# 5.1.0-ec.1
Created: 2026-09-28 20:16:37 +0000 UTC
Image Digest: `sha256:e9d31376bf80f1a6413ce6d8a6d462332cf2504106fbbd5dba201aa85ae89d81`
## Changes from 5.0.0-rc.3
### Components
* Kubectl 1.36.2
* Kubernetes upgraded from 1.36.3 to 1.36.4
* Kubernetes Tests 1.36.2
* Red Hat Enterprise Linux CoreOS 10.2 upgraded from 10.2.20260910-2 to 10.2.20260918-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| AWSServiceLBNetworkSecurityGroup
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| AzureWorkloadIdentity
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| SigstoreImageVerification
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| SigstoreImageVerificationPKI
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| VSphereMultiDisk
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| VSphereMultiNetworks
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| VolumeGroupSnapshot
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| OpenShiftPodSecurityAdmission
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| SELinuxMount
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| VSphereMultiVCenterDay2
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| TLSAdherence
(0 tests)| Disabled| Disabled| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| DRADeviceTaintRules
(0 tests)| | | | | | | | |
| EgressIPNodeSelector
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| GomaxprocsInjection
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| IngressControllerLBSecurityGroupsAWS
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| ManagedBootImagesAWSCAPI
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| OVNKubernetesUplinkMode
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | | |
| VSpherePerComponentScopedCreds
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | | |
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [d6ec9243](https://github.com/openshift/apiserver-network-proxy/commit/d6ec9243d24050d7d7ad7f939e45f821171f000e) `sha256:385039401577a8663d582145df9201a7aa66063a6bdbb76c71c7b7c8168efbd7`
* [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [8b8c4cef](https://github.com/openshift/aws-ebs-csi-driver/commit/8b8c4cef02ec9b670e2709f2aacc0ed72420be90) `sha256:55e7b7b8de17a023ff06f29e14a5c2caf0c1dfb41d953b4bf76be60e895afc54`
* [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider) git [9b18930d](https://github.com/openshift/aws-encryption-provider/commit/9b18930d2db9521a08faa7165488bdcf6482b9cf) `sha256:7833ec1b9a125338821bb56a1950570b47dfd144444f16054e7c978ccc06692f`
* [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws) git [9f2e9b3c](https://github.com/openshift/machine-api-provider-aws/commit/9f2e9b3c46b391c7219257a426ad80ca8a296af0) `sha256:01f037323c827434a3af48f1ef0f28b06ab978dce198193c6646f9eae396af21`
* [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [0d33a459](https://github.com/openshift/aws-pod-identity-webhook/commit/0d33a4596e2a22d188fe74c4a6497c37c2528c1f) `sha256:1459974341bcaac5e832975d46dbb6ee6ae66c5eb5159d916059a29d26f5eb87`
* [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure) git [63731729](https://github.com/openshift/cluster-api-provider-azure/commit/63731729974bff3be90ae2206c53d760572499d1) `sha256:5d65dbd6e83ec15aa7db85d58fc7acfecff4ae37dfd9b5d0dd4dba23ae41bdc9`
* [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver) git [9689f030](https://github.com/openshift/azure-file-csi-driver/commit/9689f03011ce700b3bffc32791af839e80d0e0ab) `sha256:fb97482cef3a093762494e2595655f787e7caac8cf300878503c79f4025ca121`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:42a23e26dfe88cd10892a5d213ad811f9801b779aa991d585af1026dec9743a1`
* [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3) git [ad4f1c2b](https://github.com/openshift/cluster-api-provider-metal3/commit/ad4f1c2bd7b527437496b71b5b93ee1439243d65) `sha256:a158b81551e3e1f22bfba65a64b473e58f9195f4293cdc9d7013f57ccb7ad8f8`
* [cluster-capi-controllers](https://github.com/openshift/cluster-api) git [303d9786](https://github.com/openshift/cluster-api/commit/303d9786a5017d299b6e7fc702bb92f5cb4550cf) `sha256:8b066ac9f30751c28cdffa48d5b08795d995e25278e879993d7a47c6835dbe16`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [8da2f1fc](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/8da2f1fcb1e76e8b1b97b16ca7bbfa7116287eb8) `sha256:fa7e919c00517e5a2133633e5d5d30e852ae31ca9e5e7ebed4e8f402f2c90568`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:43835c5db8924f77dc14962a7e934bfc84b0837a8e9de4c098091f3a03006ffc`
* [coredns](https://github.com/openshift/coredns) git [37aaba89](https://github.com/openshift/coredns/commit/37aaba896e97f4b9a091aab6d36f2213b8854474) `sha256:6a9e27bf10403405010980e28774e5797410a432741b034495bc78e015ddc7ce`
* [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [3fd668b3](https://github.com/openshift/csi-external-attacher/commit/3fd668b3f07dd382e5c7b6239d50f7988f652e64) `sha256:0dae35d4271210f39fea8117444d1926f2e5b241b7ac9ef38e3c00aba06b044a`
* [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [7ff338c9](https://github.com/openshift/csi-external-provisioner/commit/7ff338c9d1296f0e5d4d8080a76bb191c8f3be30) `sha256:a1802460ecd19c6aa8ac23a183b9c79f9bf9f9ba1af09fd180962b23d566b585`
* [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [14aa7028](https://github.com/openshift/csi-external-resizer/commit/14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf) `sha256:7218df1cd0d796ea6790648721dd64258ffbe5856ee66349d9ec78e741bcf82a`
* [csi-external-snapshotter](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:c41ae086b35590e0eaeb8bb8170b9b1265b564bf6c7067bfc40ed9421318bb1f`
* [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [5766960d](https://github.com/openshift/csi-node-driver-registrar/commit/5766960d82ffb9ef84d15e903ae57d0a6781ef11) `sha256:3f1db409be548ccbe14b061aeb7ccca3077ca89529278edf7dce051fbb13878f`
* [csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:fc8f3787ba9874c3ea59258b1e9303dd8aefec1de8207f5da9cf48afe1e38e8f`
* [driver-toolkit](https://github.com/openshift/driver-toolkit) git [b63b175a](https://github.com/openshift/driver-toolkit/commit/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a) `sha256:3729fd03a1431d34a44cb76b19bfc8951647ed68463b30160da9bf49e760b2ad`
* [driver-toolkit-10](https://github.com/openshift/driver-toolkit) git [b63b175a](https://github.com/openshift/driver-toolkit/commit/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a) `sha256:cfc86363e30536d987333de4496de0a2abc910990d1d9c768d2388bd2993452f`
* [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp) git [51c32646](https://github.com/openshift/cloud-provider-gcp/commit/51c326465b3160124b8097953b42e44f1056da5a) `sha256:16e6eef59aba8889cb2a2d77322b2fd9ad0a1e73f9a876d93720067da3309f42`
* [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver) git [049c0b96](https://github.com/openshift/gcp-pd-csi-driver/commit/049c0b96742c40fdd4384920afe17cefa5fa3d27) `sha256:755ef110100c451f739b2e0159a897369f25918db245d328e6edf30b8b2a2584`
* [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook) git [4501ff2f](https://github.com/openshift/gcp-workload-identity-federation-webhook/commit/4501ff2f53576c31df0511b69444e65e1eeba745) `sha256:5292465401b0918431bf27d51ee0bab4fc4e1f99441c963af1ea59adc80c845b`
* [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm) git [11bc35dd](https://github.com/openshift/cloud-provider-ibm/commit/11bc35dd6fd5163259023a6f1dfcc59ce813ab5f) `sha256:c8a14c5068f2834b26bbb393a8e89ea84c1e458bdc12b95e425350d86702978f`
* [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver) git [3a89d7d1](https://github.com/openshift/ibm-vpc-block-csi-driver/commit/3a89d7d17d25727270414b07d3daaa3bc329d743) `sha256:455a25c1be7eb990042c17dbcee6c4ef3a4d9bf6611b37f6be3b5eb9495daca7`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [f8e41b2e](https://github.com/openshift/ironic-rhcos-downloader/commit/f8e41b2ed8915474a99e3eb34b54692afb0611da) `sha256:8b06a61ea2651f04969ba3bd5b9a406801794957a21a933c3af718b045932b12`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [486a0418](https://github.com/openshift/ironic-static-ip-manager/commit/486a041897d703d55ef59c98e2b20a01588a0b4c) `sha256:48cd05f4c386091586a5a6a4b54c32c9c6cd89e4bf929849f6ec1cc85ff62280`
* [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server) git [3d2e9cd0](https://github.com/openshift/kubernetes-metrics-server/commit/3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71) `sha256:e45acb8bbfb6183305adaa09a0a9bb4f7e9d07e066e0e3088c64eba9bd903f17`
* [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt) git [5eb884ab](https://github.com/openshift/cloud-provider-kubevirt/commit/5eb884abcd2ff17ae8d7b2691ca12494597c08a6) `sha256:a6ec0481ae44267ad5910f3820218cb5c1f3508366e7cda6cd6cad6cbced4b22`
* [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [dc584c6b](https://github.com/openshift/cloud-provider-nutanix/commit/dc584c6b2e895a6217f9e2dbed765209af1898a1) `sha256:b5079a6f825753e71162c698dde12e6ac6d9e757853f370479811d5866d91ebd`
* [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix) git [249b7c8e](https://github.com/openshift/machine-api-provider-nutanix/commit/249b7c8edfca8f25413dc76bc5a216fbe12a9ab1) `sha256:172fe0f22370c024b91a80da5e2b84178980ae562a97fb12aaed36ba4e2ab694`
* [openshift-apiserver](https://github.com/openshift/openshift-apiserver) git [ab031522](https://github.com/openshift/openshift-apiserver/commit/ab0315228cde432c8cd62df012b791a66a72c7b3) `sha256:e8fc03c3ff2f32fa21de959f4325ab342c7f816d435b67b290b96ad028d29085`
* [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:1976cf51a82bfa9a868e306f95cfb9bf44ebdf0d7e054ada2a54dbe5425d5e1e`
* [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator) git [f90431bf](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/commit/f90431bfe8ca93850450b2b24fae152d2385ca08) `sha256:bbcfaebfc51c4799f0b8b97e471724b42b95ed74d25e81ea4db31221449a3a96`
* [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs) git [28c928ff](https://github.com/openshift/machine-api-provider-powervs/commit/28c928ff78def160837170991f084b0fe71ca9be) `sha256:2d4f1d9bb3bdd9d49000bdd972bef5f196cce1232df3a7fdf52a1d642123501d`
* [service-ca-operator](https://github.com/openshift/service-ca-operator) git [ed872ba1](https://github.com/openshift/service-ca-operator/commit/ed872ba14b615ca5726ae90e987268877a0b0b20) `sha256:e4873e019b4ae8a5a71fa3248f771e540201504fbaa3ae87fdd14f440cf24d28`
* [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere) git [eb29de19](https://github.com/openshift/cloud-provider-vsphere/commit/eb29de194594bad8e5bc572102f1008cb26655a7) `sha256:dd4f6767b77c5ba0e38d812ab5497c9f3bbdf70373668737f38539517f6e85b6`
* [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere) git [557fdf1a](https://github.com/openshift/cluster-api-provider-vsphere/commit/557fdf1a9a3540d9aa8f3a81e4a950673a416a80) `sha256:61b552f89066a2b4e651912f297bf31c04b44e8d31720b80246811421416850a`
* [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator) git [aa279467](https://github.com/openshift/vmware-vsphere-csi-driver-operator/commit/aa27946700642a9c8e518e130673097b38a2f8bb) `sha256:4c4c111c9c0d970b098bb9218dad0dd8eb00b26ced90655acbb5804446f7a688`
* [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector) git [14a2d338](https://github.com/openshift/vsphere-problem-detector/commit/14a2d33817c1ddd1d753cc76decea059376e30c9) `sha256:5d7bede8f3114de330d28849ef4ca24d61695f6842f76f19e13d848576800e29`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/db6eaf18787a49decbde2cfd368381cfe528e3cb)
* [MGMT-25431](https://issues.redhat.com/browse/MGMT-25431): CVE-2026-84445 Bump google.golang.org/grpc to v1.82.2 through indirect dependency conversion [#10975](https://github.com/openshift/assisted-service/pull/10975)
* [MGMT-24967](https://issues.redhat.com/browse/MGMT-24967): Static-IP iSCSI Boot-from-SAN Support in Assisted Installer [#10925](https://github.com/openshift/assisted-service/pull/10925)
* [OCPBUGS-115550](https://issues.redhat.com/browse/OCPBUGS-115550): Allow agent-installer invoker to have a suffix [#10968](https://github.com/openshift/assisted-service/pull/10968)
* [MGMT-25123](https://issues.redhat.com/browse/MGMT-25123): create endpoint for listing OVE images [#10933](https://github.com/openshift/assisted-service/pull/10933)
* [MGMT-25355](https://issues.redhat.com/browse/MGMT-25355): Migrate to harness-agnostic agent configuration layout [#10966](https://github.com/openshift/assisted-service/pull/10966)
* [ACM-38075](https://issues.redhat.com/browse/ACM-38075): Assisted Service Agent controller does not approve day-2 CSRs for worker nodes provisioned with pre-existing BMHs via ClusterInstance scale-out [#10944](https://github.com/openshift/assisted-service/pull/10944)
* NO-ISSUE: [master] Bump OCP versions: 4.21, 5.0, 4.16, 4.14, 4.22, 4.20, 4.19 [#10967](https://github.com/openshift/assisted-service/pull/10967)
* [MGMT-24854](https://issues.redhat.com/browse/MGMT-24854): Cilium CNI is not supported on OCP 4.22 [#10819](https://github.com/openshift/assisted-service/pull/10819)
* [MGMT-25367](https://issues.redhat.com/browse/MGMT-25367): consider imageType when selecting OpenShift version [#10917](https://github.com/openshift/assisted-service/pull/10917)
* [MGMT-25406](https://issues.redhat.com/browse/MGMT-25406): Add OpenShift-compatible CIDR length validation [#10948](https://github.com/openshift/assisted-service/pull/10948)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10946](https://github.com/openshift/assisted-service/pull/10946)
* NO-ISSUE: [master] Bump OCP versions: 4.21, 4.22, 4.20 [#10942](https://github.com/openshift/assisted-service/pull/10942)
* [ACM-41555](https://issues.redhat.com/browse/ACM-41555): Enable PQC in Dockerfiles [#10901](https://github.com/openshift/assisted-service/pull/10901)
* [MGMT-25131](https://issues.redhat.com/browse/MGMT-25131): When getting the release image for a cluster we should always prioritize cluster.OcpReleaseImage if it's set [#10938](https://github.com/openshift/assisted-service/pull/10938)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10941](https://github.com/openshift/assisted-service/pull/10941)
* NO-ISSUE: [master] Bump OCP versions: 5.0 [#10937](https://github.com/openshift/assisted-service/pull/10937)
* [APPSRE-14688](https://issues.redhat.com/browse/APPSRE-14688): remove legacy monitoring.coreos.com/v1 ServiceMonitors [#10931](https://github.com/openshift/assisted-service/pull/10931)
* NO-ISSUE: [master] Bump OCP versions: 4.17, 5.0 [#10924](https://github.com/openshift/assisted-service/pull/10924)
* [OCPBUGS-120683](https://issues.redhat.com/browse/OCPBUGS-120683): Fix NUMAResourcesOperator CR name so it can be applied [#10910](https://github.com/openshift/assisted-service/pull/10910)
* NO-ISSUE: Update operator bundle channel to ocm-5.1 [#10867](https://github.com/openshift/assisted-service/pull/10867)
* [OCPBUGS-120675](https://issues.redhat.com/browse/OCPBUGS-120675): added missing subscription name for lvms-operator [#10909](https://github.com/openshift/assisted-service/pull/10909)
* [AGENT-1529](https://issues.redhat.com/browse/AGENT-1529): Add ovnKubernetesConfig to install-config definition [#10430](https://github.com/openshift/assisted-service/pull/10430)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10912](https://github.com/openshift/assisted-service/pull/10912)
* NO-ISSUE: [master] Bump OCP versions: 4.17, 4.19, 4.20, 4.16, 4.21 [#10907](https://github.com/openshift/assisted-service/pull/10907)
* NO-ISSUE:Bump go.opentelemetry.io/otel to v1.44.0 in master [#10869](https://github.com/openshift/assisted-service/pull/10869)
* [MGMT-25130](https://issues.redhat.com/browse/MGMT-25130): assisted-service and assisted-image-service NetworkPolicy ingress has no source restriction (any pod in any namespace can reach them directly) [#10906](https://github.com/openshift/assisted-service/pull/10906)
* NO-ISSUE: Modify Konflux YAMLs to ocm-5.1 [#10874](https://github.com/openshift/assisted-service/pull/10874)
* [MGMT-25139](https://issues.redhat.com/browse/MGMT-25139): Allow setting os-stream on both clusters and infraenvs [#10742](https://github.com/openshift/assisted-service/pull/10742)
* [MGMT-20398](https://issues.redhat.com/browse/MGMT-20398): Force status on bmh after install [#10606](https://github.com/openshift/assisted-service/pull/10606)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10884](https://github.com/openshift/assisted-service/pull/10884)
* [MGMT-24877](https://issues.redhat.com/browse/MGMT-24877): Improve sensitive credential redaction [#10857](https://github.com/openshift/assisted-service/pull/10857)
* [OCPBUGS-29975](https://issues.redhat.com/browse/OCPBUGS-29975): Allow multiple machine networks for UMN clusters [#10817](https://github.com/openshift/assisted-service/pull/10817)
* [MGMT-21334](https://issues.redhat.com/browse/MGMT-21334): Don't check ImageSetRef for installed clusters [#10854](https://github.com/openshift/assisted-service/pull/10854)
* NO-ISSUE: Add missing Close() [#10856](https://github.com/openshift/assisted-service/pull/10856)
* [MGMT-24693](https://issues.redhat.com/browse/MGMT-24693): fix e2e-ai-operator-disconnected-capi [#10806](https://github.com/openshift/assisted-service/pull/10806)
* [ACM-42573](https://issues.redhat.com/browse/ACM-42573): Assisted services' networkpolicy doesn't work for external image service and local image registry in disconnected environment [#10850](https://github.com/openshift/assisted-service/pull/10850)
* [MGMT-25066](https://issues.redhat.com/browse/MGMT-25066): Add continuous node label reconciliation in InfraEnv controller [#10813](https://github.com/openshift/assisted-service/pull/10813)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10829](https://github.com/openshift/assisted-service/pull/10829)
* [MGMT-25065](https://issues.redhat.com/browse/MGMT-25065): Add InfraEnv to Agent node label propagation [#10812](https://github.com/openshift/assisted-service/pull/10812)
* NO-ISSUE: Add same-namespace egress for image-service to assisted-service [#10816](https://github.com/openshift/assisted-service/pull/10816)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/assisted-service/compare/8177722b388c34c334961352e9ab471ed4f8e95c...db6eaf18787a49decbde2cfd368381cfe528e3cb)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/4282317d91570e00028984d6f22da3a17ad5513f)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#2339](https://github.com/openshift/assisted-installer/pull/2339)
* [OCPBUGS-115550](https://issues.redhat.com/browse/OCPBUGS-115550): Allow agent-installer invoker to have a suffix [#2341](https://github.com/openshift/assisted-installer/pull/2341)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#2326](https://github.com/openshift/assisted-installer/pull/2326)
* [ACM-41555](https://issues.redhat.com/browse/ACM-41555): Enable PQC in Dockerfiles [#2307](https://github.com/openshift/assisted-installer/pull/2307)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#2309](https://github.com/openshift/assisted-installer/pull/2309)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#2304](https://github.com/openshift/assisted-installer/pull/2304)
* [MGMT-24885](https://issues.redhat.com/browse/MGMT-24885): Harden command construction and credential handling [#2275](https://github.com/openshift/assisted-installer/pull/2275)
* NO-ISSUE: Add approver bluesort [#2286](https://github.com/openshift/assisted-installer/pull/2286)
* NO-ISSUE: Modify Konflux YAMLs to ocm-5.1 [#2281](https://github.com/openshift/assisted-installer/pull/2281)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.2 [#2285](https://github.com/openshift/assisted-installer/pull/2285)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.1 [#2273](https://github.com/openshift/assisted-installer/pull/2273)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.0 [#2271](https://github.com/openshift/assisted-installer/pull/2271)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/fa7eb52b083a161b122e1c543d487edb3de0955c...4282317d91570e00028984d6f22da3a17ad5513f)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/234004589633185edd5b6c80504d7ddb81c291c7)
* [OCPBUGS-106189](https://issues.redhat.com/browse/OCPBUGS-106189): Assisted installer fails to disambiguate machines [#1625](https://github.com/openshift/assisted-installer-agent/pull/1625)
* [ACM-41555](https://issues.redhat.com/browse/ACM-41555): Enable PQC in Dockerfiles [#1622](https://github.com/openshift/assisted-installer-agent/pull/1622)
* [MGMT-20398](https://issues.redhat.com/browse/MGMT-20398): Don't start main agent until ironic reports it's ready [#1518](https://github.com/openshift/assisted-installer-agent/pull/1518)
* NO-ISSUE: Modify Konflux YAMLs to ocm-5.1 [#1602](https://github.com/openshift/assisted-installer-agent/pull/1602)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.1 [#1600](https://github.com/openshift/assisted-installer-agent/pull/1600)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.0 [#1597](https://github.com/openshift/assisted-installer-agent/pull/1597)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/b1d92ca20c3a276744861d8fb77745bb8f42ea9a...234004589633185edd5b6c80504d7ddb81c291c7)
### [agent-installer-ui](https://github.com/openshift-assisted/assisted-installer-ui/tree/001804fc52c1a1b5f81b7ff1fab6262c0857a6cb)
* chore(deps): update dependency brace-expansion to ^5.0.12 (#4063) [#4063](https://github.com/openshift-assisted/assisted-installer-ui/pull/4063)
* chore(deps): update konflux references (#4061) [#4061](https://github.com/openshift-assisted/assisted-installer-ui/pull/4061)
* chore(deps): update dependency @types/node to ^24.13.5 (#4062) [#4062](https://github.com/openshift-assisted/assisted-installer-ui/pull/4062)
* Add Single-Stack, Increase ImageSize Label and show LVMS Label (#4054) [#4054](https://github.com/openshift-assisted/assisted-installer-ui/pull/4054)
* fix(deps): update typescript type definitions (non-major) (#4022) [#4022](https://github.com/openshift-assisted/assisted-installer-ui/pull/4022)
* [OCPBUGS-121378](https://issues.redhat.com/browse/OCPBUGS-121378): Do not show IRI custom manifests in the disconnected UI (#4048) [#4048](https://github.com/openshift-assisted/assisted-installer-ui/pull/4048)
* chore(deps): update dependency axios to ^1.20.0 (#4047) [#4047](https://github.com/openshift-assisted/assisted-installer-ui/pull/4047)
* chore(deps): update dependency dompurify to ^3.4.15 (#4046) [#4046](https://github.com/openshift-assisted/assisted-installer-ui/pull/4046)
* Bump js-yaml from 4.3.1 to 4.3.2 (#4034) [#4034](https://github.com/openshift-assisted/assisted-installer-ui/pull/4034)
* Bump react-router from 7.18.1 to 7.18.2 (#4036) [#4036](https://github.com/openshift-assisted/assisted-installer-ui/pull/4036)
* [OCPBUGS-115122](https://issues.redhat.com/browse/OCPBUGS-115122): Show IPv6 Technology Preview badge in Subnets dropdown for single-cluster only (#4013) [#4013](https://github.com/openshift-assisted/assisted-installer-ui/pull/4013)
* Bump vitest from 3.2.6 to 4.1.11 (#4035) [#4035](https://github.com/openshift-assisted/assisted-installer-ui/pull/4035)
* Bump joi from 17.13.4 to 17.13.7 (#4033) [#4033](https://github.com/openshift-assisted/assisted-installer-ui/pull/4033)
* [OCPBUGS-121366](https://issues.redhat.com/browse/OCPBUGS-121366): Move IPv6 Technology Preview badge out of the header (#4027) [#4027](https://github.com/openshift-assisted/assisted-installer-ui/pull/4027)
* Remove stale OCM_REFRESH_TOKEN code (#4012) [#4012](https://github.com/openshift-assisted/assisted-installer-ui/pull/4012)
* chore(deps): update dependency postcss to ^8.5.28 (#4021) [#4021](https://github.com/openshift-assisted/assisted-installer-ui/pull/4021)
* chore(deps): update konflux references (#4020) [#4020](https://github.com/openshift-assisted/assisted-installer-ui/pull/4020)
* Change reuse SSH key label in OVE (#4018) [#4018](https://github.com/openshift-assisted/assisted-installer-ui/pull/4018)
* Bump qs from 6.15.3 to 6.16.0 (#4011) [#4011](https://github.com/openshift-assisted/assisted-installer-ui/pull/4011)
* Bump fflate from 0.4.8 to 0.4.9 (#4017) [#4017](https://github.com/openshift-assisted/assisted-installer-ui/pull/4017)
* [MGMT-25128](https://issues.redhat.com/browse/MGMT-25128): Assisted Installer UI (above-the-sea) adjustment to 4.22 GA (#3996) [#3996](https://github.com/openshift-assisted/assisted-installer-ui/pull/3996)
* Bump fast-uri from 3.1.5 to 3.1.7 (#4010) [#4010](https://github.com/openshift-assisted/assisted-installer-ui/pull/4010)
* Bump browserslist from 4.28.2 to 4.28.8 (#4007) [#4007](https://github.com/openshift-assisted/assisted-installer-ui/pull/4007)
* Bump postcss-selector-parser from 7.1.1 to 7.1.5 (#4006) [#4006](https://github.com/openshift-assisted/assisted-installer-ui/pull/4006)
* Add LVM as an operator for OVE (#4001) [#4001](https://github.com/openshift-assisted/assisted-installer-ui/pull/4001)
* Allow LSO to be selected as a standalone operator (#4000) [#4000](https://github.com/openshift-assisted/assisted-installer-ui/pull/4000)
* chore(deps): update dependency yup to ^1.7.1 (#3999) [#3999](https://github.com/openshift-assisted/assisted-installer-ui/pull/3999)
* chore(deps): update dependency js-cookie to ^3.0.8 (#3998) [#3998](https://github.com/openshift-assisted/assisted-installer-ui/pull/3998)
* Update OWNERS file (#3989) [#3989](https://github.com/openshift-assisted/assisted-installer-ui/pull/3989)
