# 4.23.0-ec.1 Created: 2026-09-28 10:46:23 +0000 UTC Image Digest: `sha256:6144dde458cb15cc382b096ed595a114baca85398a1e23a79d2dc4693e8b2121` Promoted from quay.io/openshift-release-dev/ocp-release-nightly@sha256:32207cd7bd73a90887c9475c001061ab578129d80e2847db979fb876f5283a81 ## Changes from 4.23.0-ec.0 ### Components * Kubectl 1.36.2 * Kubernetes 1.36.3 * Kubernetes Tests 1.36.2 * Red Hat Enterprise Linux CoreOS 10.2 upgraded from 10.2.20260825-0 to 10.2.20260918-0 ### FeatureGate Changes | FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA | | :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: | | GomaxprocsInjection
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) | | EtcdBackendQuota
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled | | GCPSovereignCloudInstall
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled | | OpenShiftPodSecurityAdmission
(0 tests)| Disabled
(Changed)| Disabled
(Changed)| Enabled| Enabled| Disabled
(Changed)| Disabled
(Changed)| Enabled| Enabled | | OSStreams
(0 tests)| Enabled
(Changed)| Enabled| Enabled| Enabled| Enabled
(Changed)| Enabled| Enabled| Enabled | ### Rebuilt images without code change * [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [d6ec9243](https://github.com/openshift/apiserver-network-proxy/commit/d6ec9243d24050d7d7ad7f939e45f821171f000e) `sha256:a78775dfe9face6803b655d256b4f941f04b1ec090ab429f5144fa4e035182af` * [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws) git [278e8c07](https://github.com/openshift/cloud-provider-aws/commit/278e8c07a72a50e7d3f28fc743c38c64f008f5aa) `sha256:747d6f41b367d08904ae303dc495cb97c3e9b55a2ef52e77c6c9c121fb6785d1` * [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [8b8c4cef](https://github.com/openshift/aws-ebs-csi-driver/commit/8b8c4cef02ec9b670e2709f2aacc0ed72420be90) `sha256:aed70f135c98e8d37c77ec0951458af9bf35039d835de64ca32cb6895b56e72a` * [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider) git [9b18930d](https://github.com/openshift/aws-encryption-provider/commit/9b18930d2db9521a08faa7165488bdcf6482b9cf) `sha256:48caa1769cc1aa047b18e9bc1b330865e9f0c08eeda9577db6c13bec8f4d3b04` * [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws) git [9f2e9b3c](https://github.com/openshift/machine-api-provider-aws/commit/9f2e9b3c46b391c7219257a426ad80ca8a296af0) `sha256:850e107b4fe1b308b28a840be6a6f0648d251aef71617d5918571e174dabc370` * [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [0d33a459](https://github.com/openshift/aws-pod-identity-webhook/commit/0d33a4596e2a22d188fe74c4a6497c37c2528c1f) `sha256:d1bc3d729802f03f365ea80632a3f96ae3d1829150a0e8a150441318b5ede603` * [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure) git [63731729](https://github.com/openshift/cluster-api-provider-azure/commit/63731729974bff3be90ae2206c53d760572499d1) `sha256:57007cb27649e93bd3e9b860ce4b006016472a02456e824e111c3e63e1c998bf` * [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver) git [9689f030](https://github.com/openshift/azure-file-csi-driver/commit/9689f03011ce700b3bffc32791af839e80d0e0ab) `sha256:29054caae5972c5e1df2cd76732b864ff44ceaff703d98d0e8789a69a611887d` * [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure) git [4ff6c6b8](https://github.com/openshift/machine-api-provider-azure/commit/4ff6c6b8730c1253918f1f5261b9c12cab2e5903) `sha256:5855843b9ecf7fc9ce7044ef38017fc3709403b3704b4ac288e171e545e83371` * [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:8ed07b7abfe055249f6b23f03008b9c006d18646bb3299c4592380e82ae3f92c` * [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity) git [2b4705c5](https://github.com/openshift/azure-workload-identity/commit/2b4705c5d999339ce17d47a9b2a637d238891dae) `sha256:83aedf6f033457923365b9ea3053a2609da740a57b314c0be4e08e6b23f8f50c` * [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3) git [ad4f1c2b](https://github.com/openshift/cluster-api-provider-metal3/commit/ad4f1c2bd7b527437496b71b5b93ee1439243d65) `sha256:c17f9dacf01c1211b5a2b96bdd84fa1752ec78b569db4654fbaa92229107099d` * [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [f2b0db19](https://github.com/openshift/cluster-api-provider-baremetal/commit/f2b0db1919fff1344bc68948894c6775c0bf24a3) `sha256:a3fc1615201656b6a2846ed8718ab1aab93df0e77be558bcd8cffc06cd06a52d` * [baremetal-operator](https://github.com/openshift/baremetal-operator) git [34bbeb37](https://github.com/openshift/baremetal-operator/commit/34bbeb376836bf01793d4e70d29065d619ebcaa1) `sha256:9b57c6524a36548c9f35f84859904362634342a7ea1976c4b3e768259a1e65d5` * [cli](https://github.com/openshift/oc) git [4b0a124d](https://github.com/openshift/oc/commit/4b0a124d300cef187037bda6f1b04caa69ab8b62) `sha256:68fac0f3c3a7b2328bf28985ebda5b31611ca9fa1a1bd5aeafe9ef17b727bbdc` * [cli-artifacts](https://github.com/openshift/oc) git [4b0a124d](https://github.com/openshift/oc/commit/4b0a124d300cef187037bda6f1b04caa69ab8b62) `sha256:7a77e3ce1ee60079080b37828be521aae1bf944cf65d89153194a8f05b852a30` * [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator) git [b187feee](https://github.com/openshift/cloud-credential-operator/commit/b187feee66f4ce0f992059b21a97a2ae88e4cdd9) `sha256:25d4c5f3340db7959eda1dd39415bc34511865afa9ecca6c6e1f7f910a7383cd` * [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller) git [7afccf2d](https://github.com/openshift/cloud-network-config-controller/commit/7afccf2d78f6cb5dd3181de1588c5063bd995d7d) `sha256:87324d0a1a2bf995aa5129542570a03e6464a542ec2677136db76361d3f207c5` * [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler) git [f393f542](https://github.com/openshift/kubernetes-autoscaler/commit/f393f54229e6c3ae74c35ae72012af92d31c03d3) `sha256:29ccff37c11a06fc568ac7b1f642be4379bc25c7b13f25601a8f96f039e10430` * [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator) git [e48fe117](https://github.com/openshift/cluster-autoscaler-operator/commit/e48fe1179ad671757b5a40688e2d125c1f326e8b) `sha256:022ce09a0cea5ec9c02e1aa3164589cd49420cbc100b14344dc90a1011247972` * [cluster-capi-controllers](https://github.com/openshift/cluster-api) git [303d9786](https://github.com/openshift/cluster-api/commit/303d9786a5017d299b6e7fc702bb92f5cb4550cf) `sha256:e7d736b0cd46273c11b73738be4dbded081148a6f1f28cdcfec1e06a3f026a99` * [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator) git [0da197f8](https://github.com/openshift/cluster-cloud-controller-manager-operator/commit/0da197f80d941f537331f173bc7613d6729a2767) `sha256:61787c9df733c608f2918aff1404142f95f6b3d7014d0539768a47e6c8851a66` * [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator) git [35ec0224](https://github.com/openshift/cluster-csi-snapshot-controller-operator/commit/35ec0224eb0e5219d5eae012fb703223a6f3e1f7) `sha256:b6586cb1b2ef51f310f510f5a09f439514830c07babc4164eef96971733b105a` * [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator) git [c0ed09e3](https://github.com/openshift/cluster-dns-operator/commit/c0ed09e329e9001629518604a58205e3fbe8284a) `sha256:070e484bb9cd593383dd6b6e297efb12e0f7ed31d64833b80c056c92c2b2fd19` * [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [8da2f1fc](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/8da2f1fcb1e76e8b1b97b16ca7bbfa7116287eb8) `sha256:74e906d26556ddf3ba1224c10daec6c8508f6ade9352d4e06e7a7c81bfb1b4be` * [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller) git [469bbf21](https://github.com/openshift/cluster-policy-controller/commit/469bbf211d35eee0df4422bda7e9e600b080f0f2) `sha256:8b71cb3869494a58d5d6ad5bfd2a6991374afb3d2595d1f5eea7aa73cbfb529d` * [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:70bacdcf5260b2d2bede58cbc7106d2c51edcca0b466cd9da5db4a3753cd26eb` * [configmap-reloader](https://github.com/openshift/configmap-reload) git [ce80869a](https://github.com/openshift/configmap-reload/commit/ce80869a83b55ebbdc21a5550ec5747645203bd2) `sha256:25b0783ce9b140345f2c1112dbf2b3abc613374fc6d347cce52cb8ca80e03c4b` * [console-operator](https://github.com/openshift/console-operator) git [63049512](https://github.com/openshift/console-operator/commit/630495120bc5ddc9e05cd6defc2102690ced6301) `sha256:5ea0053cddc0bde9cb475423e976cf51b22edcf36b6de118e3ccd3501898d34f` * [coredns](https://github.com/openshift/coredns) git [37aaba89](https://github.com/openshift/coredns/commit/37aaba896e97f4b9a091aab6d36f2213b8854474) `sha256:e9396c2b84de3ae1dfbd051bbca70fbb2b5546e78a92820ca0ddc18379304698` * [csi-driver-manila](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:bbeef5cf9e821bd8491a49b69eaa04218122f8975a306a43f9722698826a0a24` * [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs) git [beb9567b](https://github.com/openshift/csi-driver-nfs/commit/beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa) `sha256:6c52a63b36a30d69abcac95b793ebb4c96791f1b46624b0d050256d68b7f06db` * [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [3fd668b3](https://github.com/openshift/csi-external-attacher/commit/3fd668b3f07dd382e5c7b6239d50f7988f652e64) `sha256:6fbd37a3941555be615870d24cda1af935c773d7d6b2c016a925a1d4d204017d` * [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [7ff338c9](https://github.com/openshift/csi-external-provisioner/commit/7ff338c9d1296f0e5d4d8080a76bb191c8f3be30) `sha256:e7d38c06be783c3d988937f534c15760f08bb73a7cb95b5cfdf230bdb3e123a8` * [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [14aa7028](https://github.com/openshift/csi-external-resizer/commit/14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf) `sha256:c1cfc8d254ffa044ce26cceeabe0368c64244893c4f878c9ae8bd012331421b2` * [csi-external-snapshotter](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:106e571532e456853f5e9599f0ae40a82bdf8427a3e96a376be9e5426ea59745` * [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [5766960d](https://github.com/openshift/csi-node-driver-registrar/commit/5766960d82ffb9ef84d15e903ae57d0a6781ef11) `sha256:1347ee32863ebc6d16844f7c1b0acfe43552162569b980c754d95ba25ead7ec7` * [csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:1dff414753d43860d73929906b749eb064abfb8b5d47fad639c7271d1204d755` * [deployer](https://github.com/openshift/oc) git [4b0a124d](https://github.com/openshift/oc/commit/4b0a124d300cef187037bda6f1b04caa69ab8b62) `sha256:3bca29e5e78937195d00298a683a4f3a78ab1da1f196ca72a6765275975af63a` * [driver-toolkit](https://github.com/openshift/driver-toolkit) git [b63b175a](https://github.com/openshift/driver-toolkit/commit/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a) `sha256:a92f27ba4f0aab205f900c3bb42e58521d65150964a64e947016e9a767af540d` * [etcd](https://github.com/openshift/etcd) git [609b11ed](https://github.com/openshift/etcd/commit/609b11ed8fc404fb95572d7c87e3243a1206cdb7) `sha256:14c6d67deae63b0f0d4d6c2bcace6d75383693644375b038dcc5c7eea6df4e8a` * [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp) git [51c32646](https://github.com/openshift/cloud-provider-gcp/commit/51c326465b3160124b8097953b42e44f1056da5a) `sha256:7521c9a15ac0cfee308947208bd6cda915f5f7f84e7212cc87ad31bd95557768` * [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp) git [dbcbfe70](https://github.com/openshift/cluster-api-provider-gcp/commit/dbcbfe70efa75f192309f2d0f8daae2c6a441e90) `sha256:65897c455f2ee783e861ce456fe1583a93ea7305cfe8499f39aa03013069e4b5` * [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp) git [91033fc5](https://github.com/openshift/machine-api-provider-gcp/commit/91033fc5b42f58acdad7be8c89a0012f5f2c9b5b) `sha256:5088684cacd33e9fe71d2afdb89e82c607451c58bc64ed41ecdd684fd6c42bb6` * [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver) git [049c0b96](https://github.com/openshift/gcp-pd-csi-driver/commit/049c0b96742c40fdd4384920afe17cefa5fa3d27) `sha256:4892a61c60f49f025b004902cff6ca3cece9366afb280d000092eefe266b90cb` * [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook) git [4501ff2f](https://github.com/openshift/gcp-workload-identity-federation-webhook/commit/4501ff2f53576c31df0511b69444e65e1eeba745) `sha256:4217e28cced2ef0b0bfe9c87bd6dcb85b1467d0f876b2ae58ee639627ad7f04e` * [haproxy-router](https://github.com/openshift/router) git [33812291](https://github.com/openshift/router/commit/3381229146657d2e6bd94115dda0885f25cb3bed) `sha256:7a4c910414944ca810e409a65060c185d20d3923ce9c1c80417bd54b81e796f3` * [haproxy-router-haproxy28](https://github.com/openshift/router) git [33812291](https://github.com/openshift/router/commit/3381229146657d2e6bd94115dda0885f25cb3bed) `sha256:b24d4c18a7865b122f10780fb08ba12d64f8457e92a071da3881772ebccd09b4` * [haproxy-router-haproxy32](https://github.com/openshift/router) git [33812291](https://github.com/openshift/router/commit/3381229146657d2e6bd94115dda0885f25cb3bed) `sha256:34da917b10f956fc9858fb350f504a224252dbaf5b2f3fee3b82b71d8cccffc8` * [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm) git [11bc35dd](https://github.com/openshift/cloud-provider-ibm/commit/11bc35dd6fd5163259023a6f1dfcc59ce813ab5f) `sha256:f672b534a2ecc15b3df8db7faf5773482a1a0e7187199b0483d84eb5e0c91a49` * [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver) git [3a89d7d1](https://github.com/openshift/ibm-vpc-block-csi-driver/commit/3a89d7d17d25727270414b07d3daaa3bc329d743) `sha256:51f337cb5c7e66e9b1d3723c768249a3faf0610e4f897d9641eb1833ccba421d` * [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator) git [be4fd017](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/commit/be4fd01725ce5ab0b47f846c905a349aeee8ab53) `sha256:6c6012c8b66eb105e197dd23314be3177636068f660312bb745367495cb751e7` * [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud) git [2615d13b](https://github.com/openshift/machine-api-provider-ibmcloud/commit/2615d13b730255b21ccb401d3dc039006c54a4fe) `sha256:fd66ba616dc5cc20da0b96a71625a1481e8a717bf0f40a67f13d84939ff4b607` * [insights-runtime-exporter](https://github.com/openshift/insights-runtime-extractor) git [7c9aa149](https://github.com/openshift/insights-runtime-extractor/commit/7c9aa14915e639edd20bc0869747487e2e73fe51) `sha256:3269f842fe14383eb8bace9ee30ea38ed4f8d7b1b67ce9fe684ee122a280c559` * [insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor) git [7c9aa149](https://github.com/openshift/insights-runtime-extractor/commit/7c9aa14915e639edd20bc0869747487e2e73fe51) `sha256:99d24618835134d59a0ee443fc522a6fa943baf4fcfeef25b5e53264698cf7d8` * [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [f8e41b2e](https://github.com/openshift/ironic-rhcos-downloader/commit/f8e41b2ed8915474a99e3eb34b54692afb0611da) `sha256:2b6fc3a3dbf59bf74ca1d1abb84ee407a8372c9dcc07b99dbe2047791fc34523` * [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [486a0418](https://github.com/openshift/ironic-static-ip-manager/commit/486a041897d703d55ef59c98e2b20a01588a0b4c) `sha256:dd7a03108c663bde476dcb3f18284fa8ac779783b69dbcd2f686c57939cc8f63` * [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server) git [3d2e9cd0](https://github.com/openshift/kubernetes-metrics-server/commit/3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71) `sha256:0d55a4e1e2fc2daf7d496bf3089f8c4b6848bb7ddd48398a5b603127aeecdcc9` * [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [43c114bc](https://github.com/openshift/kube-rbac-proxy/commit/43c114bc124f59e2fc3223dea8e0a8f4cdeed18d) `sha256:f48d3b699fe24d3539f2d08d328ef3bb109c96e91d580039fc73fc6409645262` * [kube-state-metrics](https://github.com/openshift/kube-state-metrics) git [019ecc7d](https://github.com/openshift/kube-state-metrics/commit/019ecc7d533333dfd3bf8893e78cd7ec6e282f01) `sha256:7ced3c63e74823247f68e1775a250eda17c30d43e113b7bc7e5eb93d671799c9` * [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt) git [5eb884ab](https://github.com/openshift/cloud-provider-kubevirt/commit/5eb884abcd2ff17ae8d7b2691ca12494597c08a6) `sha256:98deaf04955491a94a361f3e0e38fe03117a57691451681c222ce70b96cf989d` * [machine-image-customization-controller](https://github.com/openshift/image-customization-controller) git [e49b0968](https://github.com/openshift/image-customization-controller/commit/e49b096880f17296d42a77443dc14d732683333d) `sha256:cfcff5f1357bc7661d461b34c51735be90a5dceaad746766c18054f99f1ca185` * [machine-os-images](https://github.com/openshift/machine-os-images) git [bf618aac](https://github.com/openshift/machine-os-images/commit/bf618aac93c71a56e8249669c579f0a782742e2e) `sha256:375734624232b20c1ceb0552dd7e249a3fee6297f38c56a1248d425437594e3d` * [metallb-frr](https://github.com/openshift/frr) git [54a6ea48](https://github.com/openshift/frr/commit/54a6ea48902d81460536b81ea6bdceb89c12e622) `sha256:b74cead6f146e53fc92c41f987a9ce8eeaf70bd350d317d3d43a9dae95dc9137` * [network-tools](https://github.com/openshift/network-tools) git [0b53ac3d](https://github.com/openshift/network-tools/commit/0b53ac3dccf59cd169555bf18c207122374bf003) `sha256:3bb52c0213dd23d791ad2e6fafdaf8f1f7a4d6d9266249c435e2fb9866c48942` * [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [dc584c6b](https://github.com/openshift/cloud-provider-nutanix/commit/dc584c6b2e895a6217f9e2dbed765209af1898a1) `sha256:56c1747df051969237394cbbe137771ba4e293d30bc802a6b542531714591aad` * [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix) git [249b7c8e](https://github.com/openshift/machine-api-provider-nutanix/commit/249b7c8edfca8f25413dc76bc5a216fbe12a9ab1) `sha256:37a72cfb67abf28a6313ea63bdc8fea744e381b798fcd76aedfa6db70057c3f2` * [openshift-apiserver](https://github.com/openshift/openshift-apiserver) git [ab031522](https://github.com/openshift/openshift-apiserver/commit/ab0315228cde432c8cd62df012b791a66a72c7b3) `sha256:314291d1363d8ac29ef735cc40a79dd08c48c47b6d94b9d36a4c1824937bbdb8` * [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [3b4ea3e7](https://github.com/openshift/openshift-state-metrics/commit/3b4ea3e753d97fea66e0f52c8282a711358b4ff7) `sha256:ad10141bcf48f76f09d2c416342571b47d8be6dedc935d6de1e10425aec52055` * [openstack-cinder-csi-driver](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:9aa20fcaa9e0197c2817d3469574ec61812599c14864cf66cdb1be207444fd5b` * [openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:8ea1716a91d08f79c5aa3a2ab876de4d8051f20670cd0053db7aaf612a0fff1a` * [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:dca72fda373e83e2233e5ca2771e308c2c2e4f2a5243d9181d512fd16a2bf4aa` * [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller) git [58dbc048](https://github.com/openshift/openstack-resource-controller/commit/58dbc0482c144c21effee2476947889122a518eb) `sha256:4bf34a766e5c4858364850b2a42abf9d6cd1acb65edc1a15493d9a0b6cb5fb63` * [operator-marketplace](https://github.com/operator-framework/operator-marketplace) git [fa9e19b2](https://github.com/operator-framework/operator-marketplace/commit/fa9e19b2ae7ad8de20b345e3bd736923f5c516cc) `sha256:152af65158516e45a4597ddde0aad201a96473e729e43f44c4d67a87666136f2` * [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator) git [f90431bf](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/commit/f90431bfe8ca93850450b2b24fae152d2385ca08) `sha256:6928f369e9eb3adad54a7b7308462dff22fc17a4e38021481123016145c4651b` * [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs) git [18eb5238](https://github.com/openshift/cloud-provider-powervs/commit/18eb5238fb2c86632edb24175f536d815f28ddf6) `sha256:8899c23fec0c0839b90cd11ebebe7a9547954da8b3d08c33025829bd246d8069` * [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs) git [28c928ff](https://github.com/openshift/machine-api-provider-powervs/commit/28c928ff78def160837170991f084b0fe71ca9be) `sha256:5aa513f0d3188ff9f667feb93803aabdc8955847e5b68abf51fea335917a0c8e` * [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [4ab9ff73](https://github.com/openshift/prom-label-proxy/commit/4ab9ff73c665319352288fe0b9b9e1df71832525) `sha256:f8d87d02a887f59df1503f7980d95f8edcefa2141abb2ba5dade684a30adbd5c` * [prometheus](https://github.com/openshift/prometheus) git [01d83356](https://github.com/openshift/prometheus/commit/01d8335673aa6f88f5742ef510e133efee88a7bf) `sha256:6ce3aade70fb3ade6b8fabde7e39bb1c5fd239226c033cb507c5a2c3bbb00fb6` * [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager) git [89bdff8b](https://github.com/openshift/prometheus-alertmanager/commit/89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce) `sha256:8a1e23c24975c45d191e956cc3a82f676cad39ee9946012e0ad2abc9b1964c4d` * [prometheus-config-reloader](https://github.com/openshift/prometheus-operator) git [67895c7c](https://github.com/openshift/prometheus-operator/commit/67895c7c968f42e97efec58f4140fffae4832028) `sha256:e8ff887712e8f7242f3f0548654492edff60266356fb37a3ec84047972b66ced` * [prometheus-operator](https://github.com/openshift/prometheus-operator) git [67895c7c](https://github.com/openshift/prometheus-operator/commit/67895c7c968f42e97efec58f4140fffae4832028) `sha256:813eb5d6cb8b59ff6cdd29150b6b377ba941fa335167818303c6985773f381f2` * [prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator) git [67895c7c](https://github.com/openshift/prometheus-operator/commit/67895c7c968f42e97efec58f4140fffae4832028) `sha256:9275758e5ffdcb7897d99582a52567c449e08618409610e5cf7426988fb041cb` * [route-controller-manager](https://github.com/openshift/route-controller-manager) git [59697cf7](https://github.com/openshift/route-controller-manager/commit/59697cf7af4517dd44e28179a57f7f35b6ea0e22) `sha256:895b0a63be9bdb4cc507eab9fe6d54e4bd3a22791d30fe6dec3d152e7c626389` * [service-ca-operator](https://github.com/openshift/service-ca-operator) git [ed872ba1](https://github.com/openshift/service-ca-operator/commit/ed872ba14b615ca5726ae90e987268877a0b0b20) `sha256:fcbd27440114a92c2a9ea333081479c73c20acf1f59a6db40d2c9987b7b81232` * [telemeter](https://github.com/openshift/telemeter) git [22ba1701](https://github.com/openshift/telemeter/commit/22ba1701333f3fd26490cc15b89ddf21df3f67f6) `sha256:a769a7cb38773e19e87b59b99c3e0080dc8611323d0831d3086c76223525f4e4` * [tools](https://github.com/openshift/oc) git [4b0a124d](https://github.com/openshift/oc/commit/4b0a124d300cef187037bda6f1b04caa69ab8b62) `sha256:4cf0a96c989191f93ed51a3c0826649c90dd37ead4a498b27549085dfb1af890` * [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator) git [ee9cd7ab](https://github.com/openshift/volume-data-source-validator/commit/ee9cd7aba4e096a9a957386ef20777e8950df352) `sha256:c4b629540a3d08ac3ee86aac04fe492032faa90ad8eb33d4908aa00722bf93f7` * [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere) git [eb29de19](https://github.com/openshift/cloud-provider-vsphere/commit/eb29de194594bad8e5bc572102f1008cb26655a7) `sha256:348476a3d934caa32932f9c75c6ee77eb09cdb75f2f311cc118f94452eca15c0` * [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere) git [557fdf1a](https://github.com/openshift/cluster-api-provider-vsphere/commit/557fdf1a9a3540d9aa8f3a81e4a950673a416a80) `sha256:8e11870664e845ac54cd6825962fbd198307135abdc4a2b3e8cc8d335685c1e9` * [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator) git [aa279467](https://github.com/openshift/vmware-vsphere-csi-driver-operator/commit/aa27946700642a9c8e518e130673097b38a2f8bb) `sha256:6fa61029f060bdf0cfbc5ecf0d94376c70b6f8938cea41123540d1fcf43b05d4` * [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector) git [14a2d338](https://github.com/openshift/vsphere-problem-detector/commit/14a2d33817c1ddd1d753cc76decea059376e30c9) `sha256:8f35dcfb6128b54dbfc9f2a4a5c3dafb666aff65f878500c0c0fd37e1568f200` ### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/8177722b388c34c334961352e9ab471ed4f8e95c) * [OCPBUGS-87328](https://issues.redhat.com/browse/OCPBUGS-87328): Updating ose-agent-installer-api-server-container image to be consistent with ART for 5.0 [#10434](https://github.com/openshift/assisted-service/pull/10434) * [OCPBUGS-120841](https://issues.redhat.com/browse/OCPBUGS-120841): Fix NUMAResourcesOperator CR name so it can be applied [#10923](https://github.com/openshift/assisted-service/pull/10923) * [OCPBUGS-107941](https://issues.redhat.com/browse/OCPBUGS-107941): Bump go.opentelemetry.io/otel to v1.44.0 for CVE-2026-41178 [#10855](https://github.com/openshift/assisted-service/pull/10855) * [OCPBUGS-120739](https://issues.redhat.com/browse/OCPBUGS-120739): added missing subscription name for lvms-operator [#10916](https://github.com/openshift/assisted-service/pull/10916) * [Full changelog](https://github.com/openshift/assisted-service/compare/a6888f164db6d9eb0eda1a18269ad1b6b97a6261...8177722b388c34c334961352e9ab471ed4f8e95c) ### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/fa7eb52b083a161b122e1c543d487edb3de0955c) * [OCPBUGS-87444](https://issues.redhat.com/browse/OCPBUGS-87444): Updating ose-agent-installer-csr-approver-container image to be consistent with ART for 5.0 [#2173](https://github.com/openshift/assisted-installer/pull/2173) * [OCPBUGS-87377](https://issues.redhat.com/browse/OCPBUGS-87377): Updating ose-agent-installer-orchestrator-container image to be consistent with ART for 5.0 [#2172](https://github.com/openshift/assisted-installer/pull/2172) * [Full changelog](https://github.com/openshift/assisted-installer/compare/880389d450131a12a888202877b28dbae61ac0da...fa7eb52b083a161b122e1c543d487edb3de0955c) ### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/b1d92ca20c3a276744861d8fb77745bb8f42ea9a) * [OCPBUGS-87404](https://issues.redhat.com/browse/OCPBUGS-87404): Updating ose-agent-installer-node-agent-container image to be consistent with ART for 5.0 [#1491](https://github.com/openshift/assisted-installer-agent/pull/1491) * [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/aeec165131a4c528174a58a011d1c3c31cfd7cc1...b1d92ca20c3a276744861d8fb77745bb8f42ea9a) ### [agent-installer-ui](https://github.com/openshift-assisted/assisted-installer-ui/tree/d085665f508757802bb8686c3dd39a8f1088fc06) * [OCPBUGS-121378](https://issues.redhat.com/browse/OCPBUGS-121378): Do not show IRI custom manifests in the disconnected UI (#4048) (#4053) [#4048](https://github.com/openshift-assisted/assisted-installer-ui/pull/4048) * Remove stale OCM_REFRESH_TOKEN code (#4024) [#4024](https://github.com/openshift-assisted/assisted-installer-ui/pull/4024) * [OCPBUGS-115122](https://issues.redhat.com/browse/OCPBUGS-115122): Show IPv6 Technology Preview badge in Subnets dropdown for single-cluster only (#4039) [#4039](https://github.com/openshift-assisted/assisted-installer-ui/pull/4039) * [OCPBUGS-120719](https://issues.redhat.com/browse/OCPBUGS-120719): Change reuse SSH key label in OVE (#4037) [#4037](https://github.com/openshift-assisted/assisted-installer-ui/pull/4037) * Add LVM as an operator for OVE (#4004) [#4004](https://github.com/openshift-assisted/assisted-installer-ui/pull/4004) * Allow LSO to be selected as a standalone operator (#4002) [#4002](https://github.com/openshift-assisted/assisted-installer-ui/pull/4002) * Update OWNERS file (#3995) [#3995](https://github.com/openshift-assisted/assisted-installer-ui/pull/3995) * [Full changelog](https://github.com/openshift-assisted/assisted-installer-ui/compare/93a1cdfd9a5f0a4b6be2f1fac45e151b7658d2d4...d085665f508757802bb8686c3dd39a8f1088fc06) ### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/6fe56d037dc82c8babc6d70228dc89d3606385cd) * 🌱 OCPBUGS-119953: UPSTREAM: <carry>: Remove upstream .github files unused in OpenShift CI [#634](https://github.com/openshift/cluster-api-provider-aws/pull/634) * [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/e345a83efda50037cd59ae0741a62cf7169f5def...6fe56d037dc82c8babc6d70228dc89d3606385cd) ### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, csi-driver-manila-operator, gcp-pd-csi-driver-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/57a5d72c6758cccafb9f14b1c28d1b2ea4510364) * [OCPBUGS-120666](https://issues.redhat.com/browse/OCPBUGS-120666): fix(gcp-pd): do not apply guest-cluster resources against the management cluster on HyperShift [#623](https://github.com/openshift/csi-operator/pull/623) * [OCPBUGS-114002](https://issues.redhat.com/browse/OCPBUGS-114002): GCP-1074: feat(gcp-pd): enable HyperShift support for GCP PD CSI driver operator [#607](https://github.com/openshift/csi-operator/pull/607) * [OCPBUGS-111893](https://issues.redhat.com/browse/OCPBUGS-111893): Add proxy hook for HyperShift CSI driver controller deployments [#599](https://github.com/openshift/csi-operator/pull/599) * [Full changelog](https://github.com/openshift/csi-operator/compare/9ce1841451cafd77907d38c9bf6062aeccf24eaf...57a5d72c6758cccafb9f14b1c28d1b2ea4510364) ### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/d04b52621a47868d907e986b37a01fcddeb8a23f) * [OCPBUGS-115308](https://issues.redhat.com/browse/OCPBUGS-115308): default max-pods to 250 for Custom AMI family [#42](https://github.com/openshift/aws-karpenter-provider-aws/pull/42) * [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/dc822233cc526b6cc55f20009a4c1b034f245133...d04b52621a47868d907e986b37a01fcddeb8a23f) ### [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler/tree/9b33cce5107d71df5c65dbca6c08f1f71d9e6e8a) * [OCPBUGS-87280](https://issues.redhat.com/browse/OCPBUGS-87280): Updating aws-node-termination-handler-container image to be consistent with ART for 5.0 [#11](https://github.com/openshift/aws-node-termination-handler/pull/11) * [Full changelog](https://github.com/openshift/aws-node-termination-handler/compare/e4ff2aaec292db42de9f3eef4908ba1c421a2a6c...9b33cce5107d71df5c65dbca6c08f1f71d9e6e8a) ### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/95f0a12ce3f7f3770d099d3610a376f06cc713df) * [OCPBUGS-122326](https://issues.redhat.com/browse/OCPBUGS-122326): skip public ip check for azure stack [#216](https://github.com/openshift/cloud-provider-azure/pull/216) * [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/b99e4ce4ff5c2665b273384b0673824833c40ce5...95f0a12ce3f7f3770d099d3610a376f06cc713df) ### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/64091ea10ac93fd62b83c63b4b7379063aca9058) * [OCPBUGS-121351](https://issues.redhat.com/browse/OCPBUGS-121351): UPSTREAM: 3754: chore: upgrade Azure cloud provider lib- [#181](https://github.com/openshift/azure-disk-csi-driver/pull/181) * [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/c5e303bb0c6a55332637d7a583cfceec1a3a900b...64091ea10ac93fd62b83c63b4b7379063aca9058) ### [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms/tree/6409e379fa979104a9515108608c22492bb803a7) * [CNTRLPLANE-4025](https://issues.redhat.com/browse/CNTRLPLANE-4025): support sovereign Managed HSM endpoints [#55](https://github.com/openshift/azure-kubernetes-kms/pull/55) * [Full changelog](https://github.com/openshift/azure-kubernetes-kms/compare/f7f447daa864d71c16d8ccb312b2fce91ebc0c2f...6409e379fa979104a9515108608c22492bb803a7) ### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/2060c6b26391f7dacd6fe19920b8b267f5f8f8b9) * [OCPBUGS-126682](https://issues.redhat.com/browse/OCPBUGS-126682): Inject the pull-secret as podman secret in the agent-installer-ui container [#10887](https://github.com/openshift/installer/pull/10887) * [OCPBUGS-120677](https://issues.redhat.com/browse/OCPBUGS-120677): vsphere: retry and throttle vCenter lookups during UPI VM creation [#10849](https://github.com/openshift/installer/pull/10849) * [OCPBUGS-115147](https://issues.redhat.com/browse/OCPBUGS-115147): Missing ability to not install Network Observability during installation [#10822](https://github.com/openshift/installer/pull/10822) * [OCPBUGS-114620](https://issues.redhat.com/browse/OCPBUGS-114620): bump openshift api for gcd feature gate [#10845](https://github.com/openshift/installer/pull/10845) * [OCPBUGS-119104](https://issues.redhat.com/browse/OCPBUGS-119104): gcp: allow GCD load balancer health-check firewall ranges [#10852](https://github.com/openshift/installer/pull/10852) * Revert "TRT-2925: Revert "CORS-4441: Bump Azure Marketplace Images" (#10802)" [#10819](https://github.com/openshift/installer/pull/10819) * [TRT-2925](https://issues.redhat.com/browse/TRT-2925): Revert "CORS-4441: Bump Azure Marketplace Images" (#10802) [#10814](https://github.com/openshift/installer/pull/10814) * [OCPBUGS-113634](https://issues.redhat.com/browse/OCPBUGS-113634): images: add BUILD_VERSION arg [#10801](https://github.com/openshift/installer/pull/10801) * [CORS-4441](https://issues.redhat.com/browse/CORS-4441): Bump