# 4.21.35
Created: 2026-09-25 06:48:58 +0000 UTC
Image Digest: `sha256:1f8f423477982ce16193469c26f8941ba797a6f4fc3b3621a5d426ae19deb457`
## Changes from 4.21.8
### Components
* Kubectl 1.34.1
* Kubernetes upgraded from 1.34.5 to 1.34.9
* Kubernetes Tests 1.34.1
* Red Hat Enterprise Linux CoreOS upgraded from 9.6.20260324-0 to 10.2.20260521-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: |
| EventTTL
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled| Enabled |
| GatewayAPIWithoutOLM
(0 tests)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New)| Enabled
(New) |
### Removed images
* libvirt-machine-controllers
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [35ba137a](https://github.com/openshift/apiserver-network-proxy/commit/35ba137ab96d01f0b8df729ff5ad93ac2fdad800) `sha256:5db653d4f6ffb147abd99670ae1518f535c3f31efa7ad72be632a21c53929167`
* [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws) git [fdc7f3f1](https://github.com/openshift/cloud-provider-aws/commit/fdc7f3f15c693593cb573b6bef6f0363256b6f52) `sha256:f988e8ead554f5ae5e2f8066353a341deeee92d7ee6e0122c2dd4a8a41c5366e`
* [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws) git [938565c9](https://github.com/openshift/machine-api-provider-aws/commit/938565c9f796fba385c0978a5ae1cc0a79f0f857) `sha256:23c81f1d0cb195e11662c4b20ce353200ad844951869ec82c1e7d4df6df7983c`
* [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [5cd42ed1](https://github.com/openshift/aws-pod-identity-webhook/commit/5cd42ed1e5151f45f0134593e9cfebdb6517b385) `sha256:3724c00e06ffce8ecf0bab67a5e0e7363acf9d59ba572c7022c7b4dc324fc89a`
* [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3) git [659138fe](https://github.com/openshift/cluster-api-provider-metal3/commit/659138fef3abd4c71b0b01fa1279146745699a5a) `sha256:b3dbf258905cc1d376a29c67a200f7f66bf71855d19625666815a6509329dc6c`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [4e6a729c](https://github.com/openshift/cluster-api-provider-baremetal/commit/4e6a729c5ac8fde8859db5830def262dfdee28ea) `sha256:9db65698a29ac5c2df1d75d4a59a15ebc6994223e0c23c8fce47a02ef0fe5292`
* [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg) git [d7e3fc12](https://github.com/openshift/baremetal-runtimecfg/commit/d7e3fc12bd9dc911f0fac4c9a46b814c7be62b14) `sha256:a1aa787d8108217c262fcd0fe5c117a23fadd8c859e91f7a810dc3c74966fca4`
* [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller) git [57db2d05](https://github.com/openshift/cloud-network-config-controller/commit/57db2d05e057dc90bae3dc1b0e806b3259d38fc0) `sha256:651121d0549e9d6899b24712cfed886890f6778255905c993c21d4809c2bbaeb`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [dc0d4a5c](https://github.com/openshift/cluster-bootstrap/commit/dc0d4a5cdaf8a7477cab584208dc99352f46efe2) `sha256:ebf22f6323bd2b38cb01bcb267456331b1b6ecb69c6d66fc3ca0c7e063882f89`
* [cluster-config-operator](https://github.com/openshift/cluster-config-operator) git [1eb450a3](https://github.com/openshift/cluster-config-operator/commit/1eb450a3a2456f6e3fe3d727208b5f7b0dd35aba) `sha256:7f59f35ee6657f445d98e6001b2fccdd987bf87af05161c8282a22355403967f`
* [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator) git [41a53fed](https://github.com/openshift/cluster-dns-operator/commit/41a53fed36e6e99c7c9ceb3a699c3547ee5d9bb9) `sha256:302e30c07ae928c8811277a497759c57b385c72f5f749f52560443b6cf228c16`
* [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator) git [395de967](https://github.com/openshift/cluster-kube-controller-manager-operator/commit/395de96705749de9c6a5f25747b9d5c3d5f65a8f) `sha256:adb962dc7884c977c7809496ff95caa19a97d6d74cd3d0de59f491702384ec0e`
* [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator) git [8a42beeb](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/commit/8a42beebd580bd2e241aa6d93860c09e907f2407) `sha256:295e63bf7c340bcdd2bc035d58c9811fec984b7e2fdb0a8db204978f3dd1f625`
* [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver) git [d864813c](https://github.com/openshift/cluster-machine-approver/commit/d864813cd3ab01c0f975b2bf41e9046948f0afa1) `sha256:f69eac2b49cfd5825f02d0fa9c26d6d9159b6642ba4637c15ff7abdfb691d146`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [2617a201](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/2617a201bb3607192a9f82faa18384676f611e3c) `sha256:6457124986f63555d0aeed644c0c7dbf5d928518c731cfda80dc7632cda11c6a`
* [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator) git [11ed1942](https://github.com/openshift/cluster-samples-operator/commit/11ed1942dbbf7a8334862b3d598a967e9b92aa77) `sha256:a6fa143df7edfe4f0841c1813945805d58d7d8e0be8c0d03fc5e8a5351039c97`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [b3cae8f2](https://github.com/openshift/cluster-update-keys/commit/b3cae8f22b51d9062d0ceb6ac9cf2f7651b4ce8f) `sha256:5cc8a1e84c25d5a87aac037a629cb0e784e58f99126d22dce173bc654ed6c21b`
* [cluster-version-operator](https://github.com/openshift/cluster-version-operator) git [d37e5a05](https://github.com/openshift/cluster-version-operator/commit/d37e5a056d5a9c74c2ac2d5551ef39f573c9824a) `sha256:c8a0da961c360655a30bb431cc3a4b9f25b85f408b2f95c1099aa32de248af9a`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [16114b8d](https://github.com/openshift/configmap-reload/commit/16114b8de20278b8f4b7a425ece6d35d53214773) `sha256:fea6c6aeff103590764c6b38277fbb9f7faa7058feb1e4f2476af68ec3f0d42c`
* [container-networking-plugins](https://github.com/openshift/containernetworking-plugins) git [747ad66c](https://github.com/openshift/containernetworking-plugins/commit/747ad66caa1109b2b490aebad01af42bd2d738f1) `sha256:5cd0b1cdd4511ef8ae8c9c0c68210efdd9cdcb8bb5b253fdf2853e7f0ff463e9`
* [containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins) git [747ad66c](https://github.com/openshift/containernetworking-plugins/commit/747ad66caa1109b2b490aebad01af42bd2d738f1) `sha256:6c614a3e137b9366d72062659d58a67fe8374cdb28ab3c35348c86800281355b`
* [coredns](https://github.com/openshift/coredns) git [7486e9e4](https://github.com/openshift/coredns/commit/7486e9e4330c1e41d9a91e4673b7f2782efc112c) `sha256:d26886b96df1012395e7179d95cb896d452b54319d7fbd08fd6a155d18a383a9`
* [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata) git [af250fdb](https://github.com/openshift/csi-external-snapshot-metadata/commit/af250fdbac8af84d9808a2892bfc911c04162115) `sha256:9f6a4881b6811824b38842ea4f69fc670d8c2c522550b6c63d1923a2177277a5`
* [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe) git [78dacb7c](https://github.com/openshift/csi-livenessprobe/commit/78dacb7c661a62c78036c2737401afd3eb6fd04d) `sha256:7dd57dd432a84e618b8578bc69ef26d169e18903177913fc6c163b63b0c1bea5`
* [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [d29f3f7a](https://github.com/openshift/csi-node-driver-registrar/commit/d29f3f7a4aed4465e7e40e323bd3c0e0d9871e4c) `sha256:dcef291564fcc330935a07a7662d19c5c4bb08126057b3f45acc0ad3d625ebd8`
* [docker-registry](https://github.com/openshift/image-registry) git [602f51c7](https://github.com/openshift/image-registry/commit/602f51c795dcdcd71c75f6abfe79dc0424a0476a) `sha256:9960ce0210902b4a564deb29e8922ae9c6ed319a557a2da09af2a68ee4319add`
* [driver-toolkit](https://github.com/openshift/driver-toolkit) git [f0ae9d12](https://github.com/openshift/driver-toolkit/commit/f0ae9d12ca7e3adf594ae34e394b1ea003daa4ad) `sha256:7beb06531fe028d1cb29447ba2d7676dd5a8bee7848e776536b865b5fbc123fe`
* [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook) git [d481e5cb](https://github.com/openshift/gcp-workload-identity-federation-webhook/commit/d481e5cb9323b01964bf143b58403b62fa31e5e7) `sha256:8e54d714d0c5a7bd8a2b8940f53cfbcb4b03d10d26dfa9182fe80d56241ad780`
* [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm) git [c566572b](https://github.com/openshift/cloud-provider-ibm/commit/c566572b2cf0120499e81181f1efb1e729e9c418) `sha256:c794012636b3291cc7dc936e22aa0213450f81ee74c870ab0a3a2f56edea5b92`
* [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator) git [00bc7407](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/commit/00bc740728d9f8ec86fe04199884108c2a091b58) `sha256:67dac077493c5333d15f2a71c9c34039110f2b5bce991c4633fc781167917e66`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [707c2262](https://github.com/openshift/ironic-rhcos-downloader/commit/707c226243ac401f2994952fe0e55823511111b0) `sha256:102a39c0233803f920c58a069bd42e34c634fcf7702a7418618bf09a75fd6ab4`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [b95b05fe](https://github.com/openshift/ironic-static-ip-manager/commit/b95b05fe0ba17255ef61e92d4167ca4c9de789b8) `sha256:3196341871d421e770e13c5963e10b3cbfe5d0794822299b08e9af5a6916a887`
* [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [cd636680](https://github.com/openshift/kube-rbac-proxy/commit/cd636680e06a55395c26570dff0cb37277014388) `sha256:1342421df8aadc795ea5dc9bf85fb0085b0e3ffe617f7f2b6ec5846c0d53a055`
* [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [ce5ff17e](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/ce5ff17e9a81ce754567e6dd5053d13409c251e9) `sha256:d5897593af2836ef17f04edfe4d7aab6b560a2300a3c87da8fcc97af68dbed3c`
* [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt) git [1e6fdd66](https://github.com/openshift/cloud-provider-kubevirt/commit/1e6fdd6615a55fc449b3e7ad2d6e92a27d30a934) `sha256:46533c0dd0b67810d6ef2f462ae1504e0a4412a212bf96c5a1129f17fb5fe693`
* [machine-image-customization-controller](https://github.com/openshift/image-customization-controller) git [65aeb360](https://github.com/openshift/image-customization-controller/commit/65aeb3607f05dd71ec27a4457945ce1e054ea9e9) `sha256:c5cb37d427974d994aceb86bb06e61ab8f548bf076aab50ec0ed14109dfba6a7`
* [metallb-frr](https://github.com/openshift/frr) git [c82bfaad](https://github.com/openshift/frr/commit/c82bfaad01b196e12f00622a9a609d87e0a56701) `sha256:2e226c73c062f79777b98f6b805cd5d4e9d42718e34677b1ed3f8266470c4e2d`
* [multus-admission-controller](https://github.com/openshift/multus-admission-controller) git [d95feb67](https://github.com/openshift/multus-admission-controller/commit/d95feb67adfb97346849c79e36b6a9d404296ae9) `sha256:28ba7b5fb1d2a356e9bd0b361fc6e1f4540c8e72cbce09f296fe2e95793bb26a`
* [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [e9f2f3c7](https://github.com/openshift/multus-networkpolicy/commit/e9f2f3c7e81683af3b8cc9a5a3166434c94e0498) `sha256:5b7de01dd531a1fdf03b01cce84eda51d7d8b3b9250e75bcb9b6aeabfc614761`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [08af4127](https://github.com/openshift/route-override-cni/commit/08af4127c77976510cad1c096d9aca977d8ae5af) `sha256:ac2f9a4d5b2938c354662d8e1c8a77b7ab79041e20b0debd11ff0e6e44977dcc`
* [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni) git [d691040e](https://github.com/openshift/whereabouts-cni/commit/d691040e509bb20c26b5e8366c0d6f3bb45a5e02) `sha256:63de97121420c04b65ed8f3cce568c86b59e7c8238e16cb742d92e6d6eb97ae2`
* [network-interface-bond-cni](https://github.com/openshift/bond-cni) git [297eeb43](https://github.com/openshift/bond-cni/commit/297eeb4320e07b18d559bc373b665479c760e8c7) `sha256:22c5d04ebf1fd613a2a0dc65d3682bfda98c1e3bb95c4625e8d2331b95cb3036`
* [network-tools](https://github.com/openshift/network-tools) git [d6717e45](https://github.com/openshift/network-tools/commit/d6717e453a098d551c9e2d2868e1f5317c41e688) `sha256:d85d182022c0ae8f0e620e58a579f67f9a4942a825a6c70cf611abf49ce4df6b`
* [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [33b7bec6](https://github.com/openshift/cloud-provider-nutanix/commit/33b7bec6fe27b8d126982a70b4579112cd67052b) `sha256:f47ad3f6af414fc2d79623a69566ce5bf55bcb7d9f179da80f60efc48611ad65`
* [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix) git [b15a665c](https://github.com/openshift/machine-api-provider-nutanix/commit/b15a665cd9c12c5a7d2ac81b5330b6f446c3a8be) `sha256:f34e7d1c35a8ea61faa7fe1da6252fcb16a35f73146573be61b2d73060cb1314`
* [oauth-apiserver](https://github.com/openshift/oauth-apiserver) git [71c41b2d](https://github.com/openshift/oauth-apiserver/commit/71c41b2d8abb0c6ad90dca286baf5d03c1340646) `sha256:9364681869b74c0e34659098894260ab09dca22b9cff57f62ec6120eb6055946`
* [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager) git [438d52e7](https://github.com/openshift/openshift-controller-manager/commit/438d52e79d691e016d66eabfe9a53c84229db40c) `sha256:a54c6df49ff424dbcd150f89219abfc9cbb0b8d140650a3dd6c6e72ed1fc8468`
* [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [ab605a4b](https://github.com/openshift/openshift-state-metrics/commit/ab605a4bf1c6cd5a6c58f245fb67ce648caebfa8) `sha256:00d40a4d03ed1e42ef86bfe876eb665b77d8edcfe712c0cb062cae28cc18f3d2`
* [operator-marketplace](https://github.com/operator-framework/operator-marketplace) git [efb1a1ea](https://github.com/operator-framework/operator-marketplace/commit/efb1a1ea40bc1ed3a439812cfdaa3013b80e96ce) `sha256:7f6c35ec5ff45fcc86ac38ef8c898f0792ab7a7a1953b19aa7371c9264deb3b5`
* [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs) git [551974ef](https://github.com/openshift/machine-api-provider-powervs/commit/551974ef93dedb1b9677a778e1533391448e0c56) `sha256:1f4364c69dd319f581bf1df8a581d01e0b3b3ec5ebd380cecb23071781430747`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [610c11b5](https://github.com/openshift/prom-label-proxy/commit/610c11b59dd17f1d6dc35b62ca1d0602b5c0f494) `sha256:129a8550013d0cfff7cc15aa75d017d4721508ba8087be9c281d0764f409c923`
* [prometheus-node-exporter](https://github.com/openshift/node_exporter) git [39d72873](https://github.com/openshift/node_exporter/commit/39d728735779afef886bc10a8bc7cf72f54d51a0) `sha256:d3e250396ddce5eab7a1fa99a5951e32c1960012634e461751987d20717428d9`
* [service-ca-operator](https://github.com/openshift/service-ca-operator) git [e9622ba1](https://github.com/openshift/service-ca-operator/commit/e9622ba18c86bf24aceab0c19fdcb87339c14f44) `sha256:ea4b6688f938f2e98f1fb4ecffe35e07a253a13046a847974af9132ce28ba63e`
* [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator) git [8b929332](https://github.com/openshift/volume-data-source-validator/commit/8b9293323cf8fdce93824e37168573ca3f73de3a) `sha256:aae1c06faf3141840a71e5cb87244440d7c35207598f9713090e06f19311a5fe`
* [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere) git [f69584d6](https://github.com/openshift/cloud-provider-vsphere/commit/f69584d6ed7411504b0fff77eb36d0fd64f0fd5e) `sha256:c30dc3588378bb510bacc19da27b14ad6ec5395a7fa492e8b0440e9a0b5b7f73`
* [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator) git [d6a19449](https://github.com/openshift/vmware-vsphere-csi-driver-operator/commit/d6a19449cc5d49541221d48d62c67d7a48142d19) `sha256:bc3fb9b04a31af78ee98904d598d1f3fe6d3566fe73c4bc466f3343def82bb30`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/bddba7290d9b08f7c0ce350e8082364819579525)
* [OCPBUGS-89984](https://issues.redhat.com/browse/OCPBUGS-89984): patching golang.org/x/crypto with sustaining/crypto@v0.48.0-sec.2 [#10793](https://github.com/openshift/assisted-service/pull/10793)
* [OCPBUGS-105879](https://issues.redhat.com/browse/OCPBUGS-105879): manifest_generator add a label to LUKS root [#10797](https://github.com/openshift/assisted-service/pull/10797)
* [OCPBUGS-92012](https://issues.redhat.com/browse/OCPBUGS-92012): Add sourcedir /run/chrony-dhcp to generated chrony.conf [#10510](https://github.com/openshift/assisted-service/pull/10510)
* [OCPBUGS-86856](https://issues.redhat.com/browse/OCPBUGS-86856): Fix loki and logging [#10425](https://github.com/openshift/assisted-service/pull/10425)
* [OCPBUGS-81843](https://issues.redhat.com/browse/OCPBUGS-81843): Mark raw FC/iSCSI multipath members as ineligible [#10148](https://github.com/openshift/assisted-service/pull/10148)
* [OCPBUGS-81843](https://issues.redhat.com/browse/OCPBUGS-81843): Prefer multipath disk in ABI disk selection [#10112](https://github.com/openshift/assisted-service/pull/10112)
* [OCPBUGS-79580](https://issues.redhat.com/browse/OCPBUGS-79580): Fix multi-document YAML parsing for NMStateConfig [#10058](https://github.com/openshift/assisted-service/pull/10058)
* [Full changelog](https://github.com/openshift/assisted-service/compare/1574e1fa7ee0118e3c2a6ca9653f4c38e6c888ac...bddba7290d9b08f7c0ce350e8082364819579525)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/c4e448f8e3c3f91d2dac98d846eb3fe400f15232)
* [OCPBUGS-104025](https://issues.redhat.com/browse/OCPBUGS-104025): Bump x/net to v0.35.0-sec.4 [#2298](https://github.com/openshift/assisted-installer/pull/2298)
* [OCPBUGS-81642](https://issues.redhat.com/browse/OCPBUGS-81642): fix: allow workers to join TNA cluster when 1 master + arbiter are ready [#2066](https://github.com/openshift/assisted-installer/pull/2066)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/58cd84e5f90dedf13c846cdbf24608583c260d1c...c4e448f8e3c3f91d2dac98d846eb3fe400f15232)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/5bf169cca60bec1ddc1bc5cf6b79b74bcfc16b2e)
* [OCPBUGS-104032](https://issues.redhat.com/browse/OCPBUGS-104032): CVE-2026-33814: replace golang.org/x/net with openshift-sustaining fork [#1621](https://github.com/openshift/assisted-installer-agent/pull/1621)
* [OCPBUGS-85041](https://issues.redhat.com/browse/OCPBUGS-85041): add --copy-network when manual network config is detected [#1446](https://github.com/openshift/assisted-installer-agent/pull/1446)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/e57138265957c81b33d3ac13078d35f6ca07069d...5bf169cca60bec1ddc1bc5cf6b79b74bcfc16b2e)
### [agent-installer-ui](https://github.com/openshift-assisted/assisted-installer-ui/tree/9569dc2c423736f6dcaf0dd24417cffe1a5db151)
* [OCPBUGS-119963](https://issues.redhat.com/browse/OCPBUGS-119963): Bump qs to >=6.16.0 in release-4.21 (#4044) [#4044](https://github.com/openshift-assisted/assisted-installer-ui/pull/4044)
* [OCPBUGS-123207](https://issues.redhat.com/browse/OCPBUGS-123207): Remove stale OCM_REFRESH_TOKEN code (#4026) [#4026](https://github.com/openshift-assisted/assisted-installer-ui/pull/4026)
* [OCPBUGS-104546](https://issues.redhat.com/browse/OCPBUGS-104546): Bump tmp to ^0.2.6 to address CVE-2026-44705 (#4015) [#4015](https://github.com/openshift-assisted/assisted-installer-ui/pull/4015)
* Update OWNERS file (#3991) [#3991](https://github.com/openshift-assisted/assisted-installer-ui/pull/3991)
* Bug OCPBUGS-100525,OCPBUGS-103013: Bump ip-address to 10.5.0 to fix CVE-2026-54272 and CVE-2026-69192 (#3986) [#3986](https://github.com/openshift-assisted/assisted-installer-ui/pull/3986)
* [OCPBUGS-109782](https://issues.redhat.com/browse/OCPBUGS-109782): Bump tar pkg to ^7.5.21 to address CVE-2026-73566 (#3971) [#3971](https://github.com/openshift-assisted/assisted-installer-ui/pull/3971)
