139 wires and counting

$ follow Kubernetes

Keep up with Kubernetes in about 3 minutes: what actually shipped — the commits, pull requests, releases, and security advisories that matter.

or

fair warning: these emails are deeply technical. diffs, version numbers, CVEs, benchmark deltas. if that's not your idea of a good read, this isn't your newsletter.

Folds into your digest — weekly by default, monthly if you prefer. Unsubscribe in one click.

$ status

wire 2026-09-26
stories 121

© 2026 RepoJournal Home Showcase Explore How it works Privacy

$ the-wire · showcase

kops adopts patched containerd, grpc unpinned across Kubernetes repos

By RepoJournal · Filed · About Kubernetes · Composed from the cited sources · methodology

Two security-driven dependency moves define the day: kops defaults to containerd 2.3.6 for its CVE fixes, and the gRPC pin keeping Kubernetes and externaljwt on a vulnerable version is lifted to v1.84.0.

containerd: default to 2.3.6 / runc 1.5.1 kubernetes/kops

by Ciprian Hacman

kops now defaults to containerd 2.3.6, the latest patch of the 2.3 LTS line, which the commit says includes fixes for CVE-2026-53495, GHSA-rp3h-jf77-q9p4 and CVE-2026-53493. Because containerd 2.3.5 and newer pin runc 1.5.1 in script/setup/runc-version, runc moves with it.

Bump google.golang.org/grpc to v1.84.0 and lift its pin kubernetes/kubernetes

by Davanum Srinivas

google.golang.org/grpc moves to v1.84.0 because v1.82.2 lacked the CVE-2026-84304 fix, which landed in v1.83.1+. The four modules v1.83+ pulls in through cloud.google.com/go/auth are graph-only and recorded in status.unwantedReferences rather than vendored.

kube-proxy: drop the dead cgroup walker from pkg/util/oom kubernetes/kubernetes

by Davanum Srinivas

ApplyOOMScoreAdjContainer has had no caller since 2017, and its pkg/kubelet/cm/util import dragged opencontainers/cgroups, go-systemd/dbus and godbus into kube-proxy for a single write of /proc/self/oom_score_adj. Removing it also cuts the etcd client, admission and the generic apiserver out of kube-proxy's import graph alongside the pkg/cluster/ports and responsewriters changes.

KEP-5972: Dynamic Containers kubernetes/enhancements

by tallclair

A new KEP proposes Dynamic Containers, described as making containers mutable, and carries an /label api-review tag. It lands under sig node with dchen1107 and haircommander assigned, so the shape of any future container-mutation API will go through that review.

chore(hack): stop generating hashes for unsupported Kubernetes versions kubernetes/kops

by Ciprian Hacman

generate-asset-hashes.sh was still regenerating k8s-1.25.yaml through k8s-1.31.yaml files that had been deleted when support for those versions was removed, so every run recreated them; the script now stops at the oldest supported version, 1.32. Related assetdata cleanup dropped 14 bogus SHA512 entries whose sha256 value was literally "Hash:", and the dead verify-hashes target is gone.

Quick answers

What shipped in Kubernetes on September 26, 2026?
Two security-driven dependency moves define the day: kops defaults to containerd 2.3.6 for its CVE fixes, and the gRPC pin keeping Kubernetes and externaljwt on a vulnerable version is lifted to v1.84.0. In total, 81 commits and 40 pull requests landed.
Who contributed to Kubernetes on September 26, 2026?
12 developers shipped this update, including Ciprian Hacman, kubernetes-prow[bot], neronsoda, ye11oc4t, Suhyen Im, Davanum Srinivas, esotsal, and tallclair, and 4 more.
What were the notable Kubernetes updates?
containerd: default to 2.3.6 / runc 1.5.1, Bump google.golang.org/grpc to v1.84.0 and lift its pin, and kube-proxy: drop the dead cgroup walker from pkg/util/oom.