# 5.0.0-ec.5
Created: 2026-07-30 15:47:18 +0000 UTC
Image Digest: `sha256:1b92c9a5a66cd1e50983972d4314640debf13582f23caff72a0426d31f78bc8e`
Promoted from quay.io/openshift-release-dev/ocp-release-nightly@sha256:f27e57da182694aba92a15cea1acd242b1f9d17df49f5fac4ac1158c45b78e48
## Changes from 5.0.0-ec.4
### Components
* Kubectl upgraded from 1.35.2 to 1.36.2
* Kubernetes upgraded from 1.35.3 to 1.36.2
* Kubernetes Tests 1.35.1
* Red Hat Enterprise Linux CoreOS 10.2 upgraded from 10.2.20260627-0 to 10.2.20260724-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| AzureClusterHostedDNSInstall
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| IngressControllerDynamicConfigurationManager
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| VSphereMixedNodeEnv
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| OLMLifecycleAndCompatibility
(0 tests)| Disabled| Enabled
(Changed)| Disabled| Enabled| Disabled| Enabled
(Changed)| Disabled| Enabled |
| ExternalOIDCExternalClaimsSourcing
(0 tests)| Disabled| Disabled| Enabled| Enabled| Disabled| Disabled| Enabled
(Changed)| Enabled
(Changed) |
| AuthenticationComponentProxy
(0 tests)| | | | Enabled
(New)| | | | Enabled
(New) |
| BGPBasedVIPManagement
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | | |
| GCPSovereignCloudInstall
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | | |
| IngressComponentRouteLabels
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| IngressControllerMultipleHAProxyVersions
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| KarpenterOperator
(0 tests)| | | | Enabled
(New)| | | | |
### New images
* [cluster-update-console-plugin](https://github.com/openshift/cluster-update-console-plugin) git [e222a514](https://github.com/openshift/cluster-update-console-plugin/commit/e222a514a3f1977cdc99bbf41d405729aba2d910) `sha256:86d28a61dd77b1428853489a646cdc285882bca74244140fe0bb9db4507dbcb2`
* [driver-toolkit-10](https://github.com/openshift/driver-toolkit) git [7ec03cbb](https://github.com/openshift/driver-toolkit/commit/7ec03cbba69b4dc86ee33e313bad32ae2ea2924e) `sha256:4a61b8e63ea91559546a209758218530af44f167b60dee7b6557aa9915694865`
* [haproxy-router-haproxy28](https://github.com/openshift/router) git [682319a1](https://github.com/openshift/router/commit/682319a1bb432f0203951c33336d0f55947e1099) `sha256:ad054024137e1ec5b2683960527f7e29ecd46e83ababb663e7f87c777bcc12e9`
* [haproxy-router-haproxy32](https://github.com/openshift/router) git [682319a1](https://github.com/openshift/router/commit/682319a1bb432f0203951c33336d0f55947e1099) `sha256:9245087b58e4be3f6622d17d2a1cddbd416f27b38a1427e4058f6d56ccfaac4b`
### Removed images
* oc-mirror
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [8264c02d](https://github.com/openshift/apiserver-network-proxy/commit/8264c02deda9abb6cd9a6a5c23305428431473c2) `sha256:b22bd511cf437e3bf91f93a6d1d0ac160aa2e92ec1177cb1f9569c2c04d934f0`
* [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws) git [5060934b](https://github.com/openshift/cloud-provider-aws/commit/5060934bc9ff325acf4bd0728bf37166255a501f) `sha256:447d5b45b7d625fe9d5314bf2c8fcdd7b9bc019812513e58d130c53e65e31da8`
* [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [8b8c4cef](https://github.com/openshift/aws-ebs-csi-driver/commit/8b8c4cef02ec9b670e2709f2aacc0ed72420be90) `sha256:96b113ea57cebdcb7374d2e2b7218996622a46dbb695187e24b2149614a3dbda`
* [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider) git [6ca6eea2](https://github.com/openshift/aws-encryption-provider/commit/6ca6eea2f3a9d0b090ff63ba5b8e342d5686c9a8) `sha256:b0f76eb78eb6798499316635eb1fe59985b72447f81694b7223eb7ee6a6c0585`
* [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler) git [e4ff2aae](https://github.com/openshift/aws-node-termination-handler/commit/e4ff2aaec292db42de9f3eef4908ba1c421a2a6c) `sha256:fe853b4f507169a94308dd02a54aadd3b721bc0bb0cc329c8612cd9fff1755c0`
* [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms) git [ca3d747d](https://github.com/openshift/azure-kubernetes-kms/commit/ca3d747de321b88a2c606e546851d1841d2fab9f) `sha256:1e86c8ced66e503fae4b00376b94c6e67595f5653ed2a743c469218266f53bcf`
* [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure) git [bb01d0df](https://github.com/openshift/machine-api-provider-azure/commit/bb01d0dfee4abfe7274ff96cba280ad81ad99936) `sha256:89aee960e92764cff98ff66fda3acad9ef49d56d54980c81d4eb49ede44d0edd`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:98347692b2eeefcde9dc9d340a7b49c607c825ad21e5ad7d1160d56fdc0356ea`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [f2b0db19](https://github.com/openshift/cluster-api-provider-baremetal/commit/f2b0db1919fff1344bc68948894c6775c0bf24a3) `sha256:49b095b8e1b7a94516db3f1bb8e19ab7125ca3e8db2a71482389d4d8f4db1faf`
* [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller) git [0b49df2b](https://github.com/openshift/cloud-network-config-controller/commit/0b49df2bc4b10110463f1aa2a5fc475ebaeef9ab) `sha256:7d1ee405035ff80e5ab263de59a7559e9b4b626bb73f8327a4ccd9f08ab26498`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [7b1593a4](https://github.com/openshift/cluster-bootstrap/commit/7b1593a47898b6a97dc457efaca464624e9f2afa) `sha256:41d8756ccf436aa598e14f8baf0323324bdb6452e47b11127a7c509e86269d1d`
* [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator) git [f5d3bfe6](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/commit/f5d3bfe64bda67ffb8299af01ebf2722287edf04) `sha256:54a44eeb08fb5588ebd58cfa3deefd5b73fccc161c194b388b5e72d29e824ceb`
* [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver) git [1ae3f157](https://github.com/openshift/cluster-machine-approver/commit/1ae3f157b88c167a7dbe06c36d6e55a82f7fd4f0) `sha256:c9ba5de3754d16d0ae92b91b7c9868eb42fcd5cf438d9bae8b6a5db043765a71`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [34f95b07](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/34f95b07f4afbc47558e54e4fa2710fd692e615e) `sha256:552cca5cb1f148f199e0b30e1dd2c2b06093057d4f96507fa37cfb41a7555eb8`
* [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator) git [eee95bab](https://github.com/openshift/cluster-samples-operator/commit/eee95babd52053191e29355108f7daf149dfbf8f) `sha256:e0f91f490305898d78b1e851ad2831a0c12b34f5aca5080a7a3af8dc89e3bc42`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:71cc78d70289f1f1eac8fae83779830b8a67fc1f39f2bdb8a5d92927f29bdba7`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [ce80869a](https://github.com/openshift/configmap-reload/commit/ce80869a83b55ebbdc21a5550ec5747645203bd2) `sha256:8c077de8169bdd64483159dc9d78e8013571c300ce79f923a46a0bde7d0a8463`
* [container-networking-plugins](https://github.com/openshift/containernetworking-plugins) git [d6f73950](https://github.com/openshift/containernetworking-plugins/commit/d6f73950658d258e0ddbf2a4ac92e13ac840158b) `sha256:dbd38345e48e45c9c33568c65305b01c0ea618da500b79e65a383dc7cac1acaa`
* [containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins) git [d6f73950](https://github.com/openshift/containernetworking-plugins/commit/d6f73950658d258e0ddbf2a4ac92e13ac840158b) `sha256:33de1cb83d2cabbb5f022b253f91b68e3b790680acd14dc148aa65b893997f29`
* [csi-driver-manila](https://github.com/openshift/cloud-provider-openstack) git [f8bb5994](https://github.com/openshift/cloud-provider-openstack/commit/f8bb5994f3cee8ee2bb5cca25e3e9783ad7dd57c) `sha256:615d8af00ed65ebfdf0a674c5be90b0a9a827d5e9620ece155450313f9deea6f`
* [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [96ebfa73](https://github.com/openshift/csi-external-attacher/commit/96ebfa733c06c3398555d164c788e310908fecf6) `sha256:d58d77795faa38acee129adc99b5cb0cea1e1ccad0eb7fe19bffc7c45eacfde1`
* [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [bdf440fa](https://github.com/openshift/csi-external-provisioner/commit/bdf440fab8a48e4b76cf0902ad5ba17a20881a8b) `sha256:6f3ff79727a6f3ba688a498c921a7971bd7a237f8d06b338bc35e6fd7964fd74`
* [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [c608adfc](https://github.com/openshift/csi-external-resizer/commit/c608adfc7e82c7c59221bb9d22642a1902cace43) `sha256:42d5ac49a007fb431805fb9b93c07795f7f4888c51e761afa44c51692fa58142`
* [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata) git [239703c6](https://github.com/openshift/csi-external-snapshot-metadata/commit/239703c637e005cf785892d214d219add70e3533) `sha256:27134655adccbca22d439f6358e0fd1ecfdcfac8e4205854903bfd0f1647c7a0`
* [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe) git [f649d2c7](https://github.com/openshift/csi-livenessprobe/commit/f649d2c76f2484b73c70007801eb81ab4be63635) `sha256:35d50913d76b1fdde4707f3e9d4ab6c8dfeb8f52ad561a916957cc75b6c4253b`
* [docker-builder](https://github.com/openshift/builder) git [2cda03a9](https://github.com/openshift/builder/commit/2cda03a93696d4620703848471b3b873b0b2fa1e) `sha256:06e4a09b60f82a0423f27329bf912fb9a0d668ee57519a23e3cc6c0b9336fc26`
* [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm) git [ef8fcc28](https://github.com/openshift/cloud-provider-ibm/commit/ef8fcc288d9248cd149f181e7f5c896f4a10eb3b) `sha256:337d947c981ede18cfd792ec5ba80b95a17b37ad77789a9df519e5a5c2d7b887`
* [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver) git [f78abbb3](https://github.com/openshift/ibm-vpc-block-csi-driver/commit/f78abbb3502a875b7ddf769cf6b7c1b8e3ebba29) `sha256:1258fa66b1ae6a7f1832fe0cfa019e4e8fc11e3aa62577e5d9d2f8210ff7896f`
* [insights-runtime-exporter](https://github.com/openshift/insights-runtime-extractor) git [ce30b4f9](https://github.com/openshift/insights-runtime-extractor/commit/ce30b4f9bc3ec867b976886a5207d36c50a396d9) `sha256:701d11d96230fe5b1d20c69b3fba766313ddd13940602fcb28862b80a67588c1`
* [insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor) git [ce30b4f9](https://github.com/openshift/insights-runtime-extractor/commit/ce30b4f9bc3ec867b976886a5207d36c50a396d9) `sha256:071fc332dcc9714ba77399d4e990fd900af2e6575bee30d6dd3b1da19b228422`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [f8e41b2e](https://github.com/openshift/ironic-rhcos-downloader/commit/f8e41b2ed8915474a99e3eb34b54692afb0611da) `sha256:c47732893037281dd50de8c64b7edd4230b331484619552591604283a4929acb`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [486a0418](https://github.com/openshift/ironic-static-ip-manager/commit/486a041897d703d55ef59c98e2b20a01588a0b4c) `sha256:bd474ef32ef231db6df36e6c2a35c133878063f31bfffc914ea5434c69a0cc13`
* [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [72835e43](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/72835e43c7754356645e41031f3a99926b4d42e6) `sha256:748cbd435f737155b900ba323405fb788b38347824cf67c4aa9409aae94d6469`
* [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver) git [7ff99994](https://github.com/openshift/kubevirt-csi-driver/commit/7ff99994ecc3a675fac6f9aa7fa418cdb0dca32b) `sha256:b4a1b2a1308743a2d9dca7419faff95e371e4ca4c2a5608998efd34624143359`
* [machine-image-customization-controller](https://github.com/openshift/image-customization-controller) git [7a348422](https://github.com/openshift/image-customization-controller/commit/7a348422137de33a9bfa6368b3797686ff4e8f98) `sha256:7bff78ff8f1771a3bc7afa25e3acc7f8554a559a691abd814bbf3c9975ebaa0f`
* [machine-os-images](https://github.com/openshift/machine-os-images) git [7e514b05](https://github.com/openshift/machine-os-images/commit/7e514b05e0825994d858d0a142e255abdd0e8f2d) `sha256:c33615cd861933d8a121015b4402d66915777f0186e431f52f2a7db5cbaf417d`
* [metallb-frr](https://github.com/openshift/frr) git [5d3b12b6](https://github.com/openshift/frr/commit/5d3b12b6ce0a7def4a7a4d1df7ff9e88deb430f5) `sha256:f933da9f8a082899da6e8e92113c553b1f1037c78d1eed32c977255f9f6d6d14`
* [multus-admission-controller](https://github.com/openshift/multus-admission-controller) git [4bb2e206](https://github.com/openshift/multus-admission-controller/commit/4bb2e2069c3e4f11fbc4c1befd6dc1c41fa802b7) `sha256:93ce973ded49c7b2cc4a448d6d268df5a0200fb9a6f24920c6368cbd8a2a33b5`
* [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [932bdaa4](https://github.com/openshift/multus-networkpolicy/commit/932bdaa4250d0a1db41a1a1fcac8192f2757211c) `sha256:e623746af911cfe843c5c83048f8f10ab08722ee7135bf2e9747eb9ac2988022`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [08af4127](https://github.com/openshift/route-override-cni/commit/08af4127c77976510cad1c096d9aca977d8ae5af) `sha256:d5ceb0cdd8ef19d1099cdcff1e8bc79d39f8f00cb80ea4642d7a2942ef1d9b70`
* [network-tools](https://github.com/openshift/network-tools) git [0b53ac3d](https://github.com/openshift/network-tools/commit/0b53ac3dccf59cd169555bf18c207122374bf003) `sha256:6e3687ee59ead3d189522c2307bbae291eb869229c796bd0c56b2fa791047056`
* [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix) git [b8b84ebc](https://github.com/openshift/machine-api-provider-nutanix/commit/b8b84ebcda147113477af9a4edbcdfb03e22875c) `sha256:ad297523cc1aaba696e4df4a9613c9a2ffd7465043f60d8487d69c1c538428d4`
* [oauth-proxy](https://github.com/openshift/oauth-proxy) git [2b9ee007](https://github.com/openshift/oauth-proxy/commit/2b9ee007290b0e1cb85737f3b37075343f9f4857) `sha256:3ab6e77e4a60d5482c129d83aeadbf9cea95bc787daf9d1c905cf26804591a60`
* [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager) git [5631cf49](https://github.com/openshift/openshift-controller-manager/commit/5631cf493b006cbc72a8600a7435813272d71940) `sha256:f7578820ce444e09998f767560b4886fd5b87ad46070f71dc146d080f6d38560`
* [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [0e12f5d6](https://github.com/openshift/openshift-state-metrics/commit/0e12f5d6df02b37b0353a747d144e8069c3d0c2a) `sha256:10eec8e79f04ffefe4af29f77c223b8c5cb16819ebf8c7c69471344a4bba5e12`
* [openstack-cinder-csi-driver](https://github.com/openshift/cloud-provider-openstack) git [f8bb5994](https://github.com/openshift/cloud-provider-openstack/commit/f8bb5994f3cee8ee2bb5cca25e3e9783ad7dd57c) `sha256:fa54ca72c13f16bdb02354d9e7bd0f16104333e042b6643ec626a489eeca22ad`
* [openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack) git [f8bb5994](https://github.com/openshift/cloud-provider-openstack/commit/f8bb5994f3cee8ee2bb5cca25e3e9783ad7dd57c) `sha256:bc175cab2d6d9e4fa0f0a4378d7c8bc0a784453219f8776a88f6aee268bd67a8`
* [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:86dc74128811314bb7fe7da85b85456401474728c646a14edb9acc4b2e7e508e`
* [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller) git [58dbc048](https://github.com/openshift/openstack-resource-controller/commit/58dbc0482c144c21effee2476947889122a518eb) `sha256:fa3ea2244d51fd683770764ad62e54775d3dcc4c9b14c8d86e838044a92e6e37`
* [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver) git [e7c2c09b](https://github.com/openshift/ibm-powervs-block-csi-driver/commit/e7c2c09bd0507f8bd5a6dc3921024a379f4a8af0) `sha256:4a0305a1201b474c627327a6d785e2eb2f59026b5e421f0c0c9d999d49051df6`
* [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs) git [e88cf81d](https://github.com/openshift/machine-api-provider-powervs/commit/e88cf81dd9ad174f395b86f9cdc40fa30cb06bf4) `sha256:18c7fa50cc57f97d5ba8e5aedab5f0a753bf55b0bee4c19e520554ea97660ee0`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [4ab9ff73](https://github.com/openshift/prom-label-proxy/commit/4ab9ff73c665319352288fe0b9b9e1df71832525) `sha256:a43f7d255656e9982ed36f5fc0f21d8cc128449a1c923e7c1d81b25cd80af7f5`
* [prometheus-config-reloader](https://github.com/openshift/prometheus-operator) git [6a36acbd](https://github.com/openshift/prometheus-operator/commit/6a36acbd5ecd5a308bc81267f3b0567f93377247) `sha256:c7b61ee4d16ded490049907c75dad792fe16ddade49d05c9a07a1158e12819ef`
* [prometheus-operator](https://github.com/openshift/prometheus-operator) git [6a36acbd](https://github.com/openshift/prometheus-operator/commit/6a36acbd5ecd5a308bc81267f3b0567f93377247) `sha256:74cc2e7caccacde9f45772639387dcb4e72130fb9d42325ceac9103103b82968`
* [prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator) git [6a36acbd](https://github.com/openshift/prometheus-operator/commit/6a36acbd5ecd5a308bc81267f3b0567f93377247) `sha256:42cdddf681e17b64fd0e9b71a5ad75ecaf47b153ef749072f1022efd2968287e`
* [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator) git [a6c21eee](https://github.com/openshift/volume-data-source-validator/commit/a6c21eee63d1fae58b63d8493aeb0fd662d1c91e) `sha256:cebd21e62b7b2c2b0db96faa76cd1376354fcfe5f5d53d2f570b696f16d39b6c`
* [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere) git [a1553877](https://github.com/openshift/cloud-provider-vsphere/commit/a15538776eb26d20ab2969740cee25f9b4442302) `sha256:0197c85fa14c014876e52d6ff6145d82993f3da6f7cd7811734383ca88e994ea`
* [vsphere-csi-driver](https://github.com/openshift/vmware-vsphere-csi-driver) git [6b18bb29](https://github.com/openshift/vmware-vsphere-csi-driver/commit/6b18bb29fc45383c21aa6c7513d151e443aa305e) `sha256:fca3a5053dbdbdf9befe1473fb0123a5af9ba500527b56e2b2be84eca3c9d953`
* [vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver) git [6b18bb29](https://github.com/openshift/vmware-vsphere-csi-driver/commit/6b18bb29fc45383c21aa6c7513d151e443aa305e) `sha256:3c383d82b9662344dc37739193d6543f002bf9829aca773c30defe1aca219efc`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/f46558c1df1388bc21448ae7fd3b249febb29798)
* NO-ISSUE: [master] Bump OCP versions: 4.13, 4.18, 4.19 [#10710](https://github.com/openshift/assisted-service/pull/10710)
* [ACM-35865](https://issues.redhat.com/browse/ACM-35865): CVE-2026-39828 Bump golang.org/x/crypto to v0.52.0 using replace directive (client module) [#10617](https://github.com/openshift/assisted-service/pull/10617)
* [MGMT-23744](https://issues.redhat.com/browse/MGMT-23744): CVE-2026-33997 Bump docker/docker to v28.5.2 [#10685](https://github.com/openshift/assisted-service/pull/10685)
* NO-ISSUE: [master] Bump OCP versions: 4.16, 4.14, 4.22, 4.21, 4.19, 4.20, 4.18 [#10692](https://github.com/openshift/assisted-service/pull/10692)
* [MGMT-24667](https://issues.redhat.com/browse/MGMT-24667): Fix disconnected ZTP spoke installs for OCP 5.0 OSImageStream images [#10527](https://github.com/openshift/assisted-service/pull/10527)
* [MGMT-24699](https://issues.redhat.com/browse/MGMT-24699): Assisted Service IPv6 CIDR comparison may fail with non-normalized CIDRs [#10569](https://github.com/openshift/assisted-service/pull/10569)
* [MGMT-24327](https://issues.redhat.com/browse/MGMT-24327): upgrade assisted-service postgresql from 15 to 16 [#10519](https://github.com/openshift/assisted-service/pull/10519)
* [ACM-35865](https://issues.redhat.com/browse/ACM-35865): CVE-2026-39828 Bump golang.org/x/crypto to v0.52.0 using replace directive (api module) [#10618](https://github.com/openshift/assisted-service/pull/10618)
* [ACM-35865](https://issues.redhat.com/browse/ACM-35865): CVE-2026-39828 Bump golang.org/x/crypto to v0.52.0 using replace directive (models module) [#10616](https://github.com/openshift/assisted-service/pull/10616)
* NO-ISSUE: [master] Bump OCP versions: 4.18, 5.0, 4.20, 4.16, 4.22, 4.19, 4.21, 4.14, 4.17 [#10622](https://github.com/openshift/assisted-service/pull/10622)
* [MGMT-24786](https://issues.redhat.com/browse/MGMT-24786): Add resource-scoped authorization for local auth tokens [#10603](https://github.com/openshift/assisted-service/pull/10603)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [#10581](https://github.com/openshift/assisted-service/pull/10581)
* [MGMT-18886](https://issues.redhat.com/browse/MGMT-18886): OS Streams [#10428](https://github.com/openshift/assisted-service/pull/10428)
* NO-ISSUE: hive-operator was migrated from community-operators to upstream-community-operators [#10600](https://github.com/openshift/assisted-service/pull/10600)
* [MGMT-24682](https://issues.redhat.com/browse/MGMT-24682): Remove LSO and LVMS as CNV operator dependencies [#10541](https://github.com/openshift/assisted-service/pull/10541)
* [MGMT-24705](https://issues.redhat.com/browse/MGMT-24705): CVE-2026-53488 Bump github.com/containerd/containerd to v1.7.33 through indirect dependency conversion [#10572](https://github.com/openshift/assisted-service/pull/10572)
* [ACM-36420](https://issues.redhat.com/browse/ACM-36420): CVE-2026-39821 Bump golang.org/x/net to v0.55.0 [#10548](https://github.com/openshift/assisted-service/pull/10548)
* NO-ISSUE: [master] Bump OCP versions: 4.21, 4.22, 4.20 [#10568](https://github.com/openshift/assisted-service/pull/10568)
* [MGMT-24400](https://issues.redhat.com/browse/MGMT-24400): Document TestVersion API and usage guidance [#10426](https://github.com/openshift/assisted-service/pull/10426)
* NO-ISSUE: [master] Bump OCP versions: 4.20, 4.21, 4.18, 4.19, 4.13, 4.22, 4.16, 5.0 [#10546](https://github.com/openshift/assisted-service/pull/10546)
* [MGMT-24673](https://issues.redhat.com/browse/MGMT-24673): PATCH /v2/clusters/{id} does not return updated operator_bundles [#10536](https://github.com/openshift/assisted-service/pull/10536)
* NO-ISSUE: Update linter version [#10509](https://github.com/openshift/assisted-service/pull/10509)
* [APPSRE-14691](https://issues.redhat.com/browse/APPSRE-14691): add monitoring.rhobs/v1 ServiceMonitors for COO compatibility [#10540](https://github.com/openshift/assisted-service/pull/10540)
* [Full changelog](https://github.com/openshift/assisted-service/compare/7844aebf98b6018a3f1ae684b412589d0386a48f...f46558c1df1388bc21448ae7fd3b249febb29798)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/e4afa401ce7d4f8a24a857fd2edf3338fef1556e)
* [MGMT-24702](https://issues.redhat.com/browse/MGMT-24702): CVE-2026-53488 Bump github.com/containerd/containerd to v1.7.33 [#2204](https://github.com/openshift/assisted-installer/pull/2204)
* NO-ISSUE: Bump linter [#2199](https://github.com/openshift/assisted-installer/pull/2199)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/c41e0c7d465a9357a49036b350368f008730080e...e4afa401ce7d4f8a24a857fd2edf3338fef1556e)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/bfa655c8a4905031aab68000b84535674413f3b4)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [#1555](https://github.com/openshift/assisted-installer-agent/pull/1555)
* [MGMT-24703](https://issues.redhat.com/browse/MGMT-24703): CVE-2026-53488 Bump github.com/containerd/containerd to v1.7.33 through indirect dependency conversion [#1531](https://github.com/openshift/assisted-installer-agent/pull/1531)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/bdf48b99ec8ca8ce67669fabd59a9669faa0e64e...bfa655c8a4905031aab68000b84535674413f3b4)
### [agent-installer-ui](https://github.com/openshift-assisted/assisted-installer-ui/tree/149443766b2bc3f3106bd2496de746303d829b7f)
* Bump shell-quote from 1.8.4 to 1.10.0 (#3909) [#3909](https://github.com/openshift-assisted/assisted-installer-ui/pull/3909)
* Bump body-parser from 1.20.4 to 1.20.6 (#3911) [#3911](https://github.com/openshift-assisted/assisted-installer-ui/pull/3911)
* Bump fast-uri from 3.1.2 to 3.1.4 (#3910) [#3910](https://github.com/openshift-assisted/assisted-installer-ui/pull/3910)
* [OCPBUGS-99039](https://issues.redhat.com/browse/OCPBUGS-99039): Bump dompurify to 3.4.7+ in 5.0 (#3894) [#3894](https://github.com/openshift-assisted/assisted-installer-ui/pull/3894)
* Update build_tools (#3901) [#3901](https://github.com/openshift-assisted/assisted-installer-ui/pull/3901)
* Fix operator Learn more documentation links and remove duplicates (#3899) [#3899](https://github.com/openshift-assisted/assisted-installer-ui/pull/3899)
* chore(deps): update dependency sanitize-html to ^2.17.6 (#3897) [#3897](https://github.com/openshift-assisted/assisted-installer-ui/pull/3897)
* Bump websocket-driver from 0.7.4 to 0.7.5 (#3891) [#3891](https://github.com/openshift-assisted/assisted-installer-ui/pull/3891)
* chore(deps): update dependency tar to ^7.5.20 (#3898) [#3898](https://github.com/openshift-assisted/assisted-installer-ui/pull/3898)
* chore(deps): update konflux references (#3896) [#3896](https://github.com/openshift-assisted/assisted-installer-ui/pull/3896)
* Upgrade node version in Containerfile (#3872) [#3872](https://github.com/openshift-assisted/assisted-installer-ui/pull/3872)
* Apply patches (#3819) [#3819](https://github.com/openshift-assisted/assisted-installer-ui/pull/3819)
* Upgrade path-to-regexp to ^8.4.2 (#3862) [#3862](https://github.com/openshift-assisted/assisted-installer-ui/pull/3862)
* Upgrade sanitize-html to ^2.17.4 (#3861) [#3861](https://github.com/openshift-assisted/assisted-installer-ui/pull/3861)
* Dedupe yarn.lock (#3863) [#3863](https://github.com/openshift-assisted/assisted-installer-ui/pull/3863)
* Upgrade terser-webpack-plugin to ^5.6.1 (#3818) [#3818](https://github.com/openshift-assisted/assisted-installer-ui/pull/3818)
* chore(deps): update typescript type definitions (non-major) (#3867) [#3867](https://github.com/openshift-assisted/assisted-installer-ui/pull/3867)
* chore(deps): update dependency axios to ^1.18.1 (#3868) [#3868](https://github.com/openshift-assisted/assisted-installer-ui/pull/3868)
* chore(deps): update konflux references (#3866) [#3866](https://github.com/openshift-assisted/assisted-installer-ui/pull/3866)
* Upgrade brace-expansion to ^5.0.8 (#3855) [#3855](https://github.com/openshift-assisted/assisted-installer-ui/pull/3855)
* [OCPBUGS-96781](https://issues.redhat.com/browse/OCPBUGS-96781): Bump webpack-dev-server to 5.2.5 (#3822) [#3822](https://github.com/openshift-assisted/assisted-installer-ui/pull/3822)
* chore(deps): update dependency tar to ^7.5.19 (#3826) [#3826](https://github.com/openshift-assisted/assisted-installer-ui/pull/3826)
* no-jira: Bump axios to latest (1.18.1) (#3856) [#3856](https://github.com/openshift-assisted/assisted-installer-ui/pull/3856)
* [OCPBUGS-97734](https://issues.redhat.com/browse/OCPBUGS-97734): Increase default imageStorage to 100Gi and raise minimum to 50Gi (#3820) [#3820](https://github.com/openshift-assisted/assisted-installer-ui/pull/3820)
* Show all operators on cluster installation page (#3849) [#3849](https://github.com/openshift-assisted/assisted-installer-ui/pull/3849)
* Update OWNERS file (#3850) [#3850](https://github.com/openshift-assisted/assisted-installer-ui/pull/3850)
* chore(deps): update dependency serialize-javascript to ^7.0.7 (#3825) [#3825](https://github.com/openshift-assisted/assisted-installer-ui/pull/3825)
* chore(deps): update konflux references (#3824) [#3824](https://github.com/openshift-assisted/assisted-installer-ui/pull/3824)
* Bump js-yaml from 3.14.1 to 4.3.0 (#3814) [#3814](https://github.com/openshift-assisted/assisted-installer-ui/pull/3814)
* Fix dependency ordering (#3812) [#3812](https://github.com/openshift-assisted/assisted-installer-ui/pull/3812)
* Fix machine network autoselect to work with IPv6 only clusters (#3813) [#3813](https://github.com/openshift-assisted/assisted-installer-ui/pull/3813)
* Upgrade shell-quote to ^1.8.4 (#3800) [#3800](https://github.com/openshift-assisted/assisted-installer-ui/pull/3800)
* [Full changelog](https://github.com/openshift-assisted/assisted-installer-ui/compare/bee4db5ea1024723bd1960ebb0f1ba420a303a9e...149443766b2bc3f3106bd2496de746303d829b7f)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/4c1ca15266d79b638bb0bc376b9536522f302025)
* [OCPBUGS-99425](https://issues.redhat.com/browse/OCPBUGS-99425): Use agent-preinstall-image-builder from quay-proxy [#319](https://github.com/openshift/agent-installer-utils/pull/319)
* [OCPBUGS-98692](https://issues.redhat.com/browse/OCPBUGS-98692): Update cluster-logging and loki operator versions [#315](https://github.com/openshift/agent-installer-utils/pull/315)
* [AGENT-1552](https://issues.redhat.com/browse/AGENT-1552): Add lvms-operator to config [#311](https://github.com/openshift/agent-installer-utils/pull/311)
* [OCPBUGS-98101](https://issues.redhat.com/browse/OCPBUGS-98101): Use build platform with more disk space [#312](https://github.com/openshift/agent-installer-utils/pull/312)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/c52e7a7021da1cb083a252649ec3ca28503f1ab4...4c1ca15266d79b638bb0bc376b9536522f302025)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/902df006f6c3a37aaeed7e09fa6f892788e36d00)
