NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #3105 by repository stars
Last release 3 days ago
05 Oct 2026
Ships fairly regularly
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
491 releases · first in 2020
One column per quarter.
This patch release updates the controller's Helm dependency to v3.13.3.
This patch release addresses an issue with AWS ECR authentication introduced in v1.2.0.
Release date: 2023-12-11
This patch release addresses an issue with AWS ECR authentication introduced in v1.2.0.
In addition, a variety of dependencies have been updated. Including an update of the container base image to Alpine v3.19.
Fixes:
Improvements:
This patch release ensures the controller is built with the latest Go 1.21.x release, to mitigate multiple security vulnerabilities which were publish…
Release date: 2023-12-08
This patch release ensures the controller is built with the latest Go 1.21.x
release, to mitigate multiple security vulnerabilities which were published
shortly after the release of v1.2.0.
In addition, a small number of dependencies have been updated to their latest version.
Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This minor release comes with API changes, bug fixes and several new features.
Release date: 2023-12-05
This minor release comes with API changes, bug fixes and several new features.
A new field, .spec.prefix, has been added to the Bucket API, which enables
server-side filtering of files if the object's .spec.provider is set to
generic/aws/gcp.
Two new fields, .spec.verify.matchOIDCIdentity.issuer and
.spec.verify.matchOIDCIdentity.subject have been added to the HelmChart and
OCIRepository APIs. If the image has been keylessly signed via Cosign, these
fields can be used to verify the OIDC issuer of the Fulcio certificate and the
OIDC identity's subject respectively.
A new boolean field, .spec.insecure, has been introduced to the HelmRepository
API, which allows connecting to a non-TLS HTTP container registry. It is only
considered if the object's .spec.type is set to oci.
From this release onwards, HelmRepository objects of type OCI are treated as static objects, i.e. they have an empty status. Existing objects undergo a one-time automatic migration and new objects will be undergo a one-time reconciliation to remove any status fields.
Additionally, the controller now performs a shallow clone if the
.spec.ref.name of the GitRepository object points to a branch or a tag.
Furthermore, a bug has been fixed, where the controller would try to authenticate against public OCI registries if the HelmRepository object has a reference to a Secret containing a CA certificate.
Lastly, dependencies have been updated to their latest version, including an update of Kubernetes to v1.28.4.
Fixes:
OCIChartRepository.insecure to insecureHTTP
#1299Improvements:
go-git to v5.10.0
#1271.spec.insecure to HelmRepository for type: oci
#1288This patch release fixes a bug where OCIRepository objects can't be consumed when the OCI image layer contains symlinks.
This is a patch release that fixes a regression introduced in v1.1.0 where HelmRepository objects would not be reconciled if they provided a TLS Secre
Release date: 2023-09-18
This is a patch release that fixes a regression introduced in v1.1.0 where
HelmRepository objects would not be reconciled if they provided a TLS Secret
using .spec.secretRef with a type other than Opaque or kubernetes.io/tls.
In addition, the URL lookup strategy for Buckets has been changed from path to auto, to widen support for S3-compatible object storage services.
Lastly, several dependencies have been updated to their latest versions.
Fixes:
.spec.secretRef
#1225Improvements:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
HelmRepository: The field .spec.secretRef has been __deprecated__ in favor of a new field `.spec.certSecretRef`. This field is also supported by OCI H…
Release date: 2023-08-23
This minor release comes with API changes, bug fixes and several new features.
All APIs that accept TLS data have been modified to adopt Secrets of type
kubernetes.io/tls. This includes:
.spec.secretRef has been deprecated in favor
of a new field .spec.certSecretRef.
This field is also supported by OCI HelmRepositories.caFile, keyFile and certFile keys in the
Secret specified in .spec.certSecretRef
have been deprecated in favor of ca.crt, tls.key and tls.crt.