Azure Marketplace Images [#10802](https://github.com/openshift/installer/pull/10802) * [OCPBUGS-113641](https://issues.redhat.com/browse/OCPBUGS-113641): Update timeout in GetMarketplaceImage to 5 minutes [#10803](https://github.com/openshift/installer/pull/10803) * [Full changelog](https://github.com/openshift/installer/compare/4f7b5547859546c12e3250b56728a78d923d8c3b...2060c6b26391f7dacd6fe19920b8b267f5f8f8b9) ### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/3a261a6f4a6211e8f4031611104ced4def436dde) * [OCPBUGS-112466](https://issues.redhat.com/browse/OCPBUGS-112466): Cloud Platforms: Filter out node's own IP from Upstreams [#400](https://github.com/openshift/baremetal-runtimecfg/pull/400) * [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/75dd020cfa556db528be28e0fd456aaa023a973e...3a261a6f4a6211e8f4031611104ced4def436dde) ### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/848c4c96d8e322b7987e44eecc4ad30e64ce5ed4) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#998](https://github.com/openshift/cluster-authentication-operator/pull/998) * [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/954abf76eb0000ff218257489783c8e61dc115b8...848c4c96d8e322b7987e44eecc4ad30e64ce5ed4) ### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/d7957265fdafbbb93bb2a0d4723fc9719da1378d) * [OCPBUGS-123600](https://issues.redhat.com/browse/OCPBUGS-123600): Add bmo_validations and ncsi_reject_poweroff OTE test [#657](https://github.com/openshift/cluster-baremetal-operator/pull/657) * [OCPBUGS-115281](https://issues.redhat.com/browse/OCPBUGS-115281): Increase firmware e2e timeouts and add HPE Mellanox NIC bastion mapping [#651](https://github.com/openshift/cluster-baremetal-operator/pull/651) * [OCPBUGS-114007](https://issues.redhat.com/browse/OCPBUGS-114007): Add batched firmware update tests (bmc+bios+nic) [#648](https://github.com/openshift/cluster-baremetal-operator/pull/648) * [OCPBUGS-111889](https://issues.redhat.com/browse/OCPBUGS-111889): drop IRONIC_INSECURE from BMO [#644](https://github.com/openshift/cluster-baremetal-operator/pull/644) * [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/ce1bd1f1ff5eb9335f13fa3839add119bb51f946...d7957265fdafbbb93bb2a0d4723fc9719da1378d) ### [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap/tree/9573b4d6ef1638c013cde95ec29ddcc80e10cf87) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#147](https://github.com/openshift/cluster-bootstrap/pull/147) * [OCPBUGS-87218](https://issues.redhat.com/browse/OCPBUGS-87218): Updating ose-cluster-bootstrap-container image to be consistent with ART for 5.0 [#132](https://github.com/openshift/cluster-bootstrap/pull/132) * [Full changelog](https://github.com/openshift/cluster-bootstrap/compare/7b1593a47898b6a97dc457efaca464624e9f2afa...9573b4d6ef1638c013cde95ec29ddcc80e10cf87) ### [cluster-config-api](https://github.com/openshift/api/tree/31af9f93e31ecd483504b3302d78f67c5a077a9e) * [OCPBUGS-114877](https://issues.redhat.com/browse/OCPBUGS-114877): move empty CRIOCredentialProviderConfig CR to run-level 0000_10 [#3019](https://github.com/openshift/api/pull/3019) * [OCPBUGS-114620](https://issues.redhat.com/browse/OCPBUGS-114620): Promote GCD to Default [#3017](https://github.com/openshift/api/pull/3017) * [OCPBUGS-83412](https://issues.redhat.com/browse/OCPBUGS-83412): Disable PSA for placeholder for 5.0 [#3002](https://github.com/openshift/api/pull/3002) * [OCPBUGS-112657](https://issues.redhat.com/browse/OCPBUGS-112657): Handle Sippy date-only format in featuregate-test-analyzer [#3007](https://github.com/openshift/api/pull/3007) * [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default for Hypershift [#2997](https://github.com/openshift/api/pull/2997) * [TRT-2908](https://issues.redhat.com/browse/TRT-2908): Revert openshift/api#2986 [#2992](https://github.com/openshift/api/pull/2992) * [CNTRLPLANE-3609](https://issues.redhat.com/browse/CNTRLPLANE-3609): graduate etcdBackendQuota to GA [#2987](https://github.com/openshift/api/pull/2987) * [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default for Hypershift [#2986](https://github.com/openshift/api/pull/2986) * [Full changelog](https://github.com/openshift/api/compare/dffcf504e2ea64d417e0778229b7be6df398a9be...31af9f93e31ecd483504b3302d78f67c5a077a9e) ### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/324996d8fff21db132e0c4764600d4720adab4be) * [OCPBUGS-87358](https://issues.redhat.com/browse/OCPBUGS-87358): Updating ose-cluster-config-operator-container image to be consistent with ART for 5.0 [#493](https://github.com/openshift/cluster-config-operator/pull/493) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#502](https://github.com/openshift/cluster-config-operator/pull/502) * [Full changelog](https://github.com/openshift/cluster-config-operator/compare/9f787f73f5fffca5cd511ef2c2e704afc14f68ce...324996d8fff21db132e0c4764600d4720adab4be) ### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/c00cf58dd81954ca100757f6a2d2af8d84770fd5) * [OCPBUGS-115467](https://issues.redhat.com/browse/OCPBUGS-115467): Guard against empty workspace field on vsphere [#419](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/419) * [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/14e9821d573de4c9771d87c0772b81b82565efb8...c00cf58dd81954ca100757f6a2d2af8d84770fd5) ### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/73835ffac883949ae5fcea3fd9eb0f4076ae711a) * [OCPBUGS-123640](https://issues.redhat.com/browse/OCPBUGS-123640): fix: add missing workload paritioning annotation on cert-watcher daemonset [#1709](https://github.com/openshift/cluster-etcd-operator/pull/1709) * [OCPBUGS-121354](https://issues.redhat.com/browse/OCPBUGS-121354): feat: add cert-watcher DaemonSet to restart etcd on CA bundle rotation [#1702](https://github.com/openshift/cluster-etcd-operator/pull/1702) * [OCPBUGS-111703](https://issues.redhat.com/browse/OCPBUGS-111703): Fix tnf_cluster_in_service during per-node maintenance [#1681](https://github.com/openshift/cluster-etcd-operator/pull/1681) * [OCPBUGS-114671](https://issues.redhat.com/browse/OCPBUGS-114671): fall back to intermediate ciphers during etcd bootstrap [#1690](https://github.com/openshift/cluster-etcd-operator/pull/1690) * [OCPBUGS-111300](https://issues.redhat.com/browse/OCPBUGS-111300): Derive console notification docs URL from cluster version [#1679](https://github.com/openshift/cluster-etcd-operator/pull/1679) * [CNTRLPLANE-4136](https://issues.redhat.com/browse/CNTRLPLANE-4136): update api to pull in etcd db ga [#1682](https://github.com/openshift/cluster-etcd-operator/pull/1682) * [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/6b88b761570ac42e18919ff9ee92f9c726799697...73835ffac883949ae5fcea3fd9eb0f4076ae711a) ### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/b6d3329d7059adba44dd0c3e9c0e9da264f9a551) * [OCPBUGS-121350](https://issues.redhat.com/browse/OCPBUGS-121350): imageconfig: Preserve ImageStreamImportMode during upgrade race [#1367](https://github.com/openshift/cluster-image-registry-operator/pull/1367) * [OCPBUGS-100042](https://issues.redhat.com/browse/OCPBUGS-100042): Updating ose-cluster-image-registry-operator-container image to be consistent with ART for 5.0 [#1359](https://github.com/openshift/cluster-image-registry-operator/pull/1359) * [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/94cd22d000c8b8eef24dd43cd05d06544df24930...b6d3329d7059adba44dd0c3e9c0e9da264f9a551) ### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/fe8a2bcf6342fab7aa19c47b4397a7d226962136) * [OCPBUGS-114134](https://issues.redhat.com/browse/OCPBUGS-114134): Preserve server-defaulted fields on init containers and volumes [#1563](https://github.com/openshift/cluster-ingress-operator/pull/1563) * [OCPBUGS-109738](https://issues.redhat.com/browse/OCPBUGS-109738): Add BackendTLSPolicy and ReferenceGrant e2e test coverage helpers [#1550](https://github.com/openshift/cluster-ingress-operator/pull/1550) * [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/5b9c7adbbda37bd3f5eb3b049993a0ab320958c5...fe8a2bcf6342fab7aa19c47b4397a7d226962136) ### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/b8c26db7c7c7e49476235ec83b2e81ef0996e242) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#2311](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2311) * [OCPBUGS-83400](https://issues.redhat.com/browse/OCPBUGS-83400): revert dev cert rotation [#2272](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2272) * [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/57553b18b7cdc53a203ee5e4b25968a3b0ac42ef...b8c26db7c7c7e49476235ec83b2e81ef0996e242) ### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/1ee372e7019b41fbcb4c64323142c4a06bf266d0) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#968](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/968) * [OCPBUGS-111832](https://issues.redhat.com/browse/OCPBUGS-111832): Updating ose-cluster-kube-controller-manager-operator-container image to be consistent with ART for 5.0 [#954](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/954) * [OCPBUGS-112788](https://issues.redhat.com/browse/OCPBUGS-112788): fix CVE-2026-41178 [#957](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/957) * [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/8db74e3fe8793043d942ef1f59cce3b0a0bcc548...1ee372e7019b41fbcb4c64323142c4a06bf266d0) ### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/e0d271fceb3727138177e017f860a8ff79738bb3) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#677](https://github.com/openshift/cluster-kube-scheduler-operator/pull/677) * [OCPBUGS-113761](https://issues.redhat.com/browse/OCPBUGS-113761): bump otel to v1.44.0 to fix CVE-2026-41178 [#663](https://github.com/openshift/cluster-kube-scheduler-operator/pull/663) * [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3...e0d271fceb3727138177e017f860a8ff79738bb3) ### [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/tree/ec1db56482efc9dced72b44a1c2b6817dbfffe91) * [OCPBUGS-87479](https://issues.redhat.com/browse/OCPBUGS-87479): Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART for 5.0 [#178](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/178) * [Full changelog](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/compare/f5d3bfe64bda67ffb8299af01ebf2722287edf04...ec1db56482efc9dced72b44a1c2b6817dbfffe91) ### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/11c03d0952f281ca9cfb62e528e5a0e24ae644ab) * [OCPBUGS-113529](https://issues.redhat.com/browse/OCPBUGS-113529): Always validate EgressIPs [#315](https://github.com/openshift/cluster-machine-approver/pull/315) * [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/cdf27353008200166f1ad754c4ade033370077ae...11c03d0952f281ca9cfb62e528e5a0e24ae644ab) ### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/efeeabf10a9c46f7a82086d2c04c9fc6d93a2b22) * [OCPBUGS-112571](https://issues.redhat.com/browse/OCPBUGS-112571): Makefile: version-stamp golangci-lint binary to prevent stale linter [#3061](https://github.com/openshift/cluster-monitoring-operator/pull/3061) * [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/942c2dad78d6c22c4e19a375515b17a68b3f6007...efeeabf10a9c46f7a82086d2c04c9fc6d93a2b22) ### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/3b484353063fe95156373f7cf51c5ba13f501256) * [OCPBUGS-115428](https://issues.redhat.com/browse/OCPBUGS-115428): Adds rendering of enable-multi-network-policy in ovnkube-node [#3149](https://github.com/openshift/cluster-network-operator/pull/3149) * [OCPBUGS-107980](https://issues.redhat.com/browse/OCPBUGS-107980): CVE-2026-41178 - bump go.opentelemetry.io/otel to v1.44.0 [#3133](https://github.com/openshift/cluster-network-operator/pull/3133) * [OCPBUGS-115064](https://issues.redhat.com/browse/OCPBUGS-115064): Install NOO using OLMv0 instead of OLMv1 [#3143](https://github.com/openshift/cluster-network-operator/pull/3143) * [OCPBUGS-115900](https://issues.redhat.com/browse/OCPBUGS-115900): CNF-26697: [release-5.0] CORENET-7330: Allow per-node OVN encap IP override via env-overrides [#3124](https://github.com/openshift/cluster-network-operator/pull/3124) * [OCPBUGS-105887](https://issues.redhat.com/browse/OCPBUGS-105887): [cherry-pick 5.0] Filter unsupported cipher suites to prevent ovnkube-identity crash [#3128](https://github.com/openshift/cluster-network-operator/pull/3128) * [OCPBUGS-111097](https://issues.redhat.com/browse/OCPBUGS-111097): Drop strategy.rollingUpdate and switch strategy.type to Recreate via pre-patch in frr-k8s-statuscleaner deployments on SNO [#3129](https://github.com/openshift/cluster-network-operator/pull/3129) * [Full changelog](https://github.com/openshift/cluster-network-operator/compare/c27dc71a8630e864970fd315f3e749a30950fb42...3b484353063fe95156373f7cf51c5ba13f501256) ### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/ea084dcf2a92e08a6686e89da49738383bbefd39) * [OCPBUGS-123511](https://issues.redhat.com/browse/OCPBUGS-123511): e2e: make OVS dynamic pinning tests compatible with ovsDpdk CPUs [#1631](https://github.com/openshift/cluster-node-tuning-operator/pull/1631) * [OCPBUGS-119931](https://issues.redhat.com/browse/OCPBUGS-119931): add optional --ovs-dpdk-cpu-count flag (default 0) [#1630](https://github.com/openshift/cluster-node-tuning-operator/pull/1630) * [OCPBUGS-114934](https://issues.redhat.com/browse/OCPBUGS-114934): Disable timer.migration on RHCOS 10 [#1625](https://github.com/openshift/cluster-node-tuning-operator/pull/1625) * [OCPBUGS-114144](https://issues.redhat.com/browse/OCPBUGS-114144): Update PPC help description [#1617](https://github.com/openshift/cluster-node-tuning-operator/pull/1617) * [OCPBUGS-104311](https://issues.redhat.com/browse/OCPBUGS-104311): Bump golang.org/x/net [#1600](https://github.com/openshift/cluster-node-tuning-operator/pull/1600) * [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/258062a23f0cba08eaf4d7f39b1594fadae8ecd1...ea084dcf2a92e08a6686e89da49738383bbefd39) ### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/d56fffed57ce229b53b4cb1eba63311360051806) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#771](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/771) * [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/28420873a3c92985df8ec089e6513b16c4f2f3a0...d56fffed57ce229b53b4cb1eba63311360051806) ### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/ba80c7efd89885b08dc890eb5aefb994ee1e7ab9) * [OKD-425](https://issues.redhat.com/browse/OKD-425): Revert openliberty back to 26.0.0.6 [#711](https://github.com/openshift/cluster-samples-operator/pull/711) * [OCPBUGS-111886](https://issues.redhat.com/browse/OCPBUGS-111886): Fix python:latest and nodejs template references after UBI 8 tag removal - #707 [#707](https://github.com/openshift/cluster-samples-operator/pull/707) * [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/88b9454ff474a85de5ddddf803eeb0183f05b566...ba80c7efd89885b08dc890eb5aefb994ee1e7ab9) ### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/b2ee363241ad0425efd56badb6046884cadda97d) * [OCPBUGS-111892](https://issues.redhat.com/browse/OCPBUGS-111892): Pass management cluster proxy env vars to CSI driver operator deployments [#725](https://github.com/openshift/cluster-storage-operator/pull/725) * [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/b75f14a9bdea51838b1e7fd03f86cfb46580a103...b2ee363241ad0425efd56badb6046884cadda97d) ### [cluster-update-console-plugin](https://github.com/openshift/cluster-update-console-plugin/tree/8e684dc03729798295e1b2b059826a5a5abe76c8) * [OCPBUGS-100041](https://issues.redhat.com/browse/OCPBUGS-100041): Updating cluster-update-console-plugin-container image to be consistent with ART for 5.0 [#21](https://github.com/openshift/cluster-update-console-plugin/pull/21) * [Full changelog](https://github.com/openshift/cluster-update-console-plugin/compare/02b220dd2aef5c1788768178e3ffd8592ccb89b9...8e684dc03729798295e1b2b059826a5a5abe76c8) ### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/219aba7debd16c83bb6ccdccf156af921ce54dfe) * [OCPBUGS-122172](https://issues.redhat.com/browse/OCPBUGS-122172): pkg/readiness/cluster_conditions: Conditionally include Upgradeable [#1468](https://github.com/openshift/cluster-version-operator/pull/1468) * [OCPBUGS-112659](https://issues.redhat.com/browse/OCPBUGS-112659): Remove the CRB for the default openshift-cluster-version SA [#1454](https://github.com/openshift/cluster-version-operator/pull/1454) * [OCPBUGS-111971](https://issues.redhat.com/browse/OCPBUGS-111971): pkg/agenticrun/controller: Pivot to cluster-update-advisor directory [#1448](https://github.com/openshift/cluster-version-operator/pull/1448) * [Full changelog](https://github.com/openshift/cluster-version-operator/compare/f94dc81765de89b6610894a3994a8aa4724e9787...219aba7debd16c83bb6ccdccf156af921ce54dfe) ### [console](https://github.com/openshift/console/tree/0216b2de8b57c3375fcc161d2c75a031bef72c1b) * [OCPBUGS-114008](https://issues.redhat.com/browse/OCPBUGS-114008): Strip version tag from OCI chart URL to prevent doubl… [#17097](https://github.com/openshift/console/pull/17097) * [OCPBUGS-122258](https://issues.redhat.com/browse/OCPBUGS-122258): Handle Prometheus percentage strings [#17161](https://github.com/openshift/console/pull/17161) * [OCPBUGS-123616](https://issues.redhat.com/browse/OCPBUGS-123616): increase httpRetry and update yarn [#17181](https://github.com/openshift/console/pull/17181) * [OCPBUGS-123202](https://issues.redhat.com/browse/OCPBUGS-123202): Fix Namespace column hidden on Node Pods tab with active namespace [#17175](https://github.com/openshift/console/pull/17175) * [OCPBUGS-123647](https://issues.redhat.com/browse/OCPBUGS-123647): i18n upload/download routine task - version 4.23/5.0 [#17183](https://github.com/openshift/console/pull/17183) * [OCPBUGS-120694](https://issues.redhat.com/browse/OCPBUGS-120694): Installed Operators page fails with catalogsources "forbidden ... at the cluster scope" error [#17142](https://github.com/openshift/console/pull/17142) * [OCPBUGS-121974](https://issues.redhat.com/browse/OCPBUGS-121974): Migrate OLM Cypress tests to Playwright [#17149](https://github.com/openshift/console/pull/17149) * [OCPBUGS-120712](https://issues.redhat.com/browse/OCPBUGS-120712): Update stale comment [#17143](https://github.com/openshift/console/pull/17143) * [OCPBUGS-115209](https://issues.redhat.com/browse/OCPBUGS-115209): Fix webhook creation in Git for PAC [#17123](https://github.com/openshift/console/pull/17123) * [OCPBUGS-120668](https://issues.redhat.com/browse/OCPBUGS-120668): improve playwright reliability [#17138](https://github.com/openshift/console/pull/17138) * [OCPBUGS-115402](https://issues.redhat.com/browse/OCPBUGS-115402): Rename e2e scripts so playwright is the main one [#17129](https://github.com/openshift/console/pull/17129) * [OCPBUGS-115155](https://issues.redhat.com/browse/OCPBUGS-115155): move yarn install to prow scripts [#17122](https://github.com/openshift/console/pull/17122) * [OCPBUGS-112307](https://issues.redhat.com/browse/OCPBUGS-112307): Show CPU/Memory metrics for non-admin users on Projects page [#17053](https://github.com/openshift/console/pull/17053) * [OCPBUGS-114388](https://issues.redhat.com/browse/OCPBUGS-114388): display operators in catalog when Tech Preview enabled [#17100](https://github.com/openshift/console/pull/17100) * [OCPBUGS-113650](https://issues.redhat.com/browse/OCPBUGS-113650): Helm chart is created in incorrect namespace [#17085](https://github.com/openshift/console/pull/17085) * [OCPBUGS-113704](https://issues.redhat.com/browse/OCPBUGS-113704): Helm test setup: revert silent skip and restore panic on infrastructure failure [#17087](https://github.com/openshift/console/pull/17087) * [OCPBUGS-112325](https://issues.redhat.com/browse/OCPBUGS-112325): 'Edit Machine count' from action list doesn't work [#17061](https://github.com/openshift/console/pull/17061) * [OCPBUGS-112467](https://issues.redhat.com/browse/OCPBUGS-112467): Remove empty integration-tests package from CI [#17068](https://github.com/openshift/console/pull/17068) * [OCPBUGS-111972](https://issues.redhat.com/browse/OCPBUGS-111972): Fix plugin entrypoint failing to load [#17033](https://github.com/openshift/console/pull/17033) * [OCPBUGS-112288](https://issues.redhat.com/browse/OCPBUGS-112288): Migrate app/ Cypress e2e tests to Playwright [#17049](https://github.com/openshift/console/pull/17049) * [OCPBUGS-112327](https://issues.redhat.com/browse/OCPBUGS-112327): Helm backend tests flake due to chartmuseum/zot failing to bind ports in CI [#17062](https://github.com/openshift/console/pull/17062) * [OCPBUGS-112268](https://issues.redhat.com/browse/OCPBUGS-112268): Keep OLS cluster-update prompts within OpenAI 32k limit [#17044](https://github.com/openshift/console/pull/17044) * [OCPBUGS-112088](https://issues.redhat.com/browse/OCPBUGS-112088): Migrate secrets e2e tests from Cypress to Playwright [#17043](https://github.com/openshift/console/pull/17043) * [OCPBUGS-111928](https://issues.redhat.com/browse/OCPBUGS-111928): Shared Playwright e2e context and test generation skill [#17023](https://github.com/openshift/console/pull/17023) * [OCPBUGS-111921](https://issues.redhat.com/browse/OCPBUGS-111921): make cloud provider fields optional during operator install [#17022](https://github.com/openshift/console/pull/17022) * [OCPBUGS-112009](https://issues.redhat.com/browse/OCPBUGS-112009): Fix flaky TestAsyncCache backend test due to timing-dependent assertions [#17037](https://github.com/openshift/console/pull/17037) * And 4 elided commits (e.g. from squash or rebase merges) * [Full changelog](https://github.com/openshift/console/compare/68185f46a763099efa0c89e06074e79a53193854...0216b2de8b57c3375fcc161d2c75a031bef72c1b) ### [container-networking-plugins, containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins/tree/d253ee09d629b8172ffc9c3e4b571320fc63ee34) * [OCPBUGS-114407](https://issues.redhat.com/browse/OCPBUGS-114407): Remove rhel8 build stage [#247](https://github.com/openshift/containernetworking-plugins/pull/247) * [Full changelog](https://github.com/openshift/containernetworking-plugins/compare/d6f73950658d258e0ddbf2a4ac92e13ac840158b...d253ee09d629b8172ffc9c3e4b571320fc63ee34) ### [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata/tree/b929f29695d4a1ab21a70868f681d463a673380f) * [OCPBUGS-104319](https://issues.redhat.com/browse/OCPBUGS-104319): Bump golang.org/x/net to v0.53.0 and Go to 1.25.10 [#23](https://github.com/openshift/csi-external-snapshot-metadata/pull/23) * [Full changelog](https://github.com/openshift/csi-external-snapshot-metadata/compare/239703c637e005cf785892d214d219add70e3533...b929f29695d4a1ab21a70868f681d463a673380f) ### [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe/tree/cab57d511106916bba6953977106f06b2fec01fd) * [OCPBUGS-107993](https://issues.redhat.com/browse/OCPBUGS-107993): Bump go.opentelemetry.io/otel to v1.44.0 to address CVE-2026-41178 [#95](https://github.com/openshift/csi-livenessprobe/pull/95) * [Full changelog](https://github.com/openshift/csi-livenessprobe/compare/463dc553ebb04df192d573c5a1612dcb50cb1f52...cab57d511106916bba6953977106f06b2fec01fd) ### [docker-builder](https://github.com/openshift/builder/tree/1e53243554dead3d84297e341651c5eb83eb37a4) * [OCPBUGS-95492](https://issues.redhat.com/browse/OCPBUGS-95492), [OCPBUGS-98108](https://issues.redhat.com/browse/OCPBUGS-98108): Bump golang.org/x/crypto to fix CVE-2025-22869,CVE-2025-47913,CVE-2026-46597,CVE-2026-39829,CVE-2026-39832 [#550](https://github.com/openshift/builder/pull/550) * [OCPBUGS-87365](https://issues.redhat.com/browse/OCPBUGS-87365): Updating openshift-enterprise-builder-container image to be consistent with ART for 5.0 [#539](https://github.com/openshift/builder/pull/539) * [Full changelog](https://github.com/openshift/builder/compare/2cda03a93696d4620703848471b3b873b0b2fa1e...1e53243554dead3d84297e341651c5eb83eb37a4) ### [docker-registry](https://github.com/openshift/image-registry/tree/9436b2271fc9b687bda31e335bacc4031dcba80a) * [OCPBUGS-87287](https://issues.redhat.com/browse/OCPBUGS-87287): Updating openshift-enterprise-registry-container image to be consistent with ART for 5.0 [#472](https://github.com/openshift/image-registry/pull/472) * [Full changelog](https://github.com/openshift/image-registry/compare/a91ce6edf2c5cc08aa184c47dff79e842079c533...9436b2271fc9b687bda31e335bacc4031dcba80a) ### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/bc639044a3aee89f1f9547ad0539481b8d808516) * [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Update Dockerfiles [#113](https://github.com/openshift/egress-router-cni/pull/113) * [Full changelog](https://github.com/openshift/egress-router-cni/compare/7b9f54aff1a90ba59242b305fb628db9f20d1d2c...bc639044a3aee89f1f9547ad0539481b8d808516) ### [hyperkube, kube-proxy, pod](https://github.com/openshift/kubernetes/tree/b376ee7b841bed5a51cb9520b37d87931c48a821) * [OCPBUGS-108014](https://issues.redhat.com/browse/OCPBUGS-108014): UPSTREAM: <carry>: bump otel to v1.44.0 to fix CVE-2026-41178 [#2762](https://github.com/openshift/kubernetes/pull/2762) * NO-JIRA: Make graceful-termination-duration flag required for the watch-termination command [#2763](https://github.com/openshift/kubernetes/pull/2763) * [Full changelog](https://github.com/openshift/kubernetes/compare/7b29fb077260554429dcef8234272e9fd25fcfbd...b376ee7b841bed5a51cb9520b37d87931c48a821) ### [hypershift](https://github.com/openshift/hypershift/tree/f17305a432f02f3352c052c717e98db730a6edb4) * [ACM-41684](https://issues.redhat.com/browse/ACM-41684): Switch hypershift-operator runtime to PQC base image [#9590](https://github.com/openshift/hypershift/pull/9590) * [OCPBUGS-112730](https://issues.redhat.com/browse/OCPBUGS-112730): fix(certs): normalize IP SANs to stop dual-stack KAS cert churn [#9495](https://github.com/openshift/hypershift/pull/9495) * [OCPBUGS-122229](https://issues.redhat.com/browse/OCPBUGS-122229): filter AWS-reserved tag keys before calling DeleteTags [#9576](https://github.com/openshift/hypershift/pull/9576) * [OCPBUGS-123150](https://issues.redhat.com/browse/OCPBUGS-123150): [release-5.0] [CNTRLPLANE-3626](https://redhat.atlassian.net/browse/CNTRLPLANE-3626): feat(ignition-server, ignition-server-proxy): inject centralized TLS configuration [#9408](https://github.com/openshift/hypershift/pull/9408) * [OCPBUGS-123793](https://issues.redhat.com/browse/OCPBUGS-123793): Use multiarch CI build root on release-5.0 [#9633](https://github.com/openshift/hypershift/pull/9633) * [OCPBUGS-123146](https://issues.redhat.com/browse/OCPBUGS-123146): Updating ose-hypershift-container image to be consistent with ART for 5.0 [#9597](https://github.com/openshift/hypershift/pull/9597) * [OCPBUGS-117010](https://issues.redhat.com/browse/OCPBUGS-117010): preserve immutable AWS load balancer annotations [#9489](https://github.com/openshift/hypershift/pull/9489) * [OCPBUGS-114435](https://issues.redhat.com/browse/OCPBUGS-114435): fix(konnectivity): enable --sync-forever to restore lost agent-server tunnels [#9430](https://github.com/openshift/hypershift/pull/9430) * [OCPBUGS-113998](https://issues.redhat.com/browse/OCPBUGS-113998): fix(azure): skip KMS validation for private Key Vaults on ARO HCP [#9405](https://github.com/openshift/hypershift/pull/9405) * [OCPBUGS-115188](https://issues.redhat.com/browse/OCPBUGS-115188), [OCPBUGS-121650](https://issues.redhat.com/browse/OCPBUGS-121650): backport safe-to-evict annotation and operator health probes fixes [#9534](https://github.com/openshift/hypershift/pull/9534) * [OCPBUGS-98883](https://issues.redhat.com/browse/OCPBUGS-98883), [OCPBUGS-98887](https://issues.redhat.com/browse/OCPBUGS-98887): bump haproxy to 3.0.5-6.el10_2.2 for CVE fix [#9336](https://github.com/openshift/hypershift/pull/9336) * [OCPBUGS-111891](https://issues.redhat.com/browse/OCPBUGS-111891): Add proxy env vars to cluster-storage-operator deployment [#9332](https://github.com/openshift/hypershift/pull/9332) * [ACM-41685](https://issues.redhat.com/browse/ACM-41685): Enable PQC crypto policy in hypershift-cli image [#9462](https://github.com/openshift/hypershift/pull/9462) * [CNTRLPLANE-4025](https://issues.redhat.com/browse/CNTRLPLANE-4025): feat(azure): support managed HSM for KMS encryption [#9376](https://github.com/openshift/hypershift/pull/9376) * [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default [#9372](https://github.com/openshift/hypershift/pull/9372) * [Full changelog](https://github.com/openshift/hypershift/compare/a7fbf215c7593a7f374b0cae9deaa7bc6a176874...f17305a432f02f3352c052c717e98db730a6edb4) ### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/3604a6c42f3002800e5cad2a012aacaf9b5f7405) * [OCPBUGS-108009](https://issues.redhat.com/browse/OCPBUGS-108009): UPSTREAM: 2933: Bump all go.opentelemetry.io/otel modules to v1.44.0 [#186](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/186) * [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/286dd2de7957e9c2897e152417f16907d324d819...3604a6c42f3002800e5cad2a012aacaf9b5f7405) ### [insights-operator](https://github.com/openshift/insights-operator/tree/2f616dc436db2e35d70c9a049be98c185f684243) * [OCPBUGS-111992](https://issues.redhat.com/browse/OCPBUGS-111992): add custom proxy field to insights config [#1346](https://github.com/openshift/insights-operator/pull/1346) * [OCPBUGS-112481](https://issues.redhat.com/browse/OCPBUGS-112481): Add multicluster gatherer [#1349](https://github.com/openshift/insights-operator/pull/1349) * [Full changelog](https://github.com/openshift/insights-operator/compare/8494b69b8075fd1e8eac49db77bcda7588078155...2f616dc436db2e35d70c9a049be98c185f684243) ### [ironic](https://github.com/openshift/ironic-image/tree/b5082f7909065eb50306af483309e756557f7a60) * Bug OCPBUGS-123709: Bumping sushy hash to include jobstate fixes [#914](https://github.com/openshift/ironic-image/pull/914) * NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#897](https://github.com/openshift/ironic-image/pull/897) * [Full changelog](https://github.com/openshift/ironic-image/compare/001adec7884e75a5078e4e72c8bc8d2a51376b43...b5082f7909065eb50306af483309e756557f7a60) ### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/601c9bf36bbc4a0796c4c55e59bfe3cc46252ed3) * [METAL-1931](https://issues.redhat.com/browse/METAL-1931): [5.0] Add cargo for bcrypt rust extensions [#305](https://github.com/openshift/ironic-agent-image/pull/305) * [Full changelog](https://github.com/openshift/ironic-agent-image/compare/8eb658a0ad45b0d826e36dbeb6d5b2b731762975...601c9bf36bbc4a0796c4c55e59bfe3cc46252ed3) ### [keepalived-ipfailover](https://github.com/openshift/images/tree/3f1cf0830f196a6755b8baf179fc0401188251c4) * [OCPBUGS-87506](https://issues.redhat.com/browse/OCPBUGS-87506): Updating openshift-enterprise-keepalived-ipfailover-container image to be consistent with ART for 5.0 [#238](https://github.com/openshift/images/pull/238) * [Full changelog](https://github.com/openshift/images/compare/32930575a2bb3571601a7444becc06d06e901657...3f1cf0830f196a6755b8baf179fc0401188251c4) ### [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator/tree/05d6b0c4537954b2b115c793646fb598756bb303) * [OCPBUGS-87255](https://issues.redhat.com/browse/OCPBUGS-87255): Updating ose-kube-storage-version-migrator-container image to be consistent with ART for 5.0 [#243](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/243) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#260](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/260) * [Full changelog](https://github.com/openshift/kubernetes-kube-storage-version-migrator/compare/72835e43c7754356645e41031f3a99926b4d42e6...05d6b0c4537954b2b115c793646fb598756bb303) ### [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver/tree/00dd0030fdfcdb6937ebefd8fb92363a8f78ef73) * [OCPBUGS-87572](https://issues.redhat.com/browse/OCPBUGS-87572): Updating ose-kubevirt-csi-driver-container image to be consistent with ART for 5.0 [#106](https://github.com/openshift/kubevirt-csi-driver/pull/106) * [Full changelog](https://github.com/openshift/kubevirt-csi-driver/compare/7ff99994ecc3a675fac6f9aa7fa418cdb0dca32b...00dd0030fdfcdb6937ebefd8fb92363a8f78ef73) ### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/b3cabb0301b12a2b256bf8aed85c3f4c7b0dab3c) * [OCPBUGS-120320](https://issues.redhat.com/browse/OCPBUGS-120320): Compare against oldObject in vSphere failure-domain VAPs [#1540](https://github.com/openshift/machine-api-operator/pull/1540) * [Full changelog](https://github.com/openshift/machine-api-operator/compare/0db39ee372bf7b75f56898fd2df555e063d32952...b3cabb0301b12a2b256bf8aed85c3f4c7b0dab3c) ### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/ea7d971717f7c6fac339f5cf4ffbbccb23234edc) * [OCPBUGS-126703](https://issues.redhat.com/browse/OCPBUGS-126703): Add '..' block, max-length, and cross-store uniqueness [#6483](https://github.com/openshift/machine-config-operator/pull/6483) * [OCPBUGS-122238](https://issues.redhat.com/browse/OCPBUGS-122238): [TNF] Add infinite retry on untaint systemd unit [#6553](https://github.com/openshift/machine-config-operator/pull/6553) * [OCPBUGS-122915](https://issues.redhat.com/browse/OCPBUGS-122915): Mount /etc/container in mosb [#6537](https://github.com/openshift/machine-config-operator/pull/6537) * [OCPBUGS-122217](https://issues.redhat.com/browse/OCPBUGS-122217): Dump compact cache to CM for persistence [#6525](https://github.com/openshift/machine-config-operator/pull/6525) * [OCPBUGS-121942](https://issues.redhat.com/browse/OCPBUGS-121942): Replace wildcard permissions with explicit verbs in MachineConfigServer ClusterRole [#6514](https://github.com/openshift/machine-config-operator/pull/6514) * [OCPBUGS-123672](https://issues.redhat.com/browse/OCPBUGS-123672): Pass missing proxy vars to bootstrap MCC [#6548](https://github.com/openshift/machine-config-operator/pull/6548) * [OCPBUGS-114854](https://issues.redhat.com/browse/OCPBUGS-114854): CVE-2026-15792 openshift4/ose-machine-config-rhel9-operator: BuildKit: Denial of Service via malicious client request [openshift-5.0] [#6519](https://github.com/openshift/machine-config-operator/pull/6519) * [OCPBUGS-122284](https://issues.redhat.com/browse/OCPBUGS-122284): updateLayeredOS deploy-from-self when skopeo < 1.22.2 [#6534](https://github.com/openshift/machine-config-operator/pull/6534) * [OCPBUGS-114722](https://issues.redhat.com/browse/OCPBUGS-114722): crio: drop restore support [#6465](https://github.com/openshift/machine-config-operator/pull/6465) * [OCPBUGS-121651](https://issues.redhat.com/browse/OCPBUGS-121651): remove nft chains before checking the ignition config [#6511](https://github.com/openshift/machine-config-operator/pull/6511) * [OCPBUGS-121379](https://issues.redhat.com/browse/OCPBUGS-121379): Retry on conflict in syncMachineConfigNodes [#6510](https://github.com/openshift/machine-config-operator/pull/6510) * [OCPBUGS-121850](https://issues.redhat.com/browse/OCPBUGS-121850): Fix vsphere network absolute paths [#6513](https://github.com/openshift/machine-config-operator/pull/6513) * [OCPBUGS-115056](https://issues.redhat.com/browse/OCPBUGS-115056): limit ContainerRuntimeConfig status condition to 3 [#6468](https://github.com/openshift/machine-config-operator/pull/6468) * [OCPBUGS-116711](https://issues.redhat.com/browse/OCPBUGS-116711): Skip vsphere fd-unmatched machinesets for bootimage updates [#6484](https://github.com/openshift/machine-config-operator/pull/6484) * [OCPBUGS-117427](https://issues.redhat.com/browse/OCPBUGS-117427): Increase TC-74751 Eventually timeout for vSphere OVA upload [#6491](https://github.com/openshift/machine-config-operator/pull/6491) * [OCPBUGS-116944](https://issues.redhat.com/browse/OCPBUGS-116944): Update AMI Whitelist [#6490](https://github.com/openshift/machine-config-operator/pull/6490) * [OCPBUGS-114709](https://issues.redhat.com/browse/OCPBUGS-114709): Preserve proxy environment vars [#6464](https://github.com/openshift/machine-config-operator/pull/6464) * [OCPBUGS-115195](https://issues.redhat.com/browse/OCPBUGS-115195): fix: adjust fencing validator to match MAC-address based credential secrets [#6467](https://github.com/openshift/machine-config-operator/pull/6467) * [OCPBUGS-114485](https://issues.redhat.com/browse/OCPBUGS-114485): Update the MachineOSBuild event and condition functionality to more clearly handle pod failures with retries [#6463](https://github.com/openshift/machine-config-operator/pull/6463) * [OCPBUGS-112790](https://issues.redhat.com/browse/OCPBUGS-112790): Revert TNF Graceful node shutdown [#6460](https://github.com/openshift/machine-config-operator/pull/6460) * [OCPBUGS-114389](https://issues.redhat.com/browse/OCPBUGS-114389): Use kubernetes scheme in drain controller event recorder [#6455](https://github.com/openshift/machine-config-operator/pull/6455) * [CORS-4441](https://issues.redhat.com/browse/CORS-4441): Bootimage controller should gracefully handle Azure gen1 image removal [#6453](https://github.com/openshift/machine-config-operator/pull/6453) * [OCPBUGS-113615](https://issues.redhat.com/browse/OCPBUGS-113615): Azure confidential clusters should be flagged by skew enforcement [#6448](https://github.com/openshift/machine-config-operator/pull/6448) * [OCPBUGS-112447](https://issues.redhat.com/browse/OCPBUGS-112447): Increase rpm-ostree rebase retry backoff and preserve error [#6425](https://github.com/openshift/machine-config-operator/pull/6425) * [OCPBUGS-112466](https://issues.redhat.com/browse/OCPBUGS-112466): Fix upstreams for CoreDNS pods on Cloud platforms [#6429](https://github.com/openshift/machine-config-operator/pull/6429) * [OCPBUGS-112082](https://issues.redhat.com/browse/OCPBUGS-112082): skip proxy for OSImageStream discovery in HyperShift [#6423](https://github.com/openshift/machine-config-operator/pull/6423) * [Full changelog](https://github.com/openshift/machine-config-operator/compare/c7aecba7975d129529d1ec6a67ac6e5b9991aefb...ea7d971717f7c6fac339f5cf4ffbbccb23234edc) ### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/e8610c3c8b35ec0758523c21a2e60aa8c7e59914) * NO-JIRA: [release-5.0] Sanitize alert runbook URLs [#1290](https://github.com/openshift/monitoring-plugin/pull/1290) * [OCPBUGS-114748](https://issues.redhat.com/browse/OCPBUGS-114748): [release-5.0] DOMPurify: Cross-Site Scripting via IN_PLACE sanitization [#1265](https://github.com/openshift/monitoring-plugin/pull/1265) * NO-JIRA: Add dchromik to observability-ui aliases [#1232](https://github.com/openshift/monitoring-plugin/pull/1232) * [OU-1423](https://issues.redhat.com/browse/OU-1423): fix: adjust perses mui theme to patternfly glass mode [#1198](https://github.com/openshift/monitoring-plugin/pull/1198) * [OU-1409](https://issues.redhat.com/browse/OU-1409): [release-5.0] : include the legal disclaimer in the alert actions to agentic runs [#1193](https://github.com/openshift/monitoring-plugin/pull/1193) * [OLS-3921](https://issues.redhat.com/browse/OLS-3921): disable button shrink [#1191](https://github.com/openshift/monitoring-plugin/pull/1191) * NO-JIRA: remove `cypress/` imports [#1146](https://github.com/openshift/monitoring-plugin/pull/1146) * [OU-1107](https://issues.redhat.com/browse/OU-1107), [OU-1108](https://issues.redhat.com/browse/OU-1108): ACM alerting UI with alerts and perses [#1143](https://github.com/openshift/monitoring-plugin/pull/1143) * [Full changelog](https://github.com/openshift/monitoring-plugin/compare/df674f002d52c80e82532b9c0d668291be6ed431...e8610c3c8b35ec0758523c21a2e60aa8c7e59914) ### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/c0bdec9ce6a1a69985fdba5481c47fb34461eb6c) * [OCPBUGS-104355](https://issues.redhat.com/browse/OCPBUGS-104355): [release-5.0] Bump golang.org/x/net to 0.58.0 to fix CVE-2026-33814 [#126](https://github.com/openshift/multus-admission-controller/pull/126) * [Full changelog](https://github.com/openshift/multus-admission-controller/compare/6d9df61378321846c00a32f0c42b6688daacd649...c0bdec9ce6a1a69985fdba5481c47fb34461eb6c) ### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/8f597f4b90dffe1d1cb9aee558fe53a0046c9e35) * [OCPBUGS-120678](https://issues.redhat.com/browse/OCPBUGS-120678): [Release 5.0] Cherry-pick fix for restoring conflist CNINetworkConfigList fast path and fix cached DEL without load cost [#349](https://github.com/openshift/multus-cni/pull/349) * [OCPBUGS-114733](https://issues.redhat.com/browse/OCPBUGS-114733): [release-5.0] Revert "Sort DeviceIDs in GetPodResourceMap for deterministic ordering" [#348](https://github.com/openshift/multus-cni/pull/348) * [Full changelog](https://github.com/openshift/multus-cni/compare/f099946680e376f722674e684aec96a73c58e919...8f597f4b90dffe1d1cb9aee558fe53a0046c9e35) ### [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy/tree/bfbac5025c056c4bf53aeeef50c4bcf466f5eb11) * [OCPBUGS-104353](https://issues.redhat.com/browse/OCPBUGS-104353): [release-5.0] Bump golang.org/x/net to 0.57.0 to fix CVE-2026-33814 [#121](https://github.com/openshift/multus-networkpolicy/pull/121) * [Full changelog](https://github.com/openshift/multus-networkpolicy/compare/7a26023b1ebb3d2c6120973a97a9bed9adfae334...bfbac5025c056c4bf53aeeef50c4bcf466f5eb11) ### [multus-route-override-cni](https://github.com/openshift/route-override-cni/tree/375ac966115fd03febd218a8331e8794560bd28e) * [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#78](https://github.com/openshift/route-override-cni/pull/78) * [Full changelog](https://github.com/openshift/route-override-cni/compare/08af4127c77976510cad1c096d9aca977d8ae5af...375ac966115fd03febd218a8331e8794560bd28e) ### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/4b0c2166726247e36a0125432609844045e48dc3) * [OCPBUGS-104367](https://issues.redhat.com/browse/OCPBUGS-104367): [release-5.0] Bump go to 1.25.11 and golang.org/x/net to 0.58.0 to fix CVE-2026-33814 [#421](https://github.com/openshift/whereabouts-cni/pull/421) * [Full changelog](https://github.com/openshift/whereabouts-cni/compare/d918bda28ad3d0200b6e4f2ef2801556764762e5...4b0c2166726247e36a0125432609844045e48dc3) ### [must-gather](https://github.com/openshift/must-gather/tree/f4c72a69ebedddead25591da3a115bc4b0bc49ca) * [OCPBUGS-123521](https://issues.redhat.com/browse/OCPBUGS-123521): Add windows_exporter log collection [#566](https://github.com/openshift/must-gather/pull/566) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#564](https://github.com/openshift/must-gather/pull/564) * [OCPBUGS-113491](https://issues.redhat.com/browse/OCPBUGS-113491): REDUCE_LOGS=compress_logs compresses large must-gather logs before rsync [#561](https://github.com/openshift/must-gather/pull/561) * [Full changelog](https://github.com/openshift/must-gather/compare/fd47ab2c1d183a1e66a1a74fe30cf6a26f433409...f4c72a69ebedddead25591da3a115bc4b0bc49ca) ### [network-interface-bond-cni](https://github.com/openshift/bond-cni/tree/2c395f566f259f1a1726409e2472029fa52918c9) * [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#122](https://github.com/openshift/bond-cni/pull/122) * [Full changelog](https://github.com/openshift/bond-cni/compare/19d390fd4d353619fdfb5e0070962d2ddf54b5bb...2c395f566f259f1a1726409e2472029fa52918c9) ### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/20e6b987ea44e7cf0805662e8fec44d625b6f278) * [OCPBUGS-101707](https://issues.redhat.com/browse/OCPBUGS-101707), [OCPBUGS-104373](https://issues.redhat.com/browse/OCPBUGS-104373): Fix CVE for ose-network-metrics-daemon [#148](https://github.com/openshift/network-metrics-daemon/pull/148) * [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844...20e6b987ea44e7cf0805662e8fec44d625b6f278) ### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/4509d691e67664e9b3a911278fcbf38d54bb9cfc) * [OCPNETUI-78](https://issues.redhat.com/browse/OCPNETUI-78): Remove unused Dockerfile.art [#517](https://github.com/openshift/networking-console-plugin/pull/517) * [OCPNETUI-78](https://issues.redhat.com/browse/OCPNETUI-78): Sync Dockerfile and Dockerfile.art [#495](https://github.com/openshift/networking-console-plugin/pull/495) * [OCPBUGS-112661](https://issues.redhat.com/browse/OCPBUGS-112661): Marked strings for i18n in NetworkPolicies list page [#479](https://github.com/openshift/networking-console-plugin/pull/479) * [Full changelog](https://github.com/openshift/networking-console-plugin/compare/7d9d46ba0976840e7559b5b13f14624fd807472c...4509d691e67664e9b3a911278fcbf38d54bb9cfc) ### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/a59e07d789b5a2531e94053cfe7c53edde90e931) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#229](https://github.com/openshift/oauth-apiserver/pull/229) * [Full changelog](https://github.com/openshift/oauth-apiserver/compare/51b07b6d36fd59d809d280630d542c6f702a528a...a59e07d789b5a2531e94053cfe7c53edde90e931) ### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/310d2f7b90762b407d6100eb3940bd5b2f348108) * [OCPBUGS-115304](https://issues.redhat.com/browse/OCPBUGS-115304): [release-5.0] bugfix: rewrite open redirect strings to '/' [#376](https://github.com/openshift/oauth-proxy/pull/376) * [OCPBUGS-87343](https://issues.redhat.com/browse/OCPBUGS-87343): Updating golang-github-openshift-oauth-proxy-container image to be consistent with ART for 5.0 [#367](https://github.com/openshift/oauth-proxy/pull/367) * [Full changelog](https://github.com/openshift/oauth-proxy/compare/e9046946c11e46d310c83830687eb3284cb53525...310d2f7b90762b407d6100eb3940bd5b2f348108) ### [oauth-server](https://github.com/openshift/oauth-server/tree/6c2c889640ec53563021d0c0f09c4388cdcdb806) * [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#261](https://github.com/openshift/oauth-server/pull/261) * [OCPBUGS-115306](https://issues.redhat.com/browse/OCPBUGS-115306): [release-5.0] bugfix: default to english when Accept-Language header contains more than 1000 underscores [#259](https://github.com/openshift/oauth-server/pull/259) * [Full changelog](https://github.com/openshift/oauth-server/compare/1600eafd18f46d54ad0a9ff70fa03a085f6f6218...6c2c889640ec53563021d0c0f09c4388cdcdb806) ### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/726a0562818b68faccfa130ae7ea17ff42915418) * [OCPBUGS-112448](https://issues.redhat.com/browse/OCPBUGS-112448): bump(k8s.io): 1.36.3 [#452](https://github.com/openshift/openshift-controller-manager/pull/452) * [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/5631cf493b006cbc72a8600a7435813272d71940...726a0562818b68faccfa130ae7ea17ff42915418) ### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/c3d56d2021bbb8d57bc359fabded3b35b253f55e) * [OCPBUGS-83412](https://issues.redhat.com/browse/OCPBUGS-83412): set catalogsource spec.grpcpodconfig.scc: restricted for all non-legacy cases [#1360](https://github.com/openshift/operator-framework-olm/pull/1360) * [OCPBUGS-113283](https://issues.redhat.com/browse/OCPBUGS-113283): force node arch for opm and catalogsource pod for multiarch tests; fix test failure [#1358](https://github.com/openshift/operator-framework-olm/pull/1358) * [Full changelog](https://github.com/openshift/operator-framework-olm/compare/c64b9ca2026d13e8907d547b1cbe5226b0a25219...c3d56d2021bbb8d57bc359fabded3b35b253f55e) ### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/3ce12184bf66e8be8abe365f81ffdfa7dbb4dd76) * [OCPBUGS-122287](https://issues.redhat.com/browse/OCPBUGS-122287): Fix wrong infrastructure-locked role when namespace is missing [#3438](https://github.com/openshift/ovn-kubernetes/pull/3438) * [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/7b4de5ed3bd4381e3a17cdfddbe14be1432b9860...3ce12184bf66e8be8abe365f81ffdfa7dbb4dd76) ### [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver/tree/5911994c5d70906e0f0972411176392ada9942d1) * [OCPBUGS-108052](https://issues.redhat.com/browse/OCPBUGS-108052): Mitigate CVE-2026-41178 by bumping go.opentelemetry.io/otel to v1.44.0 [#143](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/143) * OCPBUGS-93616,OCPBUGS-95518,OCPBUGS-98129, OCPBUGS-101725 and OCPBUGS-96872: Mitigate CVE-2026-39828, CVE-2026-46597 and CVE-2026-39835 [#141](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/141) * [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver/compare/e7c2c09bd0507f8bd5a6dc3921024a379f4a8af0...5911994c5d70906e0f0972411176392ada9942d1) ### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/b8af472104ce559c8fb9bf31fd4fc38bdbdc34e7) * [OCPBUGS-112719](https://issues.redhat.com/browse/OCPBUGS-112719): cherry-pick 24c6dce279c418bcb911824e8c8be1c81a1e832b - Fix fibrechannel_linux for ppc64le (#3769) [#185](https://github.com/openshift/node_exporter/pull/185) * [Full changelog](https://github.com/openshift/node_exporter/compare/4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07...b8af472104ce559c8fb9bf31fd4fc38bdbdc34e7) ### [rhel-coreos, rhel-coreos-10, rhel-coreos-10-extensions, rhel-coreos-extensions](https://github.com/openshift/os/tree/7324ccd30e5b2b3146639cb610bfe92c743c91a1) * [OCPBUGS-115309](https://issues.redhat.com/browse/OCPBUGS-115309): Re-enable sandboxed-containers extension for 5.0 [#1965](https://github.com/openshift/os/pull/1965) * [Full changelog](https://github.com/openshift/os/compare/d2f3751e77c4b79b1553d18758c2ea91f06f51fc...7324ccd30e5b2b3146639cb610bfe92c743c91a1) ### [tests](https://github.com/openshift/origin/tree/5469b61543bdbba51f6701bbc8882ccbd1fc3098) * [OCPBUGS-123600](https://issues.redhat.com/browse/OCPBUGS-123600): Register cluster-baremetal-tests-ext in extension registry [#31641](https://github.com/openshift/origin/pull/31641) * [[release-5.0] OCPBUGS-121193: Fixed Flakiness of Webhook test - ClusterResourceQuota validation](https://github.com/openshift/origin/pull/31642#top) [#31642](https://github.com/openshift/origin/pull/31642) * Revert "OCPBUGS-83412: monitortests: skip PodSecurityViolation invariant when OpenShiftPodSecurityAdmission is disabled" [#31604](https://github.com/openshift/origin/pull/31604) * [OKD-454](https://issues.redhat.com/browse/OKD-454): [release-5.0] Skip OKD job name check for cluster-bot launch jobs [#31629](https://github.com/openshift/origin/pull/31629) * [CORENET-7243](https://issues.redhat.com/browse/CORENET-7243): Add TLS Profile Compliance tests for networking components [release-5.0] [#31613](https://github.com/openshift/origin/pull/31613) * [OCPBUGS-120743](https://issues.redhat.com/browse/OCPBUGS-120743): Fix the number of requests in repeated exec [#31610](https://github.com/openshift/origin/pull/31610) * [OCPBUGS-120715](https://issues.redhat.com/browse/OCPBUGS-120715): Add Degraded=True exception for authentication operator during upgrade [#31608](https://github.com/openshift/origin/pull/31608) * [OKD-443](https://issues.redhat.com/browse/OKD-443): Handle missing OSImageStream CR on OKD SCOS during upgrades [#31592](https://github.com/openshift/origin/pull/31592) * [OCPBUGS-114674](https://issues.redhat.com/browse/OCPBUGS-114674): Allow KubeDaemonSetRolloutStuck alert on external platform clusters [#31573](https://github.com/openshift/origin/pull/31573) * [OCPBUGS-112042](https://issues.redhat.com/browse/OCPBUGS-112042): allow baremetal to progress while MCO does [#31537](https://github.com/openshift/origin/pull/31537) * [OCPBUGS-113994](https://issues.redhat.com/browse/OCPBUGS-113994): Raise status polling timeout and write bound [#31559](https://github.com/openshift/origin/pull/31559) * [OCPBUGS-114437](https://issues.redhat.com/browse/OCPBUGS-114437): Fix probe termination test to use pod status instead of kubelet event text [#31567](https://github.com/openshift/origin/pull/31567) * [OCPBUGS-113706](https://issues.redhat.com/browse/OCPBUGS-113706): Fix pathological events [#31557](https://github.com/openshift/origin/pull/31557) * [OCPBUGS-83412](https://issues.redhat.com/browse/OCPBUGS-83412): monitortests: skip PodSecurityViolation invariant when OpenShiftPodSecurityAdmission is disabled [#31561](https://github.com/openshift/origin/pull/31561) * [OCPBUGS-113760](https://issues.redhat.com/browse/OCPBUGS-113760): Allow KubeDaemonSetMisScheduled alert on external platform clusters [#31558](https://github.com/openshift/origin/pull/31558) * [OCPBUGS-111877](https://issues.redhat.com/browse/OCPBUGS-111877): tolerate brief olm Available=False during upgrades [#31529](https://github.com/openshift/origin/pull/31529) * [Full changelog](https://github.com/openshift/origin/compare/fb432ca0c1efb729d8f221c7e8231bbe88edda43...5469b61543bdbba51f6701bbc8882ccbd1fc3098) ### [thanos](https://github.com/openshift/thanos/tree/2a09eb84b92ccd71d5f1f11e0dda6d5aa9624e19) * [OCPBUGS-121890](https://issues.redhat.com/browse/OCPBUGS-121890): bump go.opentelemetry.io/otel to fix CVE-2026-41178 [#205](https://github.com/openshift/thanos/pull/205) * [Full changelog](https://github.com/openshift/thanos/compare/75fa632b483716e53aec19f6adf7d4c4652a4453...2a09eb84b92ccd71d5f1f11e0dda6d5aa9624e19) ### [vsphere-csi-driver, vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver/tree/5351c207d5668dd59a445ee57591ba13657fad89) * [OCPBUGS-126711](https://issues.redhat.com/browse/OCPBUGS-126711): UPSTREAM: 4272: Fix crash in syncer when node can't be found [#202](https://github.com/openshift/vmware-vsphere-csi-driver/pull/202) * [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver/compare/6b18bb29fc45383c21aa6c7513d151e443aa305e...5351c207d5668dd59a445ee57591ba13657fad89)