* :rocket: UPSTREAM-SYNC: Merge https://github.com/kubernetes-sigs/cluster-api-provider-aws:v2.12.1 (13af066) into main [#621](https://github.com/openshift/cluster-api-provider-aws/pull/621)
* 🐛 OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#619](https://github.com/openshift/cluster-api-provider-aws/pull/619)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/90f95c204e7897f567643951b36ed2010f658469...902df006f6c3a37aaeed7e09fa6f892788e36d00)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, csi-driver-manila-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/50f79e773ab432a91299a06003191a1fc2535746)
* [OCPBUGS-99200](https://issues.redhat.com/browse/OCPBUGS-99200): Add networking.k8s.io group policy [#581](https://github.com/openshift/csi-operator/pull/581)
* [OCPBUGS-99490](https://issues.redhat.com/browse/OCPBUGS-99490): Apply some static assets earlier, before starting controllers [#584](https://github.com/openshift/csi-operator/pull/584)
* [STOR-2997](https://issues.redhat.com/browse/STOR-2997): Minimal implementation of GCP PD CSI driver operator [#576](https://github.com/openshift/csi-operator/pull/576)
* [STOR-3030](https://issues.redhat.com/browse/STOR-3030): feat(operator): detect GCP Dedicated and use hyperdisk-balanced StorageClass [#573](https://github.com/openshift/csi-operator/pull/573)
* [STOR-2996](https://issues.redhat.com/browse/STOR-2996): Sync gcp pd csi driver operator to legacy subdir (2) [#575](https://github.com/openshift/csi-operator/pull/575)
* [STOR-2996](https://issues.redhat.com/browse/STOR-2996): Run unit-tests in /legacy subdir [#574](https://github.com/openshift/csi-operator/pull/574)
* [Full changelog](https://github.com/openshift/csi-operator/compare/2fc1e7dd8459fcf6a92cd43e99593fc847f746e2...50f79e773ab432a91299a06003191a1fc2535746)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/abcf7d1e34173037a13fc47317f313cb6ac2f667)
* [AUTOSCALE-644](https://issues.redhat.com/browse/AUTOSCALE-644): Release chores 5.0 for Karpenter [#33](https://github.com/openshift/aws-karpenter-provider-aws/pull/33)
* NO-JIRA: add finalizers resources to chart rbac [#31](https://github.com/openshift/aws-karpenter-provider-aws/pull/31)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/9d3e33c99a323659ae02d1121fe36141ccf292f0...abcf7d1e34173037a13fc47317f313cb6ac2f667)
### [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws/tree/10718580c265686b6af85caab68eed263eee2a41)
* NO-JIRA: Cache region validation response and close AWS sessions [#190](https://github.com/openshift/machine-api-provider-aws/pull/190)
* [OCPBUGS-87410](https://issues.redhat.com/browse/OCPBUGS-87410): Updating ose-machine-api-provider-aws-container image to be consistent with ART for 5.0 [#193](https://github.com/openshift/machine-api-provider-aws/pull/193)
* [Full changelog](https://github.com/openshift/machine-api-provider-aws/compare/015a38c0b149fbbc22d261c162493fd801018d4d...10718580c265686b6af85caab68eed263eee2a41)
### [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook/tree/0d33a4596e2a22d188fe74c4a6497c37c2528c1f)
* [OCPCLOUD-3583](https://issues.redhat.com/browse/OCPCLOUD-3583): Update aws-pod-identity-webhook to k8s 1.36 [#220](https://github.com/openshift/aws-pod-identity-webhook/pull/220)
* [OCPBUGS-87337](https://issues.redhat.com/browse/OCPBUGS-87337): Updating ose-aws-pod-identity-webhook-container image to be consistent with ART for 5.0 [#218](https://github.com/openshift/aws-pod-identity-webhook/pull/218)
* [Full changelog](https://github.com/openshift/aws-pod-identity-webhook/compare/dd3da573f41d7f4b78dd605373c5f1e441cb8e35...0d33a4596e2a22d188fe74c4a6497c37c2528c1f)
### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/d04449b95a54a9f41669d701ed63153575cced1e)
* [OCPBUGS-87408](https://issues.redhat.com/browse/OCPBUGS-87408), [OCPBUGS-87500](https://issues.redhat.com/browse/OCPBUGS-87500): Art consistency openshift 5.0 azure fix [#194](https://github.com/openshift/cloud-provider-azure/pull/194)
* [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/2aea5dfd437a32bd8e543c2e938af43eb1771fce...d04449b95a54a9f41669d701ed63153575cced1e)
### [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure/tree/63731729974bff3be90ae2206c53d760572499d1)
* 🚀 OCPCLOUD-3600: Merge https://github.com/kubernetes-sigs/cluster-api-provider-azure:v1.26.0 (19ff821) into main [#388](https://github.com/openshift/cluster-api-provider-azure/pull/388)
* 🐛 OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#393](https://github.com/openshift/cluster-api-provider-azure/pull/393)
* [Full changelog](https://github.com/openshift/cluster-api-provider-azure/compare/52af3f1a3ecffec69c621e80bc80adf67ecec7c0...63731729974bff3be90ae2206c53d760572499d1)
### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/e87f776402d402a3e291e24fa737fe4e5e9617aa)
* [STOR-2923](https://issues.redhat.com/browse/STOR-2923): Rebase to upstream v1.34.4 for OCP 4.23/5.0 [#149](https://github.com/openshift/azure-disk-csi-driver/pull/149)
* [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/2745f1f1d2f1172d58f18bdb42c754451da976c2...e87f776402d402a3e291e24fa737fe4e5e9617aa)
### [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver/tree/f7724fbf3ad694f957bd99fafa2fa7b658462624)
* [OCPBUGS-93742](https://issues.redhat.com/browse/OCPBUGS-93742): Bump golang.org/x/crypto/ssh to v0.53.0 [#141](https://github.com/openshift/azure-file-csi-driver/pull/141)
* [Full changelog](https://github.com/openshift/azure-file-csi-driver/compare/cda552300a8b51c40c5160ede3119643d9b4163f...f7724fbf3ad694f957bd99fafa2fa7b658462624)
### [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity/tree/2b4705c5d999339ce17d47a9b2a637d238891dae)
* [OCPBUGS-87379](https://issues.redhat.com/browse/OCPBUGS-87379): Updating ose-azure-workload-identity-webhook-container image to be consistent with ART for 5.0 [#56](https://github.com/openshift/azure-workload-identity/pull/56)
* [Full changelog](https://github.com/openshift/azure-workload-identity/compare/40d201db10263abbb9f4ace0a4ea0c63c20bbfc2...2b4705c5d999339ce17d47a9b2a637d238891dae)
### [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3/tree/0afcbf370086fe550560784f9cbf7182a9e8b72e)
* 🐛 OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#85](https://github.com/openshift/cluster-api-provider-metal3/pull/85)
* [OCPBUGS-98329](https://issues.redhat.com/browse/OCPBUGS-98329): Grant capi-installer permission on ConfigMap [#86](https://github.com/openshift/cluster-api-provider-metal3/pull/86)
* [Full changelog](https://github.com/openshift/cluster-api-provider-metal3/compare/29a96694bfc3b59d1fa95acf2ad87077cc1d3108...0afcbf370086fe550560784f9cbf7182a9e8b72e)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/d8f6a96a1c18ee540099ff73789fde54cc9b12cd)
* [CORS-4514](https://issues.redhat.com/browse/CORS-4514): Set sovereign cloud defaults for machine types [#10706](https://github.com/openshift/installer/pull/10706)
* [CORS-4537](https://issues.redhat.com/browse/CORS-4537): Add API-backed disk type availability validation [#10687](https://github.com/openshift/installer/pull/10687)
* no-jira: azure: Disable shared access key by default [#10574](https://github.com/openshift/installer/pull/10574)
* [CORS-4507](https://issues.redhat.com/browse/CORS-4507): aws: support edge machine pool management with ClusterAPI [#10625](https://github.com/openshift/installer/pull/10625)
* [CNTRLPLANE-2847](https://issues.redhat.com/browse/CNTRLPLANE-2847): bootstrap: pass rendered manifests and payload version to etcd render [#10679](https://github.com/openshift/installer/pull/10679)
* [CORS-3997](https://issues.redhat.com/browse/CORS-3997): azure: update default instance types from v3 to AMD Dasv5 [#10565](https://github.com/openshift/installer/pull/10565)
* [OCPBUGS-98141](https://issues.redhat.com/browse/OCPBUGS-98141), [OCPBUGS-99018](https://issues.redhat.com/browse/OCPBUGS-99018): bump golang.org/x/crypto to v0.52.0 [#10690](https://github.com/openshift/installer/pull/10690)
* [CORS-4539](https://issues.redhat.com/browse/CORS-4539): Support sovereign cloud service account email format for gcp/gcd [#10691](https://github.com/openshift/installer/pull/10691)
* [CORS-4538](https://issues.redhat.com/browse/CORS-4538): Use metadata project ID for sovereign cloud gather [#10688](https://github.com/openshift/installer/pull/10688)
* NO-ISSUE: Remove workaround for boot image version mismatch [#10665](https://github.com/openshift/installer/pull/10665)
* [OCPBUGS-98586](https://issues.redhat.com/browse/OCPBUGS-98586): Don't wait on oc delete in konnectivity_cleanup [#10682](https://github.com/openshift/installer/pull/10682)
* [OCPBUGS-98529](https://issues.redhat.com/browse/OCPBUGS-98529): cluster-api: disable diagnostics endpoint for local CAPI controllers [#10681](https://github.com/openshift/installer/pull/10681)
* [CORS-4423](https://issues.redhat.com/browse/CORS-4423): GCP: Use WithCredentialsJSON when Possible [#10624](https://github.com/openshift/installer/pull/10624)
* [OCPBUGS-98157](https://issues.redhat.com/browse/OCPBUGS-98157): redact machineconfigs.json from "gather bootstrap" [#10678](https://github.com/openshift/installer/pull/10678)
* [CORS-4518](https://issues.redhat.com/browse/CORS-4518): Migrate containers libs to new mono repo [#10599](https://github.com/openshift/installer/pull/10599)
* [CNTRLPLANE-2012](https://issues.redhat.com/browse/CNTRLPLANE-2012): Refactor TLS cert generation to support configurable key algorithms [#10594](https://github.com/openshift/installer/pull/10594)
* [CORS-4334](https://issues.redhat.com/browse/CORS-4334): konnectivity: remove hostNetwork from konnectivity agent [#10662](https://github.com/openshift/installer/pull/10662)
* [OCPCLOUD-3368](https://issues.redhat.com/browse/OCPCLOUD-3368): bumping o/api for new crdcompatibilitychecker and capi capabilities [#10618](https://github.com/openshift/installer/pull/10618)
* [CORS-4528](https://issues.redhat.com/browse/CORS-4528): Remove OPENSHIFT_INSTALL_EXPERIMENTAL_DUAL_STACK [#10654](https://github.com/openshift/installer/pull/10654)
* no-jira: fix vCenter validation error to use correct field name [#10663](https://github.com/openshift/installer/pull/10663)
* [OCPBUGS-92792](https://issues.redhat.com/browse/OCPBUGS-92792): vsphere - fix CNS volume destroy to aggregate errors [#10658](https://github.com/openshift/installer/pull/10658)
* [CORS-4466](https://issues.redhat.com/browse/CORS-4466): aws: expand public subnet CIDR in public-only mode [#10542](https://github.com/openshift/installer/pull/10542)
* [CNTRLPLANE-2012](https://issues.redhat.com/browse/CNTRLPLANE-2012): Add PKI config types, validation, and CR manifest generation [#10593](https://github.com/openshift/installer/pull/10593)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/installer/compare/a4e07b0b8ca5c1a1ae7524aa725c74e431abeb7e...d8f6a96a1c18ee540099ff73789fde54cc9b12cd)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/775d84f5afecf432c7a0330bfaadd669b4a68ab0)
* [METAL-1900](https://issues.redhat.com/browse/METAL-1900): Merge upstream [#510](https://github.com/openshift/baremetal-operator/pull/510)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/5d3be9399c46e8789a6e735672c5fb7abc4b46bd...775d84f5afecf432c7a0330bfaadd669b4a68ab0)
### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/660073616802e3d1258a036f2e57ca18a7baafa0)
* [OCPBUGS-99496](https://issues.redhat.com/browse/OCPBUGS-99496): Detect bootstrap apiserver shutdown via /readyz [#396](https://github.com/openshift/baremetal-runtimecfg/pull/396)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/079091da0e619331ec79b87e466781efe2445411...660073616802e3d1258a036f2e57ca18a7baafa0)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/a88e785e90aa96ac96da93359bacf3ea5c174733)
* [TRT-2817](https://issues.redhat.com/browse/TRT-2817): Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning" [#2320](https://github.com/openshift/oc/pull/2320)
* NO-JIRA: Bump k8s dependencies to 1.36 along with openshift [#2318](https://github.com/openshift/oc/pull/2318)
* [OTA-1814](https://issues.redhat.com/browse/OTA-1814): fix(alerts): Remove duplicate information in the recommend command [#2279](https://github.com/openshift/oc/pull/2279)
* NO-JIRA: Handle wrapped ENOTSUP error [#2311](https://github.com/openshift/oc/pull/2311)
* NO-JIRA: First try newer iotop-c and fallback to older one [#2317](https://github.com/openshift/oc/pull/2317)
* NO-JIRA: Register the e2e tests for accept in the subfolder [#2300](https://github.com/openshift/oc/pull/2300)
* NO-JIRA: Fix staticcheck warnings in pkg/cli/admin/mustgather [#2306](https://github.com/openshift/oc/pull/2306)
* NO-JIRA: Fix go vet warning in process.go [#2304](https://github.com/openshift/oc/pull/2304)
* NO-JIRA: Bump gitignore dependency [#2303](https://github.com/openshift/oc/pull/2303)
* [CNTRLPLANE-3786](https://issues.redhat.com/browse/CNTRLPLANE-3786): bump x/crypto to the latest version [#2301](https://github.com/openshift/oc/pull/2301)
* NO-JIRA: Move test/e2e/accept.go to its own folder [#2294](https://github.com/openshift/oc/pull/2294)
* [CNTRLPLANE-3665](https://issues.redhat.com/browse/CNTRLPLANE-3665): Add ARCHITECTURE.md, adopt shared CONTRIBUTING.md, slim README [#2293](https://github.com/openshift/oc/pull/2293)
* And 2 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/oc/compare/df12d888651c93004027efc0d58ea84a886ce8f7...a88e785e90aa96ac96da93359bacf3ea5c174733)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/672b790022dbea667460b1a0467b6a0bc39c544b)
* [MULTIARCH-5990](https://issues.redhat.com/browse/MULTIARCH-5990): IBM Cloud Staging Endpoint Support for `ccoctl` [#1062](https://github.com/openshift/cloud-credential-operator/pull/1062)
* [CCO-847](https://issues.redhat.com/browse/CCO-847): Resolve ci/prow/security job failures [#1048](https://github.com/openshift/cloud-credential-operator/pull/1048)
* [OCPBUGS-96892](https://issues.redhat.com/browse/OCPBUGS-96892): Revert "OCPBUGS-87829: Scope minted AWS IAM policies to cluster-owned resources" [#1057](https://github.com/openshift/cloud-credential-operator/pull/1057)
* [OCPBUGS-95187](https://issues.redhat.com/browse/OCPBUGS-95187): Reclassify ec2:ModifyNetworkInterfaceAttribute as unscoped [#1053](https://github.com/openshift/cloud-credential-operator/pull/1053)
* [OCPBUGS-33994](https://issues.redhat.com/browse/OCPBUGS-33994): Don't unnecessarily re-reconcile when secrets are externally managed [#1042](https://github.com/openshift/cloud-credential-operator/pull/1042)
* [OCPBUGS-87505](https://issues.redhat.com/browse/OCPBUGS-87505): Updating ose-cloud-credential-operator-container image to be consistent with ART for 5.0 [#1037](https://github.com/openshift/cloud-credential-operator/pull/1037)
* [OCPBUGS-87829](https://issues.redhat.com/browse/OCPBUGS-87829): Scope minted AWS IAM policies to cluster-owned resources [#1043](https://github.com/openshift/cloud-credential-operator/pull/1043)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/72a5a4676668c7105203aa7ec1b33a74ff23f75e...672b790022dbea667460b1a0467b6a0bc39c544b)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/482d82f81fc7b460eb3f4024c7fcb4c4a841aecd)
* [CNTRLPLANE-3361](https://issues.redhat.com/browse/CNTRLPLANE-3361): Update openshift/* [#957](https://github.com/openshift/cluster-authentication-operator/pull/957)
* NO-JIRA: Automatic agentic rebase: Update library-go to d8f45c2 [#954](https://github.com/openshift/cluster-authentication-operator/pull/954)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: implement UpdateKMSEncryptionStatus [#953](https://github.com/openshift/cluster-authentication-operator/pull/953)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: use AuthenticationInterface instead of Clientset [#952](https://github.com/openshift/cluster-authentication-operator/pull/952)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): intro authenticationEncryptionStatusProvider [#951](https://github.com/openshift/cluster-authentication-operator/pull/951)
* NO-JIRA: kms to kms key identifier check [#941](https://github.com/openshift/cluster-authentication-operator/pull/941)
* NO-JIRA: Bump library-go to sync [#948](https://github.com/openshift/cluster-authentication-operator/pull/948)
* [CNTRLPLANE-3234](https://issues.redhat.com/browse/CNTRLPLANE-3234): wire KMS health reporter status writer [#947](https://github.com/openshift/cluster-authentication-operator/pull/947)
* [OCPBUGS-87480](https://issues.redhat.com/browse/OCPBUGS-87480): Updating ose-cluster-authentication-operator-container image to be consistent with ART for 5.0 [#934](https://github.com/openshift/cluster-authentication-operator/pull/934)
* [CNTRLPLANE-2589](https://issues.redhat.com/browse/CNTRLPLANE-2589): Migrate test/e2e-encryption to OpenShift Tests Extension framework [#944](https://github.com/openshift/cluster-authentication-operator/pull/944)
* [CNTRLPLANE-2589](https://issues.redhat.com/browse/CNTRLPLANE-2589): Migrate test/e2e-encryption-rotation to OpenShift Tests Extension framework [#943](https://github.com/openshift/cluster-authentication-operator/pull/943)
* NO-JIRA: Automatic agentic rebase: Update library-go to fd74bb5 [#940](https://github.com/openshift/cluster-authentication-operator/pull/940)
* [CNTRLPLANE-2589](https://issues.redhat.com/browse/CNTRLPLANE-2589): Migrate test/e2e-encryption-perf to OpenShift Tests Extension framework [#926](https://github.com/openshift/cluster-authentication-operator/pull/926)
* NO-JIRA: bump library-go funcs [#935](https://github.com/openshift/cluster-authentication-operator/pull/935)
* NO-JIRA: Add test for KMS to KMS migration [#938](https://github.com/openshift/cluster-authentication-operator/pull/938)
* NO-JIRA: Bump library-go for sync [#936](https://github.com/openshift/cluster-authentication-operator/pull/936)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/60f4dee2ea47070dbc5bf34042db50fb2e63f7c1...482d82f81fc7b460eb3f4024c7fcb4c4a841aecd)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/70920d3c6f5ff55d0eb72368767a81aea1a62abb)
* [OCPBUGS-92799](https://issues.redhat.com/browse/OCPBUGS-92799): UPSTREAM: 10001: chore(clusterapi): add machine phase check for failed machines [#430](https://github.com/openshift/kubernetes-autoscaler/pull/430)
* [AUTOSCALE-637](https://issues.redhat.com/browse/AUTOSCALE-637): Fix VPA E2E vendoring [#429](https://github.com/openshift/kubernetes-autoscaler/pull/429)
* [AUTOSCALE-555](https://issues.redhat.com/browse/AUTOSCALE-555): adding openshift provider [#417](https://github.com/openshift/kubernetes-autoscaler/pull/417)
* NO-JIRA: add coderabbit configuration file [#422](https://github.com/openshift/kubernetes-autoscaler/pull/422)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/02af1a9fd6bcb87745979980fbbf9a2b0671dddb...70920d3c6f5ff55d0eb72368767a81aea1a62abb)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/4eba1788615dcaf77498d063f51812d5d4b2281a)
* [AUTOSCALE-642](https://issues.redhat.com/browse/AUTOSCALE-642): Release chores 5.0 [#380](https://github.com/openshift/cluster-autoscaler-operator/pull/380)
* NO-JIRA: add coderabbit configuration file [#375](https://github.com/openshift/cluster-autoscaler-operator/pull/375)
* NO-JIRA: update owners file with autoscale team members [#379](https://github.com/openshift/cluster-autoscaler-operator/pull/379)
* [AUTOSCALE-555](https://issues.redhat.com/browse/AUTOSCALE-555): change default cloud provider to openshift [#368](https://github.com/openshift/cluster-autoscaler-operator/pull/368)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/f8fc286e8fe102766b191410e66dfc2554bbe17f...4eba1788615dcaf77498d063f51812d5d4b2281a)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/fd483524f88dd685d663aa46b21803b7a24c5c69)
* [METAL-1795](https://issues.redhat.com/browse/METAL-1795): Add TLS group/curve support [#632](https://github.com/openshift/cluster-baremetal-operator/pull/632)
* [OCPBUGS-99278](https://issues.redhat.com/browse/OCPBUGS-99278): Apply cluster TLS profile to ironic-proxy container [#633](https://github.com/openshift/cluster-baremetal-operator/pull/633)
* [OCPBUGS-99220](https://issues.redhat.com/browse/OCPBUGS-99220): static-ip-manager should be optional [#631](https://github.com/openshift/cluster-baremetal-operator/pull/631)
* [OCPBUGS-66101](https://issues.redhat.com/browse/OCPBUGS-66101): Set Progressing=True during cluster update [#629](https://github.com/openshift/cluster-baremetal-operator/pull/629)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add nic_validation OTE test [#627](https://github.com/openshift/cluster-baremetal-operator/pull/627)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add multi_arch_worker OTE test [#625](https://github.com/openshift/cluster-baremetal-operator/pull/625)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add cbo OTE test [#619](https://github.com/openshift/cluster-baremetal-operator/pull/619)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Fix ironic auth tests to run inside metal3-ironic pod [#626](https://github.com/openshift/cluster-baremetal-operator/pull/626)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Fix hermetic build compatibility for go-bindata [#623](https://github.com/openshift/cluster-baremetal-operator/pull/623)
* Bug OCPBUGS-90496: Remove metadata.namespace from cluster-scoped ClusterRoleBinding [#616](https://github.com/openshift/cluster-baremetal-operator/pull/616)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add otp tags to ironic tests [#624](https://github.com/openshift/cluster-baremetal-operator/pull/624)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Remove openshift-tests-private from vendor directory [#621](https://github.com/openshift/cluster-baremetal-operator/pull/621)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add ironic_* tests to CBO test extension [#615](https://github.com/openshift/cluster-baremetal-operator/pull/615)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add self-contained OTE tests [#612](https://github.com/openshift/cluster-baremetal-operator/pull/612)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add OTE framework and deployment_sanity tests [#609](https://github.com/openshift/cluster-baremetal-operator/pull/609)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/3c65cfcd29414ddf50c0f4c3cdf6030dfd715d2f...fd483524f88dd685d663aa46b21803b7a24c5c69)
### [cluster-capi-controllers](https://github.com/openshift/cluster-api/tree/16b6909b3c73d84fe1fbda0d12f9be80aaae00db)
* 🚀 OCPCLOUD-3598: Merge https://github.com/kubernetes-sigs/cluster-api:v1.13.4 (27f4644) into main [#298](https://github.com/openshift/cluster-api/pull/298)
* [CORS-4534](https://issues.redhat.com/browse/CORS-4534): UPSTREAM: <carry>: Enable MachineTaintPropagation feature gate [#303](https://github.com/openshift/cluster-api/pull/303)
* [OCPBUGS-85337](https://issues.redhat.com/browse/OCPBUGS-85337): set imagePullPolicy IfNotPresent on provider workloads [#302](https://github.com/openshift/cluster-api/pull/302)
* [Full changelog](https://github.com/openshift/cluster-api/compare/4917d86210f4decb58a7added337c209335d1314...16b6909b3c73d84fe1fbda0d12f9be80aaae00db)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/5767be9caecedf9dbbd2bdfd04633514b34b408f)
* [CORS-4512](https://issues.redhat.com/browse/CORS-4512): aws: allow privateDNSName and assignPrimaryIPv6 field on CAPI machines in dual-stack clusters [#592](https://github.com/openshift/cluster-capi-operator/pull/592)
* [CORS-4512](https://issues.redhat.com/browse/CORS-4512): aws: set IPv6 block on AWSCluster in dual-stack clusters [#593](https://github.com/openshift/cluster-capi-operator/pull/593)
* [OCPCLOUD-3607](https://issues.redhat.com/browse/OCPCLOUD-3607): Bump K8S to 1.36 [#628](https://github.com/openshift/cluster-capi-operator/pull/628)
* [OCPCLOUD-3368](https://issues.redhat.com/browse/OCPCLOUD-3368): Adding annotations to manifests for CVO to identify [#588](https://github.com/openshift/cluster-capi-operator/pull/588)
* [OCPCLOUD-3366](https://issues.redhat.com/browse/OCPCLOUD-3366): crdcompatibility: add validation for CRDData.Type field [#625](https://github.com/openshift/cluster-capi-operator/pull/625)
* [OCPCLOUD-3542](https://issues.redhat.com/browse/OCPCLOUD-3542): Add CRD Compatibility Checker OTE e2e tests [#599](https://github.com/openshift/cluster-capi-operator/pull/599)
* [OCPBUGS-98329](https://issues.redhat.com/browse/OCPBUGS-98329): Add aggregated cluster role for extended per-provider RBAC [#623](https://github.com/openshift/cluster-capi-operator/pull/623)
* [OCPCLOUD-3539](https://issues.redhat.com/browse/OCPCLOUD-3539): add topology-aware operator for CRD Compatibility Checker [#600](https://github.com/openshift/cluster-capi-operator/pull/600)
* [OCPCLOUD-3553](https://issues.redhat.com/browse/OCPCLOUD-3553): change webhook failurePolicy to Fail [#620](https://github.com/openshift/cluster-capi-operator/pull/620)
* [OCPCLOUD-1645](https://issues.redhat.com/browse/OCPCLOUD-1645): Scope capi-controllers RBAC to least-privilege [#585](https://github.com/openshift/cluster-capi-operator/pull/585)
* [OCPCLOUD-3451](https://issues.redhat.com/browse/OCPCLOUD-3451): Scope capi-operator and capi-installer RBAC to least-privilege [#607](https://github.com/openshift/cluster-capi-operator/pull/607)
* [OCPBUGS-88035](https://issues.redhat.com/browse/OCPBUGS-88035): Add e2e test verifying CAPI EC2 instance ownership tag [#594](https://github.com/openshift/cluster-capi-operator/pull/594)
* [OCPBUGS-92817](https://issues.redhat.com/browse/OCPBUGS-92817): delete MAPI MachineSets before CAPI in e2e cleanup [#611](https://github.com/openshift/cluster-capi-operator/pull/611)
* NO-JIRA: Bump golang.org/x/net to 0.56.0 to fix CVE [#617](https://github.com/openshift/cluster-capi-operator/pull/617)
* [OCPBUGS-85337](https://issues.redhat.com/browse/OCPBUGS-85337): fix(manifests-gen): set imagePullPolicy IfNotPresent on provider workloads [#618](https://github.com/openshift/cluster-capi-operator/pull/618)
* [OCPBUGS-87268](https://issues.redhat.com/browse/OCPBUGS-87268): Updating ose-cluster-capi-operator-container image to be consistent with ART for 5.0 [#582](https://github.com/openshift/cluster-capi-operator/pull/582)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/4cf948fcb3967aceedbebd1c35cc8368857c160d...5767be9caecedf9dbbd2bdfd04633514b34b408f)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/38f5e00cbd0085f6b62b98cd9ed044f54c89ad07)
* [SPLAT-2713](https://issues.redhat.com/browse/SPLAT-2713): Reapply "Merge pull request #476" to bring in e2e for BYO SG for AWS NLB [#492](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/492)
* [OCPBUGS-98617](https://issues.redhat.com/browse/OCPBUGS-98617): Fixes daemonset Progressing=True logic [#490](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/490)
* Revert #476 "SPLAT-2713: Update AWS CCM e2e test module version" [#491](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/491)
* [SPLAT-2713](https://issues.redhat.com/browse/SPLAT-2713): Update AWS CCM e2e test module version [#476](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/476)
* [OCPBUGS-64852](https://issues.redhat.com/browse/OCPBUGS-64852): Fixes progressing=True condition reporting [#488](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/488)
* [TRT-2777](https://issues.redhat.com/browse/TRT-2777): Revert #479 "Revert 'TRT-2754: Revert Updates clusteroperator_controller progressing'" [#487](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/487)
* [OCPBUGS-64852](https://issues.redhat.com/browse/OCPBUGS-64852): Revert "TRT-2754: Revert "Updates clusteroperator_controller progressing"" [#479](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/479)