Also, the Secret now must be of type Opaque or kubernete.io/tls..spec.secretRef using the ca.crt key, which takes precedence over the
existing caFile key.Furthermore, GitRepository has a couple of new features:
.spec.proxySecretRef
has been introduced which can be used to specify the proxy configuration to
use for all remote Git operations related to the particular object..spec.verification.mode
now supports the following values:
.spec.ref.spec.ref and the commit it
points to.Starting with this version, the controller now stops exporting an object's metrics as soon as the object has been deleted.
In addition, the controller now consumes significantly less CPU and memory when reconciling Helm repository indexes.
Lastly, a new flag --interval-jitter-percentage has been introduced which can
be used to specify a jitter to the reconciliation interval in order to
distribute the load more evenly when multiple objects are set up with the same
interval.
Improvements:
GitRepository
#1109.spec.certSecretRef for specifying TLS auth data
#1160spec.ref.name with Azure Devops
#1175Fixes:
This is a patch release that fixes the AWS authentication for cross-region ECR repositories.
Release date: 2023-07-10
This is a patch release that fixes the AWS authentication for cross-region ECR repositories.
Fixes:
fluxcd/pkg/oci to fix ECR cross-region auth
#1158Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
This is the first stable release of the controller. From now on, this controller follows the Flux 2 release cadence and support pledge.
Release date: 2023-07-03
This is the first stable release of the controller. From now on, this controller follows the Flux 2 release cadence and support pledge.
Starting with this version, the build, release and provenance portions of the Flux project supply chain provisionally meet SLSA Build Level 3.
This release includes several minor changes that primarily focus on addressing forgotten and obsolete bits in the logic related to GitRepository objects.
Including a removal of the OptimizedGitClones feature flag. If your
Deployment is configured to disable this flag, you should remove it.
In addition, dependencies have been updated to their latest version, including an update of Kubernetes to v1.27.3.
For a comprehensive list of changes since v0.36.x, please refer to the
changelog for v1.0.0-rc.1, v1.0.0-rc.3 and
v1.0.0-rc.4.
Improvements:
Nothing published for this version
Nothing published for this version
Lastly, the controller's dependencies were updated to mitigate CVE-2023-33199.
Release date: 2023-06-01
This release candidate fixes a regression introduced in 1.0.0.-rc.4 where
support for Git servers that exclusively use v2 of the wire protocol like Azure
Devops and AWS CodeCommit was broken.
Lastly, the controller's dependencies were updated to mitigate CVE-2023-33199.
Improvements:
Fixes:
fluxcd/pkg/git/gogit to v0.12.0
#1111Nothing published for this version
Nothing published for this version
This release candidate comes with support for Kubernetes v1.27 and Cosign v2. It also enables the use of annotated Git tags with .spec.ref.name in Git
Release date: 2023-05-26
This release candidate comes with support for Kubernetes v1.27 and Cosign v2.
It also enables the use of annotated Git tags with .spec.ref.name in
GitRepository. Furthermore, it fixes a bug related to accessing Helm OCI
charts on ACR using OIDC auth.
Improvements:
go-git/go-git and pkg/tar
#1105Lastly, the controller's dependencies were updated to mitigate CVE-2023-1732 and CVE-2023-2253, and the controller base image was updated to Alpine 3.…
Release date: 2023-05-12
This release candidate introduces the verification of the Artifact digest in storage during reconciliation. This ensures that the Artifact is not tampered with after it was written to storage. When the digest does not match, the controller will emit a warning event and remove the file from storage, forcing the Artifact to be re-downloaded.
In addition, files with executable permissions are now archived with their mode
set to 0o744 instead of 0o644. Allowing the extracted file to be executable
by the user.
Lastly, the controller's dependencies were updated to mitigate CVE-2023-1732 and CVE-2023-2253, and the controller base image was updated to Alpine 3.18.
Improvements:
Nothing published for this version
This release candidate comes with various updates to the controller's dependencies, most notable, Helm was updated to v3.11.3.
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →