# 4.16.72
Created: 2026-10-01 07:50:52 +0000 UTC
Image Digest: `sha256:9cf7596b1c295a65f4b38d96f231690661869f496bc30dd002f07e31aac87f89`
## Changes from 4.16.36
### Components
* Kubectl 1.29.7
* Kubernetes upgraded from 1.29.11 to 1.29.14
* Kubernetes Tests 1.29.0
* Red Hat Enterprise Linux CoreOS upgraded from 416.94.202502180249-0 to 416.94.202609281908-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: |
| StreamingCollectionEncodingToJSON
(0 tests)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New) |
| StreamingCollectionEncodingToProtobuf
(0 tests)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New) |
### Removed images
* ovirt-csi-driver
* ovirt-csi-driver-operator
* ovirt-machine-controllers
### Rebuilt images without code change
* [alibaba-machine-controllers](https://github.com/openshift/cluster-api-provider-alibaba) git [248372a4](https://github.com/openshift/cluster-api-provider-alibaba/commit/248372a4f668111a7bf134527911cb656c44d47a) `sha256:ab130377be5af680a1fb815895088629f6d1cda1f7ec56149d5d9b2271e81556`
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [ca81b6a3](https://github.com/openshift/apiserver-network-proxy/commit/ca81b6a32aff6ccb327f6889ec89c01afedd8efd) `sha256:63fa3a4e7fbcc91920c31f744f3816b00d95fb3bb9c6d6e673c195e561f17f93`
* [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws) git [a53e9def](https://github.com/openshift/cloud-provider-aws/commit/a53e9def2e60eecd390575b59c85d54c5412ecd3) `sha256:1488054db7925a9e33d536292a5dbca922a59f53b1eaeccc0bb43e292213ed7d`
* [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [1d29a74a](https://github.com/openshift/aws-ebs-csi-driver/commit/1d29a74ab7cde7424cac99261b90f23dc7a2fc21) `sha256:92cd2a9dca0cf45848939ca60807be42c2bbeafadfd9a4cc295f9ec837a8aaba`
* [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider) git [c66065de](https://github.com/openshift/aws-encryption-provider/commit/c66065de639016b770f512e7cfcfcee9519fb89f) `sha256:3be5faebd096af5c05cc0f9d4a92ff0677c71435da61c22915926c12aaa490e6`
* [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver) git [6b55f6fb](https://github.com/openshift/azure-disk-csi-driver/commit/6b55f6fb004454f743aa0f2e1d96010396be4c45) `sha256:e55308f336b3c8fb9c40e1f89b99d167d01d914bbd9c0e21dea8d937d4505b50`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [27bfb59f](https://github.com/openshift/cluster-bootstrap/commit/27bfb59fd0ff399224ee673869b8875ef10f1962) `sha256:f6f545a9853c846e2c2d2eacab0b689ded4b98f2a532e26834247135c8fa7a32`
* [cluster-capi-controllers](https://github.com/openshift/cluster-api) git [5830a10a](https://github.com/openshift/cluster-api/commit/5830a10a2f545dc25ff4ca4c4efd9005088676aa) `sha256:976408be16d542082d92af6b81ce44b71b1e42836b014af9038ecfa08c53e75c`
* [cluster-config-operator](https://github.com/openshift/cluster-config-operator) git [441d29c9](https://github.com/openshift/cluster-config-operator/commit/441d29c92b1759d1780a525112e764280b78b0d6) `sha256:9b4f5d63e7552e41488b698ecbf0310159a12b7fcb59efb83583448fcf56359c`
* [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator) git [14571e8a](https://github.com/openshift/cluster-control-plane-machine-set-operator/commit/14571e8a2c4e9bf52d7cc94da87959a56dc2a44c) `sha256:269b0bd61547c6f945dcc80a6f58397e7b8b4405210e5f977b096fe825d39ee9`
* [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator) git [439826e1](https://github.com/openshift/cluster-csi-snapshot-controller-operator/commit/439826e1a723c094717877db0f2ca1848d0fb10a) `sha256:c1eddcf44f793d9bb8ca9f1573522d87f6eaba979910e7ea08631775c987c5ab`
* [cluster-kube-cluster-api-operator](https://github.com/openshift/cluster-api-operator) git [95ceaa9e](https://github.com/openshift/cluster-api-operator/commit/95ceaa9e2e1fea94e82e078a77633c8cd105a3c7) `sha256:95feb55d6b336ec50a86bf32e984bca749b59c4f8aefe7b9ce3539c6980036a1`
* [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver) git [7685374f](https://github.com/openshift/cluster-machine-approver/commit/7685374f0e84181801b6390876a0d12c61fa9913) `sha256:008409cbb5d6a1e1bdafa38d4a5618495572cd175599dc462272d8e173215f75`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [2ed3cf99](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/2ed3cf9965f8e6832cffde84f3de2fe210b79b49) `sha256:c7cf08c76cd431959e87060f90b6bb58f399d371f948d685b745e487bdc849fe`
* [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller) git [eaea543f](https://github.com/openshift/cluster-policy-controller/commit/eaea543f4c845a7b65705f12e162cc121bb12f88) `sha256:2d309dd99fd541e45350b3c5bc3cbbbc13c6825b6d94e1f6b3284809df78678d`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [e8478585](https://github.com/openshift/cluster-update-keys/commit/e8478585cca88314094112aa5933e5281f4707ea) `sha256:f080f6fb5eaeabf2e0f6c25a19846037056c2fc982d1e3925c9c5a73303fb9f7`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [dc91ddc4](https://github.com/openshift/configmap-reload/commit/dc91ddc4ad8139c9c0bccaba22b65b0bf364d81e) `sha256:659f3bb2a55e707437c5af72677e9e8210a644426c36ab8a86a89b148b41e784`
* [csi-driver-manila-operator](https://github.com/openshift/csi-driver-manila-operator) git [c25d1ff2](https://github.com/openshift/csi-driver-manila-operator/commit/c25d1ff2677a882504b18220dcbbe153781f3883) `sha256:2acff3684830a1068bee33f6f4318068fda40cfb9f86bde618256700c3e6aa40`
* [csi-driver-shared-resource](https://github.com/openshift/csi-driver-shared-resource) git [bc125def](https://github.com/openshift/csi-driver-shared-resource/commit/bc125def6a15a71b2ef8c59e9c1284e471e7d905) `sha256:cdce14653f7dab47949ceb4b7ce2be274369efe48aefb2e618bd1708b4898a65`
* [csi-driver-shared-resource-webhook](https://github.com/openshift/csi-driver-shared-resource) git [bc125def](https://github.com/openshift/csi-driver-shared-resource/commit/bc125def6a15a71b2ef8c59e9c1284e471e7d905) `sha256:38282c39601f49401605f521d59f55e0ee7ed3a85f724c89f9aa9d33652ae8fa`
* [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [7da80aab](https://github.com/openshift/csi-external-attacher/commit/7da80aab15cabd182ee35742443c0b836de4e180) `sha256:0a07a3bad416fad7a80bc28bc97ff1db0317371568aa7f47e5e2e98b0a56e4cd`
* [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [9e8af011](https://github.com/openshift/csi-external-provisioner/commit/9e8af011e0a0aea96066821b57c42bdaccf24a42) `sha256:0967f2e930946c4c022c919e3086cb2f6c28228d1e518000d1f0b5dde5d6e95c`
* [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe) git [f5e3ff55](https://github.com/openshift/csi-livenessprobe/commit/f5e3ff5532d58af34b5b407be2cac6934c1ff223) `sha256:660b13ad60062b4b228115d304e65e7801f44e17b3a55b21b3cc8cdc2015136d`
* [driver-toolkit](https://github.com/openshift/driver-toolkit) git [1d5732f0](https://github.com/openshift/driver-toolkit/commit/1d5732f0209bb7d98661a53c66c5ac265272dce6) `sha256:c83b562256615e0b9fab7e6ae2b6fadd163f0980ed70273956da5cdd807e8543`
* [egress-router-cni](https://github.com/openshift/egress-router-cni) git [7089efe6](https://github.com/openshift/egress-router-cni/commit/7089efe6100c1f52f28adccf1dccc722b8dcacdc) `sha256:e37b4787be72feb35b213537ce3e2a56732bbe145f1f96dd3afb4aa5413b60e1`
* [etcd](https://github.com/openshift/etcd) git [e7911c0d](https://github.com/openshift/etcd/commit/e7911c0d19925c0a67328052a8580a80fb40cb5b) `sha256:ec9df0d4e41fcb028ceb574f9bde5fcb3511a79adcbb739f19442beb8630a7ae`
* [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp) git [26b43dfc](https://github.com/openshift/cloud-provider-gcp/commit/26b43dfc7ddce718014b8991db10cbff30b7b117) `sha256:4a53d609b12dcf0db345a1f6fa9be86fafe28c594dc0a75b7217638422c28544`
* [gcp-pd-csi-driver-operator](https://github.com/openshift/gcp-pd-csi-driver-operator) git [799327f7](https://github.com/openshift/gcp-pd-csi-driver-operator/commit/799327f7c45b362beadc39e85b9e773cab3654c5) `sha256:7c4fa8af28aec8bb4debed9f6bb1dcf1f21c93120d19b99c3d949f3367878e8d`
* [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm) git [f961f16d](https://github.com/openshift/cloud-provider-ibm/commit/f961f16d17dcd6f7e43fd7fed967ce3b06ec9494) `sha256:df90603332bef4f216cabaf785c003bb5a26fac203960fb98825c7b600263e36`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [93b8b5fa](https://github.com/openshift/ironic-rhcos-downloader/commit/93b8b5fa33950cadd2310278b7c762ebe0057418) `sha256:41628159cddb51cf570eb9743448b93126ee1725038dd6daad8d3e62c0d31ebe`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [f44e8a08](https://github.com/openshift/ironic-static-ip-manager/commit/f44e8a08c3d82378c8404ed7e3e8ab1f1fb3f28f) `sha256:908cd256a8c7e3424360a803e63ce6131d9cc3ad1481b32b693bd732bd9b5aa9`
* [k8s-prometheus-adapter](https://github.com/openshift/k8s-prometheus-adapter) git [e4f859be](https://github.com/openshift/k8s-prometheus-adapter/commit/e4f859be4f56d1fc65138f99f5331baf17c15885) `sha256:cc301160039f845e35450914d2a0a27bcc70f9d9b4e5ad01a07c0288ce322748`
* [keepalived-ipfailover](https://github.com/openshift/images) git [b58673a3](https://github.com/openshift/images/commit/b58673a314f0e8253fabadada2ee1a9e5b11c5cf) `sha256:67392693fdc11d978b29bab05aecd364ff791da8eeae82213a1a03cb11f481ee`
* [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [c38f4734](https://github.com/openshift/kube-rbac-proxy/commit/c38f4734c6b6931c75d46674122fb4b838b6e64b) `sha256:31b634b6846efb76103ea041a3e0c0ba4be9f8328fbecb0f385d5180b2017669`
* [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [f988f894](https://github.com/openshift/multus-networkpolicy/commit/f988f894ded7e6645a1b3cc0d6090601809d4e7c) `sha256:192e2210d91650b1de712c6740c4f809bc27fc562b51fab8cf83a23ee767475e`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [73594f77](https://github.com/openshift/route-override-cni/commit/73594f7759e76600c95601138ab5be4969978f63) `sha256:435f15f3267ba5e7cb7bc33acc9e953ee52607f8572a5bdbc5db7cb15f7d98e5`
* [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [28bf5963](https://github.com/openshift/cloud-provider-nutanix/commit/28bf5963c7f82ae8d966a69562a19f038d819950) `sha256:6b484ec06966eb94ff562e9eb25d790e1c09089f417bae290ed155cacf23b75a`
* [oauth-server](https://github.com/openshift/oauth-server) git [3739138c](https://github.com/openshift/oauth-server/commit/3739138c8ebbeb73f6e89f61591dd16a3ece32e3) `sha256:8c02d52b5fdc1040a8eef95950c10594c2e53193c02371f5f77bac291c448a0d`
* [oc-mirror](https://github.com/openshift/oc-mirror) git [b137a53a](https://github.com/openshift/oc-mirror/commit/b137a53a5360a41a70432ea2bfc98a6cee6f7a4a) `sha256:723a2b0ed8bfd6c67283d6e1d3ea1295f1bca9fb01515a88699acb7ae293c1f8`
* [olm-catalogd](https://github.com/openshift/operator-framework-catalogd) git [79975a51](https://github.com/openshift/operator-framework-catalogd/commit/79975a511e1d31a09ef9b3b9e01262c8c69ff633) `sha256:2d3c9217030bc9028973bc51715fd3a95942ba80803fcc947e4316e88a1b026e`
* [olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller) git [80b8649c](https://github.com/openshift/operator-framework-operator-controller/commit/80b8649cf7a57098d03eff0d155531cf63728f41) `sha256:429c381b321323f0c36aa18b1511842c2aa0f7159b94bfc6732c1e005a36ef57`
* [olm-rukpak](https://github.com/openshift/operator-framework-rukpak) git [282cc84c](https://github.com/openshift/operator-framework-rukpak/commit/282cc84cf92dc963f5fd719e103c91b6cc0e6dc6) `sha256:99155d9bcac93289d0e0195a7fffc773aac8fff15ad3c2fd9ea4e6b395da86ef`
* [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [59b8a0ff](https://github.com/openshift/openshift-state-metrics/commit/59b8a0ffc0a472e819e0c30911201c34c85a4684) `sha256:ad701bc6515fb2368b34e0fb09a19c46781ef16dc5478d50ca6f74f9c3e1a0cb`
* [openstack-cinder-csi-driver-operator](https://github.com/openshift/openstack-cinder-csi-driver-operator) git [85b52097](https://github.com/openshift/openstack-cinder-csi-driver-operator/commit/85b52097dda6b8a5f64ceb662d477a9ae28c4ca7) `sha256:3eb4a71b7907b2e32d7a63d3143faa222b485096d8c7757fc47d3fccb27e3c6b`
* [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator) git [9c5dd8d1](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/commit/9c5dd8d17f57b1c7ffd5464a191c6ee5a7646525) `sha256:d4b747dec039a605abe866d48b886f7ca68e3c2c60fc238bf4c4635cb2b692f4`
* [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs) git [20e6dc70](https://github.com/openshift/cloud-provider-powervs/commit/20e6dc70d665e5d085df17d757a07e17c0e18fe0) `sha256:d171ae37234bd7972101d39a3786a34f4c092a227a597b1a007bd4f1cf5cbc9b`
* rhel-coreos `sha256:1064ad143dbfc0865448454869bd489862239ba4afd0faccb5a82269fa78f90f`
* rhel-coreos-extensions `sha256:e15c2fb12d76eef9e8226865a6a28f0fd44c0338dfc05c135e23702128d1a055`
* [service-ca-operator](https://github.com/openshift/service-ca-operator) git [538c7b98](https://github.com/openshift/service-ca-operator/commit/538c7b98a689e573b61e1abb1cb649da470c5fac) `sha256:63eee9a4abea38c5cb7692b4f21a43bef7e197c9e931da39e2494869f09eb802`
* [telemeter](https://github.com/openshift/telemeter) git [c1ecd105](https://github.com/openshift/telemeter/commit/c1ecd1050c8f4ddb3380cf1bfb7230ae2e35052a) `sha256:6f87cd8eac3602ec22e0791af7bf402d530030b97466dfa34ddcbc0301ba6d2b`
* [thanos](https://github.com/openshift/thanos) git [85eee25c](https://github.com/openshift/thanos/commit/85eee25c36702ec14b86dc3157856d2aa2634642) `sha256:b4a90fcf94d410c674d98d49073e60324eb8f12c1253bca33935471caa12b7b4`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/5c16119aeedc4c30e960a59ca91bbfe704879ad8)
* [OCPBUGS-58631](https://issues.redhat.com/browse/OCPBUGS-58631), [OCPBUGS-58636](https://issues.redhat.com/browse/OCPBUGS-58636): Bump glog to v1.2.5 in release-4.16 (#7901) [#7901](https://github.com/openshift/assisted-service/pull/7901)
* [OCPBUGS-47627](https://issues.redhat.com/browse/OCPBUGS-47627): dnsmasq service on OCP SNO fails to read /etc/resolv.conf file during system startup (#7857) [#7857](https://github.com/openshift/assisted-service/pull/7857)
* [OCPBUGS-54402](https://issues.redhat.com/browse/OCPBUGS-54402): Bump go-jwt to 4.5.2 to fix CVE-30204 (#7486) [#7486](https://github.com/openshift/assisted-service/pull/7486)
* [OCPBUGS-45244](https://issues.redhat.com/browse/OCPBUGS-45244): Bump moby from v26.0.0 to v27.2.1 (#7189) [#7189](https://github.com/openshift/assisted-service/pull/7189)
* [Full changelog](https://github.com/openshift/assisted-service/compare/71c1d799edcc2e4a0e0b976d2eea4a100f170285...5c16119aeedc4c30e960a59ca91bbfe704879ad8)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/64b3aebaaf12e7a8c776314cfa0f3ca31778ac61)
* [OCPBUGS-102901](https://issues.redhat.com/browse/OCPBUGS-102901): Bump x/net to v0.35.0-sec.4 [#2295](https://github.com/openshift/assisted-installer/pull/2295)
* And 3 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/ab9e2ade2f45890033a140b314ef87e367317b51...64b3aebaaf12e7a8c776314cfa0f3ca31778ac61)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/9aa0f8edb70a8dcf9a10389fc50e70e4903c2572)
* [OCPBUGS-102913](https://issues.redhat.com/browse/OCPBUGS-102913): CVE-2026-33814: replace golang.org/x/net with openshift-sustaining fork [#1616](https://github.com/openshift/assisted-installer-agent/pull/1616)
* run go mod tidy / vendor [#1019](https://github.com/openshift/assisted-installer-agent/pull/1019)
* And 4 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/9354874458a3ab97dfb7ca68de011637fd5423e3...9aa0f8edb70a8dcf9a10389fc50e70e4903c2572)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/2b81ca4678230f5a9e518e49022960990ae68ee6)
* [OCPBUGS-68046](https://issues.redhat.com/browse/OCPBUGS-68046): bump github.com/sirupsen/logrus to v1.9.3 [#239](https://github.com/openshift/agent-installer-utils/pull/239)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/6e6bb40d95bd966eb6b152e66c5b91794806c4bc...2b81ca4678230f5a9e518e49022960990ae68ee6)
### [alibaba-cloud-controller-manager](https://github.com/openshift/cloud-provider-alibaba-cloud/tree/bfcd3da8dab1170e279c5cc2dcc394c18da25793)
* [OCPBUGS-102906](https://issues.redhat.com/browse/OCPBUGS-102906): Replace golang.org/x/net with github.com/openshift-sustaining/net@v0.35.0-sec.3 to address CVE-2026-33814 [#62](https://github.com/openshift/cloud-provider-alibaba-cloud/pull/62)
* [Full changelog](https://github.com/openshift/cloud-provider-alibaba-cloud/compare/97e8335e2f0bc9ee48fe04f2c19820b557035d37...bfcd3da8dab1170e279c5cc2dcc394c18da25793)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/6db59045e2e4d6c846b3d36ffd9c287a4e715131)
* 🌱 OCPBUGS-123712: UPSTREAM: <carry>: Remove upstream .github files unused in OpenShift CI [#645](https://github.com/openshift/cluster-api-provider-aws/pull/645)
* [OCPBUGS-78227](https://issues.redhat.com/browse/OCPBUGS-78227): [release-4.16] update go mod dependency for konflux [#591](https://github.com/openshift/cluster-api-provider-aws/pull/591)
* [OCPBUGS-61942](https://issues.redhat.com/browse/OCPBUGS-61942): UPSTREAM <carry>: revert: Only tag NetworkInterfaces in RunInstances if IAM Allows It [#572](https://github.com/openshift/cluster-api-provider-aws/pull/572)
* [OCPBUGS-58666](https://issues.redhat.com/browse/OCPBUGS-58666), [OCPBUGS-58671](https://issues.redhat.com/browse/OCPBUGS-58671): bump github.com/golang/glog to v1.2.5 [#560](https://github.com/openshift/cluster-api-provider-aws/pull/560)