* [OCPBUGS-87334](https://issues.redhat.com/browse/OCPBUGS-87334): update Dockerfile base image to ocp/5.0 [#483](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/483)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/4f8df24f1c4176888643e2d3cedd6a33ae76fd4b...38f5e00cbd0085f6b62b98cd9ed044f54c89ad07)
### [cluster-config-api](https://github.com/openshift/api/tree/9bcaa16cb258e544dd76b78ff2dc3f89af840f76)
* Check all hypershift variants when the featuregate is not platform specific [#2951](https://github.com/openshift/api/pull/2951)
* [OCPBUGS-80958](https://issues.redhat.com/browse/OCPBUGS-80958): NodeUID in status to detect replaced node with same name [#2821](https://github.com/openshift/api/pull/2821)
* [OPRUN-4691](https://issues.redhat.com/browse/OPRUN-4691): Promote OLMLifecycleAndCompatibility feature gate to Default [#2920](https://github.com/openshift/api/pull/2920)
* [OPNET-780](https://issues.redhat.com/browse/OPNET-780): Add BGPBasedVIPManagement feature gate and BGP VIP management fields [#2923](https://github.com/openshift/api/pull/2923)
* [CNTRLPLANE-3361](https://issues.redhat.com/browse/CNTRLPLANE-3361): Align with latest beta API of Vault [#2936](https://github.com/openshift/api/pull/2936)
* Update KAL to latest [#2939](https://github.com/openshift/api/pull/2939)
* [NE-2569](https://issues.redhat.com/browse/NE-2569): Promote Dynamic Configuration Manager to Default [#2788](https://github.com/openshift/api/pull/2788)
* Adapt publish kubebuilder tools to ocp5 + publish k8s v1.36 kubebuilder tools [#2941](https://github.com/openshift/api/pull/2941)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): Add KMS preflight check API to operator/v1 [#2916](https://github.com/openshift/api/pull/2916)
* [CORS-4435](https://issues.redhat.com/browse/CORS-4435): GCP Sovereign Cloud Feature Gate [#2810](https://github.com/openshift/api/pull/2810)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#2813](https://github.com/openshift/api/pull/2813)
* [OCPBUGS-91634](https://issues.redhat.com/browse/OCPBUGS-91634): CAPI: Fix ImageDigestFormat validation to allow deep registry paths [#2918](https://github.com/openshift/api/pull/2918)
* Sippy timestamp filter should use Millisecond unix timestamp for proper filtering [#2928](https://github.com/openshift/api/pull/2928)
* Remove AzureClusterHostedDNSInstall Featuregate [#2902](https://github.com/openshift/api/pull/2902)
* [OCPNODE-4604](https://issues.redhat.com/browse/OCPNODE-4604): Upgrade v1 criocp payload resource [#2900](https://github.com/openshift/api/pull/2900)
* [CONSOLE-5163](https://issues.redhat.com/browse/CONSOLE-5163): Add labels field to Ingress componentRoutes [#2845](https://github.com/openshift/api/pull/2845)
* tooling: Update `verify-feature-promotion` logic for installer-focused features [#2903](https://github.com/openshift/api/pull/2903)
* [CNTRLPLANE-3751](https://issues.redhat.com/browse/CNTRLPLANE-3751): osin: Add ProxyTrustedCA field to OAuthConfig [#2917](https://github.com/openshift/api/pull/2917)
* Integrate models-schema into codegen and fix openapi verify issues [#2904](https://github.com/openshift/api/pull/2904)
* [CNTRLPLANE-3629](https://issues.redhat.com/browse/CNTRLPLANE-3629): features: promote ExternalOIDCExternalClaimsSourcing to TechPreviewNoUpgrade [#2893](https://github.com/openshift/api/pull/2893)
* [CNTRLPLANE-3745](https://issues.redhat.com/browse/CNTRLPLANE-3745): Add AuthenticationComponentProxy API for component-scoped proxy [#2909](https://github.com/openshift/api/pull/2909)
* [NE-2217](https://issues.redhat.com/browse/NE-2217): Add haproxyVersion in IngressController API [#2895](https://github.com/openshift/api/pull/2895)
* [SSCSI-245](https://issues.redhat.com/browse/SSCSI-245): Rename rotationPollIntervalSeconds to minimumRefreshAge [#2906](https://github.com/openshift/api/pull/2906)
* [OCPBUGS-94869](https://issues.redhat.com/browse/OCPBUGS-94869): fix(crd): adjust storage settings for CRIOCredentialProviderConfig [#2913](https://github.com/openshift/api/pull/2913)
* [AGENT-1522](https://issues.redhat.com/browse/AGENT-1522): Graduate InternalReleaseImage from v1alpha1 to v1 [#2880](https://github.com/openshift/api/pull/2880)
* [PIXAA-16](https://issues.redhat.com/browse/PIXAA-16): Updates API review skill [#2910](https://github.com/openshift/api/pull/2910)
* [NE-2729](https://issues.redhat.com/browse/NE-2729): Add feature gate for multiple HAProxy versions [#2852](https://github.com/openshift/api/pull/2852)
* CORENET-6714 Adding documentation [#2907](https://github.com/openshift/api/pull/2907)
* MON: rename remote write SafeAuthorization to Authorization [#2901](https://github.com/openshift/api/pull/2901)
* [AUTOSCALE-827](https://issues.redhat.com/browse/AUTOSCALE-827): add KarpenterOperator feature gate [#2898](https://github.com/openshift/api/pull/2898)
* Add Protobuf generation to the codegen utility [#1385](https://github.com/openshift/api/pull/1385)
* [SPLAT-2718](https://issues.redhat.com/browse/SPLAT-2718): Promote VSphereMixedNodeEnv to GA [#2798](https://github.com/openshift/api/pull/2798)
* [Full changelog](https://github.com/openshift/api/compare/3d22ba1007502a22d83aebecb29457d8ef124c5a...9bcaa16cb258e544dd76b78ff2dc3f89af840f76)
### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/a02c879931c6108326c0a514df0ce2e390f3536c)
* [CNTRLPLANE-2270](https://issues.redhat.com/browse/CNTRLPLANE-2270): Update README with operator responsibilities [#496](https://github.com/openshift/cluster-config-operator/pull/496)
* [Full changelog](https://github.com/openshift/cluster-config-operator/compare/a346b395960addcf7140551c78f86281d92d7dd2...a02c879931c6108326c0a514df0ce2e390f3536c)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/452cee8c1f4efb683fb6bcb15b61366695d98e1e)
* [OCPBUGS-87338](https://issues.redhat.com/browse/OCPBUGS-87338): Updating ose-cluster-control-plane-machine-set-operator-container image to be consistent with ART for 5.0 [#408](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/408)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/046a4ea83e45c3c1d5eb2d3ffc55a7e7d17fcc3c...452cee8c1f4efb683fb6bcb15b61366695d98e1e)
### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/67648d56d6b312e661714f8e7bf0e9be1d532c1c)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#285](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/285)
* [STOR-2967](https://issues.redhat.com/browse/STOR-2967): Update SnapshotMetadataService CRD asset from v1alpha1 to v1beta1 [#279](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/279)
* [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/d7262f23f8c661ef6a215377b9571b615a1ae0b8...67648d56d6b312e661714f8e7bf0e9be1d532c1c)
### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/4b8ae49940eefc50fa48da5179e735dd6ccd42d9)
* [NE-2765](https://issues.redhat.com/browse/NE-2765): Bump Kubernetes to 1.36.2 and Go to 1.26 [#483](https://github.com/openshift/cluster-dns-operator/pull/483)
* [NE-2743](https://issues.redhat.com/browse/NE-2743): Support centralized TLS security profiles for CDO metrics [#482](https://github.com/openshift/cluster-dns-operator/pull/482)
* NO-JIRA: Add aswinsuryan (asuryana@redhat.com) to OWNERS [#479](https://github.com/openshift/cluster-dns-operator/pull/479)
* [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/8395f9054f235aec2cd5185019d201146c9827ed...4b8ae49940eefc50fa48da5179e735dd6ccd42d9)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/ebea15aeb57ecaca4ff8e8fdf5aa28d5a4469d12)
* [OCPEDGE-2707](https://issues.redhat.com/browse/OCPEDGE-2707): Add TNF Pacemaker PrometheusRule alerts [#1650](https://github.com/openshift/cluster-etcd-operator/pull/1650)
* [CNTRLPLANE-2847](https://issues.redhat.com/browse/CNTRLPLANE-2847): render: Read FeatureGate CR from rendered manifests [#1648](https://github.com/openshift/cluster-etcd-operator/pull/1648)
* [OCPEDGE-2705](https://issues.redhat.com/browse/OCPEDGE-2705): Add TNF Pacemaker metrics controller [#1634](https://github.com/openshift/cluster-etcd-operator/pull/1634)
* [CNTRLPLANE-2847](https://issues.redhat.com/browse/CNTRLPLANE-2847): Support PKI customization [#1593](https://github.com/openshift/cluster-etcd-operator/pull/1593)
* [CNTRLPLANE-3727](https://issues.redhat.com/browse/CNTRLPLANE-3727): Agentic context docs and contributing guide [#1639](https://github.com/openshift/cluster-etcd-operator/pull/1639)
* [OCPBUGS-66334](https://issues.redhat.com/browse/OCPBUGS-66334): remove version check from guard precheck [#1520](https://github.com/openshift/cluster-etcd-operator/pull/1520)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/2b9daad1b36fc88a7d67e53f5210c760e9ff7800...ebea15aeb57ecaca4ff8e8fdf5aa28d5a4469d12)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/02bb5c2cd4d5f4d277cf987d6f65e58a732aefee)
* [OCPBUGS-99257](https://issues.redhat.com/browse/OCPBUGS-99257): Improve GCS KMS encryption error handling and documentation [#1344](https://github.com/openshift/cluster-image-registry-operator/pull/1344)
* [CORENET-7355](https://issues.redhat.com/browse/CORENET-7355): Remove redundant ingress rule from image-registry netpol [#1354](https://github.com/openshift/cluster-image-registry-operator/pull/1354)
* [OCPBUGS-96818](https://issues.redhat.com/browse/OCPBUGS-96818): bump golang.org/x/net [#1353](https://github.com/openshift/cluster-image-registry-operator/pull/1353)
* [OCPBUGS-85107](https://issues.redhat.com/browse/OCPBUGS-85107): fix required-scc annotation on image-pruner pods [#1351](https://github.com/openshift/cluster-image-registry-operator/pull/1351)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/d30e780bad20389fd85eaac6dbb6e1ffae958bbe...02bb5c2cd4d5f4d277cf987d6f65e58a732aefee)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/d7aafd957d1c126f5241ab716ad55ad0d160c042)
* [OCPBUGS-90616](https://issues.redhat.com/browse/OCPBUGS-90616): Add GRPCRoute to Gateway API e2e CRD test coverage [#1482](https://github.com/openshift/cluster-ingress-operator/pull/1482)
* [NE-2737](https://issues.redhat.com/browse/NE-2737): Add support for TLS curves in router deployment configuration [#1478](https://github.com/openshift/cluster-ingress-operator/pull/1478)
* [NE-2764](https://issues.redhat.com/browse/NE-2764): Bump Kubernetes to 1.36.2 and Go to 1.26 [#1505](https://github.com/openshift/cluster-ingress-operator/pull/1505)
* [OCPBUGS-98310](https://issues.redhat.com/browse/OCPBUGS-98310): Bump sail-operator install library to OSSM 3.4.0 [#1508](https://github.com/openshift/cluster-ingress-operator/pull/1508)
* [NE-2219](https://issues.redhat.com/browse/NE-2219): Select HAProxy version from IngressController API [#1498](https://github.com/openshift/cluster-ingress-operator/pull/1498)
* [TRT-2793](https://issues.redhat.com/browse/TRT-2793): Revert Bump sail-operator install library to OSSM 3.4.0 [#1507](https://github.com/openshift/cluster-ingress-operator/pull/1507)
* [OCPBUGS-98310](https://issues.redhat.com/browse/OCPBUGS-98310): vendor sail-operator install library from OSSM 3.4 [#1456](https://github.com/openshift/cluster-ingress-operator/pull/1456)
* [NE-2218](https://issues.redhat.com/browse/NE-2218): Add new HAProxy 2.8 and 3.2 image references [#1499](https://github.com/openshift/cluster-ingress-operator/pull/1499)
* [NE-2664](https://issues.redhat.com/browse/NE-2664): deploy haproxy as sidecar [#1484](https://github.com/openshift/cluster-ingress-operator/pull/1484)
* [OCPBUGS-86833](https://issues.redhat.com/browse/OCPBUGS-86833): Detect orphaned OSSM subscription after noOLM migration [#1475](https://github.com/openshift/cluster-ingress-operator/pull/1475)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/8908668eac379bd29431c70f195618efa0337522...d7aafd957d1c126f5241ab716ad55ad0d160c042)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/dab04ebace1a4b36bb40e8f4f87804754b69760b)
* [CNTRLPLANE-3361](https://issues.redhat.com/browse/CNTRLPLANE-3361): Update openshift/* [#2247](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2247)
* [CNTRLPLANE-3861](https://issues.redhat.com/browse/CNTRLPLANE-3861): Add KMS plugin sidecar revision readiness check [#2220](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2220)
* NO-JIRA: Automatic agentic rebase: Update library-go to d8f45c2 [#2238](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2238)
* NO-JIRA: Add KMS key ID identifier [#2237](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2237)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: use KubeAPIServersGetter instead of Clientset [#2235](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2235)
* NO-JIRA: Refactor KMS cases [#2229](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2229)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): intro kubeAPIServerEncryptionStatusProvider [#2230](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2230)
* NO-JIRA: Remove old test files [#2232](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2232)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#2129](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2129)
* NO-JIRA: Bump library-go to sync [#2227](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2227)
* NO-JIRA: Remove old helper and assertion func [#2223](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2223)
* [OCPBUGS-38661](https://issues.redhat.com/browse/OCPBUGS-38661): Add 10-minute degraded inertia for StaticPodsDegraded [#2221](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2221)
* [CNTRLPLANE-3234](https://issues.redhat.com/browse/CNTRLPLANE-3234): wire KMS health reporter status writer [#2224](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2224)
* [OCPBUGS-38661](https://issues.redhat.com/browse/OCPBUGS-38661): Add 10-minute degraded inertia for NodeControllerDegraded [#2219](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2219)
* NO-JIRA: Automatic agentic rebase: Update library-go to fd74bb5 [#2216](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2216)
* [CNTRLPLANE-3721](https://issues.redhat.com/browse/CNTRLPLANE-3721): Add developer/agent documentation: CONTRIBUTING.md, AGENTS.md, ARCHITECTURE.md [#2213](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2213)
* [API-1768](https://issues.redhat.com/browse/API-1768): e2e network policy tests [#2097](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2097)
* NO-JIRA: Add test for kms to kms migration [#2215](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2215)
* NO-JIRA: Bump library-go for sync [#2214](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2214)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/5e0353a93bfa9a7dbe3a5afe9e9e3b0aa66fe585...dab04ebace1a4b36bb40e8f4f87804754b69760b)
### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/4e72164b8bc505033ad565ab01d57963e7c9688e)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#930](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/930)
* [OCPBUGS-38662](https://issues.redhat.com/browse/OCPBUGS-38662): Add 10-minute degraded inertia for StaticPodsDegraded [#948](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/948)
* [OCPBUGS-38662](https://issues.redhat.com/browse/OCPBUGS-38662): Add 10-minute degraded inertia for NodeControllerDegraded [#947](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/947)
* NO-JIRA: Use %w for error wrapping consistently [#946](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/946)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/c35307f04313369c9ba4dcab3308506a3987065e...4e72164b8bc505033ad565ab01d57963e7c9688e)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#646](https://github.com/openshift/cluster-kube-scheduler-operator/pull/646)
* [OCPBUGS-38663](https://issues.redhat.com/browse/OCPBUGS-38663): Add 10-minute degraded inertia for StaticPodsDegraded [#655](https://github.com/openshift/cluster-kube-scheduler-operator/pull/655)
* [OCPBUGS-38663](https://issues.redhat.com/browse/OCPBUGS-38663): Add 10-minute degraded inertia for NodeControllerDegraded [#654](https://github.com/openshift/cluster-kube-scheduler-operator/pull/654)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/d43423b583269eea8236040424609c3f108ac9c4...56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/5042b52541130c3856028e29c7142d477c3f7d7d)
* NO-JIRA: Revert "MON-3697: use maximumStartupDurationSeconds instead of container patch" [#2982](https://github.com/openshift/cluster-monitoring-operator/pull/2982)
* [MON-4558](https://issues.redhat.com/browse/MON-4558): enable zoneinfo node-exporter collector via config [#2986](https://github.com/openshift/cluster-monitoring-operator/pull/2986)
* [OCPBUGS-98450](https://issues.redhat.com/browse/OCPBUGS-98450): fall back to kube-system/global-pull-secret for telemeter-client token [#2985](https://github.com/openshift/cluster-monitoring-operator/pull/2985)
* NO-ISSUE: Update prometheus-operator dependencies [#2966](https://github.com/openshift/cluster-monitoring-operator/pull/2966)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): manually pass features to monitoring plugin [#2987](https://github.com/openshift/cluster-monitoring-operator/pull/2987)
* [OCPBUGS-99019](https://issues.redhat.com/browse/OCPBUGS-99019): jsonnet: exclude AlertmanagerClusterFailedPeers from shipped rules [#2993](https://github.com/openshift/cluster-monitoring-operator/pull/2993)
* [MON-4523](https://issues.redhat.com/browse/MON-4523): ClusterMonitoring prometheusConfig [#2953](https://github.com/openshift/cluster-monitoring-operator/pull/2953)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): config path to point to correct directory [#2981](https://github.com/openshift/cluster-monitoring-operator/pull/2981)
* [OCPBUGS-93756](https://issues.redhat.com/browse/OCPBUGS-93756): update github.com/prometheus/prometheus [#2979](https://github.com/openshift/cluster-monitoring-operator/pull/2979)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/2b502a5c620bf10837655f72eec520d4078d5fa7...5042b52541130c3856028e29c7142d477c3f7d7d)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/00e6cc59b92af5c8f73f9c3908ed3b0ef591bf63)
* [OCPBUGS-88063](https://issues.redhat.com/browse/OCPBUGS-88063): ovn-kubernetes: Move MNP from ConfigMap to CLI flags [#3072](https://github.com/openshift/cluster-network-operator/pull/3072)
* [CNTRLPLANE-3213](https://issues.redhat.com/browse/CNTRLPLANE-3213): Enable configurable PKI for managed certificate rotation [#2958](https://github.com/openshift/cluster-network-operator/pull/2958)
* [CORENET-6581](https://issues.redhat.com/browse/CORENET-6581): Add transport label to CUDN telemetry recording rule [#2978](https://github.com/openshift/cluster-network-operator/pull/2978)
* [OCPBUGS-98619](https://issues.redhat.com/browse/OCPBUGS-98619): Bump frr-k8s MAX_FDS from 1024 to 65536 [#3054](https://github.com/openshift/cluster-network-operator/pull/3054)
* Revert "Enable Network Observability on Day 0" (#2925) [#3086](https://github.com/openshift/cluster-network-operator/pull/3086)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Enable Network Observability on Day 0 [#2925](https://github.com/openshift/cluster-network-operator/pull/2925)
* [OCPBUGS-99074](https://issues.redhat.com/browse/OCPBUGS-99074): Align frr-k8s 5.0 CRDs [#3070](https://github.com/openshift/cluster-network-operator/pull/3070)
* [CORENET-7046](https://issues.redhat.com/browse/CORENET-7046): Bump Kubernetes to 1.36.2 and OCP to 5.0 [#3017](https://github.com/openshift/cluster-network-operator/pull/3017)
* [CORENET-7125](https://issues.redhat.com/browse/CORENET-7125): iptables to nftables [#3038](https://github.com/openshift/cluster-network-operator/pull/3038)
* NO-JIRA: Refresh Reviewers & Approvers lists [#3048](https://github.com/openshift/cluster-network-operator/pull/3048)
* [OCPBUGS-62144](https://issues.redhat.com/browse/OCPBUGS-62144): Makes sure rendering for egress IP reachabilityTimeout triggers restart of ovnkube (node/control) pods [#2955](https://github.com/openshift/cluster-network-operator/pull/2955)
* [CORENET-7267](https://issues.redhat.com/browse/CORENET-7267): Add pre-merge and custom checks to CodeRabbit configuration [#3037](https://github.com/openshift/cluster-network-operator/pull/3037)
* [NVIDIA-882](https://issues.redhat.com/browse/NVIDIA-882): DPU host: add configurable mgmt-port-resource-count [#3024](https://github.com/openshift/cluster-network-operator/pull/3024)
* [OCPBUGS-88531](https://issues.redhat.com/browse/OCPBUGS-88531): Propagate restart-date annotation to CNO operand pod templates [#3030](https://github.com/openshift/cluster-network-operator/pull/3030)
* NO-JIRA: Update OWNERS file [#3045](https://github.com/openshift/cluster-network-operator/pull/3045)
* [OCPBUGS-87977](https://issues.redhat.com/browse/OCPBUGS-87977): Bump github.com/containernetworking/cni v0.8.0 -> v1.3.0 [#3031](https://github.com/openshift/cluster-network-operator/pull/3031)
* [CORENET-7114](https://issues.redhat.com/browse/CORENET-7114): Add OCP centralized TLS profile support [#3014](https://github.com/openshift/cluster-network-operator/pull/3014)
* [CORENET-7266](https://issues.redhat.com/browse/CORENET-7266): Add path-specific review instructions to CodeRabbit config [#3039](https://github.com/openshift/cluster-network-operator/pull/3039)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/7b341b420baeb655d65e551a1f04e3bcbe2631f1...00e6cc59b92af5c8f73f9c3908ed3b0ef591bf63)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/a9d25d502ca894272f88753f1bd7ecef82fb188e)
* [OCPBUGS-97809](https://issues.redhat.com/browse/OCPBUGS-97809): e2e: fix broken checks and rework netqueue tests to avoid ARM ethtool blackout flakes [#1557](https://github.com/openshift/cluster-node-tuning-operator/pull/1557)
* [OCPBUGS-98915](https://issues.redhat.com/browse/OCPBUGS-98915): E2E: LLC: Pass fresh ctx variable to DeferCleanup functions [#1562](https://github.com/openshift/cluster-node-tuning-operator/pull/1562)
* [CNF-23471](https://issues.redhat.com/browse/CNF-23471): Dedicate cpus for dpdk vswitch [#1546](https://github.com/openshift/cluster-node-tuning-operator/pull/1546)
* [OCPBUGS-98399](https://issues.redhat.com/browse/OCPBUGS-98399): E2E: Add functional test cases checking GOMAXPROCS [#1556](https://github.com/openshift/cluster-node-tuning-operator/pull/1556)
* [OCPBUGS-93863](https://issues.redhat.com/browse/OCPBUGS-93863): E2E: Fix tuned active profile check for wrapped performance profiles [#1549](https://github.com/openshift/cluster-node-tuning-operator/pull/1549)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/8b4b292a427c90a45988432380c37196fba7e9d7...a9d25d502ca894272f88753f1bd7ecef82fb188e)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/9983877dbed43c0ae050ad4646e31b9cfbd41329)
* [OCPBUGS-95475](https://issues.redhat.com/browse/OCPBUGS-95475): chore: bump containerd to 1.7.33 [#223](https://github.com/openshift/cluster-olm-operator/pull/223)
* [OPRUN-4676](https://issues.redhat.com/browse/OPRUN-4676): support service account deprecation for OCP 5.0 [#222](https://github.com/openshift/cluster-olm-operator/pull/222)
* [OPRUN-4696](https://issues.redhat.com/browse/OPRUN-4696): fix upgrade block message and add 5.0 cluster unit tests [#216](https://github.com/openshift/cluster-olm-operator/pull/216)
* NO-ISSUE: Remove stale reviewers/approvers, add trgeiger [#220](https://github.com/openshift/cluster-olm-operator/pull/220)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/795384212aa1ec66d3c176b33bd7ecc6a38fd560...9983877dbed43c0ae050ad4646e31b9cfbd41329)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/7bac3548875ec36a6c4967df818ccae533dcce7c)
* [CNTRLPLANE-3361](https://issues.redhat.com/browse/CNTRLPLANE-3361): Update openshift/* [#740](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/740)
* NO-JIRA: Automatic agentic rebase: Update library-go to d8f45c2 [#737](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/737)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: implement UpdateKMSEncryptionStatus [#736](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/736)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): encryptionstatusprovider: use OpenShiftAPIServerInterface instead of Clientset [#735](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/735)
* NO-JIRA: kms to kms key identifier check [#728](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/728)
* [OCPBUGS-87507](https://issues.redhat.com/browse/OCPBUGS-87507): Updating ose-cluster-openshift-apiserver-operator-container image to be consistent with ART for 5.0 [#705](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/705)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): intro openShiftAPIServerEncryptionStatusProvider [#734](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/734)
* NO-JIRA: Bump library-go to sync [#732](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/732)
* [CNTRLPLANE-3234](https://issues.redhat.com/browse/CNTRLPLANE-3234): wire KMS health reporter status writer [#730](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/730)
* [OCPBUGS-86583](https://issues.redhat.com/browse/OCPBUGS-86583): Allow Prometheus to scrape check-endpoints metrics on port 17698 [#729](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/729)
* NO-JIRA: Automatic agentic rebase: Update library-go to fd74bb5 [#727](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/727)
* NO-JIRA: update func from library-go [#724](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/724)
* NO-JIRA: Add test for KMS to KMS migration [#726](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/726)
* NO-JIRA: Bump library-go for sync [#725](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/725)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/ec1966f2ba07c78e248fe218cbd15564d828a8dc...7bac3548875ec36a6c4967df818ccae533dcce7c)
### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/01afc4aac71a8e8be26383a0421bed7673391750)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Bump to Kube v1.36.2 [#197](https://github.com/openshift/cluster-policy-controller/pull/197)
* [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/050c1ee6aeb0838daf75858fd853cca1e0098fa9...01afc4aac71a8e8be26383a0421bed7673391750)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/8ac48254009fb4987bee1f3e00cbb8e4d730f545)
* [STOR-3011](https://issues.redhat.com/browse/STOR-3011): Implement CSO upgrade check and Prometheus alerts for SELinuxMount readiness [#714](https://github.com/openshift/cluster-storage-operator/pull/714)
* [STOR-2954](https://issues.redhat.com/browse/STOR-2954): Inject TLS from CVO to operators, update hypershift TLS based on CVO [#712](https://github.com/openshift/cluster-storage-operator/pull/712)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/1715686df95688a690e8071c88112aaf3983f4c8...8ac48254009fb4987bee1f3e00cbb8e4d730f545)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/70bafacd988182acbc5160d61088a6d1ddad785a)
* [TRT-2842](https://issues.redhat.com/browse/TRT-2842): Revert #1427 "OTA-1997: Allow the CVO to use the agentic-skills payload image when creating proposals." [#1431](https://github.com/openshift/cluster-version-operator/pull/1431)
* [OTA-1997](https://issues.redhat.com/browse/OTA-1997): Allow the CVO to use the agentic-skills payload image when creating proposals. [#1427](https://github.com/openshift/cluster-version-operator/pull/1427)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084), [OTA-2097](https://issues.redhat.com/browse/OTA-2097): pkg/agenticrun/controller: Additional logging to AgenticRun CRD detection [#1428](https://github.com/openshift/cluster-version-operator/pull/1428)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084): Conditionally deploy console plugin when AgenticRun CRD is present [#1425](https://github.com/openshift/cluster-version-operator/pull/1425)
* NO-JIRA: Fix make build target cd issue [#1404](https://github.com/openshift/cluster-version-operator/pull/1404)
* [OTA-2064](https://issues.redhat.com/browse/OTA-2064): Rename Proposal API to AgenticRun [#1422](https://github.com/openshift/cluster-version-operator/pull/1422)
* [OTA-1967](https://issues.redhat.com/browse/OTA-1967): install: Drop Lightspeed CustomResourceDefinitions (Proposal, etc.) [#1412](https://github.com/openshift/cluster-version-operator/pull/1412)
* [OTA-1956](https://issues.redhat.com/browse/OTA-1956): install: Split multi-document YAML and add missing annotations [#1423](https://github.com/openshift/cluster-version-operator/pull/1423)
* [OCPCLOUD-3368](https://issues.redhat.com/browse/OCPCLOUD-3368): bumping with o/api changes to reflect new capabilities (crdcompatibilitychecker+capi) [#1403](https://github.com/openshift/cluster-version-operator/pull/1403)
* [TRT-2776](https://issues.redhat.com/browse/TRT-2776): Revert #1398 "install: Split multi-document YAML and add missing annotations" [#1420](https://github.com/openshift/cluster-version-operator/pull/1420)
* [OTA-1956](https://issues.redhat.com/browse/OTA-1956): install: Split multi-document YAML and add missing annotations [#1398](https://github.com/openshift/cluster-version-operator/pull/1398)
* [OTA-1966](https://issues.redhat.com/browse/OTA-1966): AGENTS: Drop 'Deploying CVO with Lightspeed Proposals' section [#1414](https://github.com/openshift/cluster-version-operator/pull/1414)
* [OTA-1836](https://issues.redhat.com/browse/OTA-1836): Fix empty lister for API server (simplified a bit) [#1397](https://github.com/openshift/cluster-version-operator/pull/1397)
* [OCPBUGS-84513](https://issues.redhat.com/browse/OCPBUGS-84513): set terminationMessagePolicy on update-payload pods [#1417](https://github.com/openshift/cluster-version-operator/pull/1417)
* NO-JIRA: CONTRIBUTING.md: Improve the review process wording [#1419](https://github.com/openshift/cluster-version-operator/pull/1419)
* [OTA-1966](https://issues.redhat.com/browse/OTA-1966): pkg/readiness/crd_compat: Drop unnecessary CustomResourceDefinition check [#1415](https://github.com/openshift/cluster-version-operator/pull/1415)
* NO-JIRA: Handle the tests on Microshift environment [#1416](https://github.com/openshift/cluster-version-operator/pull/1416)
* [OCPBUGS-87461](https://issues.redhat.com/browse/OCPBUGS-87461): Updating cluster-version-operator-container image to be consistent with ART for 5.0 [#1400](https://github.com/openshift/cluster-version-operator/pull/1400)
* [CNTRLPLANE-3429](https://issues.redhat.com/browse/CNTRLPLANE-3429): Respect configured cipher order for inject-tls [#1386](https://github.com/openshift/cluster-version-operator/pull/1386)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/dd0a8410467a09cd181216e191825d4088ea2115...70bafacd988182acbc5160d61088a6d1ddad785a)
### [console](https://github.com/openshift/console/tree/6d0dcf1d76337e46d95ea1b546d5ffe692d7918d)
* [OCPBUGS-99226](https://issues.redhat.com/browse/OCPBUGS-99226): Disable Knative e2e cypress test [#16782](https://github.com/openshift/console/pull/16782)
* [OCPBUGS-99052](https://issues.redhat.com/browse/OCPBUGS-99052): recover from reverse proxy panic on browser disconnect [#16776](https://github.com/openshift/console/pull/16776)
* [OTA-2066](https://issues.redhat.com/browse/OTA-2066): AIA mitigations [#16763](https://github.com/openshift/console/pull/16763)
* [CONSOLE-5065](https://issues.redhat.com/browse/CONSOLE-5065): Clean up Console extension code reference processing [#16115](https://github.com/openshift/console/pull/16115)
* [CONSOLE-5426](https://issues.redhat.com/browse/CONSOLE-5426): remove GraphQL proxy endpoint [#16769](https://github.com/openshift/console/pull/16769)
* [OCPBUGS-79520](https://issues.redhat.com/browse/OCPBUGS-79520): Fix kebab actions on Installed Operators list page [#16682](https://github.com/openshift/console/pull/16682)
* [HELM-731](https://issues.redhat.com/browse/HELM-731): Upgrade helm in console [#16607](https://github.com/openshift/console/pull/16607)
* [OCPBUGS-98489](https://issues.redhat.com/browse/OCPBUGS-98489): CVE-2026-59869 bump js-yaml [#16760](https://github.com/openshift/console/pull/16760)
* [CONSOLE-5415](https://issues.redhat.com/browse/CONSOLE-5415), [OCPBUGS-94037](https://issues.redhat.com/browse/OCPBUGS-94037): Bump react-router to ~7.18.1 [#16726](https://github.com/openshift/console/pull/16726)
* NO-ISSUE: Add empty Prow techPreview e2e entrypoint scripts [#16766](https://github.com/openshift/console/pull/16766)
* NO-ISSUE: Match operator lifecycle versions by major.minor only [#16698](https://github.com/openshift/console/pull/16698)
* [CONSOLE-3956](https://issues.redhat.com/browse/CONSOLE-3956): Replace custom Shortcut components with PF ShortcutGrid [#16207](https://github.com/openshift/console/pull/16207)
* NO-ISSUE: Skip OLMv0-specific e2e tests when techPreview is enabled [#16759](https://github.com/openshift/console/pull/16759)
* [CONSOLE-5423](https://issues.redhat.com/browse/CONSOLE-5423): Add rspack support for dynamic plugins [#16752](https://github.com/openshift/console/pull/16752)
* [CONSOLE-5421](https://issues.redhat.com/browse/CONSOLE-5421): Rename "Self-support" to "Unsupported" and stack support phase date [#16742](https://github.com/openshift/console/pull/16742)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Fix flaky Playwright e2e tests caused by OAuth redirect timing [#16740](https://github.com/openshift/console/pull/16740)
* [CONSOLE-5306](https://issues.redhat.com/browse/CONSOLE-5306): Surface Playwright report link in Prow Spyglass [#16743](https://github.com/openshift/console/pull/16743)
* [OCPBUGS-50016](https://issues.redhat.com/browse/OCPBUGS-50016), [OCPBUGS-86587](https://issues.redhat.com/browse/OCPBUGS-86587): Bump to PF 6.6.0 [#16750](https://github.com/openshift/console/pull/16750)
* [OCPBUGS-88715](https://issues.redhat.com/browse/OCPBUGS-88715): Bump follow-redirects from 1.15.3 to 1.16.0 to remediate CVE-2026-40895 [#16590](https://github.com/openshift/console/pull/16590)
* [CONSOLE-5356](https://issues.redhat.com/browse/CONSOLE-5356): Add optional onSubmit parameter to useLabelsModal hook [#16560](https://github.com/openshift/console/pull/16560)
* [CONSOLE-5124](https://issues.redhat.com/browse/CONSOLE-5124): Multi-domain console backend support [#16686](https://github.com/openshift/console/pull/16686)
* NO-ISSUE: Return self-support when date is before all lifecycle phases [#16699](https://github.com/openshift/console/pull/16699)
* [CONSOLE-5398](https://issues.redhat.com/browse/CONSOLE-5398): Remove events card from node overview dashboard [#16697](https://github.com/openshift/console/pull/16697)
* [OCPBUGS-84721](https://issues.redhat.com/browse/OCPBUGS-84721): Fix WebSocket InvalidStateError in pod terminal [#16377](https://github.com/openshift/console/pull/16377)
* [CONSOLE-5306](https://issues.redhat.com/browse/CONSOLE-5306): Add Prow-compatible JUnit reporter for Playwright e2e tests [#16501](https://github.com/openshift/console/pull/16501)
* NO-JIRA: Prepare for publishing new 4.23 prerelease plugin SDK packages [#16713](https://github.com/openshift/console/pull/16713)
* [OCPBUGS-78980](https://issues.redhat.com/browse/OCPBUGS-78980): Update @graphql-codegen packages for Node.js 25 compatibility [#16240](https://github.com/openshift/console/pull/16240)
* [CONSOLE-5271](https://issues.redhat.com/browse/CONSOLE-5271): Gate lifecycle metadata on server-side OLM lifecycle flag [#16668](https://github.com/openshift/console/pull/16668)
* [OCPBUGS-94089](https://issues.redhat.com/browse/OCPBUGS-94089): Fix helm backend test setup reliability [#16687](https://github.com/openshift/console/pull/16687)
* [CONSOLE-5361](https://issues.redhat.com/browse/CONSOLE-5361): Add toast overflow and notification drawer integration [#16636](https://github.com/openshift/console/pull/16636)
* [CONSOLE-5183](https://issues.redhat.com/browse/CONSOLE-5183): Add persistent pod terminal sessions to Cloud Shell drawer [#16269](https://github.com/openshift/console/pull/16269)
* [OCPBUGS-83817](https://issues.redhat.com/browse/OCPBUGS-83817): Fix orphaned shell processes in pod terminal on WebSocket disconnect [#16307](https://github.com/openshift/console/pull/16307)
* [CONSOLE-5238](https://issues.redhat.com/browse/CONSOLE-5238): Remove unused telemetry Cypress integration tests [#16685](https://github.com/openshift/console/pull/16685)
* [CONSOLE-5283](https://issues.redhat.com/browse/CONSOLE-5283): Migrate dashboard Cypress tests to Playwright [#16669](https://github.com/openshift/console/pull/16669)
* [CONSOLE-5158](https://issues.redhat.com/browse/CONSOLE-5158): Add filter by group for nodes [#16253](https://github.com/openshift/console/pull/16253)
* [OCPBUGS-83799](https://issues.redhat.com/browse/OCPBUGS-83799): Fix Workloads sidebar ordering when DeploymentConfig capability is disabled [#16351](https://github.com/openshift/console/pull/16351)
* [CONSOLE-4954](https://issues.redhat.com/browse/CONSOLE-4954): Add Workload tab to Node view [#16574](https://github.com/openshift/console/pull/16574)
* [OCPBUGS-87353](https://issues.redhat.com/browse/OCPBUGS-87353): Updating openshift-enterprise-console-container image to be consistent with ART for 5.0 [#16558](https://github.com/openshift/console/pull/16558)
* And 3 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/c7f0a381cc07df0b368936505f6c24fa91d83849...6d0dcf1d76337e46d95ea1b546d5ffe692d7918d)
### [console-operator](https://github.com/openshift/console-operator/tree/694a2de9e7d36a7453de16c5a7f29ce39e0d5ce3)
* NO-JIRA: Revert "Merge pull request #1170 from logonoff/http2" [#1194](https://github.com/openshift/console-operator/pull/1194)
* [CONSOLE-5433](https://issues.redhat.com/browse/CONSOLE-5433): Add default-deny NetworkPolicy for openshift-console-user-settings namespace [#1195](https://github.com/openshift/console-operator/pull/1195)
* [OCPBUGS-93982](https://issues.redhat.com/browse/OCPBUGS-93982): gate Progressing on version transition and operand rollout status [#1188](https://github.com/openshift/console-operator/pull/1188)
* [HELM-639](https://issues.redhat.com/browse/HELM-639): Update Helm download manifests for Helm 3 and Helm 4. [#1175](https://github.com/openshift/console-operator/pull/1175)
* [CONSOLE-5122](https://issues.redhat.com/browse/CONSOLE-5122): Multi-domain console route, ConfigMap, and OAuth support [#1184](https://github.com/openshift/console-operator/pull/1184)
* [OCPBUGS-67134](https://issues.redhat.com/browse/OCPBUGS-67134): add grace period before reporting Available=False [#1179](https://github.com/openshift/console-operator/pull/1179)
* [TRT-2780](https://issues.redhat.com/browse/TRT-2780): Revert #1178 [#1186](https://github.com/openshift/console-operator/pull/1186)
* [OCPBUGS-93982](https://issues.redhat.com/browse/OCPBUGS-93982): skip generation check when deployment was just updated [#1178](https://github.com/openshift/console-operator/pull/1178)
* [CONSOLE-5271](https://issues.redhat.com/browse/CONSOLE-5271): Set olmLifecycleEnabled based on OLMLifecycleAndCompatibility FeatureGate [#1174](https://github.com/openshift/console-operator/pull/1174)
* [OCPBUGS-87517](https://issues.redhat.com/browse/OCPBUGS-87517): Updating openshift-enterprise-console-operator-container image to be consistent with ART for 5.0 [#1171](https://github.com/openshift/console-operator/pull/1171)
* [Full changelog](https://github.com/openshift/console-operator/compare/58e10b0ac1a23d864ee9eae2631c705c3b670a4c...694a2de9e7d36a7453de16c5a7f29ce39e0d5ce3)
### [coredns](https://github.com/openshift/coredns/tree/37aaba896e97f4b9a091aab6d36f2213b8854474)
* [NE-2744](https://issues.redhat.com/browse/NE-2744): UPSTREAM: 8227: fix(tls): use Go TLS defaults [#194](https://github.com/openshift/coredns/pull/194)
* [OCPBUGS-87352](https://issues.redhat.com/browse/OCPBUGS-87352): Updating coredns-container image to be consistent with ART for 5.0 [#189](https://github.com/openshift/coredns/pull/189)
* [Full changelog](https://github.com/openshift/coredns/compare/97f7cc327ab5df7d6da38137b7be338efa9a3551...37aaba896e97f4b9a091aab6d36f2213b8854474)
### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa)
* [OCPBUGS-97795](https://issues.redhat.com/browse/OCPBUGS-97795): Bump golang.org/x/crypto to v0.53.0 [#197](https://github.com/openshift/csi-driver-nfs/pull/197)
* [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/a40a98e2027a63e2a8ddd3589ee3c5142104dbd6...beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa)
### [csi-external-snapshotter, csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter/tree/b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8)
* [STOR-3004](https://issues.redhat.com/browse/STOR-3004): Rebase external-snapshotter to v8.6.0 [#224](https://github.com/openshift/csi-external-snapshotter/pull/224)
* [Full changelog](https://github.com/openshift/csi-external-snapshotter/compare/e695e2bd0b548afd0fce049d86d4af29dd34e574...b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8)
### [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar/tree/02d5345005aeb6aac2277818937501cdd1a3a88e)
* NO-ISSUE: Bump github.com/moby/spdystream to v0.5.1 [#107](https://github.com/openshift/csi-node-driver-registrar/pull/107)
* [Full changelog](https://github.com/openshift/csi-node-driver-registrar/compare/f0378629c970bc897439caaa85c4aec0971c1130...02d5345005aeb6aac2277818937501cdd1a3a88e)
### [docker-registry](https://github.com/openshift/image-registry/tree/eb1b09dc465a8d53c5683da40f5d5fd306fd945a)
* [OCPBUGS-96818](https://issues.redhat.com/browse/OCPBUGS-96818): bump golang.com/x/crypto [#473](https://github.com/openshift/image-registry/pull/473)
* [Full changelog](https://github.com/openshift/image-registry/compare/57039cd2d9c87547cdf9a8d1dc7cb94f1ca089f7...eb1b09dc465a8d53c5683da40f5d5fd306fd945a)
### [driver-toolkit](https://github.com/openshift/driver-toolkit/tree/7ec03cbba69b4dc86ee33e313bad32ae2ea2924e)
* [MGMT-24788](https://issues.redhat.com/browse/MGMT-24788): Fix pod deletion message contaminating RHCOS kernel version string [#197](https://github.com/openshift/driver-toolkit/pull/197)
* [OCPBUGS-69851](https://issues.redhat.com/browse/OCPBUGS-69851): Fix e2e test failure caused by TTY carriage returns in oc run output [#196](https://github.com/openshift/driver-toolkit/pull/196)
* [Full changelog](https://github.com/openshift/driver-toolkit/compare/9e5bed0f68cc7aef416d2a48522c7d195e5dbb17...7ec03cbba69b4dc86ee33e313bad32ae2ea2924e)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/a923d37cfe033853603240f862cb907ba997cb68)
* [OCPBUGS-87977](https://issues.redhat.com/browse/OCPBUGS-87977): bump containernetworking/cni to v1.3.0 [#102](https://github.com/openshift/egress-router-cni/pull/102)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/d37f51e057620bdee564f68dcfde955acf033d3e...a923d37cfe033853603240f862cb907ba997cb68)
### [etcd](https://github.com/openshift/etcd/tree/64f8851a001f7e102d47bfe51ca0dac23951879a)
* [OCPBUGS-94014](https://issues.redhat.com/browse/OCPBUGS-94014): Rebase v3.6.13 on main (5.0/4.23) [#392](https://github.com/openshift/etcd/pull/392)
* [Full changelog](https://github.com/openshift/etcd/compare/bf6c0094589afdf6c814a28c24f8f1bb5a577816...64f8851a001f7e102d47bfe51ca0dac23951879a)
### [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp/tree/30cc04797f50e78e91f8e47cc6c36c0da84eee2c)
* [OCPBUGS-84569](https://issues.redhat.com/browse/OCPBUGS-84569): Fix node.kubernetes.io/exclude-from-external-load-balancers on masters [#121](https://github.com/openshift/cloud-provider-gcp/pull/121)
* [Full changelog](https://github.com/openshift/cloud-provider-gcp/compare/1a542ecb49b1b26ea7ecd6344a9ebe7dbe09b6b6...30cc04797f50e78e91f8e47cc6c36c0da84eee2c)
### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/194befaa927c8e6ca56526218f2d4f5e2d4bd431)
* 🐛 OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#299](https://github.com/openshift/cluster-api-provider-gcp/pull/299)
* [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/ffbf9c2a410aa425c29c4628fa250d2e949b6876...194befaa927c8e6ca56526218f2d4f5e2d4bd431)
### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/1d098131fa7123b9793e01dcdac4d0b18b9ef1ae)
* [OCPBUGS-91738](https://issues.redhat.com/browse/OCPBUGS-91738): golang.org/x/net bumped from v0.51.0 to v0.55.0 [#172](https://github.com/openshift/machine-api-provider-gcp/pull/172)
* [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/af29978573161a98d41f1baae67d05da7398a646...1d098131fa7123b9793e01dcdac4d0b18b9ef1ae)
### [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver/tree/2dad9ff88511cc4e82a777c49ec55cbed2e3a057)
* [STOR-2915](https://issues.redhat.com/browse/STOR-2915): Update go.opentelemetry.io/otel and otel/sdk to v1.43.0 [#125](https://github.com/openshift/gcp-pd-csi-driver/pull/125)
* [STOR-2915](https://issues.redhat.com/browse/STOR-2915): Rebase to upstream v1.26.0 for OCP 5.0 [#124](https://github.com/openshift/gcp-pd-csi-driver/pull/124)
* [Full changelog](https://github.com/openshift/gcp-pd-csi-driver/compare/3b9e6d19109ebfafa13f638f469071027f82b744...2dad9ff88511cc4e82a777c49ec55cbed2e3a057)
### [gcp-pd-csi-driver-operator](https://github.com/openshift/csi-operator/tree/50f79e773ab432a91299a06003191a1fc2535746)
* [OCPBUGS-99200](https://issues.redhat.com/browse/OCPBUGS-99200): Add networking.k8s.io group policy [#581](https://github.com/openshift/csi-operator/pull/581)
* [OCPBUGS-99490](https://issues.redhat.com/browse/OCPBUGS-99490): Apply some static assets earlier, before starting controllers [#584](https://github.com/openshift/csi-operator/pull/584)
* [STOR-2997](https://issues.redhat.com/browse/STOR-2997): Minimal implementation of GCP PD CSI driver operator [#576](https://github.com/openshift/csi-operator/pull/576)
* [STOR-3030](https://issues.redhat.com/browse/STOR-3030): feat(operator): detect GCP Dedicated and use hyperdisk-balanced StorageClass [#573](https://github.com/openshift/csi-operator/pull/573)
* [STOR-2996](https://issues.redhat.com/browse/STOR-2996): Sync gcp pd csi driver operator to legacy subdir (2) [#575](https://github.com/openshift/csi-operator/pull/575)
* [STOR-2996](https://issues.redhat.com/browse/STOR-2996): Run unit-tests in /legacy subdir [#574](https://github.com/openshift/csi-operator/pull/574)
* [OCPBUGS-85106](https://issues.redhat.com/browse/OCPBUGS-85106): Add required-scc annotation to EFS and SMB operator deployments [#569](https://github.com/openshift/csi-operator/pull/569)
* [OCPBUGS-90151](https://issues.redhat.com/browse/OCPBUGS-90151): hack/update-metadata.sh: allow MAX_OCP_VERSION override [#571](https://github.com/openshift/csi-operator/pull/571)
* [STOR-2996](https://issues.redhat.com/browse/STOR-2996): Sync gcp pd csi driver operator to legacy subdir [#570](https://github.com/openshift/csi-operator/pull/570)
* [OCPBUGS-87449](https://issues.redhat.com/browse/OCPBUGS-87449): Updating ose-openstack-cinder-csi-driver-operator-container image to be consistent with ART for 5.0 [#566](https://github.com/openshift/csi-operator/pull/566)
* [STOR-2920](https://issues.redhat.com/browse/STOR-2920): Bump OLM metadata to 5.0 [#568](https://github.com/openshift/csi-operator/pull/568)
* [STOR-2996](https://issues.redhat.com/browse/STOR-2996): Add gcp pd csi driver operator to legacy subdir [#562](https://github.com/openshift/csi-operator/pull/562)
* [OCPBUGS-87270](https://issues.redhat.com/browse/OCPBUGS-87270): Updating csi-driver-manila-operator-container image to be consistent with ART for 5.0 [#563](https://github.com/openshift/csi-operator/pull/563)
* [OCPBUGS-87236](https://issues.redhat.com/browse/OCPBUGS-87236): Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 5.0 [#561](https://github.com/openshift/csi-operator/pull/561)
* [OCPBUGS-87387](https://issues.redhat.com/browse/OCPBUGS-87387): Updating ose-azure-file-csi-driver-operator-container image to be consistent with ART for 5.0 [#565](https://github.com/openshift/csi-operator/pull/565)
* [OCPBUGS-87368](https://issues.redhat.com/browse/OCPBUGS-87368): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART for 5.0 [#564](https://github.com/openshift/csi-operator/pull/564)
* [OCPBUGS-87470](https://issues.redhat.com/browse/OCPBUGS-87470): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 5.0 [#567](https://github.com/openshift/csi-operator/pull/567)
* [OCPBUGS-87219](https://issues.redhat.com/browse/OCPBUGS-87219): Updating ose-aws-efs-csi-driver-operator-container image to be consistent with ART for 5.0 [#560](https://github.com/openshift/csi-operator/pull/560)
* [OCPBUGS-42363](https://issues.redhat.com/browse/OCPBUGS-42363): Re-enable Azure Disk load test [#558](https://github.com/openshift/csi-operator/pull/558)
* [OCPBUGS-86023](https://issues.redhat.com/browse/OCPBUGS-86023): Add memory limits to SMB CSI sidecar containers [#557](https://github.com/openshift/csi-operator/pull/557)
* [OCPBUGS-85457](https://issues.redhat.com/browse/OCPBUGS-85457): Add init container for Manila node daemonset [#552](https://github.com/openshift/csi-operator/pull/552)
* [OCPBUGS-84052](https://issues.redhat.com/browse/OCPBUGS-84052): Mount writable /tmp in SMB CSI driver [#545](https://github.com/openshift/csi-operator/pull/545)
* [OSASINFRA-3675](https://issues.redhat.com/browse/OSASINFRA-3675): Rework authentication in Manila CSI Driver Operator [#373](https://github.com/openshift/csi-operator/pull/373)
* [OCPBUGS-80930](https://issues.redhat.com/browse/OCPBUGS-80930): Add VolumeAttributesClass e2e test manifests for Azure disk [#538](https://github.com/openshift/csi-operator/pull/538)
* [OCPBUGS-78291](https://issues.redhat.com/browse/OCPBUGS-78291): Allow azure-disk sidecars to read VolumeAttributeClasses [#525](https://github.com/openshift/csi-operator/pull/525)
* [STOR-2762](https://issues.redhat.com/browse/STOR-2762): Bump all deps for 4.22 [#526](https://github.com/openshift/csi-operator/pull/526)
* [OCPBUGS-77674](https://issues.redhat.com/browse/OCPBUGS-77674): Updating ose-openstack-cinder-csi-driver-operator-container image to be consistent with ART for 4.22 [#516](https://github.com/openshift/csi-operator/pull/516)
* [OCPBUGS-77553](https://issues.redhat.com/browse/OCPBUGS-77553): Updating csi-driver-manila-operator-container image to be consistent with ART for 4.22 [#513](https://github.com/openshift/csi-operator/pull/513)
* [OCPBUGS-77612](https://issues.redhat.com/browse/OCPBUGS-77612): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART for 4.22 [#514](https://github.com/openshift/csi-operator/pull/514)
* [STOR-2884](https://issues.redhat.com/browse/STOR-2884): Add service to generate a TLS cert for EFS operator [#522](https://github.com/openshift/csi-operator/pull/522)
* [STOR-2884](https://issues.redhat.com/browse/STOR-2884): Add service to generate a TLS cert for SMB operator [#520](https://github.com/openshift/csi-operator/pull/520)
* NO-JIRA: Inherit any OpenShift global CodeRabbit setting [#519](https://github.com/openshift/csi-operator/pull/519)
* [OCPBUGS-77623](https://issues.redhat.com/browse/OCPBUGS-77623): Updating ose-azure-file-csi-driver-operator-container image to be consistent with ART for 4.22 [#515](https://github.com/openshift/csi-operator/pull/515)
* [OCPBUGS-77571](https://issues.redhat.com/browse/OCPBUGS-77571): Add only to tags to volume object, if volume is not already tagged [#518](https://github.com/openshift/csi-operator/pull/518)
* [OCPBUGS-77497](https://issues.redhat.com/browse/OCPBUGS-77497): Fix readonly root fs in Azure init containers [#512](https://github.com/openshift/csi-operator/pull/512)
* NO-JIRA: Add coderabbit, including instructions [#509](https://github.com/openshift/csi-operator/pull/509)
* [STOR-2752](https://issues.redhat.com/browse/STOR-2752): Early chore: update OCP version in OLM metadata [#505](https://github.com/openshift/csi-operator/pull/505)
* Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.22 [#517](https://github.com/openshift/csi-operator/pull/517)
* [OCPBUGS-77378](https://issues.redhat.com/browse/OCPBUGS-77378): Updating ose-aws-efs-csi-driver-operator-container image to be consistent with ART for 4.22 [#510](https://github.com/openshift/csi-operator/pull/510)
* [OCPBUGS-77405](https://issues.redhat.com/browse/OCPBUGS-77405): Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 4.22 [#511](https://github.com/openshift/csi-operator/pull/511)
* [OCPBUGS-76298](https://issues.redhat.com/browse/OCPBUGS-76298): missing readOnlyRootFilesystem in AWS init containers [#506](https://github.com/openshift/csi-operator/pull/506)
* [OCPBUGS-74971](https://issues.redhat.com/browse/OCPBUGS-74971): Fix azure-disk secret namespace/name args [#502](https://github.com/openshift/csi-operator/pull/502)
* [OCPBUGS-74521](https://issues.redhat.com/browse/OCPBUGS-74521): Remove VolumeAttributesClass FeatureGate [#503](https://github.com/openshift/csi-operator/pull/503)
* [STOR-2523](https://issues.redhat.com/browse/STOR-2523): hypershift: Add desired-version annotation to controller Deployments and use DeploymentVersionController in csi driver operators [#457](https://github.com/openshift/csi-operator/pull/457)
* [OCPBUGS-70304](https://issues.redhat.com/browse/OCPBUGS-70304): Fix azure-file secret namespace/name [#500](https://github.com/openshift/csi-operator/pull/500)
* [OCPBUGS-66113](https://issues.redhat.com/browse/OCPBUGS-66113): Some containers do not have readOnlyRootFilesystem [#476](https://github.com/openshift/csi-operator/pull/476)
* [OCPBUGS-70085](https://issues.redhat.com/browse/OCPBUGS-70085): Updating ose-openstack-cinder-csi-driver-operator-container image to be consistent with ART for 4.22 [#483](https://github.com/openshift/csi-operator/pull/483)
* [OCPBUGS-70339](https://issues.redhat.com/browse/OCPBUGS-70339): deploy prometheus role and binding on hypershift guest [#488](https://github.com/openshift/csi-operator/pull/488)
* [OCPBUGS-63698](https://issues.redhat.com/browse/OCPBUGS-63698): fix(azure): add token-minter for self-managed hosted clusters [#461](https://github.com/openshift/csi-operator/pull/461)
* [OCPBUGS-69739](https://issues.redhat.com/browse/OCPBUGS-69739): Updating csi-driver-manila-operator-container image to be consistent with ART for 4.22 [#480](https://github.com/openshift/csi-operator/pull/480)
* [OCPBUGS-69907](https://issues.redhat.com/browse/OCPBUGS-69907): Updating ose-azure-file-csi-driver-operator-container image to be consistent with ART for 4.22 [#482](https://github.com/openshift/csi-operator/pull/482)
* [OCPBUGS-69710](https://issues.redhat.com/browse/OCPBUGS-69710): Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 4.22 [#479](https://github.com/openshift/csi-operator/pull/479)
* NO-JIRA: Add /sniff-test claude command [#486](https://github.com/openshift/csi-operator/pull/486)
* [OCPBUGS-69883](https://issues.redhat.com/browse/OCPBUGS-69883): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART for 4.22 [#481](https://github.com/openshift/csi-operator/pull/481)
* [OCPBUGS-69982](https://issues.redhat.com/browse/OCPBUGS-69982): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.22 [#484](https://github.com/openshift/csi-operator/pull/484)
* [OCPBUGS-69695](https://issues.redhat.com/browse/OCPBUGS-69695): Updating ose-aws-efs-csi-driver-operator-container image to be consistent with ART for 4.22 [#478](https://github.com/openshift/csi-operator/pull/478)
* [STOR-2543](https://issues.redhat.com/browse/STOR-2543): add VAC manifest for tests in AWS EBS [#475](https://github.com/openshift/csi-operator/pull/475)
* [STOR-1945](https://issues.redhat.com/browse/STOR-1945): STOR-2056: Add SupportedSizeRange for azurefile-nfs [#477](https://github.com/openshift/csi-operator/pull/477)