* NO-ISSUE: Add Yarn resolutions for js-cookie and basic-ftp (#3985) [#3985](https://github.com/openshift-assisted/assisted-installer-ui/pull/3985)
* Tweak boot instructions for disconnected (#3968) [#3968](https://github.com/openshift-assisted/assisted-installer-ui/pull/3968)
* [MGMT-24639](https://issues.redhat.com/browse/MGMT-24639): Choosing 5 masters on hosts page instead of 3 that was configured on cluster details causing the Hosts page stuck with no error/warning (#3942) [#3942](https://github.com/openshift-assisted/assisted-installer-ui/pull/3942)
* Hardcode OVE openshift version from 4.21 to 4.21.27 (#3976) [#3976](https://github.com/openshift-assisted/assisted-installer-ui/pull/3976)
* Resolve console warnings/errors (#3967) [#3967](https://github.com/openshift-assisted/assisted-installer-ui/pull/3967)
* Add rule for creating/editing forms (#3962) [#3962](https://github.com/openshift-assisted/assisted-installer-ui/pull/3962)
* chore(deps): update dependency ws to ^8.21.3 (#3974) [#3974](https://github.com/openshift-assisted/assisted-installer-ui/pull/3974)
* chore(deps): update dependency dompurify to ^3.4.14 (#3973) [#3973](https://github.com/openshift-assisted/assisted-installer-ui/pull/3973)
* Resolve duplicate 'useFeature' issue (#3969) [#3969](https://github.com/openshift-assisted/assisted-installer-ui/pull/3969)
* [MGMT-24493](https://issues.redhat.com/browse/MGMT-24493): Allow HTTPS proxy for Discovery ISO (#3777) [#3777](https://github.com/openshift-assisted/assisted-installer-ui/pull/3777)
* [MGMT-24494](https://issues.redhat.com/browse/MGMT-24494): Add exclusive NTP sources to the Add hosts discovery ISO … (#3934) [#3934](https://github.com/openshift-assisted/assisted-installer-ui/pull/3934)
* MGMT-24202 | [Staging] [UI] - Air-gapped -Technology Preview badge placement is inconsistent (should appear at end of line) (#3965) [#3965](https://github.com/openshift-assisted/assisted-installer-ui/pull/3965)
* Fix BasicStep Form import (#3966) [#3966](https://github.com/openshift-assisted/assisted-installer-ui/pull/3966)
* NO-ISSUE: Improve the /ocm folder structure (#3817) [#3817](https://github.com/openshift-assisted/assisted-installer-ui/pull/3817)
* chore(deps): update dependency postcss to ^8.5.26 (#3963) [#3963](https://github.com/openshift-assisted/assisted-installer-ui/pull/3963)
* chore(deps): update dependency sanitize-html to ^2.17.7 (#3964) [#3964](https://github.com/openshift-assisted/assisted-installer-ui/pull/3964)
* [Full changelog](https://github.com/openshift-assisted/assisted-installer-ui/compare/e46bd4d04173f9ce7c76dc1afe73e8c3ebcb608a...001804fc52c1a1b5f81b7ff1fab6262c0857a6cb)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/cd6b338387fa652ffd1c23fc0ebb939486afe83b)
* [OCPBUGS-111479](https://issues.redhat.com/browse/OCPBUGS-111479): Quote variable expansion in `skopeo inspect` invocation [#348](https://github.com/openshift/agent-installer-utils/pull/348)
* [OCPBUGS-63475](https://issues.redhat.com/browse/OCPBUGS-63475): Refresh rendezvous IP selection list [#345](https://github.com/openshift/agent-installer-utils/pull/345)
* [OCPBUGS-123720](https://issues.redhat.com/browse/OCPBUGS-123720): Fix agent TUI timeout [#346](https://github.com/openshift/agent-installer-utils/pull/346)
* [AGENT-1577](https://issues.redhat.com/browse/AGENT-1577): Use master branch of appliance as image builder [#333](https://github.com/openshift/agent-installer-utils/pull/333)
* [OCPBUGS-114020](https://issues.redhat.com/browse/OCPBUGS-114020): Use branch 5.1 for Konflux builds [#344](https://github.com/openshift/agent-installer-utils/pull/344)
* [AGENT-1573](https://issues.redhat.com/browse/AGENT-1573): Add release-5.1 config for ISOBuilder [#327](https://github.com/openshift/agent-installer-utils/pull/327)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/33aa46920190a1c587599dfda77d9c1e3899e255...cd6b338387fa652ffd1c23fc0ebb939486afe83b)
### [agentic-skills](https://github.com/openshift/agentic-skills/tree/6968f9025f62487cab799b5ad7e675ad13fa1f5a)
* [GITOPS-10499](https://issues.redhat.com/browse/GITOPS-10499): Add Argo knowledge skill [#38](https://github.com/openshift/agentic-skills/pull/38)
* NO-JIRA: resolve skill-scanner findings for CI eval job [#49](https://github.com/openshift/agentic-skills/pull/49)
* NO-ISSUE: fix: add compatibility attribute to the product-lifecycle skill [#50](https://github.com/openshift/agentic-skills/pull/50)
* [OBSINTA-1609](https://issues.redhat.com/browse/OBSINTA-1609): cluster-troubleshoot skill rename tools to scripts [#46](https://github.com/openshift/agentic-skills/pull/46)
* [OTA-2024](https://issues.redhat.com/browse/OTA-2024), [OTA-2070](https://issues.redhat.com/browse/OTA-2070): Add eval test cases for cluster-update skills [#34](https://github.com/openshift/agentic-skills/pull/34)
* [Full changelog](https://github.com/openshift/agentic-skills/compare/b199bef90aa2f1c5f307a302783e3c8cae26517e...6968f9025f62487cab799b5ad7e675ad13fa1f5a)
### [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws/tree/e44d1350940f8fcc82fd60f91c5984d7952a3b08)
* UPSTREAM-SYNC: Merge https://github.com/kubernetes/cloud-provider-aws:master (853eb04) into main [#162](https://github.com/openshift/cloud-provider-aws/pull/162)
* [Full changelog](https://github.com/openshift/cloud-provider-aws/compare/278e8c07a72a50e7d3f28fc743c38c64f008f5aa...e44d1350940f8fcc82fd60f91c5984d7952a3b08)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/c5a9d1911d7a0659cc233809bcd1874790c93b8b)
* 🌱 NO-JIRA: UPSTREAM: <carry>: Remove upstream .github files unused in OpenShift CI [#632](https://github.com/openshift/cluster-api-provider-aws/pull/632)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/6fe56d037dc82c8babc6d70228dc89d3606385cd...c5a9d1911d7a0659cc233809bcd1874790c93b8b)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, csi-driver-manila-operator, gcp-pd-csi-driver-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/773340ccc6a7dc3657fe222c7ebd2fcc19adcd56)
* [STOR-3074](https://issues.redhat.com/browse/STOR-3074): Bump OLM metadata to 5.1 [#627](https://github.com/openshift/csi-operator/pull/627)
* [OCPBUGS-112272](https://issues.redhat.com/browse/OCPBUGS-112272): node ServiceMonitor serverName uses guest namespace on HyperShift [#603](https://github.com/openshift/csi-operator/pull/603)
* [OCPBUGS-115269](https://issues.redhat.com/browse/OCPBUGS-115269): openstack-manila: Consume CA cert from CCO secret [#617](https://github.com/openshift/csi-operator/pull/617)
* NO-JIRA: Add reference to cluster-storage-operator in AGENTS.md [#616](https://github.com/openshift/csi-operator/pull/616)
* [STOR-3090](https://issues.redhat.com/browse/STOR-3090): Enable pod-delete-after-umount CSI suite for driver OCP manifests [#596](https://github.com/openshift/csi-operator/pull/596)
* [OCPBUGS-120667](https://issues.redhat.com/browse/OCPBUGS-120667): fix(gcp-pd): don't apply guest-cluster resources against the management cluster on HyperShift [#618](https://github.com/openshift/csi-operator/pull/618)
* [OCPBUGS-105410](https://issues.redhat.com/browse/OCPBUGS-105410): Remove MutableCSINodeAllocatableCount featuregate [#600](https://github.com/openshift/csi-operator/pull/600)
* [GCP-1074](https://issues.redhat.com/browse/GCP-1074): feat(gcp-pd): enable HyperShift support for GCP PD CSI driver operator [#601](https://github.com/openshift/csi-operator/pull/601)
* [OCPBUGS-111088](https://issues.redhat.com/browse/OCPBUGS-111088): Replace deprecated pod.spec.service account [#604](https://github.com/openshift/csi-operator/pull/604)
* [OCPBUGS-105392](https://issues.redhat.com/browse/OCPBUGS-105392): Add proxy hook for HyperShift CSI driver controller deployments [#594](https://github.com/openshift/csi-operator/pull/594)
* [Full changelog](https://github.com/openshift/csi-operator/compare/31b3192f3a5182ee1b523370cdfd94833b75e6d1...773340ccc6a7dc3657fe222c7ebd2fcc19adcd56)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/27c9527374d3d714ade3988f18cdc6eb46bc8262)
* [OCPBUGS-85090](https://issues.redhat.com/browse/OCPBUGS-85090): Align simulated with actual allocatable resources [#46](https://github.com/openshift/aws-karpenter-provider-aws/pull/46)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#44](https://github.com/openshift/aws-karpenter-provider-aws/pull/44)
* [AUTOSCALE-904](https://issues.redhat.com/browse/AUTOSCALE-904): Add agentic SDLC artifacts to aws-karpenter-provider-aws [#41](https://github.com/openshift/aws-karpenter-provider-aws/pull/41)
* [OCPBUGS-85085](https://issues.redhat.com/browse/OCPBUGS-85085): default max-pods to 250 for Custom AMI family [#40](https://github.com/openshift/aws-karpenter-provider-aws/pull/40)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/d04b52621a47868d907e986b37a01fcddeb8a23f...27c9527374d3d714ade3988f18cdc6eb46bc8262)
### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/2b2ba3b799d7e126826d63dc153611b97cced61f)
* [OCPBUGS-105320](https://issues.redhat.com/browse/OCPBUGS-105320): skip public ip check for azure stack [#203](https://github.com/openshift/cloud-provider-azure/pull/203)
* [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/b99e4ce4ff5c2665b273384b0673824833c40ce5...2b2ba3b799d7e126826d63dc153611b97cced61f)
### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/60a5e9629990ac41a7fcce81924318d087943183)
* [OCPBUGS-111076](https://issues.redhat.com/browse/OCPBUGS-111076): UPSTREAM: 3754: chore: upgrade Azure cloud provider lib- [#180](https://github.com/openshift/azure-disk-csi-driver/pull/180)
* [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/64091ea10ac93fd62b83c63b4b7379063aca9058...60a5e9629990ac41a7fcce81924318d087943183)
### [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms/tree/21fc3813f6cc12ce6246531891b5ad395e2afaad)
* [OCPSTRAT-3549](https://issues.redhat.com/browse/OCPSTRAT-3549): support sovereign Managed HSM endpoints [#54](https://github.com/openshift/azure-kubernetes-kms/pull/54)
* [Full changelog](https://github.com/openshift/azure-kubernetes-kms/compare/6409e379fa979104a9515108608c22492bb803a7...21fc3813f6cc12ce6246531891b5ad395e2afaad)
### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/4ba9605f3a9af6ddc31afb86a95439454fdd2965)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): refactor: remove AzureWorkloadIdentity feature gate [#207](https://github.com/openshift/machine-api-provider-azure/pull/207)
* [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/4ff6c6b8730c1253918f1f5261b9c12cab2e5903...4ba9605f3a9af6ddc31afb86a95439454fdd2965)
### [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity/tree/3f118b30e806a344c9fbc08245fea677a9979cad)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#69](https://github.com/openshift/azure-workload-identity/pull/69)
* [OCPBUGS-123198](https://issues.redhat.com/browse/OCPBUGS-123198): Bump golang.org/x/net to v0.53.0 to address CVE-2026-33814 [#70](https://github.com/openshift/azure-workload-identity/pull/70)
* [Full changelog](https://github.com/openshift/azure-workload-identity/compare/2b4705c5d999339ce17d47a9b2a637d238891dae...3f118b30e806a344c9fbc08245fea677a9979cad)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/987d45178f07740138e98234ff2cbc5571d4b7a5)
* [OCPBUGS-115550](https://issues.redhat.com/browse/OCPBUGS-115550): use different INSTALL_INVOKER for unconfigured ignition [#10848](https://github.com/openshift/installer/pull/10848)
* [OCPBUGS-99762](https://issues.redhat.com/browse/OCPBUGS-99762): retry Azure bootstrap ignition upload [#10835](https://github.com/openshift/installer/pull/10835)
* [OCPBUGS-90536](https://issues.redhat.com/browse/OCPBUGS-90536): openstack: Guard network resource names on `os_net_id` being defined [#10639](https://github.com/openshift/installer/pull/10639)
* [OCPBUGS-123770](https://issues.redhat.com/browse/OCPBUGS-123770): Inject the pull-secret as podman secret in the agent-installer-ui container [#10882](https://github.com/openshift/installer/pull/10882)
* [OCPBUGS-112483](https://issues.redhat.com/browse/OCPBUGS-112483): use api-int record for ignition host when using externally managed LB and DNS [#10860](https://github.com/openshift/installer/pull/10860)
* no-jira: aws: fetch instance type on demand instead of listing all [#10851](https://github.com/openshift/installer/pull/10851)
* [OCPBUGS-61892](https://issues.redhat.com/browse/OCPBUGS-61892): fix swap disk nil-panic and block swap on control plane [#10859](https://github.com/openshift/installer/pull/10859)
* [OCPBUGS-59743](https://issues.redhat.com/browse/OCPBUGS-59743): azure: reject data disks on Azure Stack Hub [#10823](https://github.com/openshift/installer/pull/10823)
* [OCPBUGS-86133](https://issues.redhat.com/browse/OCPBUGS-86133): dont allow duplicate failure domains and fields [#10741](https://github.com/openshift/installer/pull/10741)
* [OCPBUGS-91640](https://issues.redhat.com/browse/OCPBUGS-91640): Warn about ignored install-config fields in ABI [#10646](https://github.com/openshift/installer/pull/10646)
* [OCPBUGS-114375](https://issues.redhat.com/browse/OCPBUGS-114375): azure: skip AppendVarPartition when DiskSetup provides a user-defined /var mount [#10818](https://github.com/openshift/installer/pull/10818)
* [OCPBUGS-115187](https://issues.redhat.com/browse/OCPBUGS-115187): Gather master only from primary IP on baremetal [#10838](https://github.com/openshift/installer/pull/10838)
* [OCPBUGS-114882](https://issues.redhat.com/browse/OCPBUGS-114882): OCPBUGS-112662: GCD load balancer health-check firewall ranges [#10850](https://github.com/openshift/installer/pull/10850)
* [SPLAT-2923](https://issues.redhat.com/browse/SPLAT-2923): vsphere: retry and throttle vCenter lookups during UPI VM creation [#10847](https://github.com/openshift/installer/pull/10847)
* [OCPBUGS-59521](https://issues.redhat.com/browse/OCPBUGS-59521): azure: fixes when setting DiskEncryptionSet on data disks [#10776](https://github.com/openshift/installer/pull/10776)
* [CORS-4550](https://issues.redhat.com/browse/CORS-4550): bump openshift api for gcd feature gate [#10775](https://github.com/openshift/installer/pull/10775)
* [OCPBUGS-59520](https://issues.redhat.com/browse/OCPBUGS-59520): azure: require storageAccountType when managedDisk is specified [#10805](https://github.com/openshift/installer/pull/10805)
* [AGENT-626](https://issues.redhat.com/browse/AGENT-626): Allow UserManaged LoadBalancer on baremetal/vsphere platforms [#10558](https://github.com/openshift/installer/pull/10558)
* [OCPBUGS-59522](https://issues.redhat.com/browse/OCPBUGS-59522): azure: reject securityEncryptionType on data disks [#10777](https://github.com/openshift/installer/pull/10777)
* [OCPBUGS-45804](https://issues.redhat.com/browse/OCPBUGS-45804): Update timeout in GetMarketplaceImage to 5 minutes [#10767](https://github.com/openshift/installer/pull/10767)
* [CORS-4441](https://issues.redhat.com/browse/CORS-4441): Bump Azure Marketplace Images [#10764](https://github.com/openshift/installer/pull/10764)
* [OCPBUGS-105510](https://issues.redhat.com/browse/OCPBUGS-105510): images: add BUILD_VERSION arg [#10781](https://github.com/openshift/installer/pull/10781)
* [CORS-4308](https://issues.redhat.com/browse/CORS-4308): networking: enforce NetworkObservabilityInstall feature gate [#10774](https://github.com/openshift/installer/pull/10774)
* [MULTIARCH-6274](https://issues.redhat.com/browse/MULTIARCH-6274): agent: Enable platform external s390x [#10588](https://github.com/openshift/installer/pull/10588)
* [OCPBUGS-54305](https://issues.redhat.com/browse/OCPBUGS-54305): Power VS: Get permitted network from user [#9607](https://github.com/openshift/installer/pull/9607)
* [OSASINFRA-4359](https://issues.redhat.com/browse/OSASINFRA-4359): Bump CAPO in openshift/installer [#10726](https://github.com/openshift/installer/pull/10726)
* [OCPBUGS-60993](https://issues.redhat.com/browse/OCPBUGS-60993): Enrich IBI config image proxy NoProxy with cluster networks [#10649](https://github.com/openshift/installer/pull/10649)
* [CORS-4308](https://issues.redhat.com/browse/CORS-4308): Enable Network Observability during installation [#10382](https://github.com/openshift/installer/pull/10382)
* [OPNET-781](https://issues.redhat.com/browse/OPNET-781): Add BGP VIP management support [#10718](https://github.com/openshift/installer/pull/10718)
* [Full changelog](https://github.com/openshift/installer/compare/b6f119779c7ce529a94c7b8956a057343675f212...987d45178f07740138e98234ff2cbc5571d4b7a5)
### [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal/tree/20e143749b9bdb4b0cb8387bacae2ad5feece6bf)
* [OCPBUGS-123730](https://issues.redhat.com/browse/OCPBUGS-123730): Bump golang.org/x/net to v0.58.0 to address CVE-2026-33814 [#279](https://github.com/openshift/cluster-api-provider-baremetal/pull/279)
* [OCPBUGS-112338](https://issues.redhat.com/browse/OCPBUGS-112338): Fix race that can provision multiple hosts [#275](https://github.com/openshift/cluster-api-provider-baremetal/pull/275)
* [Full changelog](https://github.com/openshift/cluster-api-provider-baremetal/compare/f2b0db1919fff1344bc68948894c6775c0bf24a3...20e143749b9bdb4b0cb8387bacae2ad5feece6bf)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/8511455cfcf63d7daa377b4db8050e99ce0e7603)
* [OCPBUGS-121877](https://issues.redhat.com/browse/OCPBUGS-121877): pull in gophercloud fix for fast inspection [#525](https://github.com/openshift/baremetal-operator/pull/525)
* [OCPBUGS-122043](https://issues.redhat.com/browse/OCPBUGS-122043), [OCPBUGS-91736](https://issues.redhat.com/browse/OCPBUGS-91736): Merge upstream [#524](https://github.com/openshift/baremetal-operator/pull/524)
* NO-ISSUE: Merge upstream 2026-09-03 [#523](https://github.com/openshift/baremetal-operator/pull/523)
* NO-ISSUE: Restore .golangci.yaml downstream [#522](https://github.com/openshift/baremetal-operator/pull/522)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/34bbeb376836bf01793d4e70d29065d619ebcaa1...8511455cfcf63d7daa377b4db8050e99ce0e7603)
### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/3a0594b2c808b056d037e82093f0ca2268832792)
* [OCPBUGS-98258](https://issues.redhat.com/browse/OCPBUGS-98258): Cloud Platforms: Filter out node's own IP from Upstreams [#399](https://github.com/openshift/baremetal-runtimecfg/pull/399)
* [OCPBUGS-86571](https://issues.redhat.com/browse/OCPBUGS-86571): node-ip: wait for both address families on dual-stack clusters [#391](https://github.com/openshift/baremetal-runtimecfg/pull/391)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/3a261a6f4a6211e8f4031611104ced4def436dde...3a0594b2c808b056d037e82093f0ca2268832792)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/75a043dda6d517af6f40fcf77f371be33e80b59a)
* [OCPBUGS-126457](https://issues.redhat.com/browse/OCPBUGS-126457): [oc create route edge --help] Typo in WildcardPolicy option description [#2409](https://github.com/openshift/oc/pull/2409)
* [OCPBUGS-122354](https://issues.redhat.com/browse/OCPBUGS-122354): Fix inconsistent terminology in oc set probe help example [#2404](https://github.com/openshift/oc/pull/2404)
* [OCPBUGS-122036](https://issues.redhat.com/browse/OCPBUGS-122036): docs(env): add deployment example for configmap import in oc set env help [#2401](https://github.com/openshift/oc/pull/2401)
* NO-JIRA: README: Mention gcc as an oc dependency [#2402](https://github.com/openshift/oc/pull/2402)
* [OCPBUGS-122005](https://issues.redhat.com/browse/OCPBUGS-122005): Add IDMS support to `oc image info` [#2397](https://github.com/openshift/oc/pull/2397)
* [OCPBUGS-114015](https://issues.redhat.com/browse/OCPBUGS-114015): Added deployment example to oc set env help command [#2389](https://github.com/openshift/oc/pull/2389)
* NO-JIRA: Move to openshift/osincli [#2386](https://github.com/openshift/oc/pull/2386)
* NO-JIRA: Fix `oc` builds on Mac OS X Apple Silicon machines [#2246](https://github.com/openshift/oc/pull/2246)
* [Full changelog](https://github.com/openshift/oc/compare/4b0a124d300cef187037bda6f1b04caa69ab8b62...75a043dda6d517af6f40fcf77f371be33e80b59a)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/5c4a3963b75cd85a180c2680d9ae77f5a98c5019)
* [CCO-771](https://issues.redhat.com/browse/CCO-771): Add ccoctl apply secrets command for AWS, Azure and GCP [#1095](https://github.com/openshift/cloud-credential-operator/pull/1095)
* [OCPBUGS-17664](https://issues.redhat.com/browse/OCPBUGS-17664): Improve error messages for SCP-denied IAM operations [#1084](https://github.com/openshift/cloud-credential-operator/pull/1084)
* [CCO-849](https://issues.redhat.com/browse/CCO-849): bump go toolchain to 1.26.5 to resolve snyk complaints [#1065](https://github.com/openshift/cloud-credential-operator/pull/1065)
* [OCPBUGS-112282](https://issues.redhat.com/browse/OCPBUGS-112282): In testing skip pod-identity-webhook checks on external platform [#1085](https://github.com/openshift/cloud-credential-operator/pull/1085)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/b187feee66f4ce0f992059b21a97a2ae88e4cdd9...5c4a3963b75cd85a180c2680d9ae77f5a98c5019)
### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/d3b5de705d133ad568e37b8ccf027d5ccd5e7d38)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): refactor: remove Azure workload identity feature gate [#266](https://github.com/openshift/cloud-network-config-controller/pull/266)
* [OCPBUGS-112564](https://issues.redhat.com/browse/OCPBUGS-112564): Fix CVE-2026-41178 - bump go.opentelemetry.io/otel to v1.44.0 [#262](https://github.com/openshift/cloud-network-config-controller/pull/262)
* [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/7afccf2d78f6cb5dd3181de1588c5063bd995d7d...d3b5de705d133ad568e37b8ccf027d5ccd5e7d38)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/e5d042008d9aab23414c4be66fcfbd430d0f996d)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2463 [#997](https://github.com/openshift/cluster-authentication-operator/pull/997)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#991](https://github.com/openshift/cluster-authentication-operator/pull/991)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2439 [#987](https://github.com/openshift/cluster-authentication-operator/pull/987)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pick https://github.com/openshift/library-go/pull/2449- #2287 [#985](https://github.com/openshift/cluster-authentication-operator/pull/985)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2451 [#984](https://github.com/openshift/cluster-authentication-operator/pull/984)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire EncryptionConfigurationComputer into encryption controllers [#983](https://github.com/openshift/cluster-authentication-operator/pull/983)
* NO-JIRA: Bump library-go [#977](https://github.com/openshift/cluster-authentication-operator/pull/977)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire preflight deployer [#975](https://github.com/openshift/cluster-authentication-operator/pull/975)
* NO-JIRA: Update library-go to get latest changes [#976](https://github.com/openshift/cluster-authentication-operator/pull/976)
* NO-JIRA: bump library-go changes [#974](https://github.com/openshift/cluster-authentication-operator/pull/974)
* NO-JIRA: update KMS tests with bump library-go changes [#969](https://github.com/openshift/cluster-authentication-operator/pull/969)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/848c4c96d8e322b7987e44eecc4ad30e64ce5ed4...e5d042008d9aab23414c4be66fcfbd430d0f996d)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/a819db459f3e0a88becba4c58bf053c6dbda28f2)
* [AUTOSCALE-898](https://issues.redhat.com/browse/AUTOSCALE-898): Add agentic SDLC files [#437](https://github.com/openshift/kubernetes-autoscaler/pull/437)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/f393f54229e6c3ae74c35ae72012af92d31c03d3...a819db459f3e0a88becba4c58bf053c6dbda28f2)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/e4f426dcd988735d1e49da743240231be6ab6a40)
* [AUTOSCALE-899](https://issues.redhat.com/browse/AUTOSCALE-899): add claude and contributing files [#399](https://github.com/openshift/cluster-autoscaler-operator/pull/399)
* [OCPBUGS-111092](https://issues.redhat.com/browse/OCPBUGS-111092): update version to properly detect errors [#395](https://github.com/openshift/cluster-autoscaler-operator/pull/395)
* [OCPBUGS-105277](https://issues.redhat.com/browse/OCPBUGS-105277): implement startupTaints [#383](https://github.com/openshift/cluster-autoscaler-operator/pull/383)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/e48fe1179ad671757b5a40688e2d125c1f326e8b...e4f426dcd988735d1e49da743240231be6ab6a40)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/e1eabae06e1c08f4becfa99e56ca9f707fa10abd)
* Metal-1833: Add attach_non_bootable_iso OTE test [#617](https://github.com/openshift/cluster-baremetal-operator/pull/617)
* [OCPBUGS-115207](https://issues.redhat.com/browse/OCPBUGS-115207): Make HostPath VolumeMounts ReadOnly for image customization container [#658](https://github.com/openshift/cluster-baremetal-operator/pull/658)
* [OCPBUGS-86888](https://issues.redhat.com/browse/OCPBUGS-86888): Fix IDMS YAML serialization for oc image extract [#645](https://github.com/openshift/cluster-baremetal-operator/pull/645)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add bmo_validations and ncsi_reject_poweroff OTE test [#618](https://github.com/openshift/cluster-baremetal-operator/pull/618)
* [OCPBUGS-115067](https://issues.redhat.com/browse/OCPBUGS-115067): Use bcrypt DefaultCost for Ironic passwords [#650](https://github.com/openshift/cluster-baremetal-operator/pull/650)