* [OCPBUGS-104484](https://issues.redhat.com/browse/OCPBUGS-104484): Pin minimatch to ^10.2.6 and brace-expansion to ^5.0.9 (CVE-2026-14257) (#3960) [#3960](https://github.com/openshift-assisted/assisted-installer-ui/pull/3960)
* move @types/react-dom to dependencies to fix Hermeto (#3956) [#3956](https://github.com/openshift-assisted/assisted-installer-ui/pull/3956)
* [OCPBUGS-99307](https://issues.redhat.com/browse/OCPBUGS-99307): 4.21 agent-installer OVE installation fails due to custom-manifests (#3914) [#3914](https://github.com/openshift-assisted/assisted-installer-ui/pull/3914)
* [OCPBUGS-91632](https://issues.redhat.com/browse/OCPBUGS-91632): Bump ws to 8.21.0 for CVE-2026-45736 (#3905) [#3905](https://github.com/openshift-assisted/assisted-installer-ui/pull/3905)
* [OCPBUGS-98269](https://issues.redhat.com/browse/OCPBUGS-98269): Bump tar to 7.5.19 in 4.21 (#3893) [#3893](https://github.com/openshift-assisted/assisted-installer-ui/pull/3893)
* [OCPBUGS-98435](https://issues.redhat.com/browse/OCPBUGS-98435): Bump js-yaml to 4.3.0 in 4.21 (#3877) [#3877](https://github.com/openshift-assisted/assisted-installer-ui/pull/3877)
* [OCPBUGS-89700](https://issues.redhat.com/browse/OCPBUGS-89700): bump form-data to 2.5.6 and 4.0.6 via scoped resolutions to address CVE-2026-12143 (#3878) [#3878](https://github.com/openshift-assisted/assisted-installer-ui/pull/3878)
* Update OWNERS file (#3882) [#3882](https://github.com/openshift-assisted/assisted-installer-ui/pull/3882)
* Apply patches (#3875) [#3875](https://github.com/openshift-assisted/assisted-installer-ui/pull/3875)
* patch CVE-2026-9277 and CVE-2026-42338 via yarn resolutions (#3853) [#3853](https://github.com/openshift-assisted/assisted-installer-ui/pull/3853)
* [OCPBUGS-88390](https://issues.redhat.com/browse/OCPBUGS-88390), [OCPBUGS-88411](https://issues.redhat.com/browse/OCPBUGS-88411): Bump axios to 1.18.1 (#3858) [#3858](https://github.com/openshift-assisted/assisted-installer-ui/pull/3858)
* prefill staticip on ove below the sea (#3769) [#3769](https://github.com/openshift-assisted/assisted-installer-ui/pull/3769)
* Custom manifests are broken in local Assisted UI (#3770) [#3770](https://github.com/openshift-assisted/assisted-installer-ui/pull/3770)
* Operators section should not be displayed on review and installation progress pages when no operators are selected (#3751) [#3751](https://github.com/openshift-assisted/assisted-installer-ui/pull/3751)
* Remove Arbiter button (#3749) [#3749](https://github.com/openshift-assisted/assisted-installer-ui/pull/3749)
* [OCPBUGS-85541](https://issues.redhat.com/browse/OCPBUGS-85541): Bump msw pkg version to 2.13.5 (#3729) [#3729](https://github.com/openshift-assisted/assisted-installer-ui/pull/3729)
* fix monted pull secret parsing (#3727) [#3727](https://github.com/openshift-assisted/assisted-installer-ui/pull/3727)
* [OCPBUGS-84235](https://issues.redhat.com/browse/OCPBUGS-84235): add pull secret auto populate logic to ABI local UI (#3509) [#3509](https://github.com/openshift-assisted/assisted-installer-ui/pull/3509)
* Allow to install SNO topology (#3722) [#3722](https://github.com/openshift-assisted/assisted-installer-ui/pull/3722)
* [OCPBUGS-85261](https://issues.redhat.com/browse/OCPBUGS-85261): [release-4.21] OCPBUGS-84147 | [Below the sea UI] Leaky Abstraction: Transient 500 errors exposed during host binding process (#3684) [#3684](https://github.com/openshift-assisted/assisted-installer-ui/pull/3684)
* Remove 2 node arbiter option from the control plane dropdown option (#3680) [#3680](https://github.com/openshift-assisted/assisted-installer-ui/pull/3680)
* [OCPBUGS-84608](https://issues.redhat.com/browse/OCPBUGS-84608), [OCPBUGS-84830](https://issues.redhat.com/browse/OCPBUGS-84830), [OCPBUGS-84993](https://issues.redhat.com/browse/OCPBUGS-84993), [OCPBUGS-85009](https://issues.redhat.com/browse/OCPBUGS-85009), [OCPBUGS-85039](https://issues.redhat.com/browse/OCPBUGS-85039): Bump axios to ^1.15.1 (#3690) [#3690](https://github.com/openshift-assisted/assisted-installer-ui/pull/3690)
* [MGMT-24152](https://issues.redhat.com/browse/MGMT-24152): UI allows editing pull secret in draft cluster (#3674) [#3674](https://github.com/openshift-assisted/assisted-installer-ui/pull/3674)
* Update OWNERS file (#3654) [#3654](https://github.com/openshift-assisted/assisted-installer-ui/pull/3654)
* Bump happy-dom from 20.0.2 to 20.8.9 (#3525) [#3525](https://github.com/openshift-assisted/assisted-installer-ui/pull/3525)
* fix operators list in ABI below the sea (#3599) [#3599](https://github.com/openshift-assisted/assisted-installer-ui/pull/3599)
* [OCPBUGS-81589](https://issues.redhat.com/browse/OCPBUGS-81589): bump react-router-dom-v5-compat to ^6.30.3 to address CVE-2026-22029 (#3581) [#3581](https://github.com/openshift-assisted/assisted-installer-ui/pull/3581)
* [OCPBUGS-83303](https://issues.redhat.com/browse/OCPBUGS-83303): bump axios to ^1.15.0 for fixing CVE-2026-40175 (#3583) [#3583](https://github.com/openshift-assisted/assisted-installer-ui/pull/3583)
* [OCPBUGS-81587](https://issues.redhat.com/browse/OCPBUGS-81587): upgrade lodash and lodash-es to 4.17.23 to address CVE-2025-13465 (#3535) [#3535](https://github.com/openshift-assisted/assisted-installer-ui/pull/3535)
* Add support for release branches in PR workflow (#3528) [#3528](https://github.com/openshift-assisted/assisted-installer-ui/pull/3528)
* populate default values in local ui from infraEnv (#3503) [#3503](https://github.com/openshift-assisted/assisted-installer-ui/pull/3503)
* [Full changelog](https://github.com/openshift-assisted/assisted-installer-ui/compare/479a68f329b4c4088a999a6f4f1c4a078a9b4e93...9569dc2c423736f6dcaf0dd24417cffe1a5db151)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/cc8ca89bc5a0ce79227e8ab0860693950608ca04)
* [OCPBUGS-105452](https://issues.redhat.com/browse/OCPBUGS-105452): Update Konflux references [#335](https://github.com/openshift/agent-installer-utils/pull/335)
* [OCPBUGS-101761](https://issues.redhat.com/browse/OCPBUGS-101761): Update Konflux references [#330](https://github.com/openshift/agent-installer-utils/pull/330)
* [OCPBUGS-100311](https://issues.redhat.com/browse/OCPBUGS-100311): Update Konflux release version to 4.21.27 [#326](https://github.com/openshift/agent-installer-utils/pull/326)
* [OCPBUGS-99907](https://issues.redhat.com/browse/OCPBUGS-99907): Update Konflux references [#304](https://github.com/openshift/agent-installer-utils/pull/304)
* [OCPBUGS-99647](https://issues.redhat.com/browse/OCPBUGS-99647): Use agent-preinstall-image-builder from quay-proxy [#322](https://github.com/openshift/agent-installer-utils/pull/322)
* [OCPBUGS-98628](https://issues.redhat.com/browse/OCPBUGS-98628): Increase time for Konflux on-push job [#318](https://github.com/openshift/agent-installer-utils/pull/318)
* [OCPBUGS-98628](https://issues.redhat.com/browse/OCPBUGS-98628): Increase resources for syft [#317](https://github.com/openshift/agent-installer-utils/pull/317)
* [OCPBUGS-98628](https://issues.redhat.com/browse/OCPBUGS-98628): Update Konflux version to 4.21.24 [#314](https://github.com/openshift/agent-installer-utils/pull/314)
* [OCPBUGS-84120](https://issues.redhat.com/browse/OCPBUGS-84120): Update OCP version for Konflux [#301](https://github.com/openshift/agent-installer-utils/pull/301)
* [OCPBUGS-85526](https://issues.redhat.com/browse/OCPBUGS-85526): update konflux references [#287](https://github.com/openshift/agent-installer-utils/pull/287)
* [OCPBUGS-83852](https://issues.redhat.com/browse/OCPBUGS-83852): Pass environment through to podman [#292](https://github.com/openshift/agent-installer-utils/pull/292)
* [OCPBUGS-82588](https://issues.redhat.com/browse/OCPBUGS-82588): Update OCP version in Konflux [#285](https://github.com/openshift/agent-installer-utils/pull/285)
* [OCPBUGS-82539](https://issues.redhat.com/browse/OCPBUGS-82539): Update Konflux references [#265](https://github.com/openshift/agent-installer-utils/pull/265)
* [OCPBUGS-81645](https://issues.redhat.com/browse/OCPBUGS-81645): Update operator versions [#282](https://github.com/openshift/agent-installer-utils/pull/282)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/78ce8714080ef537e56d6b199f3a2d1e0dc74f0e...cc8ca89bc5a0ce79227e8ab0860693950608ca04)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/2932c37fdd58de0c01f29a1e7c1531fd7e4395ee)
* π [release-4.21] OCPBUGS-81976: Bump go-jose/go-jose/v4@v4.1.4 [#609](https://github.com/openshift/cluster-api-provider-aws/pull/609)
* π OCPBUGS-112498: UPSTREAM: 6132: Persist ProviderID immediately after instance creation [#627](https://github.com/openshift/cluster-api-provider-aws/pull/627)
* π OCPBUGS-121766: UPSTREAM: <carry>: Fix unit tests for OpenShift CI environment [#628](https://github.com/openshift/cluster-api-provider-aws/pull/628)
* π± [release-4.21] OCPBUGS-120321: UPSTREAM: <carry>: Remove upstream .github files unused in OpenShift CI [#635](https://github.com/openshift/cluster-api-provider-aws/pull/635)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/10ceef5e6f6d0cb79a3345de4fd8851f6300205c...2932c37fdd58de0c01f29a1e7c1531fd7e4395ee)
### [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver/tree/1d8cec7d0eeedf1497c3ee6c32ee3391ebb13709)
* [OCPBUGS-80734](https://issues.redhat.com/browse/OCPBUGS-80734): Bump google.golang.org/grpc to v1.79.3 [#310](https://github.com/openshift/aws-ebs-csi-driver/pull/310)
* [Full changelog](https://github.com/openshift/aws-ebs-csi-driver/compare/57eebffcc8abbbbb6edcf3b536b769d97e31819c...1d8cec7d0eeedf1497c3ee6c32ee3391ebb13709)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, csi-driver-manila-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/a52a578c6aea1ac5da131f60b8e359969151d7e1)
* [OCPBUGS-104051](https://issues.redhat.com/browse/OCPBUGS-104051): CVE-2026-33814: replace golang.org/x/net with openshift-sustaining fork [#613](https://github.com/openshift/csi-operator/pull/613)
* [OCPBUGS-109655](https://issues.redhat.com/browse/OCPBUGS-109655): csi-driver-smb: DeleteVolume call fails to mkdir under /tmp [#598](https://github.com/openshift/csi-operator/pull/598)
* [OCPBUGS-85572](https://issues.redhat.com/browse/OCPBUGS-85572): Add init container for Manila node daemonset [#554](https://github.com/openshift/csi-operator/pull/554)
* [OCPBUGS-85234](https://issues.redhat.com/browse/OCPBUGS-85234): Mount writable /tmp in SMB CSI driver [#551](https://github.com/openshift/csi-operator/pull/551)
* [OCPBUGS-80844](https://issues.redhat.com/browse/OCPBUGS-80844): Bump google.golang.org/grpc to v1.79.3 [#539](https://github.com/openshift/csi-operator/pull/539)
* [Full changelog](https://github.com/openshift/csi-operator/compare/181ea25a74b12d1641ef2e0021228311e56626de...a52a578c6aea1ac5da131f60b8e359969151d7e1)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/f4af9b89aed3a47b2168d7bd5a7dd8b6453f1945)
* [OCPBUGS-104008](https://issues.redhat.com/browse/OCPBUGS-104008): Fix CVE-2026-33814 [#36](https://github.com/openshift/aws-karpenter-provider-aws/pull/36)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/ff9c8d4e8fdc55d3e60c6add0942c018826ae870...f4af9b89aed3a47b2168d7bd5a7dd8b6453f1945)
### [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider/tree/887615ffa8a595ee3693e92fa56db4dd30f20f73)
* [OCPBUGS-80711](https://issues.redhat.com/browse/OCPBUGS-80711): Bump google.golang.org/grpc to v1.79.3 [#40](https://github.com/openshift/aws-encryption-provider/pull/40)
* [Full changelog](https://github.com/openshift/aws-encryption-provider/compare/19e7b623429799c9c549690a1b5ab499844411f9...887615ffa8a595ee3693e92fa56db4dd30f20f73)
### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/53d73b17f0209026eef63d68e39faf195472adf5)
* [OCPBUGS-104016](https://issues.redhat.com/browse/OCPBUGS-104016), [OCPBUGS-104207](https://issues.redhat.com/browse/OCPBUGS-104207): Replace golang.org/x/net with github.com/openshift-sustaining/net@v0.50.0-sec.3 to address CVE-2026-33814 [#205](https://github.com/openshift/cloud-provider-azure/pull/205)
* [OCPBUGS-80738](https://issues.redhat.com/browse/OCPBUGS-80738), [OCPBUGS-80739](https://issues.redhat.com/browse/OCPBUGS-80739): Bump google.golang.org/grpc to v1.79.3 [#178](https://github.com/openshift/cloud-provider-azure/pull/178)
* [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/83b3f9ec7df408c3d53d5f8e6fe84e0bdd4398e8...53d73b17f0209026eef63d68e39faf195472adf5)
### [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure/tree/3ae65a465e6da7d92ecec285fe8543acd8bb3dd4)
* [OCPBUGS-89991](https://issues.redhat.com/browse/OCPBUGS-89991): Address CVE-2026-39829 [#398](https://github.com/openshift/cluster-api-provider-azure/pull/398)
* [OCPBUGS-80740](https://issues.redhat.com/browse/OCPBUGS-80740): Bump google.golang.org/grpc to v1.79.3 [#383](https://github.com/openshift/cluster-api-provider-azure/pull/383)
* [Full changelog](https://github.com/openshift/cluster-api-provider-azure/compare/5d6af81d7ab9b289c3def6c0350313118d63923a...3ae65a465e6da7d92ecec285fe8543acd8bb3dd4)
### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/8318a54892a51c76e3233e2fd60fb5d499afb6dc)
* [OCPBUGS-96484](https://issues.redhat.com/browse/OCPBUGS-96484): Bump golang.org/x/net to v0.55.0 [#166](https://github.com/openshift/azure-disk-csi-driver/pull/166)
* [OCPBUGS-85285](https://issues.redhat.com/browse/OCPBUGS-85285): check for node name in waitForDiskManagedByTobeRemoved [#147](https://github.com/openshift/azure-disk-csi-driver/pull/147)
* UPSTREAM: 3569: OCPBUGS-80741: Bump grpc to v1.79.3 [#137](https://github.com/openshift/azure-disk-csi-driver/pull/137)
* [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/30e9538b918b1a43ea613832a4be305576dcbae4...8318a54892a51c76e3233e2fd60fb5d499afb6dc)
### [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver/tree/c0415d38bb792e507e0d2346b44d057ab7b2e024)
* [OCPBUGS-104045](https://issues.redhat.com/browse/OCPBUGS-104045): Bump golang.org/x/net to v0.50.0-sec.4 [#155](https://github.com/openshift/azure-file-csi-driver/pull/155)
* [OCPBUGS-111837](https://issues.redhat.com/browse/OCPBUGS-111837): fix failing unit tests in azure-file-csi-driver [#152](https://github.com/openshift/azure-file-csi-driver/pull/152)
* [OCPBUGS-92988](https://issues.redhat.com/browse/OCPBUGS-92988): Bump golang.org/x/crypto to v0.48.0-sec.1 [#145](https://github.com/openshift/azure-file-csi-driver/pull/145)
* UPSTREAM: 3023: OCPBUGS-80744: Bump grpc to v1.79.3 [#125](https://github.com/openshift/azure-file-csi-driver/pull/125)
* [Full changelog](https://github.com/openshift/azure-file-csi-driver/compare/c77d75f90b7f84dfc25ba3439bc5eff87c3a2755...c0415d38bb792e507e0d2346b44d057ab7b2e024)
### [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms/tree/97a682d9baff04f7c873ae378dee4afb6b697252)
* [OCPBUGS-104007](https://issues.redhat.com/browse/OCPBUGS-104007): [release-4.21] Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [#58](https://github.com/openshift/azure-kubernetes-kms/pull/58)
* [OCPBUGS-80712](https://issues.redhat.com/browse/OCPBUGS-80712): Bump google.golang.org/grpc to 1.64.1-sec.1 patch [#34](https://github.com/openshift/azure-kubernetes-kms/pull/34)
* [Full changelog](https://github.com/openshift/azure-kubernetes-kms/compare/fe1d311ba5aadc40b5f48d47d43175157a73c881...97a682d9baff04f7c873ae378dee4afb6b697252)
### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/65ba1a8d7133b2947eec2fe16e43de0134921e03)
* [OCPBUGS-104120](https://issues.redhat.com/browse/OCPBUGS-104120): replace golang.org/x/net with openshift-sustaining/net@v0.50.0-sec.4 [#210](https://github.com/openshift/machine-api-provider-azure/pull/210)
* [PIXAA-7](https://issues.redhat.com/browse/PIXAA-7): Leverage SpotRebalanceRecommendation for instance termination when available [#199](https://github.com/openshift/machine-api-provider-azure/pull/199)
* [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/b8b8cb1c5af7d2a3ef9a4a99a0739a2166a7932c...65ba1a8d7133b2947eec2fe16e43de0134921e03)
### [azure-service-operator](https://github.com/openshift/azure-service-operator/tree/5e84c83176d7630f70802b35cb10cdf2b60fd6d3)
* [OCPBUGS-80713](https://issues.redhat.com/browse/OCPBUGS-80713): Bump google.golang.org/grpc to v1.79.3 [#28](https://github.com/openshift/azure-service-operator/pull/28)
* [OCPBUGS-83864](https://issues.redhat.com/browse/OCPBUGS-83864): UPSTREAM: <carry>: add openshift/e2e-tests.sh [#24](https://github.com/openshift/azure-service-operator/pull/24)
* [Full changelog](https://github.com/openshift/azure-service-operator/compare/17e574628ee7ef8aa694cfc0ab5e5232b651fbf8...5e84c83176d7630f70802b35cb10cdf2b60fd6d3)
### [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity/tree/ae8ffaf0b4a893e9b38fb4007de3cef8492b71f3)
* [OCPBUGS-81978](https://issues.redhat.com/browse/OCPBUGS-81978): Bump go-jose/go-jose/v4@v4.1.4 [#50](https://github.com/openshift/azure-workload-identity/pull/50)
* [Full changelog](https://github.com/openshift/azure-workload-identity/compare/3f2a6e0d1ea68af321f9674b0b097939be7d2014...ae8ffaf0b4a893e9b38fb4007de3cef8492b71f3)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/006669f5812a47dbc733b6736584b87ef696e898)
* [OCPBUGS-90031](https://issues.redhat.com/browse/OCPBUGS-90031), [OCPBUGS-92990](https://issues.redhat.com/browse/OCPBUGS-92990): Replace golang.org/x/crypto with github.com/openshift-sustaining/crypto v0.48.0-sec.2 [#10820](https://github.com/openshift/installer/pull/10820)
* [OCPBUGS-100062](https://issues.redhat.com/browse/OCPBUGS-100062): openstack: Reserve addresses for load balancer [#10724](https://github.com/openshift/installer/pull/10724)
* [OCPBUGS-112472](https://issues.redhat.com/browse/OCPBUGS-112472): Update timeout in GetMarketplaceImage to 5 minutes [#10785](https://github.com/openshift/installer/pull/10785)
* [OCPBUGS-104042](https://issues.redhat.com/browse/OCPBUGS-104042): Bump golang.org/x/net to v0.50.0-sec.4 [#10806](https://github.com/openshift/installer/pull/10806)
* [OCPBUGS-113535](https://issues.redhat.com/browse/OCPBUGS-113535): Update RHCOS-release-4.21 bootimage metadata to 9.6.20260815-0 [#10792](https://github.com/openshift/installer/pull/10792)
* [OCPBUGS-87813](https://issues.redhat.com/browse/OCPBUGS-87813): [release-4.21] fix: reset associatedVCenter in failure domain validation loop [#10605](https://github.com/openshift/installer/pull/10605)
* [OCPBUGS-112029](https://issues.redhat.com/browse/OCPBUGS-112029): Bump google-cloud-cli to 563.0.0-1 [#10769](https://github.com/openshift/installer/pull/10769)
* [OCPBUGS-76552](https://issues.redhat.com/browse/OCPBUGS-76552): Revert storage account API version for client [#10296](https://github.com/openshift/installer/pull/10296)