* [OCPBUGS-53726](https://issues.redhat.com/browse/OCPBUGS-53726): Update golang-jwt to v4.5.2 [#547](https://github.com/openshift/cluster-api-provider-aws/pull/547)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/60d797bea7418e10ec26ae1ccef4e42249705b6c...6db59045e2e4d6c846b3d36ffd9c287a4e715131)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator](https://github.com/openshift/csi-operator/tree/c1c48cd02b9dcf3cc19993b448301ec78b586f28)
* [OCPBUGS-102919](https://issues.redhat.com/browse/OCPBUGS-102919), [OCPBUGS-102939](https://issues.redhat.com/browse/OCPBUGS-102939): CVE-2026-33814: replace golang.org/x/net with openshift-sustaining fork [#608](https://github.com/openshift/csi-operator/pull/608)
* [OCPBUGS-64831](https://issues.redhat.com/browse/OCPBUGS-64831): Use 127.0.0.1 for healtz http-endpoints [#467](https://github.com/openshift/csi-operator/pull/467)
* [OCPBUGS-64768](https://issues.redhat.com/browse/OCPBUGS-64768): Add RBAC ClusterRole and Binding for driver node [#465](https://github.com/openshift/csi-operator/pull/465)
* [OCPBUGS-61253](https://issues.redhat.com/browse/OCPBUGS-61253): add ability to control kube rbac proxy container image… [#426](https://github.com/openshift/csi-operator/pull/426)
* [OCPBUGS-60598](https://issues.redhat.com/browse/OCPBUGS-60598): Bump library-go [#423](https://github.com/openshift/csi-operator/pull/423)
* [OCPBUGS-59606](https://issues.redhat.com/browse/OCPBUGS-59606): Backport stale conditions fix [#407](https://github.com/openshift/csi-operator/pull/407)
* [OCPBUGS-60248](https://issues.redhat.com/browse/OCPBUGS-60248): add tag matching to Azure File storage class [#414](https://github.com/openshift/csi-operator/pull/414)
* [Full changelog](https://github.com/openshift/csi-operator/compare/ff69cd0336ab92035d3d57af0ec71ff7b52f0f17...c1c48cd02b9dcf3cc19993b448301ec78b586f28)
### [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws/tree/169f6ab7eda8badff93a34074b03841e8f716dbb)
* [OCPBUGS-73903](https://issues.redhat.com/browse/OCPBUGS-73903): Fix reconciler consistency checks in Update and Exists [#168](https://github.com/openshift/machine-api-provider-aws/pull/168)
* [OCPBUGS-63140](https://issues.redhat.com/browse/OCPBUGS-63140): client: re-use a single file for building the session instead of randomly named files [#144](https://github.com/openshift/machine-api-provider-aws/pull/144)
* [Full changelog](https://github.com/openshift/machine-api-provider-aws/compare/0c8198618609197cc6cbcfd4016ba8400d8c13d5...169f6ab7eda8badff93a34074b03841e8f716dbb)
### [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook/tree/459c531487ae4dd94301e2996bf817d47124854c)
* [OCPBUGS-52513](https://issues.redhat.com/browse/OCPBUGS-52513): github.com/go-jose/go-jose/v4 v4.0.5 [#203](https://github.com/openshift/aws-pod-identity-webhook/pull/203)
* [Full changelog](https://github.com/openshift/aws-pod-identity-webhook/compare/746491a64a4efc04132ceb641cee52c2ead3facd...459c531487ae4dd94301e2996bf817d47124854c)
### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/a3ebdc0ff7017b46f6eb23503140c90a738cdeb1)
* [OCPBUGS-79998](https://issues.redhat.com/browse/OCPBUGS-79998), [OCPBUGS-85635](https://issues.redhat.com/browse/OCPBUGS-85635), [OCPBUGS-85636](https://issues.redhat.com/browse/OCPBUGS-85636): Bump google.golang.org/grpc to v1.79.3 [#182](https://github.com/openshift/cloud-provider-azure/pull/182)
* [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/e5bac3341fce67c12047caaafcf188c3f3049dc3...a3ebdc0ff7017b46f6eb23503140c90a738cdeb1)
### [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure/tree/d5d7c1df941bca00c137cff299a5e7c63dc3f077)
* [OCPBUGS-78176](https://issues.redhat.com/browse/OCPBUGS-78176): [release-4.16] update go mod dependency for konflux [#364](https://github.com/openshift/cluster-api-provider-azure/pull/364)
* [Full changelog](https://github.com/openshift/cluster-api-provider-azure/compare/a81e3b31948468d76ac744bbbb74b0c423fc969e...d5d7c1df941bca00c137cff299a5e7c63dc3f077)
### [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver/tree/308c5c2e6ad62302139a51b8315f11c2360982d0)
* [OCPBUGS-102923](https://issues.redhat.com/browse/OCPBUGS-102923): Bump golang.org/x/net to v0.35.0-sec.4 [#160](https://github.com/openshift/azure-file-csi-driver/pull/160)
* UPSTREAM: 3221: OCPBUGS-115466: Bump golang.org/x/crypto to v0.33.0-sec.5 [#165](https://github.com/openshift/azure-file-csi-driver/pull/165)
* [OCPBUGS-89335](https://issues.redhat.com/browse/OCPBUGS-89335): Address CVE-2026-33186 [#139](https://github.com/openshift/azure-file-csi-driver/pull/139)
* [Full changelog](https://github.com/openshift/azure-file-csi-driver/compare/7a36778add73d12eb08ff6be357d8d351af651a7...308c5c2e6ad62302139a51b8315f11c2360982d0)
### [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms/tree/de2338968fa1fd9ee8ee7dc44ef4120008affbca)
* [OCPBUGS-79927](https://issues.redhat.com/browse/OCPBUGS-79927): Bump google.golang.org/grpc to 1.64.1-sec.1 patch [#48](https://github.com/openshift/azure-kubernetes-kms/pull/48)
* [OCPBUGS-53494](https://issues.redhat.com/browse/OCPBUGS-53494): bump golang-jwt v4 [#13](https://github.com/openshift/azure-kubernetes-kms/pull/13)
* [Full changelog](https://github.com/openshift/azure-kubernetes-kms/compare/47d243b5a993fd0817eecf89a6d7896a3c911ecb...de2338968fa1fd9ee8ee7dc44ef4120008affbca)
### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/5d4b4f31f704af72810ed3f403aae478e52140b0)
* [OCPBUGS-66044](https://issues.redhat.com/browse/OCPBUGS-66044): Set updateDomainCount to one when faultDomainCount is one [#177](https://github.com/openshift/machine-api-provider-azure/pull/177)
* [OCPBUGS-52476](https://issues.redhat.com/browse/OCPBUGS-52476): Remove unused vnet package [#131](https://github.com/openshift/machine-api-provider-azure/pull/131)
* [OCPBUGS-56169](https://issues.redhat.com/browse/OCPBUGS-56169): [release-4.16] Update virtualmachines service to armcompute/v5 SDK [#147](https://github.com/openshift/machine-api-provider-azure/pull/147)
* [OCPBUGS-56656](https://issues.redhat.com/browse/OCPBUGS-56656): Fix failure when attempting to modify immutable availabilitySet [#151](https://github.com/openshift/machine-api-provider-azure/pull/151)
* [OCPBUGS-56092](https://issues.redhat.com/browse/OCPBUGS-56092): Update eviction policy for Spot VMs from Deallocate to Delete [#142](https://github.com/openshift/machine-api-provider-azure/pull/142)
* [OCPBUGS-54990](https://issues.redhat.com/browse/OCPBUGS-54990): Re-reconcile machine on NIC provisioning failure [#137](https://github.com/openshift/machine-api-provider-azure/pull/137)
* [OCPBUGS-50966](https://issues.redhat.com/browse/OCPBUGS-50966): dynamically setting the amount of fault domains [#129](https://github.com/openshift/machine-api-provider-azure/pull/129)
* [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/e4e11505b645e2af8eb28c5dc353c41a6740db00...5d4b4f31f704af72810ed3f403aae478e52140b0)
### [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity/tree/5b8d171e853d10ba151bfac4ac1e76109524ca4b)
* [OCPBUGS-53798](https://issues.redhat.com/browse/OCPBUGS-53798): github.com/golang-jwt/jwt/v4 v4.5.2 [#33](https://github.com/openshift/azure-workload-identity/pull/33)
* [OCPBUGS-52510](https://issues.redhat.com/browse/OCPBUGS-52510): github.com/go-jose/go-jose/v4 v4.0.5 [#29](https://github.com/openshift/azure-workload-identity/pull/29)
* [Full changelog](https://github.com/openshift/azure-workload-identity/compare/4aca092a13f62e48c700a910e8f3f0f228a7d822...5b8d171e853d10ba151bfac4ac1e76109524ca4b)
### [baremetal-installer, installer, installer-altinfra, installer-artifacts](https://github.com/openshift/installer/tree/ad2a7643cc0b3b062a639fa106a8169f376f6065)
* [OCPBUGS-127603](https://issues.redhat.com/browse/OCPBUGS-127603): Update gcloud version to one that can be found [#10918](https://github.com/openshift/installer/pull/10918)
* [OCPBUGS-67206](https://issues.redhat.com/browse/OCPBUGS-67206): Update RHCOS-release-4.16 bootimage metadata to 416.94.202608150307-0 [#10798](https://github.com/openshift/installer/pull/10798)
* Revert "OCPBUGS-60668: Update RHCOS-release-4.16 bootimage metadata to 416.94.202601221345-0" [#10846](https://github.com/openshift/installer/pull/10846)
* [OCPBUGS-60668](https://issues.redhat.com/browse/OCPBUGS-60668): Update RHCOS-release-4.16 bootimage metadata to 416.94.202601221345-0 [#10281](https://github.com/openshift/installer/pull/10281)
* [OCPBUGS-74885](https://issues.redhat.com/browse/OCPBUGS-74885): Azure UPI ARM template: use storageAccountId [#10282](https://github.com/openshift/installer/pull/10282)
* [OCPBUGS-76586](https://issues.redhat.com/browse/OCPBUGS-76586): terraform/provider/google: Fixing GCP inconsistencies present with the service account creation [#10298](https://github.com/openshift/installer/pull/10298)
* [OCPBUGS-73879](https://issues.redhat.com/browse/OCPBUGS-73879): data/manifests/bootkube/cvo-overrides: Default to eus-4.16 [#10226](https://github.com/openshift/installer/pull/10226)
* [OCPBUGS-54165](https://issues.redhat.com/browse/OCPBUGS-54165): aws: fix NLB creation in secret regions [#10031](https://github.com/openshift/installer/pull/10031)
* [OCPBUGS-53237](https://issues.redhat.com/browse/OCPBUGS-53237): Validation for API and Ingress VIPs when using user-managed load balancer [#10048](https://github.com/openshift/installer/pull/10048)
* [OCPBUGS-62952](https://issues.redhat.com/browse/OCPBUGS-62952): Update the RHCOS 4.16 bootimage metadata [#10022](https://github.com/openshift/installer/pull/10022)
* [OCPBUGS-62653](https://issues.redhat.com/browse/OCPBUGS-62653): Release 4.16 bump terraform provider azurerm [#9993](https://github.com/openshift/installer/pull/9993)
* [OCPBUGS-59162](https://issues.redhat.com/browse/OCPBUGS-59162): vSphere - remove unit tests using nip.io [#9835](https://github.com/openshift/installer/pull/9835)
* [OCPBUGS-62235](https://issues.redhat.com/browse/OCPBUGS-62235): Make swift containers removal not fatal for UPI. [#9961](https://github.com/openshift/installer/pull/9961)
* [OCPBUGS-58290](https://issues.redhat.com/browse/OCPBUGS-58290): sort zone slices extracted from map of byo subnets [#9819](https://github.com/openshift/installer/pull/9819)
* [OCPBUGS-55807](https://issues.redhat.com/browse/OCPBUGS-55807): update resolv.conf every time on bootstrap node [#9694](https://github.com/openshift/installer/pull/9694)
* [OCPBUGS-57460](https://issues.redhat.com/browse/OCPBUGS-57460): vsphere - check if host is powered down or on standby before uploading template [#9786](https://github.com/openshift/installer/pull/9786)
* [OCPBUGS-36677](https://issues.redhat.com/browse/OCPBUGS-36677): Power VS: Enable incoming traffic on port 5000 during installation in a restricted network [#8711](https://github.com/openshift/installer/pull/8711)
* [OCPBUGS-57498](https://issues.redhat.com/browse/OCPBUGS-57498): ensure ctrplane nodes can access bootstrap MCS [#9788](https://github.com/openshift/installer/pull/9788)
* [OCPBUGS-54240](https://issues.redhat.com/browse/OCPBUGS-54240): Update timeout for GCP WaitFor operation [#9715](https://github.com/openshift/installer/pull/9715)
* [OCPBUGS-35040](https://issues.redhat.com/browse/OCPBUGS-35040): Power VS: Add ports needed for private clusters to security group [#8546](https://github.com/openshift/installer/pull/8546)
* [OCPBUGS-54327](https://issues.redhat.com/browse/OCPBUGS-54327): Remove error logging when determining image arch [#9610](https://github.com/openshift/installer/pull/9610)
* [OCPBUGS-54345](https://issues.redhat.com/browse/OCPBUGS-54345): Remove tmp directory used for agent pxe files [#9611](https://github.com/openshift/installer/pull/9611)
* [OCPBUGS-54263](https://issues.redhat.com/browse/OCPBUGS-54263): IBMCloud: Move to IBM TF openshift fork [#9604](https://github.com/openshift/installer/pull/9604)
* [OCPBUGS-50547](https://issues.redhat.com/browse/OCPBUGS-50547): aws/edge/byovpc: tag edge subnets with shared value [#9482](https://github.com/openshift/installer/pull/9482)
* [OCPBUGS-52191](https://issues.redhat.com/browse/OCPBUGS-52191): [release-4.16] capi/aws: bump provider for LB DNS lookup fix [#9547](https://github.com/openshift/installer/pull/9547)
* [OCPBUGS-51207](https://issues.redhat.com/browse/OCPBUGS-51207): Log correct hostname for validation status [#9511](https://github.com/openshift/installer/pull/9511)
* [OCPBUGS-51111](https://issues.redhat.com/browse/OCPBUGS-51111): PowerVS: destroy dhcp hack [#9502](https://github.com/openshift/installer/pull/9502)
* [Full changelog](https://github.com/openshift/installer/compare/ed196179749c9370de6906453fb78f16b37a6e42...ad2a7643cc0b3b062a639fa106a8169f376f6065)
### [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal/tree/e8c0c0eddddf4c23ead0b0d9d63371d18edf2ea9)
* [OCPBUGS-78099](https://issues.redhat.com/browse/OCPBUGS-78099): [release-4.16] fix vendor/ for hermetic migration 4.16 [#243](https://github.com/openshift/cluster-api-provider-baremetal/pull/243)
* [Full changelog](https://github.com/openshift/cluster-api-provider-baremetal/compare/2b396e06c0a92acbfa688cd782ec4bf319ff3608...e8c0c0eddddf4c23ead0b0d9d63371d18edf2ea9)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/df0d060090789a9e1e40a9e5939758b8c1259411)
* [OCPBUGS-77278](https://issues.redhat.com/browse/OCPBUGS-77278): Unblock BMH direct deletion when detached annotation is present [#463](https://github.com/openshift/baremetal-operator/pull/463)
* [OCPBUGS-53322](https://issues.redhat.com/browse/OCPBUGS-53322): BMO can expose any secret via BMCEventSubscription CRD [#407](https://github.com/openshift/baremetal-operator/pull/407)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/f3125db3aff53a63b215a514421505db6a28f4c5...df0d060090789a9e1e40a9e5939758b8c1259411)
### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/db2c4c714cfe25c1fc2ab015aadd2c124b6cb5f8)
* [OCPBUGS-60113](https://issues.redhat.com/browse/OCPBUGS-60113): Re-add ENABLE_NODEIP_DEBUG env var [#362](https://github.com/openshift/baremetal-runtimecfg/pull/362)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/f55a330f8139ef660b3f60b735ef77538f7b9cbe...db2c4c714cfe25c1fc2ab015aadd2c124b6cb5f8)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/33afbae38573e7a0944ab0d00c8acee6b321c196)
* [OCPBUGS-91215](https://issues.redhat.com/browse/OCPBUGS-91215), [OCPBUGS-91552](https://issues.redhat.com/browse/OCPBUGS-91552), [OCPBUGS-91589](https://issues.redhat.com/browse/OCPBUGS-91589): Bump golang.org/x/net to openshift-sustaining/net v0.35.0-sec.2 [#2346](https://github.com/openshift/oc/pull/2346)
* [OCPBUGS-111894](https://issues.redhat.com/browse/OCPBUGS-111894): Fix pre-existing unit test failures [#2374](https://github.com/openshift/oc/pull/2374)
* [OCPBUGS-64616](https://issues.redhat.com/browse/OCPBUGS-64616): Help with must-gather scheduling through suggesting preferance of nodes [#2151](https://github.com/openshift/oc/pull/2151)
* [OCPBUGS-64561](https://issues.redhat.com/browse/OCPBUGS-64561): Update go-jose, x/crypto, x/net [#2144](https://github.com/openshift/oc/pull/2144)
* [OCPBUGS-59938](https://issues.redhat.com/browse/OCPBUGS-59938): Adding sos.conf file for default sos config into the tools image [#2064](https://github.com/openshift/oc/pull/2064)
* [OCPBUGS-60675](https://issues.redhat.com/browse/OCPBUGS-60675): Use fedora image in unit tests instead of centos [#2079](https://github.com/openshift/oc/pull/2079)
* [OCPBUGS-51043](https://issues.redhat.com/browse/OCPBUGS-51043): Add HOST env var in oc debug for sos report collects more [#1977](https://github.com/openshift/oc/pull/1977)
* [Full changelog](https://github.com/openshift/oc/compare/cf533b548154f7f2e828a44864477bbbb881692d...33afbae38573e7a0944ab0d00c8acee6b321c196)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/89ea129d6b1759840fc256ee8780190a0f500b3a)
* [OCPBUGS-81849](https://issues.redhat.com/browse/OCPBUGS-81849): Bump go-jose/go-jose/v4@v4.1.4 [#1040](https://github.com/openshift/cloud-credential-operator/pull/1040)
* [OCPBUGS-79941](https://issues.redhat.com/browse/OCPBUGS-79941): Bump google.golang.org/grpc to v1.79.3 [#1026](https://github.com/openshift/cloud-credential-operator/pull/1026)
* [OCPBUGS-65802](https://issues.redhat.com/browse/OCPBUGS-65802): ccoctl azure: retry custom role creation on consistency errors [#952](https://github.com/openshift/cloud-credential-operator/pull/952)
* [OCPBUGS-63550](https://issues.redhat.com/browse/OCPBUGS-63550): ccoctl: add public-key-file flag to create-all [#940](https://github.com/openshift/cloud-credential-operator/pull/940)
* [OCPBUGS-55129](https://issues.redhat.com/browse/OCPBUGS-55129): snyk to ignore SNYK-GOLANG-GOLANGORGXNETHTML-9572088 [#918](https://github.com/openshift/cloud-credential-operator/pull/918)
* [OCPBUGS-60973](https://issues.redhat.com/browse/OCPBUGS-60973): ccoctl: aws to use proper issuer url on subsequent runs [#909](https://github.com/openshift/cloud-credential-operator/pull/909)
* [OCPBUGS-60861](https://issues.redhat.com/browse/OCPBUGS-60861): ccoctl: only add owned tag to azure resources on create [#902](https://github.com/openshift/cloud-credential-operator/pull/902)
* [OCPBUGS-58676](https://issues.redhat.com/browse/OCPBUGS-58676): github.com/golang/glog v1.2.5 [#893](https://github.com/openshift/cloud-credential-operator/pull/893)
* [OCPBUGS-56981](https://issues.redhat.com/browse/OCPBUGS-56981): Azure: resolve nil pointer exception when role assignment exists [#867](https://github.com/openshift/cloud-credential-operator/pull/867)