* [OCPBUGS-114433](https://issues.redhat.com/browse/OCPBUGS-114433): Increase firmware e2e timeouts and add HPE Mellanox NIC bastion mapping [#649](https://github.com/openshift/cluster-baremetal-operator/pull/649)
* [OCPQE-32100](https://issues.redhat.com/browse/OCPQE-32100): Add batched firmware update tests (bmc+bios+nic) [#643](https://github.com/openshift/cluster-baremetal-operator/pull/643)
* [OCPBUGS-105610](https://issues.redhat.com/browse/OCPBUGS-105610): drop IRONIC_INSECURE from BMO [#642](https://github.com/openshift/cluster-baremetal-operator/pull/642)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/402bb6ef1e5cc450cd72282ed891102510b5388c...e1eabae06e1c08f4becfa99e56ca9f707fa10abd)
### [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap/tree/86a2349618a095e9558a008130f64ebb16ee8c30)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#146](https://github.com/openshift/cluster-bootstrap/pull/146)
* [CNTRLPLANE-3717](https://issues.redhat.com/browse/CNTRLPLANE-3717): Add Agentic SDLC context files [#133](https://github.com/openshift/cluster-bootstrap/pull/133)
* [CNF-23048](https://issues.redhat.com/browse/CNF-23048): Migrate away from deprecated ioutil [#123](https://github.com/openshift/cluster-bootstrap/pull/123)
* [Full changelog](https://github.com/openshift/cluster-bootstrap/compare/9573b4d6ef1638c013cde95ec29ddcc80e10cf87...86a2349618a095e9558a008130f64ebb16ee8c30)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/02013fdb38814f1ddc8ac46e568d7369e6ec687b)
* [OCPBUGS-100155](https://issues.redhat.com/browse/OCPBUGS-100155): fix flaky MachineSet sync test by atomically verifying InfraTemplate [#647](https://github.com/openshift/cluster-capi-operator/pull/647)
* [OCPBUGS-114670](https://issues.redhat.com/browse/OCPBUGS-114670): fix(capi2mapi): normalize empty SSHKeyName to nil for MAPI AWS conversion [#659](https://github.com/openshift/cluster-capi-operator/pull/659)
* [OCPBUGS-115197](https://issues.redhat.com/browse/OCPBUGS-115197): machinesync: preserve Synchronized condition lastTransitionTime in CAPI-to-MAPI sync [#656](https://github.com/openshift/cluster-capi-operator/pull/656)
* NO-JIRA: Skip CAPI IPAM test on MicroShift [#661](https://github.com/openshift/cluster-capi-operator/pull/661)
* [OCPCLOUD-3557](https://issues.redhat.com/browse/OCPCLOUD-3557): split capi-controllers and machine-api-migration [#622](https://github.com/openshift/cluster-capi-operator/pull/622)
* NO-JIRA: port OTP CAPI tests to OTE framework [#627](https://github.com/openshift/cluster-capi-operator/pull/627)
* [OCPBUGS-105850](https://issues.redhat.com/browse/OCPBUGS-105850): skip Cluster API Machine Management tests on External topology [#646](https://github.com/openshift/cluster-capi-operator/pull/646)
* NO-JIRA: embed transformer YAML so go mod vendor copies it [#657](https://github.com/openshift/cluster-capi-operator/pull/657)
* [OCPCLOUD-3442](https://issues.redhat.com/browse/OCPCLOUD-3442): Migrate four controllers to per-controller condition reporting [#577](https://github.com/openshift/cluster-capi-operator/pull/577)
* NO-JIRA: Fix flaky CI unit tests: reduce parallelism [#645](https://github.com/openshift/cluster-capi-operator/pull/645)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/5afa8634c5bd26c8ed12dbecb0c31e79ed2fb39c...02013fdb38814f1ddc8ac46e568d7369e6ec687b)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/9ca11878cc35862f4af4c194985b4f3ae3a835fa)
* [OCPBUGS-111416](https://issues.redhat.com/browse/OCPBUGS-111416): Moved node sync job creation from manifest to operator controller [#504](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/504)
* [OCPBUGS-105385](https://issues.redhat.com/browse/OCPBUGS-105385): Bump cloud-provider-aws to fix NLB e2e occasional timeout failures [#503](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/503)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/0da197f80d941f537331f173bc7613d6729a2767...9ca11878cc35862f4af4c194985b4f3ae3a835fa)
### [cluster-config-api](https://github.com/openshift/api/tree/9fb49bfd35acae3aad6414514f669568ada12ada)
* NO-JIRA: Fix codegen diagnostic formatting [#3049](https://github.com/openshift/api/pull/3049)
* operator: Add an option to configure OVN-Kubernetes GatewayConfig without an uplink specified. [#3009](https://github.com/openshift/api/pull/3009)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): chore: remove AzureWorkloadIdentity feature gate [#3018](https://github.com/openshift/api/pull/3018)
* [OPRUN-4768](https://issues.redhat.com/browse/OPRUN-4768): Add serving TLS curve preferences [#3044](https://github.com/openshift/api/pull/3044)
* Remove feature gate VolumeGroupSnapshot [#3027](https://github.com/openshift/api/pull/3027)
* [STOR-3089](https://issues.redhat.com/browse/STOR-3089): Graduate SELinuxMount to GA [#3023](https://github.com/openshift/api/pull/3023)
* [OCPBUGS-112638](https://issues.redhat.com/browse/OCPBUGS-112638): register DRADeviceTaintRules in TPNU [#3004](https://github.com/openshift/api/pull/3004)
* Fix validation pattern for machine/vsphereprovider [#3033](https://github.com/openshift/api/pull/3033)
* features: enable TLSAdherence feature gate for OKD featureset [#3021](https://github.com/openshift/api/pull/3021)
* [CORENET-7538](https://issues.redhat.com/browse/CORENET-7538): Add EgressIPNodeSelector feature gate [#3032](https://github.com/openshift/api/pull/3032)
* [SPLAT-2890](https://issues.redhat.com/browse/SPLAT-2890): Add VSphereScopedCredentials feature gate [#2988](https://github.com/openshift/api/pull/2988)
* [MCO-2332](https://issues.redhat.com/browse/MCO-2332): MCO-2333: Introduce CAPI resource types to boot image update API [#2990](https://github.com/openshift/api/pull/2990)
* [OCPBUGS-99266](https://issues.redhat.com/browse/OCPBUGS-99266): move empty CRIOCredentialProviderConfig CR to run-level 0000_10 [#3011](https://github.com/openshift/api/pull/3011)
* [OCPBUGS-105399](https://issues.redhat.com/browse/OCPBUGS-105399), [OCPBUGS-105400](https://issues.redhat.com/browse/OCPBUGS-105400): Remove SigstoreImageVerification and SigstoreImageVerificationPKI feature gates [#3000](https://github.com/openshift/api/pull/3000)
* [OCPBUGS-112330](https://issues.redhat.com/browse/OCPBUGS-112330): Fix 'supercede' typos in machineconfiguration types [#2996](https://github.com/openshift/api/pull/2996)
* [SPLAT-2864](https://issues.redhat.com/browse/SPLAT-2864): Promote VSphereMultiVCenterDay2 to GA [#2968](https://github.com/openshift/api/pull/2968)
* [CORS-4550](https://issues.redhat.com/browse/CORS-4550): Promote GCD to Default [#2991](https://github.com/openshift/api/pull/2991)
* [OCPBUGS-105407](https://issues.redhat.com/browse/OCPBUGS-105407): Remove VSphereMultiNetworks feature gate [#2975](https://github.com/openshift/api/pull/2975)
* config/v1: add IBMCloudServiceTransitGateway and IBMCloudServicePowerVS to IBMCloudServiceName [#2959](https://github.com/openshift/api/pull/2959)
* [OCPNODE-4526](https://issues.redhat.com/browse/OCPNODE-4526): Block '..' traversal in StorePath [#2999](https://github.com/openshift/api/pull/2999)
* [OCPBUGS-74510](https://issues.redhat.com/browse/OCPBUGS-74510): Remove VSphereMultiDisk feature gate [#2973](https://github.com/openshift/api/pull/2973)
* Add printer columns to PodNetworkConnectivityCheck CRD [#2977](https://github.com/openshift/api/pull/2977)
* [NE-2387](https://issues.redhat.com/browse/NE-2387): IngressController AWS NLB Security Group Selection [#2914](https://github.com/openshift/api/pull/2914)
* [OCPBUGS-112479](https://issues.redhat.com/browse/OCPBUGS-112479): Handle Sippy date-only format in featuregate-test-analyzer [#2998](https://github.com/openshift/api/pull/2998)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default for Hypershift [#2993](https://github.com/openshift/api/pull/2993)
* [TRT-2908](https://issues.redhat.com/browse/TRT-2908): Revert "CNTRLPLANE-3871: promote OSStreams feature gate to Default for Hypershift" [#2989](https://github.com/openshift/api/pull/2989)
* [OCPBUGS-105409](https://issues.redhat.com/browse/OCPBUGS-105409): chore: remove AWSServiceLBNetworkSecurityGroup feature gate [#2974](https://github.com/openshift/api/pull/2974)
* [CORS-4529](https://issues.redhat.com/browse/CORS-4529): Azure IL6 Secret Cloud support [#2919](https://github.com/openshift/api/pull/2919)
* [CNTRLPLANE-3609](https://issues.redhat.com/browse/CNTRLPLANE-3609): graduate etcdBackendQuota to GA [#2946](https://github.com/openshift/api/pull/2946)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default for Hypershift [#2950](https://github.com/openshift/api/pull/2950)
* [OCPNODE-4601](https://issues.redhat.com/browse/OCPNODE-4601): Add {system,container}GomaxprocsBehavior field [#2934](https://github.com/openshift/api/pull/2934)
* [Full changelog](https://github.com/openshift/api/compare/31af9f93e31ecd483504b3302d78f67c5a077a9e...9fb49bfd35acae3aad6414514f669568ada12ada)
### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/6a4d4a58182fa4e810c9c6bf66d14eea4cfe37bb)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#504](https://github.com/openshift/cluster-config-operator/pull/504)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#500](https://github.com/openshift/cluster-config-operator/pull/500)
* [OCPEDGE-2747](https://issues.redhat.com/browse/OCPEDGE-2747): feat: add topology transition controller for day-2 SNO to HA transitions [#495](https://github.com/openshift/cluster-config-operator/pull/495)
* [Full changelog](https://github.com/openshift/cluster-config-operator/compare/324996d8fff21db132e0c4764600d4720adab4be...6a4d4a58182fa4e810c9c6bf66d14eea4cfe37bb)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/81541d53f815a4cb25255b0dad33f449762c4609)
* [OCPBUGS-86988](https://issues.redhat.com/browse/OCPBUGS-86988): Guard against empty workspace field on vsphere [#407](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/407)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/c00cf58dd81954ca100757f6a2d2af8d84770fd5...81541d53f815a4cb25255b0dad33f449762c4609)
### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/03b68fd87ae423f78b2a31174d6c432acad47eb5)
* [OCPBUGS-104846](https://issues.redhat.com/browse/OCPBUGS-104846): Remove VolumeGroupSnapshot feature gate [#297](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/297)
* [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/35ec0224eb0e5219d5eae012fb703223a6f3e1f7...03b68fd87ae423f78b2a31174d6c432acad47eb5)
### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/c480e21c16d3383a7c09752f8dea61743c765cfa)
* [ART-23537](https://issues.redhat.com/browse/ART-23537): Fix hermetic build failure by removing update-bindata from build target [#489](https://github.com/openshift/cluster-dns-operator/pull/489)
* [NE-2880](https://issues.redhat.com/browse/NE-2880): Update GitHub issue template URLs [#487](https://github.com/openshift/cluster-dns-operator/pull/487)
* [NE-2126](https://issues.redhat.com/browse/NE-2126): Migrating DNS operator test cases from QE repo [#485](https://github.com/openshift/cluster-dns-operator/pull/485)
* [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/c0ed09e329e9001629518604a58205e3fbe8284a...c480e21c16d3383a7c09752f8dea61743c765cfa)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/891802de59125027f63e4e15d153ca9f4301744f)
* [CNTRLPLANE-4414](https://issues.redhat.com/browse/CNTRLPLANE-4414): allow TLS 1.3 profiles without ciphers [#1710](https://github.com/openshift/cluster-etcd-operator/pull/1710)
* NO-JIRA: refactor: remove unused cert-watcher daemonset manifest [#1711](https://github.com/openshift/cluster-etcd-operator/pull/1711)
* [OCPBUGS-123168](https://issues.redhat.com/browse/OCPBUGS-123168): fix: add missing workload paritioning annotation on cert-watcher daemonset [#1706](https://github.com/openshift/cluster-etcd-operator/pull/1706)
* [OCPBUGS-104851](https://issues.redhat.com/browse/OCPBUGS-104851): feat: add cert-watcher DaemonSet to restart etcd on CA bundle rotation [#1675](https://github.com/openshift/cluster-etcd-operator/pull/1675)
* [OCPBUGS-94106](https://issues.redhat.com/browse/OCPBUGS-94106): fall back to intermediate ciphers during etcd bootstrap [#1689](https://github.com/openshift/cluster-etcd-operator/pull/1689)
* [OCPBUGS-80957](https://issues.redhat.com/browse/OCPBUGS-80957): Reset node status when UID changes [#1687](https://github.com/openshift/cluster-etcd-operator/pull/1687)
* [OCPBUGS-105322](https://issues.redhat.com/browse/OCPBUGS-105322): fix etcdSignerCAExpiration* alert description wording [#1686](https://github.com/openshift/cluster-etcd-operator/pull/1686)
* [CNTRLPLANE-4131](https://issues.redhat.com/browse/CNTRLPLANE-4131): update to latest api to pull in etcd db ga [#1680](https://github.com/openshift/cluster-etcd-operator/pull/1680)
* [OCPBUGS-109740](https://issues.redhat.com/browse/OCPBUGS-109740): Fix tnf_cluster_in_service during per-node maintenance [#1678](https://github.com/openshift/cluster-etcd-operator/pull/1678)
* [OCPBUGS-109743](https://issues.redhat.com/browse/OCPBUGS-109743): Derive console notification docs URL from cluster version [#1676](https://github.com/openshift/cluster-etcd-operator/pull/1676)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/fb6ecceb7232511baa7df34d38e65415de52322d...891802de59125027f63e4e15d153ca9f4301744f)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/7c198c202079bc9dc76debab40dcf5610bcf8707)
* [OCPBUGS-114531](https://issues.redhat.com/browse/OCPBUGS-114531): Add 2m degraded inertia to ImagePrunerController [#1365](https://github.com/openshift/cluster-image-registry-operator/pull/1365)
* [OCPBUGS-112551](https://issues.redhat.com/browse/OCPBUGS-112551): imageconfig: Preserve ImageStreamImportMode during upgrade race [#1363](https://github.com/openshift/cluster-image-registry-operator/pull/1363)
* [OCPBUGS-86308](https://issues.redhat.com/browse/OCPBUGS-86308): do not report progressing during cluster scale up [#1361](https://github.com/openshift/cluster-image-registry-operator/pull/1361)
* [OCPBUGS-113705](https://issues.redhat.com/browse/OCPBUGS-113705): CNTRLPLANE-3779: Migrated go standard cases to ote [#1343](https://github.com/openshift/cluster-image-registry-operator/pull/1343)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/ef16ea310611b60b6b3a0e7593030b3784805b28...7c198c202079bc9dc76debab40dcf5610bcf8707)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/a373f6b0e8b36ed26c84e2d0f1dee64dd81351d4)
* [OCPBUGS-122346](https://issues.redhat.com/browse/OCPBUGS-122346): Fix GatewayClass index registration retries during bootstrap [#1588](https://github.com/openshift/cluster-ingress-operator/pull/1588)
* [OCPBUGS-105442](https://issues.redhat.com/browse/OCPBUGS-105442): Remove escalate/bind from Sail Library ClusterRole [#1548](https://github.com/openshift/cluster-ingress-operator/pull/1548)
* [NE-2909](https://issues.redhat.com/browse/NE-2909): Address Gateway API management-mode follow-ups [#1595](https://github.com/openshift/cluster-ingress-operator/pull/1595)
* [OCPBUGS-105317](https://issues.redhat.com/browse/OCPBUGS-105317): Bump to OSSM 3.4.2 and istio 1.30.4 [#1576](https://github.com/openshift/cluster-ingress-operator/pull/1576)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): docs: clarify Azure workload identity token file [#1586](https://github.com/openshift/cluster-ingress-operator/pull/1586)
* NO-JIRA: Add pedjak to OWNERS [#1596](https://github.com/openshift/cluster-ingress-operator/pull/1596)
* [NE-2388](https://issues.redhat.com/browse/NE-2388): aws nlb security groups [#1500](https://github.com/openshift/cluster-ingress-operator/pull/1500)
* [NE-2779](https://issues.redhat.com/browse/NE-2779): Implement Gateway API management mode [#1547](https://github.com/openshift/cluster-ingress-operator/pull/1547)
* [OCPBUGS-86050](https://issues.redhat.com/browse/OCPBUGS-86050): Update ROUTER_CURVES environment variable for go 1.26 [#1542](https://github.com/openshift/cluster-ingress-operator/pull/1542)
* [OCPBUGS-6718](https://issues.redhat.com/browse/OCPBUGS-6718): minimize wildcard RBAC permissions [#1579](https://github.com/openshift/cluster-ingress-operator/pull/1579)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): refactor: remove Azure workload identity feature gate [#1575](https://github.com/openshift/cluster-ingress-operator/pull/1575)
* [NE-2491](https://issues.redhat.com/browse/NE-2491): Delete the CRL controller [#1536](https://github.com/openshift/cluster-ingress-operator/pull/1536)
* [WAF-3](https://issues.redhat.com/browse/WAF-3): Implement extension provider capability for WAF [#1555](https://github.com/openshift/cluster-ingress-operator/pull/1555)
* [OCPBUGS-62627](https://issues.redhat.com/browse/OCPBUGS-62627): Suppress Progressing during infrastructure-driven ingress unavailability [#1496](https://github.com/openshift/cluster-ingress-operator/pull/1496)
* [OCPBUGS-92835](https://issues.redhat.com/browse/OCPBUGS-92835): add grace period to Available condition for deployment… [#1544](https://github.com/openshift/cluster-ingress-operator/pull/1544)
* [OCPBUGS-109582](https://issues.redhat.com/browse/OCPBUGS-109582): Normalize malformed CIDRs to avoid upgrade disruptions [#1549](https://github.com/openshift/cluster-ingress-operator/pull/1549)
* [OCPBUGS-91026](https://issues.redhat.com/browse/OCPBUGS-91026): Add missing KAS-defaulted fields to ValidatingAdmissionPolicy manifest [#1560](https://github.com/openshift/cluster-ingress-operator/pull/1560)
* [OCPBUGS-112280](https://issues.redhat.com/browse/OCPBUGS-112280): Preserve server-defaulted fields on init containers and volumes [#1557](https://github.com/openshift/cluster-ingress-operator/pull/1557)
* [NE-2856](https://issues.redhat.com/browse/NE-2856): Fix staticcheck warnings across multiple packages [#1553](https://github.com/openshift/cluster-ingress-operator/pull/1553)
* [NE-2032](https://issues.redhat.com/browse/NE-2032): e2e: Signal service deprovisioning issues during Gateway DNS test [#1220](https://github.com/openshift/cluster-ingress-operator/pull/1220)
* [OCPBUGS-101783](https://issues.redhat.com/browse/OCPBUGS-101783): reconcile canary certificate on dependency creation [#1538](https://github.com/openshift/cluster-ingress-operator/pull/1538)
* [OCPBUGS-100074](https://issues.redhat.com/browse/OCPBUGS-100074): Use /healthz for router startup probe [#1528](https://github.com/openshift/cluster-ingress-operator/pull/1528)
* [OCPBUGS-86841](https://issues.redhat.com/browse/OCPBUGS-86841): Add BackendTLSPolicy and ReferenceGrant e2e test coverage helpers [#1467](https://github.com/openshift/cluster-ingress-operator/pull/1467)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/fe8a2bcf6342fab7aa19c47b4397a7d226962136...a373f6b0e8b36ed26c84e2d0f1dee64dd81351d4)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/ae7f3ea3f0fb68b2eafb247049835d5d8543923e)
* [OPRUN-4768](https://issues.redhat.com/browse/OPRUN-4768): bump openshift/api [#2316](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2316)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2463 [#2309](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2309)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#2307](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2307)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2439 [#2282](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2282)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pick https://github.com/openshift/library-go/pull/2449 [#2287](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2287)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2451 [#2289](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2289)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire EncryptionConfigurationComputer into encryption controllers [#2292](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2292)
* NO-JIRA: Bump library-go [#2286](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2286)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire preflight deployer [#2276](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2276)
* NO-JIRA: Update library-go to get latest changes [#2280](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2280)
* [OCPBUGS-80958](https://issues.redhat.com/browse/OCPBUGS-80958): Kube apiserver node replace [#2199](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2199)
* NO-JIRA: bump library-go changes [#2270](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2270)
* [OCPBUGS-38661](https://issues.redhat.com/browse/OCPBUGS-38661): Use 10min inertia for GuardControllerDegraded [#2273](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2273)
* [OCPBUGS-85183](https://issues.redhat.com/browse/OCPBUGS-85183): Add kind-aware staleness detection for runtime-config entries [#2179](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2179)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2430 [#2271](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2271)
* NO-JIRA:Remove old perf tests and update Makefile [#2269](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2269)
* [CNTRLPLANE-4110](https://issues.redhat.com/browse/CNTRLPLANE-4110): Migrate e2e encryption perf cases to ote [#2256](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2256)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/b8c26db7c7c7e49476235ec83b2e81ef0996e242...ae7f3ea3f0fb68b2eafb247049835d5d8543923e)
### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/416af3a20bd39d33d7506f04a6c483528aa9e6dc)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#967](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/967)
* [OCPBUGS-107974](https://issues.redhat.com/browse/OCPBUGS-107974): fix CVE-2026-41178 [#955](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/955)
* [OCPBUGS-38662](https://issues.redhat.com/browse/OCPBUGS-38662): Use 10min inertia for GuardControllerDegraded [#956](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/956)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/1ee372e7019b41fbcb4c64323142c4a06bf266d0...416af3a20bd39d33d7506f04a6c483528aa9e6dc)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/7d896ecefe171028a01f6b7cfdbf30bc5828b414)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#676](https://github.com/openshift/cluster-kube-scheduler-operator/pull/676)
* [OCPBUGS-107969](https://issues.redhat.com/browse/OCPBUGS-107969): bump otel to v1.44.0 to fix CVE-2026-41178 [#662](https://github.com/openshift/cluster-kube-scheduler-operator/pull/662)
* [OCPBUGS-38663](https://issues.redhat.com/browse/OCPBUGS-38663): Use 10min inertia for GuardControllerDegraded [#661](https://github.com/openshift/cluster-kube-scheduler-operator/pull/661)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/e0d271fceb3727138177e017f860a8ff79738bb3...7d896ecefe171028a01f6b7cfdbf30bc5828b414)
### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/c96773c19165a46d55007cd6a14d24376ab83d4c)
* [OCPBUGS-57437](https://issues.redhat.com/browse/OCPBUGS-57437): Always validate EgressIPs [#309](https://github.com/openshift/cluster-machine-approver/pull/309)
* [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/11c03d0952f281ca9cfb62e528e5a0e24ae644ab...c96773c19165a46d55007cd6a14d24376ab83d4c)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/ffa52202be7ea5a7b313d10ed1cc9af8f97ed968)
* [MON-4689](https://issues.redhat.com/browse/MON-4689), [OCPBUGS-123539](https://issues.redhat.com/browse/OCPBUGS-123539): Bump prometheus-operator jsonnet and libs to v0.94.0 [#3083](https://github.com/openshift/cluster-monitoring-operator/pull/3083)
* [OCPBUGS-123792](https://issues.redhat.com/browse/OCPBUGS-123792): restore node-exporter textfile metrics with read-only rootfs [#3088](https://github.com/openshift/cluster-monitoring-operator/pull/3088)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3089](https://github.com/openshift/cluster-monitoring-operator/pull/3089)
* NO-JIRA: Skip flaky TestTelemetryReport/rate_issues subtest [#3087](https://github.com/openshift/cluster-monitoring-operator/pull/3087)
* [OCPBUGS-83375](https://issues.redhat.com/browse/OCPBUGS-83375): Create alerting rule for metrics-server failing to scrape kubelet [#2933](https://github.com/openshift/cluster-monitoring-operator/pull/2933)
* [MON-4638](https://issues.redhat.com/browse/MON-4638): align ThanosQueryOverload description with for=1h [#3062](https://github.com/openshift/cluster-monitoring-operator/pull/3062)
* [MON-4665](https://issues.redhat.com/browse/MON-4665): wire zoneinfo node-exporter collector from ClusterMonitorin… [#3063](https://github.com/openshift/cluster-monitoring-operator/pull/3063)
* NO-JIRA: Makefile: ensure JUnit test name prefix is applied even on test failure [#3079](https://github.com/openshift/cluster-monitoring-operator/pull/3079)
* NO-ISSUE: update jsonnet dependencies [#3077](https://github.com/openshift/cluster-monitoring-operator/pull/3077)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3076](https://github.com/openshift/cluster-monitoring-operator/pull/3076)
* [MON-4560](https://issues.redhat.com/browse/MON-4560): implement merge logic in CMO for the new field in the ClusterMonitoring CRD [#3056](https://github.com/openshift/cluster-monitoring-operator/pull/3056)
* [MON-4632](https://issues.redhat.com/browse/MON-4632), [MON-4633](https://issues.redhat.com/browse/MON-4633): Send metrics ramen:dr_policy_type:max and ramen:dr_protected_apps:max via Telemetry [#3074](https://github.com/openshift/cluster-monitoring-operator/pull/3074)
* [MON-4617](https://issues.redhat.com/browse/MON-4617): Update kube-prometheus and add resourceMetricsAPI field [#3069](https://github.com/openshift/cluster-monitoring-operator/pull/3069)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3068](https://github.com/openshift/cluster-monitoring-operator/pull/3068)
* NO-JIRA: Fix staticcheck warnings across multiple packages [#3059](https://github.com/openshift/cluster-monitoring-operator/pull/3059)
* NO-JIRA: test: produce JUnit XML from e2e runs in CI [#3054](https://github.com/openshift/cluster-monitoring-operator/pull/3054)
* NO-JIRA: Makefile: version-stamp golangci-lint binary to prevent stale linter - #3057#3057 [#3057](https://github.com/openshift/cluster-monitoring-operator/pull/3057)
* [OCPBUGS-99769](https://issues.redhat.com/browse/OCPBUGS-99769): wrap library-go resourceCache with mutex for thread safety [#3040](https://github.com/openshift/cluster-monitoring-operator/pull/3040)
* NO-JIRA: hack/tools: remove unused vendor directory [#3055](https://github.com/openshift/cluster-monitoring-operator/pull/3055)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/efeeabf10a9c46f7a82086d2c04c9fc6d93a2b22...ffa52202be7ea5a7b313d10ed1cc9af8f97ed968)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/61de77e4d4c4f65cd5b3d73e00308bfe837c1066)
* NO-JIRA: fix(ovn-kubernetes): disable local DB probes [#3163](https://github.com/openshift/cluster-network-operator/pull/3163)
* [CORENET-7275](https://issues.redhat.com/browse/CORENET-7275): Add AGENTS.md, point CodeRabbit knowledge base at it [#3146](https://github.com/openshift/cluster-network-operator/pull/3146)
* [CORENET-7479](https://issues.redhat.com/browse/CORENET-7479): Add status.vrfName and shortNames to UDN/CUDN CRDs [#3145](https://github.com/openshift/cluster-network-operator/pull/3145)
* [OCPBUGS-113591](https://issues.redhat.com/browse/OCPBUGS-113591): golangci-lint: enable ContextTodo/ContextBackground in usetesting [#3138](https://github.com/openshift/cluster-network-operator/pull/3138)
* [OCPBUGS-92080](https://issues.redhat.com/browse/OCPBUGS-92080): Adds rendering of enable-multi-network-policy in ovnkube-node [#3084](https://github.com/openshift/cluster-network-operator/pull/3084)
* [OCPBUGS-112562](https://issues.redhat.com/browse/OCPBUGS-112562): CVE-2026-41178 - bump go.opentelemetry.io/otel to v1.44.0 [#3132](https://github.com/openshift/cluster-network-operator/pull/3132)
* [OCPBUGS-112278](https://issues.redhat.com/browse/OCPBUGS-112278): Add ConfigMap hash annotation to networking console plugin deployment [#3131](https://github.com/openshift/cluster-network-operator/pull/3131)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Install NOO using OLMv0 instead of OLMv1 [#3115](https://github.com/openshift/cluster-network-operator/pull/3115)
* [OCPBUGS-64582](https://issues.redhat.com/browse/OCPBUGS-64582): Drop strategy.rollingUpdate and switch strategy.type to Recreate via pre-patch in frr-k8s-statuscleaner deployments on SNO [#3121](https://github.com/openshift/cluster-network-operator/pull/3121)
* [OCPBUGS-105887](https://issues.redhat.com/browse/OCPBUGS-105887): Filter unsupported cipher suites to prevent ovnkube-identity crash [#3119](https://github.com/openshift/cluster-network-operator/pull/3119)
* NO-ISSUE: modernise the codebase using go fix [#3113](https://github.com/openshift/cluster-network-operator/pull/3113)
* [CORENET-7330](https://issues.redhat.com/browse/CORENET-7330): Allow per-node OVN encap IP override via env-overrides [#2998](https://github.com/openshift/cluster-network-operator/pull/2998)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/d7a55c9a073db7e954d3dd484e9d400dc5b5b3ac...61de77e4d4c4f65cd5b3d73e00308bfe837c1066)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/b4c215b68874838b91ee73dcd2fc63897add46f6)
* [OCPBUGS-112336](https://issues.redhat.com/browse/OCPBUGS-112336): apis: add missing fields to apis v1 [#1597](https://github.com/openshift/cluster-node-tuning-operator/pull/1597)
* NO-JIRA: Fix CentOS Stream image build failing in dnf history undo [#1633](https://github.com/openshift/cluster-node-tuning-operator/pull/1633)
* [CNF-23698](https://issues.redhat.com/browse/CNF-23698): e2e: make OVS dynamic pinning tests compatible with ovsDpdk CPUs [#1598](https://github.com/openshift/cluster-node-tuning-operator/pull/1598)
* [CNF-25173](https://issues.redhat.com/browse/CNF-25173): e2e: resolve primary MCP from profile in test 32364 [#1624](https://github.com/openshift/cluster-node-tuning-operator/pull/1624)
* [OCPBUGS-113651](https://issues.redhat.com/browse/OCPBUGS-113651): Disable timer.migration on RHCOS 10 [#1614](https://github.com/openshift/cluster-node-tuning-operator/pull/1614)
* [CNF-26060](https://issues.redhat.com/browse/CNF-26060): add optional --ovs-dpdk-cpu-count flag (default 0) [#1590](https://github.com/openshift/cluster-node-tuning-operator/pull/1590)
* NO-JIRA: Bump Kubernetes, OpenShift and other dependencies [#1615](https://github.com/openshift/cluster-node-tuning-operator/pull/1615)
* [OCPBUGS-113647](https://issues.redhat.com/browse/OCPBUGS-113647): E2E: Minor fixes to Memory Manager and hugepages split tests [#1578](https://github.com/openshift/cluster-node-tuning-operator/pull/1578)
* [OCPBUGS-112537](https://issues.redhat.com/browse/OCPBUGS-112537): E2E: Fix ovs dynamic pinning, kubelet and mustgather tests [#1565](https://github.com/openshift/cluster-node-tuning-operator/pull/1565)
* [CNF-26497](https://issues.redhat.com/browse/CNF-26497): unconditionally disable fwupd-refresh.timer [#1591](https://github.com/openshift/cluster-node-tuning-operator/pull/1591)
* [OCPBUGS-112025](https://issues.redhat.com/browse/OCPBUGS-112025): Bump golang.org/x/net [#1593](https://github.com/openshift/cluster-node-tuning-operator/pull/1593)
* [OCPBUGS-105476](https://issues.redhat.com/browse/OCPBUGS-105476): Update PPC help description [#1582](https://github.com/openshift/cluster-node-tuning-operator/pull/1582)
* [OCPBUGS-105458](https://issues.redhat.com/browse/OCPBUGS-105458): Use Add() instead of AddRateLimited() for routine Profile enqueues [#1584](https://github.com/openshift/cluster-node-tuning-operator/pull/1584)
* NO-JIRA: ci: disable smt alignment for ovsDpdk tests [#1589](https://github.com/openshift/cluster-node-tuning-operator/pull/1589)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/accb8e2235f97d682b9d3aea95295bdfaf9b15e0...b4c215b68874838b91ee73dcd2fc63897add46f6)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/9afc2cacd8fcb69af291396d387b52d3ca140eb1)
* [OCPBUGS-105876](https://issues.redhat.com/browse/OCPBUGS-105876): Wire availableInertia into the olm StatusSyncer [#233](https://github.com/openshift/cluster-olm-operator/pull/233)
* [OPRUN-4645](https://issues.redhat.com/browse/OPRUN-4645): observe and apply TLS curve preferences to operand deployments [#226](https://github.com/openshift/cluster-olm-operator/pull/226)
* NO-ISSUE: Bump helm.sh/helm/v3 from 3.21.3 to 3.21.4 [#235](https://github.com/openshift/cluster-olm-operator/pull/235)
* NO-ISSUE: Bump the k8s-dependencies group across 1 directory with 5 updates [#237](https://github.com/openshift/cluster-olm-operator/pull/237)
* NO-ISSUE: Bump golang.org/x/text from 0.40.0 to 0.41.0 [#234](https://github.com/openshift/cluster-olm-operator/pull/234)
* NO-ISSUE: Bump github.com/stretchr/testify from 1.11.1 to 1.12.1 [#236](https://github.com/openshift/cluster-olm-operator/pull/236)
* NO-ISSUE: Bump the k8s-dependencies group across 1 directory with 5 updates [#227](https://github.com/openshift/cluster-olm-operator/pull/227)
* NO-ISSUE: Bump github.com/operator-framework/operator-controller from 1.5.1 to 1.11.0 [#228](https://github.com/openshift/cluster-olm-operator/pull/228)
* NO-ISSUE: Update dependabot config with NO-ISSUE prefix [#232](https://github.com/openshift/cluster-olm-operator/pull/232)
* NO-ISSUE: Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 [#231](https://github.com/openshift/cluster-olm-operator/pull/231)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/228ec940921e4443b2724ef512c0d211d4a38ba7...9afc2cacd8fcb69af291396d387b52d3ca140eb1)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/4978130a0b2ed26971dca5e7758d6310d1b5a2b1)
* [OPRUN-4768](https://issues.redhat.com/browse/OPRUN-4768): bump openshift/api [#782](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/782)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2463- #2309 [#770](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/770)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#768](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/768)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2439 [#767](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/767)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pick https://github.com/openshift/library-go/pull/2449- #2287 [#764](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/764)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2451 [#763](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/763)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire EncryptionConfigurationComputer into encryption controllers [#762](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/762)
* NO-JIRA: Bump library-go [#760](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/760)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire preflight deployer [#758](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/758)
* NO-JIRA: Update library-go to get latest changes [#759](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/759)
* NO-JIRA: Update KMS cases and bump library-go [#756](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/756)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2430 [#754](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/754)
* [OCPBUGS-105786](https://issues.redhat.com/browse/OCPBUGS-105786): Revert "Revert "NO-JIRA: Disable WatchList feature gate due to the missing support of Project watch"" [#751](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/751)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/d56fffed57ce229b53b4cb1eba63311360051806...4978130a0b2ed26971dca5e7758d6310d1b5a2b1)
### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/c9e9a348260921c9e788e33a51e904502cbe2d13)
* [CNTRLPLANE-3731](https://issues.redhat.com/browse/CNTRLPLANE-3731): Add Agentic SDLC context files to cluster-policy-controller [#191](https://github.com/openshift/cluster-policy-controller/pull/191)
* [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/469bbf211d35eee0df4422bda7e9e600b080f0f2...c9e9a348260921c9e788e33a51e904502cbe2d13)
### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/a4147d3308b2e935f58cf05eac4bf5fa35fa6cf8)
* [OKD-425](https://issues.redhat.com/browse/OKD-425): Revert openliberty back to 26.0.0.6 [#709](https://github.com/openshift/cluster-samples-operator/pull/709)
* [TRT-2905](https://issues.redhat.com/browse/TRT-2905): Fix python:latest and nodejs template references after UBI 8 tag removal [#706](https://github.com/openshift/cluster-samples-operator/pull/706)
* [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/ba80c7efd89885b08dc890eb5aefb994ee1e7ab9...a4147d3308b2e935f58cf05eac4bf5fa35fa6cf8)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/da41a216e9cdc764fb8e2fd0447029e68893e1ee)
* [GCP-958](https://issues.redhat.com/browse/GCP-958): re-enable GCP PD CSI driver in HyperShift path [#742](https://github.com/openshift/cluster-storage-operator/pull/742)
* [GCP-958](https://issues.redhat.com/browse/GCP-958): temporarily disable GCP PD CSI driver in HyperShift path [#739](https://github.com/openshift/cluster-storage-operator/pull/739)
* [GCP-1075](https://issues.redhat.com/browse/GCP-1075): feat(gcp-pd): enable HyperShift support for GCP PD CSI driver operator [#728](https://github.com/openshift/cluster-storage-operator/pull/728)
* [OCPBUGS-112710](https://issues.redhat.com/browse/OCPBUGS-112710): clusterrole/openshift-csi-main-snapshotter-role needs volume group snapshot rules [#727](https://github.com/openshift/cluster-storage-operator/pull/727)
* [OCPBUGS-91027](https://issues.redhat.com/browse/OCPBUGS-91027): Add KAS-defaulted fields to storage-operator ValidatingAdmissionPolicy manifests [#726](https://github.com/openshift/cluster-storage-operator/pull/726)
* [OCPBUGS-105391](https://issues.redhat.com/browse/OCPBUGS-105391): Pass management cluster proxy env vars to CSI driver operator deployments [#723](https://github.com/openshift/cluster-storage-operator/pull/723)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/b2ee363241ad0425efd56badb6046884cadda97d...da41a216e9cdc764fb8e2fd0447029e68893e1ee)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/882fd242b69c14e475f5671294712cec88c62c7f)
* [OKD-194](https://issues.redhat.com/browse/OKD-194): Add OKD cincinnati as the default update service for OKD [#1466](https://github.com/openshift/cluster-version-operator/pull/1466)
* [OTA-2109](https://issues.redhat.com/browse/OTA-2109): harden console plugin nginx TLS configuration [#1453](https://github.com/openshift/cluster-version-operator/pull/1453)
* [OTA-2110](https://issues.redhat.com/browse/OTA-2110): remove cluster_id from LLM-bound readiness payload [#1451](https://github.com/openshift/cluster-version-operator/pull/1451)
* [OTA-2111](https://issues.redhat.com/browse/OTA-2111): set readOnlyRootFilesystem on console plugin container [#1452](https://github.com/openshift/cluster-version-operator/pull/1452)
* [OTA-2108](https://issues.redhat.com/browse/OTA-2108): restrict console plugin NetworkPolicy to openshift-console namespace [#1450](https://github.com/openshift/cluster-version-operator/pull/1450)
* [OTA-2106](https://issues.redhat.com/browse/OTA-2106): drop NetworkCheck (SDN gone, proxy data unused) [#1442](https://github.com/openshift/cluster-version-operator/pull/1442)
* NO-ISSUE: pkg/readiness/cluster_conditions: Conditionally include Upgradeable [#1463](https://github.com/openshift/cluster-version-operator/pull/1463)
* [OCPBUGS-54864](https://issues.redhat.com/browse/OCPBUGS-54864): reduce verbosity of skipping metrics log messages [#1439](https://github.com/openshift/cluster-version-operator/pull/1439)
* NO-ISSUE: OWNERS: Pratik is no longer at Red Hat :( [#1449](https://github.com/openshift/cluster-version-operator/pull/1449)
* [OCPBUGS-80925](https://issues.redhat.com/browse/OCPBUGS-80925): Remove the CRB for the default openshift-cluster-version SA [#1366](https://github.com/openshift/cluster-version-operator/pull/1366)
* [OCPBUGS-110322](https://issues.redhat.com/browse/OCPBUGS-110322): pkg/agenticrun/controller: Pivot to cluster-update-advisor directory [#1446](https://github.com/openshift/cluster-version-operator/pull/1446)
* "OTA-2107: Harden AgenticRun against indirect prompt injection" [#1443](https://github.com/openshift/cluster-version-operator/pull/1443)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/219aba7debd16c83bb6ccdccf156af921ce54dfe...882fd242b69c14e475f5671294712cec88c62c7f)
### [configmap-reloader](https://github.com/openshift/configmap-reload/tree/596569055fdaa7f01d0ecdd5a29579d5f9196328)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#84](https://github.com/openshift/configmap-reload/pull/84)
* [Full changelog](https://github.com/openshift/configmap-reload/compare/ce80869a83b55ebbdc21a5550ec5747645203bd2...596569055fdaa7f01d0ecdd5a29579d5f9196328)
### [console](https://github.com/openshift/console/tree/afe3510f5b5737edb0ab93a584db5d0d85c49f73)
* [OCPBUGS-126807](https://issues.redhat.com/browse/OCPBUGS-126807): Post qa-verify evidence via gh's native --attach instead of base64 [#17193](https://github.com/openshift/console/pull/17193)
* [OCPBUGS-125223](https://issues.redhat.com/browse/OCPBUGS-125223): restore some old test-prow-e2e scenarios [#17187](https://github.com/openshift/console/pull/17187)
* [OCPBUGS-126219](https://issues.redhat.com/browse/OCPBUGS-126219): i18n upload/download routine task - version 4.23/5.0 (Additional) [#17190](https://github.com/openshift/console/pull/17190)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#17176](https://github.com/openshift/console/pull/17176)
* [OCPBUGS-90834](https://issues.redhat.com/browse/OCPBUGS-90834): Fix empty vSphere connection details after upgrade [#17020](https://github.com/openshift/console/pull/17020)
* [OCPBUGS-123141](https://issues.redhat.com/browse/OCPBUGS-123141): i18n upload/download routine task - version 4.23/5.0 [#17165](https://github.com/openshift/console/pull/17165)
* [CONSOLE-4998](https://issues.redhat.com/browse/CONSOLE-4998): Add types for serverless resources [#17152](https://github.com/openshift/console/pull/17152)
* [OCPBUGS-121263](https://issues.redhat.com/browse/OCPBUGS-121263): bump go-git to 5.19.2 [#17148](https://github.com/openshift/console/pull/17148)
* [OCPBUGS-115458](https://issues.redhat.com/browse/OCPBUGS-115458): CVE-2026-84375 bump js-yaml to 3.15.2/4.3.2 [#17133](https://github.com/openshift/console/pull/17133)
* [OCPBUGS-115318](https://issues.redhat.com/browse/OCPBUGS-115318): fix Helm test flake by replacing pkill with PID-file cleanup [#17128](https://github.com/openshift/console/pull/17128)
* [OCPBUGS-120684](https://issues.redhat.com/browse/OCPBUGS-120684): Update stale comment [#17141](https://github.com/openshift/console/pull/17141)
* NO-JIRA: add prettier to playwright folder [#17137](https://github.com/openshift/console/pull/17137)
* [OCPBUGS-115300](https://issues.redhat.com/browse/OCPBUGS-115300): Stabilize topology, node-groups, and debug-pod e2e [#17134](https://github.com/openshift/console/pull/17134)
* [OCPBUGS-115300](https://issues.redhat.com/browse/OCPBUGS-115300): Fix Playwright login helper idempotency and session recovery [#17126](https://github.com/openshift/console/pull/17126)
* [HELM-480](https://issues.redhat.com/browse/HELM-480): Change handler return code [#17042](https://github.com/openshift/console/pull/17042)
* [OCPBUGS-115298](https://issues.redhat.com/browse/OCPBUGS-115298): Rename e2e scripts so playwright is the main one [#17127](https://github.com/openshift/console/pull/17127)
* [CONSOLE-5002](https://issues.redhat.com/browse/CONSOLE-5002): `UserPreferenceContext`and linting follow up [#17124](https://github.com/openshift/console/pull/17124)
* [OCPBUGS-109632](https://issues.redhat.com/browse/OCPBUGS-109632): Fix webhook creation in Git for PAC [#17078](https://github.com/openshift/console/pull/17078)
* NO-JIRA: fix session-persistence tests failing due to pre-loaded storageState [#17121](https://github.com/openshift/console/pull/17121)
* [CONSOLE-5002](https://issues.redhat.com/browse/CONSOLE-5002): re-render user preferences only when a listened key changes [#17104](https://github.com/openshift/console/pull/17104)
* [OCPBUGS-114052](https://issues.redhat.com/browse/OCPBUGS-114052): move yarn install to prow scripts [#17119](https://github.com/openshift/console/pull/17119)
* [OCPBUGS-115128](https://issues.redhat.com/browse/OCPBUGS-115128): Upgrade grpc to v1.83.2 and x/net to v0.58.0 [#17120](https://github.com/openshift/console/pull/17120)
* [RFE-9146](https://issues.redhat.com/browse/RFE-9146): Docs followup for service account impersonation [#17093](https://github.com/openshift/console/pull/17093)
* [CONSOLE-5000](https://issues.redhat.com/browse/CONSOLE-5000): Remove Redux activeNamespace in favor of NamespaceContext [#17102](https://github.com/openshift/console/pull/17102)
* NO-JIRA: Improve readability of `test-frontend` output [#17080](https://github.com/openshift/console/pull/17080)
* [OCPBUGS-112809](https://issues.redhat.com/browse/OCPBUGS-112809): Restore panic on Helm test infrastructure failure [#17077](https://github.com/openshift/console/pull/17077)
* [OCPBUGS-85646](https://issues.redhat.com/browse/OCPBUGS-85646): display operators in catalog when Tech Preview enabled [#16976](https://github.com/openshift/console/pull/16976)
* [OCPBUGS-95590](https://issues.redhat.com/browse/OCPBUGS-95590): Hide Builds nav section when Build capability is disabled [#16891](https://github.com/openshift/console/pull/16891)
* [CONSOLE-5001](https://issues.redhat.com/browse/CONSOLE-5001): Remove ImmutableJS [#17024](https://github.com/openshift/console/pull/17024)
* [OCPBUGS-105603](https://issues.redhat.com/browse/OCPBUGS-105603): Strip version tag from OCI chart URL to prevent doubl… [#16999](https://github.com/openshift/console/pull/16999)
* [OCPBUGS-99884](https://issues.redhat.com/browse/OCPBUGS-99884): Fix "Set as default" StorageClass action [#17066](https://github.com/openshift/console/pull/17066)
* [OCPBUGS-112462](https://issues.redhat.com/browse/OCPBUGS-112462): Remove empty integration-tests package from CI [#17064](https://github.com/openshift/console/pull/17064)
* [OCPBUGS-52186](https://issues.redhat.com/browse/OCPBUGS-52186): Show CPU/Memory metrics for non-admin users on Projects page [#17001](https://github.com/openshift/console/pull/17001)
* [OCPBUGS-111698](https://issues.redhat.com/browse/OCPBUGS-111698): Migrate app/ Cypress e2e tests to Playwright [#17015](https://github.com/openshift/console/pull/17015)
* [OCPBUGS-112046](https://issues.redhat.com/browse/OCPBUGS-112046): fix Helm test flake by detecting dead processes early [#17039](https://github.com/openshift/console/pull/17039)
* [CONSOLE-5463](https://issues.redhat.com/browse/CONSOLE-5463): Turn on react compiler linting rules [#17032](https://github.com/openshift/console/pull/17032)
* [OCPBUGS-75963](https://issues.redhat.com/browse/OCPBUGS-75963): Fix Edit Machine count action on MachineSet details page [#17038](https://github.com/openshift/console/pull/17038)
* [OCPBUGS-95597](https://issues.redhat.com/browse/OCPBUGS-95597): Fix UI validation for private Bitbucket repositories [#17028](https://github.com/openshift/console/pull/17028)
* [OCPBUGS-111634](https://issues.redhat.com/browse/OCPBUGS-111634): Keep OLS cluster-update prompts within OpenAI 32k limit [#17018](https://github.com/openshift/console/pull/17018)
* [OCPBUGS-111699](https://issues.redhat.com/browse/OCPBUGS-111699): Migrate secrets e2e tests from Cypress to Playwright [#17006](https://github.com/openshift/console/pull/17006)
* [CONSOLE-5159](https://issues.redhat.com/browse/CONSOLE-5159), [OCPBUGS-95606](https://issues.redhat.com/browse/OCPBUGS-95606): Replace deprecated Node10 moduleResolution with Bundler for TS6 compatibility [#16259](https://github.com/openshift/console/pull/16259)
* [OCPBUGS-111929](https://issues.redhat.com/browse/OCPBUGS-111929): Fix plugin entrypoint failing to load [#17027](https://github.com/openshift/console/pull/17027)
* [HELM-827](https://issues.redhat.com/browse/HELM-827): Add RTL unit tests for 9 critical Helm plugin components [#16909](https://github.com/openshift/console/pull/16909)
* NO-JIRA: add myself to owners and add frontend owners to .claude [#17025](https://github.com/openshift/console/pull/17025)
* [OCPBUGS-86298](https://issues.redhat.com/browse/OCPBUGS-86298): Fix missing Impersonate action on RoleBinding detail page [#16783](https://github.com/openshift/console/pull/16783)
* [OCPBUGS-86294](https://issues.redhat.com/browse/OCPBUGS-86294): Fix MachineAutoscaler modal crash when opened from detail page [#16781](https://github.com/openshift/console/pull/16781)
* [OCPBUGS-86511](https://issues.redhat.com/browse/OCPBUGS-86511): Fix flaky TestAsyncCache backend test [#17009](https://github.com/openshift/console/pull/17009)
* [OCPBUGS-111644](https://issues.redhat.com/browse/OCPBUGS-111644): Shared Playwright e2e context and test generation skill [#16986](https://github.com/openshift/console/pull/16986)
* [CONSOLE-5003](https://issues.redhat.com/browse/CONSOLE-5003): reimplement and enable jest linting [#17019](https://github.com/openshift/console/pull/17019)
* [OCPBUGS-95594](https://issues.redhat.com/browse/OCPBUGS-95594): make cloud provider fields optional during operator install [#16927](https://github.com/openshift/console/pull/16927)
* [OCPBUGS-14473](https://issues.redhat.com/browse/OCPBUGS-14473): Guard against undefined data in dashboard charts [#16952](https://github.com/openshift/console/pull/16952)
* And 22 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/ce87b012a919897ec15cfd3043a7e79d33f5ecd8...afe3510f5b5737edb0ab93a584db5d0d85c49f73)
### [console-operator](https://github.com/openshift/console-operator/tree/b8447d3ef1eb621046ebdce84efb8ceb736dabdb)
* [CONSOLE-5405](https://issues.redhat.com/browse/CONSOLE-5405): Update console-operator to Kubernetes 1.36 [#1211](https://github.com/openshift/console-operator/pull/1211)
* [OCPBUGS-104500](https://issues.redhat.com/browse/OCPBUGS-104500): Use content hash for ConfigMap deployment annotations [#1217](https://github.com/openshift/console-operator/pull/1217)
* [OCPBUGS-71237](https://issues.redhat.com/browse/OCPBUGS-71237): Generate session-secret for all auth types [#1204](https://github.com/openshift/console-operator/pull/1204)
* [OCPBUGS-58422](https://issues.redhat.com/browse/OCPBUGS-58422): Handle disabled Ingress capability in HyperShift [#1182](https://github.com/openshift/console-operator/pull/1182)
* [OCPBUGS-92204](https://issues.redhat.com/browse/OCPBUGS-92204): Clear stale OIDC degraded condition on auth type change [#1212](https://github.com/openshift/console-operator/pull/1212)
* [CNF-23047](https://issues.redhat.com/browse/CNF-23047): Migrate away from deprecated ioutil [#1072](https://github.com/openshift/console-operator/pull/1072)
* [OCPBUGS-104854](https://issues.redhat.com/browse/OCPBUGS-104854): Fix excessive DeploymentUpdated events via content hash [#1210](https://github.com/openshift/console-operator/pull/1210)