* [OCPBUGS-87815](https://issues.redhat.com/browse/OCPBUGS-87815): [release-4.21] Add omitempty to vSphere and Nutanix MachinePool slice fields [#10607](https://github.com/openshift/installer/pull/10607)
* [OCPBUGS-88740](https://issues.redhat.com/browse/OCPBUGS-88740): Update RHCOS-release-4.21 data/data/coreos/rhcos.json to 9.6.20260616-0 [#10651](https://github.com/openshift/installer/pull/10651)
* [OCPBUGS-81986](https://issues.redhat.com/browse/OCPBUGS-81986): Bump go-jose/v4 to 4.1.4 [#10598](https://github.com/openshift/installer/pull/10598)
* [OCPBUGS-77049](https://issues.redhat.com/browse/OCPBUGS-77049): Update RHCOS-release-4.21 bootimage metadata to 9.6.20260520-0 [#10579](https://github.com/openshift/installer/pull/10579)
* [OCPBUGS-82068](https://issues.redhat.com/browse/OCPBUGS-82068): Azure: Sign blob container using user delegated creds [#10465](https://github.com/openshift/installer/pull/10465)
* [OCPBUGS-84225](https://issues.redhat.com/browse/OCPBUGS-84225): ibmcloud: bump vpc-go-sdk and capibm [#10514](https://github.com/openshift/installer/pull/10514)
* [OCPBUGS-82439](https://issues.redhat.com/browse/OCPBUGS-82439): [release-4.21] Mount pullsecret manifest to UI container [#10489](https://github.com/openshift/installer/pull/10489)
* [OCPBUGS-79074](https://issues.redhat.com/browse/OCPBUGS-79074): [release 4.21] - Allow all instance types in the install config for GCP [#10417](https://github.com/openshift/installer/pull/10417)
* [OCPBUGS-79378](https://issues.redhat.com/browse/OCPBUGS-79378): Use correct Project ID with GCP Shared VPC [#10423](https://github.com/openshift/installer/pull/10423)
* [Full changelog](https://github.com/openshift/installer/compare/7d1b7c2bb80b61eb26df7f7e64a5a5e98acb6401...006669f5812a47dbc733b6736584b87ef696e898)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/d5c58b32e71e0e979e190b40a3804d012509d93b)
* [OCPBUGS-97982](https://issues.redhat.com/browse/OCPBUGS-97982): Add BMH finalizer on PreprovisioningImage [#506](https://github.com/openshift/baremetal-operator/pull/506)
* [OCPBUGS-87964](https://issues.redhat.com/browse/OCPBUGS-87964): Fix preprovisioning network Secret lifecycle during BMH deletion [#492](https://github.com/openshift/baremetal-operator/pull/492)
* [OCPBUGS-82141](https://issues.redhat.com/browse/OCPBUGS-82141): Fix PPI for ACM [#476](https://github.com/openshift/baremetal-operator/pull/476)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/9b3a716e8e4809b40f79627dd2a5deb365e088d9...d5c58b32e71e0e979e190b40a3804d012509d93b)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/d0bf7cc5959bf8408912e5276f2ea9e269ede24d)
* [OCPBUGS-104179](https://issues.redhat.com/browse/OCPBUGS-104179): [release-4.21] Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [#2379](https://github.com/openshift/oc/pull/2379)
* Fix for OCPBUGS-88239: CVE-2026-39821 [#2361](https://github.com/openshift/oc/pull/2361)
* [OCPBUGS-98550](https://issues.redhat.com/browse/OCPBUGS-98550): Revert pull request 2310 [#2348](https://github.com/openshift/oc/pull/2348)
* [OCPBUGS-98550](https://issues.redhat.com/browse/OCPBUGS-98550): bump x/crypto to the latest version [#2310](https://github.com/openshift/oc/pull/2310)
* [OCPBUGS-81981](https://issues.redhat.com/browse/OCPBUGS-81981): Bump go-jose/go-jose/v4 to v4.1.4 [#2271](https://github.com/openshift/oc/pull/2271)
* [MCO-1961](https://issues.redhat.com/browse/MCO-1961): Allow multiple machine-os versions [#2244](https://github.com/openshift/oc/pull/2244)
* [COS-4005](https://issues.redhat.com/browse/COS-4005): Allow periods in display name labels for version validation [#2243](https://github.com/openshift/oc/pull/2243)
* [Full changelog](https://github.com/openshift/oc/compare/56a56a3a76474ed4329fff4fc9958e2c60c3ab3f...d0bf7cc5959bf8408912e5276f2ea9e269ede24d)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/bd0a5785a37eeccedb3ba357eb4254860acd6ef4)
* NO-JIRA: Revert "OCPBUGS-87110 Scope minted AWS IAM policies to cluster-owned resources" [#1060](https://github.com/openshift/cloud-credential-operator/pull/1060)
* [OCPBUGS-87110](https://issues.redhat.com/browse/OCPBUGS-87110): Scope minted AWS IAM policies to cluster-owned resources [#1046](https://github.com/openshift/cloud-credential-operator/pull/1046)
* [OCPBUGS-81982](https://issues.redhat.com/browse/OCPBUGS-81982): Bump go-jose/go-jose/v4@v4.1.4 [#1027](https://github.com/openshift/cloud-credential-operator/pull/1027)
* [OCPBUGS-79367](https://issues.redhat.com/browse/OCPBUGS-79367): google.golang.org/grpc v1.79.3 [#993](https://github.com/openshift/cloud-credential-operator/pull/993)
* [OCPBUGS-78199](https://issues.redhat.com/browse/OCPBUGS-78199): Fix infrastructure resource name filtering in watch predicate [#988](https://github.com/openshift/cloud-credential-operator/pull/988)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/0c51a1b875a53fc5dda059789c3ec8a5d2212114...bd0a5785a37eeccedb3ba357eb4254860acd6ef4)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/419ef9d44ad0e63927900add4a90fcb9a9fce3d0)
* [OCPBUGS-104035](https://issues.redhat.com/browse/OCPBUGS-104035): Bump golang.org/x/net from v0.43.0 to v0.50.0-sec.4 [#980](https://github.com/openshift/cluster-authentication-operator/pull/980)
* [OCPBUGS-81677](https://issues.redhat.com/browse/OCPBUGS-81677): Do not return error when an IdP returns 500 during a grant check [#868](https://github.com/openshift/cluster-authentication-operator/pull/868)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/d235c0bb7443119e12ec2c8db57035f652f1d871...419ef9d44ad0e63927900add4a90fcb9a9fce3d0)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/a921db0077641ab179c3048c9b5d21f54bb36e55)
* [OCPBUGS-109654](https://issues.redhat.com/browse/OCPBUGS-109654): UPSTREAM: 9458: fix(clusterapi): use kind-aware version discovery for infra references [#436](https://github.com/openshift/kubernetes-autoscaler/pull/436)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/838a5957d0bebc33c7a0a8a7efd4f5dcb4098286...a921db0077641ab179c3048c9b5d21f54bb36e55)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/b2423439fe1004bae5e84500cf449d033c1f0378)
* [OCPBUGS-104038](https://issues.redhat.com/browse/OCPBUGS-104038): Bump x/net package in release-4.21 [#386](https://github.com/openshift/cluster-autoscaler-operator/pull/386)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/dec12ba632a4810b4ff43a9172f462a1dd291e44...b2423439fe1004bae5e84500cf449d033c1f0378)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/13af370f526ab7541a8a73aa0d94952496ccca58)
* [OCPBUGS-88481](https://issues.redhat.com/browse/OCPBUGS-88481): Fix empty IRONIC_BASE_URL [#614](https://github.com/openshift/cluster-baremetal-operator/pull/614)
* [OCPBUGS-78580](https://issues.redhat.com/browse/OCPBUGS-78580): Allow ProvisioningCIDR for unmanaged network [#576](https://github.com/openshift/cluster-baremetal-operator/pull/576)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/e01ffcf3dc86dfea4646ca71a78b17cc9a740d80...13af370f526ab7541a8a73aa0d94952496ccca58)
### [cluster-capi-controllers](https://github.com/openshift/cluster-api/tree/9dd5eba07922bb84bf1ec2b16cbbedd6ad195874)
* [OCPBUGS-80749](https://issues.redhat.com/browse/OCPBUGS-80749): Bump google.golang.org/grpc to v1.79.3 [#293](https://github.com/openshift/cluster-api/pull/293)
* [Full changelog](https://github.com/openshift/cluster-api/compare/a957484acb353220da0d3062867168d24494a2b6...9dd5eba07922bb84bf1ec2b16cbbedd6ad195874)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/87a6893e678af405043625bc3a209b30836f299f)
* [OCPBUGS-104049](https://issues.redhat.com/browse/OCPBUGS-104049): Bump golang.org/x/net to v0.50.0-sec.3 [#662](https://github.com/openshift/cluster-capi-operator/pull/662)
* NO-JIRA: Allow sustaining engineering to self serve dependency updates [#554](https://github.com/openshift/cluster-capi-operator/pull/554)
* [OCPBUGS-80753](https://issues.redhat.com/browse/OCPBUGS-80753): Bump google.golang.org/grpc to v1.79.3 [#550](https://github.com/openshift/cluster-capi-operator/pull/550)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/80728a61725bb6ec7f4515c2ac2b3a249f3c5742...87a6893e678af405043625bc3a209b30836f299f)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/c050cf15d939b1456e99caa71a46fb797d7b56c1)
* [OCPBUGS-82034](https://issues.redhat.com/browse/OCPBUGS-82034): Add delete permission for Azure load balancers in credentials request [#441](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/441)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/6148c0cca626bcf0bfebcc6dd0c77a41944cba87...c050cf15d939b1456e99caa71a46fb797d7b56c1)
### [cluster-config-api](https://github.com/openshift/api/tree/1cb630ce7109e6c4780332bb8140c8c4f7157426)
* [OCPBUGS-98251](https://issues.redhat.com/browse/OCPBUGS-98251): add new serviceAccountToken fs type [#2924](https://github.com/openshift/api/pull/2924)
* [OCPBUGS-78330](https://issues.redhat.com/browse/OCPBUGS-78330), [OCPBUGS-82146](https://issues.redhat.com/browse/OCPBUGS-82146), [OCPBUGS-85550](https://issues.redhat.com/browse/OCPBUGS-85550), [OCPBUGS-88295](https://issues.redhat.com/browse/OCPBUGS-88295), [OCPBUGS-88297](https://issues.redhat.com/browse/OCPBUGS-88297): NE-2480: Promote GatewayAPIWithoutOLM feature gate to Default [#2865](https://github.com/openshift/api/pull/2865)
* [OCPBUGS-78330](https://issues.redhat.com/browse/OCPBUGS-78330), [OCPBUGS-82146](https://issues.redhat.com/browse/OCPBUGS-82146), [OCPBUGS-85550](https://issues.redhat.com/browse/OCPBUGS-85550), [OCPBUGS-88295](https://issues.redhat.com/browse/OCPBUGS-88295), [OCPBUGS-88297](https://issues.redhat.com/browse/OCPBUGS-88297): Promote GatewayAPIWithoutOLM feature gate to TechPreview [#2873](https://github.com/openshift/api/pull/2873)
* [OCPBUGS-85149](https://issues.redhat.com/browse/OCPBUGS-85149): Backport GatewayAPIWithoutOLM feature gate as disabled [#2864](https://github.com/openshift/api/pull/2864)
* [OCPBUGS-86493](https://issues.redhat.com/browse/OCPBUGS-86493): Add labelSelector to MachineSet status for scale subresource [#2857](https://github.com/openshift/api/pull/2857)
* [OCPBUGS-83756](https://issues.redhat.com/browse/OCPBUGS-83756): fix(config/v1): define constants for authentication types as typed constants [#2815](https://github.com/openshift/api/pull/2815)
* [CNTRLPLANE-2796](https://issues.redhat.com/browse/CNTRLPLANE-2796): promote the event-ttl feature [#2809](https://github.com/openshift/api/pull/2809)
* [OCPBUGS-82578](https://issues.redhat.com/browse/OCPBUGS-82578): [release-4.21] postpone the removal of the DeploymentConfig API [#2801](https://github.com/openshift/api/pull/2801)
* [Full changelog](https://github.com/openshift/api/compare/b0658d22beea435e3a576165207416842cb2753b...1cb630ce7109e6c4780332bb8140c8c4f7157426)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/c4fdb41e357280bfa7e8ebbc934007a657168310)
* [OCPBUGS-90510](https://issues.redhat.com/browse/OCPBUGS-90510): Fixed issue where nameserver is not set when recreating cpms [#411](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/411)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/2dde33fb94aae47b460a5f6a672d06c9ee4225d8...c4fdb41e357280bfa7e8ebbc934007a657168310)
### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/eb43a7a80d1b314eb8bbe63b6b73de91ba8cc7aa)
* [OCPBUGS-104057](https://issues.redhat.com/browse/OCPBUGS-104057): CVE-2026-33814: replace golang.org/x/net with openshift-sustaining fork [#296](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/296)
* [OCPBUGS-82971](https://issues.redhat.com/browse/OCPBUGS-82971): Fix PDB unhealthyPodEvictionPolicy field name [#272](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/272)
* [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/43ad01e88038be54792f16f0d692b96da1244404...eb43a7a80d1b314eb8bbe63b6b73de91ba8cc7aa)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/1cad682c3cdb0db2bd19c4cba27098703477734f)
* [OCPBUGS-100121](https://issues.redhat.com/browse/OCPBUGS-100121): Revert 'OCPBUGS-88490: fix etcd operator deadlock when etcd-endpoints configmap is stale' [#1662](https://github.com/openshift/cluster-etcd-operator/pull/1662)
* [OCPBUGS-90543](https://issues.redhat.com/browse/OCPBUGS-90543): fix etcd operator deadlock when etcd-endpoints configmap is stale [#1637](https://github.com/openshift/cluster-etcd-operator/pull/1637)
* [OCPBUGS-84336](https://issues.redhat.com/browse/OCPBUGS-84336): fix(tnf): gate dual-replica setup and keep retrying [#1620](https://github.com/openshift/cluster-etcd-operator/pull/1620)
* [OCPBUGS-84336](https://issues.redhat.com/browse/OCPBUGS-84336): fix(tnf): align Pacemaker kubelet and etcd retry pacing [#1604](https://github.com/openshift/cluster-etcd-operator/pull/1604)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/5c38f917a43058c73479673a05d4e782524a3a41...1cad682c3cdb0db2bd19c4cba27098703477734f)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/044fc0bce30bed270732f61213e2895d667ebf87)
* [OCPBUGS-75001](https://issues.redhat.com/browse/OCPBUGS-75001): Backport Azure ARM SDK migration and Azure Stack Hub compatibility [#1303](https://github.com/openshift/cluster-image-registry-operator/pull/1303)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/b2dfc3bba3dfd8dba90918a4a3be74deb3c548dd...044fc0bce30bed270732f61213e2895d667ebf87)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/f30c6160c94034639739df5ce940d60d1d7c028a)
* [OCPBUGS-93736](https://issues.redhat.com/browse/OCPBUGS-93736): Guard OLM subscription lookup with capability check [#1490](https://github.com/openshift/cluster-ingress-operator/pull/1490)
* [OCPBUGS-104065](https://issues.redhat.com/browse/OCPBUGS-104065): Replace golang.org/x/net with github.com/openshift-sustaining/net v0.50.0-sec.3 to mitigate CVE-2026-33814 [#1554](https://github.com/openshift/cluster-ingress-operator/pull/1554)
* [OCPBUGS-99453](https://issues.redhat.com/browse/OCPBUGS-99453): Respect proxy configuration on gwapi provisioning [#1518](https://github.com/openshift/cluster-ingress-operator/pull/1518)
* [OCPBUGS-99909](https://issues.redhat.com/browse/OCPBUGS-99909): E2E test for internal LoadBalancer Annotations [#1525](https://github.com/openshift/cluster-ingress-operator/pull/1525)
* [OCPBUGS-99483](https://issues.redhat.com/browse/OCPBUGS-99483): Add e2e test for Gateway API infrastructure annotations [#1520](https://github.com/openshift/cluster-ingress-operator/pull/1520)
* [OCPBUGS-94189](https://issues.redhat.com/browse/OCPBUGS-94189): Add INFO logs alongside event recorder calls [#1489](https://github.com/openshift/cluster-ingress-operator/pull/1489)
* [OCPBUGS-98966](https://issues.redhat.com/browse/OCPBUGS-98966): Bump Istio version from v1.27.3 to v1.27.8 [#1509](https://github.com/openshift/cluster-ingress-operator/pull/1509)
* [OCPBUGS-78330](https://issues.redhat.com/browse/OCPBUGS-78330), [OCPBUGS-82146](https://issues.redhat.com/browse/OCPBUGS-82146), [OCPBUGS-85550](https://issues.redhat.com/browse/OCPBUGS-85550), [OCPBUGS-88295](https://issues.redhat.com/browse/OCPBUGS-88295), [OCPBUGS-88297](https://issues.redhat.com/browse/OCPBUGS-88297): Remove feature-set annotations from Sail Library RBAC Manifests [#1462](https://github.com/openshift/cluster-ingress-operator/pull/1462)
* [OCPBUGS-78330](https://issues.redhat.com/browse/OCPBUGS-78330), [OCPBUGS-82146](https://issues.redhat.com/browse/OCPBUGS-82146), [OCPBUGS-85550](https://issues.redhat.com/browse/OCPBUGS-85550), [OCPBUGS-88295](https://issues.redhat.com/browse/OCPBUGS-88295), [OCPBUGS-88297](https://issues.redhat.com/browse/OCPBUGS-88297): Replace OLM-based Istio install with Sail Library [#1442](https://github.com/openshift/cluster-ingress-operator/pull/1442)
* [OCPBUGS-86718](https://issues.redhat.com/browse/OCPBUGS-86718): Add configuration override for X-SSL strip [#1471](https://github.com/openshift/cluster-ingress-operator/pull/1471)
* [OCPBUGS-85149](https://issues.redhat.com/browse/OCPBUGS-85149): Fix e2e tests to work on platforms with unmanaged DNS [#1437](https://github.com/openshift/cluster-ingress-operator/pull/1437)
* [OCPBUGS-74373](https://issues.redhat.com/browse/OCPBUGS-74373): Remove restriction of unmanaged x-k8s.io [#1446](https://github.com/openshift/cluster-ingress-operator/pull/1446)
* [OCPBUGS-86027](https://issues.redhat.com/browse/OCPBUGS-86027): Fix logging for unmanaged controllers [#1448](https://github.com/openshift/cluster-ingress-operator/pull/1448)
* [OCPBUGS-80759](https://issues.redhat.com/browse/OCPBUGS-80759): Authorization bypass due to improper HTTP/2 path validation [#1441](https://github.com/openshift/cluster-ingress-operator/pull/1441)
* [OCPBUGS-82544](https://issues.redhat.com/browse/OCPBUGS-82544): set trustBundleName in Istio global values [#1418](https://github.com/openshift/cluster-ingress-operator/pull/1418)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/c2ed7331f378e499b2092f04ca7aaf8b3a075274...f30c6160c94034639739df5ce940d60d1d7c028a)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/dc1c217c263cd220ddd2ed6fe827a466d47e3ebb)
* [OCPBUGS-81747](https://issues.redhat.com/browse/OCPBUGS-81747): scc: fix uid{Min,Max}Range for nested-container [#2092](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2092)
* [OCPBUGS-85563](https://issues.redhat.com/browse/OCPBUGS-85563): [4.21] operator should not override authentication config serviceAccountIssuer with the default one during the operator initialization [#2151](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2151)
* [OCPBUGS-85270](https://issues.redhat.com/browse/OCPBUGS-85270): fsync static pod cert and manifest writes for crash durability [#2144](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2144)
* [OCPBUGS-83855](https://issues.redhat.com/browse/OCPBUGS-83855): Allow setting the oauthMetadata when auth type is None [#2116](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2116)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/8ee10fb411a0c7f0e91b3e6d9e3bd3843a93e882...dc1c217c263cd220ddd2ed6fe827a466d47e3ebb)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/5ef1df3be41d38ddae9b3d22ce51ba486939e9f1)
* [OCPBUGS-83737](https://issues.redhat.com/browse/OCPBUGS-83737): add /var/run/kubernetes as emptyDir [#641](https://github.com/openshift/cluster-kube-scheduler-operator/pull/641)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/e60e39de9cdd273dadd341d0f56350f504db9623...5ef1df3be41d38ddae9b3d22ce51ba486939e9f1)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/9b8c136071a82310b47a9ceab869257378a929c3)
* [OCPBUGS-112573](https://issues.redhat.com/browse/OCPBUGS-112573): [release-4.21] Makefile: version-stamp golangci-lint binary to prevent stale linter [#3065](https://github.com/openshift/cluster-monitoring-operator/pull/3065)