* NO-JIRA: Migrate away from deprecated ioutil [#474](https://github.com/openshift/csi-operator/pull/474)
* [CNTRLPLANE-1285](https://issues.redhat.com/browse/CNTRLPLANE-1285): enable readOnlyRootFilesystem [#419](https://github.com/openshift/csi-operator/pull/419)
* [OCPBUGS-65858](https://issues.redhat.com/browse/OCPBUGS-65858): allow all-egress for efs operator [#472](https://github.com/openshift/csi-operator/pull/472)
* [STOR-2538](https://issues.redhat.com/browse/STOR-2538): Migrate aws sdk to v2 [#442](https://github.com/openshift/csi-operator/pull/442)
* No-JIRA: Update owners [#471](https://github.com/openshift/csi-operator/pull/471)
* [STOR-2627](https://issues.redhat.com/browse/STOR-2627): Enable nodeAllocatableUpdatePeriodSeconds in AWS EBS [#435](https://github.com/openshift/csi-operator/pull/435)
* [OCPBUGS-65606](https://issues.redhat.com/browse/OCPBUGS-65606): adds the csi-external-resizer to the image-references [#469](https://github.com/openshift/csi-operator/pull/469)
* [STOR-2592](https://issues.redhat.com/browse/STOR-2592): Bump all deps for 4.21 and remove hypershift client [#468](https://github.com/openshift/csi-operator/pull/468)
* [STOR-2523](https://issues.redhat.com/browse/STOR-2523): Add hypershift managed-by labels for csi driver operators [#446](https://github.com/openshift/csi-operator/pull/446)
* [OCPBUGS-62802](https://issues.redhat.com/browse/OCPBUGS-62802): Add RBAC ClusterRole and Binding for driver node [#443](https://github.com/openshift/csi-operator/pull/443)
* NO-JIRA: add ai-helpers claude marketplace [#451](https://github.com/openshift/csi-operator/pull/451)
* NO-JIRA: Normalize generation of driver metrics RBAC proxy sidecar [#380](https://github.com/openshift/csi-operator/pull/380)
* [OCPBUGS-61436](https://issues.redhat.com/browse/OCPBUGS-61436), [OCPBUGS-61450](https://issues.redhat.com/browse/OCPBUGS-61450), [STOR-2600](https://issues.redhat.com/browse/STOR-2600): Bump OLM metadata to 4.21 [#430](https://github.com/openshift/csi-operator/pull/430)
* [OCPBUGS-62404](https://issues.redhat.com/browse/OCPBUGS-62404): Updating ose-openstack-cinder-csi-driver-operator-container image to be consistent with ART for 4.21 [#438](https://github.com/openshift/csi-operator/pull/438)
* [STOR-1945](https://issues.redhat.com/browse/STOR-1945): STOR-2056: add Azure File NFS test manifest [#445](https://github.com/openshift/csi-operator/pull/445)
* [OCPBUGS-62374](https://issues.redhat.com/browse/OCPBUGS-62374): Updating ose-azure-file-csi-driver-operator-container image to be consistent with ART for 4.21 [#437](https://github.com/openshift/csi-operator/pull/437)
* [MULTIARCH-5554](https://issues.redhat.com/browse/MULTIARCH-5554): update smb-csi-driver-operator support to add ppc64le [#428](https://github.com/openshift/csi-operator/pull/428)
* [OCPBUGS-62427](https://issues.redhat.com/browse/OCPBUGS-62427): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.21 [#439](https://github.com/openshift/csi-operator/pull/439)
* [OCPBUGS-62348](https://issues.redhat.com/browse/OCPBUGS-62348): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART for 4.21 [#436](https://github.com/openshift/csi-operator/pull/436)
* [OCPBUGS-61955](https://issues.redhat.com/browse/OCPBUGS-61955): Add withCABundleDaemonSetHook() to AWS EFS operator [#433](https://github.com/openshift/csi-operator/pull/433)
* [OCPBUGS-60637](https://issues.redhat.com/browse/OCPBUGS-60637): add runAsUser hook for operator deployment controller [#431](https://github.com/openshift/csi-operator/pull/431)
* NO-JIRA: Centralize injection of hosted-kubeconfig volume [#311](https://github.com/openshift/csi-operator/pull/311)
* NO-JIRA: Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 4.21 [#429](https://github.com/openshift/csi-operator/pull/429)
* [OCPBUGS-54385](https://issues.redhat.com/browse/OCPBUGS-54385): Avoid informer resync [#432](https://github.com/openshift/csi-operator/pull/432)
* NO-JIRA: Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 4.21 [#427](https://github.com/openshift/csi-operator/pull/427)
* NO-JIRA: Updating ose-aws-efs-csi-driver-operator-container image to be consistent with ART for 4.21 [#425](https://github.com/openshift/csi-operator/pull/425)
* NO-JIRA: azure-disk, azure-file sync code de-duplication [#303](https://github.com/openshift/csi-operator/pull/303)
* [STOR-2477](https://issues.redhat.com/browse/STOR-2477): Correct efs single-zone storageclass [#404](https://github.com/openshift/csi-operator/pull/404)
* [OCPBUGS-60655](https://issues.redhat.com/browse/OCPBUGS-60655): Disable LUN stress test for azure-file [#418](https://github.com/openshift/csi-operator/pull/418)
* [OCPBUGS-60464](https://issues.redhat.com/browse/OCPBUGS-60464): Bump library-go to fix panic [#417](https://github.com/openshift/csi-operator/pull/417)
* [STOR-2394](https://issues.redhat.com/browse/STOR-2394): Bump all deps for 4.20 [#408](https://github.com/openshift/csi-operator/pull/408)
* [STOR-2479](https://issues.redhat.com/browse/STOR-2479): Add CredentialsRequest for the EFS node DaemonSet [#389](https://github.com/openshift/csi-operator/pull/389)
* [STOR-2330](https://issues.redhat.com/browse/STOR-2330): Add labels to subscribe openstack cinder and manila CSI driver controllers to NPs [#409](https://github.com/openshift/csi-operator/pull/409)
* [OCPBUGS-57395](https://issues.redhat.com/browse/OCPBUGS-57395): Remove stale conditions [#406](https://github.com/openshift/csi-operator/pull/406)
* [OCPBUGS-58254](https://issues.redhat.com/browse/OCPBUGS-58254): Bump library-go [#405](https://github.com/openshift/csi-operator/pull/405)
* [STOR-2331](https://issues.redhat.com/browse/STOR-2331): Add labels to subscribe SMB CSI driver operator and controller to NPs [#400](https://github.com/openshift/csi-operator/pull/400)
* [STOR-2330](https://issues.redhat.com/browse/STOR-2330): Add labels to subscribe Azure disk and file CSI driver controllers to NPs [#396](https://github.com/openshift/csi-operator/pull/396)
* [OCPBUGS-57768](https://issues.redhat.com/browse/OCPBUGS-57768): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.20 [#399](https://github.com/openshift/csi-operator/pull/399)
* [OCPBUGS-57739](https://issues.redhat.com/browse/OCPBUGS-57739): Updating ose-openstack-cinder-csi-driver-operator-container image to be consistent with ART for 4.20 [#398](https://github.com/openshift/csi-operator/pull/398)
* [OCPBUGS-57700](https://issues.redhat.com/browse/OCPBUGS-57700): Updating ose-azure-file-csi-driver-operator-container image to be consistent with ART for 4.20 [#397](https://github.com/openshift/csi-operator/pull/397)
* [OCPBUGS-57565](https://issues.redhat.com/browse/OCPBUGS-57565): Updating csi-driver-manila-operator-container image to be consistent with ART for 4.20 [#394](https://github.com/openshift/csi-operator/pull/394)
* [STOR-2331](https://issues.redhat.com/browse/STOR-2331): Add labels to subscribe AWS-EFS CSI driver operator to NPs [#391](https://github.com/openshift/csi-operator/pull/391)
* [OCPBUGS-57680](https://issues.redhat.com/browse/OCPBUGS-57680): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART for 4.20 [#395](https://github.com/openshift/csi-operator/pull/395)
* [STOR-2477](https://issues.redhat.com/browse/STOR-2477): create-efs-volume: add single-zone support [#390](https://github.com/openshift/csi-operator/pull/390)
* [OCPBUGS-57545](https://issues.redhat.com/browse/OCPBUGS-57545): Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 4.20 [#393](https://github.com/openshift/csi-operator/pull/393)
* Updating ose-aws-efs-csi-driver-operator-container image to be consistent with ART for 4.20 [#392](https://github.com/openshift/csi-operator/pull/392)
* [STOR-2330](https://issues.redhat.com/browse/STOR-2330): Add labels to subscribe AWS-EBS CSI driver controller to NPs [#387](https://github.com/openshift/csi-operator/pull/387)
* NO-JIRA: create-efs-volume: print files to log as a fallback [#388](https://github.com/openshift/csi-operator/pull/388)
* NO-JIRA: Update openstack approvers [#385](https://github.com/openshift/csi-operator/pull/385)
* [OCPBUGS-54975](https://issues.redhat.com/browse/OCPBUGS-54975): Fix Cinder, Manila driver metrics [#379](https://github.com/openshift/csi-operator/pull/379)
* [OCPBUGS-56128](https://issues.redhat.com/browse/OCPBUGS-56128): openstack-cinder: Set --with-topology flag for node driver also [#383](https://github.com/openshift/csi-operator/pull/383)
* [STOR-2408](https://issues.redhat.com/browse/STOR-2408): Bump OLM metadata to 4.20 [#382](https://github.com/openshift/csi-operator/pull/382)
* [OCPBUGS-50493](https://issues.redhat.com/browse/OCPBUGS-50493): Use 127.0.0.1 for healtz http-endpoints [#364](https://github.com/openshift/csi-operator/pull/364)
* NO-JIRA: build only needed cmd in container image [#329](https://github.com/openshift/csi-operator/pull/329)
* [OCPBUGS-54382](https://issues.redhat.com/browse/OCPBUGS-54382): Correct ASH driver inject env config [#376](https://github.com/openshift/csi-operator/pull/376)
* [OSASINFRA-3652](https://issues.redhat.com/browse/OSASINFRA-3652): openstack-cinder: Use new --with-topology flag [#345](https://github.com/openshift/csi-operator/pull/345)
* [STOR-2126](https://issues.redhat.com/browse/STOR-2126): Enable readOnlyFileSystem [#370](https://github.com/openshift/csi-operator/pull/370)
* [OCPBUGS-54447](https://issues.redhat.com/browse/OCPBUGS-54447): Enable required driver services [#369](https://github.com/openshift/csi-operator/pull/369)
* [OCPBUGS-54180](https://issues.redhat.com/browse/OCPBUGS-54180): Disable remove-not-ready-taint for azure disk csi driver [#371](https://github.com/openshift/csi-operator/pull/371)
* [OCPBUGS-54230](https://issues.redhat.com/browse/OCPBUGS-54230): Bump library-go [#372](https://github.com/openshift/csi-operator/pull/372)
* [STOR-1877](https://issues.redhat.com/browse/STOR-1877): Run operators without root user control [#368](https://github.com/openshift/csi-operator/pull/368)
* [STOR-1880](https://issues.redhat.com/browse/STOR-1880): Role and ClusterRole with too wide permissions [#367](https://github.com/openshift/csi-operator/pull/367)
* [OCPBUGS-41827](https://issues.redhat.com/browse/OCPBUGS-41827): update injector to use a secret rather than an environment variable [#357](https://github.com/openshift/csi-operator/pull/357)
* NO-JIRA: Fixed typo in README.md [#348](https://github.com/openshift/csi-operator/pull/348)
* [STOR-2252](https://issues.redhat.com/browse/STOR-2252): Bump all deps [#361](https://github.com/openshift/csi-operator/pull/361)
* NO-JIRA: NO-JIRA: Remove bertinatto from OWNERS [#363](https://github.com/openshift/csi-operator/pull/363)
* [CFE-1132](https://issues.redhat.com/browse/CFE-1132): EFS Access Point Tags Update DAY2 [#313](https://github.com/openshift/csi-operator/pull/313)
* [CFE-1131](https://issues.redhat.com/browse/CFE-1131): AWS Tags DAY2 Update [#297](https://github.com/openshift/csi-operator/pull/297)
* [STOR-2263](https://issues.redhat.com/browse/STOR-2263): correct smb csi driver test manifest [#360](https://github.com/openshift/csi-operator/pull/360)
* NO-JIRA: Remove `inject-proxy` annotations for aws-ebs, aws-efs node daemonsets [#308](https://github.com/openshift/csi-operator/pull/308)
* [OCPBUGS-48507](https://issues.redhat.com/browse/OCPBUGS-48507): openstack-manila: update PodDisruptionBudget name [#353](https://github.com/openshift/csi-operator/pull/353)
* [STOR-2078](https://issues.redhat.com/browse/STOR-2078): Enable VolumeAttributesClass on AWS EBS for resizer + provisioner [#314](https://github.com/openshift/csi-operator/pull/314)
* NO-JIRA: Update golang.org/x/net to v0.34.0 [#352](https://github.com/openshift/csi-operator/pull/352)
* [OCPBUGS-45073](https://issues.redhat.com/browse/OCPBUGS-45073): Support HCP labels [#332](https://github.com/openshift/csi-operator/pull/332)
* [STOR-2260](https://issues.redhat.com/browse/STOR-2260): Bump OLM metadata to 4.19 [#351](https://github.com/openshift/csi-operator/pull/351)
* [OCPBUGS-45591](https://issues.redhat.com/browse/OCPBUGS-45591): Updating ose-openstack-cinder-csi-driver-operator-container image to be consistent with ART for 4.19 [#342](https://github.com/openshift/csi-operator/pull/342)
* [OCPBUGS-44723](https://issues.redhat.com/browse/OCPBUGS-44723): remove EFS driver metrics [#330](https://github.com/openshift/csi-operator/pull/330)
* [OCPBUGS-45374](https://issues.redhat.com/browse/OCPBUGS-45374): Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 4.19 [#337](https://github.com/openshift/csi-operator/pull/337)
* [OCPBUGS-45622](https://issues.redhat.com/browse/OCPBUGS-45622): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.19 [#343](https://github.com/openshift/csi-operator/pull/343)
* Updating ose-azure-file-csi-driver-operator-container image to be consistent with ART for 4.19 [#341](https://github.com/openshift/csi-operator/pull/341)
* [OCPBUGS-45508](https://issues.redhat.com/browse/OCPBUGS-45508): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART for 4.19 [#340](https://github.com/openshift/csi-operator/pull/340)
* [OCPBUGS-45395](https://issues.redhat.com/browse/OCPBUGS-45395): Updating csi-driver-manila-operator-container image to be consistent with ART for 4.19 [#339](https://github.com/openshift/csi-operator/pull/339)
* [OCPBUGS-45352](https://issues.redhat.com/browse/OCPBUGS-45352): Updating ose-aws-efs-csi-driver-operator-container image to be consistent with ART for 4.19 [#336](https://github.com/openshift/csi-operator/pull/336)
* [OCPBUGS-45267](https://issues.redhat.com/browse/OCPBUGS-45267): openstack-manila: modify assets selectors [#335](https://github.com/openshift/csi-operator/pull/335)
* [OCPBUGS-43357](https://issues.redhat.com/browse/OCPBUGS-43357): support hcp tolerations [#326](https://github.com/openshift/csi-operator/pull/326)
* [OSASINFRA-3626](https://issues.redhat.com/browse/OSASINFRA-3626): Resize support with the OpenStack Manila CSI Driver [#322](https://github.com/openshift/csi-operator/pull/322)
* [STOR-2017](https://issues.redhat.com/browse/STOR-2017): Bump library-go and API [#325](https://github.com/openshift/csi-operator/pull/325)
* [AUTH-482](https://issues.redhat.com/browse/AUTH-482): set required-scc for openshift workloads [#306](https://github.com/openshift/csi-operator/pull/306)
* NO-JIRA: ignore cmd/generator/main.go in .snyk [#295](https://github.com/openshift/csi-operator/pull/295)
* [OSASINFRA-3535](https://issues.redhat.com/browse/OSASINFRA-3535): openstack-cinder: Watch management cluster for cloud-provider config [#321](https://github.com/openshift/csi-operator/pull/321)
* [OCPBUGS-44340](https://issues.redhat.com/browse/OCPBUGS-44340): Fix error handling for starter controller [#318](https://github.com/openshift/csi-operator/pull/318)
* [OSASINFRA-3638](https://issues.redhat.com/browse/OSASINFRA-3638): Add support for Hypershift to Manila CSI [#312](https://github.com/openshift/csi-operator/pull/312)
* [OSASINFRA-3535](https://issues.redhat.com/browse/OSASINFRA-3535): Add support for Hypershift to Cinder CSI [#302](https://github.com/openshift/csi-operator/pull/302)
* NO-JIRA: Add openstack-approvers to root OWNERS [#315](https://github.com/openshift/csi-operator/pull/315)
* [OSASINFRA-3621](https://issues.redhat.com/browse/OSASINFRA-3621): Remove legacy csi-driver-manila-operator [#317](https://github.com/openshift/csi-operator/pull/317)
* [OSASINFRA-3618](https://issues.redhat.com/browse/OSASINFRA-3618): Add Cinder CSI support (part 3) [#298](https://github.com/openshift/csi-operator/pull/298)
* [OSASINFRA-3654](https://issues.redhat.com/browse/OSASINFRA-3654): Include OpenStack test manifest to test/e2e [#316](https://github.com/openshift/csi-operator/pull/316)
* [OSASINFRA-3620](https://issues.redhat.com/browse/OSASINFRA-3620): Add manila csi [#288](https://github.com/openshift/csi-operator/pull/288)
* NO-JIRA: Add OWNERS files for OpenStack-specific components/assets [#299](https://github.com/openshift/csi-operator/pull/299)
* [HOSTEDCP-2032](https://issues.redhat.com/browse/HOSTEDCP-2032): Set azure disk & file Secrets Store CSI Volume [#309](https://github.com/openshift/csi-operator/pull/309)
* [STOR-1844](https://issues.redhat.com/browse/STOR-1844): remove config/samba/manifests/preview symlink [#305](https://github.com/openshift/csi-operator/pull/305)
* [OCPBUGS-42325](https://issues.redhat.com/browse/OCPBUGS-42325): Set separate secrets for file and disk config on HyperShift [#290](https://github.com/openshift/csi-operator/pull/290)
* [OCPBUGS-43562](https://issues.redhat.com/browse/OCPBUGS-43562): Add missing proxy hook for `openstack-cinder` driver [#304](https://github.com/openshift/csi-operator/pull/304)
* [OCPBUGS-43653](https://issues.redhat.com/browse/OCPBUGS-43653): Add missing credentials secret hook [#307](https://github.com/openshift/csi-operator/pull/307)
* [OSASINFRA-3628](https://issues.redhat.com/browse/OSASINFRA-3628): Make guest namespace configurable [#294](https://github.com/openshift/csi-operator/pull/294)
* [STOR-1844](https://issues.redhat.com/browse/STOR-1844): update OLM manifests to use stable channel [#300](https://github.com/openshift/csi-operator/pull/300)
* [OSASINFRA-3618](https://issues.redhat.com/browse/OSASINFRA-3618): Add Cinder CSI support (part 2) [#275](https://github.com/openshift/csi-operator/pull/275)
* [OCPBUGS-42939](https://issues.redhat.com/browse/OCPBUGS-42939): Correct aws efs csi driver config as removable [#293](https://github.com/openshift/csi-operator/pull/293)
* [OCPBUGS-38922](https://issues.redhat.com/browse/OCPBUGS-38922): add tag matching to Azure File storage class [#272](https://github.com/openshift/csi-operator/pull/272)
* [OCPBUGS-41365](https://issues.redhat.com/browse/OCPBUGS-41365): add ability to control kube rbac proxy container image… [#289](https://github.com/openshift/csi-operator/pull/289)
* NO-JIRA: Add SidecarConfig.WithPatches [#285](https://github.com/openshift/csi-operator/pull/285)
* NO-JIRA: Remove generated assets before generation [#287](https://github.com/openshift/csi-operator/pull/287)
* NO-JIRA: List all supported operators in README [#277](https://github.com/openshift/csi-operator/pull/277)
* [OSASINFRA-3611](https://issues.redhat.com/browse/OSASINFRA-3611): Add legacy csi-driver-manila-operator [#280](https://github.com/openshift/csi-operator/pull/280)
* NO-JIRA: Move doc on migrating CSI Driver in-tree [#279](https://github.com/openshift/csi-operator/pull/279)
* [OCPBUGS-41265](https://issues.redhat.com/browse/OCPBUGS-41265): Disable LUN stress test for azure-disk [#282](https://github.com/openshift/csi-operator/pull/282)
* [OSASINFRA-3609](https://issues.redhat.com/browse/OSASINFRA-3609): Update legacy/openstack-cinder-csi-driver-operator [#281](https://github.com/openshift/csi-operator/pull/281)
* [OSASINFRA-3609](https://issues.redhat.com/browse/OSASINFRA-3609): Add Cinder CSI support (part 1) [#278](https://github.com/openshift/csi-operator/pull/278)
* [STOR-1422](https://issues.redhat.com/browse/STOR-1422): Bump(openshift/api): to get EFS volume metrics GA [#273](https://github.com/openshift/csi-operator/pull/273)
* [OCPBUGS-40526](https://issues.redhat.com/browse/OCPBUGS-40526): Updating ose-azure-file-csi-driver-operator-container image to be consistent with ART for 4.18 [#270](https://github.com/openshift/csi-operator/pull/270)
* [OCPBUGS-41149](https://issues.redhat.com/browse/OCPBUGS-41149): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.18 [#271](https://github.com/openshift/csi-operator/pull/271)
* [OCPBUGS-39591](https://issues.redhat.com/browse/OCPBUGS-39591): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART for 4.18 [#269](https://github.com/openshift/csi-operator/pull/269)
* [OCPBUGS-39445](https://issues.redhat.com/browse/OCPBUGS-39445): Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 4.18 [#268](https://github.com/openshift/csi-operator/pull/268)
* Updating ose-aws-efs-csi-driver-operator-container image to be consistent with ART for 4.18 [#267](https://github.com/openshift/csi-operator/pull/267)
* [OCPBUGS-38578](https://issues.redhat.com/browse/OCPBUGS-38578): Update aws-efs-csi-driver-operator image-references name [#264](https://github.com/openshift/csi-operator/pull/264)
* [STOR-1819](https://issues.redhat.com/browse/STOR-1819): Distribute OCP specific test manifest with create-efs-volume [#260](https://github.com/openshift/csi-operator/pull/260)
* [OCPBUGS-38620](https://issues.redhat.com/browse/OCPBUGS-38620): Some CSI driver containers missing terminationMessagePolicy [#262](https://github.com/openshift/csi-operator/pull/262)
* [STOR-2009](https://issues.redhat.com/browse/STOR-2009): Bump OLM metadata to 4.18 [#259](https://github.com/openshift/csi-operator/pull/259)
* [OCPBUGS-38578](https://issues.redhat.com/browse/OCPBUGS-38578): efs: fix tools image reference [#261](https://github.com/openshift/csi-operator/pull/261)
* [STOR-1993](https://issues.redhat.com/browse/STOR-1993): add init container in EFS CSI controller pod [#252](https://github.com/openshift/csi-operator/pull/252)
* [STOR-1819](https://issues.redhat.com/browse/STOR-1819): Add manifest with OCP specific test config [#258](https://github.com/openshift/csi-operator/pull/258)
* [STOR-1422](https://issues.redhat.com/browse/STOR-1422): Volume Metrics for EFS CSI Driver [#255](https://github.com/openshift/csi-operator/pull/255)
* [STOR-1819](https://issues.redhat.com/browse/STOR-1819): Add manifest with OCP specific test config [#254](https://github.com/openshift/csi-operator/pull/254)
* NO-JIRA: use service account namespace placeholder for smb role bindings [#250](https://github.com/openshift/csi-operator/pull/250)
* [STOR-2002](https://issues.redhat.com/browse/STOR-2002): add Azure File snapshot support [#253](https://github.com/openshift/csi-operator/pull/253)
* [OCPBUGS-37488](https://issues.redhat.com/browse/OCPBUGS-37488): add init container in EBS CSI controller pod [#248](https://github.com/openshift/csi-operator/pull/248)
* [STOR-1856](https://issues.redhat.com/browse/STOR-1856): add STS hook for EFS credentials request controller [#251](https://github.com/openshift/csi-operator/pull/251)
* [STOR-1874](https://issues.redhat.com/browse/STOR-1874): Use real HyperShift API [#236](https://github.com/openshift/csi-operator/pull/236)
* [OCPBUGS-37274](https://issues.redhat.com/browse/OCPBUGS-37274): Add FIPS_ENABLED to env vars for aws-efs-csi-driver (2) [#249](https://github.com/openshift/csi-operator/pull/249)
* [STOR-1856](https://issues.redhat.com/browse/STOR-1856): remove aws efs operator legacy dir [#244](https://github.com/openshift/csi-operator/pull/244)
* [STOR-1596](https://issues.redhat.com/browse/STOR-1596): Bump all deps for 4.17 [#240](https://github.com/openshift/csi-operator/pull/240)
* [STOR-1856](https://issues.redhat.com/browse/STOR-1856): STOR-1606: migrate legacy AWS EFS operator code to csi-operator [#237](https://github.com/openshift/csi-operator/pull/237)
* [OCPBUGS-36936](https://issues.redhat.com/browse/OCPBUGS-36936): Updating ose-smb-csi-driver-operator-container image to be consistent with ART for 4.17 [#241](https://github.com/openshift/csi-operator/pull/241)
* [OCPBUGS-36948](https://issues.redhat.com/browse/OCPBUGS-36948): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.17 [#243](https://github.com/openshift/csi-operator/pull/243)
* [OCPBUGS-36942](https://issues.redhat.com/browse/OCPBUGS-36942): Updating ose-azure-file-csi-driver-operator-container image to be consistent with ART for 4.17 [#242](https://github.com/openshift/csi-operator/pull/242)
* [STOR-1606](https://issues.redhat.com/browse/STOR-1606): Bump OLM metadata to 4.17 [#239](https://github.com/openshift/csi-operator/pull/239)
* [OCPBUGS-34451](https://issues.redhat.com/browse/OCPBUGS-34451): Bump go version to be consistent with ART [#238](https://github.com/openshift/csi-operator/pull/238)
* [STOR-1290](https://issues.redhat.com/browse/STOR-1290): don't pass credentials via environment variables in AWS EBS [#202](https://github.com/openshift/csi-operator/pull/202)
* [STOR-1856](https://issues.redhat.com/browse/STOR-1856): migrate AWS EFS operator to csi-operator [#232](https://github.com/openshift/csi-operator/pull/232)
* NO-JIRA: keep smb test storageclass consistent with official doc [#234](https://github.com/openshift/csi-operator/pull/234)
* [OCPBUGS-34667](https://issues.redhat.com/browse/OCPBUGS-34667): Ensure Node Metric Service is created in the openshift-cluster-csi-drivers namespace for both OpenShift and Hypershift [#233](https://github.com/openshift/csi-operator/pull/233)
* [OCPBUGS-34189](https://issues.redhat.com/browse/OCPBUGS-34189): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART for 4.17 [#227](https://github.com/openshift/csi-operator/pull/227)
* [OCPBUGS-32370](https://issues.redhat.com/browse/OCPBUGS-32370): Configure scraping of node metrics [#223](https://github.com/openshift/csi-operator/pull/223)
* [OCPBUGS-33776](https://issues.redhat.com/browse/OCPBUGS-33776): Adjust port for registrar sidecar in aws-ebs csi driver container [#225](https://github.com/openshift/csi-operator/pull/225)
* [OCPBUGS-32785](https://issues.redhat.com/browse/OCPBUGS-32785): add token audience for Azure File [#224](https://github.com/openshift/csi-operator/pull/224)
* [STOR-1726](https://issues.redhat.com/browse/STOR-1726): auto-generate assets for CIFS/Samba driver [#217](https://github.com/openshift/csi-operator/pull/217)
* [OCPBUGS-28230](https://issues.redhat.com/browse/OCPBUGS-28230): Add terminationMessagePolicy to all containers [#216](https://github.com/openshift/csi-operator/pull/216)
* [STOR-1726](https://issues.redhat.com/browse/STOR-1726): Delete static resources when ClusterCSIDriver is removed [#215](https://github.com/openshift/csi-operator/pull/215)
* [AUTH-482](https://issues.redhat.com/browse/AUTH-482): set required-scc for openshift workloads [#170](https://github.com/openshift/csi-operator/pull/170)
* NO-JIRA: Remove unused assests for __azure-file__ [#213](https://github.com/openshift/csi-operator/pull/213)
* [OCPBUGS-31044](https://issues.redhat.com/browse/OCPBUGS-31044): Add cluster-wide proxy in the azure-file driver node container [#207](https://github.com/openshift/csi-operator/pull/207)
* [OCPBUGS-31306](https://issues.redhat.com/browse/OCPBUGS-31306): Azure Disk: Add cluster-wide proxy in the driver container in the node [#206](https://github.com/openshift/csi-operator/pull/206)
* [OCPBUGS-28230](https://issues.redhat.com/browse/OCPBUGS-28230): enforce termination message policy on all platform pods [#214](https://github.com/openshift/csi-operator/pull/214)
* [STOR-1726](https://issues.redhat.com/browse/STOR-1726): Add OLM metadata for SMB operator [#210](https://github.com/openshift/csi-operator/pull/210)
* [STOR-1726](https://issues.redhat.com/browse/STOR-1726): Add test manifest for SMB CSI driver [#212](https://github.com/openshift/csi-operator/pull/212)
* [STOR-1818](https://issues.redhat.com/browse/STOR-1818): enable pvcDataSource capability for tests [#204](https://github.com/openshift/csi-operator/pull/204)
* [STOR-1726](https://issues.redhat.com/browse/STOR-1726): Simple rename of objects in `assets/overlays/samba/generated/standalone/` [#211](https://github.com/openshift/csi-operator/pull/211)
* [STOR-1726](https://issues.redhat.com/browse/STOR-1726): Add Dockerfile for Samba operator [#209](https://github.com/openshift/csi-operator/pull/209)
* Bump github.com/prometheus/client_model from 0.5.0 to 0.6.0 [#168](https://github.com/openshift/csi-operator/pull/168)
* [STOR-1726](https://issues.redhat.com/browse/STOR-1726): Minimal implementation of CIFS/Samba CSI driver operator [#205](https://github.com/openshift/csi-operator/pull/205)