* [OCPBUGS-109670](https://issues.redhat.com/browse/OCPBUGS-109670): Derive documentationBaseURL dynamically from OPERATOR_IMAGE_VERSION [#1209](https://github.com/openshift/console-operator/pull/1209)
* [Full changelog](https://github.com/openshift/console-operator/compare/630495120bc5ddc9e05cd6defc2102690ced6301...b8447d3ef1eb621046ebdce84efb8ceb736dabdb)
### [container-networking-plugins, containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins/tree/b0bea6bcba28cab2ffa15da03cbae98805af7eca)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#228](https://github.com/openshift/containernetworking-plugins/pull/228)
* [Full changelog](https://github.com/openshift/containernetworking-plugins/compare/d253ee09d629b8172ffc9c3e4b571320fc63ee34...b0bea6bcba28cab2ffa15da03cbae98805af7eca)
### [csi-driver-manila, openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/fb1be731410a5d4eb6b3a3692c9081856df72c10)
* [OCPBUGS-98116](https://issues.redhat.com/browse/OCPBUGS-98116): Bump golang.org/x/crypto to v0.52.0 [#410](https://github.com/openshift/cloud-provider-openstack/pull/410)
* [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/aa9a8100e87ff13abf4dd6343c84c9f4948debef...fb1be731410a5d4eb6b3a3692c9081856df72c10)
### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/69f816f69e1273868bc19cb13fe6dbd9a7a9ff5f)
* UPSTREAM-SYNC: Merge https://github.com/kubernetes-csi/csi-driver-nfs:master (f12e133) into main [#199](https://github.com/openshift/csi-driver-nfs/pull/199)
* [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa...69f816f69e1273868bc19cb13fe6dbd9a7a9ff5f)
### [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata/tree/e8f0f2a3e9e358061148f90dc41f97cfb0bc5a54)
* NO-ISSUE: Bump golang.org/x/net to v0.53.0 and Go to 1.25.10 [#22](https://github.com/openshift/csi-external-snapshot-metadata/pull/22)
* [Full changelog](https://github.com/openshift/csi-external-snapshot-metadata/compare/b929f29695d4a1ab21a70868f681d463a673380f...e8f0f2a3e9e358061148f90dc41f97cfb0bc5a54)
### [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe/tree/4d22ba873038484dcd7fa67553d00ae01d20428a)
* [OCPBUGS-122222](https://issues.redhat.com/browse/OCPBUGS-122222): Bump go.opentelemetry.io/otel to v1.44.0 to address CVE-2026-41178 [#96](https://github.com/openshift/csi-livenessprobe/pull/96)
* [Full changelog](https://github.com/openshift/csi-livenessprobe/compare/cab57d511106916bba6953977106f06b2fec01fd...4d22ba873038484dcd7fa67553d00ae01d20428a)
### [docker-builder](https://github.com/openshift/builder/tree/c71e860460d9a120f29202dfc8a8eb30cb2ca30f)
* NO-JIRA: Bump golang.org/x/crypto, update CI builder images and go directive to go1.26 [#555](https://github.com/openshift/builder/pull/555)
* [Full changelog](https://github.com/openshift/builder/compare/35b0a13b45e95c19046a59dc8727cf60210d6a0d...c71e860460d9a120f29202dfc8a8eb30cb2ca30f)
### [docker-registry](https://github.com/openshift/image-registry/tree/823010aa7b0dcf1da53a26c2ec135d0a32e63d85)
* [OCPBUGS-99398](https://issues.redhat.com/browse/OCPBUGS-99398): Fix resolveUpstreamRef to properly propagate not-found errors [#475](https://github.com/openshift/image-registry/pull/475)
* [Full changelog](https://github.com/openshift/image-registry/compare/9436b2271fc9b687bda31e335bacc4031dcba80a...823010aa7b0dcf1da53a26c2ec135d0a32e63d85)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/49554e572efac19f660a00ecfe2ccbc4e84be1e0)
* [OCPBUGS-105251](https://issues.redhat.com/browse/OCPBUGS-105251): Update Dockerfiles [#111](https://github.com/openshift/egress-router-cni/pull/111)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/bc639044a3aee89f1f9547ad0539481b8d808516...49554e572efac19f660a00ecfe2ccbc4e84be1e0)
### [etcd](https://github.com/openshift/etcd/tree/24fb7ef2afe9c4e4ca179f70b101d8ac2a0daeab)
* [CNTRLPLANE-3724](https://issues.redhat.com/browse/CNTRLPLANE-3724): add agentic context docs for the openshift/etcd fork [#411](https://github.com/openshift/etcd/pull/411)
* [Full changelog](https://github.com/openshift/etcd/compare/609b11ed8fc404fb95572d7c87e3243a1206cdb7...24fb7ef2afe9c4e4ca179f70b101d8ac2a0daeab)
### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/5c3d894654ec0316347b26fb586a074bab160b2e)
* UPSTREAM-SYNC: Merge https://github.com/kubernetes-sigs/cluster-api-provider-gcp:v1.13.1 (8198b8b) into main [#302](https://github.com/openshift/cluster-api-provider-gcp/pull/302)
* [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/dbcbfe70efa75f192309f2d0f8daae2c6a441e90...5c3d894654ec0316347b26fb586a074bab160b2e)
### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/aac3d11bb011778fbb4f7717c59c18f617f82ad1)
* [OCPBUGS-82191](https://issues.redhat.com/browse/OCPBUGS-82191): Wait for RUNNING before providerID; retry stockout [#160](https://github.com/openshift/machine-api-provider-gcp/pull/160)
* [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/91033fc5b42f58acdad7be8c89a0012f5f2c9b5b...aac3d11bb011778fbb4f7717c59c18f617f82ad1)
### [haproxy-router, haproxy-router-haproxy28, haproxy-router-haproxy32](https://github.com/openshift/router/tree/d5cf9f2aa0bdd024f51a208f12558da9bac5ed38)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Lock DeleteFunc to stop SARCompleted overwriting rejection [#840](https://github.com/openshift/router/pull/840)
* [Full changelog](https://github.com/openshift/router/compare/3381229146657d2e6bd94115dda0885f25cb3bed...d5cf9f2aa0bdd024f51a208f12558da9bac5ed38)
### [hyperkube, kube-proxy, pod](https://github.com/openshift/kubernetes/tree/7cb7f330df454d8581b579ad835ad6b263533126)
* NO-JIRA: Rebase master to Kubernetes v1.36.4 [#2777](https://github.com/openshift/kubernetes/pull/2777)
* NO-JIRA: Skip SELinuxMountReadWriteOncePodOnly tests now that SELinuxMount is GA [#2782](https://github.com/openshift/kubernetes/pull/2782)
* [OCPBUGS-104846](https://issues.redhat.com/browse/OCPBUGS-104846): UPSTREAM: 141358: Enable group snapshot tests in all configurations [#2747](https://github.com/openshift/kubernetes/pull/2747)
* NO-JIRA: Make graceful-termination-duration flag required for the watch-termination command [#2761](https://github.com/openshift/kubernetes/pull/2761)
* [Full changelog](https://github.com/openshift/kubernetes/compare/b376ee7b841bed5a51cb9520b37d87931c48a821...7cb7f330df454d8581b579ad835ad6b263533126)
### [hypershift](https://github.com/openshift/hypershift/tree/2e7d902422a7dd111801a917ba75935b97dced71)
* [AUTOSCALE-873](https://issues.redhat.com/browse/AUTOSCALE-873): Add sidecar to standalone karpenter-operator [#9565](https://github.com/openshift/hypershift/pull/9565)
* [CNTRLPLANE-4090](https://issues.redhat.com/browse/CNTRLPLANE-4090): Move CPO, HCCO and etcd recovery manifest constructors to shared packages [#9592](https://github.com/openshift/hypershift/pull/9592)
* [OCPBUGS-113995](https://issues.redhat.com/browse/OCPBUGS-113995): classify WebIdentityErr by cause to prevent false invalid creds [#9406](https://github.com/openshift/hypershift/pull/9406)
* [OCPBUGS-115468](https://issues.redhat.com/browse/OCPBUGS-115468): fix NodePool: truncate oversized machine messages instead of dropping them [#9567](https://github.com/openshift/hypershift/pull/9567)
* feat(kubevirt): OCPBUGS-55974: add CPU model configuration for NodePool VMs [#7431](https://github.com/openshift/hypershift/pull/7431)
* [CNTRLPLANE-4209](https://issues.redhat.com/browse/CNTRLPLANE-4209): Consolidate Azure lifecycle test lanes [#9572](https://github.com/openshift/hypershift/pull/9572)
* [GCP-510](https://issues.redhat.com/browse/GCP-510): Implement GCP NodePool CLI Commands [#9466](https://github.com/openshift/hypershift/pull/9466)
* [OCPBUGS-84562](https://issues.redhat.com/browse/OCPBUGS-84562): Configure AWS CCM region directly [#9602](https://github.com/openshift/hypershift/pull/9602)
* NO-JIRA: ci(deps): bump astral-sh/setup-uv from 6.1.0 to 10.1.0 [#9682](https://github.com/openshift/hypershift/pull/9682)
* NO-JIRA: chore(owners): add core approvers [#9651](https://github.com/openshift/hypershift/pull/9651)
* [CNTRLPLANE-4090](https://issues.redhat.com/browse/CNTRLPLANE-4090): Move metric name constants to shared packages [#9540](https://github.com/openshift/hypershift/pull/9540)
* [OCPBUGS-125803](https://issues.redhat.com/browse/OCPBUGS-125803): skip TLS flag propagation tests for older operator versions [#9641](https://github.com/openshift/hypershift/pull/9641)
* [CNTRLPLANE-4453](https://issues.redhat.com/browse/CNTRLPLANE-4453): clarify private Key Vault validation comments [#9645](https://github.com/openshift/hypershift/pull/9645)
* [CNTRLPLANE-4209](https://issues.redhat.com/browse/CNTRLPLANE-4209): Update Azure lifecycle test-flow documentation [#9573](https://github.com/openshift/hypershift/pull/9573)
* [CNTRLPLANE-4456](https://issues.redhat.com/browse/CNTRLPLANE-4456): Run envtests for release-5.0 [#9649](https://github.com/openshift/hypershift/pull/9649)
* [AUTOSCALE-974](https://issues.redhat.com/browse/AUTOSCALE-974), [AUTOSCALE-980](https://issues.redhat.com/browse/AUTOSCALE-980): allow Karpenter to be deployed on Azure [#9545](https://github.com/openshift/hypershift/pull/9545)
* [OCPBUGS-123512](https://issues.redhat.com/browse/OCPBUGS-123512): fix(e2e): derive node runtimes from upgraded NodePool state [#9611](https://github.com/openshift/hypershift/pull/9611)
* [OCPBUGS-122236](https://issues.redhat.com/browse/OCPBUGS-122236): stabilize JUnit test identities [#9580](https://github.com/openshift/hypershift/pull/9580)
* chore(renovate): enable supported release branches [#9631](https://github.com/openshift/hypershift/pull/9631)
* [CNTRLPLANE-4209](https://issues.redhat.com/browse/CNTRLPLANE-4209): Reject shared variants in concurrent e2e lanes [#9571](https://github.com/openshift/hypershift/pull/9571)
* [OCPBUGS-109672](https://issues.redhat.com/browse/OCPBUGS-109672): fix(cpo) wait for etcd health, not just DNS [#9460](https://github.com/openshift/hypershift/pull/9460)
* [OCPBUGS-123645](https://issues.redhat.com/browse/OCPBUGS-123645): add missing Azure v2 matrix coverage [#9616](https://github.com/openshift/hypershift/pull/9616)
* NO-JIRA: fix(e2e): restore Eventually retry for post-upgrade health condition check [#9632](https://github.com/openshift/hypershift/pull/9632)
* [OCPBUGS-89689](https://issues.redhat.com/browse/OCPBUGS-89689): karpenter control plane upgrade premature drift fix [#9234](https://github.com/openshift/hypershift/pull/9234)
* [CNTRLPLANE-3880](https://issues.redhat.com/browse/CNTRLPLANE-3880): Add E2E test for etcd snapshot restore to prevent split brain regression [#9356](https://github.com/openshift/hypershift/pull/9356)
* NO-JIRA: Bump envtest workflow timeout to 20 minutes [#9630](https://github.com/openshift/hypershift/pull/9630)
* [CNTRLPLANE-4090](https://issues.redhat.com/browse/CNTRLPLANE-4090): Move labels, taints, scheduler, VAP and misc constants to shared packages [#9544](https://github.com/openshift/hypershift/pull/9544)
* NO-JIRA: Fix CONTRIBUTING.md link path and remove trailing blank lines [#9621](https://github.com/openshift/hypershift/pull/9621)
* [OCPBUGS-122011](https://issues.redhat.com/browse/OCPBUGS-122011): fix(e2e): Make `InstallHyperShiftOperator` platform aware [#9555](https://github.com/openshift/hypershift/pull/9555)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): Enable HC and HCP status-write linting [#9563](https://github.com/openshift/hypershift/pull/9563)
* [CNTRLPLANE-3608](https://issues.redhat.com/browse/CNTRLPLANE-3608): Add nested virtualization support for AWS EC2 NodePools [#8681](https://github.com/openshift/hypershift/pull/8681)
* [GCP-1122](https://issues.redhat.com/browse/GCP-1122): chore: add pvasant to gcp-reviewers alias [#9465](https://github.com/openshift/hypershift/pull/9465)
* [CNTRLPLANE-4393](https://issues.redhat.com/browse/CNTRLPLANE-4393): document CAPI provider image override mechanisms [#9482](https://github.com/openshift/hypershift/pull/9482)
* [CNTRLPLANE-3277](https://issues.redhat.com/browse/CNTRLPLANE-3277): Add Azure OAuth LoadBalancer private topology e2e test [#8584](https://github.com/openshift/hypershift/pull/8584)
* [OCPBUGS-122232](https://issues.redhat.com/browse/OCPBUGS-122232): Gate CAPI API version by management release [#9587](https://github.com/openshift/hypershift/pull/9587)
* [CNTRLPLANE-4093](https://issues.redhat.com/browse/CNTRLPLANE-4093): Move shared label constants to api/hypershift/v1beta1 [#9415](https://github.com/openshift/hypershift/pull/9415)
* [CNTRLPLANE-4207](https://issues.redhat.com/browse/CNTRLPLANE-4207): document Azure lifecycle test sharding [#9504](https://github.com/openshift/hypershift/pull/9504)
* [GCP-958](https://issues.redhat.com/browse/GCP-958): test(e2e/v2): register gcp-pd-csi-driver control plane workloads [#9589](https://github.com/openshift/hypershift/pull/9589)
* [OCPBUGS-97942](https://issues.redhat.com/browse/OCPBUGS-97942): fix(cli): add --service-publishing-strategy flag to hcp create cluster agent [#8985](https://github.com/openshift/hypershift/pull/8985)
* NO-JIRA: build(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 [#9546](https://github.com/openshift/hypershift/pull/9546)
* [CNTRLPLANE-4094](https://issues.redhat.com/browse/CNTRLPLANE-4094): Move ExternalDNSLBPort and KASRouteHostname to support/netutil [#9414](https://github.com/openshift/hypershift/pull/9414)
* NO-JIRA: fix(ci): use --target for pip install on ARC runner [#9531](https://github.com/openshift/hypershift/pull/9531)
* [CNTRLPLANE-4150](https://issues.redhat.com/browse/CNTRLPLANE-4150): feat: Maintain ingress serving cert for HostedCluster ingress [#9132](https://github.com/openshift/hypershift/pull/9132)
* [CNTRLPLANE-4207](https://issues.redhat.com/browse/CNTRLPLANE-4207): update v2 test flow documentation [#9569](https://github.com/openshift/hypershift/pull/9569)
* [CNTRLPLANE-4369](https://issues.redhat.com/browse/CNTRLPLANE-4369): add prow job id tag to e2e v2 aws resources [#9542](https://github.com/openshift/hypershift/pull/9542)
* NO-JIRA: fix(managed-azure): continue resource group cleanup when HC destroy fails [#9404](https://github.com/openshift/hypershift/pull/9404)
* [ACM-41684](https://issues.redhat.com/browse/ACM-41684): Switch hypershift-operator runtime to PQC base image [#9453](https://github.com/openshift/hypershift/pull/9453)
* NO-JIRA: fix(install): increase WaitUntilAvailable timeout from 5m to 10m [#9306](https://github.com/openshift/hypershift/pull/9306)
* [OCPBUGS-87991](https://issues.redhat.com/browse/OCPBUGS-87991): validate additionalNetworks name format in KubeVirt NodePools [#8710](https://github.com/openshift/hypershift/pull/8710)
* NO-JIRA: feat(azure): Add scripts to setup credentials and check resources [#9446](https://github.com/openshift/hypershift/pull/9446)
* [CNTRLPLANE-4005](https://issues.redhat.com/browse/CNTRLPLANE-4005): Skip CDI importer pods from custom labels and tolerations checks [#9240](https://github.com/openshift/hypershift/pull/9240)
* [OCPBUGS-109724](https://issues.redhat.com/browse/OCPBUGS-109724): fix KubeVirt custom baseDomain ingress documentation [#9318](https://github.com/openshift/hypershift/pull/9318)
* NO-JIRA: spread AKS nodes across availability zones [#9449](https://github.com/openshift/hypershift/pull/9449)
* [CNTRLPLANE-4370](https://issues.redhat.com/browse/CNTRLPLANE-4370): Revert "Merge pull request #9543 from ironcladlou/e2e-promotion" [#9574](https://github.com/openshift/hypershift/pull/9574)
* [OCPBUGS-114415](https://issues.redhat.com/browse/OCPBUGS-114415): Increase relay timeouts to prevent intermittent test failures [#9459](https://github.com/openshift/hypershift/pull/9459)
* NO-JIRA: Gate GCP credential validation by control plane version [#9562](https://github.com/openshift/hypershift/pull/9562)
* [OCPBUGS-120840](https://issues.redhat.com/browse/OCPBUGS-120840): remove TechPreviewNoUpgrade from AWS cluster creation args [#9535](https://github.com/openshift/hypershift/pull/9535)
* [OCPBUGS-121208](https://issues.redhat.com/browse/OCPBUGS-121208): filter AWS-reserved tag keys before calling DeleteTags [#9538](https://github.com/openshift/hypershift/pull/9538)
* [GCP-883](https://issues.redhat.com/browse/GCP-883): Optimize GCP PSC NAT allocation [#9472](https://github.com/openshift/hypershift/pull/9472)
* [CNTRLPLANE-3603](https://issues.redhat.com/browse/CNTRLPLANE-3603): Migrate clients from CAPI v1beta1 to v1beta2 [#8717](https://github.com/openshift/hypershift/pull/8717)
* NO-JIRA: remove duplicate e2e v2 test flow doc [#9553](https://github.com/openshift/hypershift/pull/9553)
* [CNTRLPLANE-4370](https://issues.redhat.com/browse/CNTRLPLANE-4370): enforce explicit blocking/informing labels on all v2 e2e tests [#9543](https://github.com/openshift/hypershift/pull/9543)
* NO-JIRA: ci(deps): bump actions/actions-runner from 2.336.0 to 2.337.0- #9513 [#9513](https://github.com/openshift/hypershift/pull/9513)
* [CNTRLPLANE-3998](https://issues.redhat.com/browse/CNTRLPLANE-3998): warn when deprecated kube-apiserver verbosity annotation is set [#9461](https://github.com/openshift/hypershift/pull/9461)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): migrate HCCO/route status patches to statuspatching [#9385](https://github.com/openshift/hypershift/pull/9385)
* [OCPBUGS-99534](https://issues.redhat.com/browse/OCPBUGS-99534): etcd initialization bugs after etcdctl snapshot restore [#9048](https://github.com/openshift/hypershift/pull/9048)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): increase e2e v2 control plane upgrade coverage for v1 parity [#9491](https://github.com/openshift/hypershift/pull/9491)
* [OCPBUGS-120685](https://issues.redhat.com/browse/OCPBUGS-120685): fix(e2e): select a live NodePool for osImageStream node OS verification [#9506](https://github.com/openshift/hypershift/pull/9506)
* [ROSAENG-63186](https://issues.redhat.com/browse/ROSAENG-63186): fix(hcco): Add VAP to protect kas-bootstrap RBAC bindings from deletion [#9203](https://github.com/openshift/hypershift/pull/9203)
* NO-JIRA: remove unsafe v1 framework usage from karpenter upgrade test [#9522](https://github.com/openshift/hypershift/pull/9522)
* [CNTRLPLANE-2007](https://issues.redhat.com/browse/CNTRLPLANE-2007): KubeVirt default ingress passthrough with HostNetwork endpoint publishing strategy [#9514](https://github.com/openshift/hypershift/pull/9514)
* [CNTRLPLANE-4207](https://issues.redhat.com/browse/CNTRLPLANE-4207): Balance Azure v2 lifecycle test shards [#9419](https://github.com/openshift/hypershift/pull/9419)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): add hcpstatuspatch linter and status-patching AGENTS.md guidance [#9388](https://github.com/openshift/hypershift/pull/9388)
* [OCPBUGS-114459](https://issues.redhat.com/browse/OCPBUGS-114459): recognize domain-specific test fields [#9454](https://github.com/openshift/hypershift/pull/9454)
* [GCP-503](https://issues.redhat.com/browse/GCP-503): feat(gcp): Implement OrphanDeleter [#8884](https://github.com/openshift/hypershift/pull/8884)
* [OCPBUGS-115269](https://issues.redhat.com/browse/OCPBUGS-115269): openstack: Start populating cacert in clouds.yaml [#9467](https://github.com/openshift/hypershift/pull/9467)
* [CNTRLPLANE-3951](https://issues.redhat.com/browse/CNTRLPLANE-3951): fix(e2e): accept node deletion as success in TestSpotTerminationHandler [#9428](https://github.com/openshift/hypershift/pull/9428)
* [OCPBUGS-74960](https://issues.redhat.com/browse/OCPBUGS-74960): fix orphaned security group during VPC endpoint deletion [#9517](https://github.com/openshift/hypershift/pull/9517)
* NO-JIRA: test(backuprestore): enable SnapshotMoveData in backup configurations [#9429](https://github.com/openshift/hypershift/pull/9429)
* [GCP-958](https://issues.redhat.com/browse/GCP-958): feat(gcp): complete GCP PD CSI driver wiring in HyperShift [#9450](https://github.com/openshift/hypershift/pull/9450)
* [RHOBS-1707](https://issues.redhat.com/browse/RHOBS-1707): Add OpenTelemetry SDK tracing to hypershift-operator [#9390](https://github.com/openshift/hypershift/pull/9390)
* [OCPBUGS-105464](https://issues.redhat.com/browse/OCPBUGS-105464): fix(nodepool): inject default worker SG by status ID, not fail-open capability flag [#9456](https://github.com/openshift/hypershift/pull/9456)
* [OCPBUGS-84368](https://issues.redhat.com/browse/OCPBUGS-84368): add safe-to-evict annotation and remove tolerations to fix autoscaler scale-down and drain loop [#8338](https://github.com/openshift/hypershift/pull/8338)
* [AUTOSCALE-998](https://issues.redhat.com/browse/AUTOSCALE-998): inject token-minter image to standalone karpenter-operator [#9492](https://github.com/openshift/hypershift/pull/9492)
* [OCPBUGS-120685](https://issues.redhat.com/browse/OCPBUGS-120685): fix(e2e): label flaking nodepool osImageStream test informing [#9505](https://github.com/openshift/hypershift/pull/9505)
* NO-JIRA: feat(chaibot): add per-platform Slack handle pings to CI health report [#9478](https://github.com/openshift/hypershift/pull/9478)
* build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /hack/tools [#9479](https://github.com/openshift/hypershift/pull/9479)
* build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 [#9480](https://github.com/openshift/hypershift/pull/9480)
* [OCPBUGS-114408](https://issues.redhat.com/browse/OCPBUGS-114408): fix(api): allow spaces in AWS resource tag keys and values [#9425](https://github.com/openshift/hypershift/pull/9425)
* [GCP-1113](https://issues.redhat.com/browse/GCP-1113): retry transient network errors in hypershift create iam gcp [#9436](https://github.com/openshift/hypershift/pull/9436)
* [OCPBUGS-115542](https://issues.redhat.com/browse/OCPBUGS-115542): fix(e2e): poll for etcd-init completion before reading restore logs [#9481](https://github.com/openshift/hypershift/pull/9481)
* [OCPBUGS-114368](https://issues.redhat.com/browse/OCPBUGS-114368): Retry Microsoft Graph transport failures [#9421](https://github.com/openshift/hypershift/pull/9421)
* [OCPBUGS-86690](https://issues.redhat.com/browse/OCPBUGS-86690): fix Azure cluster deletion hanging when resource groups are already deleted [#8682](https://github.com/openshift/hypershift/pull/8682)
* [CNTRLPLANE-4041](https://issues.redhat.com/browse/CNTRLPLANE-4041): add new release branches to renovate config [#9470](https://github.com/openshift/hypershift/pull/9470)
* [OCPBUGS-77781](https://issues.redhat.com/browse/OCPBUGS-77781): fix(certs): normalize IP SANs to stop dual-stack KAS cert churn [#9286](https://github.com/openshift/hypershift/pull/9286)
* [CNTRLPLANE-4205](https://issues.redhat.com/browse/CNTRLPLANE-4205): document OSImageStream behaviour deviations [#9486](https://github.com/openshift/hypershift/pull/9486)
* [CNTRLPLANE-3755](https://issues.redhat.com/browse/CNTRLPLANE-3755): fix(e2e): add version gating to EnsureCAPIFinalizers tests [#9443](https://github.com/openshift/hypershift/pull/9443)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): enable e2e v2 aws control plane upgrade tests [#9474](https://github.com/openshift/hypershift/pull/9474)
* [OCPBUGS-115403](https://issues.redhat.com/browse/OCPBUGS-115403): ensure informing junit files are unique across test groups [#9473](https://github.com/openshift/hypershift/pull/9473)
* [ACM-41685](https://issues.redhat.com/browse/ACM-41685): Enable PQC crypto policy in hypershift-cli image [#9463](https://github.com/openshift/hypershift/pull/9463)
* [OCPBUGS-113712](https://issues.redhat.com/browse/OCPBUGS-113712): preserve immutable AWS load balancer annotations [#9469](https://github.com/openshift/hypershift/pull/9469)
* NO-JIRA: chore(konflux): update Tekton task bundles to latest versions [#9483](https://github.com/openshift/hypershift/pull/9483)
* [CNTRLPLANE-4204](https://issues.redhat.com/browse/CNTRLPLANE-4204): reorganize OSImageStream e2e tests after graduation [#9418](https://github.com/openshift/hypershift/pull/9418)
* [CNTRLPLANE-3201](https://issues.redhat.com/browse/CNTRLPLANE-3201): feat(e2e): enable etcd snapshot backup test on Azure [#9226](https://github.com/openshift/hypershift/pull/9226)
* [CNTRLPLANE-2029](https://issues.redhat.com/browse/CNTRLPLANE-2029): docs(backuprestore): add Agent and KubeVirt platform prerequisites [#9072](https://github.com/openshift/hypershift/pull/9072)
* [CNTRLPLANE-3950](https://issues.redhat.com/browse/CNTRLPLANE-3950): fix flaky TestKMSRootVolumeEncryption race condition. [#9304](https://github.com/openshift/hypershift/pull/9304)
* [CNTRLPLANE-4208](https://issues.redhat.com/browse/CNTRLPLANE-4208): Right-size Azure v2 e2e worker counts [#9426](https://github.com/openshift/hypershift/pull/9426)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): port karpenter upgrade test to v2 [#9397](https://github.com/openshift/hypershift/pull/9397)
* NO-JIRA: fix(azure): orphan AzureMachines when capi-provider cannot run [#9403](https://github.com/openshift/hypershift/pull/9403)
* [OCPBUGS-99021](https://issues.redhat.com/browse/OCPBUGS-99021): Use separate certificate signers for konnectivity [#9098](https://github.com/openshift/hypershift/pull/9098)
* [OCPBUGS-99329](https://issues.redhat.com/browse/OCPBUGS-99329): avoid cache miss false-negative on credential Secret lookup [#9074](https://github.com/openshift/hypershift/pull/9074)
* NO-JIRA: group ChaiBot health report by OCP version [#9447](https://github.com/openshift/hypershift/pull/9447)
* NO-JIRA: Migrate hypershift-ci-python and contrib/oidc to uv for managing python deps [#9442](https://github.com/openshift/hypershift/pull/9442)
* [GCP-421](https://issues.redhat.com/browse/GCP-421): feat(install): bump external-dns to 1.3.5 and bundle DNSEndpoint CRD [#9433](https://github.com/openshift/hypershift/pull/9433)
* NO-JIRA: test(e2e/v2): add upsert desired-state-hash E2E tests [#9257](https://github.com/openshift/hypershift/pull/9257)
* [RFE-9138](https://issues.redhat.com/browse/RFE-9138): feat: label some hosted control plane services [#8298](https://github.com/openshift/hypershift/pull/8298)
* [OCPBUGS-109595](https://issues.redhat.com/browse/OCPBUGS-109595): use RetryWatcher and TCP keepalive for create-guests watch resilience [#9435](https://github.com/openshift/hypershift/pull/9435)
* [OCPBUGS-95614](https://issues.redhat.com/browse/OCPBUGS-95614): fix(cpo): include unavailable components in KASLoadBalancerNotReachable message [#9232](https://github.com/openshift/hypershift/pull/9232)
* [OCPBUGS-114014](https://issues.redhat.com/browse/OCPBUGS-114014): add Agent CAPI pause step to cross-cluster migration [#9416](https://github.com/openshift/hypershift/pull/9416)
* [CNTRLPLANE-4216](https://issues.redhat.com/browse/CNTRLPLANE-4216): Migrate Azure VM instance families to Dsv5 [#9423](https://github.com/openshift/hypershift/pull/9423)
* [CNTRLPLANE-4006](https://issues.redhat.com/browse/CNTRLPLANE-4006): fix(e2e) disable client-side rate limiting and increase NodePool config timeout [#9331](https://github.com/openshift/hypershift/pull/9331)
* [CNTRLPLANE-4004](https://issues.redhat.com/browse/CNTRLPLANE-4004): test(envtest): add CEL validation tests for AWS resource tag types [#9375](https://github.com/openshift/hypershift/pull/9375)
* [OCPBUGS-86669](https://issues.redhat.com/browse/OCPBUGS-86669): fix(cli): make deleteCLISecrets non-fatal during cluster destroy [#8787](https://github.com/openshift/hypershift/pull/8787)
* [CNTRLPLANE-3999](https://issues.redhat.com/browse/CNTRLPLANE-3999): add declarative TestPlan for composing v2 cluster variants and test matrices [#9420](https://github.com/openshift/hypershift/pull/9420)
* NO-JIRA: test(e2e): allow more time for control plane pod restarts [#9422](https://github.com/openshift/hypershift/pull/9422)
* [OCPBUGS-113580](https://issues.redhat.com/browse/OCPBUGS-113580): Bound NodePool metrics cache reads [#9389](https://github.com/openshift/hypershift/pull/9389)
* NO-JIRA: Makefile: fix PULL_BASE_SHA leading space breaking local verify [#9395](https://github.com/openshift/hypershift/pull/9395)
* [OCPBUGS-97811](https://issues.redhat.com/browse/OCPBUGS-97811): fix Tenant API downtime during a management worker node [#9279](https://github.com/openshift/hypershift/pull/9279)
* NO-JIRA: Run lint and vet against all build tags [#9427](https://github.com/openshift/hypershift/pull/9427)
* [OCPBUGS-114265](https://issues.redhat.com/browse/OCPBUGS-114265): Use managemet cluster kubeconfig for CAPI migration test [#9412](https://github.com/openshift/hypershift/pull/9412)
* [OCPBUGS-100142](https://issues.redhat.com/browse/OCPBUGS-100142): fix(konnectivity): fallback to alternative DNS-resolved IPs on connection failure [#9181](https://github.com/openshift/hypershift/pull/9181)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): migrate CPO status patches to statuspatching helpers [#8966](https://github.com/openshift/hypershift/pull/8966)
* [OCPSTRAT-3686](https://issues.redhat.com/browse/OCPSTRAT-3686): Add pipeline for nightly release tag process [#9371](https://github.com/openshift/hypershift/pull/9371)
* [OCPBUGS-111601](https://issues.redhat.com/browse/OCPBUGS-111601): Fix v2 control plane upgrade rollout race [#9384](https://github.com/openshift/hypershift/pull/9384)
* [CNTRLPLANE-2883](https://issues.redhat.com/browse/CNTRLPLANE-2883): Migrate ARM64 NodePool creation test to v2 [#8926](https://github.com/openshift/hypershift/pull/8926)
* [CNTRLPLANE-4115](https://issues.redhat.com/browse/CNTRLPLANE-4115): fix(ci): report actionable cause when /rebase push hits workflow files [#9358](https://github.com/openshift/hypershift/pull/9358)
* [OCPBUGS-113991](https://issues.redhat.com/browse/OCPBUGS-113991): Scope forced NodePool cleanup to the target cluster [#9398](https://github.com/openshift/hypershift/pull/9398)
* [CNTRLPLANE-1831](https://issues.redhat.com/browse/CNTRLPLANE-1831): address review feedback on DR documentation [#9407](https://github.com/openshift/hypershift/pull/9407)
* [OCPBUGS-98467](https://issues.redhat.com/browse/OCPBUGS-98467): fix(konnectivity): enable --sync-forever to restore lost agent-server tunnels [#9260](https://github.com/openshift/hypershift/pull/9260)
* [CNTRLPLANE-3616](https://issues.redhat.com/browse/CNTRLPLANE-3616): e2e tests for TLS profile change of konnectivity-server [#8886](https://github.com/openshift/hypershift/pull/8886)
* [CNTRLPLANE-3626](https://issues.redhat.com/browse/CNTRLPLANE-3626): feat(ignition-server, ignition-server-proxy): inject centralized TLS configuration [#8910](https://github.com/openshift/hypershift/pull/8910)
* [OCPBUGS-112450](https://issues.redhat.com/browse/OCPBUGS-112450): introduce e2e v2 linting rules and enforcement [#9357](https://github.com/openshift/hypershift/pull/9357)
* [CNTRLPLANE-1831](https://issues.redhat.com/browse/CNTRLPLANE-1831): restructure backup/restore disaster recovery documentation [#9382](https://github.com/openshift/hypershift/pull/9382)
* [ACM-42704](https://issues.redhat.com/browse/ACM-42704): Add Konflux MCE 5.1 pipelines for hypershift CLI and operator [#9396](https://github.com/openshift/hypershift/pull/9396)
* [OCPBUGS-111601](https://issues.redhat.com/browse/OCPBUGS-111601): Prevent conversion webhook startup deadlock [#9387](https://github.com/openshift/hypershift/pull/9387)
* [ROSAENG-14082](https://issues.redhat.com/browse/ROSAENG-14082): --dump-guest-cluster option can now optionally be supplied with policies [#8882](https://github.com/openshift/hypershift/pull/8882)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): port core karpenter autonode e2e tests to v2 framework [#9292](https://github.com/openshift/hypershift/pull/9292)
* [GCP-916](https://issues.redhat.com/browse/GCP-916): allow goog-partner-solution label key in GCP resourceLabels [#9267](https://github.com/openshift/hypershift/pull/9267)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default [#9328](https://github.com/openshift/hypershift/pull/9328)
* [CNTRLPLANE-3903](https://issues.redhat.com/browse/CNTRLPLANE-3903): Add unit test for hcp version command [#9218](https://github.com/openshift/hypershift/pull/9218)
* [OCPBUGS-111985](https://issues.redhat.com/browse/OCPBUGS-111985), [OCPBUGS-111986](https://issues.redhat.com/browse/OCPBUGS-111986): bump haproxy to 3.0.5-6.el10_2.2 to fix CVE-2026-55203 and CVE-2026-55204 [#9333](https://github.com/openshift/hypershift/pull/9333)
* [OCPBUGS-112328](https://issues.redhat.com/browse/OCPBUGS-112328): Clear SSHKey from HCP and delete synced secret when HC SSHKey is removed [#9374](https://github.com/openshift/hypershift/pull/9374)
* [CNTRLPLANE-4169](https://issues.redhat.com/browse/CNTRLPLANE-4169): Add GHA envtest jobs for Kubernetes 1.36 [#9353](https://github.com/openshift/hypershift/pull/9353)
* [CNTRLPLANE-3604](https://issues.redhat.com/browse/CNTRLPLANE-3604): Capi v1beta2 storage migration [#8938](https://github.com/openshift/hypershift/pull/8938)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): migrate HO karpenter status patch to statuspatching helper [#8968](https://github.com/openshift/hypershift/pull/8968)
* no-jira: add karpenter-operator dev image override annotation [#9295](https://github.com/openshift/hypershift/pull/9295)
* [CNTRLPLANE-4025](https://issues.redhat.com/browse/CNTRLPLANE-4025): feat(azure): support managed HSM for KMS encryption [#9199](https://github.com/openshift/hypershift/pull/9199)
* [OCPBUGS-44164](https://issues.redhat.com/browse/OCPBUGS-44164): Fix TestNodePoolReplaceUpgrade flaky timeout on OpenStack [#8749](https://github.com/openshift/hypershift/pull/8749)
* revert: OCPBUGS-112478: fix(cpo): handle service-ca generation errors in CSI serving cert reconciliation [#9365](https://github.com/openshift/hypershift/pull/9365)
* [CNTRLPLANE-3954](https://issues.redhat.com/browse/CNTRLPLANE-3954): add kube-scheduler metrics endpoint e2e coverage [#9159](https://github.com/openshift/hypershift/pull/9159)
* NO-JIRA: align aws_test.go test case names with testcasename linter [#9367](https://github.com/openshift/hypershift/pull/9367)
* [CNTRLPLANE-4003](https://issues.redhat.com/browse/CNTRLPLANE-4003): Add per-tag override field for AWS resource tag precedence [#9152](https://github.com/openshift/hypershift/pull/9152)
* [OCPBUGS-97705](https://issues.redhat.com/browse/OCPBUGS-97705): fix(azure): skip KMS validation for private Key Vaults on ARO HCP [#8965](https://github.com/openshift/hypershift/pull/8965)
* chore: add .pi symlink for Claude Code skill discovery [#9361](https://github.com/openshift/hypershift/pull/9361)
* [OCPBUGS-85182](https://issues.redhat.com/browse/OCPBUGS-85182): Remove MutatingAdmissionPolicy runtime-config from KAS [#9350](https://github.com/openshift/hypershift/pull/9350)
* [OCPBUGS-86771](https://issues.redhat.com/browse/OCPBUGS-86771): docs(api): document issuerURL immutability and serviceAccountIssuer override [#8916](https://github.com/openshift/hypershift/pull/8916)
* NO-JIRA: chore(owners): add members to core-reviewers [#9352](https://github.com/openshift/hypershift/pull/9352)
* [OCPBUGS-85065](https://issues.redhat.com/browse/OCPBUGS-85065): Fix repeated CPO Deployment churn due to OPENSHIFT_IMG_OVERRIDES reordering [#8656](https://github.com/openshift/hypershift/pull/8656)
* NO-JIRA: align GCP creds metric test case names with testcasename linter [#9351](https://github.com/openshift/hypershift/pull/9351)
* [GCP-959](https://issues.redhat.com/browse/GCP-959): Add GCP PSC conditions to metrics and add platform-specific gauges [#9258](https://github.com/openshift/hypershift/pull/9258)
* [CNTRLPLANE-3899](https://issues.redhat.com/browse/CNTRLPLANE-3899): Add shared cmd/ unit tests for create nodepool agent [#9162](https://github.com/openshift/hypershift/pull/9162)
* [CNTRLPLANE-4008](https://issues.redhat.com/browse/CNTRLPLANE-4008): enable hypershiftlinter and fix test naming [#9271](https://github.com/openshift/hypershift/pull/9271)
* [OCPBUGS-86670](https://issues.redhat.com/browse/OCPBUGS-86670): fix(cpo): handle service-ca generation errors in CSI serving cert reconciliation [#8622](https://github.com/openshift/hypershift/pull/8622)
* [OCPBUGS-105194](https://issues.redhat.com/browse/OCPBUGS-105194): Add retry with exponential back-off for transient dump errors [#9303](https://github.com/openshift/hypershift/pull/9303)
* [CNTRLPLANE-4041](https://issues.redhat.com/browse/CNTRLPLANE-4041): fix(build): bump missed second-stage base image in Dockerfile.e2e to 5.1 [#9345](https://github.com/openshift/hypershift/pull/9345)
* [CNTRLPLANE-4026](https://issues.redhat.com/browse/CNTRLPLANE-4026): fix(ci): Enable Dependabot to track and automate GHA runner image updates [#9330](https://github.com/openshift/hypershift/pull/9330)
* [CNTRLPLANE-4041](https://issues.redhat.com/browse/CNTRLPLANE-4041): bump base images in dockerfiles to 5.1 [#9325](https://github.com/openshift/hypershift/pull/9325)
* NO-JIRA: fix(ci): update restructure-commits workflow path after skills migration [#9335](https://github.com/openshift/hypershift/pull/9335)
* [CNTRLPLANE-4115](https://issues.redhat.com/browse/CNTRLPLANE-4115): Revert invalid workflows permission from rebase.yaml [#9329](https://github.com/openshift/hypershift/pull/9329)
* [OCPBUGS-99550](https://issues.redhat.com/browse/OCPBUGS-99550): Managed Azure setup_aks_cluster.sh fails to run with "--kubernetes-version 1.33.0" flag [#9080](https://github.com/openshift/hypershift/pull/9080)
* [OCPBUGS-105282](https://issues.redhat.com/browse/OCPBUGS-105282): Add proxy env vars to cluster-storage-operator deployment [#9256](https://github.com/openshift/hypershift/pull/9256)
* [CNTRLPLANE-4115](https://issues.redhat.com/browse/CNTRLPLANE-4115): Fix /rebase workflow: add missing workflows permission [#9323](https://github.com/openshift/hypershift/pull/9323)
* NO-JIRA: Convert Claude commands to agentskills.io skill format for harness portability [#9062](https://github.com/openshift/hypershift/pull/9062)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): add [FeatureGate:OSStreams] tag for FG promotion tracking [#9297](https://github.com/openshift/hypershift/pull/9297)
* [OCPBUGS-83564](https://issues.redhat.com/browse/OCPBUGS-83564): Apply registry overrides to release image pullspec before fetching [#9108](https://github.com/openshift/hypershift/pull/9108)
* [CNTRLPLANE-4008](https://issues.redhat.com/browse/CNTRLPLANE-4008): feat: add hypershiftlinter golangci-lint plugin [#9237](https://github.com/openshift/hypershift/pull/9237)
* [OCPBUGS-105875](https://issues.redhat.com/browse/OCPBUGS-105875): fix(hcco): run kas-connection-checker as non-root [#9296](https://github.com/openshift/hypershift/pull/9296)
* [ARO-26896](https://issues.redhat.com/browse/ARO-26896): feat: hardcode ETCD_METRICS=extensive in etcd StatefulSet template [#9192](https://github.com/openshift/hypershift/pull/9192)
* [OCPBUGS-105802](https://issues.redhat.com/browse/OCPBUGS-105802): Use the correct v1 mcfg api for OSImageStream during ignition [#9283](https://github.com/openshift/hypershift/pull/9283)
* [CNTRLPLANE-4043](https://issues.redhat.com/browse/CNTRLPLANE-4043): ci(e2e): add CI workflow to verify e2e compilation on PRs [#9305](https://github.com/openshift/hypershift/pull/9305)
* And 2 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/hypershift/compare/808f24aeb3b93ff4563f2e42c66c6cbf1d059ee6...2e7d902422a7dd111801a917ba75935b97dced71)
### [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/tree/d9ad359f7beec76743bd6f4559db26434211661e)
* [OCPBUGS-113538](https://issues.redhat.com/browse/OCPBUGS-113538): Enable SELinuxMount tests [#180](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/180)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/compare/be4fd01725ce5ab0b47f846c905a349aeee8ab53...d9ad359f7beec76743bd6f4559db26434211661e)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/edb8427aa57d4c223d1915ebd90d4034f8fb5f24)
* [OCPBUGS-114006](https://issues.redhat.com/browse/OCPBUGS-114006): UPSTREAM: 2933: Bump all go.opentelemetry.io/otel modules to v1.44.0 [#165](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/165)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/286dd2de7957e9c2897e152417f16907d324d819...edb8427aa57d4c223d1915ebd90d4034f8fb5f24)
### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/c2439897d64ade66b2159b48dc7ae68712b98400)
* [CNF-23394](https://issues.redhat.com/browse/CNF-23394): mockgen deprecated: use uber-go/mock instead [#73](https://github.com/openshift/machine-api-provider-ibmcloud/pull/73)
* [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/2615d13b730255b21ccb401d3dc039006c54a4fe...c2439897d64ade66b2159b48dc7ae68712b98400)
### [insights-operator](https://github.com/openshift/insights-operator/tree/8f15e3157ff09f54ab22801f5b21da35a195cc6d)
* [CCXDEV-16666](https://issues.redhat.com/browse/CCXDEV-16666): gather InferenceService from the KServe operator [#1345](https://github.com/openshift/insights-operator/pull/1345)
* [OCPBUGS-97968](https://issues.redhat.com/browse/OCPBUGS-97968): add insights-runtime-extractor-scc missing fields [#1359](https://github.com/openshift/insights-operator/pull/1359)
* [CCXDEV-16041](https://issues.redhat.com/browse/CCXDEV-16041): multiclusterhub gatherer [#1343](https://github.com/openshift/insights-operator/pull/1343)
* NO-JIRA: improve create-gatherer skill [#1348](https://github.com/openshift/insights-operator/pull/1348)
* [CCXDEV-16040](https://issues.redhat.com/browse/CCXDEV-16040): Add multicluster gatherer [#1337](https://github.com/openshift/insights-operator/pull/1337)
* [CCXDEV-16594](https://issues.redhat.com/browse/CCXDEV-16594): add custom proxy field to insights config [#1329](https://github.com/openshift/insights-operator/pull/1329)
* [Full changelog](https://github.com/openshift/insights-operator/compare/2f616dc436db2e35d70c9a049be98c185f684243...8f15e3157ff09f54ab22801f5b21da35a195cc6d)
### [insights-runtime-exporter, insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor/tree/ba3de3b9777161897b75fc5a88e179dfbe8f6c53)
* NO-JIRA: chore: add slashpai to owner list [#91](https://github.com/openshift/insights-runtime-extractor/pull/91)
* [Full changelog](https://github.com/openshift/insights-runtime-extractor/compare/7c9aa14915e639edd20bc0869747487e2e73fe51...ba3de3b9777161897b75fc5a88e179dfbe8f6c53)
### [ironic](https://github.com/openshift/ironic-image/tree/7259590df97ae85745c0bbebd4b8859c74b636e0)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#917](https://github.com/openshift/ironic-image/pull/917)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#910](https://github.com/openshift/ironic-image/pull/910)
* NO-ISSUE: Manually sync Ironic - part 2 [#909](https://github.com/openshift/ironic-image/pull/909)
* NO-ISSUE: Manually sync Ironic and Sushy from the forks [#906](https://github.com/openshift/ironic-image/pull/906)
* [METAL-1931](https://issues.redhat.com/browse/METAL-1931): Add cargo for bcrypt rust extensions [#895](https://github.com/openshift/ironic-image/pull/895)
* [Full changelog](https://github.com/openshift/ironic-image/compare/001adec7884e75a5078e4e72c8bc8d2a51376b43...7259590df97ae85745c0bbebd4b8859c74b636e0)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/4f03543ffd7a704225a3011ee93754354cdd6923)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#319](https://github.com/openshift/ironic-agent-image/pull/319)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#317](https://github.com/openshift/ironic-agent-image/pull/317)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#302](https://github.com/openshift/ironic-agent-image/pull/302)
* [METAL-1931](https://issues.redhat.com/browse/METAL-1931): Add cargo for bcrypt rust extensions [#303](https://github.com/openshift/ironic-agent-image/pull/303)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/601c9bf36bbc4a0796c4c55e59bfe3cc46252ed3...4f03543ffd7a704225a3011ee93754354cdd6923)
### [karpenter-operator](https://github.com/openshift/karpenter-operator/tree/69615069919bf76e68d485681f0fda1bbab4e1c0)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): Add minimum instance size requirements [#36](https://github.com/openshift/karpenter-operator/pull/36)
* NO-JIRA: fixup OWNERS_ALIASES [#35](https://github.com/openshift/karpenter-operator/pull/35)
* NO-JIRA: chore: update build tool versions [#34](https://github.com/openshift/karpenter-operator/pull/34)
* [AUTOSCALE-873](https://issues.redhat.com/browse/AUTOSCALE-873): fix: apply OpenShift Karpenter CRD adjustments [#33](https://github.com/openshift/karpenter-operator/pull/33)
* [AUTOSCALE-974](https://issues.redhat.com/browse/AUTOSCALE-974): deploy karpenter-provider-azure on HCP [#32](https://github.com/openshift/karpenter-operator/pull/32)
* [AUTOSCALE-946](https://issues.redhat.com/browse/AUTOSCALE-946): migrate approver for node CSRs [#29](https://github.com/openshift/karpenter-operator/pull/29)
* no-jira: remove aggregate cluster role [#30](https://github.com/openshift/karpenter-operator/pull/30)
* [AUTOSCALE-998](https://issues.redhat.com/browse/AUTOSCALE-998): deploy karpenter-provider-aws on HCP [#26](https://github.com/openshift/karpenter-operator/pull/26)
* [AUTOSCALE-968](https://issues.redhat.com/browse/AUTOSCALE-968): sync AKSNodeClass CRD and add Azure cloud provider [#28](https://github.com/openshift/karpenter-operator/pull/28)
* [AUTOSCALE-906](https://issues.redhat.com/browse/AUTOSCALE-906): add agentic SDLC context files [#27](https://github.com/openshift/karpenter-operator/pull/27)
* [AUTOSCALE-976](https://issues.redhat.com/browse/AUTOSCALE-976): enable CRD controller for management cluster mode [#24](https://github.com/openshift/karpenter-operator/pull/24)
* [AUTOSCALE-872](https://issues.redhat.com/browse/AUTOSCALE-872): Implement OpenshiftEC2NodeClass objects [#25](https://github.com/openshift/karpenter-operator/pull/25)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): Apply NodeOverlay to hostedcluster during karpenter-core e2e for AWS HCP AutoNode [#22](https://github.com/openshift/karpenter-operator/pull/22)
* [Full changelog](https://github.com/openshift/karpenter-operator/compare/56725605325c54693ebed5b0983d5d0478a87fca...69615069919bf76e68d485681f0fda1bbab4e1c0)
### [keepalived-ipfailover](https://github.com/openshift/images/tree/32930575a2bb3571601a7444becc06d06e901657)
* [NE-2126](https://issues.redhat.com/browse/NE-2126): Migrating Ipfailover test cases to images repo [#245](https://github.com/openshift/images/pull/245)
* [Full changelog](https://github.com/openshift/images/compare/3f1cf0830f196a6755b8baf179fc0401188251c4...32930575a2bb3571601a7444becc06d06e901657)
### [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy/tree/15f06dc655748d92897ba0d37cb8a0c40fb5d6fa)
* [CNTRLPLANE-3685](https://issues.redhat.com/browse/CNTRLPLANE-3685): docs - add Agentic SDLC context files [#144](https://github.com/openshift/kube-rbac-proxy/pull/144)
* NO-JIRA: update OWNERS [#147](https://github.com/openshift/kube-rbac-proxy/pull/147)
* NO-JIRA: Merge upstream v0.22.1 [#146](https://github.com/openshift/kube-rbac-proxy/pull/146)
* [Full changelog](https://github.com/openshift/kube-rbac-proxy/compare/43c114bc124f59e2fc3223dea8e0a8f4cdeed18d...15f06dc655748d92897ba0d37cb8a0c40fb5d6fa)
### [kube-state-metrics](https://github.com/openshift/kube-state-metrics/tree/4fcfe28da069857ca4afdcba3a7f167753f4ade8)
* NO-ISSUE: [bot] Bump openshift/kube-state-metrics to v2.20.0 [#155](https://github.com/openshift/kube-state-metrics/pull/155)
* [Full changelog](https://github.com/openshift/kube-state-metrics/compare/019ecc7d533333dfd3bf8893e78cd7ec6e282f01...4fcfe28da069857ca4afdcba3a7f167753f4ade8)
### [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator/tree/3f74baced64e1be5ec9ca16e3a682cd4eca67c06)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#262](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/262)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#259](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/259)
* [Full changelog](https://github.com/openshift/kubernetes-kube-storage-version-migrator/compare/72835e43c7754356645e41031f3a99926b4d42e6...3f74baced64e1be5ec9ca16e3a682cd4eca67c06)
### [kube-vip](https://github.com/openshift/kube-vip/tree/b272a7342833dad64574158101decb94ebe703d0)
* NO-JIRA: Merge https://github.com/kube-vip/kube-vip:main (https://github.com/openshift/kube-vip/commit/6cbf5aaeda356be0ee3fc5d8482d483c28bb4103) into main [#19](https://github.com/openshift/kube-vip/pull/19)
* [Full changelog](https://github.com/openshift/kube-vip/compare/1bb8a96eb31eaacc7cb49a9e8e397b66e62d87e9...b272a7342833dad64574158101decb94ebe703d0)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/26d7767bee99ff544430fd138571989f52d67c00)
* [OCPCLOUD-3438](https://issues.redhat.com/browse/OCPCLOUD-3438): Bump govmomi to 0.53.0 [#1498](https://github.com/openshift/machine-api-operator/pull/1498)
* NO-ISSUE: Add opt-in kube-rbac-proxy sidecar for pprof endpoint (AWS) [#1502](https://github.com/openshift/machine-api-operator/pull/1502)
* [OCPBUGS-47508](https://issues.redhat.com/browse/OCPBUGS-47508): Set --max-concurrent-reconciles=10 for AWS machine controller [#1521](https://github.com/openshift/machine-api-operator/pull/1521)
* [SPLAT-2825](https://issues.redhat.com/browse/SPLAT-2825): Moved OTE machine tests to openshift/disruptive-longrunning [#1539](https://github.com/openshift/machine-api-operator/pull/1539)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): refactor: remove AzureWorkloadIdentity feature gate [#1537](https://github.com/openshift/machine-api-operator/pull/1537)
* [SPLAT-2826](https://issues.redhat.com/browse/SPLAT-2826): Compare against oldObject in vSphere failure-domain VAPs [#1536](https://github.com/openshift/machine-api-operator/pull/1536)
* [OCPBUGS-74510](https://issues.redhat.com/browse/OCPBUGS-74510): Removed VSphereMultiDisk feature gate [#1532](https://github.com/openshift/machine-api-operator/pull/1532)
* [OCPBUGS-105407](https://issues.redhat.com/browse/OCPBUGS-105407): Remove VSphereMultiNetworks feature gate from e2e test [#1533](https://github.com/openshift/machine-api-operator/pull/1533)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/b3cabb0301b12a2b256bf8aed85c3f4c7b0dab3c...26d7767bee99ff544430fd138571989f52d67c00)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/86eb9d92e9cfc578224b86467ae45e86485a63b1)
* [OCPBUGS-63048](https://issues.redhat.com/browse/OCPBUGS-63048): Kube object asserts do not handle case where object is replaced [#6059](https://github.com/openshift/machine-config-operator/pull/6059)
* [OCPBUGS-100366](https://issues.redhat.com/browse/OCPBUGS-100366): Re-queue ContainerRuntimeConfig on status update failure [#6415](https://github.com/openshift/machine-config-operator/pull/6415)
* [OCPBUGS-90502](https://issues.redhat.com/browse/OCPBUGS-90502): Run nmstatectl format in nmstate-configuration [#6209](https://github.com/openshift/machine-config-operator/pull/6209)
* [OCPBUGS-115002](https://issues.redhat.com/browse/OCPBUGS-115002): Remove BootImageSkewEnforcement references to gate component from MCO [#6522](https://github.com/openshift/machine-config-operator/pull/6522)
* [OCPBUGS-114882](https://issues.redhat.com/browse/OCPBUGS-114882): drop GCD health-check ranges in openshift-gcp-routes [#6501](https://github.com/openshift/machine-config-operator/pull/6501)