* [OCPBUGS-53416](https://issues.redhat.com/browse/OCPBUGS-53416): github.com/golang/glog v1.2.4 [#843](https://github.com/openshift/cloud-credential-operator/pull/843)
* [OCPBUGS-53822](https://issues.redhat.com/browse/OCPBUGS-53822): update github.com/golang-jwt/jwt [#839](https://github.com/openshift/cloud-credential-operator/pull/839)
* [OCPBUGS-51544](https://issues.redhat.com/browse/OCPBUGS-51544): Ignore SNYK-GOLANG-GOLANGORGXOAUTH2JWS-8749594 due to not being affected [#829](https://github.com/openshift/cloud-credential-operator/pull/829)
* [OCPBUGS-52512](https://issues.redhat.com/browse/OCPBUGS-52512): github.com/go-jose/go-jose/v4 v4.0.5 [#826](https://github.com/openshift/cloud-credential-operator/pull/826)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/87a85dc8e12e74149583877996ae38597e78e3dd...89ea129d6b1759840fc256ee8780190a0f500b3a)
### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/b3854cc9ce8b5823078d9fe837f43106d807435a)
* [OCPBUGS-66346](https://issues.redhat.com/browse/OCPBUGS-66346): [release-4.16] Fix capacity calculation [#195](https://github.com/openshift/cloud-network-config-controller/pull/195)
* [OCPBUGS-65567](https://issues.redhat.com/browse/OCPBUGS-65567): [release-4.16] Change the capacity struct from int to ptrOfInt [#192](https://github.com/openshift/cloud-network-config-controller/pull/192)
* [OCPBUGS-56359](https://issues.redhat.com/browse/OCPBUGS-56359): Increase API call timeout to 30 second [#172](https://github.com/openshift/cloud-network-config-controller/pull/172)
* [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/8ceee78810756afaa2efb75f60bef0358502834f...b3854cc9ce8b5823078d9fe837f43106d807435a)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/0e39ace55e81b082a50f67402e7776adb8c6c8a7)
* [OCPBUGS-54655](https://issues.redhat.com/browse/OCPBUGS-54655): Avoid duplicate OAuth client creation [#766](https://github.com/openshift/cluster-authentication-operator/pull/766)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/4782c451e1aab859b7db09aee01af10c1ebf428c...0e39ace55e81b082a50f67402e7776adb8c6c8a7)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/1f7a1aa91071c56901a8be989beb341731c8a4ff)
* [OCPBUGS-78702](https://issues.redhat.com/browse/OCPBUGS-78702): allow clusterapi provider to skip paused resources [#415](https://github.com/openshift/kubernetes-autoscaler/pull/415)
* [OCPBUGS-60915](https://issues.redhat.com/browse/OCPBUGS-60915): revert openshift replica fix [#377](https://github.com/openshift/kubernetes-autoscaler/pull/377)
* [OCPBUGS-59267](https://issues.redhat.com/browse/OCPBUGS-59267): Fix cool down status condition to trigger scale down [#363](https://github.com/openshift/kubernetes-autoscaler/pull/363)
* [OCPBUGS-60609](https://issues.redhat.com/browse/OCPBUGS-60609): fix checkpoint gc of unknown recommenders [#372](https://github.com/openshift/kubernetes-autoscaler/pull/372)
* [OCPBUGS-54326](https://issues.redhat.com/browse/OCPBUGS-54326): improve replica counting and decrease target size behavior [#353](https://github.com/openshift/kubernetes-autoscaler/pull/353)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/f0bac124f7a1c6dee6e40fe90415cb95017f83a1...1f7a1aa91071c56901a8be989beb341731c8a4ff)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/075e448e1b5530fcf2905a69d04387218c6d90ec)
* [OCPBUGS-102934](https://issues.redhat.com/browse/OCPBUGS-102934): Bump x/net package in release-4.16 [#390](https://github.com/openshift/cluster-autoscaler-operator/pull/390)
* [OCPBUGS-52329](https://issues.redhat.com/browse/OCPBUGS-52329): set max soft bulk taint count to zero [#341](https://github.com/openshift/cluster-autoscaler-operator/pull/341)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/40cadf8a4729ca808a3413e9b8593ab7aab0bed7...075e448e1b5530fcf2905a69d04387218c6d90ec)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/c6f66328514396b014ce76779297f9181d886983)
* [OCPBUGS-77447](https://issues.redhat.com/browse/OCPBUGS-77447): Bump github.com/go-errors/errors to v1.5.1 [#562](https://github.com/openshift/cluster-baremetal-operator/pull/562)
* [OCPBUGS-64741](https://issues.redhat.com/browse/OCPBUGS-64741): Always have a service for ironic-api port [#524](https://github.com/openshift/cluster-baremetal-operator/pull/524)
* [OCPBUGS-63417](https://issues.redhat.com/browse/OCPBUGS-63417): Fix ironic inspector container privileges [#513](https://github.com/openshift/cluster-baremetal-operator/pull/513)
* [OCPBUGS-61504](https://issues.redhat.com/browse/OCPBUGS-61504): Remove webhookport (9447) as HostPort [#506](https://github.com/openshift/cluster-baremetal-operator/pull/506)
* [OCPBUGS-54546](https://issues.redhat.com/browse/OCPBUGS-54546): Add missing relatedObjects [#470](https://github.com/openshift/cluster-baremetal-operator/pull/470)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/03738f2d941b836800926fc701202b8d4b9d0605...c6f66328514396b014ce76779297f9181d886983)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/be91ee59e14dff88506df6e70e35470638bc3589)
* [OCPBUGS-79943](https://issues.redhat.com/browse/OCPBUGS-79943): Bump google.golang.org/grpc to v1.79.3 [#573](https://github.com/openshift/cluster-capi-operator/pull/573)
* NO-JIRA: Allow sustaining engineering to self serve dependency updates [#560](https://github.com/openshift/cluster-capi-operator/pull/560)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/c699f6cfedbcd8509a85db2be3e6f90712b728fe...be91ee59e14dff88506df6e70e35470638bc3589)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/d721cd62b5edec3f1b0b7a61b3e6e2af50bb71bc)
* [OCPBUGS-63168](https://issues.redhat.com/browse/OCPBUGS-63168): ccm: disable unused secure-serving port and webhook [#422](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/422)
* [OCPBUGS-60387](https://issues.redhat.com/browse/OCPBUGS-60387): Add Service using common resource templating [#411](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/411)
* [OCPBUGS-60387](https://issues.redhat.com/browse/OCPBUGS-60387): Update service selector to match deployment label [#410](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/410)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/1c26756f0b4ff5537e32db18d5fb16555f5bd58f...d721cd62b5edec3f1b0b7a61b3e6e2af50bb71bc)
### [cluster-config-api](https://github.com/openshift/api/tree/0677a8879a4608a5b6ecafd490fbbeb0ff77c6ef)
* [CNTRLPLANE-1982](https://issues.redhat.com/browse/CNTRLPLANE-1982): Promote streaming list encoding to Default [#2600](https://github.com/openshift/api/pull/2600)
* [OCPBUGS-71202](https://issues.redhat.com/browse/OCPBUGS-71202): Add HTTPKeepAliveTimeout to IngressController API [#2640](https://github.com/openshift/api/pull/2640)
* NO-JIRA: Promote streaming list encoding to Default on Hypershift. [#2568](https://github.com/openshift/api/pull/2568)
* [CNTRLPLANE-1611](https://issues.redhat.com/browse/CNTRLPLANE-1611): Add feature gates for StreamingCollectionEncoding [#2542](https://github.com/openshift/api/pull/2542)
* [OCPBUGS-58392](https://issues.redhat.com/browse/OCPBUGS-58392): Add IPsec API for NAT-T UDP encapsulation support [#2393](https://github.com/openshift/api/pull/2393)
* [OCPBUGS-56424](https://issues.redhat.com/browse/OCPBUGS-56424): Add IdleConnectionTerminationPolicy field to IngressControllerSpec [#2330](https://github.com/openshift/api/pull/2330)
* [Full changelog](https://github.com/openshift/api/compare/b7d0481c9094172326bc9462c4f85b8f3ff0d761...0677a8879a4608a5b6ecafd490fbbeb0ff77c6ef)
### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/a4b1cfb4927052f4e21e919d0af05f78ca4fcace)
* [OCPBUGS-52498](https://issues.redhat.com/browse/OCPBUGS-52498): [release-4.16] Add runbook_url for CoreDNSErrorsHigh [#431](https://github.com/openshift/cluster-dns-operator/pull/431)
* [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/8ddf28f959955e2b1b319856c0d47ae6729bcc31...a4b1cfb4927052f4e21e919d0af05f78ca4fcace)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/d9e83020b9eb7346dc8ef00961cf7837db18034e)
* [OCPBUGS-68058](https://issues.redhat.com/browse/OCPBUGS-68058): Update logrus to 1.9.3 to address CVE-2025-65637 [#1546](https://github.com/openshift/cluster-etcd-operator/pull/1546)
* [OCPBUGS-61505](https://issues.redhat.com/browse/OCPBUGS-61505): Vendor latest mixin, including additional and modified alerts for etcdDatabaseQuotaLowSpace [#1482](https://github.com/openshift/cluster-etcd-operator/pull/1482)
* [OCPBUGS-60836](https://issues.redhat.com/browse/OCPBUGS-60836): add missing ports to svc and pod spec [#1473](https://github.com/openshift/cluster-etcd-operator/pull/1473)
* [OCPBUGS-53510](https://issues.redhat.com/browse/OCPBUGS-53510): fix CVE-2025-30204 [#1403](https://github.com/openshift/cluster-etcd-operator/pull/1403)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/3f2ce4889c255391323d8bdf07dece99e87dbccd...d9e83020b9eb7346dc8ef00961cf7837db18034e)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/ed0afa7a74765b857ec0c51b84151df84d48fb3f)
* [OCPBUGS-68059](https://issues.redhat.com/browse/OCPBUGS-68059): : Bump github.com/sirupsen/logrus to v1.9.1 [#1285](https://github.com/openshift/cluster-image-registry-operator/pull/1285)
* [OCPBUGS-53870](https://issues.redhat.com/browse/OCPBUGS-53870): bump github.com/golang-jwt/jwt [#1219](https://github.com/openshift/cluster-image-registry-operator/pull/1219)
* [OCPBUGS-51600](https://issues.redhat.com/browse/OCPBUGS-51600): bump golang.org/x/oauth2 [#1210](https://github.com/openshift/cluster-image-registry-operator/pull/1210)
* [OCPBUGS-51167](https://issues.redhat.com/browse/OCPBUGS-51167): ensure that storage names don't end in dashes [#1181](https://github.com/openshift/cluster-image-registry-operator/pull/1181)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/00111bc2e57dfd2c3c1d1da39a2a5ed36de9d068...ed0afa7a74765b857ec0c51b84151df84d48fb3f)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/fd63a64723ae8d734aef449ec140e7884fa8bdf1)
* [OCPBUGS-102952](https://issues.redhat.com/browse/OCPBUGS-102952): Replace golang.org/x/net with github.com/openshift-sustaining/net@v0.35.0-sec.3 [#1573](https://github.com/openshift/cluster-ingress-operator/pull/1573)
* [OCPBUGS-86713](https://issues.redhat.com/browse/OCPBUGS-86713): Add configuration override for X-SSL strip [#1487](https://github.com/openshift/cluster-ingress-operator/pull/1487)
* [OCPBUGS-71202](https://issues.redhat.com/browse/OCPBUGS-71202): Implement HTTPKeepAliveTimeout tuning option [#1337](https://github.com/openshift/cluster-ingress-operator/pull/1337)
* [OCPBUGS-56424](https://issues.redhat.com/browse/OCPBUGS-56424): Add e2e tests for IdleConnectionTerminationPolicy [#1235](https://github.com/openshift/cluster-ingress-operator/pull/1235)
* [OCPBUGS-56424](https://issues.redhat.com/browse/OCPBUGS-56424): Add support for IdleConnectionTerminationPolicy [#1234](https://github.com/openshift/cluster-ingress-operator/pull/1234)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/57f9674e75908ca11b24792fb9f077233cd7bcf1...fd63a64723ae8d734aef449ec140e7884fa8bdf1)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/d0b79035dcec4011d4968e4701f8ff13d921cf2e)
* [OCPBUGS-68064](https://issues.redhat.com/browse/OCPBUGS-68064): CVE-2025-65637 openshift4/ose-cluster-kube-apiserver-rhel9-operator: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [openshift-4.16.z] [#2043](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2043)
* [OCPBUGS-60467](https://issues.redhat.com/browse/OCPBUGS-60467): Add missing service ports to apiserver service [#1895](https://github.com/openshift/cluster-kube-apiserver-operator/pull/1895)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/f47238554feb2fa6dbce3333adc7e26ffe2d8424...d0b79035dcec4011d4968e4701f8ff13d921cf2e)
### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/b3faac1f48914e94fa9af074f387c871dad84a9c)
* [OCPBUGS-60834](https://issues.redhat.com/browse/OCPBUGS-60834): Missing endpoint slices for open ports the operator uses [#864](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/864)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/0338b3be6912024d03def2c26f0fa10218fc2c25...b3faac1f48914e94fa9af074f387c871dad84a9c)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/39dd141c918da30da848fdb87ee333f909a16b84)
* [CNTRLPLANE-2843](https://issues.redhat.com/browse/CNTRLPLANE-2843): chore: update OWNERS [#624](https://github.com/openshift/cluster-kube-scheduler-operator/pull/624)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/630f63bc7a30d2662bbb5115233144079de6eef6...39dd141c918da30da848fdb87ee333f909a16b84)
### [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/tree/a26352fcbeebaab395b88fb011c39ed40185e0dd)
* [OCPBUGS-68069](https://issues.redhat.com/browse/OCPBUGS-68069): Bump github.com/sirupsen/logrus to v1.9.1 [#144](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/144)
* [Full changelog](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/compare/e825811333c05b705c35d2e9a9a62e55e9ab0935...a26352fcbeebaab395b88fb011c39ed40185e0dd)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/5cc2998068f123dec944beb8a813a79d369c60cd)
* NO-ISSUE: synchronize OWNERS from main branch [release-4.16] [#3113](https://github.com/openshift/cluster-monitoring-operator/pull/3113)
* [OCPBUGS-102945](https://issues.redhat.com/browse/OCPBUGS-102945): [release-4.16] Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [#3090](https://github.com/openshift/cluster-monitoring-operator/pull/3090)
* [OCPBUGS-77276](https://issues.redhat.com/browse/OCPBUGS-77276): AlertingRule: fix duplicate PrometheusRules after MD5->SHA-224 naming change [#2831](https://github.com/openshift/cluster-monitoring-operator/pull/2831)
* [OCPBUGS-64581](https://issues.redhat.com/browse/OCPBUGS-64581): Fix KSM deny-list typo [#2733](https://github.com/openshift/cluster-monitoring-operator/pull/2733)
* [OCPBUGS-64637](https://issues.redhat.com/browse/OCPBUGS-64637): Add mcd_local_unsupported_packages metric from MCO to telemetry 4.16 [#2735](https://github.com/openshift/cluster-monitoring-operator/pull/2735)
* [OCPBUGS-62765](https://issues.redhat.com/browse/OCPBUGS-62765): port metric acm_managed_cluster_worker_cores:max to OCP 4.16 [#2719](https://github.com/openshift/cluster-monitoring-operator/pull/2719)
* [OCPBUGS-63235](https://issues.redhat.com/browse/OCPBUGS-63235): test: remove image registry e2e tests [#2727](https://github.com/openshift/cluster-monitoring-operator/pull/2727)
* [OCPBUGS-61856](https://issues.redhat.com/browse/OCPBUGS-61856): chore(jsonnet): use prometheus_remote_storage_queue_highest_timestamp_seconds in PrometheusRemoteWriteBehind [#2676](https://github.com/openshift/cluster-monitoring-operator/pull/2676)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/09963a509301f71679e9c567f06c6a4deda222fd...5cc2998068f123dec944beb8a813a79d369c60cd)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/69b8dae17be7eae9345b86a378a356f0f323f44f)
* [OCPBUGS-67000](https://issues.redhat.com/browse/OCPBUGS-67000): Re-disable metrics server [#2855](https://github.com/openshift/cluster-network-operator/pull/2855)
* [OCPBUGS-63233](https://issues.redhat.com/browse/OCPBUGS-63233): Manual feature backport of cert rotation for whereabouts [#3040](https://github.com/openshift/cluster-network-operator/pull/3040)
* [OCPBUGS-84182](https://issues.redhat.com/browse/OCPBUGS-84182): fix(hypershift): use net.JoinHostPort for URL construction [#2981](https://github.com/openshift/cluster-network-operator/pull/2981)
* [OCPBUGS-75890](https://issues.redhat.com/browse/OCPBUGS-75890): Tweak iptables-alerter to try to avoid crictl bug [#2898](https://github.com/openshift/cluster-network-operator/pull/2898)
* : NO-JIRA: Update CNO reviewers/approvers [#2768](https://github.com/openshift/cluster-network-operator/pull/2768)
* [OCPBUGS-63155](https://issues.redhat.com/browse/OCPBUGS-63155): Add drop flows for GARPs [#2819](https://github.com/openshift/cluster-network-operator/pull/2819)
* [OCPBUGS-57354](https://issues.redhat.com/browse/OCPBUGS-57354): block upgrade if a CNI migration is in progress [#2760](https://github.com/openshift/cluster-network-operator/pull/2760)
* [OCPBUGS-62055](https://issues.redhat.com/browse/OCPBUGS-62055): Update CNO reviewers/approvers [#2803](https://github.com/openshift/cluster-network-operator/pull/2803)
* [OCPBUGS-44443](https://issues.redhat.com/browse/OCPBUGS-44443): Add controlplane cli image envar for use with hypershift [#2791](https://github.com/openshift/cluster-network-operator/pull/2791)
* [OCPBUGS-58392](https://issues.redhat.com/browse/OCPBUGS-58392): Add IPsec API for NAT-T UDP encapsulation support [#2736](https://github.com/openshift/cluster-network-operator/pull/2736)
* [OCPBUGS-56992](https://issues.redhat.com/browse/OCPBUGS-56992): iptables-alerter streamlining [#2717](https://github.com/openshift/cluster-network-operator/pull/2717)
* [OCPBUGS-56195](https://issues.redhat.com/browse/OCPBUGS-56195): Fix live migration with feature migration configured explicitly [#2710](https://github.com/openshift/cluster-network-operator/pull/2710)
* [OCPBUGS-53317](https://issues.redhat.com/browse/OCPBUGS-53317): Fix feature migration for EgressIP [#2673](https://github.com/openshift/cluster-network-operator/pull/2673)
* [OCPBUGS-52952](https://issues.redhat.com/browse/OCPBUGS-52952): Unexpected Behavior During Cluster Upgrade for the ovn-ipsec-host pods [#2663](https://github.com/openshift/cluster-network-operator/pull/2663)
* [Release 4.16] OCPBUGS-50712: Not update status.migration of the network.config CR to empty [#2651](https://github.com/openshift/cluster-network-operator/pull/2651)
* [OCPBUGS-51074](https://issues.redhat.com/browse/OCPBUGS-51074): Update egressfirewall CRD to be consistent with ovn-kubernetes repo [#2650](https://github.com/openshift/cluster-network-operator/pull/2650)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/b5eb4ae75b428e748cbf6a7e6b68da2b4687cbf3...69b8dae17be7eae9345b86a378a356f0f323f44f)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/26411b2287daa532bc8daad12e489ba1af0348fd)
* [OCPBUGS-82675](https://issues.redhat.com/browse/OCPBUGS-82675): Bump github.com/moby/spdystream from v0.2.0 to v0.5.1 [#1551](https://github.com/openshift/cluster-node-tuning-operator/pull/1551)
* [OCPBUGS-78766](https://issues.redhat.com/browse/OCPBUGS-78766): [4.16] PPC: filter out namespaces dir [#1466](https://github.com/openshift/cluster-node-tuning-operator/pull/1466)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/eacd6ee98ab26722603083768d4f58727a390dbe...26411b2287daa532bc8daad12e489ba1af0348fd)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/822ed169b2ecce43e75ad649467712d13c3a32ba)
* [OCPBUGS-86243](https://issues.redhat.com/browse/OCPBUGS-86243): Update grpc-go to v1.67.3-sec.1 to fix CVE-2026-33186 [#206](https://github.com/openshift/cluster-olm-operator/pull/206)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/27bf70ddf9421637e1da18b249785b2cca177272...822ed169b2ecce43e75ad649467712d13c3a32ba)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/2497afd389d884f90d3b1950f81f2d2b4116fa3d)
* [OCPBUGS-68072](https://issues.redhat.com/browse/OCPBUGS-68072): CVE-2025-65637 - Bump github.com/sirupsen/logrus from v1.9.0 to v1.9.3 [release-4.16] [#654](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/654)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/d26f3002e10be6f206f69a829d1511130e8188d9...2497afd389d884f90d3b1950f81f2d2b4116fa3d)
### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/f9a02d5c843839ee2031995459d38e4bddc6a84a)
* [OCPBUGS-63516](https://issues.redhat.com/browse/OCPBUGS-63516): references to github.com/sclorg/django-ex.git now also refer to the branch [#659](https://github.com/openshift/cluster-samples-operator/pull/659)
* [OCPBUGS-55457](https://issues.redhat.com/browse/OCPBUGS-55457): Adding mutex to func createSamples on handler.go [#633](https://github.com/openshift/cluster-samples-operator/pull/633)
* [OCPBUGS-54420](https://issues.redhat.com/browse/OCPBUGS-54420): add rhdmalone to owners [#620](https://github.com/openshift/cluster-samples-operator/pull/620)
* [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/34eec32b3f8d79e15fa5bc59ddcea0c67f1caeee...f9a02d5c843839ee2031995459d38e4bddc6a84a)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/fba24ed11cebba1a3f6986e0e468a1e9a1964285)
* [OCPBUGS-87613](https://issues.redhat.com/browse/OCPBUGS-87613): remove oVirt code from CSO 4.16 [#709](https://github.com/openshift/cluster-storage-operator/pull/709)
* [OCPBUGS-78769](https://issues.redhat.com/browse/OCPBUGS-78769): Add patch permission to provisioner role [#685](https://github.com/openshift/cluster-storage-operator/pull/685)
* [OCPBUGS-61252](https://issues.redhat.com/browse/OCPBUGS-61252): add ability to control kube rbac proxy container image on controlplane [#614](https://github.com/openshift/cluster-storage-operator/pull/614)
* [OCPBUGS-52353](https://issues.redhat.com/browse/OCPBUGS-52353): fix Vsphere cluster Storage operator in Unavailable state [#563](https://github.com/openshift/cluster-storage-operator/pull/563)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/86529c3935d12fd90f7537ade0db42f4fcb1eeb3...fba24ed11cebba1a3f6986e0e468a1e9a1964285)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/be820285dcf7b0ca4a712192ccb47fd0c843ea02)
* [OCPBUGS-58452](https://issues.redhat.com/browse/OCPBUGS-58452): Failing=Unknown upon long CO updating [#1213](https://github.com/openshift/cluster-version-operator/pull/1213)
* [OCPBUGS-55156](https://issues.redhat.com/browse/OCPBUGS-55156): Fix a panic caused by a data race [#1178](https://github.com/openshift/cluster-version-operator/pull/1178)
* [OCPBUGS-50590](https://issues.redhat.com/browse/OCPBUGS-50590): Set `openshift.io/required-scc`: privileged annotation in `version` pods [#1153](https://github.com/openshift/cluster-version-operator/pull/1153)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/671714b6563ff252cc4a8c455775d3682f2c1302...be820285dcf7b0ca4a712192ccb47fd0c843ea02)
### [console](https://github.com/openshift/console/tree/d50e2f0f098af842d8798033fcaed37ba84826ac)
* [OCPBUGS-98424](https://issues.redhat.com/browse/OCPBUGS-98424): CVE-2026-59869 bump js-yaml [#17158](https://github.com/openshift/console/pull/17158)
* Fix for OCPBUGS-92076: CVE-2026-44990 [#16719](https://github.com/openshift/console/pull/16719)
* [OCPBUGS-100513](https://issues.redhat.com/browse/OCPBUGS-100513), [OCPBUGS-101789](https://issues.redhat.com/browse/OCPBUGS-101789): Fix CVE-2026-69153 and CVE-2026-45623 - Bump postcss [#17060](https://github.com/openshift/console/pull/17060)
* [OCPBUGS-114417](https://issues.redhat.com/browse/OCPBUGS-114417): Prevent binary secret data corruption when editing [#17101](https://github.com/openshift/console/pull/17101)
* [OCPBUGS-105793](https://issues.redhat.com/browse/OCPBUGS-105793): Disable failing OLM and other e2e tests to unblock CI [#16958](https://github.com/openshift/console/pull/16958)
* [OCPBUGS-105796](https://issues.redhat.com/browse/OCPBUGS-105796): Fix operator-hub e2e test by replacing unavailable Red Hat catalog source with Community [#17081](https://github.com/openshift/console/pull/17081)
* [OCPBUGS-87987](https://issues.redhat.com/browse/OCPBUGS-87987): [release-4.16] shell-quote: Arbitrary code execution via command injection due to unescaped line terminators [#16599](https://github.com/openshift/console/pull/16599)
* [OCPBUGS-81597](https://issues.redhat.com/browse/OCPBUGS-81597): CVE-2026-4800 [#16566](https://github.com/openshift/console/pull/16566)
* [OCPBUGS-77123](https://issues.redhat.com/browse/OCPBUGS-77123): [release-4.16] CVE-2026-26996 Bump minimatch library [#16346](https://github.com/openshift/console/pull/16346)
* [OCPBUGS-79439](https://issues.redhat.com/browse/OCPBUGS-79439): Bump immutable [#16657](https://github.com/openshift/console/pull/16657)
* [OCPBUGS-88027](https://issues.redhat.com/browse/OCPBUGS-88027): Fix JSON annotation parsing to prevent OperatorHub crash [#16588](https://github.com/openshift/console/pull/16588)
* [OCPBUGS-88377](https://issues.redhat.com/browse/OCPBUGS-88377), [OCPBUGS-88380](https://issues.redhat.com/browse/OCPBUGS-88380), [OCPBUGS-88412](https://issues.redhat.com/browse/OCPBUGS-88412), [OCPBUGS-88419](https://issues.redhat.com/browse/OCPBUGS-88419), [OCPBUGS-88444](https://issues.redhat.com/browse/OCPBUGS-88444): CVE-2026-44495 [#16612](https://github.com/openshift/console/pull/16612)
* [OCPBUGS-88554](https://issues.redhat.com/browse/OCPBUGS-88554): Stabilize legacy OperatorHub Cypress waits [#16608](https://github.com/openshift/console/pull/16608)
* NO-JIRA: enable multi-architecture yarn builds [#16417](https://github.com/openshift/console/pull/16417)
* [OCPBUGS-83299](https://issues.redhat.com/browse/OCPBUGS-83299): [release-4.16] openshift4/ose-console-rhel9: Axios: Remote Code Execution via Prototype Pollution escalation [#16298](https://github.com/openshift/console/pull/16298)
* [OCPBUGS-78673](https://issues.redhat.com/browse/OCPBUGS-78673): Namespace is not persisting when switching to developer view from the topology page of admin page [#16161](https://github.com/openshift/console/pull/16161)
* [CONSOLE-5011](https://issues.redhat.com/browse/CONSOLE-5011): migrate to yarn berry [#16078](https://github.com/openshift/console/pull/16078)
* [OCPBUGS-76578](https://issues.redhat.com/browse/OCPBUGS-76578): Bump axios [#16032](https://github.com/openshift/console/pull/16032)
* NO-JIRA: Bump builder image to v29 [#15993](https://github.com/openshift/console/pull/15993)
* [OCPBUGS-74447](https://issues.redhat.com/browse/OCPBUGS-74447): Bump lodash to latest [#15967](https://github.com/openshift/console/pull/15967)
* [OCPBUGS-69678](https://issues.redhat.com/browse/OCPBUGS-69678): Disallowed Pipelines-plugin Pipelines navigation section [#15857](https://github.com/openshift/console/pull/15857)
* [OCPBUGS-64884](https://issues.redhat.com/browse/OCPBUGS-64884): Remove required flag from 'console.flag/model' pipelines-plugin extension [#15707](https://github.com/openshift/console/pull/15707)
* [OCPBUGS-64649](https://issues.redhat.com/browse/OCPBUGS-64649): `/auth/error?error=missing_state&error_type=auth` is showing blank page [#15675](https://github.com/openshift/console/pull/15675)
* [OCPBUGS-44157](https://issues.redhat.com/browse/OCPBUGS-44157): bump dompurify to latest [#15591](https://github.com/openshift/console/pull/15591)
* [OCPBUGS-62123](https://issues.redhat.com/browse/OCPBUGS-62123): Remove ancient `X-XSS-Protection` header [#15528](https://github.com/openshift/console/pull/15528)
* [OCPBUGS-61057](https://issues.redhat.com/browse/OCPBUGS-61057): OpenShift console PVC clone cannot use B as the unit [#15450](https://github.com/openshift/console/pull/15450)
* [OCPBUGS-60175](https://issues.redhat.com/browse/OCPBUGS-60175): Tolerate unknown fields in Infrastructur… [#15368](https://github.com/openshift/console/pull/15368)
* [OCPBUGS-60641](https://issues.redhat.com/browse/OCPBUGS-60641): Secret key with binary file changes when edited via Console [#15417](https://github.com/openshift/console/pull/15417)
* [OCPBUGS-59869](https://issues.redhat.com/browse/OCPBUGS-59869): Not able to launch terminal window from OCP web console due to console plugin conflicts [#15334](https://github.com/openshift/console/pull/15334)
* [OCPBUGS-57677](https://issues.redhat.com/browse/OCPBUGS-57677): Update the golang.org/x/crypto/ssh to 0.31.0 in the openshift-console image [#15328](https://github.com/openshift/console/pull/15328)
* [OCPBUGS-60115](https://issues.redhat.com/browse/OCPBUGS-60115): Cannot read properties of undefined (reading 'node-role.kubernetes.io/master') error while accessing node logs from console [#15358](https://github.com/openshift/console/pull/15358)
* [OCPBUGS-59358](https://issues.redhat.com/browse/OCPBUGS-59358): fix bug where / in console.tab/horizontalNav href brea… [#15286](https://github.com/openshift/console/pull/15286)
* [OCPBUGS-37603](https://issues.redhat.com/browse/OCPBUGS-37603): Manual backport of several incremental fixes for unauthenticated endpoints [#15312](https://github.com/openshift/console/pull/15312)
* [OCPBUGS-59274](https://issues.redhat.com/browse/OCPBUGS-59274): Add the ability to launch multiple modals with useModal hook [#15276](https://github.com/openshift/console/pull/15276)
* [OCPBUGS-59445](https://issues.redhat.com/browse/OCPBUGS-59445): Cannot read properties of undefined (reading 'filter') error while accessing nodes from console. [#15291](https://github.com/openshift/console/pull/15291)
* [OCPBUGS-58407](https://issues.redhat.com/browse/OCPBUGS-58407): Add flags in console static plugin for all the components of this epic [#15243](https://github.com/openshift/console/pull/15243)
* [OCPBUGS-56838](https://issues.redhat.com/browse/OCPBUGS-56838): Fetching taskRuns in PLR details page using PLR UID also [#15099](https://github.com/openshift/console/pull/15099)
* [OCPBUGS-58188](https://issues.redhat.com/browse/OCPBUGS-58188): Fix TypeError Cannot read properties of null (reading 'metadata') [#15214](https://github.com/openshift/console/pull/15214)
* [OCPBUGS-57326](https://issues.redhat.com/browse/OCPBUGS-57326): Remove logoutOpenShift method call [#15172](https://github.com/openshift/console/pull/15172)
* [OCPBUGS-57270](https://issues.redhat.com/browse/OCPBUGS-57270): Debug pod logs are not accessible when debugging a node via OpenShift Console [#15165](https://github.com/openshift/console/pull/15165)
* [OCPBUGS-57096](https://issues.redhat.com/browse/OCPBUGS-57096): Add all files to `vendor` regardless of gitignore [#15133](https://github.com/openshift/console/pull/15133)
* [OCPBUGS-57089](https://issues.redhat.com/browse/OCPBUGS-57089): Sample segment sessions [#15130](https://github.com/openshift/console/pull/15130)
* [OCPBUGS-56858](https://issues.redhat.com/browse/OCPBUGS-56858): remove 60 day alert from cluster update modal [#15102](https://github.com/openshift/console/pull/15102)
* [OCPBUGS-56715](https://issues.redhat.com/browse/OCPBUGS-56715): update the Deployment pod on change in imageStream [#15091](https://github.com/openshift/console/pull/15091)
* [OCPBUGS-56472](https://issues.redhat.com/browse/OCPBUGS-56472): Remove the devconsole backend common internet proxy and replace it with dedicated ones [#15072](https://github.com/openshift/console/pull/15072)
* [OCPBUGS-55378](https://issues.redhat.com/browse/OCPBUGS-55378): Do not load CSRs if user does not have permissions [#15000](https://github.com/openshift/console/pull/15000)
* [OCPBUGS-55644](https://issues.redhat.com/browse/OCPBUGS-55644): fix bug where operator appears twice [#15016](https://github.com/openshift/console/pull/15016)
* [OCPBUGS-45142](https://issues.redhat.com/browse/OCPBUGS-45142): Add missing pipelines plugin name to known plugins [#14550](https://github.com/openshift/console/pull/14550)
* [OCPBUGS-48628](https://issues.redhat.com/browse/OCPBUGS-48628): Added token to proxy header [#14693](https://github.com/openshift/console/pull/14693)
* [OCPBUGS-54174](https://issues.redhat.com/browse/OCPBUGS-54174): Update the monitoring topic used by the console team [#14900](https://github.com/openshift/console/pull/14900)
* [OCPBUGS-52450](https://issues.redhat.com/browse/OCPBUGS-52450): fix run time error when no completed version exists [#14840](https://github.com/openshift/console/pull/14840)
* [OCPBUGS-52851](https://issues.redhat.com/browse/OCPBUGS-52851): Show Observe section without PROMETHEUS and MONITORING flags [#14849](https://github.com/openshift/console/pull/14849)
* [OCPBUGS-52288](https://issues.redhat.com/browse/OCPBUGS-52288): While upgrading the cluster from UI observed `Warning alert:Admission Webhook Warning` [#14821](https://github.com/openshift/console/pull/14821)
* [OCPBUGS-49409](https://issues.redhat.com/browse/OCPBUGS-49409): ERROR in search tool: Cannot read properties of undefined (reading 'state') [#14703](https://github.com/openshift/console/pull/14703)
* [OCPBUGS-52418](https://issues.redhat.com/browse/OCPBUGS-52418): While accessing the node terminal from UI observed 'Warning alert:Admission Webhook Warning` [#14837](https://github.com/openshift/console/pull/14837)
* [OCPBUGS-49979](https://issues.redhat.com/browse/OCPBUGS-49979): Set default build option as BUILDS for Builder Image sample [#14730](https://github.com/openshift/console/pull/14730)
* [OCPBUGS-49800](https://issues.redhat.com/browse/OCPBUGS-49800): Fix Function Import: An error occurred Cannot read properties of undefined (reading 'filter') [#14715](https://github.com/openshift/console/pull/14715)
* [OCPBUGS-49801](https://issues.redhat.com/browse/OCPBUGS-49801): use default StorageClass for ServerlessFunction pipelineVolumeClaimTemplate [#14716](https://github.com/openshift/console/pull/14716)
* [OCPBUGS-46388](https://issues.redhat.com/browse/OCPBUGS-46388): fix alert rule link [#14808](https://github.com/openshift/console/pull/14808)
* [OCPBUGS-52252](https://issues.redhat.com/browse/OCPBUGS-52252): Fix alert rule link to alert in dev perspective [#14817](https://github.com/openshift/console/pull/14817)
* [OCPBUGS-46441](https://issues.redhat.com/browse/OCPBUGS-46441): Do not pass CSV name to operand list page when an exen… [#14627](https://github.com/openshift/console/pull/14627)
* [OCPBUGS-36963](https://issues.redhat.com/browse/OCPBUGS-36963): Manually create an API token for a ServiceAccount [#14057](https://github.com/openshift/console/pull/14057)
* [Full changelog](https://github.com/openshift/console/compare/ef16a1153b812d351b0e1aea835d76356b431a74...d50e2f0f098af842d8798033fcaed37ba84826ac)
### [console-operator](https://github.com/openshift/console-operator/tree/52a864c8aee7cbf431304b24d16e9d86f8a584f6)
* [OCPBUGS-77992](https://issues.redhat.com/browse/OCPBUGS-77992): update go mod dependency for konflux [#1115](https://github.com/openshift/console-operator/pull/1115)
* [OCPBUGS-60794](https://issues.redhat.com/browse/OCPBUGS-60794): Update downloads deployment configuration to use master node selector [#1036](https://github.com/openshift/console-operator/pull/1036)
* [Full changelog](https://github.com/openshift/console-operator/compare/2d0c5f37b3ff5a8a9876757d00ad42d7f673bab1...52a864c8aee7cbf431304b24d16e9d86f8a584f6)
### [container-networking-plugins, containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins/tree/b37e7f891eeff87fe5ae0a3ce8f7897933f525cb)
* [OCPBUGS-85669](https://issues.redhat.com/browse/OCPBUGS-85669): CI Build root image tag sync with ART [#234](https://github.com/openshift/containernetworking-plugins/pull/234)
* [OCPBUGS-55648](https://issues.redhat.com/browse/OCPBUGS-55648): Check error returned by ipv6 SettleAddresses [#188](https://github.com/openshift/containernetworking-plugins/pull/188)
* [Full changelog](https://github.com/openshift/containernetworking-plugins/compare/73b4123cc75abd22af8dc3b429836be2bea45fd5...b37e7f891eeff87fe5ae0a3ce8f7897933f525cb)
### [coredns](https://github.com/openshift/coredns/tree/6704e15689cbc58c40c2747d04a39a1d55104fef)
* [OCPBUGS-77463](https://issues.redhat.com/browse/OCPBUGS-77463): Modify .gitignore to not exclude vendor build folders [#168](https://github.com/openshift/coredns/pull/168)
* [Full changelog](https://github.com/openshift/coredns/compare/1e417656c1c72d3410b31ee08caf25bcdf8836e3...6704e15689cbc58c40c2747d04a39a1d55104fef)
### [csi-driver-manila, openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/9217d4a54f8308f7fea8d50d5c973cdcb6134a3c)
* [OCPBUGS-79978](https://issues.redhat.com/browse/OCPBUGS-79978): Bump google.golang.org/grpc [#389](https://github.com/openshift/cloud-provider-openstack/pull/389)
* [OCPBUGS-68080](https://issues.redhat.com/browse/OCPBUGS-68080): fix CVE-2025-65637 [#361](https://github.com/openshift/cloud-provider-openstack/pull/361)
* [OCPBUGS-58884](https://issues.redhat.com/browse/OCPBUGS-58884): CARRY: don't ignore json files [#341](https://github.com/openshift/cloud-provider-openstack/pull/341)
* [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/1d3aa2baae81b8c15260e87a816650b172c868f8...9217d4a54f8308f7fea8d50d5c973cdcb6134a3c)
### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/e1c714d2fa98555261d242f730b1a4f567fa53bf)
* [OCPBUGS-84931](https://issues.redhat.com/browse/OCPBUGS-84931): Replace google.golang.org/grpc with github.com/openshift-sustaining/grpc-go v1.67.3-sec.1 to avoid go version bump and fix CVE-2026-33186 [#182](https://github.com/openshift/csi-driver-nfs/pull/182)
* [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/406cec72a10684a7545a976a8c31e60712bcc5b2...e1c714d2fa98555261d242f730b1a4f567fa53bf)
### [csi-driver-shared-resource-operator](https://github.com/openshift/csi-driver-shared-resource-operator/tree/6ea4b3116010b80975a4fb71e5a64ed45cd37220)
* [OCPBUGS-102984](https://issues.redhat.com/browse/OCPBUGS-102984): Bump golang.org/x/net to v0.35.0-sec.3 [#128](https://github.com/openshift/csi-driver-shared-resource-operator/pull/128)
* [Full changelog](https://github.com/openshift/csi-driver-shared-resource-operator/compare/1e1194bc659a5c8cfbbfeedd9d9c15540ecda0d7...6ea4b3116010b80975a4fb71e5a64ed45cd37220)
### [csi-external-resizer](https://github.com/openshift/csi-external-resizer/tree/b0fd154a19f6c4917599d95305d32d7971af1592)
* [OCPBUGS-102985](https://issues.redhat.com/browse/OCPBUGS-102985): Bump golang.org/x/net to v0.35.0-sec.4 [#215](https://github.com/openshift/csi-external-resizer/pull/215)
* [OCPBUGS-62465](https://issues.redhat.com/browse/OCPBUGS-62465): Requeue PVC over PV creation [#174](https://github.com/openshift/csi-external-resizer/pull/174)
* [Full changelog](https://github.com/openshift/csi-external-resizer/compare/bdf5bfb4da07be6a85ae5253218f29fb8af51adf...b0fd154a19f6c4917599d95305d32d7971af1592)
### [csi-external-snapshotter, csi-snapshot-controller, csi-snapshot-validation-webhook](https://github.com/openshift/csi-external-snapshotter/tree/ee32ba01e1f89bac057611ad4580589652f250a3)
* [OCPBUGS-60450](https://issues.redhat.com/browse/OCPBUGS-60450): UPSTREAM: 1238: Snapshot Controller startup should not LIST all volumesnapshots [#186](https://github.com/openshift/csi-external-snapshotter/pull/186)
* [Full changelog](https://github.com/openshift/csi-external-snapshotter/compare/5315d37a1e5415e8b6870f23e50238681979cc28...ee32ba01e1f89bac057611ad4580589652f250a3)
### [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar/tree/d1a2105b2bacd60f02495cbe571960caf41a1830)
* [OCPBUGS-64632](https://issues.redhat.com/browse/OCPBUGS-64632): update log level verbosity to not clutter logs [#91](https://github.com/openshift/csi-node-driver-registrar/pull/91)
* [Full changelog](https://github.com/openshift/csi-node-driver-registrar/compare/8930c368500a5d1f15c3e1a5906397e206879de0...d1a2105b2bacd60f02495cbe571960caf41a1830)
### [docker-builder](https://github.com/openshift/builder/tree/1ad0db4517bd877ff36dfe48a704762a32688c7f)
* [OCPBUGS-89824](https://issues.redhat.com/browse/OCPBUGS-89824), [OCPBUGS-90269](https://issues.redhat.com/browse/OCPBUGS-90269), [OCPBUGS-92346](https://issues.redhat.com/browse/OCPBUGS-92346), [OCPBUGS-92576](https://issues.redhat.com/browse/OCPBUGS-92576), [OCPBUGS-92768](https://issues.redhat.com/browse/OCPBUGS-92768): Bump golang.org/x/crypto to fix CVE-2025-22869,CVE-2025-47913,CVE-2026-46597,CVE-2026-39829,CVE-2026-39832 [#553](https://github.com/openshift/builder/pull/553)
* [OCPBUGS-65907](https://issues.redhat.com/browse/OCPBUGS-65907): BuildConfig inline Dockerfile fails with heredoc syntax [#489](https://github.com/openshift/builder/pull/489)
* [OCPBUGS-58074](https://issues.redhat.com/browse/OCPBUGS-58074): S2I build cpu limits observed by assemble are limited to 1 cpu [#475](https://github.com/openshift/builder/pull/475)
* [OCPBUGS-53076](https://issues.redhat.com/browse/OCPBUGS-53076): Upgraded Kubernetes dependency from 1.28.2 to 1.29.0 [#468](https://github.com/openshift/builder/pull/468)
* [OCPBUGS-42893](https://issues.redhat.com/browse/OCPBUGS-42893), [OCPBUGS-42914](https://issues.redhat.com/browse/OCPBUGS-42914): buildah dependency bump to fix - Buildah allows arbitrary directory mount and symlink traversal vulnerability in the containers/storage library [#450](https://github.com/openshift/builder/pull/450)
* [Full changelog](https://github.com/openshift/builder/compare/300d9ad0370b0746bd526b304331675064214bc2...1ad0db4517bd877ff36dfe48a704762a32688c7f)
### [docker-registry](https://github.com/openshift/image-registry/tree/072c544c1eaab6d0e43fc63ab6c12c18bf524afb)
* [OCPBUGS-60183](https://issues.redhat.com/browse/OCPBUGS-60183): bump openshift/docker-distribution [#441](https://github.com/openshift/image-registry/pull/441)
* [OCPBUGS-53654](https://issues.redhat.com/browse/OCPBUGS-53654): bump jwt and oauth dependencies [#432](https://github.com/openshift/image-registry/pull/432)
* [Full changelog](https://github.com/openshift/image-registry/compare/a9eeeb94bc3276ce60a7166bc4e955c7f82c10e6...072c544c1eaab6d0e43fc63ab6c12c18bf524afb)
### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/9366599d967db2b09061fef6fb9297963a78d5e4)
* [OCPBUGS-78280](https://issues.redhat.com/browse/OCPBUGS-78280): [release-4.16] update go mod dependency for konflux [#267](https://github.com/openshift/cluster-api-provider-gcp/pull/267)
* [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/02432df87df9a731c8d630311854fbd515602e91...9366599d967db2b09061fef6fb9297963a78d5e4)
### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/7dc2012deda5ee6ad6a55a47e68a2b813ef36c3a)
* [OCPBUGS-103045](https://issues.redhat.com/browse/OCPBUGS-103045): Bump golang.org/x/net to v0.35.0-sec.3 [#191](https://github.com/openshift/machine-api-provider-gcp/pull/191)
* [OCPBUGS-79970](https://issues.redhat.com/browse/OCPBUGS-79970): Bump google.golang.org/grpc to v1.79.3 [#167](https://github.com/openshift/machine-api-provider-gcp/pull/167)
* [OCPBUGS-79970](https://issues.redhat.com/browse/OCPBUGS-79970): [release-4.16] Fix setup-envtest GCS 401 by downloading binaries directly [#176](https://github.com/openshift/machine-api-provider-gcp/pull/176)
* [OCPBUGS-55249](https://issues.redhat.com/browse/OCPBUGS-55249): Disable shielded VMs for non-UEFI disks [#116](https://github.com/openshift/machine-api-provider-gcp/pull/116)
* [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/380f339af123d187a24c4d6be972e18dd8308e6f...7dc2012deda5ee6ad6a55a47e68a2b813ef36c3a)
### [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver/tree/7d08d6facf2acfd6252f401bdbdb4425c059fdb9)
* [OCPBUGS-68087](https://issues.redhat.com/browse/OCPBUGS-68087): Update logrus to 1.9.3 [#92](https://github.com/openshift/gcp-pd-csi-driver/pull/92)
* [Full changelog](https://github.com/openshift/gcp-pd-csi-driver/compare/5ed71c64ce9c1879f0d2a17976387f1b0292796d...7d08d6facf2acfd6252f401bdbdb4425c059fdb9)
### [haproxy-router](https://github.com/openshift/router/tree/94888b69fccf33ebd6ef87fb21fbde1318f0c1e2)
* [OCPBUGS-86713](https://issues.redhat.com/browse/OCPBUGS-86713): Strip X-SSL-* headers for plain HTTP [#805](https://github.com/openshift/router/pull/805)
* [OCPBUGS-79960](https://issues.redhat.com/browse/OCPBUGS-79960): Bump google.golang.org/grpc to v1.79.3 [#769](https://github.com/openshift/router/pull/769)
* [OCPBUGS-56424](https://issues.redhat.com/browse/OCPBUGS-56424): Add support for IdleCloseTerminationPolicy [#655](https://github.com/openshift/router/pull/655)
* [OCPBUGS-49391](https://issues.redhat.com/browse/OCPBUGS-49391): Reject All CA-Signed Certs Using SHA1 [#651](https://github.com/openshift/router/pull/651)
* [Full changelog](https://github.com/openshift/router/compare/4d9b8c4afa6cd89b41f4bd5e7c09ccddd8679bc6...94888b69fccf33ebd6ef87fb21fbde1318f0c1e2)
### [hyperkube, pod](https://github.com/openshift/kubernetes/tree/41c4e9ba94f4f1bfece6b81f287a9e3cf63e79cd)
* [OCPBUGS-68041](https://issues.redhat.com/browse/OCPBUGS-68041), [OCPBUGS-68091](https://issues.redhat.com/browse/OCPBUGS-68091): CVE-2025-65637 - bump github.com/sirupsen/logrus to v1.9.3 [4.16] [#2582](https://github.com/openshift/kubernetes/pull/2582)
* [OCPBUGS-74299](https://issues.redhat.com/browse/OCPBUGS-74299): Skip E2e: attach on previously attached volumes should work [#2568](https://github.com/openshift/kubernetes/pull/2568)
* [OCPBUGS-65694](https://issues.redhat.com/browse/OCPBUGS-65694): Fix Concurrentmap Iteration [#2519](https://github.com/openshift/kubernetes/pull/2519)
* [CNTRLPLANE-1612](https://issues.redhat.com/browse/CNTRLPLANE-1612): Backport StreamingCollectionEncoding for JSON and protobuf [#2485](https://github.com/openshift/kubernetes/pull/2485)
* [OCPBUGS-61908](https://issues.redhat.com/browse/OCPBUGS-61908): UPSTREAM: <carry>: Don't retry storage calls with side effects. [#2470](https://github.com/openshift/kubernetes/pull/2470)
* [OCPBUGS-60553](https://issues.redhat.com/browse/OCPBUGS-60553): [4.16]: podresources: list: use active pods [#2454](https://github.com/openshift/kubernetes/pull/2454)
* 4.16: OCPBUGS-60872: UPSTREAM: 127757: scheduler: Improve CSILimits plugin accuracy by using VolumeAttachments [#2435](https://github.com/openshift/kubernetes/pull/2435)
* [OCPBUGS-60272](https://issues.redhat.com/browse/OCPBUGS-60272): Bump nfs server provisioner [#2402](https://github.com/openshift/kubernetes/pull/2402)
* [OCPBUGS-58054](https://issues.redhat.com/browse/OCPBUGS-58054): UPSTREAM: 130047: adjusting loopback certificate validity in kube-apiserver [#2342](https://github.com/openshift/kubernetes/pull/2342)
* [OCPBUGS-58054](https://issues.redhat.com/browse/OCPBUGS-58054): UPSTREAM: <carry>: disable some legacy cloud provider Azure tests [#2352](https://github.com/openshift/kubernetes/pull/2352)
* [OCPBUGS-57290](https://issues.redhat.com/browse/OCPBUGS-57290): UPSTREAM: <carry>: Bump cadvisor version to fix kubelet [#2325](https://github.com/openshift/kubernetes/pull/2325)
* [OCPBUGS-49906](https://issues.redhat.com/browse/OCPBUGS-49906): Bump k8s api to 1.29.14 [#2211](https://github.com/openshift/kubernetes/pull/2211)
* [Full changelog](https://github.com/openshift/kubernetes/compare/148a3899faa172900675334f74463f0f87af6594...41c4e9ba94f4f1bfece6b81f287a9e3cf63e79cd)
### [hypershift](https://github.com/openshift/hypershift/tree/0cf73de550ccb27d3d12580fae146f329e7be19a)
* [OCPBUGS-120748](https://issues.redhat.com/browse/OCPBUGS-120748): update Containerfile.cli base images to floating tags [release-4.16] [#9560](https://github.com/openshift/hypershift/pull/9560)
* [OCPBUGS-99075](https://issues.redhat.com/browse/OCPBUGS-99075): fix(backport): konnectivity agent auth [#9097](https://github.com/openshift/hypershift/pull/9097)
* [OCPBUGS-84182](https://issues.redhat.com/browse/OCPBUGS-84182): fix(cno): use brackets only for IPv6 in server URL [#8348](https://github.com/openshift/hypershift/pull/8348)
* [OCPBUGS-76534](https://issues.redhat.com/browse/OCPBUGS-76534): feat(updates): enable CVO metrics access with RHOBS monitoring flag [#7704](https://github.com/openshift/hypershift/pull/7704)
* [OCPBUGS-74375](https://issues.redhat.com/browse/OCPBUGS-74375), [OCPBUGS-74376](https://issues.redhat.com/browse/OCPBUGS-74376): Support proxy authentication when user/pass is included in URL [#7578](https://github.com/openshift/hypershift/pull/7578)
* [OCPBUGS-73118](https://issues.redhat.com/browse/OCPBUGS-73118): Fix Konflux EC voilation, update deprecated base … [#7459](https://github.com/openshift/hypershift/pull/7459)
* [OCPBUGS-63640](https://issues.redhat.com/browse/OCPBUGS-63640): [release-4.16] fix(konnectivity): resolve circular dependency causing DNS timeouts and excessive retries [#7113](https://github.com/openshift/hypershift/pull/7113)
* [OCPBUGS-64680](https://issues.redhat.com/browse/OCPBUGS-64680): Update DNS names for ovn-kubernetes cp metrics [#7158](https://github.com/openshift/hypershift/pull/7158)
* [CNTRLPLANE-1904](https://issues.redhat.com/browse/CNTRLPLANE-1904): Migrate 4.16 pipelines to common pipeline template [#7212](https://github.com/openshift/hypershift/pull/7212)
* [CNTRLPLANE-1426](https://issues.redhat.com/browse/CNTRLPLANE-1426): feat(konflux): tag MCE HO images with latest [#6839](https://github.com/openshift/hypershift/pull/6839)
* [OCPBUGS-61252](https://issues.redhat.com/browse/OCPBUGS-61252): dont use registryOverrides on kube rbac proxy image be… [#6756](https://github.com/openshift/hypershift/pull/6756)
* [OCPBUGS-61582](https://issues.redhat.com/browse/OCPBUGS-61582): Update KCM node monitor grace period [#6797](https://github.com/openshift/hypershift/pull/6797)
* [OCPBUGS-61860](https://issues.redhat.com/browse/OCPBUGS-61860): Use the common MCE konflux pipeline [#6844](https://github.com/openshift/hypershift/pull/6844)
* [OCPBUGS-60150](https://issues.redhat.com/browse/OCPBUGS-60150): Always compress and encode payload in token secret for inplace upgrades [#6750](https://github.com/openshift/hypershift/pull/6750)
* [OCPBUGS-60951](https://issues.redhat.com/browse/OCPBUGS-60951): MCE 2.6 konflux hcp cli [#6701](https://github.com/openshift/hypershift/pull/6701)
* [CNTRLPLANE-1203](https://issues.redhat.com/browse/CNTRLPLANE-1203): HO MCE change to hermetic ta build [#6654](https://github.com/openshift/hypershift/pull/6654)
* [CNTRLPLANE-1231](https://issues.redhat.com/browse/CNTRLPLANE-1231): Move CPO pipeline to hermetic builds [#6599](https://github.com/openshift/hypershift/pull/6599)
* [OCPBUGS-58505](https://issues.redhat.com/browse/OCPBUGS-58505): [release-4.16] Add missing service network DNS entries to KAS cert [#6393](https://github.com/openshift/hypershift/pull/6393)
* [OCPBUGS-57494](https://issues.redhat.com/browse/OCPBUGS-57494): Add proxy variables for the MCD Pod [#6286](https://github.com/openshift/hypershift/pull/6286)
* [OCPBUGS-55697](https://issues.redhat.com/browse/OCPBUGS-55697): Add validation to avoid conflicts between KubeAPIServer and NamedCertificates SANs [#6114](https://github.com/openshift/hypershift/pull/6114)
* [CNTRLPLANE-919](https://issues.redhat.com/browse/CNTRLPLANE-919): Konflux build pipeline service account migration [#6087](https://github.com/openshift/hypershift/pull/6087)
* [CNTRLPLANE-919](https://issues.redhat.com/browse/CNTRLPLANE-919): Konflux build pipeline service account migration [#6082](https://github.com/openshift/hypershift/pull/6082)
* [OCPBUGS-51804](https://issues.redhat.com/browse/OCPBUGS-51804): Fix golang crypto dependency go.mod replacement [#5994](https://github.com/openshift/hypershift/pull/5994)
* [OCPBUGS-54914](https://issues.redhat.com/browse/OCPBUGS-54914): Add konnectivity-proxy sidecar to openshift-oauth-apiserver [#6026](https://github.com/openshift/hypershift/pull/6026)
* [OCPBUGS-54632](https://issues.redhat.com/browse/OCPBUGS-54632): Sync RBAC for attaching volumes on VM level [#5998](https://github.com/openshift/hypershift/pull/5998)
* [OCPBUGS-49914](https://issues.redhat.com/browse/OCPBUGS-49914): Reconcile proxy CA bundle into hosted cluster [#5983](https://github.com/openshift/hypershift/pull/5983)
* [OCPBUGS-53902](https://issues.redhat.com/browse/OCPBUGS-53902): bump golang-jwt v4 and v5 [#5907](https://github.com/openshift/hypershift/pull/5907)
* Red Hat Konflux update control-plane-operator-4-16 [#5957](https://github.com/openshift/hypershift/pull/5957)
* [ART-11792](https://issues.redhat.com/browse/ART-11792): update go mod dependency for konflux [#5922](https://github.com/openshift/hypershift/pull/5922)
* [OCPBUGS-51733](https://issues.redhat.com/browse/OCPBUGS-51733), [OCPBUGS-51804](https://issues.redhat.com/browse/OCPBUGS-51804): Bump dependencies to OCP fork in backports [#5901](https://github.com/openshift/hypershift/pull/5901)
* [OCPBUGS-53308](https://issues.redhat.com/browse/OCPBUGS-53308): fix(deps): bump go-jose [#5866](https://github.com/openshift/hypershift/pull/5866)
* [OCPBUGS-52506](https://issues.redhat.com/browse/OCPBUGS-52506): refactor aws identity health check into new controller [#5781](https://github.com/openshift/hypershift/pull/5781)