* Bump google.golang.org/grpc from 1.61.0 to 1.62.1 [#190](https://github.com/openshift/csi-operator/pull/190)
* Bump github.com/go-openapi/swag from 0.22.9 to 0.23.0 [#198](https://github.com/openshift/csi-operator/pull/198)
* Bump github.com/emicklei/go-restful/v3 from 3.11.2 to 3.12.0 [#203](https://github.com/openshift/csi-operator/pull/203)
* Bump github.com/felixge/fgprof from 0.9.3 to 0.9.4 [#185](https://github.com/openshift/csi-operator/pull/185)
* [STOR-1794](https://issues.redhat.com/browse/STOR-1794): add location for azcopy logs [#200](https://github.com/openshift/csi-operator/pull/200)
* [OCPBUGS-23260](https://issues.redhat.com/browse/OCPBUGS-23260): Explicitly reserve 1 attachment for the root disk [#199](https://github.com/openshift/csi-operator/pull/199)
* Bump go.uber.org/zap from 1.26.0 to 1.27.0 [#173](https://github.com/openshift/csi-operator/pull/173)
* Bump the opentelemetry-dependencies group with 8 updates [#177](https://github.com/openshift/csi-operator/pull/177)
* Bump the golang-dependencies group with 6 updates [#191](https://github.com/openshift/csi-operator/pull/191)
* [OCPBUGS-30620](https://issues.redhat.com/browse/OCPBUGS-30620): remove legacy directory and duplicate Dockerfile.*.test files [#196](https://github.com/openshift/csi-operator/pull/196)
* [OCPBUGS-30469](https://issues.redhat.com/browse/OCPBUGS-30469): CVE-2024-24786: bump google.golang.org/protobuf to v1.33.0 [#197](https://github.com/openshift/csi-operator/pull/197)
* NO-JIRA: Configure dependabot for security updates only [#174](https://github.com/openshift/csi-operator/pull/174)
* [OCPBUGS-30620](https://issues.redhat.com/browse/OCPBUGS-30620): move test manifests to top-level directory [#194](https://github.com/openshift/csi-operator/pull/194)
* [STOR-1464](https://issues.redhat.com/browse/STOR-1464): Enable RWOP tests in CI [#187](https://github.com/openshift/csi-operator/pull/187)
* [STOR-1762](https://issues.redhat.com/browse/STOR-1762): Add azure file hypershift [#163](https://github.com/openshift/csi-operator/pull/163)
* Bump the k8s-dependencies group with 6 updates [#172](https://github.com/openshift/csi-operator/pull/172)
* [STOR-1726](https://issues.redhat.com/browse/STOR-1726): Bump `openshift/api` dependency [#169](https://github.com/openshift/csi-operator/pull/169)
* [STOR-1750](https://issues.redhat.com/browse/STOR-1750): Build image from legacy folder [#162](https://github.com/openshift/csi-operator/pull/162)
* Bump the opentelemetry-dependencies group with 8 updates [#161](https://github.com/openshift/csi-operator/pull/161)
* [STOR-1574](https://issues.redhat.com/browse/STOR-1574): Bump all deps [#156](https://github.com/openshift/csi-operator/pull/156)
* [OCPBUGS-26924](https://issues.redhat.com/browse/OCPBUGS-26924): Add healthcheck for node-driver-registrar container [#155](https://github.com/openshift/csi-operator/pull/155)
* Bump github.com/grpc-ecosystem/grpc-gateway/v2 from 2.19.0 to 2.19.1 [#149](https://github.com/openshift/csi-operator/pull/149)
* [STOR-1750](https://issues.redhat.com/browse/STOR-1750): Add legacy azure file driver [#154](https://github.com/openshift/csi-operator/pull/154)
* Bump go.etcd.io/etcd/client/v3 from 3.5.11 to 3.5.12 [#150](https://github.com/openshift/csi-operator/pull/150)
* Bump github.com/evanphx/json-patch from 5.8.1+incompatible to 5.9.0+incompatible [#148](https://github.com/openshift/csi-operator/pull/148)
* Bump github.com/go-openapi/swag from 0.22.8 to 0.22.9 [#147](https://github.com/openshift/csi-operator/pull/147)
* Bump github.com/google/uuid from 1.5.0 to 1.6.0 [#144](https://github.com/openshift/csi-operator/pull/144)
* Bump google.golang.org/grpc from 1.60.1 to 1.61.0 [#145](https://github.com/openshift/csi-operator/pull/145)
* Bump the k8s-dependencies group with 3 updates [#146](https://github.com/openshift/csi-operator/pull/146)
* [STOR-1574](https://issues.redhat.com/browse/STOR-1574): Bump library-go [#137](https://github.com/openshift/csi-operator/pull/137)
* Bump github.com/go-openapi/swag from 0.22.7 to 0.22.8 [#142](https://github.com/openshift/csi-operator/pull/142)
* Bump github.com/pkg/profile from 1.3.0 to 1.7.0 [#138](https://github.com/openshift/csi-operator/pull/138)
* Bump github.com/emicklei/go-restful/v3 from 3.11.0 to 3.11.2 [#141](https://github.com/openshift/csi-operator/pull/141)
* Bump go.uber.org/zap from 1.24.0 to 1.26.0 [#139](https://github.com/openshift/csi-operator/pull/139)
* Bump github.com/go-openapi/jsonreference from 0.20.2 to 0.20.4 [#140](https://github.com/openshift/csi-operator/pull/140)
* Bump github.com/go-openapi/swag from 0.22.4 to 0.22.7 [#136](https://github.com/openshift/csi-operator/pull/136)
* Bump github.com/prometheus/common from 0.45.0 to 0.46.0 [#135](https://github.com/openshift/csi-operator/pull/135)
* Bump the opentelemetry-dependencies group with 4 updates [#134](https://github.com/openshift/csi-operator/pull/134)
* Bump github.com/go-openapi/jsonpointer from 0.19.6 to 0.20.2 [#128](https://github.com/openshift/csi-operator/pull/128)
* Bump github.com/evanphx/json-patch from 5.6.0+incompatible to 5.8.1+incompatible [#125](https://github.com/openshift/csi-operator/pull/125)
* Bump the k8s-dependencies group with 5 updates [#133](https://github.com/openshift/csi-operator/pull/133)
* Bump go.etcd.io/etcd/client/v3 from 3.5.9 to 3.5.11 [#124](https://github.com/openshift/csi-operator/pull/124)
* [STOR-1722](https://issues.redhat.com/browse/STOR-1722): Add support hypershift for azure-disk [#73](https://github.com/openshift/csi-operator/pull/73)
* Bump github.com/go-logr/logr from 1.3.0 to 1.4.1 [#129](https://github.com/openshift/csi-operator/pull/129)
* [OCPBUGS-27267](https://issues.redhat.com/browse/OCPBUGS-27267): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.16 [#132](https://github.com/openshift/csi-operator/pull/132)
* Bump the opentelemetry-dependencies group with 2 updates [#122](https://github.com/openshift/csi-operator/pull/122)
* Bump github.com/sirupsen/logrus from 1.9.0 to 1.9.3 [#123](https://github.com/openshift/csi-operator/pull/123)
* Bump go.etcd.io/etcd/client/pkg/v3 from 3.5.9 to 3.5.11 [#119](https://github.com/openshift/csi-operator/pull/119)
* Bump github.com/fsnotify/fsnotify from 1.6.0 to 1.7.0 [#120](https://github.com/openshift/csi-operator/pull/120)
* NO-JIRA: Bump github.com/go-errors/errors from 1.4.2 to 1.5.1 [#106](https://github.com/openshift/csi-operator/pull/106)
* NO-JIRA: Bump google.golang.org/grpc from 1.59.0 to 1.60.1 [#104](https://github.com/openshift/csi-operator/pull/104)
* NO-JIRA: Bump github.com/spf13/cobra from 1.7.0 to 1.8.0 [#103](https://github.com/openshift/csi-operator/pull/103)
* NO-JIRA: Bump github.com/google/uuid from 1.3.1 to 1.5.0 [#101](https://github.com/openshift/csi-operator/pull/101)
* [OCPBUGS-27056](https://issues.redhat.com/browse/OCPBUGS-27056): Update to RHEL9 and go 1.21 [#117](https://github.com/openshift/csi-operator/pull/117)
* NO-JIRA: Bump the golang-dependencies group with 5 updates [#109](https://github.com/openshift/csi-operator/pull/109)
* NO-JIRA: Bump github.com/prometheus/client_golang from 1.17.0 to 1.18.0 [#108](https://github.com/openshift/csi-operator/pull/108)
* [STOR-1714](https://issues.redhat.com/browse/STOR-1714): AWS EBS operator: Release leadership on SIGTERM [#94](https://github.com/openshift/csi-operator/pull/94)
* NO-JIRA: Bump google.golang.org/protobuf from 1.31.0 to 1.32.0 [#107](https://github.com/openshift/csi-operator/pull/107)
* NO-JIRA: Add valid-reference label to dependabot PRs [#116](https://github.com/openshift/csi-operator/pull/116)
* [OCPBUGS-27050](https://issues.redhat.com/browse/OCPBUGS-27050): Updating ose-azure-disk-csi-driver-operator-container image to be consistent with ART for 4.16 [#114](https://github.com/openshift/csi-operator/pull/114)
* [STOR-1713](https://issues.redhat.com/browse/STOR-1713): Don't ignore azure-disk-csi-driver-operator [#110](https://github.com/openshift/csi-operator/pull/110)
* NO-JIRA: Add dependabot configuration [#97](https://github.com/openshift/csi-operator/pull/97)
* [STOR-1696](https://issues.redhat.com/browse/STOR-1696): Add legacy azure disk [#88](https://github.com/openshift/csi-operator/pull/88)
* [OCPBUGS-24245](https://issues.redhat.com/browse/OCPBUGS-24245): Add selinux [#89](https://github.com/openshift/csi-operator/pull/89)
* [OCPBUGS-25125](https://issues.redhat.com/browse/OCPBUGS-25125): Add test AssetOrderer [#86](https://github.com/openshift/csi-operator/pull/86)
* [OCPBUGS-25557](https://issues.redhat.com/browse/OCPBUGS-25557): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART [#87](https://github.com/openshift/csi-operator/pull/87)
* [OCPBUGS-25125](https://issues.redhat.com/browse/OCPBUGS-25125): Create RBAC objects first [#84](https://github.com/openshift/csi-operator/pull/84)
* [OCPBUGS-24226](https://issues.redhat.com/browse/OCPBUGS-24226): setting TLSSecurityProfile with no minTLSVersion crashes controller [#76](https://github.com/openshift/csi-operator/pull/76)
* NO-JIRA: Add "Quick start" section to `README.md` [#80](https://github.com/openshift/csi-operator/pull/80)
* [STOR-1688](https://issues.redhat.com/browse/STOR-1688): Chore: add .snyk file to ignore false positives [#85](https://github.com/openshift/csi-operator/pull/85)
* [OCPBUGS-25147](https://issues.redhat.com/browse/OCPBUGS-25147): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART [#81](https://github.com/openshift/csi-operator/pull/81)
* [OCPBUGS-23827](https://issues.redhat.com/browse/OCPBUGS-23827): CVE-2023-47108: bump go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp to v0.46 [#77](https://github.com/openshift/csi-operator/pull/77)
* [OCPBUGS-23306](https://issues.redhat.com/browse/OCPBUGS-23306): Add annotation to CSI driver Pod preventing eviction from the cluster-autoscaler [#79](https://github.com/openshift/csi-operator/pull/79)
* [OCPBUGS-24905](https://issues.redhat.com/browse/OCPBUGS-24905): Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART [#78](https://github.com/openshift/csi-operator/pull/78)
* [STOR-1500](https://issues.redhat.com/browse/STOR-1500): Switch to the new operator [#69](https://github.com/openshift/csi-operator/pull/69)
* Updating ose-aws-ebs-csi-driver-operator-container image to be consistent with ART [#75](https://github.com/openshift/csi-operator/pull/75)
* [STOR-1402](https://issues.redhat.com/browse/STOR-1402), [STOR-1453](https://issues.redhat.com/browse/STOR-1453): update libraries and specify TLS_MIN_VERSION [#71](https://github.com/openshift/csi-operator/pull/71)
* [STOR-1400](https://issues.redhat.com/browse/STOR-1400): Add support for Batch DescribeVolume [#74](https://github.com/openshift/csi-operator/pull/74)
* [STOR-1400](https://issues.redhat.com/browse/STOR-1400): Sync sidecar arguments with upstream [#72](https://github.com/openshift/csi-operator/pull/72)
* [STOR-1500](https://issues.redhat.com/browse/STOR-1500): Add log for the new operator [#70](https://github.com/openshift/csi-operator/pull/70)
* Pull the latest AWS EBS operator [#67](https://github.com/openshift/csi-operator/pull/67)
* Fix vendoring of golang.org/x/net [#68](https://github.com/openshift/csi-operator/pull/68)
* hack: remove existing path from .gitignore [#65](https://github.com/openshift/csi-operator/pull/65)
* Drop Guest prefix from client names [#64](https://github.com/openshift/csi-operator/pull/64)
* Update all generated assets in a single run [#63](https://github.com/openshift/csi-operator/pull/63)
* Verify generated assets in `make verify` [#62](https://github.com/openshift/csi-operator/pull/62)
* Move operator config into pkg/drivers [#61](https://github.com/openshift/csi-operator/pull/61)
* Add AWS EBS CSI driver operator starter [#58](https://github.com/openshift/csi-operator/pull/58)
* [OCPBUGS-21593](https://issues.redhat.com/browse/OCPBUGS-21593): CVE-2023-44487: bump golang.org/x/net to v0.17.0 [#59](https://github.com/openshift/csi-operator/pull/59)
* [STOR-1455](https://issues.redhat.com/browse/STOR-1455): Add asset generator [#53](https://github.com/openshift/csi-operator/pull/53)
* Delegate to aws-ebs-csi-driver-operator for tests and verify [#57](https://github.com/openshift/csi-operator/pull/57)
* Add aws ebs operator legacy [#56](https://github.com/openshift/csi-operator/pull/56)
* Add ci-operator config [#54](https://github.com/openshift/csi-operator/pull/54)
* Clean the repository, it will be reused for all CSI driver operators [#52](https://github.com/openshift/csi-operator/pull/52)
* Obsolete the operator [#51](https://github.com/openshift/csi-operator/pull/51)
* Fix hostpath image sample to support dynamic registration [#47](https://github.com/openshift/csi-operator/pull/47)
* Add kubelet-registration-path flag to csi-driver-registrar [#44](https://github.com/openshift/csi-operator/pull/44)
* Fix golint error [#45](https://github.com/openshift/csi-operator/pull/45)
* Output error message when failed to get CSIDriverDeployment and requeued [#46](https://github.com/openshift/csi-operator/pull/46)
* Add -nometadata to go-bindata to stop updating generated files by every build [#43](https://github.com/openshift/csi-operator/pull/43)
* Disable automatic installation of the operator in OpenShift [#41](https://github.com/openshift/csi-operator/pull/41)
* Pass SecurityContext to sidecar containers [#40](https://github.com/openshift/csi-operator/pull/40)
* Move EBS deployment sample to the right place [#39](https://github.com/openshift/csi-operator/pull/39)
* Use correct context timeouts [#38](https://github.com/openshift/csi-operator/pull/38)
* Add EBS sample deployment file [#37](https://github.com/openshift/csi-operator/pull/37)
* Add leader election to the operator [#36](https://github.com/openshift/csi-operator/pull/36)
* Embed git version into the operator binary [#35](https://github.com/openshift/csi-operator/pull/35)
* Generate bindata during build [#34](https://github.com/openshift/csi-operator/pull/34)
* Add more unit tests [#33](https://github.com/openshift/csi-operator/pull/33)
* Add controller unit tests [#32](https://github.com/openshift/csi-operator/pull/32)
* Fix deletion of non-namespaced objects [#31](https://github.com/openshift/csi-operator/pull/31)
* Fix e2e test [#30](https://github.com/openshift/csi-operator/pull/30)
* Add e2e test [#29](https://github.com/openshift/csi-operator/pull/29)
* Update to operator-sdk 0.1.1 [#28](https://github.com/openshift/csi-operator/pull/28)
* Fix liveness probe version [#27](https://github.com/openshift/csi-operator/pull/27)
* ADd a RHEL7 dockerfile and standardize format [#26](https://github.com/openshift/csi-operator/pull/26)
* Documentation update [#23](https://github.com/openshift/csi-operator/pull/23)
* Add unit test for validation [#14](https://github.com/openshift/csi-operator/pull/14)
* Fix status.conditions json name [#11](https://github.com/openshift/csi-operator/pull/11)
* Add CRD printer columns [#12](https://github.com/openshift/csi-operator/pull/12)
* Add configuration of liveness probe. [#9](https://github.com/openshift/csi-operator/pull/9)
* Increase resync period [#10](https://github.com/openshift/csi-operator/pull/10)
* Add /var/lib/kubelet HostPath directory to node drivers [#8](https://github.com/openshift/csi-operator/pull/8)
* Fix role bindings [#7](https://github.com/openshift/csi-operator/pull/7)
* Add liveness probe. [#6](https://github.com/openshift/csi-operator/pull/6)
* Fix operator images [#5](https://github.com/openshift/csi-operator/pull/5)
* Add OpenShift manifests to operator image [#4](https://github.com/openshift/csi-operator/pull/4)
* Use label selector for informers. [#3](https://github.com/openshift/csi-operator/pull/3)
* Use constants where appropriate [#2](https://github.com/openshift/csi-operator/pull/2)
* Add initial operator [#1](https://github.com/openshift/csi-operator/pull/1)
* And 27 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/csi-operator/compare/936b1710729592015497bea76b27f787ec742f3e...50f79e773ab432a91299a06003191a1fc2535746)
### [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook/tree/a8f16141e4234fa2c9f6aeb8498622af6e4a080d)
* [OCPBUGS-87344](https://issues.redhat.com/browse/OCPBUGS-87344): Updating gcp-workload-identity-federation-webhook-container image to be consistent with ART for 5.0 [#19](https://github.com/openshift/gcp-workload-identity-federation-webhook/pull/19)
* [Full changelog](https://github.com/openshift/gcp-workload-identity-federation-webhook/compare/73d67a587c98f1e2aec3969c59a66458096cd80c...a8f16141e4234fa2c9f6aeb8498622af6e4a080d)
### [haproxy-router](https://github.com/openshift/router/tree/682319a1bb432f0203951c33336d0f55947e1099)
* NO-JIRA: Add default coderabbit for the repo [#798](https://github.com/openshift/router/pull/798)
* [TRT-2841](https://issues.redhat.com/browse/TRT-2841): Revert "OCPBUGS-77056: Make external cert validation asynchronous (Resurrection)" [#824](https://github.com/openshift/router/pull/824)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Make external cert validation asynchronous (Resurrection) [#822](https://github.com/openshift/router/pull/822)
* [NE-2220](https://issues.redhat.com/browse/NE-2220): Update HAProxy RPM in the router container to 3.2.19 [#792](https://github.com/openshift/router/pull/792)
* [NE-2741](https://issues.redhat.com/browse/NE-2741): Implement TLS Curves Support for Metrics Endpoints [#811](https://github.com/openshift/router/pull/811)
* [TRT-2813](https://issues.redhat.com/browse/TRT-2813): Revert "Make external cert validation asynchronous" [#817](https://github.com/openshift/router/pull/817)
* [NE-2766](https://issues.redhat.com/browse/NE-2766): Bump Kubernetes to 1.36.2 and Go to 1.26 [#814](https://github.com/openshift/router/pull/814)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Make external cert validation asynchronous [#745](https://github.com/openshift/router/pull/745)
* [OCPBUGS-87204](https://issues.redhat.com/browse/OCPBUGS-87204): Prevent SSRF via FQDN-typed EndpointSlices [#812](https://github.com/openshift/router/pull/812)
* [NE-2218](https://issues.redhat.com/browse/NE-2218): Add HAProxy standalone images for 2.8 and 3.2 [#780](https://github.com/openshift/router/pull/780)
* [Full changelog](https://github.com/openshift/router/compare/2a6e5d1fe0879778088728603a8bf256dbb4cedb...682319a1bb432f0203951c33336d0f55947e1099)
### [hyperkube, kube-proxy, pod](https://github.com/openshift/kubernetes/tree/63ee93dac28329fd9d81e91b21ea8d8c43105d01)
* [OCPBUGS-92836](https://issues.redhat.com/browse/OCPBUGS-92836): UPSTREAM: <carry>: upkeep cpu partitioning admission webhook [#2713](https://github.com/openshift/kubernetes/pull/2713)
* [STOR-2963](https://issues.redhat.com/browse/STOR-2963): Save SELinuxWarningController upgradeability to a ConfigMap [#2720](https://github.com/openshift/kubernetes/pull/2720)
* [OCPBUGS-90520](https://issues.redhat.com/browse/OCPBUGS-90520): UPSTREAM: 140211: Promote regression-issue-74839 to 1.5 [#2709](https://github.com/openshift/kubernetes/pull/2709)
* [OCPBUGS-99058](https://issues.redhat.com/browse/OCPBUGS-99058): Disable DRA extended resource test that requires dedicated DRA infrastructure [#2721](https://github.com/openshift/kubernetes/pull/2721)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#2653](https://github.com/openshift/kubernetes/pull/2653)
* [Full changelog](https://github.com/openshift/kubernetes/compare/a466682e3867da746be24d7d56c6641612721d6c...63ee93dac28329fd9d81e91b21ea8d8c43105d01)
### [hypershift](https://github.com/openshift/hypershift/tree/872a7e821c3fe01b2f866ceada3749a899e3d64f)
* [CNTRLPLANE-3910](https://issues.redhat.com/browse/CNTRLPLANE-3910): Fix e2e test reliability for mirroring tests and test-changed target [#9086](https://github.com/openshift/hypershift/pull/9086)
* [CNTRLPLANE-3919](https://issues.redhat.com/browse/CNTRLPLANE-3919): data race in TestEnqueueNodePoolsForCloudConfig [#9095](https://github.com/openshift/hypershift/pull/9095)
* NO-JIRA: chore(konflux): update Tekton task bundles to latest versions [#9081](https://github.com/openshift/hypershift/pull/9081)
* [NE-2815](https://issues.redhat.com/browse/NE-2815): feat: configure HAProxy version selection [#9040](https://github.com/openshift/hypershift/pull/9040)
* [CNTRLPLANE-3791](https://issues.redhat.com/browse/CNTRLPLANE-3791): fix: revert api-lint --whole-files to avoid surfacing pre-existing violations [#9071](https://github.com/openshift/hypershift/pull/9071)
* [OCPBUGS-99014](https://issues.redhat.com/browse/OCPBUGS-99014): Authenticate Konnectivity agents with cluster CA [#9031](https://github.com/openshift/hypershift/pull/9031)
* [CNTRLPLANE-3032](https://issues.redhat.com/browse/CNTRLPLANE-3032): test: add e2e v2 tests for NodePool OSImageStream [#9033](https://github.com/openshift/hypershift/pull/9033)
* [OCPBUGS-98744](https://issues.redhat.com/browse/OCPBUGS-98744): compare post-upgrade RHCOS version against pre-upgrade instead of release metadata [#9014](https://github.com/openshift/hypershift/pull/9014)
* [OCPBUGS-98462](https://issues.redhat.com/browse/OCPBUGS-98462): add jitter to AWS endpoint service requeue delay [#8996](https://github.com/openshift/hypershift/pull/8996)
* [OCPBUGS-98465](https://issues.redhat.com/browse/OCPBUGS-98465): prevent DS crash in pull secret verifier and add propagation diagnostics [#8991](https://github.com/openshift/hypershift/pull/8991)
* [OCPBUGS-99289](https://issues.redhat.com/browse/OCPBUGS-99289): Exclude aggregated docs page from search index [#9043](https://github.com/openshift/hypershift/pull/9043)
* [CNTRLPLANE-3199](https://issues.redhat.com/browse/CNTRLPLANE-3199): add etcd backup infrastructure and docs for self-managed Azure [#8785](https://github.com/openshift/hypershift/pull/8785)
* [CNTRLPLANE-3862](https://issues.redhat.com/browse/CNTRLPLANE-3862): fix(ci): reintroduce verify-ci make target for GHA verify workflow [#9045](https://github.com/openshift/hypershift/pull/9045)
* [CNTRLPLANE-3859](https://issues.redhat.com/browse/CNTRLPLANE-3859): Restructure pre-commit push hooks for faster local feedback [#9042](https://github.com/openshift/hypershift/pull/9042)
* [CNTRLPLANE-3434](https://issues.redhat.com/browse/CNTRLPLANE-3434): add ho-release-gate pipeline for nightly promotion [#8602](https://github.com/openshift/hypershift/pull/8602)
* NO-JIRA: fix(cpo): regenerate stale ModernTLS test fixtures [#9041](https://github.com/openshift/hypershift/pull/9041)
* [CNTRLPLANE-647](https://issues.redhat.com/browse/CNTRLPLANE-647): Expose v4/v6InternalSubnet OVN-Kubernetes configuration in HostedCluster API [#8249](https://github.com/openshift/hypershift/pull/8249)
* [ARO-27360](https://issues.redhat.com/browse/ARO-27360): Add ACR pull identity configured metric [#8840](https://github.com/openshift/hypershift/pull/8840)
* [ARO-24037](https://issues.redhat.com/browse/ARO-24037): gate cloud config on hash to prevent serving stale content [#8946](https://github.com/openshift/hypershift/pull/8946)
* [CNTRLPLANE-3615](https://issues.redhat.com/browse/CNTRLPLANE-3615): add tls security profile configuration for the etcd [#8871](https://github.com/openshift/hypershift/pull/8871)
* [OCPBUGS-88312](https://issues.redhat.com/browse/OCPBUGS-88312): use in-cluster service for oauth-server [#8772](https://github.com/openshift/hypershift/pull/8772)
* [CNTRLPLANE-3791](https://issues.redhat.com/browse/CNTRLPLANE-3791): make pre-commit hooks resilient to mock generation failures [#9016](https://github.com/openshift/hypershift/pull/9016)
* NO-JIRA: update Tekton task bundles to latest versions [#9038](https://github.com/openshift/hypershift/pull/9038)
* [OCPBUGS-98384](https://issues.redhat.com/browse/OCPBUGS-98384): fix bastion cleanup KeyPair leak by capturing infraID/region eagerly [#8982](https://github.com/openshift/hypershift/pull/8982)
* [CNTRLPLANE-3674](https://issues.redhat.com/browse/CNTRLPLANE-3674): Add Jira Agent onboarding guide [#8814](https://github.com/openshift/hypershift/pull/8814)
* [CNTRLPLANE-3825](https://issues.redhat.com/browse/CNTRLPLANE-3825): move test conventions to TESTING.md [#9036](https://github.com/openshift/hypershift/pull/9036)
* [OCPSTRAT-3150](https://issues.redhat.com/browse/OCPSTRAT-3150): Add etcd sharding by resource kind support [#8705](https://github.com/openshift/hypershift/pull/8705)
* [OCPBUGS-98695](https://issues.redhat.com/browse/OCPBUGS-98695): add Azure CPO overrides for 4.22 [#9010](https://github.com/openshift/hypershift/pull/9010)
* NO-JIRA: ci(deps): bump actions/setup-node from 6.4.0 to 7.0.0 [#9030](https://github.com/openshift/hypershift/pull/9030)
* [CNTRLPLANE-3763](https://issues.redhat.com/browse/CNTRLPLANE-3763): tag bastion resources with e2e provenance [#9022](https://github.com/openshift/hypershift/pull/9022)
* [OCPBUGS-98575](https://issues.redhat.com/browse/OCPBUGS-98575): feat: inject hosted cluster TLS security profile into packageserver [#9001](https://github.com/openshift/hypershift/pull/9001)
* [AUTOSCALE-870](https://issues.redhat.com/browse/AUTOSCALE-870): add KarpenterOperator tech-preview FeatureGate [#8976](https://github.com/openshift/hypershift/pull/8976)
* [CNTRLPLANE-3774](https://issues.redhat.com/browse/CNTRLPLANE-3774): fix: control-plane-operator: improve opaque conditions [#8804](https://github.com/openshift/hypershift/pull/8804)
* [CNTRLPLANE-3695](https://issues.redhat.com/browse/CNTRLPLANE-3695): refactor(hcco): extract machine-config-daemon pod name format to constant [#8988](https://github.com/openshift/hypershift/pull/8988)
* [CNTRLPLANE-3820](https://issues.redhat.com/browse/CNTRLPLANE-3820): add cleanleaked tool for AWS leaked resource cleanup [#8964](https://github.com/openshift/hypershift/pull/8964)
* [SPLAT-2743](https://issues.redhat.com/browse/SPLAT-2743): aws/ccm - remove inline iam policy patch [#8835](https://github.com/openshift/hypershift/pull/8835)
* NO-JIRA: Add validateOnUpdateTableInput to envtest and fix test specs [#9015](https://github.com/openshift/hypershift/pull/9015)
* [OCPBUGS-98461](https://issues.redhat.com/browse/OCPBUGS-98461): requeue CRR on transiently unavailable resources [#8997](https://github.com/openshift/hypershift/pull/8997)
* [OCPBUGS-98718](https://issues.redhat.com/browse/OCPBUGS-98718): retry CreateVpcEndpoint on AWS throttle errors [#9012](https://github.com/openshift/hypershift/pull/9012)
* [CNTRLPLANE-3030](https://issues.redhat.com/browse/CNTRLPLANE-3030): feat(nodepool,ignition-server): consume os-stream and add ValidOSImageStream condition [#8792](https://github.com/openshift/hypershift/pull/8792)
* [OCPBUGS-88738](https://issues.redhat.com/browse/OCPBUGS-88738): clean up orphaned mirrored ConfigMaps on NodePool deletion [#8890](https://github.com/openshift/hypershift/pull/8890)
* [OCPBUGS-97830](https://issues.redhat.com/browse/OCPBUGS-97830): Add wait-for-etcd init container to oauth-apiserver [#8940](https://github.com/openshift/hypershift/pull/8940)
* fix(ci): make race detection opt-out for pre-push hook [#9003](https://github.com/openshift/hypershift/pull/9003)
* [CNTRLPLANE-3763](https://issues.redhat.com/browse/CNTRLPLANE-3763): tag CLI and e2e AWS resources with infra-id, cluster-name, and source [#8909](https://github.com/openshift/hypershift/pull/8909)
* [OCPBUGS-93462](https://issues.redhat.com/browse/OCPBUGS-93462): Fix stale resourceVersion in HCCO patchHCPStatusCondition [#8902](https://github.com/openshift/hypershift/pull/8902)
* [OCPBUGS-98466](https://issues.redhat.com/browse/OCPBUGS-98466): retry Prometheus query exec on transient konnectivity 502 [#8995](https://github.com/openshift/hypershift/pull/8995)
* [OCPBUGS-98464](https://issues.redhat.com/browse/OCPBUGS-98464): handle stale DaemonSet in GlobalPullSecret test [#8990](https://github.com/openshift/hypershift/pull/8990)
* [SPLAT-2741](https://issues.redhat.com/browse/SPLAT-2741): Add SetSecurityGroups perms for AWS CCM for BYO SG on AWS NLB [#8401](https://github.com/openshift/hypershift/pull/8401)
* [OCPBUGS-98571](https://issues.redhat.com/browse/OCPBUGS-98571): Skip Azure topology LB scope override for ARO HCP IngressController [#8992](https://github.com/openshift/hypershift/pull/8992)
* [CNTRLPLANE-3553](https://issues.redhat.com/browse/CNTRLPLANE-3553): Wire usesRunc detection into RHEL stream resolution [#8832](https://github.com/openshift/hypershift/pull/8832)
* [OCPBUGS-88531](https://issues.redhat.com/browse/OCPBUGS-88531): Remove CPO-side restart logic for CNO operands [#8751](https://github.com/openshift/hypershift/pull/8751)
* [CNTRLPLANE-3831](https://issues.redhat.com/browse/CNTRLPLANE-3831): skip UpstreamParity OIDC tests on releases before 4.23 [#8987](https://github.com/openshift/hypershift/pull/8987)
* [OCPBUGS-98086](https://issues.redhat.com/browse/OCPBUGS-98086): fix(cpo,hcco): prevent premature KAS convergence during KMS key rotation [#8970](https://github.com/openshift/hypershift/pull/8970)
* [OCPBUGS-78310](https://issues.redhat.com/browse/OCPBUGS-78310): fix(cli): initialize controller-runtime logger in product-cli [#8955](https://github.com/openshift/hypershift/pull/8955)
* [OCPBUGS-63720](https://issues.redhat.com/browse/OCPBUGS-63720): orphan machines when managed identity is invalid on clus… [#8296](https://github.com/openshift/hypershift/pull/8296)
* [OCPBUGS-98387](https://issues.redhat.com/browse/OCPBUGS-98387): Add retry logic to fix Azure self-managed e2e presubmit failures [#8983](https://github.com/openshift/hypershift/pull/8983)
* [OCPBUGS-93785](https://issues.redhat.com/browse/OCPBUGS-93785): fix(cpo): initialize nil resource requests map before applying overrides [#8924](https://github.com/openshift/hypershift/pull/8924)
* [OCPBUGS-91650](https://issues.redhat.com/browse/OCPBUGS-91650): disable consolidation in karpenter upgrade test [#8874](https://github.com/openshift/hypershift/pull/8874)
* [CNTRLPLANE-3553](https://issues.redhat.com/browse/CNTRLPLANE-3553): Wire osImageStream into NodePool controller (hash, token, status, validation) [#8730](https://github.com/openshift/hypershift/pull/8730)
* NO-JIRA: chore: Resolve git SHA for PULL_BASE_SHA in makefile [#8980](https://github.com/openshift/hypershift/pull/8980)
* [OCPBUGS-95615](https://issues.redhat.com/browse/OCPBUGS-95615): fix(kubevirt): use only first MachineInternalIP per family in EndpointSlice endpoints [#8892](https://github.com/openshift/hypershift/pull/8892)
* [CNTRLPLANE-3824](https://issues.redhat.com/browse/CNTRLPLANE-3824): Fix verify-crd-schema in git worktrees [#8975](https://github.com/openshift/hypershift/pull/8975)
* [GCP-859](https://issues.redhat.com/browse/GCP-859): scope PSC NAT subnet discovery to the management cluster VPC [#8927](https://github.com/openshift/hypershift/pull/8927)
* [CNTRLPLANE-3761](https://issues.redhat.com/browse/CNTRLPLANE-3761): replace git clean with find for mock cleanup [#8973](https://github.com/openshift/hypershift/pull/8973)
* NO-JIRA: chore: update core-reviewers membership [#8967](https://github.com/openshift/hypershift/pull/8967)
* [OTA-1764](https://issues.redhat.com/browse/OTA-1764): feat(cvo): add TLS cipher suites and minimum version flags [#8013](https://github.com/openshift/hypershift/pull/8013)
* [AROSLSRE-1158](https://issues.redhat.com/browse/AROSLSRE-1158): add --install-scope flag to hypershift install [#8725](https://github.com/openshift/hypershift/pull/8725)
* NO-JIRA: chore(deps): weekly dependabot consolidation [#8849](https://github.com/openshift/hypershift/pull/8849)
* [CNTRLPLANE-3616](https://issues.redhat.com/browse/CNTRLPLANE-3616): setting min-tls-version for the konnectivity-server container [#8866](https://github.com/openshift/hypershift/pull/8866)
* [CNTRLPLANE-3766](https://issues.redhat.com/browse/CNTRLPLANE-3766): add chai-bot CI daily health report instructions [#8918](https://github.com/openshift/hypershift/pull/8918)
* NO-JIRA: Remove address-review-comments GHA workflow [#8943](https://github.com/openshift/hypershift/pull/8943)
* [CNTRLPLANE-3698](https://issues.redhat.com/browse/CNTRLPLANE-3698): fix(install): replace context.TODO() with proper ctx parameter [#8932](https://github.com/openshift/hypershift/pull/8932)
* [CNTRLPLANE-3771](https://issues.redhat.com/browse/CNTRLPLANE-3771): fix /rebase GHA workflow for fork PRs [#8934](https://github.com/openshift/hypershift/pull/8934)
* NO-JIRA: chore: update github actions runner image to go 1.26.4 [#8888](https://github.com/openshift/hypershift/pull/8888)
* [AROSLSRE-830](https://issues.redhat.com/browse/AROSLSRE-830): Add etcd EndpointSlice self-registration to fix DNS resolution delays [#8613](https://github.com/openshift/hypershift/pull/8613)
* [OCPBUGS-92086](https://issues.redhat.com/browse/OCPBUGS-92086): GetVnetID is empty when running setup_all.sh in Managed AKS [#8830](https://github.com/openshift/hypershift/pull/8830)
* [OCPBUGS-84269](https://issues.redhat.com/browse/OCPBUGS-84269): fix(nodepool): skip CNI-internal IPs in ClusterNetworkCIDRConflict check [#8230](https://github.com/openshift/hypershift/pull/8230)
* [CNTRLPLANE-3619](https://issues.redhat.com/browse/CNTRLPLANE-3619): add azure CPO overrides for 4.22.0-4.22.3 [#8908](https://github.com/openshift/hypershift/pull/8908)
* [CNTRLPLANE-3696](https://issues.redhat.com/browse/CNTRLPLANE-3696): Remove stale TODO about ImagePullPolicy in DNS operator [#8923](https://github.com/openshift/hypershift/pull/8923)
* NO-JIRA: Fall back to AWS SDK default credential chain when no explicit credentials provided [#8889](https://github.com/openshift/hypershift/pull/8889)
* [CNTRLPLANE-3697](https://issues.redhat.com/browse/CNTRLPLANE-3697): Expand unit test coverage for KAS config params [#8922](https://github.com/openshift/hypershift/pull/8922)
* [CNTRLPLANE-3306](https://issues.redhat.com/browse/CNTRLPLANE-3306): add ExternalOIDCWithUpstreamParity e2e tests [#8287](https://github.com/openshift/hypershift/pull/8287)
* [CNTRLPLANE-3624](https://issues.redhat.com/browse/CNTRLPLANE-3624): e2e v2 test for control-plane-pki-operator TLS configuration [#8793](https://github.com/openshift/hypershift/pull/8793)
* [OCPBUGS-94238](https://issues.redhat.com/browse/OCPBUGS-94238): Add missing CLI IAM role policy entry [#8883](https://github.com/openshift/hypershift/pull/8883)
* NO-JIRA: Add missing verify targets to GitHub Actions workflow [#8870](https://github.com/openshift/hypershift/pull/8870)
* NO-JIRA: fix(e2e-v2): gate ConfigOperatorReconciliationSucceeded on 4.23+ [#8875](https://github.com/openshift/hypershift/pull/8875)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): Add shared status patching helpers with optimistic locking [#8782](https://github.com/openshift/hypershift/pull/8782)
* [OCPBUGS-94178](https://issues.redhat.com/browse/OCPBUGS-94178): Remove --skip-crd-migration-phases flags from CAPI deployment [#8881](https://github.com/openshift/hypershift/pull/8881)
* NO-JIRA: add Konflux CI scripts reference and document validate-pr-override-images [#8852](https://github.com/openshift/hypershift/pull/8852)
* [CNTRLPLANE-3529](https://issues.redhat.com/browse/CNTRLPLANE-3529): Add operator IAM role creation command and install role ARN flags [#8636](https://github.com/openshift/hypershift/pull/8636)
* [CNTRLPLANE-3737](https://issues.redhat.com/browse/CNTRLPLANE-3737): Add find-push-pipelinerun script [#8851](https://github.com/openshift/hypershift/pull/8851)
* [GCP-841](https://issues.redhat.com/browse/GCP-841): remove ClusterResourceSet feature gate from CAPG manager args [#8795](https://github.com/openshift/hypershift/pull/8795)
* [GCP-866](https://issues.redhat.com/browse/GCP-866): chore(owners): add floresroger to gcp-reviewers [#8863](https://github.com/openshift/hypershift/pull/8863)
* [CNTRLPLANE-3733](https://issues.redhat.com/browse/CNTRLPLANE-3733): add --blog flag to /pr-report skill [#8848](https://github.com/openshift/hypershift/pull/8848)
* [CNTRLPLANE-3577](https://issues.redhat.com/browse/CNTRLPLANE-3577): test(nodepool): add NodeDrainTimeout propagation tests [#8737](https://github.com/openshift/hypershift/pull/8737)
* [CNTRLPLANE-3576](https://issues.redhat.com/browse/CNTRLPLANE-3576): add RestartDateAnnotation propagation tests [#8733](https://github.com/openshift/hypershift/pull/8733)
* [CNTRLPLANE-3565](https://issues.redhat.com/browse/CNTRLPLANE-3565): test and fix destroy grace period lifecycle [#8789](https://github.com/openshift/hypershift/pull/8789)
* [OTA-1956](https://issues.redhat.com/browse/OTA-1956): Skip ConsolePlugin manifests during CVO bootstrap [#8839](https://github.com/openshift/hypershift/pull/8839)
* [OCPBUGS-92791](https://issues.redhat.com/browse/OCPBUGS-92791): fix(configrefs): exclude componentRoutes secrets from management cluster sync [#8838](https://github.com/openshift/hypershift/pull/8838)
* [CNTRLPLANE-3624](https://issues.redhat.com/browse/CNTRLPLANE-3624): add tls security profile configuration for the control-plane-pki-operator [#8768](https://github.com/openshift/hypershift/pull/8768)
* [CNTRLPLANE-3686](https://issues.redhat.com/browse/CNTRLPLANE-3686): feat(api,cpo): add observedGeneration to ControlPlaneComponentStatus [#8819](https://github.com/openshift/hypershift/pull/8819)
* [OCPBUGS-86025](https://issues.redhat.com/browse/OCPBUGS-86025): Close HTTP response bodies to prevent goroutine and connection leaks [#8560](https://github.com/openshift/hypershift/pull/8560)
* [OCPBUGS-92206](https://issues.redhat.com/browse/OCPBUGS-92206): bump catalog image version cap from 4.21 to 4.22 [#8836](https://github.com/openshift/hypershift/pull/8836)
* And 4 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/hypershift/compare/2d2b2d0805d36dcf401fdb5f3d913b9f7984ce42...872a7e821c3fe01b2f866ceada3749a899e3d64f)
### [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/tree/be4fd01725ce5ab0b47f846c905a349aeee8ab53)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#176](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/176)
* [STOR-2921](https://issues.redhat.com/browse/STOR-2921): update deployment manifests from upstream [#174](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/174)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/compare/e6d299f720a76dd25fcdc304d408f43c33a42fb6...be4fd01725ce5ab0b47f846c905a349aeee8ab53)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/be3192e4c05659282c3d1f1720f8cd93b59b399a)
* 🐛 OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#164](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/164)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/0fdc00b1c1f411da3c385e27e63d909761ad1aa9...be3192e4c05659282c3d1f1720f8cd93b59b399a)
### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/a31f65a766150264daac38fcebe1d111c5ad79a0)
* [OCPCLOUD-3641](https://issues.redhat.com/browse/OCPCLOUD-3641): Support configurable boot volume profile, size, IOPS and bandwidth [#97](https://github.com/openshift/machine-api-provider-ibmcloud/pull/97)
* [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/80a91b3fb96a4fb74ed03e895d617b462ad21db2...a31f65a766150264daac38fcebe1d111c5ad79a0)
### [insights-operator](https://github.com/openshift/insights-operator/tree/46db2e2ca9b0b7576e0b66f4521a2cf83aad8893)
* [CCXDEV-16524](https://issues.redhat.com/browse/CCXDEV-16524): gather alertmanager configuration [#1322](https://github.com/openshift/insights-operator/pull/1322)
* NO-JIRA: Update misleading docs on the QEMU gatherer [#1319](https://github.com/openshift/insights-operator/pull/1319)
* [OCPBUGS-78774](https://issues.redhat.com/browse/OCPBUGS-78774): kube-rbac-proxy must honor Central TLS configuration [#1299](https://github.com/openshift/insights-operator/pull/1299)
* [OCPBUGS-85109](https://issues.redhat.com/browse/OCPBUGS-85109): move required-scc annotation to pod template in gathering job [#1309](https://github.com/openshift/insights-operator/pull/1309)
* [OCPBUGS-93805](https://issues.redhat.com/browse/OCPBUGS-93805): update HyperShift deployment manifest [#1313](https://github.com/openshift/insights-operator/pull/1313)
* [CCXDEV-1560](https://issues.redhat.com/browse/CCXDEV-1560): Optimize the CPU usage of insights-runtime-extractor [#1220](https://github.com/openshift/insights-operator/pull/1220)
* [CCXDEV-16159](https://issues.redhat.com/browse/CCXDEV-16159): controlplanemachinesets gatherer [#1294](https://github.com/openshift/insights-operator/pull/1294)
* [Full changelog](https://github.com/openshift/insights-operator/compare/1eb28cdcfa1ec93afce5fdb582243c2ee47fc4e4...46db2e2ca9b0b7576e0b66f4521a2cf83aad8893)
### [ironic](https://github.com/openshift/ironic-image/tree/e9478ec49dd508f74234582a8247f9186f584500)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#867](https://github.com/openshift/ironic-image/pull/867)
* [METAL-1898](https://issues.redhat.com/browse/METAL-1898): Add ironic-prometheus-exporter to update-requirements workflow [#866](https://github.com/openshift/ironic-image/pull/866)
* [METAL-1878](https://issues.redhat.com/browse/METAL-1878): [s2i] Move direct dependencies from packages to source [#749](https://github.com/openshift/ironic-image/pull/749)
* NO-ISSUE: Merge upstream 2026 06 11 [#854](https://github.com/openshift/ironic-image/pull/854)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#864](https://github.com/openshift/ironic-image/pull/864)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#862](https://github.com/openshift/ironic-image/pull/862)
* [Full changelog](https://github.com/openshift/ironic-image/compare/f5123e096a6c29f82d102ab78a9b700592c6cb8d...e9478ec49dd508f74234582a8247f9186f584500)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/f0ff570e26f0312dbb02058a092887c276bf0706)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#291](https://github.com/openshift/ironic-agent-image/pull/291)
* [METAL-1878](https://issues.redhat.com/browse/METAL-1878): [s2i] Move direct dependencies from packages to source [#290](https://github.com/openshift/ironic-agent-image/pull/290)
* [OCPBUGS-94115](https://issues.redhat.com/browse/OCPBUGS-94115): Replace individual package removal with a single rpm -e loop [#281](https://github.com/openshift/ironic-agent-image/pull/281)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#267](https://github.com/openshift/ironic-agent-image/pull/267)
* [OCPBUGS-94115](https://issues.redhat.com/browse/OCPBUGS-94115): Replace dnf remove with rpm -e to prevent dependency removal [#269](https://github.com/openshift/ironic-agent-image/pull/269)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/2305acf17b295547c6ba07e75f44778ede01f120...f0ff570e26f0312dbb02058a092887c276bf0706)
### [karpenter-operator](https://github.com/openshift/karpenter-operator/tree/79a93d5b4221424832a247a618e20b8177ec71ed)
* [AUTOSCALE-644](https://issues.redhat.com/browse/AUTOSCALE-644): Release chores 5.0 for Karpenter [#18](https://github.com/openshift/karpenter-operator/pull/18)
* [AUTOSCALE-806](https://issues.redhat.com/browse/AUTOSCALE-806): Introduce Karpenter API lifecycle object and controller [#16](https://github.com/openshift/karpenter-operator/pull/16)
* [AUTOSCALE-827](https://issues.redhat.com/browse/AUTOSCALE-827): apply KarpenterOperator feature gate to manifests [#14](https://github.com/openshift/karpenter-operator/pull/14)
* [Full changelog](https://github.com/openshift/karpenter-operator/compare/01d708f6cedaa55252fedb1db24c7455678bfb81...79a93d5b4221424832a247a618e20b8177ec71ed)
### [keepalived-ipfailover](https://github.com/openshift/images/tree/13118bff15103b31a6528bf8de2d0d6de05f4742)
* [OCPBUGS-99649](https://issues.redhat.com/browse/OCPBUGS-99649): Reinstall tzdata if /usr/share/zoneinfo is missing [#246](https://github.com/openshift/images/pull/246)
* [NE-2223](https://issues.redhat.com/browse/NE-2223): Bump HAProxy to 3.2 in egress DNS proxy [#244](https://github.com/openshift/images/pull/244)
* [NE-2716](https://issues.redhat.com/browse/NE-2716): Replace iptables with nftables in origin-egress-router [#242](https://github.com/openshift/images/pull/242)
* [NE-2715](https://issues.redhat.com/browse/NE-2715): Update keepalived-ipfailover to replace iptables with nftables [#235](https://github.com/openshift/images/pull/235)
* [Full changelog](https://github.com/openshift/images/compare/34acc695df8c51e7ff10a853fb13ad1928ac2e04...13118bff15103b31a6528bf8de2d0d6de05f4742)
### [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server/tree/e24eb97b02b3d39095c70675f5594ae5bc98d238)
* [OCPBUGS-87412](https://issues.redhat.com/browse/OCPBUGS-87412): Updating ose-kube-metrics-server-container image to be consistent with ART for 5.0 [#69](https://github.com/openshift/kubernetes-metrics-server/pull/69)
* NO-JIRA: Cleanup OWNERS list [#68](https://github.com/openshift/kubernetes-metrics-server/pull/68)
* [Full changelog](https://github.com/openshift/kubernetes-metrics-server/compare/38c16c4698d131ab0e2da0d4b4b76d5322a89bab...e24eb97b02b3d39095c70675f5594ae5bc98d238)
### [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy/tree/43c114bc124f59e2fc3223dea8e0a8f4cdeed18d)
* [OCPBUGS-87245](https://issues.redhat.com/browse/OCPBUGS-87245): Updating kube-rbac-proxy-container image to be consistent with ART for 5.0 [#143](https://github.com/openshift/kube-rbac-proxy/pull/143)
* [Full changelog](https://github.com/openshift/kube-rbac-proxy/compare/d12e274605248f6c59373240a7eae7a7a357dcb3...43c114bc124f59e2fc3223dea8e0a8f4cdeed18d)
### [kube-state-metrics](https://github.com/openshift/kube-state-metrics/tree/019ecc7d533333dfd3bf8893e78cd7ec6e282f01)
* [OCPBUGS-99282](https://issues.redhat.com/browse/OCPBUGS-99282): embed a copy of the timezone database [#148](https://github.com/openshift/kube-state-metrics/pull/148)
* [Full changelog](https://github.com/openshift/kube-state-metrics/compare/b5df90392fbb08eb4c48e8a07f35b34a4c846312...019ecc7d533333dfd3bf8893e78cd7ec6e282f01)
### [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt/tree/5eb884abcd2ff17ae8d7b2691ca12494597c08a6)
* [OCPBUGS-87345](https://issues.redhat.com/browse/OCPBUGS-87345): Updating ose-kubevirt-cloud-controller-manager-container image to be consistent with ART for 5.0 [#75](https://github.com/openshift/cloud-provider-kubevirt/pull/75)
* [Full changelog](https://github.com/openshift/cloud-provider-kubevirt/compare/76dd5a6fa9e86573bf3dfb79be17edf832e3bae1...5eb884abcd2ff17ae8d7b2691ca12494597c08a6)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/3be0a58b3e9d168eb2dd746c58d79e9081f10c73)
* [SPLAT-2854](https://issues.redhat.com/browse/SPLAT-2854): Fixing issue related to unintended VAP interactions [#1518](https://github.com/openshift/machine-api-operator/pull/1518)
* [SPLAT-2858](https://issues.redhat.com/browse/SPLAT-2858): Fixing test issue where error result was for other resource type [#1522](https://github.com/openshift/machine-api-operator/pull/1522)
* [SPLAT-2813](https://issues.redhat.com/browse/SPLAT-2813): Create VAP E2Es [#1517](https://github.com/openshift/machine-api-operator/pull/1517)
* NO-JIRA: Bump golang.org/x/net to 0.56.0 to fix CVE [#1514](https://github.com/openshift/machine-api-operator/pull/1514)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/bd501fc8f16e6ce158add5ae335e9920a277fe68...3be0a58b3e9d168eb2dd746c58d79e9081f10c73)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/3b4a5c7d9fa127981c57efac6fa29bc76eac019d)
* [OCPNODE-4518](https://issues.redhat.com/browse/OCPNODE-4518): Block runc on RHEL 10 via OSImageURL stream class inspection [#6238](https://github.com/openshift/machine-config-operator/pull/6238)
* [MCO-2380](https://issues.redhat.com/browse/MCO-2380): MCO-2381: Expose MachineOSBuild Status Conditions on Paused MachineConfigPools and add E2E Tests for Paused Pool Builds [#6282](https://github.com/openshift/machine-config-operator/pull/6282)
* [MCO-2414](https://issues.redhat.com/browse/MCO-2414): Add unit tests for osImageStream [#6312](https://github.com/openshift/machine-config-operator/pull/6312)
* NO-ISSUE: extended tests, restore initial maxUnavailable when modified [#6336](https://github.com/openshift/machine-config-operator/pull/6336)
* [OCPBUGS-99695](https://issues.redhat.com/browse/OCPBUGS-99695): Add TC 88940- Apply password only if changes exist [#6328](https://github.com/openshift/machine-config-operator/pull/6328)
* NO-ISSUE: add AWS marketplace polarion ID test [#6330](https://github.com/openshift/machine-config-operator/pull/6330)
* [MCO-2184](https://issues.redhat.com/browse/MCO-2184): Adapt scale extended tests to support osstreams [#6299](https://github.com/openshift/machine-config-operator/pull/6299)
* [CNTRLPLANE-3840](https://issues.redhat.com/browse/CNTRLPLANE-3840): Remove ExternalTopologyMode guard from OSImageStream bootstrap [#6308](https://github.com/openshift/machine-config-operator/pull/6308)
* [MCO-2450](https://issues.redhat.com/browse/MCO-2450): Enable OS ImageStreams in OKD [#6314](https://github.com/openshift/machine-config-operator/pull/6314)
* [MCO-1333](https://issues.redhat.com/browse/MCO-1333): Validate OCL Containerfiles [#6187](https://github.com/openshift/machine-config-operator/pull/6187)
* NO-ISSUE: Add reusable utilities for image inspection [#6327](https://github.com/openshift/machine-config-operator/pull/6327)
* [MCO-1944](https://issues.redhat.com/browse/MCO-1944): Add NetworkPolicy Test case [#6283](https://github.com/openshift/machine-config-operator/pull/6283)
* [MCO-2413](https://issues.redhat.com/browse/MCO-2413): Image inspection cache [#6306](https://github.com/openshift/machine-config-operator/pull/6306)
* [MCO-1847](https://issues.redhat.com/browse/MCO-1847): adapt tc 52373 to new AWS marketplace feature [#6324](https://github.com/openshift/machine-config-operator/pull/6324)
* [MCO-1847](https://issues.redhat.com/browse/MCO-1847): update AWS backdated images in extended tests [#6320](https://github.com/openshift/machine-config-operator/pull/6320)
* [CORENET-5972](https://issues.redhat.com/browse/CORENET-5972): Add openvswitch-ipsec package into ipsec plugin [#4878](https://github.com/openshift/machine-config-operator/pull/4878)
* [MCO-2408](https://issues.redhat.com/browse/MCO-2408): Improve/Reduce code/duplicated logic in OsImageBuilderInNode [#6270](https://github.com/openshift/machine-config-operator/pull/6270)
* [MCO-2424](https://issues.redhat.com/browse/MCO-2424): Fix cert rotation timeout [#6309](https://github.com/openshift/machine-config-operator/pull/6309)
* [MCO-1990](https://issues.redhat.com/browse/MCO-1990): Irreconcilable configs test suite [#6085](https://github.com/openshift/machine-config-operator/pull/6085)
* [OCPBUGS-98745](https://issues.redhat.com/browse/OCPBUGS-98745): MCO-2424: add missing RBAC for pkis resource in MCC ClusterRole [#6307](https://github.com/openshift/machine-config-operator/pull/6307)
* [MCO-2301](https://issues.redhat.com/browse/MCO-2301): AWS Marketplace bootimage update support [#6015](https://github.com/openshift/machine-config-operator/pull/6015)
* [MCO-2407](https://issues.redhat.com/browse/MCO-2407): Move OSImageStream sync to MCC [#6278](https://github.com/openshift/machine-config-operator/pull/6278)
* [MCO-2427](https://issues.redhat.com/browse/MCO-2427): move password, bootimages and cpms suites to longduration suite [#6302](https://github.com/openshift/machine-config-operator/pull/6302)
* [OCPNODE-4604](https://issues.redhat.com/browse/OCPNODE-4604): upgrade CRIOCredentialProviderConfig to v1 [#6220](https://github.com/openshift/machine-config-operator/pull/6220)
* [OCPBUGS-98210](https://issues.redhat.com/browse/OCPBUGS-98210): Fix imagestream detection with extra guard [#6296](https://github.com/openshift/machine-config-operator/pull/6296)
* [MCO-1997](https://issues.redhat.com/browse/MCO-1997): MCO-2297: Add test for osImageStream [#5881](https://github.com/openshift/machine-config-operator/pull/5881)
* [AGENT-1522](https://issues.redhat.com/browse/AGENT-1522): bump InternalReleaseImage to v1 (and simply version dependency) [#6280](https://github.com/openshift/machine-config-operator/pull/6280)
* [OCPBUGS-98210](https://issues.redhat.com/browse/OCPBUGS-98210): Use release payload image for OSImageStream rebuild detection [#6284](https://github.com/openshift/machine-config-operator/pull/6284)
* [OCPBUGS-98040](https://issues.redhat.com/browse/OCPBUGS-98040): Bump golang.org/x/crypto to v0.54.0 [#6286](https://github.com/openshift/machine-config-operator/pull/6286)
* [OCPBUGS-10431](https://issues.redhat.com/browse/OCPBUGS-10431): allow worker pools to set staticPodPath by relaxing validation to only block control plane pools [#5724](https://github.com/openshift/machine-config-operator/pull/5724)
* [CNTRLPLANE-3212](https://issues.redhat.com/browse/CNTRLPLANE-3212): Enable configurable PKI for cert rotation [#5842](https://github.com/openshift/machine-config-operator/pull/5842)
* NO-ISSUE: Improve osimagestream pkg API [#6271](https://github.com/openshift/machine-config-operator/pull/6271)
* [OCPBUGS-92811](https://issues.redhat.com/browse/OCPBUGS-92811): Inject proxy into MCC deployment [#6237](https://github.com/openshift/machine-config-operator/pull/6237)
* [MCO-2152](https://issues.redhat.com/browse/MCO-2152): MCO-2153: MCO-2154: Create MCO network policies for pods [#6151](https://github.com/openshift/machine-config-operator/pull/6151)
* [OCPBUGS-57473](https://issues.redhat.com/browse/OCPBUGS-57473): create digest configmap without oc binary [#5794](https://github.com/openshift/machine-config-operator/pull/5794)
* [OCPBUGS-95030](https://issues.redhat.com/browse/OCPBUGS-95030): Update AMI Whitelist [#6253](https://github.com/openshift/machine-config-operator/pull/6253)
* [OCPBUGS-94000](https://issues.redhat.com/browse/OCPBUGS-94000): Remove sensitive ControllerConfig logging [#6245](https://github.com/openshift/machine-config-operator/pull/6245)
* NO-ISSUE: Remove dead code [#6203](https://github.com/openshift/machine-config-operator/pull/6203)
* [MCO-2393](https://issues.redhat.com/browse/MCO-2393): Use /proc/sys/crypto/fips_enabled for FIPS check in tests [#6233](https://github.com/openshift/machine-config-operator/pull/6233)
* [OCPBUGS-59958](https://issues.redhat.com/browse/OCPBUGS-59958): move cleanUpDuplicatedMC to avoid double reboot on first updated Master node [#6201](https://github.com/openshift/machine-config-operator/pull/6201)
* And 2 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/0e0f89b580ef7b792bbd302724e185644a595fa1...3b4a5c7d9fa127981c57efac6fa29bc76eac019d)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/9fbf9a64cdd3659c677452193e9afbc3d87ad702)
* [OU-1240](https://issues.redhat.com/browse/OU-1240): Makefile and package.json to enable test-frontend-ci [#1091](https://github.com/openshift/monitoring-plugin/pull/1091)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): add OWNERS_ALIAS and feature based OWNERS files [#1083](https://github.com/openshift/monitoring-plugin/pull/1083)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): update devspace setup [#1073](https://github.com/openshift/monitoring-plugin/pull/1073)
* NO-JIRA: build(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /web [#1084](https://github.com/openshift/monitoring-plugin/pull/1084)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): Remove Shared Dashbaords Components [#1077](https://github.com/openshift/monitoring-plugin/pull/1077)
* [OBSINTA-1290](https://issues.redhat.com/browse/OBSINTA-1290): fix incident detection test selectors [#1022](https://github.com/openshift/monitoring-plugin/pull/1022)
* [OU-1240](https://issues.redhat.com/browse/OU-1240): Dockerfile.test permission [#1076](https://github.com/openshift/monitoring-plugin/pull/1076)
* [OU-1240](https://issues.redhat.com/browse/OU-1240): increasing node options memory [#1069](https://github.com/openshift/monitoring-plugin/pull/1069)
* [OCPBUGS-92067](https://issues.redhat.com/browse/OCPBUGS-92067): graph redirect query parameter [#1067](https://github.com/openshift/monitoring-plugin/pull/1067)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): add styleguide and file-naming rules [#1065](https://github.com/openshift/monitoring-plugin/pull/1065)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): Update Import Linting [#1062](https://github.com/openshift/monitoring-plugin/pull/1062)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): move components and utils into shared locations [#1056](https://github.com/openshift/monitoring-plugin/pull/1056)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): don't match on feature_* webpack bundles [#1061](https://github.com/openshift/monitoring-plugin/pull/1061)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): update documentation with new frontend folder structure [#1055](https://github.com/openshift/monitoring-plugin/pull/1055)
* [OU-651](https://issues.redhat.com/browse/OU-651): Fix AlertRules page to display user defined loki alerts [#1054](https://github.com/openshift/monitoring-plugin/pull/1054)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): restructure folders [#1038](https://github.com/openshift/monitoring-plugin/pull/1038)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): Match new ols routing and names [#1052](https://github.com/openshift/monitoring-plugin/pull/1052)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): feat: align proposal url with ols detail view, check multiple namespaces for proposals [#1044](https://github.com/openshift/monitoring-plugin/pull/1044)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): swap monitoring-plugin to be feature driven [#1034](https://github.com/openshift/monitoring-plugin/pull/1034)
* [OBSINTA-1006](https://issues.redhat.com/browse/OBSINTA-1006): Add UI performance benchmarks for Incidents page [#873](https://github.com/openshift/monitoring-plugin/pull/873)
* NO-JIRA: fixing unit-test severity sort, variable template regex, and test corrections. [#1035](https://github.com/openshift/monitoring-plugin/pull/1035)
* Fix for OCPBUGS-94056: CVE-2026-13676 [#1032](https://github.com/openshift/monitoring-plugin/pull/1032)
* NO-JIRA: feat: keep current data while loading new data in perses dashboards [#1020](https://github.com/openshift/monitoring-plugin/pull/1020)
* NO-JIRA: enable coderabbit on main-alerts-management-api [#1021](https://github.com/openshift/monitoring-plugin/pull/1021)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): feat: fetch lazily ai proposal for each row in the alert list [#1014](https://github.com/openshift/monitoring-plugin/pull/1014)
* NO-JIRA: perses and monitoring automation testing - stabilization [#924](https://github.com/openshift/monitoring-plugin/pull/924)
* NO-JIRA: fix: update vulnerable dependencies [#1015](https://github.com/openshift/monitoring-plugin/pull/1015)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/d5ffdd28dcf8863f9163fe930ffa0753b09161f3...9fbf9a64cdd3659c677452193e9afbc3d87ad702)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/15a47271dcfda5c0e57a0a79720bab4e0baabdd8)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Simplify Dockerfile to rhel9-only build [#285](https://github.com/openshift/multus-cni/pull/285)
* [Full changelog](https://github.com/openshift/multus-cni/compare/b4ec7d8239ce4bd3ed949bce9816a013377b44c7...15a47271dcfda5c0e57a0a79720bab4e0baabdd8)
### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/d918bda28ad3d0200b6e4f2ef2801556764762e5)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Drop rhel8 builds, strip debug info [#405](https://github.com/openshift/whereabouts-cni/pull/405)
* [Full changelog](https://github.com/openshift/whereabouts-cni/compare/d691040e509bb20c26b5e8366c0d6f3bb45a5e02...d918bda28ad3d0200b6e4f2ef2801556764762e5)
### [must-gather](https://github.com/openshift/must-gather/tree/9bb48fe05db060476f9a380b9d6ea16f1e94a98b)
* [OCPBUGS-87538](https://issues.redhat.com/browse/OCPBUGS-87538): Updating ose-must-gather-container image to be consistent with ART for 5.0 [#553](https://github.com/openshift/must-gather/pull/553)
* [MG-247](https://issues.redhat.com/browse/MG-247): collect imagedigestmirrorsets and imagetagmirrorset resources [#538](https://github.com/openshift/must-gather/pull/538)
* [OCPBUGS-85052](https://issues.redhat.com/browse/OCPBUGS-85052): feat: add pacemaker resource to mustgather [#556](https://github.com/openshift/must-gather/pull/556)
* [Full changelog](https://github.com/openshift/must-gather/compare/16ac27eedcc79f5b57d77eb01e6b187b84fe7daa...9bb48fe05db060476f9a380b9d6ea16f1e94a98b)
### [network-interface-bond-cni](https://github.com/openshift/bond-cni/tree/19d390fd4d353619fdfb5e0070962d2ddf54b5bb)
* NO-JIRA: Sync from k8snetworkplumbingwg/bond-cni master (2026-07-07) [#121](https://github.com/openshift/bond-cni/pull/121)
* NO-JIRA: Update OWNERS: remove zshi-redhat [#120](https://github.com/openshift/bond-cni/pull/120)
* [Full changelog](https://github.com/openshift/bond-cni/compare/466a73aba120221bc080e4bbb9857ce56a7b5cce...19d390fd4d353619fdfb5e0070962d2ddf54b5bb)
### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844)
* [OCPBUGS-87459](https://issues.redhat.com/browse/OCPBUGS-87459): Updating ose-network-metrics-daemon-container image to be consistent with ART for 5.0 [#144](https://github.com/openshift/network-metrics-daemon/pull/144)
* [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/5b233ea1d80733c1b00c6bad65dec0620dbf783a...e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/2d8f85d257952c1a90467b6ee397334d49b7820e)
* [OCPBUGS-98878](https://issues.redhat.com/browse/OCPBUGS-98878): Override linkify-it to v5.0.2 and run npm audit fix (#452) [#452](https://github.com/openshift/networking-console-plugin/pull/452)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/35f8ec76aeffeab0452e36d39488ad00ac9c22c1...2d8f85d257952c1a90467b6ee397334d49b7820e)
### [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix/tree/dc584c6b2e895a6217f9e2dbed765209af1898a1)
* [OCPBUGS-87463](https://issues.redhat.com/browse/OCPBUGS-87463): Updating ose-nutanix-cloud-controller-manager-container image to be consistent with ART for 5.0 [#69](https://github.com/openshift/cloud-provider-nutanix/pull/69)
* [Full changelog](https://github.com/openshift/cloud-provider-nutanix/compare/61ec60465b92969966bc4b19637cdda75fb3105a...dc584c6b2e895a6217f9e2dbed765209af1898a1)
### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/688f57b5af12182644b33b770151352b1d54df3a)
* [CNTRLPLANE-2445](https://issues.redhat.com/browse/CNTRLPLANE-2445): K8s 1.35 rebase [#179](https://github.com/openshift/oauth-apiserver/pull/179)
* [CNTRLPLANE-2449](https://issues.redhat.com/browse/CNTRLPLANE-2449): feat: generate OpenAPI schemas from a running oauth-apiserver instance [#211](https://github.com/openshift/oauth-apiserver/pull/211)
* [Full changelog](https://github.com/openshift/oauth-apiserver/compare/9e9722dd2f3f71ec891e3413a8a8cdd6dbfe872f...688f57b5af12182644b33b770151352b1d54df3a)
### [oauth-server](https://github.com/openshift/oauth-server/tree/af32a04e7a91c538afe3808d51a5d28cf3480b22)
* [CNTRLPLANE-2446](https://issues.redhat.com/browse/CNTRLPLANE-2446): K8s 1.35 rebase [#215](https://github.com/openshift/oauth-server/pull/215)
* [CNTRLPLANE-3751](https://issues.redhat.com/browse/CNTRLPLANE-3751): Add dynamic proxy CA reload for outbound IdP transports [#244](https://github.com/openshift/oauth-server/pull/244)
* [CNTRLPLANE-3751](https://issues.redhat.com/browse/CNTRLPLANE-3751): Rebase onto 1.35 to be able to update openshift/api [#247](https://github.com/openshift/oauth-server/pull/247)
* [OCPBUGS-87407](https://issues.redhat.com/browse/OCPBUGS-87407): Updating oauth-server-container image to be consistent with ART for 5.0 [#246](https://github.com/openshift/oauth-server/pull/246)
* [CNTRLPLANE-3687](https://issues.redhat.com/browse/CNTRLPLANE-3687): contextification files [#241](https://github.com/openshift/oauth-server/pull/241)
* NO-JIRA: chore: update OWNERS file to align with other control plane repos [#242](https://github.com/openshift/oauth-server/pull/242)
* [Full changelog](https://github.com/openshift/oauth-server/compare/f892602b822782e0080abc70c6cd1d178f11e684...af32a04e7a91c538afe3808d51a5d28cf3480b22)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/be80e0c78d4e2ff3d29fd89df29dff79b00b15f6)
* [OPRUN-4436](https://issues.redhat.com/browse/OPRUN-4436): fix(test): update PolarionID:87224 for 4.23/5.0 upgrade boundary [#766](https://github.com/openshift/operator-framework-operator-controller/pull/766)
* [OPRUN-4659](https://issues.redhat.com/browse/OPRUN-4659), [OPRUN-4666](https://issues.redhat.com/browse/OPRUN-4666), [OPRUN-4671](https://issues.redhat.com/browse/OPRUN-4671), [OPRUN-4672](https://issues.redhat.com/browse/OPRUN-4672), [OPRUN-4673](https://issues.redhat.com/browse/OPRUN-4673), [OPRUN-4674](https://issues.redhat.com/browse/OPRUN-4674): Synchronize From Upstream Repositories + Remove spec.serviceAccount tests [#767](https://github.com/openshift/operator-framework-operator-controller/pull/767)
* NO-ISSUE: Remove stale reviewers/approvers, add trgeiger [#769](https://github.com/openshift/operator-framework-operator-controller/pull/769)
* [OPRUN-4392](https://issues.redhat.com/browse/OPRUN-4392), [OPRUN-4393](https://issues.redhat.com/browse/OPRUN-4393): Add OLMv1 progress deadline QE tests + fixes [#755](https://github.com/openshift/operator-framework-operator-controller/pull/755)
* [OPRUN-4437](https://issues.redhat.com/browse/OPRUN-4437): test: add allow-case for operator maxOCPVersion > cluster version [#765](https://github.com/openshift/operator-framework-operator-controller/pull/765)
* NO-ISSUE: Remove HelmChartSupport feature gate from experimental manifests [#764](https://github.com/openshift/operator-framework-operator-controller/pull/764)
* NO-ISSUE: Synchronize From Upstream Repositories [#760](https://github.com/openshift/operator-framework-operator-controller/pull/760)
* NO-ISSUE: Synchronize From Upstream Repositories [#759](https://github.com/openshift/operator-framework-operator-controller/pull/759)
* [OCPBUGS-92037](https://issues.redhat.com/browse/OCPBUGS-92037): Synchronize From Upstream Repositories [#757](https://github.com/openshift/operator-framework-operator-controller/pull/757)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/0264de126b0c71017a950b7e944b3570369fb1aa...be80e0c78d4e2ff3d29fd89df29dff79b00b15f6)
### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/3725a4aafba556cc24626541f5121ccbab54916a)
* [CNTRLPLANE-2449](https://issues.redhat.com/browse/CNTRLPLANE-2449): K8s 1.35 rebase [#616](https://github.com/openshift/openshift-apiserver/pull/616)
* [CNTRLPLANE-2449](https://issues.redhat.com/browse/CNTRLPLANE-2449): feat: generate OpenAPI schemas from a running openshift-apiserver instance [#645](https://github.com/openshift/openshift-apiserver/pull/645)
* [OCPBUGS-78480](https://issues.redhat.com/browse/OCPBUGS-78480): add watchlist new semantic support to project watcher [#661](https://github.com/openshift/openshift-apiserver/pull/661)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/831ab1bd2e1cf4e2deacf8f243e22c34b89a38c5...3725a4aafba556cc24626541f5121ccbab54916a)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/51bafa8bfb18064eae0ca9502fb4bb6c6963ff61)
* 🐛 OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#424](https://github.com/openshift/cluster-api-provider-openstack/pull/424)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/76198b243458ca266eb8b87bbcf69a7b7c3eec7f...51bafa8bfb18064eae0ca9502fb4bb6c6963ff61)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/56b3931de4636f7e0d212001f2074b9dddb45a8f)
* NO-ISSUE: Remove stale reviewers/approvers, add trgeiger [#1339](https://github.com/openshift/operator-framework-olm/pull/1339)
* NO-ISSUE: Synchronize From Upstream Repositories [#1337](https://github.com/openshift/operator-framework-olm/pull/1337)
* NO-ISSUE: Synchronize From Upstream Repositories [#1336](https://github.com/openshift/operator-framework-olm/pull/1336)
* [OCPBUGS-88737](https://issues.redhat.com/browse/OCPBUGS-88737): Update PSM/package server to support TLS profiles [#1328](https://github.com/openshift/operator-framework-olm/pull/1328)
* [OPRUN-4612](https://issues.redhat.com/browse/OPRUN-4612): Add E2E tests for ExperimentalListPackageCustomSchemas gRPC endpoint [#1327](https://github.com/openshift/operator-framework-olm/pull/1327)
* [TRT-2761](https://issues.redhat.com/browse/TRT-2761): Undo revert and fix applyClusterTLSProfile() [#1335](https://github.com/openshift/operator-framework-olm/pull/1335)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/93e5a5c64d445f71d98d70abc266b75af823370b...56b3931de4636f7e0d212001f2074b9dddb45a8f)
### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/1b7ac84cc2c8bdef32807efa5650752a46bca96c)
* NO-ISSUE: Bump github.com/operator-framework/operator-lifecycle-manager from 0.43.0 to 0.45.0 [#761](https://github.com/operator-framework/operator-marketplace/pull/761)
* NO-ISSUE: Bump dependencies to kube 1.36 [#766](https://github.com/operator-framework/operator-marketplace/pull/766)
* [OCPBUGS-85829](https://issues.redhat.com/browse/OCPBUGS-85829): bump catalog versions to 5.0 [#756](https://github.com/operator-framework/operator-marketplace/pull/756)
* NO-ISSUE: Bump github.com/onsi/gomega from 1.42.0 to 1.42.1 [#765](https://github.com/operator-framework/operator-marketplace/pull/765)
* NO-ISSUE: Bump github.com/onsi/ginkgo/v2 from 2.31.0 to 2.32.0 [#764](https://github.com/operator-framework/operator-marketplace/pull/764)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/a8006e26248b52c659315bd98eef227596964e41...1b7ac84cc2c8bdef32807efa5650752a46bca96c)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/88e9f0f146784e8525f6304a1f6f7c986eba2319)
* NO-JIRA: Update OWNERS File [#3288](https://github.com/openshift/ovn-kubernetes/pull/3288)
* NO-JIRA: DownStream Merge [07-02-2026] [#3279](https://github.com/openshift/ovn-kubernetes/pull/3279)
* [OCPBUGS-86223](https://issues.redhat.com/browse/OCPBUGS-86223): DownStream Merge [06-15-2026] [#3249](https://github.com/openshift/ovn-kubernetes/pull/3249)
* [CORENET-6688](https://issues.redhat.com/browse/CORENET-6688): Bump the downstream OVN package to 26.03 [#3258](https://github.com/openshift/ovn-kubernetes/pull/3258)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/f0527039dfc4901637721e7cecfdb9d0ea1c9c38...88e9f0f146784e8525f6304a1f6f7c986eba2319)
### [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/tree/f90431bfe8ca93850450b2b24fae152d2385ca08)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#119](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/119)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/compare/ab04496a6855098853048c957c499f2a63200f8e...f90431bfe8ca93850450b2b24fae152d2385ca08)
### [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs/tree/626c77c1b8c4b81b2d2f775f98f740dc09648061)
* NO-JIRA: Update OWNERS_ALIASES to modify approvers and reviewers [#105](https://github.com/openshift/cloud-provider-powervs/pull/105)
* No-Jira: Bump golang.org/x/crypto and golang.org/x/net to address security vulnerabilities [#106](https://github.com/openshift/cloud-provider-powervs/pull/106)
* [Full changelog](https://github.com/openshift/cloud-provider-powervs/compare/279b5927e540312bf3886267c9bcabc806d9f286...626c77c1b8c4b81b2d2f775f98f740dc09648061)
### [prometheus](https://github.com/openshift/prometheus/tree/52ee2d3abf00f3c31611cd9fff36e97cdfd28dcc)
* Bump openshift/prometheus to v3.13.1 [#347](https://github.com/openshift/prometheus/pull/347)
* NO-JIRA: [bot] Bump openshift/prometheus to v3.13.1 [#345](https://github.com/openshift/prometheus/pull/345)
* NO-JIRA: chore: revert narrow selectors detection for le/quantile labels [#344](https://github.com/openshift/prometheus/pull/344)
* [OCPBUGS-92191](https://issues.redhat.com/browse/OCPBUGS-92191): fix(tsdb): temporarily ignore Direct IO enablement errors on unsupported filesystems [#338](https://github.com/openshift/prometheus/pull/338)
* [Full changelog](https://github.com/openshift/prometheus/compare/6d5e6fee576a7e192b82209c6ce09855ca4bbaab...52ee2d3abf00f3c31611cd9fff36e97cdfd28dcc)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/5434dc397b4590f2906a9cd774d711113fc9f25b)
* [OCPBUGS-99435](https://issues.redhat.com/browse/OCPBUGS-99435): embed tzdata in the alertmanager binary [#140](https://github.com/openshift/prometheus-alertmanager/pull/140)
* Bump openshift/prometheus-alertmanager to v0.33.1 [#139](https://github.com/openshift/prometheus-alertmanager/pull/139)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/c30580cbb1af27356599c785720ee5043440e84a...5434dc397b4590f2906a9cd774d711113fc9f25b)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/6241c74e49baed25b1479c1786a6fc69b57b5a5b)
* [MON-4614](https://issues.redhat.com/browse/MON-4614): [bot] Bump openshift/node_exporter to v1.12.1 [#182](https://github.com/openshift/node_exporter/pull/182)
* [Full changelog](https://github.com/openshift/node_exporter/compare/45dec4ebf58ec9fb7083411ee4b6d46c01140c5f...6241c74e49baed25b1479c1786a6fc69b57b5a5b)
### [rhel-coreos, rhel-coreos-10, rhel-coreos-10-extensions, rhel-coreos-extensions](https://github.com/openshift/os/tree/5ffc1da076e834332482544182c22d984dbf76d2)
* [ART-19543](https://issues.redhat.com/browse/ART-19543): Refactor extensions build to use dnf download instead of rpm-ostree compose [#1945](https://github.com/openshift/os/pull/1945)
* [Full changelog](https://github.com/openshift/os/compare/d75a447b705c33cb96a43355eae4355c609d0784...5ffc1da076e834332482544182c22d984dbf76d2)
### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/59697cf7af4517dd44e28179a57f7f35b6ea0e22)
* [NE-2767](https://issues.redhat.com/browse/NE-2767): Bump Kubernetes to 1.36.2 [#100](https://github.com/openshift/route-controller-manager/pull/100)
* [OCPBUGS-92032](https://issues.redhat.com/browse/OCPBUGS-92032): Dockerfile: Copy only build-required files in builder stage [#99](https://github.com/openshift/route-controller-manager/pull/99)
* [Full changelog](https://github.com/openshift/route-controller-manager/compare/01ccbfb991fdbc559820a04c4932fc5ddf2339d0...59697cf7af4517dd44e28179a57f7f35b6ea0e22)
### [service-ca-operator](https://github.com/openshift/service-ca-operator/tree/e260be2b3710137012814ce9ca48f155f24f0b02)
* [OCPBUGS-87390](https://issues.redhat.com/browse/OCPBUGS-87390): Updating ose-service-ca-operator-container image to be consistent with ART for 5.0 [#361](https://github.com/openshift/service-ca-operator/pull/361)
* NO-JIRA: Bump github.com/openshift/build-machinery-go [#367](https://github.com/openshift/service-ca-operator/pull/367)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: inject centralized TLS into service-ca operand [#365](https://github.com/openshift/service-ca-operator/pull/365)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: have CVO inject the centralized TLS configuration into the operator's config [#359](https://github.com/openshift/service-ca-operator/pull/359)
* [Full changelog](https://github.com/openshift/service-ca-operator/compare/883c387c71c59767f08e21ca57c810b56ab16d01...e260be2b3710137012814ce9ca48f155f24f0b02)
### [telemeter](https://github.com/openshift/telemeter/tree/22ba1701333f3fd26490cc15b89ddf21df3f67f6)
* [OCPBUGS-93760](https://issues.redhat.com/browse/OCPBUGS-93760): bump github.com/prometheus/prometheus [#611](https://github.com/openshift/telemeter/pull/611)
* [Full changelog](https://github.com/openshift/telemeter/compare/a1dabee1951bd2878719a6da9d5d4304332ef0d4...22ba1701333f3fd26490cc15b89ddf21df3f67f6)
### [tests](https://github.com/openshift/origin/tree/a7b3bba9780389699e8426c6d3f1afee8464a5ad)
* [NE-2789](https://issues.redhat.com/browse/NE-2789): Add a guard to skip IngressControllerMultipleHAProxyVersions tests if IngressController CRD lacks haproxyVersion field [#31424](https://github.com/openshift/origin/pull/31424)
* NO-JIRA: chore(extended/prometheus): reduce targets-auth skip list and handle mTLS [#31372](https://github.com/openshift/origin/pull/31372)
* NO-JIRA: Ensure Platform Prometheus targets are not scraped with insecure_skip_verify [#31373](https://github.com/openshift/origin/pull/31373)
* NO-JIRA: Add e2e test to detect named ports in NetworkPolicies [#31375](https://github.com/openshift/origin/pull/31375)
* [OCPQUAL-20](https://issues.redhat.com/browse/OCPQUAL-20): Regenerate retry allowlist from 5.0 CI data [#31411](https://github.com/openshift/origin/pull/31411)
* [OCPBUGS-87079](https://issues.redhat.com/browse/OCPBUGS-87079): Add polling and longer waits in the EgressFirewall tests to avoid flakiness [#31376](https://github.com/openshift/origin/pull/31376)
* [NE-2789](https://issues.redhat.com/browse/NE-2789): Create 5 e2e test cases to help graduate the featuregate: IngressControllerMultipleHAProxyVersions [#31392](https://github.com/openshift/origin/pull/31392)
* [OCPBUGS-85696](https://issues.redhat.com/browse/OCPBUGS-85696): Adding logs and exponential backoff on execPod [#31352](https://github.com/openshift/origin/pull/31352)
* NO-JIRA: .devcontainer: bump Fedora base image to 44 for Go 1.26 [#31413](https://github.com/openshift/origin/pull/31413)
* [CONSOLE-5209](https://issues.redhat.com/browse/CONSOLE-5209): Add e2e tests for IngressComponentRouteLabels feature gate [#31385](https://github.com/openshift/origin/pull/31385)
* [OCPNODE-4538](https://issues.redhat.com/browse/OCPNODE-4538): Add e2e tests for DRA Partitionable Devices (KEP-4815) [#31230](https://github.com/openshift/origin/pull/31230)
* [TRT-2689](https://issues.redhat.com/browse/TRT-2689): Add `verify-apm` to the `verify` target [#31379](https://github.com/openshift/origin/pull/31379)
* [OCPBUGS-99166](https://issues.redhat.com/browse/OCPBUGS-99166): wait for default ServiceAccount before creating IRI test pod [#31401](https://github.com/openshift/origin/pull/31401)
* [MCO-2371](https://issues.redhat.com/browse/MCO-2371): Add back "should match os version" test [#31301](https://github.com/openshift/origin/pull/31301)
* [AGENT-1522](https://issues.redhat.com/browse/AGENT-1522): bump InternalReleaseImage to v1 [#31294](https://github.com/openshift/origin/pull/31294)
* NO-ISSUE: Fix longrunning suite for node test cases [#31339](https://github.com/openshift/origin/pull/31339)
* NO-ISSUE: Always emit precondition validation synthetic test entry [#31388](https://github.com/openshift/origin/pull/31388)
* [OCPBUGS-98956](https://issues.redhat.com/browse/OCPBUGS-98956): use admin-client namespace creation for IRI workload test [#31394](https://github.com/openshift/origin/pull/31394)
* [OCPNODE-4055](https://issues.redhat.com/browse/OCPNODE-4055): Add Additional Storage Support - API validation test cases [#31384](https://github.com/openshift/origin/pull/31384)
* NO-ISSUE: Remove Feature:NodeSwap tag and update README selectors [#31389](https://github.com/openshift/origin/pull/31389)
* [OCPNODE-4604](https://issues.redhat.com/browse/OCPNODE-4604): allow registry.redhat.io reboot requried test [#31383](https://github.com/openshift/origin/pull/31383)
* [OCPNODE-4604](https://issues.redhat.com/browse/OCPNODE-4604): upgrade to test v1 CRIOCredentialProviderConfig [#31324](https://github.com/openshift/origin/pull/31324)
* [TRT-2689](https://issues.redhat.com/browse/TRT-2689): Add devcontainer, APM config, and agentic CI scaffolding [#31371](https://github.com/openshift/origin/pull/31371)
* [OCPBUGS-97603](https://issues.redhat.com/browse/OCPBUGS-97603): Use framework-managed namespace for workload test [#31366](https://github.com/openshift/origin/pull/31366)
* [OCPBUGS-84512](https://issues.redhat.com/browse/OCPBUGS-84512): Remove exception terminationMessagePolicy=TerminationMessageFallbackToLogsOnError [#31327](https://github.com/openshift/origin/pull/31327)
* [OCPNODE-4494](https://issues.redhat.com/browse/OCPNODE-4494): Testcase to test runc Upgrade case [#31266](https://github.com/openshift/origin/pull/31266)
* [OCPBUGS-97822](https://issues.redhat.com/browse/OCPBUGS-97822): Wait for DNS before running http2 tests [#31368](https://github.com/openshift/origin/pull/31368)
* [CNTRLPLANE-2157](https://issues.redhat.com/browse/CNTRLPLANE-2157): Migrate test cases to Project API testing KubeAPI server functionality [#31310](https://github.com/openshift/origin/pull/31310)
* [OCPNODE-4554](https://issues.redhat.com/browse/OCPNODE-4554): Automate OCP-70203: ICSP and IDMS/ITMS can coexist in cluster [#31229](https://github.com/openshift/origin/pull/31229)
* NO-JIRA: e2e: extracting fencing credentials rotation into standalone test [#31340](https://github.com/openshift/origin/pull/31340)
* NO-JIRA: Fix Flaky e2e tests - Update the Cleanup order [#31347](https://github.com/openshift/origin/pull/31347)
* [OCPNODE-4604](https://issues.redhat.com/browse/OCPNODE-4604): add quay-proxy.ci.openshift.org as alllowed to reboot requried test [#31356](https://github.com/openshift/origin/pull/31356)
* [OCPBUGS-84521](https://issues.redhat.com/browse/OCPBUGS-84521): remove openshift/cluster-machine-approver `terminationMessagePolicy` exemption [#31362](https://github.com/openshift/origin/pull/31362)
* [OCPBUGS-88742](https://issues.redhat.com/browse/OCPBUGS-88742): Fix nested container test mount check for BusyBox [#31361](https://github.com/openshift/origin/pull/31361)
* NO-ISSUE: Remove exception for OCPBUGS-45921 [#31346](https://github.com/openshift/origin/pull/31346)
* [OCPCLOUD-3010](https://issues.redhat.com/browse/OCPCLOUD-3010): Enable OTE for Cluster CAPI Operator [#31307](https://github.com/openshift/origin/pull/31307)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/origin/compare/6df9cfeba6d5782ad77b3f7bd4bd72f1fdddde07...a7b3bba9780389699e8426c6d3f1afee8464a5ad)
### [thanos](https://github.com/openshift/thanos/tree/7923992496585d7471b26abbd15bfa7aaa745755)
* [OCPBUGS-97627](https://issues.redhat.com/browse/OCPBUGS-97627): [bot] Bump openshift/thanos to v0.42.2 [#194](https://github.com/openshift/thanos/pull/194)
* NO-JIRA: chore: revert narrow selectors detection for le/quantile labels [#193](https://github.com/openshift/thanos/pull/193)
* [Full changelog](https://github.com/openshift/thanos/compare/779d690da4fafe809a689f02e889e6fd9ffd4405...7923992496585d7471b26abbd15bfa7aaa745755)
### [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere/tree/557fdf1a9a3540d9aa8f3a81e4a950673a416a80)
* 🚀 OCPCLOUD-3604: Merge https://github.com/kubernetes-sigs/cluster-api-provider-vsphere:v1.16.1 (5b57d1d) into main [#112](https://github.com/openshift/cluster-api-provider-vsphere/pull/112)
* 🐛 OCPBUGS-85337: set imagePullPolicy IfNotPresent on provider workloads [#114](https://github.com/openshift/cluster-api-provider-vsphere/pull/114)
* [Full changelog](https://github.com/openshift/cluster-api-provider-vsphere/compare/cd9a63d6ef3eedebc687ec6b675db1a1ad947ebb...557fdf1a9a3540d9aa8f3a81e4a950673a416a80)
### [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator/tree/9bf3f85fde177dc4b65ea92d08b472f6573633f8)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#350](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/350)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver-operator/compare/030ff0e326205bcacaddb901d6b3cb6ab4db63dd...9bf3f85fde177dc4b65ea92d08b472f6573633f8)
### [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector/tree/b2f09a5b559ddb0a114892889f88dcff1037b2c3)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#226](https://github.com/openshift/vsphere-problem-detector/pull/226)
* [Full changelog](https://github.com/openshift/vsphere-problem-detector/compare/34586ec43cc2a94c098ac27cf0f2b89f1460b323...b2f09a5b559ddb0a114892889f88dcff1037b2c3)