NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #3105 by repository stars
Last release 2 days ago
05 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
491 releases · first in 2020
One column per quarter.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This patch release comes with a fix for rsa-sha2-512 and rsa-sha2-256 algorithms not being prioritized for ssh-rsa host keys.
Release date: 2025-06-27
This patch release comes with a fix for rsa-sha2-512 and rsa-sha2-256 algorithms
not being prioritized for ssh-rsa host keys.
Fixes:
This patch release comes with a fix for the knownhosts: key mismatch error in the GitRepository API when using SSH authentication, and a fix for authe
Release date: 2025-06-13
This patch release comes with a fix for the knownhosts: key mismatch
error in the GitRepository API when using SSH authentication, and
a fix for authentication with
public ECR repositories
in the OCIRepository API.
Fix:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This minor release promotes the OCIRepository API to GA, and comes with new features, improvements and bug fixes.
Release date: 2025-05-27
This minor release promotes the OCIRepository API to GA, and comes with new features, improvements and bug fixes.
The OCIRepository API has been promoted from v1beta2 to v1 (GA).
The v1 API is backwards compatible with v1beta2.
OCIRepository API now supports object-level workload identity by setting
.spec.provider to one of aws, azure, or gcp, and setting
.spec.serviceAccountName to the name of a service account in the same
namespace that has been configured with appropriate cloud permissions.
For this feature to work, the controller feature gate
ObjectLevelWorkloadIdentity must be enabled. See a complete guide
here.
OCIRepository API now caches registry credentials for cloud providers by default. This behavior can be disabled or fine-tuned by adjusting the token cache controller flags (see docs). The token cache also exposes metrics that are documented here.
GitRepository API now supports sparse checkout by setting a list
of directories in the .spec.sparseCheckout field. This allows
for optimizing the amount of data fetched from the Git repository.
GitRepository API now supports mTLS authentication for HTTPS Git repositories
by setting the fields tls.crt, tls.key, and ca.crt in the .data field
of the referenced Secret in .spec.secretRef.
GitRepository API now caches credentials for non-generic providers by default.
This behavior can be disabled or fine-tuned by adjusting the
token cache controller flags (see docs).
The token cache also exposes metrics that are documented
here.
In addition, the Kubernetes dependencies have been updated to v1.33 and various other controller dependencies have been updated to their latest version. The controller is now built with Go 1.24.
Fixes:
Masterminds/semver to v3.3.0
#1785Improvements:
GitRepository
#1774GitRepository
#1778GitRepository
#1745
#1788
#1789Nothing published for this version
Nothing published for this version
Nothing published for this version
Remove deprecated object metrics from controllers #1686
Release date: 2025-02-13
This minor release comes with various bug fixes and improvements.
The GitRepository API now supports authenticating through GitHub App for GitHub repositories. See docs.
In addition, the Kubernetes dependencies have been updated to v1.32.1, Helm has been updated to v3.17.0 and various other controller dependencies have been updated to their latest version.
Fixes:
Improvements:
This patch release comes with a fix to the GitRepository API to keep it backwards compatible by removing the default value for .spec.provider field wh
Release date: 2024-09-26
This patch release comes with a fix to the GitRepository API to keep it
backwards compatible by removing the default value for .spec.provider field
when not set in the API. The controller will internally consider an empty value
for the provider as the generic provider.
Fix:
This minor release promotes the Bucket API to GA, and comes with new features, improvements and bug fixes.
Release date: 2024-09-25
This minor release promotes the Bucket API to GA, and comes with new features, improvements and bug fixes.
The Bucket API has been promoted from v1beta2 to v1 (GA).
The v1 API is backwards compatible with v1beta2.
Bucket API now supports proxy through the field .spec.proxySecretRef and custom TLS client certificate and CA through the field .spec.certSecretRef.
Bucket API now also supports specifying a custom STS configuration through the field .spec.sts. This is currently only supported for the providers generic and aws. When specifying a custom STS configuration one must specify which STS provider to use. For the generic bucket provider we support the ldap STS provider, and for the aws bucket provider we support the aws STS provider. For the aws STS provider, one may use the default main STS endpoint, or the regional STS endpoints, or even an interface endpoint.
OCIRepository API now supports proxy through the field .spec.proxySecretRef.
Warning: Proxy is not supported for cosign keyless verification.
GitRepository API now supports OIDC authentication for Azure DevOps repositories through the field .spec.provider using the value azure. See the docs for details here.
In addition, the Kubernetes dependencies have been updated to v1.31.1, Helm has been updated to v3.16.1 and various other controller dependencies have been updated to their latest version. The controller is now built with Go 1.23.
Fixes:
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
The v1 API is backwards compatible with v1beta2, with the exception of the removal of the deprecated field .spec.valuesFile which was replaced with sp…
Release date: 2024-05-03
This minor release promotes the Helm APIs to GA, and comes with new features, improvements and bug fixes.
The HelmRepository API has been promoted from v1beta2 to v1 (GA).
The v1 API is backwards compatible with v1beta2.
For HelmRepository of type oci, the .spec.insecure field allows connecting
over HTTP to an insecure non-TLS container registry.
To upgrade from v1beta2, after deploying the new CRD and controller,
set apiVersion: source.toolkit.fluxcd.io/v1 in the YAML files that
contain HelmRepository definitions.
Bumping the API version in manifests can be done gradually.
It is advised not to delay this procedure as the beta versions will be removed after 6 months.
The HelmChart API have been promoted from v1beta2 to v1 (GA).
The v1 API is backwards compatible with v1beta2, with the exception
of the removal of the deprecated field .spec.valuesFile which was replaced with spec.valuesFiles.
The HelmChart API was extended with support for
Notation signature verification
of Helm OCI charts.
A new optional field .spec.ignoreMissingValuesFiles has been added,
which allows the controller to ignore missing values files rather than failing to reconcile the HelmChart.
The OCIRepository API was extended with support for
Notation signature verification
of OCI artifacts.
A new optional field .spec.ref.semverFilter has been added,
which allows the controller to filter the tags based on regular expressions
before applying the semver range. This allows
picking the latest release candidate
instead of the latest stable release.
In addition, the controller has been updated to Kubernetes v1.30.0, Helm v3.14.4, and various other dependencies to their latest version to patch upstream CVEs.
Improvements:
source.toolkit.fluxcd.io/v1 (GA)
#1428.spec.ignoreMissingValuesFiles to HelmChart API
#1447.spec.ref.semverFilter in OCIRepository API
#1407Fixes:
This patch release comes with improvements to the HelmChart name validation and adds logging sanitization of connection error messages for Bucket sour
Release date: 2024-04-04
This patch release comes with improvements to the HelmChart name validation
and adds logging sanitization of connection error messages for Bucket sources.
Fixes:
Improvements:
This patch release updates the Kubernetes dependencies to v1.28.6 and various other dependencies to their latest version to patch upstream CVEs.
Your coding agent can read these notes before it upgrades. Set up the MCP server →