* [OCPBUGS-52857](https://issues.redhat.com/browse/OCPBUGS-52857): Make managed-trust-bundle optional [#5809](https://github.com/openshift/hypershift/pull/5809)
* [OCPBUGS-52426](https://issues.redhat.com/browse/OCPBUGS-52426): change plaform to platform [#5773](https://github.com/openshift/hypershift/pull/5773)
* [OCPBUGS-50993](https://issues.redhat.com/browse/OCPBUGS-50993): Honor proxy vars in the util insecure http client [#5662](https://github.com/openshift/hypershift/pull/5662)
* [OCPBUGS-46466](https://issues.redhat.com/browse/OCPBUGS-46466): Consistently look up and dial cloud API hostnames [#5301](https://github.com/openshift/hypershift/pull/5301)
* [OCPBUGS-50698](https://issues.redhat.com/browse/OCPBUGS-50698): add region to AWS creds passed to operators managed by CPO [#5670](https://github.com/openshift/hypershift/pull/5670)
* [OCPBUGS-51296](https://issues.redhat.com/browse/OCPBUGS-51296): 4.17 Add HostedCluster additional trustbundles to konnectivity-https-proxy [#5707](https://github.com/openshift/hypershift/pull/5707)
* NO-JIRA: chore(deps): update dependency mkdocs-material to v9.6.5 [#5686](https://github.com/openshift/hypershift/pull/5686)
* [OCPBUGS-50694](https://issues.redhat.com/browse/OCPBUGS-50694): OCPBUGS-50692: Fix IsIPv4 function identifying also addresses instead of CIDRs [#5620](https://github.com/openshift/hypershift/pull/5620)
* [Full changelog](https://github.com/openshift/hypershift/compare/67b0bb8b5f45f72a6012d3757bb4ff963bb26719...0cf73de550ccb27d3d12580fae146f329e7be19a)
### [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver/tree/eb7b9c09f81b2e9a78bfa75d57cd4eab37989b52)
* [OCPBUGS-79964](https://issues.redhat.com/browse/OCPBUGS-79964): Bump google.golang.org/grpc to v1.79.3 [#145](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/145)
* [OCPBUGS-77210](https://issues.redhat.com/browse/OCPBUGS-77210): [release-4.16] standardize build paths [#124](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/124)
* [OCPBUGS-58737](https://issues.redhat.com/browse/OCPBUGS-58737): bump github.com/golang/glog to version v1.2.4 [#106](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/106)
* [OCPBUGS-56063](https://issues.redhat.com/browse/OCPBUGS-56063): tech debt: rework vendor patches [#91](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/91)
* [OCPBUGS-53910](https://issues.redhat.com/browse/OCPBUGS-53910): bump github.com/golang-jwt/jwt/v4 to v4.5.2 [#84](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/84)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver/compare/957197389ec49234c3883bbb730bb630b459e24f...eb7b9c09f81b2e9a78bfa75d57cd4eab37989b52)
### [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/tree/9ca537683fc2ae2e7847032441fde42ff3171a48)
* [OCPBUGS-59727](https://issues.redhat.com/browse/OCPBUGS-59727): [IBM VPC] set offlineExpansion to false in e2e test manifest [#149](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/149)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/compare/5d5d8010a59916cc264d0ab14962be85a35b7228...9ca537683fc2ae2e7847032441fde42ff3171a48)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/509d38bce1d5b272b3ddac09e28f77270d688f92)
* [OCPBUGS-103009](https://issues.redhat.com/browse/OCPBUGS-103009): Replace golang.org/x/net with openshift-sustaining/net [#170](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/170)
* [OCPBUGS-115544](https://issues.redhat.com/browse/OCPBUGS-115544): Fetch envtest assets from the controller-tools releases [#181](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/181)
* [OCPBUGS-67288](https://issues.redhat.com/browse/OCPBUGS-67288): [release-4.16] Fix incomplete vendor/ [#138](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/138)
* [OCPBUGS-51818](https://issues.redhat.com/browse/OCPBUGS-51818): CVE-2025-22869 Update golang.org/x/crypto to patched OpenShift fork [#109](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/109)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/7d4f93efe65a7c070ded6b889b61ae3d51e259fb...509d38bce1d5b272b3ddac09e28f77270d688f92)
### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/aabc3a7fdf353d651289f16c65af1660530f677f)
* [OCPBUGS-103003](https://issues.redhat.com/browse/OCPBUGS-103003): replace golang.org/x/net with openshift-sustaining/net v0.35.0-sec.4 [#106](https://github.com/openshift/machine-api-provider-ibmcloud/pull/106)
* NO-JIRA: fix unit tests broken by deprecated kubebuilder-tools bucket [#113](https://github.com/openshift/machine-api-provider-ibmcloud/pull/113)
* [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/d29506e7fea609bc8f004256c9c057e5429f72a1...aabc3a7fdf353d651289f16c65af1660530f677f)
### [insights-operator](https://github.com/openshift/insights-operator/tree/a06a980f229864e7e5894416f2583e03f4b03fcd)
* [OCPBUGS-68370](https://issues.redhat.com/browse/OCPBUGS-68370): Add filtering to add other possible pod status to QEMU gatherer [#1200](https://github.com/openshift/insights-operator/pull/1200)
* [OCPBUGS-67009](https://issues.redhat.com/browse/OCPBUGS-67009): QEMU logs are not gathered if there are pending status virt-launcher pods [#1197](https://github.com/openshift/insights-operator/pull/1197)
* And 5 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/insights-operator/compare/80aaae316ad37023a112db855525c0e7bf18db74...a06a980f229864e7e5894416f2583e03f4b03fcd)
### [ironic](https://github.com/openshift/ironic-image/tree/2cdb8c3b0d533f223e8d6728f20af9642d83697d)
* [OCPBUGS-85333](https://issues.redhat.com/browse/OCPBUGS-85333): update ironic-image commit hash to address CVE-2026-43003 [#912](https://github.com/openshift/ironic-image/pull/912)
* [OCPBUGS-100162](https://issues.redhat.com/browse/OCPBUGS-100162): bump openstack-ironic pin for CVE-2026-44918 fix [#908](https://github.com/openshift/ironic-image/pull/908)
* [OCPBUGS-104459](https://issues.redhat.com/browse/OCPBUGS-104459): bump openstack-ironic pin for CVE-2026-54423 fix(release-4.16) [#877](https://github.com/openshift/ironic-image/pull/877)
* [OCPBUGS-76457](https://issues.redhat.com/browse/OCPBUGS-76457): Bump pyasn1 to 0.5.1-4 [#828](https://github.com/openshift/ironic-image/pull/828)
* [OCPBUGS-69789](https://issues.redhat.com/browse/OCPBUGS-69789): Bump eventlet version to 0.33.1-7 [#763](https://github.com/openshift/ironic-image/pull/763)
* [METAL-1306](https://issues.redhat.com/browse/METAL-1306): Do not use openstack packages [#648](https://github.com/openshift/ironic-image/pull/648)
* [Full changelog](https://github.com/openshift/ironic-image/compare/ca45bd4c13d6e6bda4808439d4e76dccee26079e...2cdb8c3b0d533f223e8d6728f20af9642d83697d)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/eff76836721d2b4b507ff2ba33ff61b389c9b57c)
* [OCPBUGS-85333](https://issues.redhat.com/browse/OCPBUGS-85333): Update ironic-python-agent commit hash to address CVE-2026-43003 [#316](https://github.com/openshift/ironic-agent-image/pull/316)
* [OCPBUGS-99890](https://issues.redhat.com/browse/OCPBUGS-99890): Bump ironic-python-agent pinned commit for CVE-2026-66138 [#310](https://github.com/openshift/ironic-agent-image/pull/310)
* [OCPBUGS-95070](https://issues.redhat.com/browse/OCPBUGS-95070): Replace individual package removal with a single rpm -e loop [#288](https://github.com/openshift/ironic-agent-image/pull/288)
* [OCPBUGS-95070](https://issues.redhat.com/browse/OCPBUGS-95070): Replace dnf remove with rpm -e to prevent dependency removal [#276](https://github.com/openshift/ironic-agent-image/pull/276)
* [OCPBUGS-61165](https://issues.redhat.com/browse/OCPBUGS-61165): netutils: Use ethtool ioctl to get permanent mac address [#215](https://github.com/openshift/ironic-agent-image/pull/215)
* [OCPBUGS-69781](https://issues.redhat.com/browse/OCPBUGS-69781): Bump eventlet version to 0.33.1-7 [#232](https://github.com/openshift/ironic-agent-image/pull/232)
* [METAL-1306](https://issues.redhat.com/browse/METAL-1306): Do not use openstack packages [#180](https://github.com/openshift/ironic-agent-image/pull/180)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/3c5298e05497b59a876c73c51359f49f3cc2cb99...eff76836721d2b4b507ff2ba33ff61b389c9b57c)
### [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server/tree/4659393c07e7c262c582d13461e60465c40d0e43)
* NO-ISSUE: synchronize OWNERS from main branch [release-4.16] [#85](https://github.com/openshift/kubernetes-metrics-server/pull/85)
* [OCPBUGS-79929](https://issues.redhat.com/browse/OCPBUGS-79929): Bump google.golang.org/grpc to v1.79.3 [#66](https://github.com/openshift/kubernetes-metrics-server/pull/66)
* [Full changelog](https://github.com/openshift/kubernetes-metrics-server/compare/9116b918b6b9c2336fcbbf6c7c78c2e28fa2714a...4659393c07e7c262c582d13461e60465c40d0e43)
### [kube-proxy, sdn](https://github.com/openshift/sdn/tree/53fea06bf50bdeff168cdf1ca3f5e19375c56f02)
* [OCPBUGS-54457](https://issues.redhat.com/browse/OCPBUGS-54457): Drop SYNACK as well in MCS side [#658](https://github.com/openshift/sdn/pull/658)
* [OCPBUGS-44674](https://issues.redhat.com/browse/OCPBUGS-44674): Handle `openshift-host-network` namespace as special when it modifies [#648](https://github.com/openshift/sdn/pull/648)
* [Full changelog](https://github.com/openshift/sdn/compare/e5c0eb43e18810d1b0b4491164fe3305f18fec1e...53fea06bf50bdeff168cdf1ca3f5e19375c56f02)
### [kube-state-metrics](https://github.com/openshift/kube-state-metrics/tree/7861a865875eaa2b5ce956f842fd2b3bb588192a)
* [OCPBUGS-74875](https://issues.redhat.com/browse/OCPBUGS-74875): Deduplicate CRS stores [#133](https://github.com/openshift/kube-state-metrics/pull/133)
* [Full changelog](https://github.com/openshift/kube-state-metrics/compare/9b67b8d1adbd63e27b622b3d050e0673766a6f2d...7861a865875eaa2b5ce956f842fd2b3bb588192a)
### [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator/tree/6f2133209d90d822e79d679ed483eeb755ceaaf8)
* NO-JIRA: Add DOWNSTREAM_OWNERS (release 4-16). [#227](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/227)
* [Full changelog](https://github.com/openshift/kubernetes-kube-storage-version-migrator/compare/969a60e9e2466c44f5b3ffd43fe3ecab11bf1e51...6f2133209d90d822e79d679ed483eeb755ceaaf8)
### [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt/tree/f331bdbaf28fd6249d83e46bacd926c0c395e1ff)
* [OCPBUGS-95082](https://issues.redhat.com/browse/OCPBUGS-95082): OWNERS: Update component to Cloud Compute / KubeVirt Provider [#82](https://github.com/openshift/cloud-provider-kubevirt/pull/82)
* [Full changelog](https://github.com/openshift/cloud-provider-kubevirt/compare/3db76104a38bd9160ca24e2ed4a33649843f210a...f331bdbaf28fd6249d83e46bacd926c0c395e1ff)
### [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver/tree/0a4bf7557b991e554df1613473f1d7e700ab5a6f)
* [OCPBUGS-79930](https://issues.redhat.com/browse/OCPBUGS-79930): Bump google.golang.org/grpc to v1.79.3 [#108](https://github.com/openshift/kubevirt-csi-driver/pull/108)
* [OCPBUGS-54632](https://issues.redhat.com/browse/OCPBUGS-54632): Ensure volume stays attached through reboots [#57](https://github.com/openshift/kubevirt-csi-driver/pull/57)
* [OCPBUGS-44622](https://issues.redhat.com/browse/OCPBUGS-44622): During detach don't return error if VM is not found [#49](https://github.com/openshift/kubevirt-csi-driver/pull/49)
* [Full changelog](https://github.com/openshift/kubevirt-csi-driver/compare/0693093f773c5046e231f174e7930315feabd996...0a4bf7557b991e554df1613473f1d7e700ab5a6f)
### [libvirt-machine-controllers](https://github.com/openshift/cluster-api-provider-libvirt/tree/0e11df99c202c12d1d58dd6e46d3e6d50b2ad252)
* [OCPBUGS-77196](https://issues.redhat.com/browse/OCPBUGS-77196): Fix incomplete vendor/ [#302](https://github.com/openshift/cluster-api-provider-libvirt/pull/302)
* [OCPBUGS-26525](https://issues.redhat.com/browse/OCPBUGS-26525): Updating ose-libvirt-machine-controllers-container image to be consistent with ART for 4.16 [#283](https://github.com/openshift/cluster-api-provider-libvirt/pull/283)
* [Full changelog](https://github.com/openshift/cluster-api-provider-libvirt/compare/a336f0b5f7ee99c418aaab3d511707bd0064bd56...0e11df99c202c12d1d58dd6e46d3e6d50b2ad252)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/77f20f3ab94f7cd55555d7ef58134505ec24e8cd)
* [OCPBUGS-98439](https://issues.redhat.com/browse/OCPBUGS-98439): Use resource group when generating default Azure image [#1516](https://github.com/openshift/machine-api-operator/pull/1516)
* [OCPBUGS-76849](https://issues.redhat.com/browse/OCPBUGS-76849): bumped logrus to v1.9.3 [#1463](https://github.com/openshift/machine-api-operator/pull/1463)
* [OCPBUGS-57210](https://issues.redhat.com/browse/OCPBUGS-57210): Updates GCP CredentialsRequest [#1378](https://github.com/openshift/machine-api-operator/pull/1378)
* [OCPBUGS-55248](https://issues.redhat.com/browse/OCPBUGS-55248), [OCPBUGS-55249](https://issues.redhat.com/browse/OCPBUGS-55249): Updates GCP credentials request [#1355](https://github.com/openshift/machine-api-operator/pull/1355)
* [OCPBUGS-53045](https://issues.redhat.com/browse/OCPBUGS-53045): add image/read permissions [#1348](https://github.com/openshift/machine-api-operator/pull/1348)
* [OCPBUGS-52342](https://issues.redhat.com/browse/OCPBUGS-52342): Drop oVirt support [#1336](https://github.com/openshift/machine-api-operator/pull/1336)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/ac37878bf75e8b7ee850976663ef6eb61045195a...77f20f3ab94f7cd55555d7ef58134505ec24e8cd)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/7327bb2359dd01f5b98c6bc3bd43ae134b080d02)
* [OCPBUGS-98960](https://issues.redhat.com/browse/OCPBUGS-98960): Remove sensitive ControllerConfig logging [#6315](https://github.com/openshift/machine-config-operator/pull/6315)
* [OCPBUGS-98253](https://issues.redhat.com/browse/OCPBUGS-98253): Bootstrap MCS logging entire ignition [#6290](https://github.com/openshift/machine-config-operator/pull/6290)
* [OCPBUGS-62171](https://issues.redhat.com/browse/OCPBUGS-62171): Fix - NetworkManager restart or crash renders br-ex unusable [#5354](https://github.com/openshift/machine-config-operator/pull/5354)
* [OCPBUGS-60113](https://issues.redhat.com/browse/OCPBUGS-60113): Enable debug logging for nodeip-configuration [#5218](https://github.com/openshift/machine-config-operator/pull/5218)
* [OCPBUGS-77253](https://issues.redhat.com/browse/OCPBUGS-77253): Machine-config controller should not log about non-existent pull-secret changes [#5694](https://github.com/openshift/machine-config-operator/pull/5694)
* [OCPBUGS-77184](https://issues.redhat.com/browse/OCPBUGS-77184): machine-config-daemon: openshift: Exposure of Sensitive Data in Log Files in the Machine Configuration Daemon. [openshift-4] [#5685](https://github.com/openshift/machine-config-operator/pull/5685)
* [OCPBUGS-63155](https://issues.redhat.com/browse/OCPBUGS-63155): [release-4.16] Networking: reset ovn-remote config and allow ovnkube controller to set it [#5359](https://github.com/openshift/machine-config-operator/pull/5359)
* [OCPBUGS-60773](https://issues.redhat.com/browse/OCPBUGS-60773): scope MCD node listers to current node [#5260](https://github.com/openshift/machine-config-operator/pull/5260)
* [OCPBUGS-63553](https://issues.redhat.com/browse/OCPBUGS-63553): Add control-plane label for master nodes on legacy clusters [#5376](https://github.com/openshift/machine-config-operator/pull/5376)
* [OCPBUGS-57423](https://issues.redhat.com/browse/OCPBUGS-57423): pkg/operator/status: Drop PoolUpdating as an Upgradeable=False condition [#5119](https://github.com/openshift/machine-config-operator/pull/5119)
* [OCPBUGS-63332](https://issues.redhat.com/browse/OCPBUGS-63332): Recheck generatedByControllerVersion annotation prior to deleting a degraded MC [#5364](https://github.com/openshift/machine-config-operator/pull/5364)
* [OCPBUGS-56753](https://issues.redhat.com/browse/OCPBUGS-56753): Support NODEIP_HINT in IPI deployments too [#5079](https://github.com/openshift/machine-config-operator/pull/5079)
* [OCPBUGS-62689](https://issues.redhat.com/browse/OCPBUGS-62689): Add mcd_local_unsupported_packages recording rule [#5328](https://github.com/openshift/machine-config-operator/pull/5328)
* [OCPBUGS-59931](https://issues.redhat.com/browse/OCPBUGS-59931), [OPNET-681](https://issues.redhat.com/browse/OPNET-681): Support migration to NMState [#5205](https://github.com/openshift/machine-config-operator/pull/5205)
* [OCPBUGS-61869](https://issues.redhat.com/browse/OCPBUGS-61869): Override NMState service definition [#5290](https://github.com/openshift/machine-config-operator/pull/5290)
* [OCPBUGS-60621](https://issues.redhat.com/browse/OCPBUGS-60621): Add workaround fix for static pod race [#5252](https://github.com/openshift/machine-config-operator/pull/5252)
* [OCPBUGS-56558](https://issues.redhat.com/browse/OCPBUGS-56558): Log CRC MC deletion [#5178](https://github.com/openshift/machine-config-operator/pull/5178)
* [OCPBUGS-58270](https://issues.redhat.com/browse/OCPBUGS-58270): Do not set cpu system reserve below the default value [#5163](https://github.com/openshift/machine-config-operator/pull/5163)
* add missing vendors [#4952](https://github.com/openshift/machine-config-operator/pull/4952)
* [OCPBUGS-48283](https://issues.redhat.com/browse/OCPBUGS-48283): Do not run resolv-prepender from NM dispatcher [#4784](https://github.com/openshift/machine-config-operator/pull/4784)
* [OCPBUGS-56868](https://issues.redhat.com/browse/OCPBUGS-56868): daemon: fix ostree-finalize-staged race workaround for package mode RHEL workers [#5090](https://github.com/openshift/machine-config-operator/pull/5090)
* [OCPBUGS-56626](https://issues.redhat.com/browse/OCPBUGS-56626): error from generateAndValidateRenderedMachineConfig function can be misleading [#5075](https://github.com/openshift/machine-config-operator/pull/5075)
* [OCPBUGS-54831](https://issues.redhat.com/browse/OCPBUGS-54831): Make mtu-migration run after wait-for-primary-ip [#4990](https://github.com/openshift/machine-config-operator/pull/4990)
* [OCPBUGS-55684](https://issues.redhat.com/browse/OCPBUGS-55684): MSBIC should not update windows machinesets [#5028](https://github.com/openshift/machine-config-operator/pull/5028)
* [OCPBUGS-35921](https://issues.redhat.com/browse/OCPBUGS-35921): userCA and cloudCA certfiicates are not removed from nodes and ignition config [#4419](https://github.com/openshift/machine-config-operator/pull/4419)
* [OCPBUGS-53248](https://issues.redhat.com/browse/OCPBUGS-53248): Enforce VIPs to be collocated at the same host [#4923](https://github.com/openshift/machine-config-operator/pull/4923)
* [OCPBUGS-53043](https://issues.redhat.com/browse/OCPBUGS-53043): Enable nmstate-configuration on all platforms [#4910](https://github.com/openshift/machine-config-operator/pull/4910)
* [OCPBUGS-52952](https://issues.redhat.com/browse/OCPBUGS-52952): Add ipsec connect wait service [#4931](https://github.com/openshift/machine-config-operator/pull/4931)
* [OCPBUGS-54163](https://issues.redhat.com/browse/OCPBUGS-54163): Fixing typos for MachineConfigNode [#4942](https://github.com/openshift/machine-config-operator/pull/4942)
* [OCPBUGS-53434](https://issues.redhat.com/browse/OCPBUGS-53434): Update ObservedGeneration in KubeletConfig [#4935](https://github.com/openshift/machine-config-operator/pull/4935)
* [OCPBUGS-53313](https://issues.redhat.com/browse/OCPBUGS-53313): daemon: ensure ostree-finalize-staged is started before rebooting [#4928](https://github.com/openshift/machine-config-operator/pull/4928)
* [OCPBUGS-52421](https://issues.redhat.com/browse/OCPBUGS-52421): Update format verbs for alert logs [#4901](https://github.com/openshift/machine-config-operator/pull/4901)
* [OCPBUGS-51347](https://issues.redhat.com/browse/OCPBUGS-51347): Update the storage.conf configuration file template [#4881](https://github.com/openshift/machine-config-operator/pull/4881)
* [OCPBUGS-52593](https://issues.redhat.com/browse/OCPBUGS-52593): Update cluster-reader ClusterRole permissions [#4905](https://github.com/openshift/machine-config-operator/pull/4905)
* [OCPBUGS-52404](https://issues.redhat.com/browse/OCPBUGS-52404): create /run/nodeip-configuration before use [#4897](https://github.com/openshift/machine-config-operator/pull/4897)
* [OCPBUGS-52310](https://issues.redhat.com/browse/OCPBUGS-52310): configure-ovs workaround for ovs-if-br-ex bug [#4892](https://github.com/openshift/machine-config-operator/pull/4892)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/4da8e68d757e78574fa3ca9ab6b0552fc9111e66...7327bb2359dd01f5b98c6bc3bd43ae134b080d02)
### [machine-image-customization-controller](https://github.com/openshift/image-customization-controller/tree/5460f7c3af5d8f6e63bff592373141bf23a3d192)
* [OCPBUGS-68093](https://issues.redhat.com/browse/OCPBUGS-68093): [4.16] uplift logrus [#153](https://github.com/openshift/image-customization-controller/pull/153)
* [Full changelog](https://github.com/openshift/image-customization-controller/compare/394809633b6b2e33ea1af444f7237f066bf0abb1...5460f7c3af5d8f6e63bff592373141bf23a3d192)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/4a52a4593fea1b939142add3dd7e9e5c7a06f880)
* [OCPBUGS-87878](https://issues.redhat.com/browse/OCPBUGS-87878): Add support for hermetic builds via Cachi2 prefetched CoreOS ISOs [#102](https://github.com/openshift/machine-os-images/pull/102)
* [OCPBUGS-54169](https://issues.redhat.com/browse/OCPBUGS-54169): Change rhcos release browser url [#57](https://github.com/openshift/machine-os-images/pull/57)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/3cc97098ecb9870dcb571f1ed1e26e2f70ce9f8c...4a52a4593fea1b939142add3dd7e9e5c7a06f880)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/51ee4ad7f484c6bfed068296d98dceea7a12c8ae)
* NO-JIRA: [release-4.16] Sanitize alert runbook URLs [#1292](https://github.com/openshift/monitoring-plugin/pull/1292)
* Fix for OCPBUGS-113514: CVE-2026-18446 [#1184](https://github.com/openshift/monitoring-plugin/pull/1184)
* Fix for OCPBUGS-94001: CVE-2026-13676 [#1049](https://github.com/openshift/monitoring-plugin/pull/1049)
* Fix for OCPBUGS-90069 OCPBUGS-90073: CVE-2026-12151 CVE-2026-9697 [#1007](https://github.com/openshift/monitoring-plugin/pull/1007)
* [OCPBUGS-79441](https://issues.redhat.com/browse/OCPBUGS-79441): immutable bump [#898](https://github.com/openshift/monitoring-plugin/pull/898)
* [OU-1260](https://issues.redhat.com/browse/OU-1260): [release-4.16] feat: use npm instead of yarn [#813](https://github.com/openshift/monitoring-plugin/pull/813)
* [OCPBUGS-76807](https://issues.redhat.com/browse/OCPBUGS-76807): fix for CVE-2025-69873 [#849](https://github.com/openshift/monitoring-plugin/pull/849)
* [OCPBUGS-54316](https://issues.redhat.com/browse/OCPBUGS-54316): Fix "Export as CSV" [#469](https://github.com/openshift/monitoring-plugin/pull/469)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/fcd3a8cc6a5d5fcce5222a29c8de09fa04d8fc24...51ee4ad7f484c6bfed068296d98dceea7a12c8ae)
### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/a15bf454ad4446cefdb708ea3f121d08a0df83ee)
* [OCPBUGS-58767](https://issues.redhat.com/browse/OCPBUGS-58767): Update the github.com/golang/glog module to v1.2.4 [#103](https://github.com/openshift/multus-admission-controller/pull/103)
* [Full changelog](https://github.com/openshift/multus-admission-controller/compare/88c596ed782cf6c3f94efa286b3568d12acde436...a15bf454ad4446cefdb708ea3f121d08a0df83ee)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/89c3e1cc0eb7a7c8b0686916bfcb375edb78f7dd)
* [OCPBUGS-85251](https://issues.redhat.com/browse/OCPBUGS-85251): Fix server url in kubeconfig [#300](https://github.com/openshift/multus-cni/pull/300)
* NO-ISSUE: [release-4.16] Bump Go to 1.21 and fix CI build root image [#292](https://github.com/openshift/multus-cni/pull/292)
* [OCPBUGS-47472](https://issues.redhat.com/browse/OCPBUGS-47472): adds getcontext (backport 4.16) [#261](https://github.com/openshift/multus-cni/pull/261)
* [Full changelog](https://github.com/openshift/multus-cni/compare/c4aa21b9bfed4ebafc2e67ca1474e245b67b5f9f...89c3e1cc0eb7a7c8b0686916bfcb375edb78f7dd)
### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/b8c8fc124b5933ae8bc08107b1d992bc607b325b)
* [OCPBUGS-70215](https://issues.redhat.com/browse/OCPBUGS-70215): Prevent accidental IP deallocation in statefulsets [#396](https://github.com/openshift/whereabouts-cni/pull/396)
* [OCPBUGS-55618](https://issues.redhat.com/browse/OCPBUGS-55618): Fixes leftover podref issue [#365](https://github.com/openshift/whereabouts-cni/pull/365)
* [OCPBUGS-50005](https://issues.redhat.com/browse/OCPBUGS-50005): [Release-4.17]Kubeconfig loop [#340](https://github.com/openshift/whereabouts-cni/pull/340)
* [Full changelog](https://github.com/openshift/whereabouts-cni/compare/dab1dd29b18521916c18a278faa734f038eccdf1...b8c8fc124b5933ae8bc08107b1d992bc607b325b)
### [must-gather](https://github.com/openshift/must-gather/tree/fd6cbc7b46924094c746ae024c80a4b8a5e57ce6)
* [OCPBUGS-86218](https://issues.redhat.com/browse/OCPBUGS-86218): Collect object size with the object count [#550](https://github.com/openshift/must-gather/pull/550)
* [OCPBUGS-66106](https://issues.redhat.com/browse/OCPBUGS-66106): Separate resources with comma to fix malformed inspect [#515](https://github.com/openshift/must-gather/pull/515)
* [OCPBUGS-42960](https://issues.redhat.com/browse/OCPBUGS-42960): Gather OSUS data [#455](https://github.com/openshift/must-gather/pull/455)
* [Full changelog](https://github.com/openshift/must-gather/compare/962e04c71ef0dabf68f36b8b29117fb11734f473...fd6cbc7b46924094c746ae024c80a4b8a5e57ce6)
### [network-interface-bond-cni](https://github.com/openshift/bond-cni/tree/e6880659ea1327c5b48dcf64a426eadfbafc0f1b)
* [OCPBUGS-61348](https://issues.redhat.com/browse/OCPBUGS-61348): Bump github.com/containernetworking/plugins from to 1.7.1 [#95](https://github.com/openshift/bond-cni/pull/95)
* NO-JIRA: Updating ose-network-interface-bond-cni-container image to be consistent with ART for 4.16 [#91](https://github.com/openshift/bond-cni/pull/91)
* NO-JIRA: Add ci-operator.yaml file on release-4.16 [#84](https://github.com/openshift/bond-cni/pull/84)
* [Full changelog](https://github.com/openshift/bond-cni/compare/bb911451158fc06f193917863778434944e88ae1...e6880659ea1327c5b48dcf64a426eadfbafc0f1b)
### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/1210db38beff72968f1227f10312a9086b1b914e)
* [OCPBUGS-58777](https://issues.redhat.com/browse/OCPBUGS-58777): Bump github.com/golang/glog to v1.2.4 (#113) [#113](https://github.com/openshift/network-metrics-daemon/pull/113)
* [OCPBUGS-60186](https://issues.redhat.com/browse/OCPBUGS-60186): Replace e2e test image (#122) [#122](https://github.com/openshift/network-metrics-daemon/pull/122)
* swtich golint install method (#123) [#123](https://github.com/openshift/network-metrics-daemon/pull/123)
* [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/48059263880572c52fb8b21f1441370100dc167a...1210db38beff72968f1227f10312a9086b1b914e)
### [network-tools](https://github.com/openshift/network-tools/tree/234ed43e3e7b2cfcb76a19c80fcdb573a625309f)
* add missing go vendors [#140](https://github.com/openshift/network-tools/pull/140)
* [Full changelog](https://github.com/openshift/network-tools/compare/39eca100c0978fb59234e21bf549b130914616ac...234ed43e3e7b2cfcb76a19c80fcdb573a625309f)
### [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix/tree/2f2e121b6caea7073a5b7d64312f08f9d91233bb)
* [OCPBUGS-51854](https://issues.redhat.com/browse/OCPBUGS-51854): CVE-2025-22868 [#110](https://github.com/openshift/machine-api-provider-nutanix/pull/110)
* [OCPBUGS-47266](https://issues.redhat.com/browse/OCPBUGS-47266): fixing CVE-2024-45338 [#93](https://github.com/openshift/machine-api-provider-nutanix/pull/93)
* [Full changelog](https://github.com/openshift/machine-api-provider-nutanix/compare/f053e5a0ee58d20066efff8db01578785ea83dad...2f2e121b6caea7073a5b7d64312f08f9d91233bb)
### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/6f6120779248fcd0941c6d4f507f56e66cb06cc7)
* [OCPBUGS-74112](https://issues.redhat.com/browse/OCPBUGS-74112): UPSTREAM: <carry>: bump kubernetes-apiserver to pick up loopback cert expiration update [#166](https://github.com/openshift/oauth-apiserver/pull/166)
* NO-JIRA: (chore): update OWNERS file [#172](https://github.com/openshift/oauth-apiserver/pull/172)
* [Full changelog](https://github.com/openshift/oauth-apiserver/compare/f09a9be33b6455664a6842980fca4bd8008e9e6e...6f6120779248fcd0941c6d4f507f56e66cb06cc7)
### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/d17d71703099c69d02644fe7f777beed63d2b30f)
* [OCPBUGS-61446](https://issues.redhat.com/browse/OCPBUGS-61446): Update x/crypto to v0.31.0 [#335](https://github.com/openshift/oauth-proxy/pull/335)
* [OCPBUGS-62707](https://issues.redhat.com/browse/OCPBUGS-62707): Fix oauth-proxy e2e-component tests [#338](https://github.com/openshift/oauth-proxy/pull/338)
* [Full changelog](https://github.com/openshift/oauth-proxy/compare/30f8012482023689655252dc2af2f17fe6a09253...d17d71703099c69d02644fe7f777beed63d2b30f)
### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/aeebf898c582b48dda33f083b38d143b9d37ec7c)
* [OCPBUGS-82682](https://issues.redhat.com/browse/OCPBUGS-82682): Address CVE-2026-35469 [#649](https://github.com/openshift/openshift-apiserver/pull/649)
* [OCPBUGS-68104](https://issues.redhat.com/browse/OCPBUGS-68104): CVE-2025-65637 - Bump github.com/sirupsen/logrus from v1.9.0 to v1.9.3 [release-4.16] [#610](https://github.com/openshift/openshift-apiserver/pull/610)
* [OCPBUGS-74113](https://issues.redhat.com/browse/OCPBUGS-74113): UPSTREAM: <carry>: bump kubernetes-apiserver to pick up loopback cert expiration update [#595](https://github.com/openshift/openshift-apiserver/pull/595)
* [OCPBUGS-63394](https://issues.redhat.com/browse/OCPBUGS-63394): Wire dry run option to Image API server operations [#566](https://github.com/openshift/openshift-apiserver/pull/566)
* [OCPBUGS-61474](https://issues.redhat.com/browse/OCPBUGS-61474): Skip blocked registry check for registries with mirrors [#552](https://github.com/openshift/openshift-apiserver/pull/552)
* [OCPBUGS-56612](https://issues.redhat.com/browse/OCPBUGS-56612): Fix image reference in TestImageStreamImportQuayIO [#516](https://github.com/openshift/openshift-apiserver/pull/516)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/fcee0c265f79dcecccfd0d276e6fcc0af7dbcf11...aeebf898c582b48dda33f083b38d143b9d37ec7c)
### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/90f73f7ea939b221b79684ebe6d2feb843fc1f83)
* [OCPBUGS-61707](https://issues.redhat.com/browse/OCPBUGS-61707): legacy image pull secret rollback controller [#416](https://github.com/openshift/openshift-controller-manager/pull/416)
* [OCPBUGS-60233](https://issues.redhat.com/browse/OCPBUGS-60233): ignore error failing to find pull/push secrets [#409](https://github.com/openshift/openshift-controller-manager/pull/409)
* [OCPBUGS-57513](https://issues.redhat.com/browse/OCPBUGS-57513): Set node-pullsecrets volume to read-only to protect image pull credentials [#394](https://github.com/openshift/openshift-controller-manager/pull/394)
* [OCPBUGS-56354](https://issues.redhat.com/browse/OCPBUGS-56354): Empty proxy variables are causing issues during the build [#382](https://github.com/openshift/openshift-controller-manager/pull/382)
* [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/bcf6e58edbcc8e7ce6f7e4d0658635688e0fc114...90f73f7ea939b221b79684ebe6d2feb843fc1f83)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/3b972b2bcb5c5d779ea4335faf71abab4d9e5a1c)
* [OCPBUGS-58028](https://issues.redhat.com/browse/OCPBUGS-58028): Merge https://github.com/kubernetes-sigs/cluster-api-provider-openstack:release-0.10 into release-4.16 [#346](https://github.com/openshift/cluster-api-provider-openstack/pull/346)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/bafa26de94c06009f563c8283ac42a78478667c5...3b972b2bcb5c5d779ea4335faf71abab4d9e5a1c)
### [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack/tree/84d4c65669fd54d91e33bc378d7eb45a3974399a)
* [OCPBUGS-78170](https://issues.redhat.com/browse/OCPBUGS-78170): hermetic 4.16 [#163](https://github.com/openshift/machine-api-provider-openstack/pull/163)
* [OCPBUGS-76794](https://issues.redhat.com/browse/OCPBUGS-76794): Fix make test [#155](https://github.com/openshift/machine-api-provider-openstack/pull/155)
* [Full changelog](https://github.com/openshift/machine-api-provider-openstack/compare/5ada1cbab3a9354488b1e74e85c36285302c3382...84d4c65669fd54d91e33bc378d7eb45a3974399a)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/c6bdcdc0f8d54b42e0ee12ded744b0cd3914ba20)
* [OCPBUGS-103065](https://issues.redhat.com/browse/OCPBUGS-103065), [OCPBUGS-103070](https://issues.redhat.com/browse/OCPBUGS-103070), [OCPBUGS-103078](https://issues.redhat.com/browse/OCPBUGS-103078): Replace golang.org/x/net with github.com/openshift-sustaining/net@v0.35.0-sec.3 [#1367](https://github.com/openshift/operator-framework-olm/pull/1367)
* [OCPBUGS-79980](https://issues.redhat.com/browse/OCPBUGS-79980), [OCPBUGS-79981](https://issues.redhat.com/browse/OCPBUGS-79981), [OCPBUGS-87898](https://issues.redhat.com/browse/OCPBUGS-87898): Fix CVE-2026-33186 with openshift-sustaining/grpc-go v1.67.3-sec.1 [release-4.16] [#1318](https://github.com/openshift/operator-framework-olm/pull/1318)
* [OCPBUGS-82057](https://issues.redhat.com/browse/OCPBUGS-82057): Drop github.com/distribution/distribution dep [#1302](https://github.com/openshift/operator-framework-olm/pull/1302)
* [OCPBUGS-77959](https://issues.redhat.com/browse/OCPBUGS-77959): Remove the collect-profiles info from the microshift kustomization file [#1251](https://github.com/openshift/operator-framework-olm/pull/1251)
* [OCPBUGS-77169](https://issues.redhat.com/browse/OCPBUGS-77169): Remove the collect-profiles job [#1235](https://github.com/openshift/operator-framework-olm/pull/1235)
* [OCPBUGS-58881](https://issues.redhat.com/browse/OCPBUGS-58881): operatorgroup: ensure clusterroleselectors in clusterrole aggregation rules are sorted [#1102](https://github.com/openshift/operator-framework-olm/pull/1102)
* [OCPBUGS-59647](https://issues.redhat.com/browse/OCPBUGS-59647): Reduce Frequency of Update Requests for Copied CSVs (#3597) [#1042](https://github.com/openshift/operator-framework-olm/pull/1042)
* [OCPBUGS-60847](https://issues.redhat.com/browse/OCPBUGS-60847): Add NetworkPolicy as a supported kind [#1050](https://github.com/openshift/operator-framework-olm/pull/1050)
* [OCPBUGS-61388](https://issues.redhat.com/browse/OCPBUGS-61388): [4.16] e2e stability fixes [#1083](https://github.com/openshift/operator-framework-olm/pull/1083)
* [OCPBUGS-57429](https://issues.redhat.com/browse/OCPBUGS-57429): reduce cache expiry frequency [release-4.19] [#1022](https://github.com/openshift/operator-framework-olm/pull/1022)