* [OCPBUGS-104068](https://issues.redhat.com/browse/OCPBUGS-104068): [release-4.21] Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [#3070](https://github.com/openshift/cluster-monitoring-operator/pull/3070)
* [OCPBUGS-105305](https://issues.redhat.com/browse/OCPBUGS-105305): [release-4.21] wrap library-go resourceCache with mutex for thread safety [#3044](https://github.com/openshift/cluster-monitoring-operator/pull/3044)
* [OCPBUGS-104537](https://issues.redhat.com/browse/OCPBUGS-104537): Backport e2e stabilization 4.21 [#3027](https://github.com/openshift/cluster-monitoring-operator/pull/3027)
* [OCPBUGS-100369](https://issues.redhat.com/browse/OCPBUGS-100369): [release-4.21] fix: watch cluster wide proxy changes and apply changes accordingly [#3021](https://github.com/openshift/cluster-monitoring-operator/pull/3021)
* [OCPBUGS-99763](https://issues.redhat.com/browse/OCPBUGS-99763): fall back to kube-system/global-pull-secret for telemeter-client token [#3002](https://github.com/openshift/cluster-monitoring-operator/pull/3002)
* [OCPBUGS-92194](https://issues.redhat.com/browse/OCPBUGS-92194): set Prometheus shards value explicitly [#2975](https://github.com/openshift/cluster-monitoring-operator/pull/2975)
* [OCPBUGS-94077](https://issues.redhat.com/browse/OCPBUGS-94077): ship collector:node_scrape_collector_success:avg to Telemetry [#2978](https://github.com/openshift/cluster-monitoring-operator/pull/2978)
* [OCPBUGS-88323](https://issues.redhat.com/browse/OCPBUGS-88323): [release-4.21] fix(TestDocExamples) flake: use internal registry for test pods [#2980](https://github.com/openshift/cluster-monitoring-operator/pull/2980)
* [OCPBUGS-86806](https://issues.redhat.com/browse/OCPBUGS-86806): jsonnet: exclude ReplicationController from catch-all β¦ [#2939](https://github.com/openshift/cluster-monitoring-operator/pull/2939)
* [OCPBUGS-86991](https://issues.redhat.com/browse/OCPBUGS-86991): increase lookup interval [#2946](https://github.com/openshift/cluster-monitoring-operator/pull/2946)
* [OCPBUGS-80765](https://issues.redhat.com/browse/OCPBUGS-80765): bump 4.21 grpc to v1.79.3 [#2875](https://github.com/openshift/cluster-monitoring-operator/pull/2875)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/830f20030a4600916885be7988a5bd5444b7c6ae...9b8c136071a82310b47a9ceab869257378a929c3)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/d1d5e0e61459c068cd5024746b54275685279f9f)
* [OCPBUGS-112789](https://issues.redhat.com/browse/OCPBUGS-112789): [4.21] frr-k8s: use Recreate strategy for statuscleaner deployment [#3135](https://github.com/openshift/cluster-network-operator/pull/3135)
* [OCPBUGS-105600](https://issues.redhat.com/browse/OCPBUGS-105600): Remove version-specific CNI binary copy logic [#3117](https://github.com/openshift/cluster-network-operator/pull/3117)
* [OCPBUGS-99747](https://issues.redhat.com/browse/OCPBUGS-99747): Bump frr-k8s MAX_FDS from 1024 to 65536 [#3092](https://github.com/openshift/cluster-network-operator/pull/3092)
* [OCPBUGS-98747](https://issues.redhat.com/browse/OCPBUGS-98747): Remove --enable-interconnect flag from OVN-K manifests [#3055](https://github.com/openshift/cluster-network-operator/pull/3055)
* [OCPBUGS-98548](https://issues.redhat.com/browse/OCPBUGS-98548): Bump github.com/containernetworking/cni v0.8.0 -> v1.3.0 [#3049](https://github.com/openshift/cluster-network-operator/pull/3049)
* [OCPBUGS-84169](https://issues.redhat.com/browse/OCPBUGS-84169): Handle zero-worker HyperShift clusters in daemonset rollout [4.21 backport] [#2972](https://github.com/openshift/cluster-network-operator/pull/2972)
* [OCPBUGS-83422](https://issues.redhat.com/browse/OCPBUGS-83422): wait for patch port to apply drop garp flows [#2946](https://github.com/openshift/cluster-network-operator/pull/2946)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/259ea6b026f6663fa720a1e11c913a61122402f9...d1d5e0e61459c068cd5024746b54275685279f9f)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/6075cffc70be79fa499558474f135ea244c93fc0)
* [OCPBUGS-114931](https://issues.redhat.com/browse/OCPBUGS-114931): Update PPC help description [#1623](https://github.com/openshift/cluster-node-tuning-operator/pull/1623)
* [OCPBUGS-112011](https://issues.redhat.com/browse/OCPBUGS-112011): BUG-FIX Latency Test [#1592](https://github.com/openshift/cluster-node-tuning-operator/pull/1592)
* [OCPBUGS-114013](https://issues.redhat.com/browse/OCPBUGS-114013): Use Add() instead of AddRateLimited() for routine Profile enqueues [#1616](https://github.com/openshift/cluster-node-tuning-operator/pull/1616)
* [OCPBUGS-104586](https://issues.redhat.com/browse/OCPBUGS-104586): e2e: fix: clear hugepages before switching kernelPageSize to 4k [#1576](https://github.com/openshift/cluster-node-tuning-operator/pull/1576)
* [OCPBUGS-100540](https://issues.redhat.com/browse/OCPBUGS-100540): e2e: fix broken checks and rework netqueue tests to avoid ARM ethtool blackout flakes [#1573](https://github.com/openshift/cluster-node-tuning-operator/pull/1573)
* [OCPBUGS-90529](https://issues.redhat.com/browse/OCPBUGS-90529): perf: latency: compute memory resources dynamically [#1521](https://github.com/openshift/cluster-node-tuning-operator/pull/1521)
* [OCPBUGS-82896](https://issues.redhat.com/browse/OCPBUGS-82896): Bump github.com/moby/spdystream from v0.5.0 to v0.5.1 [#1531](https://github.com/openshift/cluster-node-tuning-operator/pull/1531)
* [OCPBUGS-86809](https://issues.redhat.com/browse/OCPBUGS-86809): Requeue PerformanceStatus update when status write fails [#1524](https://github.com/openshift/cluster-node-tuning-operator/pull/1524)
* [OCPBUGS-85016](https://issues.redhat.com/browse/OCPBUGS-85016): e2e: Add irqbalance StartLimitBurst >= 100 config test [#1505](https://github.com/openshift/cluster-node-tuning-operator/pull/1505)
* [OCPBUGS-81122](https://issues.redhat.com/browse/OCPBUGS-81122): CNF-21333: [4.21]:perfprof: enable exec-cpu-affinity by default [#1484](https://github.com/openshift/cluster-node-tuning-operator/pull/1484)
* [OCPBUGS-76375](https://issues.redhat.com/browse/OCPBUGS-76375): AA: E2E: LLC: Add tests related to odd cpus [#1467](https://github.com/openshift/cluster-node-tuning-operator/pull/1467)
* [OCPBUGS-77464](https://issues.redhat.com/browse/OCPBUGS-77464): E2E: Add test case to check Infrastructure pods affinity [#1476](https://github.com/openshift/cluster-node-tuning-operator/pull/1476)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/273d20bbc2aa6cff97365f8c58bf888f6a7db245...6075cffc70be79fa499558474f135ea244c93fc0)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/03bedb913bce9c7deabf7868e5cbefc57cf3490b)
* [OCPBUGS-80769](https://issues.redhat.com/browse/OCPBUGS-80769): Bump google.golang.org/grpc to v1.79.3 [#197](https://github.com/openshift/cluster-olm-operator/pull/197)
* [OCPBUGS-76269](https://issues.redhat.com/browse/OCPBUGS-76269): add resources to clusterOperator relatedObjects [#170](https://github.com/openshift/cluster-olm-operator/pull/170)
* [OCPBUGS-81311](https://issues.redhat.com/browse/OCPBUGS-81311): Fix golangci-lint timeout in CI [#189](https://github.com/openshift/cluster-olm-operator/pull/189)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/a1d96ed2e60a60e466245c7c08f001d2a386f274...03bedb913bce9c7deabf7868e5cbefc57cf3490b)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/810221c4d6f91efae7277224e3022ec5c4778e14)
* [OCPBUGS-105475](https://issues.redhat.com/browse/OCPBUGS-105475): Add HostToContainer mountPropagation to node-pullsecrets volume mount [#750](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/750)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/52fd1773757b2c3ff497e7db084c3d71cde5478f...810221c4d6f91efae7277224e3022ec5c4778e14)
### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/e510507e20f6eb09694c880ecd79fa512a2b3470)
* [OCPBUGS-98251](https://issues.redhat.com/browse/OCPBUGS-98251): [4.21] add serviceAccountToken volume type to psalabelsyncer [#193](https://github.com/openshift/cluster-policy-controller/pull/193)
* [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/8b775487512fb543bff470ff1042bd3ac31b29be...e510507e20f6eb09694c880ecd79fa512a2b3470)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/e403475164a4de23d358a93106a35353ec29f3d7)
* [OCPBUGS-79531](https://issues.redhat.com/browse/OCPBUGS-79531): volume-data-source-validator should run on master nodes [#687](https://github.com/openshift/cluster-storage-operator/pull/687)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/dd362d767167a8ac1889d2ee2a719cf68fac0522...e403475164a4de23d358a93106a35353ec29f3d7)
### [console](https://github.com/openshift/console/tree/2f1997abe650fbe9de360a061360c5fc0a67f6d9)
* [OCPBUGS-122212](https://issues.redhat.com/browse/OCPBUGS-122212): Wait for demo plugin deployment readiness [#17160](https://github.com/openshift/console/pull/17160)
* [OCPBUGS-116250](https://issues.redhat.com/browse/OCPBUGS-116250): Validate chart URL in /api/helm/verify [#17136](https://github.com/openshift/console/pull/17136)
* [OCPBUGS-113468](https://issues.redhat.com/browse/OCPBUGS-113468): Remove unscoped CSV watch from ClusterNotUpgradeableAlert [#17079](https://github.com/openshift/console/pull/17079)
* Fix for OCPBUGS-92072: CVE-2026-44990 [#16714](https://github.com/openshift/console/pull/16714)
* [OCPBUGS-113732](https://issues.redhat.com/browse/OCPBUGS-113732): make cloud provider fields optional during operator install [#17091](https://github.com/openshift/console/pull/17091)
* [OCPBUGS-100518](https://issues.redhat.com/browse/OCPBUGS-100518), [OCPBUGS-101793](https://issues.redhat.com/browse/OCPBUGS-101793): Fix CVE-2026-69153 and CVE-2026-45623 - Bump postcss [#17055](https://github.com/openshift/console/pull/17055)
* Fix OCPBUGS-99410: CVE-2026-59877 [#16835](https://github.com/openshift/console/pull/16835)
* [OCPBUGS-112273](https://issues.redhat.com/browse/OCPBUGS-112273): Fix flaky TestAsyncCache backend test [#17046](https://github.com/openshift/console/pull/17046)
* Fix for OCPBUGS-101827: CVE-2026-69152 [#16931](https://github.com/openshift/console/pull/16931)
* Fix for OCPBUGS-105892: CVE-2026-73086 [#16966](https://github.com/openshift/console/pull/16966)
* [OCPBUGS-105864](https://issues.redhat.com/browse/OCPBUGS-105864): Fix leading whitespace in Quick Start execute code snippets [#16961](https://github.com/openshift/console/pull/16961)
* Fix for OCPBUGS-89706: CVE-2026-12143 [#16645](https://github.com/openshift/console/pull/16645)
* [OCPBUGS-98434](https://issues.redhat.com/browse/OCPBUGS-98434): CVE-2026-59869 bump js-yaml [#16772](https://github.com/openshift/console/pull/16772)
* [OCPBUGS-100058](https://issues.redhat.com/browse/OCPBUGS-100058): quickstart page i18n misses (Fix Quick Starts i18n bundle lookup for zh-CN) [#16868](https://github.com/openshift/console/pull/16868)
* [OCPBUGS-100377](https://issues.redhat.com/browse/OCPBUGS-100377): Re-enable Knative Cypress e2e tests [#16896](https://github.com/openshift/console/pull/16896)
* [OCPBUGS-99544](https://issues.redhat.com/browse/OCPBUGS-99544): '0 B' is shown on details page when create pvc with 'EiB' unit [#16806](https://github.com/openshift/console/pull/16806)
* [OCPBUGS-99546](https://issues.redhat.com/browse/OCPBUGS-99546): Incorrect translations for 'CatalogSources' and 'OperatorGroups' in l⦠[#16808](https://github.com/openshift/console/pull/16808)
* [OCPBUGS-99311](https://issues.redhat.com/browse/OCPBUGS-99311): Disable Knative e2e Cypress tests in CI [#16794](https://github.com/openshift/console/pull/16794)
* [OCPBUGS-99163](https://issues.redhat.com/browse/OCPBUGS-99163): fixing severity not showing number of issues [#16618](https://github.com/openshift/console/pull/16618)
* [OCPBUGS-84287](https://issues.redhat.com/browse/OCPBUGS-84287): Bump follow-redirects to 1.16.0 to fix CVE-2026-40895 [#16670](https://github.com/openshift/console/pull/16670)
* [OCPBUGS-81618](https://issues.redhat.com/browse/OCPBUGS-81618): CVE-2026-4800 [#16572](https://github.com/openshift/console/pull/16572)
* [OCPBUGS-90498](https://issues.redhat.com/browse/OCPBUGS-90498): Projects cannot be filtered by display name in the console list view [#16653](https://github.com/openshift/console/pull/16653)
* [OCPBUGS-95544](https://issues.redhat.com/browse/OCPBUGS-95544): Fix RoleBindings tab error for non-cluster-admin users [#16695](https://github.com/openshift/console/pull/16695)
* [OCPBUGS-86743](https://issues.redhat.com/browse/OCPBUGS-86743), [OCPBUGS-87090](https://issues.redhat.com/browse/OCPBUGS-87090), [OCPBUGS-88749](https://issues.redhat.com/browse/OCPBUGS-88749): [release-4.21] bump package: webpack-dev-server, protobufjs, fast-uri [#16654](https://github.com/openshift/console/pull/16654)
* [OCPBUGS-90553](https://issues.redhat.com/browse/OCPBUGS-90553): Backport inventory card filter link fix to release-4.21 [#16678](https://github.com/openshift/console/pull/16678)
* [OCPBUGS-86456](https://issues.redhat.com/browse/OCPBUGS-86456): [release-4.21] shell-quote: Arbitrary code execution via command injection due to unescaped line terminators [#16536](https://github.com/openshift/console/pull/16536)
* [OCPBUGS-88358](https://issues.redhat.com/browse/OCPBUGS-88358): Allow VolumeSnapshot restore when parent PVC is deleted [#16602](https://github.com/openshift/console/pull/16602)
* [OCPBUGS-86581](https://issues.redhat.com/browse/OCPBUGS-86581): Fix macOS Option key in pod terminal [#16505](https://github.com/openshift/console/pull/16505)
* [OCPBUGS-85674](https://issues.redhat.com/browse/OCPBUGS-85674): Prevent binary secret data corruption when editing [#16448](https://github.com/openshift/console/pull/16448)
* [OCPBUGS-79459](https://issues.redhat.com/browse/OCPBUGS-79459): CVE-2026-29063 Immutable.js: Improperly Controlled Mod⦠[#16503](https://github.com/openshift/console/pull/16503)
* [OCPBUGS-86427](https://issues.redhat.com/browse/OCPBUGS-86427): Fix Shipwright detail pages crashing with React error #310 [#16487](https://github.com/openshift/console/pull/16487)
* [OCPBUGS-86314](https://issues.redhat.com/browse/OCPBUGS-86314): Show empty state instead of 403 error for users without projects [#16478](https://github.com/openshift/console/pull/16478)
* [OCPBUGS-84967](https://issues.redhat.com/browse/OCPBUGS-84967): Remove DataViewToolbar wrapper from bottom pagination [#16484](https://github.com/openshift/console/pull/16484)
* [OCPBUGS-83287](https://issues.redhat.com/browse/OCPBUGS-83287): [release-4.21] CVE-2026-26996 Bump minimatch library [#16276](https://github.com/openshift/console/pull/16276)
* [OCPBUGS-85520](https://issues.redhat.com/browse/OCPBUGS-85520): Fix create visual connector in Topology [#16439](https://github.com/openshift/console/pull/16439)
* NO-JIRA: enable multi-architecture yarn builds [#16420](https://github.com/openshift/console/pull/16420)
* [OCPBUGS-85040](https://issues.redhat.com/browse/OCPBUGS-85040): Remove PII from events [#16401](https://github.com/openshift/console/pull/16401)
* [OCPBUGS-84967](https://issues.redhat.com/browse/OCPBUGS-84967): Add bottom pagination to ConsoleDataView for mobile responsiveness [#16396](https://github.com/openshift/console/pull/16396)
* [OCPBUGS-84858](https://issues.redhat.com/browse/OCPBUGS-84858): Fix ConsoleDataView filter order: Name and Label shoul⦠[#16386](https://github.com/openshift/console/pull/16386)
* [OCPBUGS-83494](https://issues.redhat.com/browse/OCPBUGS-83494): remove dev to admin links as dev monitoring views are enabled [#16164](https://github.com/openshift/console/pull/16164)
* [OCPBUGS-83572](https://issues.redhat.com/browse/OCPBUGS-83572): fix Developer Sandbox telemetry [#16286](https://github.com/openshift/console/pull/16286)
* [OCPBUGS-83418](https://issues.redhat.com/browse/OCPBUGS-83418): Fix resource log dropdown TypeError [#16281](https://github.com/openshift/console/pull/16281)
* [OCPBUGS-81517](https://issues.redhat.com/browse/OCPBUGS-81517): Follow up on fixing the remaining issues in the multi-group impersonation feature [#16236](https://github.com/openshift/console/pull/16236)
* [OCPBUGS-81714](https://issues.redhat.com/browse/OCPBUGS-81714): Add missing i18n translations for Pagination component [#16255](https://github.com/openshift/console/pull/16255)
* [OCPBUGS-79351](https://issues.redhat.com/browse/OCPBUGS-79351): Make folder field optional for vsphere [#16189](https://github.com/openshift/console/pull/16189)
* [OCPBUGS-79040](https://issues.redhat.com/browse/OCPBUGS-79040): Fix incorrect OLMv1 documentation URL [#16186](https://github.com/openshift/console/pull/16186)
* [OCPBUGS-81308](https://issues.redhat.com/browse/OCPBUGS-81308): Fix VolumeSnapshot and VolumeSnapshotContent tables sorting [#16216](https://github.com/openshift/console/pull/16216)
* [OCPBUGS-79037](https://issues.redhat.com/browse/OCPBUGS-79037): Fix useOperatorCatalogCategories hook. [#16185](https://github.com/openshift/console/pull/16185)
* [OCPBUGS-81330](https://issues.redhat.com/browse/OCPBUGS-81330): Fix entire app suspending to load perspective switcher icon [#16226](https://github.com/openshift/console/pull/16226)
* [OCPBUGS-81488](https://issues.redhat.com/browse/OCPBUGS-81488): Add robots.txt policy to console [#16227](https://github.com/openshift/console/pull/16227)
* [OCPBUGS-80931](https://issues.redhat.com/browse/OCPBUGS-80931): Hide filter category selector when only one filter exists [#16199](https://github.com/openshift/console/pull/16199)
* [OCPBUGS-77246](https://issues.redhat.com/browse/OCPBUGS-77246): AsyncComponent type improvements [#16058](https://github.com/openshift/console/pull/16058)
* [OCPBUGS-79035](https://issues.redhat.com/browse/OCPBUGS-79035): Fix TypeError in OLS code import to console [#16184](https://github.com/openshift/console/pull/16184)
* [OCPBUGS-78799](https://issues.redhat.com/browse/OCPBUGS-78799): Fix search component to not pass ALL_NAMESPACES_KEY to⦠[#16170](https://github.com/openshift/console/pull/16170)
* [OCPBUGS-79533](https://issues.redhat.com/browse/OCPBUGS-79533): enable keyboard shortcut for DataViewTextFilter [#16195](https://github.com/openshift/console/pull/16195)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/680f343ea2b9d198ae861dade4ba8cf329181d5e...2f1997abe650fbe9de360a061360c5fc0a67f6d9)
### [console-operator](https://github.com/openshift/console-operator/tree/f730484ce5f2606e7f665d561227c374183fff14)
* [OCPBUGS-100111](https://issues.redhat.com/browse/OCPBUGS-100111): Sort plugin list to make them deterministic [#1203](https://github.com/openshift/console-operator/pull/1203)
* [OCPBUGS-98987](https://issues.redhat.com/browse/OCPBUGS-98987): [4.21] Stabilize telemetry config to prevent continuous console pod rollouts [#1192](https://github.com/openshift/console-operator/pull/1192)
* [NETOBSERV-2296](https://issues.redhat.com/browse/NETOBSERV-2296): add missing annotations on netobserv quickstart [#1096](https://github.com/openshift/console-operator/pull/1096)
* [OCPBUGS-86119](https://issues.redhat.com/browse/OCPBUGS-86119): Add unit and e2e test coverage for cert rotation redeployment [#1162](https://github.com/openshift/console-operator/pull/1162)
* [OCPBUGS-82037](https://issues.redhat.com/browse/OCPBUGS-82037): Redeploy console pods upon cert rotation [#1139](https://github.com/openshift/console-operator/pull/1139)
* [OCPBUGS-78929](https://issues.redhat.com/browse/OCPBUGS-78929): Remove orphaned console-conversion-webhook deployment and related resource [#1128](https://github.com/openshift/console-operator/pull/1128)
* [Full changelog](https://github.com/openshift/console-operator/compare/898badb9b69b19c80eb586e94b501203209aca6e...f730484ce5f2606e7f665d561227c374183fff14)
### [csi-driver-manila, openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/063501a59511f2924cd40222ba0d2cca03af8388)
* [OCPBUGS-96550](https://issues.redhat.com/browse/OCPBUGS-96550): Bump golang.org/x/net to v0.50.0-sec.4 [#417](https://github.com/openshift/cloud-provider-openstack/pull/417)
* [OCPBUGS-80845](https://issues.redhat.com/browse/OCPBUGS-80845): bump google.golang.org/grpc@v1.79.3 [#384](https://github.com/openshift/cloud-provider-openstack/pull/384)
* UPSTREAM-SYNC: Sync release-4.21 with upstream release-1.34 [#371](https://github.com/openshift/cloud-provider-openstack/pull/371)
* [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/bf508c062084dc6dec20480f7d173f047ad4f2d6...063501a59511f2924cd40222ba0d2cca03af8388)
### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/b5e4888ca8e420ba9245805a1a8c976074a8b793)
* [OCPBUGS-82899](https://issues.redhat.com/browse/OCPBUGS-82899): Bump github.com/moby/spdystream@v0.5.1 [#191](https://github.com/openshift/csi-driver-nfs/pull/191)
* [OCPBUGS-80783](https://issues.redhat.com/browse/OCPBUGS-80783): CVE-2026-33186: bump google.golang.org/grpc v1.79.3 [#176](https://github.com/openshift/csi-driver-nfs/pull/176)
* [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/49f2d86fb6172d9d8909ed0f70cb3bc71a4f7c01...b5e4888ca8e420ba9245805a1a8c976074a8b793)
### [csi-external-attacher](https://github.com/openshift/csi-external-attacher/tree/6a3be10e6795c8149c4bd3c9856f7e2d312108e2)
* [OCPBUGS-80784](https://issues.redhat.com/browse/OCPBUGS-80784): Bump google.golang.org/grpc to v1.79.3 [#102](https://github.com/openshift/csi-external-attacher/pull/102)
* [Full changelog](https://github.com/openshift/csi-external-attacher/compare/344669a2189fecdf5471fdc9a1246dd751cb1afb...6a3be10e6795c8149c4bd3c9856f7e2d312108e2)
### [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner/tree/8d29fc4b7cb1f910c4c03e0a63fdd375d6294125)
* UPSTREAM: 1544: OCPBUGS-96508: Bump golang.org/x/net to v0.50.0-sec.4 [#149](https://github.com/openshift/csi-external-provisioner/pull/149)
* [OCPBUGS-82900](https://issues.redhat.com/browse/OCPBUGS-82900): Address CVE-2026-35469 [#139](https://github.com/openshift/csi-external-provisioner/pull/139)
* [OCPBUGS-80785](https://issues.redhat.com/browse/OCPBUGS-80785): Bump google.golang.org/grpc to v1.79.3 [#132](https://github.com/openshift/csi-external-provisioner/pull/132)
* [Full changelog](https://github.com/openshift/csi-external-provisioner/compare/f18190fb8aa26bdcb4ceb57cdd6cf77b5488ed58...8d29fc4b7cb1f910c4c03e0a63fdd375d6294125)
### [csi-external-resizer](https://github.com/openshift/csi-external-resizer/tree/d5c2c2b47fbd76677d6060956f309bc675957c31)
* [OCPBUGS-104092](https://issues.redhat.com/browse/OCPBUGS-104092): Bump golang.org/x/net to v0.50.0-sec.4 [#210](https://github.com/openshift/csi-external-resizer/pull/210)
* [OCPBUGS-80786](https://issues.redhat.com/browse/OCPBUGS-80786): Bump google.golang.org/grpc to v1.79.3 [#200](https://github.com/openshift/csi-external-resizer/pull/200)
* [Full changelog](https://github.com/openshift/csi-external-resizer/compare/d880a1ec6da02dbf61600ec7999266185ca9f784...d5c2c2b47fbd76677d6060956f309bc675957c31)
### [csi-external-snapshotter, csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter/tree/2c14afc50a30de62cb00cc8263b061383cfbd3b5)
* [OCPBUGS-89328](https://issues.redhat.com/browse/OCPBUGS-89328): UPSTREAM: 1392: Fix VolumeSnapshotContent deletion [#223](https://github.com/openshift/csi-external-snapshotter/pull/223)
* [OCPBUGS-80788](https://issues.redhat.com/browse/OCPBUGS-80788), [OCPBUGS-80791](https://issues.redhat.com/browse/OCPBUGS-80791): Bump google.golang.org/grpc to v1.79.3 [#208](https://github.com/openshift/csi-external-snapshotter/pull/208)
* [Full changelog](https://github.com/openshift/csi-external-snapshotter/compare/9098db0e434e0d986eeadd2ebe69119540a550d1...2c14afc50a30de62cb00cc8263b061383cfbd3b5)
### [docker-builder](https://github.com/openshift/builder/tree/3c27415e6167879dc02bf2fc4388a7d914109b2c)
* [OCPBUGS-90033](https://issues.redhat.com/browse/OCPBUGS-90033), [OCPBUGS-90475](https://issues.redhat.com/browse/OCPBUGS-90475), [OCPBUGS-92525](https://issues.redhat.com/browse/OCPBUGS-92525), [OCPBUGS-92654](https://issues.redhat.com/browse/OCPBUGS-92654), [OCPBUGS-92992](https://issues.redhat.com/browse/OCPBUGS-92992): Bump golang.org/x/crypto to fix CVE-2025-22869,CVE-2025-47913,CVE-2026-46597,CVE-2026-39829,CVE-2026-39832 [#547](https://github.com/openshift/builder/pull/547)
* [Full changelog](https://github.com/openshift/builder/compare/48fce231bac118a63992f466acc8b29a29e1ddde...3c27415e6167879dc02bf2fc4388a7d914109b2c)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/0ec77dd178e3b0433f01fce5bcce96abcc126deb)
* [OCPBUGS-98548](https://issues.redhat.com/browse/OCPBUGS-98548): Bump containernetworking/cni to v1.3.0 github.com/containernetworking/plugins to 1.4.0 [#106](https://github.com/openshift/egress-router-cni/pull/106)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/5e0f8d1b545899fda27c5e1cc8707d33cba1b534...0ec77dd178e3b0433f01fce5bcce96abcc126deb)
### [etcd](https://github.com/openshift/etcd/tree/b6dda5413ec33fc88fc9751d98d3b4bd96ea877d)
* [OCPBUGS-100390](https://issues.redhat.com/browse/OCPBUGS-100390): UPSTREAM: 21443: Revert "Reuse events between sync loops" [#394](https://github.com/openshift/etcd/pull/394)
* [Full changelog](https://github.com/openshift/etcd/compare/806f690e1f140e0aea2eb05ef5f288b756b62895...b6dda5413ec33fc88fc9751d98d3b4bd96ea877d)
### [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp/tree/0b668ce7bac61039537f573ad6d6f7297dd34b05)
* NO-JIRA: Update OWNERS [#159](https://github.com/openshift/cloud-provider-gcp/pull/159)
* [OCPBUGS-115261](https://issues.redhat.com/browse/OCPBUGS-115261): Fix node.kubernetes.io/exclude-from-external-load-balancers on masters [#142](https://github.com/openshift/cloud-provider-gcp/pull/142)
* [OCPBUGS-83615](https://issues.redhat.com/browse/OCPBUGS-83615): Fix OSD ILB bug [#108](https://github.com/openshift/cloud-provider-gcp/pull/108)
* [Full changelog](https://github.com/openshift/cloud-provider-gcp/compare/8732386c3ddcb98dae624f7bb925ed0ef8d077d5...0b668ce7bac61039537f573ad6d6f7297dd34b05)
### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/fe230b8a6407a06e1be9d6994a92ac8c5a43237d)
* [OCPBUGS-80805](https://issues.redhat.com/browse/OCPBUGS-80805): Bump google.golang.org/grpc to v1.79.3 [#287](https://github.com/openshift/cluster-api-provider-gcp/pull/287)
* [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/e2d0c20eab31c513764507a6d8774de2aef3db2c...fe230b8a6407a06e1be9d6994a92ac8c5a43237d)
### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/53820aadd2cc313cb0ce54788bb1fceec5b95eed)
* [OCPBUGS-104131](https://issues.redhat.com/browse/OCPBUGS-104131): Bump golang.org/x/net to v0.50.0-sec.3 [#186](https://github.com/openshift/machine-api-provider-gcp/pull/186)
* [OCPBUGS-105415](https://issues.redhat.com/browse/OCPBUGS-105415): [release-4.21] Add the N4A machine type [#179](https://github.com/openshift/machine-api-provider-gcp/pull/179)
* [OCPBUGS-80828](https://issues.redhat.com/browse/OCPBUGS-80828): Bump gRPC-Go package for CVE fix [#154](https://github.com/openshift/machine-api-provider-gcp/pull/154)
* [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/91f71c9adfd6b715a6ef340bb43ea5e1a8b44245...53820aadd2cc313cb0ce54788bb1fceec5b95eed)
### [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver/tree/1da557fe54562347dbf18bee04fe6564a2697707)
* [OCPBUGS-80809](https://issues.redhat.com/browse/OCPBUGS-80809): Bump google.golang.org/grpc to v1.79.3 in release-4.21 [#104](https://github.com/openshift/gcp-pd-csi-driver/pull/104)
* [Full changelog](https://github.com/openshift/gcp-pd-csi-driver/compare/0660d93fa9545ded2f6a49f4462de3ed68000232...1da557fe54562347dbf18bee04fe6564a2697707)
### [gcp-pd-csi-driver-operator](https://github.com/openshift/gcp-pd-csi-driver-operator/tree/8d9f11a7f2c4e757bfc5e99ba69084d29a28b79b)
* [OCPBUGS-97960](https://issues.redhat.com/browse/OCPBUGS-97960): no-op OWNERS change to trigger postsubmit jobs [#197](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/197)
* [OCPBUGS-80808](https://issues.redhat.com/browse/OCPBUGS-80808): Bump google.golang.org/grpc to v1.79.3 [#184](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/184)
* [Full changelog](https://github.com/openshift/gcp-pd-csi-driver-operator/compare/ddfc0f93d244d5d9be6d5ab7631f4b1db8bec043...8d9f11a7f2c4e757bfc5e99ba69084d29a28b79b)
### [haproxy-router](https://github.com/openshift/router/tree/22531cf0bb2435e73437be73c244913de4844812)
* [OCPBUGS-86729](https://issues.redhat.com/browse/OCPBUGS-86729): Prevent SSRF via FQDN-typed EndpointSlices [#818](https://github.com/openshift/router/pull/818)
* [OCPBUGS-86718](https://issues.redhat.com/browse/OCPBUGS-86718): Strip X-SSL-* headers for plain HTTP [#795](https://github.com/openshift/router/pull/795)
* [OCPBUGS-87002](https://issues.redhat.com/browse/OCPBUGS-87002): Replace HTTP backend liveness check with admin socket check [#786](https://github.com/openshift/router/pull/786)
* [OCPBUGS-80810](https://issues.redhat.com/browse/OCPBUGS-80810): Bump google.golang.org/grpc to v1.79.3 [#770](https://github.com/openshift/router/pull/770)
* [Full changelog](https://github.com/openshift/router/compare/5949f713517b3cc158cd78b34d71d5a9084d2e1c...22531cf0bb2435e73437be73c244913de4844812)
### [hyperkube, kube-proxy, pod](https://github.com/openshift/kubernetes/tree/601ff80b0459adda2d2c5865bfb8d568a1fa68b7)
* UPSTREAM: <carry>: OCPBUGS-99230: Fix ClusterIsIPv6() detection for dual-stack v6-primary clusters [#2722](https://github.com/openshift/kubernetes/pull/2722)
* [OCPBUGS-87157](https://issues.redhat.com/browse/OCPBUGS-87157): Fix performance related issues when selinux metrics are emitted [#2678](https://github.com/openshift/kubernetes/pull/2678)
* NO-JIRA: Update openshift-hack/rebase.sh [#2745](https://github.com/openshift/kubernetes/pull/2745)
* [OCPBUGS-94059](https://issues.redhat.com/browse/OCPBUGS-94059): backport kubernetes/conformance umbrella suite [#2708](https://github.com/openshift/kubernetes/pull/2708)
* [OCPBUGS-91759](https://issues.redhat.com/browse/OCPBUGS-91759): Rebase v1.34.9 in release-4.21 [#2702](https://github.com/openshift/kubernetes/pull/2702)
* [OCPBUGS-87017](https://issues.redhat.com/browse/OCPBUGS-87017): fix flake race in VAP e2e case [#2677](https://github.com/openshift/kubernetes/pull/2677)
* [OCPBUGS-85500](https://issues.redhat.com/browse/OCPBUGS-85500): Bump Kubernetes v1.34.8 to release-4.21 [#2665](https://github.com/openshift/kubernetes/pull/2665)
* "OCPBUGS-83608: Bump to k8s v1.34.7" [#2647](https://github.com/openshift/kubernetes/pull/2647)
* NO-JIRA: UPSTREAM: <carry>: Add jacobsee and jubittajohn to DOWNSTREAM_OWNERS [#2636](https://github.com/openshift/kubernetes/pull/2636)
* [OCPBUGS-78991](https://issues.redhat.com/browse/OCPBUGS-78991): Bump 1.34.6 to release-4.21 [#2634](https://github.com/openshift/kubernetes/pull/2634)
* [Full changelog](https://github.com/openshift/kubernetes/compare/8b1d67b459cd554cd4b6d878e9bf4d425b3bf9a0...601ff80b0459adda2d2c5865bfb8d568a1fa68b7)
### [hypershift](https://github.com/openshift/hypershift/tree/86702ff674f423e3785551d4579a07bb3615d1ee)
* [OCPBUGS-120751](https://issues.redhat.com/browse/OCPBUGS-120751): update Containerfile.cli runtime base image to floating tag [release-4.21] [#9557](https://github.com/openshift/hypershift/pull/9557)
* [OCPBUGS-125792](https://issues.redhat.com/browse/OCPBUGS-125792): hardcode ETCD_METRICS=extensive in etcd StatefulSet template [#9696](https://github.com/openshift/hypershift/pull/9696)
* [OCPBUGS-82913](https://issues.redhat.com/browse/OCPBUGS-82913): Address CVE-2026-35469 [#9023](https://github.com/openshift/hypershift/pull/9023)
* [OCPBUGS-96712](https://issues.redhat.com/browse/OCPBUGS-96712): Apply MetricsSet relabel configs to KAS ServiceMonitor [#9294](https://github.com/openshift/hypershift/pull/9294)
* [OCPBUGS-105505](https://issues.redhat.com/browse/OCPBUGS-105505): fix(upsert): add desired-state hash to detect spec field removals [#9268](https://github.com/openshift/hypershift/pull/9268)
* [OCPBUGS-104592](https://issues.redhat.com/browse/OCPBUGS-104592): Add proxy env vars to AWS cloud-controller-manager deployment [#9224](https://github.com/openshift/hypershift/pull/9224)
* [OCPBUGS-105434](https://issues.redhat.com/browse/OCPBUGS-105434): [release-4.21] fix router component ordering to prevent missing HAProxy backends [#9263](https://github.com/openshift/hypershift/pull/9263)
* [OCPBUGS-94179](https://issues.redhat.com/browse/OCPBUGS-94179): fix registry override matching and propagation to init containers [#8879](https://github.com/openshift/hypershift/pull/8879)
* [OCPBUGS-100194](https://issues.redhat.com/browse/OCPBUGS-100194): fix(cpo): set correct --advertise-client-url for etcd grpc-proxy [#9184](https://github.com/openshift/hypershift/pull/9184)
* [CNTRLPLANE-3873](https://issues.redhat.com/browse/CNTRLPLANE-3873): Backport controlPlaneVersion status to release-4.21 [#9054](https://github.com/openshift/hypershift/pull/9054)
* [OCPBUGS-99646](https://issues.redhat.com/browse/OCPBUGS-99646): OCPBUGS-86296: Propagate management cluster proxy env vars to konnectivity sidecar [#9087](https://github.com/openshift/hypershift/pull/9087)
* [OCPBUGS-90087](https://issues.redhat.com/browse/OCPBUGS-90087): [release-4.21] clear stale EtcdRecoveryActive failure condition when etcd is healthy [#8807](https://github.com/openshift/hypershift/pull/8807)
* [OCPBUGS-97922](https://issues.redhat.com/browse/OCPBUGS-97922): fix(nodepool): skip CNI-internal IPs in ClusterNetworkCIDRConflict check [#8949](https://github.com/openshift/hypershift/pull/8949)
* [OCPBUGS-99100](https://issues.redhat.com/browse/OCPBUGS-99100): fix(backport): konnectivity agent auth [#9093](https://github.com/openshift/hypershift/pull/9093)
* [OCPBUGS-91671](https://issues.redhat.com/browse/OCPBUGS-91671): [release-4.21] OCPBUGS-74960: prevent resource leak on deletion and handle DependencyViolation [#8798](https://github.com/openshift/hypershift/pull/8798)
* [OCPBUGS-90084](https://issues.redhat.com/browse/OCPBUGS-90084): Fix NodePool reconciliation failure when updating mirrored immutable ConfigMaps [#8812](https://github.com/openshift/hypershift/pull/8812)
* [OCPBUGS-93927](https://issues.redhat.com/browse/OCPBUGS-93927): fix(cpo): deduplicate VPC endpoint subnets by AZ to prevent DuplicateSubnetsInSameZone [#8862](https://github.com/openshift/hypershift/pull/8862)
* [OCPBUGS-86295](https://issues.redhat.com/browse/OCPBUGS-86295): CAPI image overrides aware of registry config [#8559](https://github.com/openshift/hypershift/pull/8559)
* [OCPBUGS-83833](https://issues.redhat.com/browse/OCPBUGS-83833): fix(deps): update dependencies to address CVE-2025-52881 [#8748](https://github.com/openshift/hypershift/pull/8748)
* [OCPBUGS-92089](https://issues.redhat.com/browse/OCPBUGS-92089): fix(cpo): prevent informer creation for inaccessible resource types [#8833](https://github.com/openshift/hypershift/pull/8833)
* [OCPBUGS-89353](https://issues.redhat.com/browse/OCPBUGS-89353): build(operator): drop hypershift-no-cgo from operator container images [#8757](https://github.com/openshift/hypershift/pull/8757)
* [OCPBUGS-80813](https://issues.redhat.com/browse/OCPBUGS-80813): Bump google.golang.org/grpc to v1.79.3 [#8443](https://github.com/openshift/hypershift/pull/8443)
* [OCPBUGS-86040](https://issues.redhat.com/browse/OCPBUGS-86040): [release-4.21] Verify cert revocation against all KAS pods [#8539](https://github.com/openshift/hypershift/pull/8539)
* NO-JIRA: fix(tekton): remove path filter from control-plane-operator pipelines [#8667](https://github.com/openshift/hypershift/pull/8667)
* [OCPBUGS-86416](https://issues.redhat.com/browse/OCPBUGS-86416): add Konflux pipeline definitions for CPO 4.21 [#8607](https://github.com/openshift/hypershift/pull/8607)
* [OCPBUGS-86477](https://issues.redhat.com/browse/OCPBUGS-86477): [release-4.21] add CP pull-secret watches for in-place propagation [#8583](https://github.com/openshift/hypershift/pull/8583)
* [OCPBUGS-86416](https://issues.redhat.com/browse/OCPBUGS-86416): set limits for aro.openshift.io/swift-nic in request overrides for ARO swift [#8565](https://github.com/openshift/hypershift/pull/8565)
* [OCPBUGS-81671](https://issues.redhat.com/browse/OCPBUGS-81671): Ignition generalize image download errors [#8158](https://github.com/openshift/hypershift/pull/8158)
* [OCPBUGS-85781](https://issues.redhat.com/browse/OCPBUGS-85781): Add AWS ISO domains to konnectivity IsCloudAPI [#8531](https://github.com/openshift/hypershift/pull/8531)
* [OCPBUGS-85621](https://issues.redhat.com/browse/OCPBUGS-85621): fix CVE-2026-33186 by updating grpc-go [#8518](https://github.com/openshift/hypershift/pull/8518)
* [OCPBUGS-83710](https://issues.redhat.com/browse/OCPBUGS-83710): fix(kubevirt): filter link-local addresses from EndpointSlice endpoints [#8270](https://github.com/openshift/hypershift/pull/8270)
* [OCPBUGS-85538](https://issues.redhat.com/browse/OCPBUGS-85538): [release-4.21] Set unhealthyPodEvictionPolicy to AlwaysAllow on all PDBs [#8214](https://github.com/openshift/hypershift/pull/8214)
* [OCPBUGS-85538](https://issues.redhat.com/browse/OCPBUGS-85538): [release-4.21] CNTRLPLANE-2740: Add KAS liveness readiness sidecar to OAS and OAuth API Server [#8213](https://github.com/openshift/hypershift/pull/8213)
* [OCPBUGS-76447](https://issues.redhat.com/browse/OCPBUGS-76447): Add UserAgent telemetry to CPO Azure SDK clients [#7685](https://github.com/openshift/hypershift/pull/7685)
* [OCPBUGS-81745](https://issues.redhat.com/browse/OCPBUGS-81745): [release-4.21] Honor AWS AMI override in NodePool token generation [#8170](https://github.com/openshift/hypershift/pull/8170)
* [OCPBUGS-81836](https://issues.redhat.com/browse/OCPBUGS-81836): OCPBUGS-81670: fix(cpo-v2): preserve HCCO modifications to OCM Controllers field [#8157](https://github.com/openshift/hypershift/pull/8157)
* [OCPBUGS-81490](https://issues.redhat.com/browse/OCPBUGS-81490): fix(cpo): skip router LB services for ARO HCP [#8135](https://github.com/openshift/hypershift/pull/8135)
* [OCPBUGS-77966](https://issues.redhat.com/browse/OCPBUGS-77966): fix: global-pull-secret-syncer pod ~15-minute delay scheduling on new nodes [#8129](https://github.com/openshift/hypershift/pull/8129)
* [OCPBUGS-81287](https://issues.redhat.com/browse/OCPBUGS-81287): fix(release): allow multiple machine-os component versions [#8103](https://github.com/openshift/hypershift/pull/8103)
* [OCPBUGS-81285](https://issues.redhat.com/browse/OCPBUGS-81285): fix(releaseinfo): allow periods in version display name regex [#8102](https://github.com/openshift/hypershift/pull/8102)
* [OCPBUGS-78933](https://issues.redhat.com/browse/OCPBUGS-78933): fix(cpo): Don't remove HCP Ingress from routes when CapabilityRoute is disabled [#8014](https://github.com/openshift/hypershift/pull/8014)
* [Full changelog](https://github.com/openshift/hypershift/compare/12f76eff41be4731c12021f93b15427137acd7ef...86702ff674f423e3785551d4579a07bb3615d1ee)
### [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver/tree/f0baa47e75ab0bef0ec56ab48d9a725e00f6b40f)
* [OCPBUGS-80815](https://issues.redhat.com/browse/OCPBUGS-80815): Bump google.golang.org/grpc to v1.79.3 [#146](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/146)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver/compare/8fe7dafcf238c9416094672e1baf45105622e575...f0baa47e75ab0bef0ec56ab48d9a725e00f6b40f)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/d2dc1470a6b71312fcfefdf4d334288302b6cfec)
* [OCPBUGS-104105](https://issues.redhat.com/browse/OCPBUGS-104105): Replace golang.org/x/net with openshift-sustaining/net [#175](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/175)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/f7e3ec30f746add35458fad54dd6bccb97e307bf...d2dc1470a6b71312fcfefdf4d334288302b6cfec)
### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/22e131a00d874c240531c40141a8a780fbb48bd5)
* [OCPBUGS-104113](https://issues.redhat.com/browse/OCPBUGS-104113): replace golang.org/x/net with openshift-sustaining/net v0.50.0-sec.4 [#101](https://github.com/openshift/machine-api-provider-ibmcloud/pull/101)
* [OCPBUGS-77445](https://issues.redhat.com/browse/OCPBUGS-77445): [release-4.21] bump vpc go sdk [#81](https://github.com/openshift/machine-api-provider-ibmcloud/pull/81)
* NO-JIRA: Modernize test infrastructure to align with other MAPI providers [#84](https://github.com/openshift/machine-api-provider-ibmcloud/pull/84)
* [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/e72a84714e5fb8c3256def77f7d77ffdc4b9b82e...22e131a00d874c240531c40141a8a780fbb48bd5)
### [insights-operator](https://github.com/openshift/insights-operator/tree/1117c195d377924c2843df48e42096b8de3291bc)
* [OCPBUGS-123175](https://issues.redhat.com/browse/OCPBUGS-123175): add custom proxy field to insights config [#1365](https://github.com/openshift/insights-operator/pull/1365)
* [OCPBUGS-104096](https://issues.redhat.com/browse/OCPBUGS-104096): Bump golang.org/x/net to v0.50.0-sec.3 [#1352](https://github.com/openshift/insights-operator/pull/1352)
* [OCPBUGS-109390](https://issues.redhat.com/browse/OCPBUGS-109390): secrets and configmap revisions count gathering [#1342](https://github.com/openshift/insights-operator/pull/1342)
* [OCPBUGS-100248](https://issues.redhat.com/browse/OCPBUGS-100248): Fix indentation bug on livenessProbe [#1333](https://github.com/openshift/insights-operator/pull/1333)
* [OCPBUGS-99015](https://issues.redhat.com/browse/OCPBUGS-99015): update HyperShift deployment manifest [#1323](https://github.com/openshift/insights-operator/pull/1323)
* [OCPBUGS-91985](https://issues.redhat.com/browse/OCPBUGS-91985): fall back to kube-system/global-pull-secret for Insights token [#1310](https://github.com/openshift/insights-operator/pull/1310)
* [OCPBUGS-87191](https://issues.redhat.com/browse/OCPBUGS-87191): extractro controller [#1300](https://github.com/openshift/insights-operator/pull/1300)
* [OCPBUGS-86805](https://issues.redhat.com/browse/OCPBUGS-86805): add config option to disable runtime extractor [#1295](https://github.com/openshift/insights-operator/pull/1295)
* [OCPBUGS-80818](https://issues.redhat.com/browse/OCPBUGS-80818): Bump google.golang.org/grpc to v1.79.3 [#1285](https://github.com/openshift/insights-operator/pull/1285)
* [OCPBUGS-81573](https://issues.redhat.com/browse/OCPBUGS-81573): kubeletconfig gatherer [#1266](https://github.com/openshift/insights-operator/pull/1266)
* [OCPBUGS-79534](https://issues.redhat.com/browse/OCPBUGS-79534): [release-4.21] Add OpenTelemetry CR Gatherer [#1258](https://github.com/openshift/insights-operator/pull/1258)
* [Full changelog](https://github.com/openshift/insights-operator/compare/a6cc2a3f799e5cf4ca85e631f6b903999f2b2ad6...1117c195d377924c2843df48e42096b8de3291bc)
### [insights-runtime-exporter, insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor/tree/8c41cb8680f29a915d33e4954fc5ff7f5352411b)
* Updating ose-insights-runtime-extractor-container image to be consistent with ART for 4.21 [#78](https://github.com/openshift/insights-runtime-extractor/pull/78)
* Updating ose-insights-runtime-exporter-container image to be consistent with ART for 4.21 [#77](https://github.com/openshift/insights-runtime-extractor/pull/77)
* Updating ose-insights-runtime-exporter-container image to be consistent with ART for 4.21 [#75](https://github.com/openshift/insights-runtime-extractor/pull/75)
* Updating ose-insights-runtime-exporter-container image to be consistent with ART for 4.21 [#71](https://github.com/openshift/insights-runtime-extractor/pull/71)
* [Full changelog](https://github.com/openshift/insights-runtime-extractor/compare/cdf2f43554a3a0eb033beb29f8b73d854d05f6f3...8c41cb8680f29a915d33e4954fc5ff7f5352411b)
### [ironic](https://github.com/openshift/ironic-image/tree/d9db7430c1e402239d980e0c10428341f49937de)
* [OCPBUGS-115166](https://issues.redhat.com/browse/OCPBUGS-115166): ZTP deployment failed on an iDRAC10 cluster [#919](https://github.com/openshift/ironic-image/pull/919)
* [OCPBUGS-105861](https://issues.redhat.com/browse/OCPBUGS-105861): update ironic pin to include CVE-2026-54423 fix (release-4.21) [#890](https://github.com/openshift/ironic-image/pull/890)
* [OCPBUGS-88473](https://issues.redhat.com/browse/OCPBUGS-88473): Update openstack-ironic commit hash in requirements.cachito that addresses CVE-2026-43003 [#885](https://github.com/openshift/ironic-image/pull/885)
* [OCPBUGS-97991](https://issues.redhat.com/browse/OCPBUGS-97991): Update openstack-ironic commit hash for CVE-2026-44918 [#876](https://github.com/openshift/ironic-image/pull/876)
* [OCPBUGS-90554](https://issues.redhat.com/browse/OCPBUGS-90554): [4.21] Fix parallel power concurrency [#856](https://github.com/openshift/ironic-image/pull/856)
* [OCPBUGS-82294](https://issues.redhat.com/browse/OCPBUGS-82294), [OCPBUGS-84370](https://issues.redhat.com/browse/OCPBUGS-84370): Update sushy and Ironic to resolve Cisco vMedia Insert and BIOS Settings update issues. [#829](https://github.com/openshift/ironic-image/pull/829)
* [OCPBUGS-84853](https://issues.redhat.com/browse/OCPBUGS-84853): Bump pyasn to 0.5.1-5 [#823](https://github.com/openshift/ironic-image/pull/823)
* [OCPBUGS-82298](https://issues.redhat.com/browse/OCPBUGS-82298): Bump sushy hash to include Supermicro ARS-111GL-NHR fix [#840](https://github.com/openshift/ironic-image/pull/840)
* [Full changelog](https://github.com/openshift/ironic-image/compare/d23a6091f362d46421276749a5faa9871dbc20e7...d9db7430c1e402239d980e0c10428341f49937de)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/156ef6b4730f01279216d3296349ca0cae29466c)
* [OCPBUGS-100051](https://issues.redhat.com/browse/OCPBUGS-100051): Bump ironic-python-agent pinned commit for CVE-2026-66138 [#296](https://github.com/openshift/ironic-agent-image/pull/296)
* [OCPBUGS-88473](https://issues.redhat.com/browse/OCPBUGS-88473): Update commit SHA in requirements.cachito to address CVE-2026-43003 [#298](https://github.com/openshift/ironic-agent-image/pull/298)
* [OCPBUGS-95062](https://issues.redhat.com/browse/OCPBUGS-95062): Replace individual package removal with a single rpm -e loop [#283](https://github.com/openshift/ironic-agent-image/pull/283)
* [OCPBUGS-95062](https://issues.redhat.com/browse/OCPBUGS-95062): Replace dnf remove with rpm -e to prevent dependency removal [#271](https://github.com/openshift/ironic-agent-image/pull/271)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/ff276c00e345b9cb9298ce9dbdd7f19a8b14dbce...156ef6b4730f01279216d3296349ca0cae29466c)
### [keepalived-ipfailover](https://github.com/openshift/images/tree/f0241a3d2a12a8b2965cc36542babce8a1dffcf8)
* [OCPBUGS-99781](https://issues.redhat.com/browse/OCPBUGS-99781): Reinstall tzdata if /usr/share/zoneinfo is missing [#248](https://github.com/openshift/images/pull/248)
* [Full changelog](https://github.com/openshift/images/compare/e00f5806587e71188805bab43dad9099524b9059...f0241a3d2a12a8b2965cc36542babce8a1dffcf8)
### [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server/tree/ff4f3e2a6d2b0e8a860831b98733cff152cfddd3)
* [OCPBUGS-80716](https://issues.redhat.com/browse/OCPBUGS-80716): Bump google.golang.org/grpc to v1.79.3 [#61](https://github.com/openshift/kubernetes-metrics-server/pull/61)
* [Full changelog](https://github.com/openshift/kubernetes-metrics-server/compare/ed76a5e8051caae6519342ae189088b8ddd09979...ff4f3e2a6d2b0e8a860831b98733cff152cfddd3)
### [kube-state-metrics](https://github.com/openshift/kube-state-metrics/tree/8406e402ad020185813942842d4914ff7730fdc1)
* [OCPBUGS-99400](https://issues.redhat.com/browse/OCPBUGS-99400): fix CronJob timezone panic and embed tzdata in kube-state-metrics [#151](https://github.com/openshift/kube-state-metrics/pull/151)
* Fix for OCPBUGS-81988: CVE-2026-34986 bump github.com/go-jose/go-jose [#143](https://github.com/openshift/kube-state-metrics/pull/143)
* [OCPBUGS-80823](https://issues.redhat.com/browse/OCPBUGS-80823): Bump google.golang.org/grpc to v1.79.3 [#138](https://github.com/openshift/kube-state-metrics/pull/138)
* [Full changelog](https://github.com/openshift/kube-state-metrics/compare/cb0aa591e89797cc0f45b934b8baeccc3a3b09bf...8406e402ad020185813942842d4914ff7730fdc1)
### [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver/tree/8a115121952348de9a4e4a73478755258a401a86)
* [OCPBUGS-80717](https://issues.redhat.com/browse/OCPBUGS-80717): Bump google.golang.org/grpc to v1.79.3 [#98](https://github.com/openshift/kubevirt-csi-driver/pull/98)
* [Full changelog](https://github.com/openshift/kubevirt-csi-driver/compare/4bb70e49c9d05690f3a26edc0a6feaf093169cbb...8a115121952348de9a4e4a73478755258a401a86)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/aac6c87b2ebf762bf049c6a69aedbc6096323e1c)
* [OCPBUGS-104125](https://issues.redhat.com/browse/OCPBUGS-104125): replace golang.org/x/net with openshift-sustaining/net@v0.50.0-sec.4 [#1542](https://github.com/openshift/machine-api-operator/pull/1542)
* [OCPBUGS-86493](https://issues.redhat.com/browse/OCPBUGS-86493): Populate status label selector for scale subresource [#1501](https://github.com/openshift/machine-api-operator/pull/1501)
* [OCPBUGS-77943](https://issues.redhat.com/browse/OCPBUGS-77943): Remove cluster-api-provider-libvirt references [#1473](https://github.com/openshift/machine-api-operator/pull/1473)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/83936ddec5de0d3c9e6db44e541e0abac2b60b6c...aac6c87b2ebf762bf049c6a69aedbc6096323e1c)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/0c32560860e39c44babcc69692782c63119fb331)
* [OCPBUGS-120453](https://issues.redhat.com/browse/OCPBUGS-120453): Update message for MachineOSBuildFailed condition [#6493](https://github.com/openshift/machine-config-operator/pull/6493)
* [OCPBUGS-116929](https://issues.redhat.com/browse/OCPBUGS-116929): Update AMI Whitelist [#6486](https://github.com/openshift/machine-config-operator/pull/6486)
* [OCPBUGS-112469](https://issues.redhat.com/browse/OCPBUGS-112469): Fix SHA idempotency test in nmstate-configuration.sh [#6430](https://github.com/openshift/machine-config-operator/pull/6430)
* [OCPBUGS-114391](https://issues.redhat.com/browse/OCPBUGS-114391): Use kubernetes scheme in drain controller event recorder [#6457](https://github.com/openshift/machine-config-operator/pull/6457)
* [OCPBUGS-109656](https://issues.redhat.com/browse/OCPBUGS-109656): Fix duplicate template error [#6405](https://github.com/openshift/machine-config-operator/pull/6405)
* [OCPBUGS-105303](https://issues.redhat.com/browse/OCPBUGS-105303): Use providerSpec.Template in vSphere machineset reconciliation [#6381](https://github.com/openshift/machine-config-operator/pull/6381)
* [OCPBUGS-105214](https://issues.redhat.com/browse/OCPBUGS-105214): Update AMI Whitelist [#6376](https://github.com/openshift/machine-config-operator/pull/6376)
* [OCPBUGS-93806](https://issues.redhat.com/browse/OCPBUGS-93806): move cleanUpDuplicatedMC to avoid double reboot on first updated Master node [#6241](https://github.com/openshift/machine-config-operator/pull/6241)
* [OCPBUGS-97905](https://issues.redhat.com/browse/OCPBUGS-97905): Inject proxy into MCC deployment [#6276](https://github.com/openshift/machine-config-operator/pull/6276)
* [OCPBUGS-88510](https://issues.redhat.com/browse/OCPBUGS-88510): fix: update arbiter crio config [#6189](https://github.com/openshift/machine-config-operator/pull/6189)
* [release:4.21] OCPBUGS-89234: In OCB to check when a image is removed the old build is triggered again and the MC should start updating directly and no new MOSB should be triggred [#6196](https://github.com/openshift/machine-config-operator/pull/6196)
* [OCPBUGS-95588](https://issues.redhat.com/browse/OCPBUGS-95588): Remove sensitive ControllerConfig logging [#6257](https://github.com/openshift/machine-config-operator/pull/6257)
* [OCPBUGS-91971](https://issues.redhat.com/browse/OCPBUGS-91971): Make vsphere template updates atomic [#6229](https://github.com/openshift/machine-config-operator/pull/6229)
* [OCPBUGS-94108](https://issues.redhat.com/browse/OCPBUGS-94108): Fix kubelet certificate wait loop in criometricsproxy.yaml [#6248](https://github.com/openshift/machine-config-operator/pull/6248)
* [OCPBUGS-96153](https://issues.redhat.com/browse/OCPBUGS-96153): Update AMI Whitelist [#6261](https://github.com/openshift/machine-config-operator/pull/6261)
* [OCPBUGS-93937](https://issues.redhat.com/browse/OCPBUGS-93937): Bootstrap MCS logging entire ignition [#6244](https://github.com/openshift/machine-config-operator/pull/6244)
* [OCPBUGS-91734](https://issues.redhat.com/browse/OCPBUGS-91734): Replace wildcard permissions with explicit verbs and resources in MCC ClusterRole [#6208](https://github.com/openshift/machine-config-operator/pull/6208)
* [OCPBUGS-89243](https://issues.redhat.com/browse/OCPBUGS-89243): Process rebuild annotation on machine-os-builder restart [#6197](https://github.com/openshift/machine-config-operator/pull/6197)
* [OCPBUGS-88709](https://issues.redhat.com/browse/OCPBUGS-88709): Update custom containerfile OCB test to work in a disconnected environment [#6193](https://github.com/openshift/machine-config-operator/pull/6193)
* [OCPBUGS-88340](https://issues.redhat.com/browse/OCPBUGS-88340): vSphere boot image hot loop detection is non-functional due to stable template names [#6180](https://github.com/openshift/machine-config-operator/pull/6180)
* [OCPBUGS-89340](https://issues.redhat.com/browse/OCPBUGS-89340): Remove skopeo-install script [#6202](https://github.com/openshift/machine-config-operator/pull/6202)
* [OCPBUGS-88334](https://issues.redhat.com/browse/OCPBUGS-88334): Skip chrony-wait on first node join [#6178](https://github.com/openshift/machine-config-operator/pull/6178)
* [OCPBUGS-88335](https://issues.redhat.com/browse/OCPBUGS-88335): daemon: don't pull/extract extensions for all OS updates [#6179](https://github.com/openshift/machine-config-operator/pull/6179)
* [OCPBUGS-86998](https://issues.redhat.com/browse/OCPBUGS-86998): configure-ovs: copy lldp mode to br-ex port [#6134](https://github.com/openshift/machine-config-operator/pull/6134)
* [OCPBUGS-87008](https://issues.redhat.com/browse/OCPBUGS-87008): Stabilize ocl 4.21 [#6138](https://github.com/openshift/machine-config-operator/pull/6138)
* [OCPBUGS-86979](https://issues.redhat.com/browse/OCPBUGS-86979): Update AMI Whitelist [#6129](https://github.com/openshift/machine-config-operator/pull/6129)
* [OCPBUGS-86576](https://issues.redhat.com/browse/OCPBUGS-86576): Verify extension packages are installed [#6090](https://github.com/openshift/machine-config-operator/pull/6090)
* [OCPBUGS-84481](https://issues.redhat.com/browse/OCPBUGS-84481): MCS fallback to latest v3 [#5883](https://github.com/openshift/machine-config-operator/pull/5883)
* [OCPBUGS-86216](https://issues.redhat.com/browse/OCPBUGS-86216): Fix re-cordon detection [#6066](https://github.com/openshift/machine-config-operator/pull/6066)
* [OCPBUGS-86232](https://issues.redhat.com/browse/OCPBUGS-86232): Apply password only if changes exist [#6068](https://github.com/openshift/machine-config-operator/pull/6068)
* [OCPBUGS-86037](https://issues.redhat.com/browse/OCPBUGS-86037): use `--delete-if-present` for karg removal [#6058](https://github.com/openshift/machine-config-operator/pull/6058)
* [OCPBUGS-85645](https://issues.redhat.com/browse/OCPBUGS-85645): Add terminationMessagePolicy to build pod containers [#6045](https://github.com/openshift/machine-config-operator/pull/6045)
* [OCPBUGS-85386](https://issues.redhat.com/browse/OCPBUGS-85386): Fix CVE-2026-34986 [#6025](https://github.com/openshift/machine-config-operator/pull/6025)
* [OCPBUGS-85286](https://issues.redhat.com/browse/OCPBUGS-85286): Fix Admin Ack message for azure/vsphere clusters upgrading to 4.22 [#6017](https://github.com/openshift/machine-config-operator/pull/6017)
* [OCPBUGS-85126](https://issues.redhat.com/browse/OCPBUGS-85126): Fix units rollback if update failure [#6008](https://github.com/openshift/machine-config-operator/pull/6008)
* [OCPBUGS-84941](https://issues.redhat.com/browse/OCPBUGS-84941): Fix ssh and password rollbacks [#5987](https://github.com/openshift/machine-config-operator/pull/5987)
* [OCPBUGS-84970](https://issues.redhat.com/browse/OCPBUGS-84970): Fix encapsulated IGN version [#5996](https://github.com/openshift/machine-config-operator/pull/5996)
* [OCPBUGS-84878](https://issues.redhat.com/browse/OCPBUGS-84878): Update AMI Whitelist [#5915](https://github.com/openshift/machine-config-operator/pull/5915)
* [OCPBUGS-84253](https://issues.redhat.com/browse/OCPBUGS-84253): improve JSON unmarshalling for secret decoding [#5877](https://github.com/openshift/machine-config-operator/pull/5877)
* [OCPBUGS-83874](https://issues.redhat.com/browse/OCPBUGS-83874): Allow enablement of systemd units with existing files [#5869](https://github.com/openshift/machine-config-operator/pull/5869)
* [OCPBUGS-83708](https://issues.redhat.com/browse/OCPBUGS-83708): Update AMI Whitelist [#5857](https://github.com/openshift/machine-config-operator/pull/5857)
* [OCPBUGS-83390](https://issues.redhat.com/browse/OCPBUGS-83390): Use HA leader election defaults for MCO on SNO [#5838](https://github.com/openshift/machine-config-operator/pull/5838)
* [OCPBUGS-81711](https://issues.redhat.com/browse/OCPBUGS-81711): When adding new nodes, MCD executes commands after setting the nodes' state as Done [#5836](https://github.com/openshift/machine-config-operator/pull/5836)
* [OCPBUGS-79482](https://issues.redhat.com/browse/OCPBUGS-79482): Skip boot image updates until cluster is stable [#5804](https://github.com/openshift/machine-config-operator/pull/5804)
* [OCPBUGS-79426](https://issues.redhat.com/browse/OCPBUGS-79426): Update AMI Whitelist [#5798](https://github.com/openshift/machine-config-operator/pull/5798)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/a2530e2fdbd881f9c3b0cb49f224ead07d797f10...0c32560860e39c44babcc69692782c63119fb331)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/581c9d9e453c73f67a93c44fb6715057c0cc8bf5)
* [OCPBUGS-87873](https://issues.redhat.com/browse/OCPBUGS-87873): Add support for hermetic builds via Cachi2 prefetched CoreOS ISOs [#97](https://github.com/openshift/machine-os-images/pull/97)
* [OCPBUGS-85478](https://issues.redhat.com/browse/OCPBUGS-85478): Force rebuild for OCP 4.21 [#93](https://github.com/openshift/machine-os-images/pull/93)
* [OCPBUGS-85478](https://issues.redhat.com/browse/OCPBUGS-85478): Force rebuild for OCP 4.21 [#89](https://github.com/openshift/machine-os-images/pull/89)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/9a8e96a60bb6d8e3c86c2780fd4212e80f5d28e5...581c9d9e453c73f67a93c44fb6715057c0cc8bf5)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/bf3d167908ec0e4ac35c9c07eeadb1dd979d4efb)
* NO-JIRA: [release-4.21] Sanitize alert runbook URLs [#1296](https://github.com/openshift/monitoring-plugin/pull/1296)
* Fix OCPBUGS-104124: CVE-2026-33814 Replace golang.org/x/net with the patched github.com/openshift-sustaining/net@v0.50.0-sec.4 fork to remediate CVE-2026-33814 [#1201](https://github.com/openshift/monitoring-plugin/pull/1201)
* [OCPBUGS-98789](https://issues.redhat.com/browse/OCPBUGS-98789): [release-4.21] replace outdated react-linkify dependency [#1149](https://github.com/openshift/monitoring-plugin/pull/1149)
* [OCPBUGS-98425](https://issues.redhat.com/browse/OCPBUGS-98425): fix for CVE-2026-59869 [#1136](https://github.com/openshift/monitoring-plugin/pull/1136)
* Fix for OCPBUGS-89702: CVE-2026-12143 [#1090](https://github.com/openshift/monitoring-plugin/pull/1090)
* NO-JIRA: [release-4.21] - e2e monitoring stabilization [#919](https://github.com/openshift/monitoring-plugin/pull/919)
* [OCPBUGS-99028](https://issues.redhat.com/browse/OCPBUGS-99028): Fix CVE-2026-49978 - bump DOMPurify to >= 3.4.7 [#1086](https://github.com/openshift/monitoring-plugin/pull/1086)
* [OU-1240](https://issues.redhat.com/browse/OU-1240): Makefile and package.json to enable test-frontend-ci [#1095](https://github.com/openshift/monitoring-plugin/pull/1095)
* [OCPBUGS-99283](https://issues.redhat.com/browse/OCPBUGS-99283): graph redirect query parameter [#1072](https://github.com/openshift/monitoring-plugin/pull/1072)
* [OU-651](https://issues.redhat.com/browse/OU-651): Fix AlertRules page to display user defined loki alerts [#1060](https://github.com/openshift/monitoring-plugin/pull/1060)
* Fix for OCPBUGS-91631: CVE-2026-45736 [#1024](https://github.com/openshift/monitoring-plugin/pull/1024)
* [OU-1396](https://issues.redhat.com/browse/OU-1396): [release-4.21] fix: use replace to set variables to avoid navigation trap [#1033](https://github.com/openshift/monitoring-plugin/pull/1033)
* NO-JIRA: fix incidents unit test [#1037](https://github.com/openshift/monitoring-plugin/pull/1037)
* Fix for OCPBUGS-94011: CVE-2026-13676 [#1029](https://github.com/openshift/monitoring-plugin/pull/1029)
* [OCPBUGS-87088](https://issues.redhat.com/browse/OCPBUGS-87088): [release-4.21] fast-uri: URI authority bypass due to improper delimiter handling [#973](https://github.com/openshift/monitoring-plugin/pull/973)
* [OCPBUGS-88396](https://issues.redhat.com/browse/OCPBUGS-88396): CVE-2026-44487 bump axios to 1.16.0 [#999](https://github.com/openshift/monitoring-plugin/pull/999)
* [OCPBUGS-84290](https://issues.redhat.com/browse/OCPBUGS-84290): bump follow-redirects to 1.16.0 [#987](https://github.com/openshift/monitoring-plugin/pull/987)
* [OCPBUGS-84828](https://issues.redhat.com/browse/OCPBUGS-84828), [OCPBUGS-84991](https://issues.redhat.com/browse/OCPBUGS-84991), [OCPBUGS-85007](https://issues.redhat.com/browse/OCPBUGS-85007), [OCPBUGS-85037](https://issues.redhat.com/browse/OCPBUGS-85037): Update Axios to v1.15.2 [#982](https://github.com/openshift/monitoring-plugin/pull/982)
* [OCPBUGS-79460](https://issues.redhat.com/browse/OCPBUGS-79460): immutable bump: fix for CVE-2026-29063 [4.21] [#947](https://github.com/openshift/monitoring-plugin/pull/947)
* [OU-1368](https://issues.redhat.com/browse/OU-1368): reset queries when namespace changes in dev perspective [#940](https://github.com/openshift/monitoring-plugin/pull/940)
* [OU-1367](https://issues.redhat.com/browse/OU-1367): prevent namespace and project desync [#937](https://github.com/openshift/monitoring-plugin/pull/937)
* NO-JIRA: release-4.21 e2e-monitoring and e2e-coo working [#904](https://github.com/openshift/monitoring-plugin/pull/904)
* [OCPBUGS-83494](https://issues.redhat.com/browse/OCPBUGS-83494): [release-4.21] feat: re enable dev console views [#856](https://github.com/openshift/monitoring-plugin/pull/856)
* [OCPBUGS-83304](https://issues.redhat.com/browse/OCPBUGS-83304): [release-4.21] openshift4/ose-monitoring-plugin-rhel9: Axios: Remote Code Execution via Prototype Pollution escalation [#890](https://github.com/openshift/monitoring-plugin/pull/890)
* [OCPBUGS-82302](https://issues.redhat.com/browse/OCPBUGS-82302): [release-4.21] fix: re encode params when redirecting from graph to query-browser [#871](https://github.com/openshift/monitoring-plugin/pull/871)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/9d65f65fad61b07bc2bc5f69803692f77ff95181...bf3d167908ec0e4ac35c9c07eeadb1dd979d4efb)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/838992e31e88cdf921fa32e0da8846beb301a020)
* [OCPBUGS-120763](https://issues.redhat.com/browse/OCPBUGS-120763): [Release 4.21] Cherry-pick fix for the issue of stripping delegate datastore config on CNI DEL, leaking IPAM addresses [#351](https://github.com/openshift/multus-cni/pull/351)
* [OCPBUGS-80831](https://issues.redhat.com/browse/OCPBUGS-80831): bump grpc to 1.79.3 to address CVE-2026-33186 [#310](https://github.com/openshift/multus-cni/pull/310)
* [OCPBUGS-82064](https://issues.redhat.com/browse/OCPBUGS-82064): Bump CNI version to 1.1.0 [#284](https://github.com/openshift/multus-cni/pull/284)
* [Full changelog](https://github.com/openshift/multus-cni/compare/93556f99405e29900c5445f7bbf7c70b8935e339...838992e31e88cdf921fa32e0da8846beb301a020)
### [must-gather](https://github.com/openshift/must-gather/tree/eeb267f4b7f8016f13d12866013cad43c7403482)
* [OCPBUGS-85050](https://issues.redhat.com/browse/OCPBUGS-85050): Collect object size with the object count [#542](https://github.com/openshift/must-gather/pull/542)
* [Full changelog](https://github.com/openshift/must-gather/compare/b4b434c427ddde3dafd8518d1aa754e49b7bfef1...eeb267f4b7f8016f13d12866013cad43c7403482)
### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/9af0359dc73e8489059057a625d53c5293923993)
* [OCPBUGS-104121](https://issues.redhat.com/browse/OCPBUGS-104121): Replace golang.org/x/net with github.com/openshift-sustaining/net@v0.50.0-sec.3 to address CVE-2026-33814 [#150](https://github.com/openshift/network-metrics-daemon/pull/150)
* [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/844fa588c4200b8ff768d1916d63f1d4c1db2daf...9af0359dc73e8489059057a625d53c5293923993)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/053ddf6c5f90ae6d01422e931710ee34d61bfff9)
* maintenance: Bump the npm group across 1 directory with 20 updates [#536](https://github.com/openshift/networking-console-plugin/pull/536)
* maintenance: Bump the npm group with 232 updates [#498](https://github.com/openshift/networking-console-plugin/pull/498)
* [OCPNETUI-82](https://issues.redhat.com/browse/OCPNETUI-82): Lower Dockerfile base image versions [#518](https://github.com/openshift/networking-console-plugin/pull/518)
* [OCPBUGS-85606](https://issues.redhat.com/browse/OCPBUGS-85606): Fix React error on MultiNetworkPolicies page [#484](https://github.com/openshift/networking-console-plugin/pull/484)
* [OCPBUGS-98790](https://issues.redhat.com/browse/OCPBUGS-98790): Updating linkify-it to 5.0.2 to fix CVE-2026-48801 [#463](https://github.com/openshift/networking-console-plugin/pull/463)
* [OCPBUGS-74099](https://issues.redhat.com/browse/OCPBUGS-74099): fixed translations of pod column titles [#435](https://github.com/openshift/networking-console-plugin/pull/435)
* [OCPBUGS-92375](https://issues.redhat.com/browse/OCPBUGS-92375): Updated doc links based on release [#439](https://github.com/openshift/networking-console-plugin/pull/439)
* [OCPBUGS-88313](https://issues.redhat.com/browse/OCPBUGS-88313): Trim subnet input in UDN creation form [#430](https://github.com/openshift/networking-console-plugin/pull/430)
* [OCPBUGS-81620](https://issues.redhat.com/browse/OCPBUGS-81620): Update lodash to 4.18.1 for CVE-2026-4800 [#372](https://github.com/openshift/networking-console-plugin/pull/372)
* [OCPBUGS-83388](https://issues.redhat.com/browse/OCPBUGS-83388): Fix CVE-2026-34043 in serialize-javascript [#369](https://github.com/openshift/networking-console-plugin/pull/369)
* [OCPBUGS-82161](https://issues.redhat.com/browse/OCPBUGS-82161): Migrate to npm [#359](https://github.com/openshift/networking-console-plugin/pull/359)
* [OCPBUGS-66283](https://issues.redhat.com/browse/OCPBUGS-66283), [OCPBUGS-67252](https://issues.redhat.com/browse/OCPBUGS-67252), [OCPBUGS-70285](https://issues.redhat.com/browse/OCPBUGS-70285), [OCPBUGS-74473](https://issues.redhat.com/browse/OCPBUGS-74473): Fix CVEs via upgrading yarn.lock [#346](https://github.com/openshift/networking-console-plugin/pull/346)
* [CNV-59877](https://issues.redhat.com/browse/CNV-59877): Fix permissions request for NADs [#353](https://github.com/openshift/networking-console-plugin/pull/353)
* [OCPBUGS-77887](https://issues.redhat.com/browse/OCPBUGS-77887): Clean up cruft in /var/cache/dnf [#361](https://github.com/openshift/networking-console-plugin/pull/361)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/0e839893223991122cfb7cf8722ba651727aa9f3...053ddf6c5f90ae6d01422e931710ee34d61bfff9)
### [oauth-server](https://github.com/openshift/oauth-server/tree/85a8ae3529821203c39559c4df6231ef3607e64e)
* [OCPBUGS-81816](https://issues.redhat.com/browse/OCPBUGS-81816): Bump github.com/go-jose/go-jose/v3 from v3.0.3 to v3.0.5 [#234](https://github.com/openshift/oauth-server/pull/234)
* [Full changelog](https://github.com/openshift/oauth-server/compare/2b8183592190365c269ca0c92b1955bbad9a0236...85a8ae3529821203c39559c4df6231ef3607e64e)
### [oc-mirror](https://github.com/openshift/oc-mirror/tree/4b703bbbc654f820f6877f635f1785cb599ed896)
* [OCPBUGS-105785](https://issues.redhat.com/browse/OCPBUGS-105785): fix for CVE-2026-39829 [#1503](https://github.com/openshift/oc-mirror/pull/1503)
* Fix for OCPBUGS-81971: CVE-2026-34986 github.com/go-jose/go-jose/v4 [#1426](https://github.com/openshift/oc-mirror/pull/1426)
* [OCPBUGS-82546](https://issues.redhat.com/browse/OCPBUGS-82546): Only print catalog rebuild message if there are catalogs to rebuild [#1388](https://github.com/openshift/oc-mirror/pull/1388)
* [OCPBUGS-82543](https://issues.redhat.com/browse/OCPBUGS-82543): Fix printing collection messages with 0 collection items [#1387](https://github.com/openshift/oc-mirror/pull/1387)
* [OCPBUGS-81743](https://issues.redhat.com/browse/OCPBUGS-81743): Remove status field from CatalogSource, ClusterCatalog... [#1383](https://github.com/openshift/oc-mirror/pull/1383)
* [Full changelog](https://github.com/openshift/oc-mirror/compare/12f1b068e9928aa68e5505fc16fcaaac3dfd27d3...4b703bbbc654f820f6877f635f1785cb599ed896)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/400e482b88c53973f595fc30de366aa2675f33c5)
* [OCPBUGS-104166](https://issues.redhat.com/browse/OCPBUGS-104166): [release-4.21] Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [#801](https://github.com/openshift/operator-framework-operator-controller/pull/801)
* [OCPBUGS-100383](https://issues.redhat.com/browse/OCPBUGS-100383): Fix cache path to avoid /var/cache/dnf conflict [#785](https://github.com/openshift/operator-framework-operator-controller/pull/785)
* [OCPBUGS-98090](https://issues.redhat.com/browse/OCPBUGS-98090): fix(test): use in-cluster catalog for preflight permission checks [release-4.21] [#778](https://github.com/openshift/operator-framework-operator-controller/pull/778)
* [OCPBUGS-99756](https://issues.redhat.com/browse/OCPBUGS-99756): increase catalog HTTP client timeout from 10s to 5m [#774](https://github.com/openshift/operator-framework-operator-controller/pull/774)
* [OCPBUGS-86842](https://issues.redhat.com/browse/OCPBUGS-86842): [release-4.21] catalogd: clean up orphaned temp dirs in catalog storage [#742](https://github.com/openshift/operator-framework-operator-controller/pull/742)
* [OCPBUGS-81993](https://issues.redhat.com/browse/OCPBUGS-81993), [OCPBUGS-81994](https://issues.redhat.com/browse/OCPBUGS-81994): Bump github.com/go-jose/go-jose/v4 to 4.1.4 [#718](https://github.com/openshift/operator-framework-operator-controller/pull/718)
* [OCPBUGS-80839](https://issues.redhat.com/browse/OCPBUGS-80839), [OCPBUGS-80840](https://issues.redhat.com/browse/OCPBUGS-80840): Bump google.golang.org/grpc to v1.79.3 [#721](https://github.com/openshift/operator-framework-operator-controller/pull/721)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/d0f315fc0008290ca7d6d908ba1d2465907fc7de...400e482b88c53973f595fc30de366aa2675f33c5)
### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/f427de801b98823e486bdd5955468d88e95c2ac4)
* [OCPBUGS-82918](https://issues.redhat.com/browse/OCPBUGS-82918): Address CVE-2026-35469 [#646](https://github.com/openshift/openshift-apiserver/pull/646)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/64dea074d6b457e1fae3598cea0bb72493d2cab8...f427de801b98823e486bdd5955468d88e95c2ac4)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/d02231d0a92491926666f4f1f5e45a7e2c733cb7)
* UPSTREAM-SYNC: Merge https://github.com/kubernetes-sigs/cluster-api-provider-openstack:release-0.13 into release-4.21 [#417](https://github.com/openshift/cluster-api-provider-openstack/pull/417)
* UPSTREAM-SYNC: Merge https://github.com/kubernetes-sigs/cluster-api-provider-openstack:release-0.13 into release-4.21 [#394](https://github.com/openshift/cluster-api-provider-openstack/pull/394)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/e1c0f2f9e2e70843d5c42dfe3bddf70530a97b0f...d02231d0a92491926666f4f1f5e45a7e2c733cb7)
### [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack/tree/b7456a2a12d1e65a5688693a005ad1e18aaee1be)
* [OCPBUGS-97825](https://issues.redhat.com/browse/OCPBUGS-97825): Revendor CAPO [#176](https://github.com/openshift/machine-api-provider-openstack/pull/176)
* [Full changelog](https://github.com/openshift/machine-api-provider-openstack/compare/b1fdb10f47f3bdb5c2902fac1d53bfa98c3a88ab...b7456a2a12d1e65a5688693a005ad1e18aaee1be)
### [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller/tree/1ff3909142325a184993917fd9447c24cd6ce63f)
* [OCPBUGS-104030](https://issues.redhat.com/browse/OCPBUGS-104030): Replace golang.org/x/net with github.com/openshift-sustaining/net@v0.43.0-sec.3 to address CVE-2026-33814 [#44](https://github.com/openshift/openstack-resource-controller/pull/44)
* UPSTREAM-SYNC: Bump envtest version [#47](https://github.com/openshift/openstack-resource-controller/pull/47)
* [Full changelog](https://github.com/openshift/openstack-resource-controller/compare/70f5ad34915041c82ad0a8ed6ea64bd8859d1e72...1ff3909142325a184993917fd9447c24cd6ce63f)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/e0c18696b033d125090f0af6205ec5cd39eaf9de)
* [OCPBUGS-104147](https://issues.redhat.com/browse/OCPBUGS-104147), [OCPBUGS-104152](https://issues.redhat.com/browse/OCPBUGS-104152): CVE-2026-33814: Replace golang.org/x/net with github.com/openshift-sustaining/net@v0.50.0-sec.3 [#1363](https://github.com/openshift/operator-framework-olm/pull/1363)
* [OCPBUGS-95444](https://issues.redhat.com/browse/OCPBUGS-95444), [OCPBUGS-95447](https://issues.redhat.com/browse/OCPBUGS-95447): bumping containerd to v1.7.33 [#1354](https://github.com/openshift/operator-framework-olm/pull/1354)
* [OCPBUGS-81995](https://issues.redhat.com/browse/OCPBUGS-81995), [OCPBUGS-81996](https://issues.redhat.com/browse/OCPBUGS-81996), [OCPBUGS-81997](https://issues.redhat.com/browse/OCPBUGS-81997): Bump github.com/go-jose/go-jose/v4 to v4.1.4 [#1294](https://github.com/openshift/operator-framework-olm/pull/1294)
* [OCPBUGS-80847](https://issues.redhat.com/browse/OCPBUGS-80847), [OCPBUGS-80848](https://issues.redhat.com/browse/OCPBUGS-80848), [OCPBUGS-80849](https://issues.redhat.com/browse/OCPBUGS-80849): Bump google.golang.org/grpc to v1.79.3 for CVE-2026-33186[Release-4.21] [#1289](https://github.com/openshift/operator-framework-olm/pull/1289)
* [OCPBUGS-79398](https://issues.redhat.com/browse/OCPBUGS-79398): Fix SA restore resourceVersion conflict error [#1266](https://github.com/openshift/operator-framework-olm/pull/1266)
* [OCPBUGS-79400](https://issues.redhat.com/browse/OCPBUGS-79400): Fix nil pointer dereference in sortUnpackJobs when sorting non-failed jobs [#1265](https://github.com/openshift/operator-framework-olm/pull/1265)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/c859a9b75e743b5899ba1e7a2adbcc85633a7d64...e0c18696b033d125090f0af6205ec5cd39eaf9de)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/e2e61dbe576da162f711394c89068b8067f72343)
* [OCPBUGS-112513](https://issues.redhat.com/browse/OCPBUGS-112513): NO-JIRA: Branch Sync release-4.22 to release-4.21 [08-21-2026] [#3413](https://github.com/openshift/ovn-kubernetes/pull/3413)
* [OCPBUGS-99165](https://issues.redhat.com/browse/OCPBUGS-99165): Branch Sync release-4.22 to release-4.21 [08-13-2026] [#3393](https://github.com/openshift/ovn-kubernetes/pull/3393)
* [OCPBUGS-105516](https://issues.redhat.com/browse/OCPBUGS-105516), [OCPBUGS-105605](https://issues.redhat.com/browse/OCPBUGS-105605): Branch Sync release-4.22 to release-4.21 [08-10-2026] [#3374](https://github.com/openshift/ovn-kubernetes/pull/3374)
* [OCPBUGS-90029](https://issues.redhat.com/browse/OCPBUGS-90029), [OCPBUGS-90470](https://issues.redhat.com/browse/OCPBUGS-90470), [OCPBUGS-92544](https://issues.redhat.com/browse/OCPBUGS-92544), [OCPBUGS-93018](https://issues.redhat.com/browse/OCPBUGS-93018): Branch Sync release-4.22 to release-4.21 [08-06-2026] [#3365](https://github.com/openshift/ovn-kubernetes/pull/3365)
* [OCPBUGS-95075](https://issues.redhat.com/browse/OCPBUGS-95075): Branch Sync release-4.22 to release-4.21 [07-29-2026] [#3337](https://github.com/openshift/ovn-kubernetes/pull/3337)
* [OCPBUGS-99276](https://issues.redhat.com/browse/OCPBUGS-99276), [OCPBUGS-99277](https://issues.redhat.com/browse/OCPBUGS-99277): Branch Sync release-4.22 to release-4.21 [07-20-2026] [#3306](https://github.com/openshift/ovn-kubernetes/pull/3306)
* [OCPBUGS-99165](https://issues.redhat.com/browse/OCPBUGS-99165): Branch Sync release-4.22 to release-4.21 [07-15-2026] [#3300](https://github.com/openshift/ovn-kubernetes/pull/3300)
* [OCPBUGS-98398](https://issues.redhat.com/browse/OCPBUGS-98398): Branch Sync release-4.22 to release-4.21 [06-10-2026] [#3243](https://github.com/openshift/ovn-kubernetes/pull/3243)
* [OCPBUGS-84923](https://issues.redhat.com/browse/OCPBUGS-84923): Branch Sync release-4.22 to release-4.21 [04-27-2026] [#3160](https://github.com/openshift/ovn-kubernetes/pull/3160)
* [OCPBUGS-81634](https://issues.redhat.com/browse/OCPBUGS-81634), [OCPBUGS-83814](https://issues.redhat.com/browse/OCPBUGS-83814): Branch Sync release-4.22 to release-4.21 [04-16-2026] [#3145](https://github.com/openshift/ovn-kubernetes/pull/3145)
* [OCPBUGS-83566](https://issues.redhat.com/browse/OCPBUGS-83566): Branch Sync release-4.22 to release-4.21 [03-25-2026] [#3087](https://github.com/openshift/ovn-kubernetes/pull/3087)
* [OCPBUGS-81475](https://issues.redhat.com/browse/OCPBUGS-81475): node: fix serviceUpdateNotNeeded nil pointer comparison [#3098](https://github.com/openshift/ovn-kubernetes/pull/3098)
* [OCPBUGS-77257](https://issues.redhat.com/browse/OCPBUGS-77257), [OCPBUGS-78094](https://issues.redhat.com/browse/OCPBUGS-78094): Branch Sync release-4.22 to release-4.21 [03-23-2026] [#3080](https://github.com/openshift/ovn-kubernetes/pull/3080)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/010f7c2967b53f6c1be8286078cd4ae0dd65beae...e2e61dbe576da162f711394c89068b8067f72343)
### [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver/tree/bd7dd70130c531cce7d9a50138fe4286e4208b69)
* [OCPBUGS-104161](https://issues.redhat.com/browse/OCPBUGS-104161), [OCPBUGS-89654](https://issues.redhat.com/browse/OCPBUGS-89654), [OCPBUGS-90028](https://issues.redhat.com/browse/OCPBUGS-90028), [OCPBUGS-90454](https://issues.redhat.com/browse/OCPBUGS-90454), [OCPBUGS-91231](https://issues.redhat.com/browse/OCPBUGS-91231), [OCPBUGS-92545](https://issues.redhat.com/browse/OCPBUGS-92545), [OCPBUGS-93024](https://issues.redhat.com/browse/OCPBUGS-93024), [OCPBUGS-93510](https://issues.redhat.com/browse/OCPBUGS-93510), [OCPBUGS-95008](https://issues.redhat.com/browse/OCPBUGS-95008), [OCPBUGS-96558](https://issues.redhat.com/browse/OCPBUGS-96558): Bump golang.org dependencies [#144](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/144)
* [OCPBUGS-80852](https://issues.redhat.com/browse/OCPBUGS-80852): Fix CVE-2026-33186 by bumping google.golang.org/grpc to 1.79.3 [#127](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/127)
* [OCPBUGS-82924](https://issues.redhat.com/browse/OCPBUGS-82924): Fix CVE-2026-35469 by bumping github.com/moby/spdystream to v0.5.1 [#121](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/121)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver/compare/791e12aba9ab7c4fed1e5f9554e5b9ec86342e1a...bd7dd70130c531cce7d9a50138fe4286e4208b69)
### [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/tree/ac080eb0fe6c3849d2ff8cd8233a6d911f508043)
* [OCPBUGS-104163](https://issues.redhat.com/browse/OCPBUGS-104163): Mitigate CVE-2026-33814 by bumping golang.org/x/net to v0.57.0 [#122](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/122)
* Updating ose-powervs-block-csi-driver-operator-container image to be consistent with ART for 4.21 [#107](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/107)
* [OCPBUGS-80853](https://issues.redhat.com/browse/OCPBUGS-80853): Fix CVE-2026-33186 by bumping google.golang.org/grpc to v1.79.3 [#106](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/106)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/compare/e22228ae9f53298e7520d9ae2b9230b2d5dd4cff...ac080eb0fe6c3849d2ff8cd8233a6d911f508043)
### [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs/tree/40d1c0adfedeca36498a5d93d69aee96831c756d)
* [OCPBUGS-80854](https://issues.redhat.com/browse/OCPBUGS-80854): bump google.golang.org/grpc to v1.79.3 to fix CVE-2026-33186 [#98](https://github.com/openshift/cloud-provider-powervs/pull/98)
* [Full changelog](https://github.com/openshift/cloud-provider-powervs/compare/969a04e9dcb4cdde10e3038a9e28d2e27548918d...40d1c0adfedeca36498a5d93d69aee96831c756d)
### [prometheus](https://github.com/openshift/prometheus/tree/6e65a831d39940685cf4cfaf6343278c163edede)
* [OCPBUGS-93729](https://issues.redhat.com/browse/OCPBUGS-93729): fix for CVE-2026-42151 [#357](https://github.com/openshift/prometheus/pull/357)
* [OCPBUGS-88670](https://issues.redhat.com/browse/OCPBUGS-88670): remote: validate snappy decoded length before allocation in read endpoint [#331](https://github.com/openshift/prometheus/pull/331)
* [OCPBUGS-93920](https://issues.redhat.com/browse/OCPBUGS-93920): fix(tsdb): temporarily ignore Direct IO enablement errors on unsupported filesystems [#340](https://github.com/openshift/prometheus/pull/340)
* [OCPBUGS-86250](https://issues.redhat.com/browse/OCPBUGS-86250): fix: TLS client cert rotation when no CA is configured [#314](https://github.com/openshift/prometheus/pull/314)
* [OCPBUGS-80855](https://issues.redhat.com/browse/OCPBUGS-80855): Bump google.golang.org/grpc to v1.79.3 [#309](https://github.com/openshift/prometheus/pull/309)
* [Full changelog](https://github.com/openshift/prometheus/compare/59769d912ceab62bf0b7325c505ed463e64ab734...6e65a831d39940685cf4cfaf6343278c163edede)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/99c776df40d65fb32f96a09b063d9c159f843f9a)
* [OCPBUGS-104155](https://issues.redhat.com/browse/OCPBUGS-104155): Use github.com/openshift-sustaining/net patch to fix CVE-2026-33814 [#169](https://github.com/openshift/prometheus-alertmanager/pull/169)
* [OCPBUGS-98182](https://issues.redhat.com/browse/OCPBUGS-98182): build(deps): bump github.com/hashicorp/memberlist to a forked version which fixes CVE-2026-14362 [#158](https://github.com/openshift/prometheus-alertmanager/pull/158)
* [OCPBUGS-100352](https://issues.redhat.com/browse/OCPBUGS-100352): Set testdata CA expiry to 20 years from issue date (#4112) [#145](https://github.com/openshift/prometheus-alertmanager/pull/145)
* [OCPBUGS-99446](https://issues.redhat.com/browse/OCPBUGS-99446): embed tzdata in the alertmanager binary [#142](https://github.com/openshift/prometheus-alertmanager/pull/142)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/3dbe0b64ae3b9439b888be65a32431c7bf0d6806...99c776df40d65fb32f96a09b063d9c159f843f9a)
### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/d392d80ac2194cf33969ec56aed5d624da8053e0)
* [OCPBUGS-104160](https://issues.redhat.com/browse/OCPBUGS-104160), [OCPBUGS-104188](https://issues.redhat.com/browse/OCPBUGS-104188): [release-4.21] Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [#394](https://github.com/openshift/prometheus-operator/pull/394)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/3de9763f36128ffa8b25a63c9447f6d64114c270...d392d80ac2194cf33969ec56aed5d624da8053e0)
### [rhel-coreos, rhel-coreos-extensions](https://github.com/openshift/os/tree/b3f3bce740fa6b32bf2c06dd8a6f31bdb831915e)
* [OCPBUGS-105490](https://issues.redhat.com/browse/OCPBUGS-105490): NetworkManager-ovs has moved to RHCOS [#1957](https://github.com/openshift/os/pull/1957)
* [OCPBUGS-82523](https://issues.redhat.com/browse/OCPBUGS-82523): post-process: Remove workaround for openvswitch additional group [#1926](https://github.com/openshift/os/pull/1926)
* [Full changelog](https://github.com/openshift/os/compare/83a448067f52b8e70b2fe26d8a1deeab41fe4348...b3f3bce740fa6b32bf2c06dd8a6f31bdb831915e)
### [rhel-coreos-10, rhel-coreos-10-extensions](https://github.com/openshift/os/tree/10f1a2e738aa55fff22dbe0346609e83a5f6eb90)
* [OCPBUGS-82523](https://issues.redhat.com/browse/OCPBUGS-82523): post-process: Remove workaround for openvswitch additional group [#1926](https://github.com/openshift/os/pull/1926)
* [Full changelog](https://github.com/openshift/os/compare/83a448067f52b8e70b2fe26d8a1deeab41fe4348...10f1a2e738aa55fff22dbe0346609e83a5f6eb90)
### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/166a3e96f8151d9e789b3951ae75b03cdede5081)
* [OCPBUGS-80726](https://issues.redhat.com/browse/OCPBUGS-80726): Bump google.golang.org/grpc to v1.79.3 [#82](https://github.com/openshift/route-controller-manager/pull/82)
* [Full changelog](https://github.com/openshift/route-controller-manager/compare/559b7122d1a0cad4ff475b496c2896b39eed8c08...166a3e96f8151d9e789b3951ae75b03cdede5081)
### [telemeter](https://github.com/openshift/telemeter/tree/b79b872a65edd845891db70f6c9a184458a178da)
* [OCPBUGS-80868](https://issues.redhat.com/browse/OCPBUGS-80868): Bump google.golang.org/grpc to v1.79.3 [#589](https://github.com/openshift/telemeter/pull/589)
* [OCPBUGS-81817](https://issues.redhat.com/browse/OCPBUGS-81817): [release-1.21] Fix CVE-2026-34986 [#593](https://github.com/openshift/telemeter/pull/593)
* [Full changelog](https://github.com/openshift/telemeter/compare/a54acdfeb2d62c79516d099e37f3319205c903a7...b79b872a65edd845891db70f6c9a184458a178da)
### [tests](https://github.com/openshift/origin/tree/c941d145e570817f0408dc531c4261eecc21c4e7)
* [OCPBUGS-69943](https://issues.redhat.com/browse/OCPBUGS-69943): feat: render OTE JSON results in spyglass [#30633](https://github.com/openshift/origin/pull/30633)
* [OCPBUGS-120726](https://issues.redhat.com/browse/OCPBUGS-120726): fix: skip MCPs with non-ready nodes during MCN property validation [#31524](https://github.com/openshift/origin/pull/31524)
* [OCPBUGS-115200](https://issues.redhat.com/browse/OCPBUGS-115200): fix: adjusting DaemonSet test to dynamically compute expected pod count [#31523](https://github.com/openshift/origin/pull/31523)
* [OCPBUGS-115282](https://issues.redhat.com/browse/OCPBUGS-115282): Raise status polling timeout and write bound [#31587](https://github.com/openshift/origin/pull/31587)
* [OCPBUGS-114439](https://issues.redhat.com/browse/OCPBUGS-114439): Fix probe termination test to use pod status instead of kubelet event text [#31569](https://github.com/openshift/origin/pull/31569)
* [OCPBUGS-100439](https://issues.redhat.com/browse/OCPBUGS-100439): retry GetVotingMemberNames on transient etcd client fails [#31507](https://github.com/openshift/origin/pull/31507)
* [OCPBUGS-99671](https://issues.redhat.com/browse/OCPBUGS-99671): Backport node_e2e test migrations [#31426](https://github.com/openshift/origin/pull/31426)
* [OCPBUGS-99300](https://issues.redhat.com/browse/OCPBUGS-99300): admit and extract non-payload 4.21 [#31386](https://github.com/openshift/origin/pull/31386)
* [OCPBUGS-90523](https://issues.redhat.com/browse/OCPBUGS-90523): Use AdminPolicyBasedExternalRoute CR for external gateway test [#31316](https://github.com/openshift/origin/pull/31316)
* [OCPBUGS-94114](https://issues.redhat.com/browse/OCPBUGS-94114): support Parents field on origin test suites [#31353](https://github.com/openshift/origin/pull/31353)
* [OCPBUGS-88564](https://issues.redhat.com/browse/OCPBUGS-88564): fix CUDN status condition tests for NetworkAllocationSucceeded condition [#31300](https://github.com/openshift/origin/pull/31300)
* [OCPBUGS-84252](https://issues.redhat.com/browse/OCPBUGS-84252): Move imagepolicy test to disruptive long-running suite [#31061](https://github.com/openshift/origin/pull/31061)
* [OCPBUGS-78330](https://issues.redhat.com/browse/OCPBUGS-78330), [OCPBUGS-82146](https://issues.redhat.com/browse/OCPBUGS-82146), [OCPBUGS-85550](https://issues.redhat.com/browse/OCPBUGS-85550), [OCPBUGS-88295](https://issues.redhat.com/browse/OCPBUGS-88295), [OCPBUGS-88297](https://issues.redhat.com/browse/OCPBUGS-88297), [OCPBUGS-88320](https://issues.redhat.com/browse/OCPBUGS-88320), [OCPBUGS-88322](https://issues.redhat.com/browse/OCPBUGS-88322), [OCPBUGS-88324](https://issues.redhat.com/browse/OCPBUGS-88324): Backport noOLM Gateway API test coverage and upgrade tests [#31232](https://github.com/openshift/origin/pull/31232)
* [OCPBUGS-88328](https://issues.redhat.com/browse/OCPBUGS-88328): Fix Pod.Create() to use --local flag for template proc⦠[#31269](https://github.com/openshift/origin/pull/31269)
* [OCPBUGS-85149](https://issues.redhat.com/browse/OCPBUGS-85149): Enable Gateway API tests on vSphere and baremetal [#31139](https://github.com/openshift/origin/pull/31139)
* [OCPQE-32041](https://issues.redhat.com/browse/OCPQE-32041): bump(k8s): move docker types into container package [#31169](https://github.com/openshift/origin/pull/31169)
* [OCPBUGS-74373](https://issues.redhat.com/browse/OCPBUGS-74373): Remove restriction of unmanaged x-k8s.io [#30718](https://github.com/openshift/origin/pull/30718)
* [OCPBUGS-84655](https://issues.redhat.com/browse/OCPBUGS-84655): fix openshift/network/third-party suite selecting zero tests [#31091](https://github.com/openshift/origin/pull/31091)
* [OCPBUGS-84978](https://issues.redhat.com/browse/OCPBUGS-84978): Skip image-registry operator tests for Libvirt platform in upgrade jobs. [#31123](https://github.com/openshift/origin/pull/31123)
* [OCPBUGS-84947](https://issues.redhat.com/browse/OCPBUGS-84947): test: add monitortest to detect pods stuck in Pending state [#31117](https://github.com/openshift/origin/pull/31117)
* [OCPBUGS-84947](https://issues.redhat.com/browse/OCPBUGS-84947): Add [Late] test to collect CRI-O goroutine dumps via SIGUSR1 [#31118](https://github.com/openshift/origin/pull/31118)
* [OCPBUGS-81638](https://issues.redhat.com/browse/OCPBUGS-81638): Manual cherry-pick node swap feature testcases to 4.21 [#30973](https://github.com/openshift/origin/pull/30973)
* [OCPBUGS-82064](https://issues.redhat.com/browse/OCPBUGS-82064): Assert CNI version greater than equal to 1.0.0 [#30977](https://github.com/openshift/origin/pull/30977)
* [OCPBUGS-81638](https://issues.redhat.com/browse/OCPBUGS-81638): Add openshift/disruptive-longrunning testsuite in release-4.21 branch [#30976](https://github.com/openshift/origin/pull/30976)
* [OCPBUGS-78780](https://issues.redhat.com/browse/OCPBUGS-78780): changed http to https for three places to reduce test false positives and false negatives [#30902](https://github.com/openshift/origin/pull/30902)
* [Full changelog](https://github.com/openshift/origin/compare/47530573ae526a48dff70a294e26c31eb5ebff1a...c941d145e570817f0408dc531c4261eecc21c4e7)
### [thanos](https://github.com/openshift/thanos/tree/afeb1c85ba9ee06676a0e657bfa4f4139ccc47b3)
* [OCPBUGS-84492](https://issues.redhat.com/browse/OCPBUGS-84492): Revert "OCPBUGS-80870: CVE-2026-33186 openshift4/ose-thanos-rhel9: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation [openshift-4.21]" [#180](https://github.com/openshift/thanos/pull/180)
* [OCPBUGS-80870](https://issues.redhat.com/browse/OCPBUGS-80870): CVE-2026-33186 openshift4/ose-thanos-rhel9: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation [openshift-4.21] [#174](https://github.com/openshift/thanos/pull/174)
* [Full changelog](https://github.com/openshift/thanos/compare/6ea20ffaa35b7b31fe7ef9a99287bdd4a1c1e4e8...afeb1c85ba9ee06676a0e657bfa4f4139ccc47b3)
### [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere/tree/3adfe2b56b259b2d27906d8772354f817e338da5)
* [OCPBUGS-80875](https://issues.redhat.com/browse/OCPBUGS-80875): Bump google.golang.org/grpc to v1.79.3 [#102](https://github.com/openshift/cluster-api-provider-vsphere/pull/102)
* [Full changelog](https://github.com/openshift/cluster-api-provider-vsphere/compare/6626b2998e29189d1ff031c0a589f9c3413feac4...3adfe2b56b259b2d27906d8772354f817e338da5)
### [vsphere-csi-driver, vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver/tree/d163d71ccf646b3c2b36f4f2fd6ef78f3c254ed5)
* [OCPBUGS-96573](https://issues.redhat.com/browse/OCPBUGS-96573): Bump golang.org/x/net to v0.50.0-sec.4 [#196](https://github.com/openshift/vmware-vsphere-csi-driver/pull/196)
* [OCPBUGS-93031](https://issues.redhat.com/browse/OCPBUGS-93031): Bump golang.org/x/crypto/ssh to v0.48.0-sec.1 [#190](https://github.com/openshift/vmware-vsphere-csi-driver/pull/190)
* [OCPBUGS-80878](https://issues.redhat.com/browse/OCPBUGS-80878): Bump google.golang.org/grpc to 1.79.3 [#171](https://github.com/openshift/vmware-vsphere-csi-driver/pull/171)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver/compare/5e680186a305e1e0a11950630f7addcb1aa19e0e...d163d71ccf646b3c2b36f4f2fd6ef78f3c254ed5)
### [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector/tree/a644ba6cea8f898ef9a856b8ef955e23a1bf4868)
* [OCPBUGS-104206](https://issues.redhat.com/browse/OCPBUGS-104206): Bump golang.org/x/net to v0.50.0-sec.4 [#230](https://github.com/openshift/vsphere-problem-detector/pull/230)
* [OCPBUGS-87097](https://issues.redhat.com/browse/OCPBUGS-87097): Fixed compute cluster permission logic for single fd with read-only custom resourcepool [#222](https://github.com/openshift/vsphere-problem-detector/pull/222)
* [Full changelog](https://github.com/openshift/vsphere-problem-detector/compare/a35d685a88aca94ed1d805c1079ebf14dfb81c9d...a644ba6cea8f898ef9a856b8ef955e23a1bf4868)