Zum Inhalt springen

KEDA Release Notes

2 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

KEDA

KEDA 2.21.0: Drei Breaking Changes und Fix für CVE-2026-77524

KEDA 2.21.0 bringt drei Breaking Changes und behebt die kritische Sicherheitslücke CVE-2026-77524, indem die Audience von Service-Account-Tokens (u. a. Vault Kubernetes Authentication und boundServiceAccountToken in TriggerAuthentication) erzwungen wird; vor dem Upgrade von 2.20 ist der Upgrade-Leitfaden zu beachten.

We are happy to release KEDA 2.21.0 🎉

[!IMPORTANT] KEDA 2.21.0 contains three breaking changes. If you are upgrading from KEDA 2.20, review Upgrading from KEDA 2.20 to 2.21 before upgrading.

Before upgrading from KEDA 2.20

Service account token audience enforcement (CVE-2026-77524)

KEDA 2.21 fixes the critical CVE-2026-77524 / GHSA-637c-6jxx-4rwm. You are affected if you use:

  • Vault Kubernetes authentication, including configurations using the operator token, an existing projected token, or credential.serviceAccountName.
  • Any TriggerAuthentication or ClusterTriggerAuthentication using boundServiceAccountToken, including integrations with Metrics API, Prometheus, Loki, Datadog Cluster Agent, and other token-authenticated receivers.

You are not affected if you use ordinary Vault token authentication, API keys, OAuth credentials, or another authentication method that does not use a bound service account token. Before upgrading, review carefully the upgrade guide

Temporal Rules-Based Versioning settings …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

KEDA

KEDA 2.20.2: Neue HPAActive-Condition und Absturz-Fixes

KEDA v2.20.2 führt eine eigene HPAActive-Condition für ScaledObject ein, sodass kurzzeitige HPA-Metriklücken die Ready-Condition nicht mehr auf False setzen, und behebt mehrere Abstürze, darunter einen Concurrent-Map-Writes-Panic im Root-CA-CertPool sowie mehrere Nil-Pointer-Dereferenzierungen.

Release KEDA v2.20.2 :rocket:

⚠️⚠️⚠️⚠️ ⚠️ Please read upgrade notes if you are upgrading from version < 2.20.0: https://github.com/kedacore/keda/releases/tag/v2.20.0 ⚠️⚠️⚠️⚠️⚠️

Improvements

  • General: Introduce a dedicated HPAActive condition on ScaledObject mirroring the HPA's own ScalingActive status, so transient HPA metric gaps no longer flip the Ready condition to False (#7914)

Fixes

  • General: Fix concurrent map writes panic in the shared root CA CertPool (#7910)
  • General: Fix nil pointer dereference in AWS Secret Manager TriggerAuthentication when awsSecretManager.credentials is omitted and no awsSecretManager.podIdentity is set (#7927)
  • General: Fix nil pointer dereference in customScalingStrategy.GetEffectiveMaxScale when customScalingQueueLengthDeduction is omitted; the optional field is now treated as zero deduction instead of panicking (#7798)
  • General: Fix nil pointer dereference in GetCurrentReplicas when a Deployment/StatefulSet/ReplicaSet is returned from the informer cache with an undefaulted spec.replicas; a nil value is now treated as the Kubernetes default of 1 instead of panicking (#7863) …

Originalquelle(öffnet in neuem Tab)Problem melden