* [OCPBUGS-56358](https://issues.redhat.com/browse/OCPBUGS-56358): fix(olm): improve error logging for missing olm.managed label (#3558) [#1006](https://github.com/openshift/operator-framework-olm/pull/1006)
* [OCPBUGS-53395](https://issues.redhat.com/browse/OCPBUGS-53395): Ensure that PSA label is latest instead of pinning versions [#987](https://github.com/openshift/operator-framework-olm/pull/987)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/48d68f52674ad5afb2d40d032abb0892a5dafee6...c6bdcdc0f8d54b42e0ee12ded744b0cd3914ba20)
### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/5d0e13792f967e2809b99f2b4cb43b00e2e5ef8d)
* [OCPBUGS-68108](https://issues.redhat.com/browse/OCPBUGS-68108), [OCPBUGS-68109](https://issues.redhat.com/browse/OCPBUGS-68109): CVE-2025-65637 fixed in logrus v1.9.3+ [#722](https://github.com/operator-framework/operator-marketplace/pull/722)
* [OCPBUGS-62220](https://issues.redhat.com/browse/OCPBUGS-62220): Remove Expect func so that the test case can use the retry logic [#671](https://github.com/operator-framework/operator-marketplace/pull/671)
* [OCPBUGS-61920](https://issues.redhat.com/browse/OCPBUGS-61920): Update memoryTarget on catalog source pods [#664](https://github.com/operator-framework/operator-marketplace/pull/664)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/208d5aa79e2f953d0e621070091409ab43cb54e1...5d0e13792f967e2809b99f2b4cb43b00e2e5ef8d)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/5b36fd8eb481809b4d2e2d65c5a6ce8f03407749)
* [OCPBUGS-83497](https://issues.redhat.com/browse/OCPBUGS-83497): External gateway: Remove routes for external gateway pods in terminating or not ready state [#3140](https://github.com/openshift/ovn-kubernetes/pull/3140)
* [OCPBUGS-78033](https://issues.redhat.com/browse/OCPBUGS-78033): Add pperiyasamy to OWNERS for release-4.16 [#3047](https://github.com/openshift/ovn-kubernetes/pull/3047)
* [OCPBUGS-77685](https://issues.redhat.com/browse/OCPBUGS-77685): Clear stale conntrack UDP entries for nodePorts [#3038](https://github.com/openshift/ovn-kubernetes/pull/3038)
* [OCPBUGS-77187](https://issues.redhat.com/browse/OCPBUGS-77187): Fix conntrack reconciliation to use service port instead of endpoint port [#2998](https://github.com/openshift/ovn-kubernetes/pull/2998)
* [CORENET-6055](https://issues.redhat.com/browse/CORENET-6055), [OCPBUGS-76277](https://issues.redhat.com/browse/OCPBUGS-76277): [release-4.16] Dockerfile: Unpin OVN and consume the latest from FDP [#2972](https://github.com/openshift/ovn-kubernetes/pull/2972)
* [OCPBUGS-71219](https://issues.redhat.com/browse/OCPBUGS-71219): [release-4.16] CVE-2025-65637 Bump github.com/sirupsen/logrus to v1.9.1 through indirect dependency conversion (go-controller module) [#2906](https://github.com/openshift/ovn-kubernetes/pull/2906)
* [OCPBUGS-72541](https://issues.redhat.com/browse/OCPBUGS-72541): NetPol & MultiNetPol: Process update only when spec fields and/or related annotation are updated [#2933](https://github.com/openshift/ovn-kubernetes/pull/2933)
* [OCPBUGS-68349](https://issues.redhat.com/browse/OCPBUGS-68349): Add ricky-rav to OWNERS for release-4.16 [#2899](https://github.com/openshift/ovn-kubernetes/pull/2899)
* [OCPBUGS-66155](https://issues.redhat.com/browse/OCPBUGS-66155): Skip Pending pods in EgressIP status updates [#2880](https://github.com/openshift/ovn-kubernetes/pull/2880)
* [OCPBUGS-64944](https://issues.redhat.com/browse/OCPBUGS-64944): [release-4.16]: Configure sec nic EIPv6 address with NODAD and maximum lifetime [#2853](https://github.com/openshift/ovn-kubernetes/pull/2853)
* [OCPBUGS-64858](https://issues.redhat.com/browse/OCPBUGS-64858): Fix stale EIP assignments during failover and controller restart [#2851](https://github.com/openshift/ovn-kubernetes/pull/2851)
* [OCPBUGS-63155](https://issues.redhat.com/browse/OCPBUGS-63155): Fix EgressIP stale GARP post reboot + pod restart [#2809](https://github.com/openshift/ovn-kubernetes/pull/2809)
* [OCPBUGS-63230](https://issues.redhat.com/browse/OCPBUGS-63230): Fix dnsnameresolver address set [#2812](https://github.com/openshift/ovn-kubernetes/pull/2812)
* [OCPBUGS-60079](https://issues.redhat.com/browse/OCPBUGS-60079): Always enable global IPv6 forwarding [#2743](https://github.com/openshift/ovn-kubernetes/pull/2743)
* [OCPBUGS-60494](https://issues.redhat.com/browse/OCPBUGS-60494): Update OWNERS file: Add Patryk/Martin as approvers [#2718](https://github.com/openshift/ovn-kubernetes/pull/2718)
* [OCPBUGS-58161](https://issues.redhat.com/browse/OCPBUGS-58161): Unpin OVS patch versions [#2648](https://github.com/openshift/ovn-kubernetes/pull/2648)
* [OCPBUGS-57396](https://issues.redhat.com/browse/OCPBUGS-57396): Fix predicate for cluster subnet route to gateway router [#2645](https://github.com/openshift/ovn-kubernetes/pull/2645)
* [OCPBUGS-55282](https://issues.redhat.com/browse/OCPBUGS-55282): Fix hybrid overlay node subnets collision with cluster subnets [#2621](https://github.com/openshift/ovn-kubernetes/pull/2621)
* [OCPBUGS-48121](https://issues.redhat.com/browse/OCPBUGS-48121): Increase InformerSyncTimeout to 60s [#2624](https://github.com/openshift/ovn-kubernetes/pull/2624)
* [OCPBUGS-56242](https://issues.redhat.com/browse/OCPBUGS-56242): Handles unspecified protocol in network policy port [#2571](https://github.com/openshift/ovn-kubernetes/pull/2571)
* [OCPBUGS-56812](https://issues.redhat.com/browse/OCPBUGS-56812): egressfirewall: avoid nil dereference on node delete [#2591](https://github.com/openshift/ovn-kubernetes/pull/2591)
* [OCPBUGS-52503](https://issues.redhat.com/browse/OCPBUGS-52503): Fixes unexpected mp0 route removal during start up [#2479](https://github.com/openshift/ovn-kubernetes/pull/2479)
* [OCPBUGS-54204](https://issues.redhat.com/browse/OCPBUGS-54204): Update OVN to FDP25.A.1 24.03.5-40. [#2497](https://github.com/openshift/ovn-kubernetes/pull/2497)
* [OCPBUGS-50595](https://issues.redhat.com/browse/OCPBUGS-50595): kubevirt, localnet: Reduce live migration downtime [#2469](https://github.com/openshift/ovn-kubernetes/pull/2469)
* [OCPBUGS-50594](https://issues.redhat.com/browse/OCPBUGS-50594): fixes overzealous deletion of SNAT in egressIP [#2456](https://github.com/openshift/ovn-kubernetes/pull/2456)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/b24157b7b38f1be8a6175a2c7cae0fe8ece97f67...5b36fd8eb481809b4d2e2d65c5a6ce8f03407749)
### [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver/tree/f8017f850d974ab5bb9978430d29f7d5f9a60397)
* [OCPBUGS-105268](https://issues.redhat.com/browse/OCPBUGS-105268): Mitigate CVE-2025-30204 by bumping github.com/golang-jwt/jwt/v4 to v4.5.2 [#139](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/139)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver/compare/26162badb8422f36d9b52fac8467d48bf6078f5a...f8017f850d974ab5bb9978430d29f7d5f9a60397)
### [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs/tree/2bfcc0f832d5237690ea900996e7679a5b5f0cd7)
* [OCPBUGS-61511](https://issues.redhat.com/browse/OCPBUGS-61511): Use OS_GIT_VERSION in Makefile when found (for Konflux builds) [#127](https://github.com/openshift/machine-api-provider-powervs/pull/127)
* [OCPBUGS-54752](https://issues.redhat.com/browse/OCPBUGS-54752): Fix for CVE-2024-51744 in github.com/golang-jwt/jwt/v4 in release-4.16 [#114](https://github.com/openshift/machine-api-provider-powervs/pull/114)
* [Full changelog](https://github.com/openshift/machine-api-provider-powervs/compare/60ebedf061fe1bb5279650fd637108b13b92d95f...2bfcc0f832d5237690ea900996e7679a5b5f0cd7)
### [prom-label-proxy](https://github.com/openshift/prom-label-proxy/tree/d2a9459d0ede714fc75612ee19c98a6c9aaebbee)
* NO-ISSUE: synchronize OWNERS from main branch [release-4.16] [#404](https://github.com/openshift/prom-label-proxy/pull/404)
* [Full changelog](https://github.com/openshift/prom-label-proxy/compare/5e14722ecfb3323ce2eb9c75a6bd9c5274b06040...d2a9459d0ede714fc75612ee19c98a6c9aaebbee)
### [prometheus](https://github.com/openshift/prometheus/tree/9e07787900a6116c45788511755ef29d27a08444)
* [OCPBUGS-88616](https://issues.redhat.com/browse/OCPBUGS-88616): remote: validate snappy decoded length before allocation in read endpoint [#349](https://github.com/openshift/prometheus/pull/349)
* [OCPBUGS-79985](https://issues.redhat.com/browse/OCPBUGS-79985): Bump google.golang.org/grpc [#321](https://github.com/openshift/prometheus/pull/321)
* [OCPBUGS-61856](https://issues.redhat.com/browse/OCPBUGS-61856): chore: compute highestTimestamp at queryManager level [#270](https://github.com/openshift/prometheus/pull/270)
* [OCPBUGS-56739](https://issues.redhat.com/browse/OCPBUGS-56739): BACKPORT: fix promtool analyze block shows metric name with 0 cardinality [#255](https://github.com/openshift/prometheus/pull/255)
* [OCPBUGS-54942](https://issues.redhat.com/browse/OCPBUGS-54942): Scraping: Bump cache iteration after error to avoid false duplicate detection. [#250](https://github.com/openshift/prometheus/pull/250)
* [Full changelog](https://github.com/openshift/prometheus/compare/09479fe37af9d9f187cb21796e73213c80c902fc...9e07787900a6116c45788511755ef29d27a08444)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/6c59aedca381cd8c96d87bc05454012a7e72f583)
* [OCPBUGS-103072](https://issues.redhat.com/browse/OCPBUGS-103072): Use github.com/openshift-sustaining/net patch to fix CVE-2026-33814 [#174](https://github.com/openshift/prometheus-alertmanager/pull/174)
* [OCPBUGS-100357](https://issues.redhat.com/browse/OCPBUGS-100357): Set testdata CA expiry to 20 years from issue date (#4112) [#146](https://github.com/openshift/prometheus-alertmanager/pull/146)
* [OCPBUGS-76536](https://issues.redhat.com/browse/OCPBUGS-76536): Include go-verify-deps expected files in gitignore [#116](https://github.com/openshift/prometheus-alertmanager/pull/116)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/e9aea929f309f412678fdf1064e1f74db3ba08b4...6c59aedca381cd8c96d87bc05454012a7e72f583)
### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/d19158d9b111d5196ee649f493e56682424e4736)
* [OCPBUGS-103085](https://issues.redhat.com/browse/OCPBUGS-103085), [OCPBUGS-103089](https://issues.redhat.com/browse/OCPBUGS-103089): [release-4.16] Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [#401](https://github.com/openshift/prometheus-operator/pull/401)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/c7262a43c0ddf2adc6be3863ac9a5056cb89c177...d19158d9b111d5196ee649f493e56682424e4736)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/769870ef6ad956c1c349374d549d44c73cb66a9e)
* NO-ISSUE: synchronize OWNERS from main branch [release-4.16] [#203](https://github.com/openshift/node_exporter/pull/203)
* [Full changelog](https://github.com/openshift/node_exporter/compare/29ba26d1bc31e5ff6b398f20dbdd72b4ca3ba897...769870ef6ad956c1c349374d549d44c73cb66a9e)
### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/c1af9e08f34658e703dd0d1bce5f2df8207c7cfd)
* [OCPBUGS-79934](https://issues.redhat.com/browse/OCPBUGS-79934): Bump google.golang.org/grpc to v1.79.3 [#87](https://github.com/openshift/route-controller-manager/pull/87)
* [OCPBUGS-56152](https://issues.redhat.com/browse/OCPBUGS-56152): Added error event for failed ingress to route conversion [#61](https://github.com/openshift/route-controller-manager/pull/61)
* [OCPBUGS-55201](https://issues.redhat.com/browse/OCPBUGS-55201): ingress: Reset metrics when ingress is deleted [#58](https://github.com/openshift/route-controller-manager/pull/58)
* [Full changelog](https://github.com/openshift/route-controller-manager/compare/3112b458983c6fca6f77d5a945fb0026186dace6...c1af9e08f34658e703dd0d1bce5f2df8207c7cfd)
### [tests](https://github.com/openshift/origin/tree/ad93a681f5fdebdab588ee5402181c29aba4af10)
* [OCPBUGS-105460](https://issues.redhat.com/browse/OCPBUGS-105460): Use tagged version for openshift/kubernetes dependency [#31541](https://github.com/openshift/origin/pull/31541)
* [OCPBUGS-74299](https://issues.redhat.com/browse/OCPBUGS-74299): Update to latest openshift/kubernetes [#30825](https://github.com/openshift/origin/pull/30825)
* [OCPBUGS-63395](https://issues.redhat.com/browse/OCPBUGS-63395): Backport pr 29834 to release-4.18 [#30409](https://github.com/openshift/origin/pull/30409)
* [OCPBUGS-62934](https://issues.redhat.com/browse/OCPBUGS-62934): Fix bearer token exposure in exit condition as well [#30365](https://github.com/openshift/origin/pull/30365)
* [OCPBUGS-61170](https://issues.redhat.com/browse/OCPBUGS-61170): images/tests: Remove rteval [#30203](https://github.com/openshift/origin/pull/30203)
* NO-JIRA: Update extended/networking OWNERS [#30091](https://github.com/openshift/origin/pull/30091)
* [OCPBUGS-60272](https://issues.redhat.com/browse/OCPBUGS-60272): Bump kubernetes version to fix NFS ganesha version [#30086](https://github.com/openshift/origin/pull/30086)
* [OCPBUGS-57311](https://issues.redhat.com/browse/OCPBUGS-57311): Replace RunHostCmd with Exec function to censor bearer token being exposed [#29908](https://github.com/openshift/origin/pull/29908)
* [OCPBUGS-57203](https://issues.redhat.com/browse/OCPBUGS-57203): fix: remove un-needed test [#29849](https://github.com/openshift/origin/pull/29849)
* [OCPBUGS-34163](https://issues.redhat.com/browse/OCPBUGS-34163): Fix regex parser for censoring private key [#29805](https://github.com/openshift/origin/pull/29805)
* [OCPBUGS-56704](https://issues.redhat.com/browse/OCPBUGS-56704): aws/edge: prevent test using unschedulable nodes [#29847](https://github.com/openshift/origin/pull/29847)
* [OCPBUGS-55476](https://issues.redhat.com/browse/OCPBUGS-55476): support provider type external [#29738](https://github.com/openshift/origin/pull/29738)
* [OCPBUGS-55636](https://issues.redhat.com/browse/OCPBUGS-55636): [build] Ensure Git Clone Does Not Run Privileged [#29746](https://github.com/openshift/origin/pull/29746)
* [OCPBUGS-54768](https://issues.redhat.com/browse/OCPBUGS-54768): Fix egress firewall tests by updating the URL from docs.openshift.com to redhat.com [#29663](https://github.com/openshift/origin/pull/29663)
* [OCPBUGS-52581](https://issues.redhat.com/browse/OCPBUGS-52581): Use payload pullspec for image info test [#29589](https://github.com/openshift/origin/pull/29589)
* [OCPBUGS-52343](https://issues.redhat.com/browse/OCPBUGS-52343): Try also user CA for getting openshift-tests image [#29578](https://github.com/openshift/origin/pull/29578)
* [Full changelog](https://github.com/openshift/origin/compare/079a3fd6918185ca2a7bd99acf96f7dde5392002...ad93a681f5fdebdab588ee5402181c29aba4af10)
### [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere/tree/54af90db28cb799836ebce77ae9a266f106d8cc5)
* [OCPBUGS-78028](https://issues.redhat.com/browse/OCPBUGS-78028): hermetic migration 4.16 [#107](https://github.com/openshift/cloud-provider-vsphere/pull/107)
* [Full changelog](https://github.com/openshift/cloud-provider-vsphere/compare/023a3655c181512a870fe1c865dbdbd31690f439...54af90db28cb799836ebce77ae9a266f106d8cc5)
### [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere/tree/dc5cdf19ea688fbbd2bceb7209d09611647a9d51)
* [OCPBUGS-78020](https://issues.redhat.com/browse/OCPBUGS-78020): hermetic migration 4.16 [#86](https://github.com/openshift/cluster-api-provider-vsphere/pull/86)
* [OCPBUGS-61653](https://issues.redhat.com/browse/OCPBUGS-61653): Fix unit tests [#72](https://github.com/openshift/cluster-api-provider-vsphere/pull/72)
* [Full changelog](https://github.com/openshift/cluster-api-provider-vsphere/compare/be22f10a56a18cd94406eea442e0113d866618ea...dc5cdf19ea688fbbd2bceb7209d09611647a9d51)
### [vsphere-csi-driver, vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver/tree/5a7e624152717123899ac967d24be592456da44b)
* [OCPBUGS-86874](https://issues.redhat.com/browse/OCPBUGS-86874): Bump google.golang.org/grpc [#182](https://github.com/openshift/vmware-vsphere-csi-driver/pull/182)
* [OCPBUGS-68119](https://issues.redhat.com/browse/OCPBUGS-68119): CVE-2025-65637: Bump github.com/sirupsen/logrus to v1.8.3 [#158](https://github.com/openshift/vmware-vsphere-csi-driver/pull/158)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver/compare/03b7e8ebf2c6347b40a340d892e1a66d47806300...5a7e624152717123899ac967d24be592456da44b)
### [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator/tree/7940ea1685dee6d3f29a6360dac9a82dd1b09230)
* [OCPBUGS-51206](https://issues.redhat.com/browse/OCPBUGS-51206): Set reconcile-sync to 10 minute for ListVolume [#294](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/294)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver-operator/compare/a18e490913432458e1e9c6ba7bd94cd40b06a931...7940ea1685dee6d3f29a6360dac9a82dd1b09230)
### [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector/tree/cd51b622232c45f73a8c468845ab8f3ee2624e80)
* [OCPBUGS-103110](https://issues.redhat.com/browse/OCPBUGS-103110): Bump golang.org/x/net to v0.35.0-sec.4 [#235](https://github.com/openshift/vsphere-problem-detector/pull/235)
* [OCPBUGS-86445](https://issues.redhat.com/browse/OCPBUGS-86445): fix concurrent map writes [#219](https://github.com/openshift/vsphere-problem-detector/pull/219)
* [Full changelog](https://github.com/openshift/vsphere-problem-detector/compare/3683c120278fb79a30340f66d22948aaddf3c16a...cd51b622232c45f73a8c468845ab8f3ee2624e80)