* [OPNET-801](https://issues.redhat.com/browse/OPNET-801): Switch on-prem HAProxy pods to haproxy-router-haproxy32 image [#6502](https://github.com/openshift/machine-config-operator/pull/6502)
* [OCPBUGS-122237](https://issues.redhat.com/browse/OCPBUGS-122237): [TNF] Add infinite retry on untaint systemd unit [#6535](https://github.com/openshift/machine-config-operator/pull/6535)
* [OCPBUGS-116491](https://issues.redhat.com/browse/OCPBUGS-116491): Correctly handle MC deletion in image mode when no new build is required [#6528](https://github.com/openshift/machine-config-operator/pull/6528)
* [OCPBUGS-121353](https://issues.redhat.com/browse/OCPBUGS-121353): Pass missing proxy vars to bootstrap MCC [#6526](https://github.com/openshift/machine-config-operator/pull/6526)
* [MCO-2575](https://issues.redhat.com/browse/MCO-2575): Refactor verification functions for `calculateStatus` test cases [#6543](https://github.com/openshift/machine-config-operator/pull/6543)
* [MCO-2570](https://issues.redhat.com/browse/MCO-2570): remove poll methods [#6532](https://github.com/openshift/machine-config-operator/pull/6532)
* [OCPBUGS-114737](https://issues.redhat.com/browse/OCPBUGS-114737): updateLayeredOS deploy-from-self when skopeo < 1.22.2 [#6475](https://github.com/openshift/machine-config-operator/pull/6475)
* [OCPBUGS-122209](https://issues.redhat.com/browse/OCPBUGS-122209): Fix IsBootImageUpdateSupported to include vSphere and Azure platforms [#6523](https://github.com/openshift/machine-config-operator/pull/6523)
* [OCPBUGS-105283](https://issues.redhat.com/browse/OCPBUGS-105283): Mount /etc/container in mosb [#6451](https://github.com/openshift/machine-config-operator/pull/6451)
* [OCPBUGS-95238](https://issues.redhat.com/browse/OCPBUGS-95238): Dump compact cache to CM for persistence [#6379](https://github.com/openshift/machine-config-operator/pull/6379)
* [OCPBUGS-114664](https://issues.redhat.com/browse/OCPBUGS-114664): Fix CVE-2026-15792: Upgrade BuildKit to v0.31.2 [#6472](https://github.com/openshift/machine-config-operator/pull/6472)
* [OCPBUGS-120711](https://issues.redhat.com/browse/OCPBUGS-120711): Fix vsphere network absolute paths [#6497](https://github.com/openshift/machine-config-operator/pull/6497)
* [OCPBUGS-112721](https://issues.redhat.com/browse/OCPBUGS-112721): Retry on conflict in syncMachineConfigNodes [#6496](https://github.com/openshift/machine-config-operator/pull/6496)
* [OCPBUGS-116490](https://issues.redhat.com/browse/OCPBUGS-116490): remove nft chains before checking the ignition config [#6485](https://github.com/openshift/machine-config-operator/pull/6485)
* NO-ISSUE: check mosb failed message in test 85980 [#6500](https://github.com/openshift/machine-config-operator/pull/6500)
* [OCPBUGS-109657](https://issues.redhat.com/browse/OCPBUGS-109657): Assert errors in TestGetPrimaryPoolForNode [#6482](https://github.com/openshift/machine-config-operator/pull/6482)
* [OCPBUGS-115123](https://issues.redhat.com/browse/OCPBUGS-115123): Replace wildcard permissions with explicit verbs in MachineConfigServer ClusterRole [#6470](https://github.com/openshift/machine-config-operator/pull/6470)
* [OCPBUGS-112348](https://issues.redhat.com/browse/OCPBUGS-112348): Increase TC-74751 Eventually timeout for vSphere OVA upload [#6481](https://github.com/openshift/machine-config-operator/pull/6481)
* [OCPBUGS-115158](https://issues.redhat.com/browse/OCPBUGS-115158): Update AMI Whitelist [#6474](https://github.com/openshift/machine-config-operator/pull/6474)
* [OCPBUGS-115203](https://issues.redhat.com/browse/OCPBUGS-115203): Skip vsphere fd-unmatched machinesets for bootimage updates [#6477](https://github.com/openshift/machine-config-operator/pull/6477)
* [MCO-2530](https://issues.redhat.com/browse/MCO-2530): Remove unused functions, constants, parameters, and returns throughout the codebase [#6403](https://github.com/openshift/machine-config-operator/pull/6403)
* [MCO-2427](https://issues.redhat.com/browse/MCO-2427): Move OCB and OSStreams tests to longduration suite [#6454](https://github.com/openshift/machine-config-operator/pull/6454)
* [OCPBUGS-109659](https://issues.redhat.com/browse/OCPBUGS-109659): Check conddegraded nil before dereference in TestCalculateStatus [#6462](https://github.com/openshift/machine-config-operator/pull/6462)
* [OCPBUGS-69681](https://issues.redhat.com/browse/OCPBUGS-69681): limit ContainerRuntimeConfig status condition to 3 [#6434](https://github.com/openshift/machine-config-operator/pull/6434)
* [OCPBUGS-111648](https://issues.redhat.com/browse/OCPBUGS-111648): crio: drop restore support [#6412](https://github.com/openshift/machine-config-operator/pull/6412)
* [OCPBUGS-112043](https://issues.redhat.com/browse/OCPBUGS-112043): Preserve proxy environment vars [#6424](https://github.com/openshift/machine-config-operator/pull/6424)
* [OPNET-679](https://issues.redhat.com/browse/OPNET-679): grant NET_ADMIN capability to coredns-monitor [#6449](https://github.com/openshift/machine-config-operator/pull/6449)
* [OCPEDGE-2984](https://issues.redhat.com/browse/OCPEDGE-2984): fix: adjust fencing validator to match MAC-address based credential secrets [#6450](https://github.com/openshift/machine-config-operator/pull/6450)
* [OCPBUGS-112465](https://issues.redhat.com/browse/OCPBUGS-112465): Update the MachineOSBuild event and condition functionality to more clearly handle pod failures with retries [#6431](https://github.com/openshift/machine-config-operator/pull/6431)
* [OCPBUGS-112784](https://issues.redhat.com/browse/OCPBUGS-112784): Revert TNF Graceful node shutdown [#6442](https://github.com/openshift/machine-config-operator/pull/6442)
* [OCPBUGS-105399](https://issues.redhat.com/browse/OCPBUGS-105399): Remove SigstoreImageVerification feature gate references [#6445](https://github.com/openshift/machine-config-operator/pull/6445)
* [OCPBUGS-64623](https://issues.redhat.com/browse/OCPBUGS-64623): Use kubernetes scheme in drain controller event recorder [#6446](https://github.com/openshift/machine-config-operator/pull/6446)
* [OCPNODE-4526](https://issues.redhat.com/browse/OCPNODE-4526): Add '..' block, max-length, and cross-store uniqueness [#6433](https://github.com/openshift/machine-config-operator/pull/6433)
* [OCPBUGS-100065](https://issues.redhat.com/browse/OCPBUGS-100065): on-prem: tune API VIP haproxy health checks [#6400](https://github.com/openshift/machine-config-operator/pull/6400)
* [OCPBUGS-109746](https://issues.redhat.com/browse/OCPBUGS-109746): OCPBUGS-112085: CORS-4441: Bootimage controller should gracefully handle Azure gen1 image removal [#6404](https://github.com/openshift/machine-config-operator/pull/6404)
* NO-ISSUE: Extend timeout for waiting for `UpdatePrepared` MCN condition for SNO resiliency [#6428](https://github.com/openshift/machine-config-operator/pull/6428)
* [OCPBUGS-98258](https://issues.redhat.com/browse/OCPBUGS-98258): Fix upstreams for CoreDNS pods on Cloud platforms [#6383](https://github.com/openshift/machine-config-operator/pull/6383)
* NO-JIRA: Skip OVN-K VRFs in ofport-request dispatcher script [#6398](https://github.com/openshift/machine-config-operator/pull/6398)
* [OCPBUGS-109739](https://issues.redhat.com/browse/OCPBUGS-109739): Increase rpm-ostree rebase retry backoff and preserve error [#6413](https://github.com/openshift/machine-config-operator/pull/6413)
* [OCPBUGS-112075](https://issues.redhat.com/browse/OCPBUGS-112075): skip proxy for OSImageStream discovery in HyperShift [#6420](https://github.com/openshift/machine-config-operator/pull/6420)
* [OCPBUGS-65504](https://issues.redhat.com/browse/OCPBUGS-65504): machine-config ClusterOperator relatedObjects missing ClusterRoleBinding [#6369](https://github.com/openshift/machine-config-operator/pull/6369)
* [AGENT-1570](https://issues.redhat.com/browse/AGENT-1570): Remove all NoRegistryClusterInstall feature gate check [#6396](https://github.com/openshift/machine-config-operator/pull/6396)
* [MCO-2411](https://issues.redhat.com/browse/MCO-2411): Add AWS marketplace AMI band check target [#6365](https://github.com/openshift/machine-config-operator/pull/6365)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/966718a5dab28fc1594d233a1293f2edc56620c9...86eb9d92e9cfc578224b86467ae45e86485a63b1)
### [machine-image-customization-controller](https://github.com/openshift/image-customization-controller/tree/87f4774be1fc58b6b3868c57326a80f95bd81594)
* [OCPBUGS-112616](https://issues.redhat.com/browse/OCPBUGS-112616): Update xz and ignition/v2 with known vulnerabilities [#185](https://github.com/openshift/image-customization-controller/pull/185)
* [OCPBUGS-112617](https://issues.redhat.com/browse/OCPBUGS-112617): Stop accepting IRONIC_AGENT_PULL_SECRET from the envi… [#186](https://github.com/openshift/image-customization-controller/pull/186)
* [Full changelog](https://github.com/openshift/image-customization-controller/compare/e49b096880f17296d42a77443dc14d732683333d...87f4774be1fc58b6b3868c57326a80f95bd81594)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/2910fb3fef2f907bcb7863471240ba0289621ea6)
* [OCPBUGS-112613](https://issues.redhat.com/browse/OCPBUGS-112613): Validate aarch64 ISO checksum after cross-arch extraction [#113](https://github.com/openshift/machine-os-images/pull/113)
* [TRT-2935](https://issues.redhat.com/browse/TRT-2935): Revert machine-os-images PR #110 — fatal aarch64 ISO check crashes metal3 init-container [#112](https://github.com/openshift/machine-os-images/pull/112)
* [OKD-429](https://issues.redhat.com/browse/OKD-429): Fix OKD/SCOS builds to use centos CoreOS streams [#109](https://github.com/openshift/machine-os-images/pull/109)
* [OCPBUGS-112613](https://issues.redhat.com/browse/OCPBUGS-112613): Validate aarch64 ISO checksum after cross-arch extraction [#110](https://github.com/openshift/machine-os-images/pull/110)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/bf618aac93c71a56e8249669c579f0a782742e2e...2910fb3fef2f907bcb7863471240ba0289621ea6)
### [metallb-frr](https://github.com/openshift/frr/tree/4eebe4a1e50697ea070eec07c7ff022313ef3a8e)
* [OKD-453](https://issues.redhat.com/browse/OKD-453): Dockerfile.openshift: conditionally install frr or frr10 based on OS version [#137](https://github.com/openshift/frr/pull/137)
* [Full changelog](https://github.com/openshift/frr/compare/54a6ea48902d81460536b81ea6bdceb89c12e622...4eebe4a1e50697ea070eec07c7ff022313ef3a8e)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/b5465f7ec7b9a2139c0299f474779ccc3fd109de)
* NO-JIRA: sanitize runbook_url [#1255](https://github.com/openshift/monitoring-plugin/pull/1255)
* [OU-1150](https://issues.redhat.com/browse/OU-1150): more refactors [#1286](https://github.com/openshift/monitoring-plugin/pull/1286)
* NO-JIRA: duplicate dashboard creates perses project [#1258](https://github.com/openshift/monitoring-plugin/pull/1258)
* [OCPBUGS-123668](https://issues.redhat.com/browse/OCPBUGS-123668): patch adm-zip vulnerable version [#1274](https://github.com/openshift/monitoring-plugin/pull/1274)
* NO-JIRA: feat: migrate to vitest [#1237](https://github.com/openshift/monitoring-plugin/pull/1237)
* [OU-1220](https://issues.redhat.com/browse/OU-1220): Add column to display dashboard id in perses dashboard list page [#1257](https://github.com/openshift/monitoring-plugin/pull/1257)
* [OU-791](https://issues.redhat.com/browse/OU-791): hide Export as CSV link on empty Alerts page [#1251](https://github.com/openshift/monitoring-plugin/pull/1251)
* NO-JIRA: fix(metrics): sync query-browser URL into Redux after navigation [#1238](https://github.com/openshift/monitoring-plugin/pull/1238)
* [OU-1344](https://issues.redhat.com/browse/OU-1344): Add granular permission checks [#1185](https://github.com/openshift/monitoring-plugin/pull/1185)
* NO-JIRA: Pin node 22 and migrate deprecated i18next-parser [#1235](https://github.com/openshift/monitoring-plugin/pull/1235)
* NO-JIRA: use existing env var as a dashboard project in the OLS show time… [#1236](https://github.com/openshift/monitoring-plugin/pull/1236)
* [OU-1147](https://issues.redhat.com/browse/OU-1147): Perses UI Customization. Allow semantic tokens to map correctly with PatternFly themes and modes [#1226](https://github.com/openshift/monitoring-plugin/pull/1226)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): refactor variables [#1224](https://github.com/openshift/monitoring-plugin/pull/1224)
* [OCPBUGS-119714](https://issues.redhat.com/browse/OCPBUGS-119714), [OCPBUGS-119717](https://issues.redhat.com/browse/OCPBUGS-119717): fix: upgrade fast-uri to 3.1.7 [#1234](https://github.com/openshift/monitoring-plugin/pull/1234)
* [OCPBUGS-115456](https://issues.redhat.com/browse/OCPBUGS-115456): fix: upgrade vulnerable dependencies [#1233](https://github.com/openshift/monitoring-plugin/pull/1233)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): lint tags [#1221](https://github.com/openshift/monitoring-plugin/pull/1221)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): perses version upgrade fixes [#1228](https://github.com/openshift/monitoring-plugin/pull/1228)
* [OCPBUGS-114786](https://issues.redhat.com/browse/OCPBUGS-114786), [OCPBUGS-114789](https://issues.redhat.com/browse/OCPBUGS-114789), [OCPBUGS-114792](https://issues.redhat.com/browse/OCPBUGS-114792): fix: upgrade vulnerable fast-uri dependency [#1200](https://github.com/openshift/monitoring-plugin/pull/1200)
* NO-JIRA: Add dchromik to observability-ui aliases [#1230](https://github.com/openshift/monitoring-plugin/pull/1230)
* NO-JIRA: upgrade webpack [#1213](https://github.com/openshift/monitoring-plugin/pull/1213)
* [OCPBUGS-114776](https://issues.redhat.com/browse/OCPBUGS-114776), [OCPBUGS-114795](https://issues.redhat.com/browse/OCPBUGS-114795): fix: upgrade vulnerable dompurify dependency [#1199](https://github.com/openshift/monitoring-plugin/pull/1199)
* [OU-1423](https://issues.redhat.com/browse/OU-1423): fix: adjust perses mui theme to patternfly glass mode [#1195](https://github.com/openshift/monitoring-plugin/pull/1195)
* NO-JIRA: swap perses to ols specific tag for ols testing run [#1194](https://github.com/openshift/monitoring-plugin/pull/1194)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): include the legal disclaimer in the alert actions to agentic runs [#1188](https://github.com/openshift/monitoring-plugin/pull/1188)
* [OU-1417](https://issues.redhat.com/browse/OU-1417): Fix Perses tooltips background color in OCP 5 [#1178](https://github.com/openshift/monitoring-plugin/pull/1178)
* [OLS-3921](https://issues.redhat.com/browse/OLS-3921): disable button shrink [#1186](https://github.com/openshift/monitoring-plugin/pull/1186)
* [OU-1422](https://issues.redhat.com/browse/OU-1422): feat: update perses dependecies to allow to tag the OLS contributed panels [#1045](https://github.com/openshift/monitoring-plugin/pull/1045)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): rename tags to be the same as backend features [#1128](https://github.com/openshift/monitoring-plugin/pull/1128)
* [OU-1471](https://issues.redhat.com/browse/OU-1471): don't throw when listing globaldatasource for fallback [#1153](https://github.com/openshift/monitoring-plugin/pull/1153)
* [OU-1514](https://issues.redhat.com/browse/OU-1514): update useFeatures hook to feature driven backend [#1151](https://github.com/openshift/monitoring-plugin/pull/1151)
* NO-JIRA: chore: organize dev dependencies and avoid cypress binary install [#1148](https://github.com/openshift/monitoring-plugin/pull/1148)
* NO-JIRA: feat: replace outdated react-linkify dependency [#1144](https://github.com/openshift/monitoring-plugin/pull/1144)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): remove incidents feature from backend and tests [#1127](https://github.com/openshift/monitoring-plugin/pull/1127)
* [OU-1107](https://issues.redhat.com/browse/OU-1107), [OU-1108](https://issues.redhat.com/browse/OU-1108): ACM alerting UI with alerts and perses [#1105](https://github.com/openshift/monitoring-plugin/pull/1105)
* And 2 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/ead9ddbe0f08c13ba813004e31506de40586313e...b5465f7ec7b9a2139c0299f474779ccc3fd109de)
### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/5429edee2dc087ba0c4595c11bdd5f6d2e52436e)
* [CORENET-7375](https://issues.redhat.com/browse/CORENET-7375): d/s merge Bump Kubernetes to 1.36.2 and Go to 1.26 [#123](https://github.com/openshift/multus-admission-controller/pull/123)
* [OCPBUGS-112557](https://issues.redhat.com/browse/OCPBUGS-112557): Bump golang.org/x/net to 0.57.0 to fix CVE-2026-33814 [#125](https://github.com/openshift/multus-admission-controller/pull/125)
* [Full changelog](https://github.com/openshift/multus-admission-controller/compare/c0bdec9ce6a1a69985fdba5481c47fb34461eb6c...5429edee2dc087ba0c4595c11bdd5f6d2e52436e)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/f046826640baf19d335411b2116fe8d2124158d3)
* [OCPBUGS-114000](https://issues.redhat.com/browse/OCPBUGS-114000): DS Merge 08/27/2026 [#344](https://github.com/openshift/multus-cni/pull/344)
* [Full changelog](https://github.com/openshift/multus-cni/compare/8f597f4b90dffe1d1cb9aee558fe53a0046c9e35...f046826640baf19d335411b2116fe8d2124158d3)
### [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy/tree/39e9cccfa32951d0243c99638099da0a84d0d598)
* NO-JIRA: Downstream merge 20260826 [#120](https://github.com/openshift/multus-networkpolicy/pull/120)
* [Full changelog](https://github.com/openshift/multus-networkpolicy/compare/bfbac5025c056c4bf53aeeef50c4bcf466f5eb11...39e9cccfa32951d0243c99638099da0a84d0d598)
### [multus-route-override-cni](https://github.com/openshift/route-override-cni/tree/ce65e37e2571101213bb32643316812df311701b)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#66](https://github.com/openshift/route-override-cni/pull/66)
* [Full changelog](https://github.com/openshift/route-override-cni/compare/375ac966115fd03febd218a8331e8794560bd28e...ce65e37e2571101213bb32643316812df311701b)
### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/40982ea3951b3713e3bb3e1bb75657a325499c54)
* [OCPBUGS-112555](https://issues.redhat.com/browse/OCPBUGS-112555): Fix for CVE-2026-33814 [#418](https://github.com/openshift/whereabouts-cni/pull/418)
* [Full changelog](https://github.com/openshift/whereabouts-cni/compare/4b0c2166726247e36a0125432609844045e48dc3...40982ea3951b3713e3bb3e1bb75657a325499c54)
### [must-gather](https://github.com/openshift/must-gather/tree/521d3451f4918c2bd058bde62d642d9b227a5d65)
* [WINC-2092](https://issues.redhat.com/browse/WINC-2092): Add windows_exporter log collection [#560](https://github.com/openshift/must-gather/pull/560)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#563](https://github.com/openshift/must-gather/pull/563)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/must-gather/compare/6d934efb71dda67a5aec2adba14d75f4bd228fa0...521d3451f4918c2bd058bde62d642d9b227a5d65)
### [network-interface-bond-cni](https://github.com/openshift/bond-cni/tree/b8723844dc69940f55208cdb265653ab57f959f0)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#113](https://github.com/openshift/bond-cni/pull/113)
* [Full changelog](https://github.com/openshift/bond-cni/compare/2c395f566f259f1a1726409e2472029fa52918c9...b8723844dc69940f55208cdb265653ab57f959f0)
### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/e8830cdeabf085090c13ee68cd19a81ef6fd2adf)
* [CORENET-7238](https://issues.redhat.com/browse/CORENET-7238): Update OWNERS file [#145](https://github.com/openshift/network-metrics-daemon/pull/145)
* [OCPBUGS-112553](https://issues.redhat.com/browse/OCPBUGS-112553), [OCPBUGS-112568](https://issues.redhat.com/browse/OCPBUGS-112568): Fix CVE for ose-network-metrics-daemon [#147](https://github.com/openshift/network-metrics-daemon/pull/147)
* [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/20e6b987ea44e7cf0805662e8fec44d625b6f278...e8830cdeabf085090c13ee68cd19a81ef6fd2adf)
### [network-tools](https://github.com/openshift/network-tools/tree/03ae0e816cbf7608e6a326ac71a0a00619941e08)
* NO-JIRA: Added iperf3 [#189](https://github.com/openshift/network-tools/pull/189)
* [Full changelog](https://github.com/openshift/network-tools/compare/0b53ac3dccf59cd169555bf18c207122374bf003...03ae0e816cbf7608e6a326ac71a0a00619941e08)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/943fc215c1b8dfb4c5a8c5645dbe94cad6402126)
* [OCPNETUI-65](https://issues.redhat.com/browse/OCPNETUI-65): Enable dependabot updates on release-5.0 [#524](https://github.com/openshift/networking-console-plugin/pull/524)
* [OCPBUGS-86053](https://issues.redhat.com/browse/OCPBUGS-86053): Fix MultiNetworkPolicy list crash when spec is missing [#523](https://github.com/openshift/networking-console-plugin/pull/523)
* [OCPNETUI-78](https://issues.redhat.com/browse/OCPNETUI-78): Remove unused Dockerfile.art [#516](https://github.com/openshift/networking-console-plugin/pull/516)
* [OCPNETUI-63](https://issues.redhat.com/browse/OCPNETUI-63): Drop unused Helm charts [#473](https://github.com/openshift/networking-console-plugin/pull/473)
* [OCPNETUI-14](https://issues.redhat.com/browse/OCPNETUI-14): Add Cypress E2E tests for network-to-VM cross-navigation [#493](https://github.com/openshift/networking-console-plugin/pull/493)
* [OCPNETUI-65](https://issues.redhat.com/browse/OCPNETUI-65): Add multi-branch dependabot config [#487](https://github.com/openshift/networking-console-plugin/pull/487)
* [CNV-67257](https://issues.redhat.com/browse/CNV-67257): Set physicalNetworkName on OVN localnet NADs created from the console [#477](https://github.com/openshift/networking-console-plugin/pull/477)
* [OCPBUGS-105358](https://issues.redhat.com/browse/OCPBUGS-105358): Fix NAD config generated in form for OVN K8s secondary localnet networks [#496](https://github.com/openshift/networking-console-plugin/pull/496)
* [OCPNETUI-81](https://issues.redhat.com/browse/OCPNETUI-81): Retry fetching from npm registry to unblock OKD build [#494](https://github.com/openshift/networking-console-plugin/pull/494)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add CI scripts for hot-cluster E2E infrastructure [#489](https://github.com/openshift/networking-console-plugin/pull/489)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add ci-env-controller Helm chart for test environment lifecycle [#491](https://github.com/openshift/networking-console-plugin/pull/491)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add ci-test-stack Helm chart for E2E test environments [#490](https://github.com/openshift/networking-console-plugin/pull/490)
* [OCPNETUI-22](https://issues.redhat.com/browse/OCPNETUI-22): Add Cypress E2E tests for Service create and edit form [#480](https://github.com/openshift/networking-console-plugin/pull/480)
* [OCPNETUI-78](https://issues.redhat.com/browse/OCPNETUI-78): Sync Dockerfile and Dockerfile.art [#485](https://github.com/openshift/networking-console-plugin/pull/485)
* [OCPNETUI-59](https://issues.redhat.com/browse/OCPNETUI-59): Add Cypress E2E tests for Service and Route endpoint health [#481](https://github.com/openshift/networking-console-plugin/pull/481)
* [OCPNETUI-66](https://issues.redhat.com/browse/OCPNETUI-66): Drop unused devcontainer config [#474](https://github.com/openshift/networking-console-plugin/pull/474)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add Cypress test specs and runner scripts [#470](https://github.com/openshift/networking-console-plugin/pull/470)
* [OCPBUGS-113967](https://issues.redhat.com/browse/OCPBUGS-113967): Fix 404 error on MultiNetworkPolicy page when "All projects" is selected [#483](https://github.com/openshift/networking-console-plugin/pull/483)
* [OCPBUGS-91643](https://issues.redhat.com/browse/OCPBUGS-91643): Fixed IP sorting in service overview [#482](https://github.com/openshift/networking-console-plugin/pull/482)
* [OCPBUGS-112660](https://issues.redhat.com/browse/OCPBUGS-112660): Marked strings for i18n in NetworkPolicies list page [#478](https://github.com/openshift/networking-console-plugin/pull/478)
* [OCPBUGS-86249](https://issues.redhat.com/browse/OCPBUGS-86249): fixed edit pod selector [#476](https://github.com/openshift/networking-console-plugin/pull/476)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add Cypress E2E framework config and support files [#468](https://github.com/openshift/networking-console-plugin/pull/468)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add Cypress page objects and test constants [#469](https://github.com/openshift/networking-console-plugin/pull/469)
* chore(i18n): update Sprint 1 translations and Memsource CLI skill docs [#471](https://github.com/openshift/networking-console-plugin/pull/471)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/9673bbb20265696103dbe228a28ee601d0e43d77...943fc215c1b8dfb4c5a8c5645dbe94cad6402126)
### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/dd82b4a7e06ef4c0ad5abc2a7fbbb2882d765b41)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#228](https://github.com/openshift/oauth-apiserver/pull/228)
* [OCPBUGS-108041](https://issues.redhat.com/browse/OCPBUGS-108041): fix CVE-2026-41178 by bumping otel to v1.44.0 [#219](https://github.com/openshift/oauth-apiserver/pull/219)
* [CNTRLPLANE-2260](https://issues.redhat.com/browse/CNTRLPLANE-2260): test migration of tokenreview tests to OTE [#212](https://github.com/openshift/oauth-apiserver/pull/212)
* NO-JIRA: Remove cluster profile directory authentication as it is no longer injected in CI [#217](https://github.com/openshift/oauth-apiserver/pull/217)
* [Full changelog](https://github.com/openshift/oauth-apiserver/compare/a59e07d789b5a2531e94053cfe7c53edde90e931...dd82b4a7e06ef4c0ad5abc2a7fbbb2882d765b41)
### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/fa3b694f10331ec3ffd8c6c20b7933cb8ded0111)
* [ACM-37203](https://issues.redhat.com/browse/ACM-37203): Add support for configurable TLS profiles [#372](https://github.com/openshift/oauth-proxy/pull/372)
* [OCPBUGS-115305](https://issues.redhat.com/browse/OCPBUGS-115305): bugfix: rewrite open redirect strings to '/' [#374](https://github.com/openshift/oauth-proxy/pull/374)
* NO-JIRA: Add control-plane-approvers to OWNERS [#373](https://github.com/openshift/oauth-proxy/pull/373)
* [Full changelog](https://github.com/openshift/oauth-proxy/compare/310d2f7b90762b407d6100eb3940bd5b2f348108...fa3b694f10331ec3ffd8c6c20b7933cb8ded0111)
### [oauth-server](https://github.com/openshift/oauth-server/tree/5d2515f56de6fab67875c72bc98fad6a43100a16)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#260](https://github.com/openshift/oauth-server/pull/260)
* [OCPBUGS-115307](https://issues.redhat.com/browse/OCPBUGS-115307): bugfix: default to english when Accept-Language header contains more than 1000 underscores [#253](https://github.com/openshift/oauth-server/pull/253)
* [Full changelog](https://github.com/openshift/oauth-server/compare/6c2c889640ec53563021d0c0f09c4388cdcdb806...5d2515f56de6fab67875c72bc98fad6a43100a16)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/0c85f963ea84d2eba058c4217921ac51e9643093)
* NO-ISSUE: Synchronize From Upstream Repositories [#791](https://github.com/openshift/operator-framework-operator-controller/pull/791)
* [OCPBUGS-83515](https://issues.redhat.com/browse/OCPBUGS-83515): UPSTREAM: <carry>: use internal shell image for catalog FBC curl Job [#792](https://github.com/openshift/operator-framework-operator-controller/pull/792)
* NO-ISSUE: Synchronize From Upstream Repositories [#790](https://github.com/openshift/operator-framework-operator-controller/pull/790)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/49582d3d95fd5e5c8e2d232bf0d5568860514e5d...0c85f963ea84d2eba058c4217921ac51e9643093)
### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/5235418de7c86e6fae1004f84e55a2fbc1d3ac1c)
* [CNTRLPLANE-3878](https://issues.redhat.com/browse/CNTRLPLANE-3878): bump(k8s.io): 1.36.3 [#451](https://github.com/openshift/openshift-controller-manager/pull/451)
* [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/726a0562818b68faccfa130ae7ea17ff42915418...5235418de7c86e6fae1004f84e55a2fbc1d3ac1c)
### [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics/tree/5322ac5a46da4c11c310dc13ae41e6f80045379e)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#139](https://github.com/openshift/openshift-state-metrics/pull/139)
* [Full changelog](https://github.com/openshift/openshift-state-metrics/compare/3b4ea3e753d97fea66e0f52c8282a711358b4ff7...5322ac5a46da4c11c310dc13ae41e6f80045379e)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/eaa0992898ac0984f25d2fced6b69a1f8db54c7d)
* Fix release 0.14 sync: incomplete vendoring in hack/tools [#433](https://github.com/openshift/cluster-api-provider-openstack/pull/433)
* Fix rebasebot post-rebase hook helper path lookup [#432](https://github.com/openshift/cluster-api-provider-openstack/pull/432)
* Fix rebasebot merge-bot by removing stale API version artifacts [#431](https://github.com/openshift/cluster-api-provider-openstack/pull/431)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/9f64446f441ff7bcebd123a0dc35d4156c309681...eaa0992898ac0984f25d2fced6b69a1f8db54c7d)
### [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller/tree/642037113b21f8b553ae449ed79888afd46cd006)
* UPSTREAM-SYNC: Merge https://github.com/k-orc/openstack-resource-controller:release-2.0 into main [#40](https://github.com/openshift/openstack-resource-controller/pull/40)
* [Full changelog](https://github.com/openshift/openstack-resource-controller/compare/58dbc0482c144c21effee2476947889122a518eb...642037113b21f8b553ae449ed79888afd46cd006)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/031c587813b3542c17ec1e861ec3dc37dacccfec)
* [OCPBUGS-122255](https://issues.redhat.com/browse/OCPBUGS-122255): tests-extension: fix PolarionID:68521 and Polarion:27680 [#1376](https://github.com/openshift/operator-framework-olm/pull/1376)
* [OCPBUGS-83412](https://issues.redhat.com/browse/OCPBUGS-83412): set catalogsource spec.grpcpodconfig.scc: restricted for all non-legacy cases [#1359](https://github.com/openshift/operator-framework-olm/pull/1359)
* [OCPBUGS-104542](https://issues.redhat.com/browse/OCPBUGS-104542): force node arch for opm and catalogsource pod for multiarch tests; fix test failure [#1357](https://github.com/openshift/operator-framework-olm/pull/1357)
* [OCPBUGS-23954](https://issues.redhat.com/browse/OCPBUGS-23954), [OCPBUGS-78095](https://issues.redhat.com/browse/OCPBUGS-78095): Synchronize From Upstream Repositories [#1355](https://github.com/openshift/operator-framework-olm/pull/1355)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/c3d56d2021bbb8d57bc359fabded3b35b253f55e...031c587813b3542c17ec1e861ec3dc37dacccfec)
### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/6f413fbbfad17b2cfdf94d9f5b6f34da5028a763)
* NO-ISSUE: Bump github.com/onsi/ginkgo/v2 from 2.32.1 to 2.32.2 [#794](https://github.com/operator-framework/operator-marketplace/pull/794)
* NO-ISSUE: Bump github.com/onsi/gomega from 1.42.1 to 1.43.0 [#781](https://github.com/operator-framework/operator-marketplace/pull/781)
* NO-ISSUE: Bump github.com/sirupsen/logrus from 1.10.1 to 1.10.2 [#779](https://github.com/operator-framework/operator-marketplace/pull/779)
* NO-ISSUE: Bump github.com/stretchr/testify from 1.12.0 to 1.12.1 [#777](https://github.com/operator-framework/operator-marketplace/pull/777)
* NO-ISSUE: Bump the k8s-dependencies group across 1 directory with 3 updates [#776](https://github.com/operator-framework/operator-marketplace/pull/776)
* NO-ISSUE: Bump github.com/sirupsen/logrus from 1.10.0 to 1.10.1 [#778](https://github.com/operator-framework/operator-marketplace/pull/778)
* NO-ISSUE: Bump github.com/sirupsen/logrus from 1.9.4 to 1.10.0 [#774](https://github.com/operator-framework/operator-marketplace/pull/774)
* NO-ISSUE: Bump github.com/onsi/ginkgo/v2 from 2.32.0 to 2.32.1 [#773](https://github.com/operator-framework/operator-marketplace/pull/773)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/fa9e19b2ae7ad8de20b345e3bd736923f5c516cc...6f413fbbfad17b2cfdf94d9f5b6f34da5028a763)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/dc48a3f1faa7ad835c3e412611452d2385f0dd90)
* [CORENET-7562](https://issues.redhat.com/browse/CORENET-7562), [OCPBUGS-98726](https://issues.redhat.com/browse/OCPBUGS-98726), [OCPBUGS-99645](https://issues.redhat.com/browse/OCPBUGS-99645): DownStream Merge [09-11-2026] [#3439](https://github.com/openshift/ovn-kubernetes/pull/3439)
* [OCPBUGS-112563](https://issues.redhat.com/browse/OCPBUGS-112563), [OCPBUGS-99451](https://issues.redhat.com/browse/OCPBUGS-99451): DownStream Merge [08-31-2026] [#3434](https://github.com/openshift/ovn-kubernetes/pull/3434)
* [CORENET-7467](https://issues.redhat.com/browse/CORENET-7467): run OTE tests only in ovn-kubernetes conformance suites [#3416](https://github.com/openshift/ovn-kubernetes/pull/3416)
* [OCPBUGS-112470](https://issues.redhat.com/browse/OCPBUGS-112470): Register test images using tests extension [#3363](https://github.com/openshift/ovn-kubernetes/pull/3363)
* NO-JIRA: DownStream Merge [08-17-2026] [#3402](https://github.com/openshift/ovn-kubernetes/pull/3402)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/7b4de5ed3bd4381e3a17cdfddbe14be1432b9860...dc48a3f1faa7ad835c3e412611452d2385f0dd90)
### [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver/tree/cfe345c7dd6e7f817927847690658b199c3d1653)
* [MULTIARCH-6346](https://issues.redhat.com/browse/MULTIARCH-6346): Rebase with upstream - go modules updates and code changes [#138](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/138)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver/compare/5911994c5d70906e0f0972411176392ada9942d1...cfe345c7dd6e7f817927847690658b199c3d1653)
### [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs/tree/f89ff660316e922f2f232379c3a03d8ad8d54a30)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#109](https://github.com/openshift/cloud-provider-powervs/pull/109)
* No-Jira: Update packages in go.mod [#108](https://github.com/openshift/cloud-provider-powervs/pull/108)
* [Full changelog](https://github.com/openshift/cloud-provider-powervs/compare/18eb5238fb2c86632edb24175f536d815f28ddf6...f89ff660316e922f2f232379c3a03d8ad8d54a30)
### [prom-label-proxy](https://github.com/openshift/prom-label-proxy/tree/23e6f4a0c6b58930e7509fd063d7924025a69594)
* NO-ISSUE: [bot] Bump openshift/prom-label-proxy to v0.15.1 [#399](https://github.com/openshift/prom-label-proxy/pull/399)
* [Full changelog](https://github.com/openshift/prom-label-proxy/compare/4ab9ff73c665319352288fe0b9b9e1df71832525...23e6f4a0c6b58930e7509fd063d7924025a69594)
### [prometheus](https://github.com/openshift/prometheus/tree/c2c48fe1a4c9d2c0b6bc9f1fa9a41d669eac35f4)
* NO-JIRA: [bot] Bump openshift/prometheus to v3.14.0 [#363](https://github.com/openshift/prometheus/pull/363)
* NO-ISSUE: [bot] Bump openshift/prometheus to v3.14.0 [#361](https://github.com/openshift/prometheus/pull/361)
* [Full changelog](https://github.com/openshift/prometheus/compare/01d8335673aa6f88f5742ef510e133efee88a7bf...c2c48fe1a4c9d2c0b6bc9f1fa9a41d669eac35f4)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/6636dd048c835df8496f7e8fc878a0983bce0d9f)
* Bump openshift/prometheus-alertmanager to v0.34.1 [#177](https://github.com/openshift/prometheus-alertmanager/pull/177)
* Bump openshift/prometheus-alertmanager to v0.34.0 [#168](https://github.com/openshift/prometheus-alertmanager/pull/168)
* NO-ISSUE: Remove unused upstream .github/workflows [#167](https://github.com/openshift/prometheus-alertmanager/pull/167)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce...6636dd048c835df8496f7e8fc878a0983bce0d9f)
### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/64fea598a4ac46a0976ecb75bfe5dbef01416630)
* [MON-4689](https://issues.redhat.com/browse/MON-4689): Bump openshift/prometheus-operator to v0.94.0 [#400](https://github.com/openshift/prometheus-operator/pull/400)
* NO-ISSUE: [bot] Bump openshift/prometheus-operator to v0.93.1 [#393](https://github.com/openshift/prometheus-operator/pull/393)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/67895c7c968f42e97efec58f4140fffae4832028...64fea598a4ac46a0976ecb75bfe5dbef01416630)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/df6c312185d3c8f2fbd7f6f66dc410165bb65682)
* NO-ISSUE: [bot] Bump openshift/node_exporter to v1.12.1 [#186](https://github.com/openshift/node_exporter/pull/186)
* [OCPBUGS-100376](https://issues.redhat.com/browse/OCPBUGS-100376): cherry-pick 24c6dce279c418bcb911824e8c8be1c81a1e832b - Fix fibrechannel_linux for ppc64le (#3769) [#184](https://github.com/openshift/node_exporter/pull/184)
* [Full changelog](https://github.com/openshift/node_exporter/compare/b8af472104ce559c8fb9bf31fd4fc38bdbdc34e7...df6c312185d3c8f2fbd7f6f66dc410165bb65682)
### [rhel-coreos, rhel-coreos-10, rhel-coreos-10-extensions, rhel-coreos-extensions](https://github.com/openshift/os/tree/7324ccd30e5b2b3146639cb610bfe92c743c91a1)
* [OCPBUGS-115309](https://issues.redhat.com/browse/OCPBUGS-115309): Re-enable sandboxed-containers extension for 5.0 [#1965](https://github.com/openshift/os/pull/1965)
* [Full changelog](https://github.com/openshift/os/compare/d2f3751e77c4b79b1553d18758c2ea91f06f51fc...7324ccd30e5b2b3146639cb610bfe92c743c91a1)
### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/a158fff7ce3826058bd2d7338b206cdd600d0d40)
* [OCPBUGS-104856](https://issues.redhat.com/browse/OCPBUGS-104856): clear unmanaged-route metric when the route is removed [#102](https://github.com/openshift/route-controller-manager/pull/102)
* [Full changelog](https://github.com/openshift/route-controller-manager/compare/59697cf7af4517dd44e28179a57f7f35b6ea0e22...a158fff7ce3826058bd2d7338b206cdd600d0d40)
### [telemeter](https://github.com/openshift/telemeter/tree/562e12c31ded836d7891a3b3138ad604070b9c5a)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#615](https://github.com/openshift/telemeter/pull/615)
* [OCPBUGS-115550](https://issues.redhat.com/browse/OCPBUGS-115550): Add 'agent-installer-postconfig' install_type [#616](https://github.com/openshift/telemeter/pull/616)
* [BIZ-794](https://issues.redhat.com/browse/BIZ-794): separte managed and self-managed ACM capacity [#612](https://github.com/openshift/telemeter/pull/612)
* [Full changelog](https://github.com/openshift/telemeter/compare/22ba1701333f3fd26490cc15b89ddf21df3f67f6...562e12c31ded836d7891a3b3138ad604070b9c5a)
### [tests](https://github.com/openshift/origin/tree/3c85f767a0988a90bba4cc7ebaff609331c4c7ea)
* [OCPBUGS-112722](https://issues.redhat.com/browse/OCPBUGS-112722): make webhook build resolution wait phase-independent [#31655](https://github.com/openshift/origin/pull/31655)
* [OCPBUGS-121385](https://issues.redhat.com/browse/OCPBUGS-121385): Resolve Additional Storage agnhost image through mirror [#31618](https://github.com/openshift/origin/pull/31618)
* [NE-2750](https://issues.redhat.com/browse/NE-2750): implement feature test for GatewayAPIManagementMode [#31503](https://github.com/openshift/origin/pull/31503)
* [OCPEDGE-3076](https://issues.redhat.com/browse/OCPEDGE-3076): Fix TNF kubelet disruption test race condition [#31650](https://github.com/openshift/origin/pull/31650)
* [OCPSTRAT-3661](https://issues.redhat.com/browse/OCPSTRAT-3661): Always emit passing cases for found issues in RBAC monitor test [#31639](https://github.com/openshift/origin/pull/31639)
* NO-ISSUE: Automated - Update synthetic test data [#31607](https://github.com/openshift/origin/pull/31607)
* NO-JIRA: Add a new test for mass DNS disruption [#31625](https://github.com/openshift/origin/pull/31625)
* [OCPBUGS-114022](https://issues.redhat.com/browse/OCPBUGS-114022): Avoid polling skipped Prometheus target namespaces [#31563](https://github.com/openshift/origin/pull/31563)
* [TRT-2830](https://issues.redhat.com/browse/TRT-2830): add REVIEW.md for agentic review responses [#31637](https://github.com/openshift/origin/pull/31637)
* [OCPSTRAT-3661](https://issues.redhat.com/browse/OCPSTRAT-3661): Add Sippy discovered exceptions for RBAC monitor test [#31616](https://github.com/openshift/origin/pull/31616)
* [OCPBUGS-104846](https://issues.redhat.com/browse/OCPBUGS-104846): Filter both [FeatureGate:] and [OCPFeatureGate:] [#31623](https://github.com/openshift/origin/pull/31623)
* [OCPBUGS-121384](https://issues.redhat.com/browse/OCPBUGS-121384): Isolate KubeletEnsureSecretPulledImages test setup [#31619](https://github.com/openshift/origin/pull/31619)
* [OKD-454](https://issues.redhat.com/browse/OKD-454): Skip OKD job name check for cluster-bot launch jobs [#31628](https://github.com/openshift/origin/pull/31628)
* [OCPBUGS-92837](https://issues.redhat.com/browse/OCPBUGS-92837): test/router: wait for all per-route metrics before asserting [#31344](https://github.com/openshift/origin/pull/31344)
* [CORENET-6746](https://issues.redhat.com/browse/CORENET-6746): Allow EgressIP NoMatchingNodeFound events to repeat pathologically [#31614](https://github.com/openshift/origin/pull/31614)
* [OCPBUGS-86789](https://issues.redhat.com/browse/OCPBUGS-86789): Bump network config timeout to 25 minutes [#31599](https://github.com/openshift/origin/pull/31599)
* [CNTRLPLANE-3789](https://issues.redhat.com/browse/CNTRLPLANE-3789): Add e2e tests for authentication component proxy [#31446](https://github.com/openshift/origin/pull/31446)
* [OCPBUGS-84250](https://issues.redhat.com/browse/OCPBUGS-84250): Increase router verbosity in DCM tests [#31555](https://github.com/openshift/origin/pull/31555)
* NO-JIRA: test: poll final EgressFirewall DNS deny assertion [#31473](https://github.com/openshift/origin/pull/31473)
* [OCPBUGS-66213](https://issues.redhat.com/browse/OCPBUGS-66213): add link to jira card [#31609](https://github.com/openshift/origin/pull/31609)
* [NE-2839](https://issues.redhat.com/browse/NE-2839): Add HAProxy version upgrade tests [#31602](https://github.com/openshift/origin/pull/31602)
* [CORENET-7243](https://issues.redhat.com/browse/CORENET-7243): Add TLS Profile Compliance tests for networking components [#31500](https://github.com/openshift/origin/pull/31500)
* [OCPSTRAT-3618](https://issues.redhat.com/browse/OCPSTRAT-3618): Fix check in auth test for 1.37 given new NamedAuthorizer behavior [#31574](https://github.com/openshift/origin/pull/31574)
* [OCPSTRAT-3618](https://issues.redhat.com/browse/OCPSTRAT-3618): Update etcd test data for k8s 1.37 release [#31605](https://github.com/openshift/origin/pull/31605)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Register cluster-baremetal-tests-ext in extension registry [#31197](https://github.com/openshift/origin/pull/31197)
* [OCPSTRAT-3661](https://issues.redhat.com/browse/OCPSTRAT-3661): Add monitortest to verify possible Cluster Admin escalation paths [#31536](https://github.com/openshift/origin/pull/31536)
* [OCPBUGS-66213](https://issues.redhat.com/browse/OCPBUGS-66213): image registry single replica exceptions [#31544](https://github.com/openshift/origin/pull/31544)
* [OCPBUGS-111997](https://issues.redhat.com/browse/OCPBUGS-111997): Add Degraded=True exception for authentication operator during upgrade [#31535](https://github.com/openshift/origin/pull/31535)
* [TRT-2939](https://issues.redhat.com/browse/TRT-2939): Revert "Merge pull request #31495 from jcmoraisjr/NE-2839-haproxy-version-upgrade-tests" [#31598](https://github.com/openshift/origin/pull/31598)
* [OCPBUGS-77283](https://issues.redhat.com/browse/OCPBUGS-77283): bump kubevirt fedora containerDisk to multi-arch v1.8.2 + permanent exception [#31284](https://github.com/openshift/origin/pull/31284)
* [OCPBUGS-112662](https://issues.redhat.com/browse/OCPBUGS-112662): Fix the number of requests in repeated exec [#31548](https://github.com/openshift/origin/pull/31548)
* [OCPBUGS-115153](https://issues.redhat.com/browse/OCPBUGS-115153): Make extension test-binary extraction architecture-aware [#31579](https://github.com/openshift/origin/pull/31579)
* NO-ISSUE: Automated - Update synthetic test data [#31581](https://github.com/openshift/origin/pull/31581)
* [NE-2839](https://issues.redhat.com/browse/NE-2839): Add HAProxy version upgrade tests [#31495](https://github.com/openshift/origin/pull/31495)
* [OCPBUGS-111643](https://issues.redhat.com/browse/OCPBUGS-111643): Fixed Flakiness of Webhook test - ClusterResourceQuota validation [#31531](https://github.com/openshift/origin/pull/31531)
* [OCPNODE-4470](https://issues.redhat.com/browse/OCPNODE-4470): Add DRA consumable capacity e2e tests [#31448](https://github.com/openshift/origin/pull/31448)
* [OCPBUGS-112390](https://issues.redhat.com/browse/OCPBUGS-112390): Fix node replacement test timestamp filter and allow job retry [#31492](https://github.com/openshift/origin/pull/31492)
* [TRT-2930](https://issues.redhat.com/browse/TRT-2930): skip regional-PD e2e on GCP families without pd-standard [#31572](https://github.com/openshift/origin/pull/31572)
* [ROSAENG-391](https://issues.redhat.com/browse/ROSAENG-391): Add CustomResourcePublishOpenAPI conformance test to retry allowlist [#31552](https://github.com/openshift/origin/pull/31552)
* [OCPBUGS-114341](https://issues.redhat.com/browse/OCPBUGS-114341): Allow KubeDaemonSetRolloutStuck alert on external platform clusters [#31564](https://github.com/openshift/origin/pull/31564)
* [OCPBUGS-111581](https://issues.redhat.com/browse/OCPBUGS-111581): Fix probe termination test to use pod status instead of kubelet event text [#31528](https://github.com/openshift/origin/pull/31528)
* [OCPBUGS-112283](https://issues.redhat.com/browse/OCPBUGS-112283): Allow KubeDaemonSetMisScheduled alert on external platform clusters [#31556](https://github.com/openshift/origin/pull/31556)
* [OCPBUGS-99536](https://issues.redhat.com/browse/OCPBUGS-99536): Raise status polling timeout and write bound [#31534](https://github.com/openshift/origin/pull/31534)
* [OCPBUGS-86257](https://issues.redhat.com/browse/OCPBUGS-86257): Fix pathological events [#31543](https://github.com/openshift/origin/pull/31543)
* [OCPBUGS-105399](https://issues.redhat.com/browse/OCPBUGS-105399), [OCPBUGS-105400](https://issues.redhat.com/browse/OCPBUGS-105400): Remove TechPreview skips and event matchers from sigstore imagepolicy tests [#31521](https://github.com/openshift/origin/pull/31521)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): e2e TLS test for service-operator-ca [#31480](https://github.com/openshift/origin/pull/31480)
* [OCPBUGS-112470](https://issues.redhat.com/browse/OCPBUGS-112470): fix duplicate destination tags in openshift-tests images output [#31542](https://github.com/openshift/origin/pull/31542)
* [OCPBUGS-84517](https://issues.redhat.com/browse/OCPBUGS-84517): Remove stale openshift-marketplace terminationMessagePolicy exemption [#31355](https://github.com/openshift/origin/pull/31355)
* [CONSOLE-5188](https://issues.redhat.com/browse/CONSOLE-5188): remove console exceptions [#31280](https://github.com/openshift/origin/pull/31280)
* [OCPBUGS-100298](https://issues.redhat.com/browse/OCPBUGS-100298): pin internal-lb-monitor pollers to worker nodes [#31466](https://github.com/openshift/origin/pull/31466)
* [OCPBUGS-84513](https://issues.redhat.com/browse/OCPBUGS-84513): remove openshift-cluster-version terminationMessagePolicy exemption [#31359](https://github.com/openshift/origin/pull/31359)
* [OCPBUGS-105461](https://issues.redhat.com/browse/OCPBUGS-105461): allow baremetal to progress while MCO does [#31511](https://github.com/openshift/origin/pull/31511)
* [OCPBUGS-105874](https://issues.redhat.com/browse/OCPBUGS-105874): Avoid TLS port-forward to stale endpoints on degraded TNF clusters. [#31502](https://github.com/openshift/origin/pull/31502)
* [OCPBUGS-111704](https://issues.redhat.com/browse/OCPBUGS-111704): router/metrics: enable proxy protocol for client on AWS clusters [#31526](https://github.com/openshift/origin/pull/31526)
* [OCPBUGS-109671](https://issues.redhat.com/browse/OCPBUGS-109671): monitortests: allow image-registry node-ca Progressing on DualReplica [#31517](https://github.com/openshift/origin/pull/31517)
* [CNTRLPLANE-1739](https://issues.redhat.com/browse/CNTRLPLANE-1739): e2e additional tests for pki config [#31491](https://github.com/openshift/origin/pull/31491)
* [OCPBUGS-104561](https://issues.redhat.com/browse/OCPBUGS-104561): test: exclude NTO debug pods from best-effort QoS invariant [#31472](https://github.com/openshift/origin/pull/31472)
* [OCPBUGS-105876](https://issues.redhat.com/browse/OCPBUGS-105876): tolerate brief olm Available=False during upgrades [#31518](https://github.com/openshift/origin/pull/31518)
* NO-JIRA: Remove exception OCPBUGS-66225 [#31471](https://github.com/openshift/origin/pull/31471)
* NO-JIRA: Remove exception OCPBUGS-86009 [#31470](https://github.com/openshift/origin/pull/31470)
* [OCPCLOUD-3420](https://issues.redhat.com/browse/OCPCLOUD-3420): Remove exceptions OCPBUGS-42837 and OCPBUGS-64852 [#31469](https://github.com/openshift/origin/pull/31469)
* [MON-4471](https://issues.redhat.com/browse/MON-4471): test/extended/prometheus: move alert tests to "Test Framework" [#30703](https://github.com/openshift/origin/pull/30703)
* [OCPBUGS-106190](https://issues.redhat.com/browse/OCPBUGS-106190): Make oc rsh test resilient [#31515](https://github.com/openshift/origin/pull/31515)
* [TRT-2898](https://issues.redhat.com/browse/TRT-2898): Fix leaked ClusterRoleBinding in pull_secrets test [#31514](https://github.com/openshift/origin/pull/31514)
* And 2 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/origin/compare/d829b900b99e4d9afc163b14be91a385ed7ea705...3c85f767a0988a90bba4cc7ebaff609331c4c7ea)
### [thanos](https://github.com/openshift/thanos/tree/6caa7c9cad471582053356a0854cc86b152546fb)
* [OCPBUGS-120744](https://issues.redhat.com/browse/OCPBUGS-120744): bump go.opentelemetry.io/otel to fix CVE-2026-41178 [#204](https://github.com/openshift/thanos/pull/204)
* [Full changelog](https://github.com/openshift/thanos/compare/2a09eb84b92ccd71d5f1f11e0dda6d5aa9624e19...6caa7c9cad471582053356a0854cc86b152546fb)
### [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator/tree/845636b46d1c4fb1f30fcf5332276573aafeee19)
* [OCPBUGS-127004](https://issues.redhat.com/browse/OCPBUGS-127004): Bump golang.org/x/net to version 0.57.0 that fixes CVE-2026-33814 [#17](https://github.com/openshift/volume-data-source-validator/pull/17)
* [Full changelog](https://github.com/openshift/volume-data-source-validator/compare/ee9cd7aba4e096a9a957386ef20777e8950df352...845636b46d1c4fb1f30fcf5332276573aafeee19)
### [vsphere-csi-driver, vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver/tree/95294a0fad39bfedf30836e43250e999695ca726)
* [OCPBUGS-122179](https://issues.redhat.com/browse/OCPBUGS-122179): Fix credential exposure in logs (CWE-532) [#199](https://github.com/openshift/vmware-vsphere-csi-driver/pull/199)
* [OCPBUGS-114884](https://issues.redhat.com/browse/OCPBUGS-114884): UPSTREAM: 4272: Fix crash in syncer when node can't be found [#201](https://github.com/openshift/vmware-vsphere-csi-driver/pull/201)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver/compare/6b18bb29fc45383c21aa6c7513d151e443aa305e...95294a0fad39bfedf30836e43250e999695ca726)