NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #3105 by repository stars
Last release 3 days ago
05 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
491 releases · first in 2020
One column per quarter.
docker.io/fluxcd/source-controller:v1.9.6
docker.io/fluxcd/source-controller:v1.9.6ghcr.io/fluxcd/source-controller:v1.9.6Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-10-01
This patch release normalizes Azure Blob listing ETags so that the listing digest stays consistent with the stored artifact revision and unchanged containers are no longer re-downloaded on every reconcile, and evicts stale Helm repository index entries from the cache so that repositories with frequently changing indexes no longer fail with "Cache is full".
Fixes:
Improvements:
docker.io/fluxcd/source-controller:v1.9.5
docker.io/fluxcd/source-controller:v1.9.5ghcr.io/fluxcd/source-controller:v1.9.5Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-08-31
This patch release upgrades Helm to v4.2.4 to stay in sync with helm-controller 1.6, which moved back from the Flux fork of Helm to upstream. It also updates the fluxcd/pkg dependencies, which bring Kubernetes to 1.36.4.
Improvements:
docker.io/fluxcd/source-controller:v1.9.4
docker.io/fluxcd/source-controller:v1.9.4ghcr.io/fluxcd/source-controller:v1.9.4Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-08-07
This patch release aligns Helm repository index loading with upstream Helm v4 by
skipping empty entries, improves the error handling in the Bucket reconciler
for optional fields in Azure responses, resolves OCI Helm charts by digest so
that verification and download operate on the same content, and limits GCS
static authentication to secrets holding service account keys. It also updates
the fluxcd/pkg dependencies, which align the ECR host detection with upstream.
Fixes:
Improvements:
docker.io/fluxcd/source-controller:v1.9.3
docker.io/fluxcd/source-controller:v1.9.3ghcr.io/fluxcd/source-controller:v1.9.3Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-07-13
This patch release fixes the HelmChart CRD description for .status.url, which
was copy-pasted from Bucket and pointed users at BucketStatus.Artifact
instead of HelmChartStatus.Artifact.
Improvements:
docker.io/fluxcd/source-controller:v1.9.2
docker.io/fluxcd/source-controller:v1.9.2ghcr.io/fluxcd/source-controller:v1.9.2Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-07-07
This patch release disables Flux variable substitution on the source-controller
CRDs by annotating them with kustomize.toolkit.fluxcd.io/substitute: disabled,
so that Kustomizations with post-build substitution enabled no longer corrupt
the CRD schemas when they contain ${...} sequences. It also caches the
registry authorization token during Notation verification, so the token is
fetched once per verification instead of once per request, reducing
token-endpoint traffic against the registry.
Fixes:
Improvements:
docker.io/fluxcd/source-controller:v1.9.1
docker.io/fluxcd/source-controller:v1.9.1ghcr.io/fluxcd/source-controller:v1.9.1Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-06-30
This patch release updates Kubernetes to 1.36.2 and the fluxcd/pkg dependencies, adds kubectl categories to the source-controller CRDs and documents the controller's command-line options.
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
docker.io/fluxcd/source-controller:v1.9.0
docker.io/fluxcd/source-controller:v1.9.0ghcr.io/fluxcd/source-controller:v1.9.0Supported architectures: linux/amd64, linux/arm64 and linux/arm/v7.
The container images are built on GitHub hosted runners and are signed with cosign and GitHub OIDC.
To verify the images and their provenance (SLSA level 3), please see the security documentation.
Release date: 2026-06-17
This minor release comes with new authentication and verification features for the source APIs, along with various improvements, fixes and dependency updates.
The GitRepository controller now supports AWS CodeCommit as a Git provider, allowing authentication to CodeCommit repositories.
Git commit and tag verification now supports SSH signatures in addition to
OpenPGP, so commits and tags signed with SSH keys can be verified via
.spec.verify.
The OCIRepository controller now supports configuring a custom Sigstore trusted root for keyless signature verification, via a Secret referenced in the verification configuration.
OCI artifacts are now resolved and stored strictly by their content digest.
Fixes:
Improvements:
This patch release hardens path handling in the source reconcilers and updates go-git to v5.19.1, which fixes CVE-2026-45571 (crafted repositories may…
Release date: 2026-05-20
This patch release hardens path handling in the source reconcilers and updates
go-git to v5.19.1, which fixes
CVE-2026-45571 (crafted
repositories may modify the main and submodule .git directories) and
CVE-2026-45570 (improper
single-quote escaping in the SSH transport). It also fixes Helm chart
resolution for OCI tags that encode semver build metadata, updates Helm to
v4.2.0 to align with helm-controller, and adds support for GCP sovereign cloud
artifact registries via the fluxcd/pkg update.
