com/browse/OCPBUGS-68024): CVE-2025-65637: Bump github.com/sirupsen/logrus to v1.9.3 [#323](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/323) * [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver-operator/compare/e0d46570a06caff3439b410b9c9f75cb383a3d2d...cb86a71f40db49e599591fd59a70ffc56a7fa99f) ### [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector/tree/b5411c84f19f7b7eb550a9ea5eff273bec67c7ce) * [OCPBUGS-68031](https://issues.redhat.com/browse/OCPBUGS-68031): bump github.com/sirupsen/logrus to v1.9.3 [#201](https://github.com/openshift/vsphere-problem-detector/pull/201) * [Full changelog](https://github.com/openshift/vsphere-problem-detector/compare/15ed0ae1d7bcfc9fd24e32bf3650e0e960c115be...b5411c84f19f7b7eb550a9ea5eff273bec67c7ce)