Fixes:
Improvements:
This patch release comes with dependency updates, including go-git v5.19.0 which fixes CVE-2026-45022.
Release date: 2026-05-12
This patch release comes with dependency updates, including go-git v5.19.0 which fixes CVE-2026-45022.
Improvements:
This patch release updates go-git to v5.18.0, which includes performance improvements for Git operations, and comes with dependency updates.
This patch release fixes the Azure Blob prefix option not being passed to the storage client, and improves the error message when using encrypted SSH
Release date: 2026-04-07
This patch release fixes the Azure Blob prefix option not being passed to the storage client, and improves the error message when using encrypted SSH keys without a password.
Fixes:
Improvements:
This patch release fixes Azure Container Registry authentication by using the ACR-specific auth scope instead of the generic registry scope.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Remove deprecated APIs in group source.toolkit.fluxcd.io/v1beta2 #1983
Release date: 2026-02-17
This minor release comes with Helm v4 support, cosign v3 verification, and various improvements.
⚠️ The v1beta2 APIs were removed. Before upgrading the CRDs, Flux users
must run flux migrate to
migrate the cluster storage off v1beta2.
The HelmChart controller now uses Helm v4. The HelmRepository type oci
has been moved to maintenance mode, users should migrate to OCIRepository.
CRD validation for v1 has been aligned with v1beta2 so that invalid
specs are rejected at admission time.
The OCIRepository controller now supports verifying artifacts signed with both cosign v2 and cosign v3.
The github provider now supports looking up the GitHub App installation ID
automatically, removing the need to configure it manually.
In addition, the Kubernetes dependencies have been updated to v1.35.0 and the controller is now built with Go 1.26.
Improvements:
source.toolkit.fluxcd.io/v1beta2
#1983HelmRepository type oci to maintenance mode
#1985This patch release fixes Azure Workload Identity in Azure China Cloud.
This patch release fixes support for SOCKS5 proxy in the controller APIs.
Release date: 2025-10-28
This patch release fixes support for SOCKS5 proxy in the controller APIs.
Fixes:
The controller is now built with Go 1.25.2 which includes fixes for vulnerabilities in the Go stdlib: CVE-2025-58183, CVE-2025-58188 and many others.…
Release date: 2025-10-08
This patch release comes with various dependency updates.
The controller is now built with Go 1.25.2 which includes fixes for vulnerabilities in the Go stdlib: CVE-2025-58183, CVE-2025-58188 and many others. The full list of security fixes can be found here.
Improvements:
This patch release comes with a fix for TLS certs handling in the HelmChart reconciler when auth credentials are not specified.
Release date: 2025-10-06
This patch release comes with a fix for TLS certs handling in the HelmChart reconciler when auth credentials are not specified.
Fixes:
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Remove deprecated APIs in group source.toolkit.fluxcd.io/v1beta1 #1861
Release date: 2025-09-15
This minor release comes with new features, improvements and bug fixes.
A new ExternalArtifact API has been added to the source.toolkit.fluxcd.io group. This API enables advanced source composition and decomposition patterns implemented by the source-watcher controller.
GitRepository controller now includes fixes for stalling issues and improved error handling. Multi-tenant workload identity support has been added for Azure repositories when the ObjectLevelWorkloadIdentity feature gate is enabled. TLS configuration support has been added for GitHub App authentication.
Bucket controller now supports multi-tenant workload identity for AWS, Azure and GCP providers when the ObjectLevelWorkloadIdentity feature gate is enabled. A default service account flag has been added for lockdown scenarios.
The controller now supports system certificate pools for improved CA compatibility, and TLS ServerName pinning has been removed from TLS configuration for better flexibility. A --default-service-account=<sa name> flag was introduced for workload identity multi-tenancy lockdown.
In addition, the Kubernetes dependencies have been updated to v1.34, Helm has been updated to v3.19 and various other controller dependencies have been updated to their latest version. The controller is now built with Go 1.25.
Fixes:
Improvements:
fluxcd/pkg/artifact
#1883source.toolkit.fluxcd.io/v1beta1
#1861Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →