# 5.1.0-ec.0
Created: 2026-09-07 12:35:19 +0000 UTC
Image Digest: `sha256:fb3f97aff01775af56a97e7df31ad384ec53c16dfd3e31a25f26e5e2ee07d1b3`
Promoted from quay.io/openshift-release-dev/ocp-release-nightly@sha256:202d18caabc8e7bf76f8ab82429757c40d0ab02a2dfc04c901fd32cb12c0aff5
## Changes from 5.0.0-ec.6
### Components
* Kubectl 1.36.2
* Kubernetes upgraded from 1.36.2 to 1.36.3
* Kubernetes Tests 1.36.2
* Red Hat Enterprise Linux CoreOS 10.2 upgraded from 10.2.20260808-0 to 10.2.20260831-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| AWSServiceLBNetworkSecurityGroup
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| SigstoreImageVerification
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| SigstoreImageVerificationPKI
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| VSphereMultiDisk
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| VSphereMultiNetworks
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| GCPSovereignCloudInstall
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled
(Changed)| Enabled
(Changed) |
| AdditionalStorageConfig
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| EtcdBackendQuota
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| ExternalOIDCWithUpstreamParity
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| SELinuxMountGAReadiness
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| VSphereMultiVCenterDay2
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| VolumeGroupSnapshot
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| OSStreams
(0 tests)| Enabled
(Changed)| Enabled| Enabled| Enabled| Enabled
(Changed)| Enabled| Enabled| Enabled |
| GomaxprocsInjection
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| IngressControllerLBSecurityGroupsAWS
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
### New images
* [kube-vip](https://github.com/openshift/kube-vip) git [3aaf76bd](https://github.com/openshift/kube-vip/commit/3aaf76bd7be6d066b87f85eb30ba77edc0a57dcd) `sha256:d51eb9f3429e7be2680a57323aeec855b33cb3659b3cd4c2739994f2a36e36cc`
### Removed images
* oc-mirror
### Rebuilt images without code change
* [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws) git [278e8c07](https://github.com/openshift/cloud-provider-aws/commit/278e8c07a72a50e7d3f28fc743c38c64f008f5aa) `sha256:a507e7ffdc626ceaf7761f90c6cfcc074c65c4b7ad08a2883fb041dce1c9c3a7`
* [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [8b8c4cef](https://github.com/openshift/aws-ebs-csi-driver/commit/8b8c4cef02ec9b670e2709f2aacc0ed72420be90) `sha256:da7f8a9b483175d8c16c15627117d8b8886d93853e6595f41ebe07e8cd479255`
* [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws) git [dc822233](https://github.com/openshift/aws-karpenter-provider-aws/commit/dc822233cc526b6cc55f20009a4c1b034f245133) `sha256:8268bd623d21ed880a53a777e8325ce565c56f6f8a87d75964546b47f2473890`
* [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider) git [9b18930d](https://github.com/openshift/aws-encryption-provider/commit/9b18930d2db9521a08faa7165488bdcf6482b9cf) `sha256:7e160a09ff482abe2a7cef36969bdcaf0573a172aa721d7045861d9a727cd58f`
* [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws) git [9f2e9b3c](https://github.com/openshift/machine-api-provider-aws/commit/9f2e9b3c46b391c7219257a426ad80ca8a296af0) `sha256:9e0b6265ecee164e4e1f215980b2f4c264f83350f23de67e105cddb3427df0d1`
* [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler) git [e4ff2aae](https://github.com/openshift/aws-node-termination-handler/commit/e4ff2aaec292db42de9f3eef4908ba1c421a2a6c) `sha256:5a03ec6f5740f00cd9fc229d0fff4596a653fc08188dc5fb5ab0fba56740943a`
* [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [0d33a459](https://github.com/openshift/aws-pod-identity-webhook/commit/0d33a4596e2a22d188fe74c4a6497c37c2528c1f) `sha256:2ddfea92795309e5d0a811e63aa7f0ff8141ea2fb55cc7983db3906dd23690e5`
* [azure-cloud-controller-manager](https://github.com/openshift/cloud-provider-azure) git [b99e4ce4](https://github.com/openshift/cloud-provider-azure/commit/b99e4ce4ff5c2665b273384b0673824833c40ce5) `sha256:93b9979510a12ae05ae50e5c5bcc18cbd8612f119e617ac86e459d2e51969785`
* [azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure) git [b99e4ce4](https://github.com/openshift/cloud-provider-azure/commit/b99e4ce4ff5c2665b273384b0673824833c40ce5) `sha256:02f0c285d67b1d551f55877674d23c44f55140cbd71e7f946817babf6cd849f9`
* [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure) git [63731729](https://github.com/openshift/cluster-api-provider-azure/commit/63731729974bff3be90ae2206c53d760572499d1) `sha256:908a5d1591f83b039c40828764f93bd8a278a875d440e42b9b6f057502d13c6e`
* [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver) git [9689f030](https://github.com/openshift/azure-file-csi-driver/commit/9689f03011ce700b3bffc32791af839e80d0e0ab) `sha256:fba648532076e22c357d5656b06174d817922417519118180f16186d5c26241a`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:845d0cc9dad69e0f7f44b7dead9b6a5c504dfd0c79123e695d9061ffa620ded4`
* [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity) git [2b4705c5](https://github.com/openshift/azure-workload-identity/commit/2b4705c5d999339ce17d47a9b2a637d238891dae) `sha256:08095d8709201e3ca1160752e5405006c571fedc411c69fd06ae5eda9c4c9889`
* [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3) git [ad4f1c2b](https://github.com/openshift/cluster-api-provider-metal3/commit/ad4f1c2bd7b527437496b71b5b93ee1439243d65) `sha256:ef5682bfde44742e15e604b8bbb61565db4a16f5db951a5e0a441db6cb837ad9`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [f2b0db19](https://github.com/openshift/cluster-api-provider-baremetal/commit/f2b0db1919fff1344bc68948894c6775c0bf24a3) `sha256:de846c32e413a65310952c7587ea444ef383fb11dede3f916777a026b23865e6`
* [baremetal-operator](https://github.com/openshift/baremetal-operator) git [34bbeb37](https://github.com/openshift/baremetal-operator/commit/34bbeb376836bf01793d4e70d29065d619ebcaa1) `sha256:3ffe07fb0bf6407d2889f99ae88bfeb1aa90fe17c56e53bc2bbd9b7558dec425`
* [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler) git [f393f542](https://github.com/openshift/kubernetes-autoscaler/commit/f393f54229e6c3ae74c35ae72012af92d31c03d3) `sha256:f9457da4b34b6e4dec9336f30050d4128f2d38e40a35b4168d6eeabb17c104ae`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [7b1593a4](https://github.com/openshift/cluster-bootstrap/commit/7b1593a47898b6a97dc457efaca464624e9f2afa) `sha256:84b55b589de3081d762b2dc33ef08acaaf6ad9d603b93d753e76eff6335bf629`
* [cluster-config-operator](https://github.com/openshift/cluster-config-operator) git [9f787f73](https://github.com/openshift/cluster-config-operator/commit/9f787f73f5fffca5cd511ef2c2e704afc14f68ce) `sha256:62454ced9aa173dfc9c328a37414cf08a6713fa012a74a3762357aec4174b1bc`
* [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator) git [35ec0224](https://github.com/openshift/cluster-csi-snapshot-controller-operator/commit/35ec0224eb0e5219d5eae012fb703223a6f3e1f7) `sha256:4cd0b21c4c7c2cb5976805be501a6ec233218888396ea0d1c18ea6cc27ccc252`
* [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator) git [c0ed09e3](https://github.com/openshift/cluster-dns-operator/commit/c0ed09e329e9001629518604a58205e3fbe8284a) `sha256:b70878efd2e8a13f1479e5d650158c86e6cee8ad0881fe6f248b758ff9fca43d`
* [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator) git [f5d3bfe6](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/commit/f5d3bfe64bda67ffb8299af01ebf2722287edf04) `sha256:a4afa7841f2817e067345eeb8b3c9439aebc0d65b6e6813575e9669fdf6cc8b0`
* [cluster-update-console-plugin](https://github.com/openshift/cluster-update-console-plugin) git [02b220dd](https://github.com/openshift/cluster-update-console-plugin/commit/02b220dd2aef5c1788768178e3ffd8592ccb89b9) `sha256:8f2120e2d10579d47dd49ecd802d456bc0b6bc0bcca36fd34cb7aa0e8b5b59b5`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:c5bab156db178c30afe679b35092e692114a0d7b5d5d46faec3aea13b61e6283`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [ce80869a](https://github.com/openshift/configmap-reload/commit/ce80869a83b55ebbdc21a5550ec5747645203bd2) `sha256:55775dcaf8b48006f6b77c0e311d93b481b61c0b151043a8c645c85fdf2cae9e`
* [coredns](https://github.com/openshift/coredns) git [37aaba89](https://github.com/openshift/coredns/commit/37aaba896e97f4b9a091aab6d36f2213b8854474) `sha256:9485337e870eefa343f9b3353f223edc2e9e8efa77d56a8727bdc8f9f47ab0d5`
* [csi-driver-manila](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:28188937988f8134c9a4ceb13d1cd17511eabfff2ef0a16b0557d582a852d604`
* [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs) git [beb9567b](https://github.com/openshift/csi-driver-nfs/commit/beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa) `sha256:49b5b39c9570fac1adc23aad5299f2084d4aa3e76fb4312f8e117fe1e3c45e7b`
* [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [3fd668b3](https://github.com/openshift/csi-external-attacher/commit/3fd668b3f07dd382e5c7b6239d50f7988f652e64) `sha256:6b7e63eb6d9f7c84ccb8595924829fc35aa777553623c8954ae3936079e19989`
* [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [7ff338c9](https://github.com/openshift/csi-external-provisioner/commit/7ff338c9d1296f0e5d4d8080a76bb191c8f3be30) `sha256:96a4d8317f7ebf535d55dced74c9d56a0b1ac1160927c3d086058e2b4ec1146e`
* [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [14aa7028](https://github.com/openshift/csi-external-resizer/commit/14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf) `sha256:2f77acfe23b64a5d6a5b0df691ec8180f6d3f96f22567e8045a9864ee5af9042`
* [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata) git [239703c6](https://github.com/openshift/csi-external-snapshot-metadata/commit/239703c637e005cf785892d214d219add70e3533) `sha256:b13187550e05169f7c0c29c376ff560cc6bdbe93f6b9574ce6f5787c619c4c4c`
* [csi-external-snapshotter](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:c77589454bfcfb127a29ceb658a47892ab25e944dc11f203e5feef358157e210`
* [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe) git [463dc553](https://github.com/openshift/csi-livenessprobe/commit/463dc553ebb04df192d573c5a1612dcb50cb1f52) `sha256:4e449ed926621daf6c69d37e5df3b25e3672281abd33836d2fdaa5472eb399ef`
* [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [5766960d](https://github.com/openshift/csi-node-driver-registrar/commit/5766960d82ffb9ef84d15e903ae57d0a6781ef11) `sha256:2c33dcadfdc877b1d863778f5410ed495422fa0a1a4be2eb7df2f50cbd8ef6fa`
* [csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:07e79ad68d00520e0913082bf1a849117d4c5662da52175390327da2770802c8`
* [docker-builder](https://github.com/openshift/builder) git [2cda03a9](https://github.com/openshift/builder/commit/2cda03a93696d4620703848471b3b873b0b2fa1e) `sha256:de32a57dca3d23331e259803c14eaaaa21e0b4237e34cccc657feb0df03c492e`
* [driver-toolkit](https://github.com/openshift/driver-toolkit) git [b63b175a](https://github.com/openshift/driver-toolkit/commit/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a) `sha256:16264407dd8c87bb3e086e4ac5665d0cc99a7288c3ec316b436440206e2d826b`
* [driver-toolkit-10](https://github.com/openshift/driver-toolkit) git [b63b175a](https://github.com/openshift/driver-toolkit/commit/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a) `sha256:ade4607ecaadd8a4acfd0a92f6874c7783a31a63ec86a53dad72cc69de38fda2`
* [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp) git [51c32646](https://github.com/openshift/cloud-provider-gcp/commit/51c326465b3160124b8097953b42e44f1056da5a) `sha256:5db20e07cdbe64816828260d07298df8c1c02d36db9669303182dc096adaba78`
* [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook) git [4501ff2f](https://github.com/openshift/gcp-workload-identity-federation-webhook/commit/4501ff2f53576c31df0511b69444e65e1eeba745) `sha256:210ff56503b41036f7665c3706e4b9848723afdbd20220152306de60997704a3`
* [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm) git [11bc35dd](https://github.com/openshift/cloud-provider-ibm/commit/11bc35dd6fd5163259023a6f1dfcc59ce813ab5f) `sha256:c7fab348a6e077f41876180a97aba20874f2c32fcd26fc168001e1ae20718129`
* [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver) git [3a89d7d1](https://github.com/openshift/ibm-vpc-block-csi-driver/commit/3a89d7d17d25727270414b07d3daaa3bc329d743) `sha256:5ce24e0e2259511d3607f6f6cdf6c289560d9bebcb9a2b5dc7cb0d732882d595`
* [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator) git [be4fd017](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/commit/be4fd01725ce5ab0b47f846c905a349aeee8ab53) `sha256:b1185cdb152302d51438be6eea32c911d85174927d2d71aeafbac348b6f77600`
* [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud) git [286dd2de](https://github.com/openshift/cluster-api-provider-ibmcloud/commit/286dd2de7957e9c2897e152417f16907d324d819) `sha256:3a7f6f80caf1b83044cea4a16f4e8876c26b67d1eed5970d014dfeb3ad7fd1b2`
* [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud) git [2615d13b](https://github.com/openshift/machine-api-provider-ibmcloud/commit/2615d13b730255b21ccb401d3dc039006c54a4fe) `sha256:5d8119fd04b1802620a879998841402beea998e7d43d5251527e8312f3db0114`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [f8e41b2e](https://github.com/openshift/ironic-rhcos-downloader/commit/f8e41b2ed8915474a99e3eb34b54692afb0611da) `sha256:1e4e7c4a93c8afe52d53855afa726c7f5f0627e6c041053d0784fbc0c7ff4aa2`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [486a0418](https://github.com/openshift/ironic-static-ip-manager/commit/486a041897d703d55ef59c98e2b20a01588a0b4c) `sha256:cb6b34de9350146256f9d10a59d7a44268effb5ff1f6547e80837ba3f71ba845`
* [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server) git [3d2e9cd0](https://github.com/openshift/kubernetes-metrics-server/commit/3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71) `sha256:2eea5279fe3c23b942e7910b36d6c4739ab2126178beacb18f56a4e30191b81b`
* [kube-state-metrics](https://github.com/openshift/kube-state-metrics) git [019ecc7d](https://github.com/openshift/kube-state-metrics/commit/019ecc7d533333dfd3bf8893e78cd7ec6e282f01) `sha256:876d70ce89074445257878ae069e140496bec9044c1d0dfc51afb6898bfd73cb`
* [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [72835e43](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/72835e43c7754356645e41031f3a99926b4d42e6) `sha256:7727f83744b874ca7a91fd127df438476e90c9e53afa3d2d9c51569c1849b3a4`
* [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt) git [5eb884ab](https://github.com/openshift/cloud-provider-kubevirt/commit/5eb884abcd2ff17ae8d7b2691ca12494597c08a6) `sha256:43e4ae979d35fc8c9cf6147ff81c58243573038689064c95e4e747014d754677`
* [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver) git [7ff99994](https://github.com/openshift/kubevirt-csi-driver/commit/7ff99994ecc3a675fac6f9aa7fa418cdb0dca32b) `sha256:d31fac7206f5924c5abc94f894dfbe3950345d73cf25a17ddde7f0d6e4a9400f`
* [metallb-frr](https://github.com/openshift/frr) git [54a6ea48](https://github.com/openshift/frr/commit/54a6ea48902d81460536b81ea6bdceb89c12e622) `sha256:e090ca20991651bfa09ffaab78e59a274d4e8f961b2f48c5794162428150ac44`
* [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni) git [d918bda2](https://github.com/openshift/whereabouts-cni/commit/d918bda28ad3d0200b6e4f2ef2801556764762e5) `sha256:f48bc355f5071dd50cc5abc391e2d680674cd68a34f8bd12a179099232e54321`
* [network-tools](https://github.com/openshift/network-tools) git [0b53ac3d](https://github.com/openshift/network-tools/commit/0b53ac3dccf59cd169555bf18c207122374bf003) `sha256:42ce1809152c37de350b052f5ad5e76a6e6ebfccfcbaebc26fce7b23a4352120`
* [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [dc584c6b](https://github.com/openshift/cloud-provider-nutanix/commit/dc584c6b2e895a6217f9e2dbed765209af1898a1) `sha256:27191923b628033ca2e503033a5eb602a528a699b66d001cb08e6fa0669c292f`
* [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix) git [249b7c8e](https://github.com/openshift/machine-api-provider-nutanix/commit/249b7c8edfca8f25413dc76bc5a216fbe12a9ab1) `sha256:fc5bd14db5abf256729993b473f6d1a2432f287b51d714bc18f2e2517444072c`
* [openstack-cinder-csi-driver](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:f915cc991b5fc0e6bc2e3032ea3945c2a436bb8fe213747e2299922d6ae64469`
* [openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:3a1d497689004e17e1a706a462b3b364a24c2f79d38a122feb470563bb54aeff`
* [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:51aafc1aeac58d0ef4297292429dff8ab2451c0d9a87ca6ebcdc880485b6f314`
* [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller) git [58dbc048](https://github.com/openshift/openstack-resource-controller/commit/58dbc0482c144c21effee2476947889122a518eb) `sha256:a4dce6665e31fcfc745a7c983b5df640cd12e944bcce9f895b786842e1ce5fde`
* [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator) git [f90431bf](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/commit/f90431bfe8ca93850450b2b24fae152d2385ca08) `sha256:c043fe479c954b1677a6eee20a233e21125084596a50659167a8cc08c8b54c5c`
* [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs) git [18eb5238](https://github.com/openshift/cloud-provider-powervs/commit/18eb5238fb2c86632edb24175f536d815f28ddf6) `sha256:def192bd578b4088799a1e22d4d4dcd80e7d5b40643e7537c7bb033b6f8dbab1`
* [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs) git [e88cf81d](https://github.com/openshift/machine-api-provider-powervs/commit/e88cf81dd9ad174f395b86f9cdc40fa30cb06bf4) `sha256:370124b6fbf644aea0e498c33544887211ccc8d99dcbfb3802feeae29ca99381`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [4ab9ff73](https://github.com/openshift/prom-label-proxy/commit/4ab9ff73c665319352288fe0b9b9e1df71832525) `sha256:352181d2f3fae35cce4c91491b84cba06c1f260ab51f9e7d1865b70fe5db387b`
* [prometheus](https://github.com/openshift/prometheus) git [01d83356](https://github.com/openshift/prometheus/commit/01d8335673aa6f88f5742ef510e133efee88a7bf) `sha256:59867269024a16dae8e29ba173cd1637de50340e0a125011383377600f231e9d`
* [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager) git [89bdff8b](https://github.com/openshift/prometheus-alertmanager/commit/89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce) `sha256:9e5e9cc8785eac5992ffe61b40fe245b81b46b7532978fa67247b25bde9b98d4`
* [route-controller-manager](https://github.com/openshift/route-controller-manager) git [59697cf7](https://github.com/openshift/route-controller-manager/commit/59697cf7af4517dd44e28179a57f7f35b6ea0e22) `sha256:c82b1d4c2b0348d0fc7e99d3f6e57c959a300c7aecc4537734778d3c41e60017`
* [service-ca-operator](https://github.com/openshift/service-ca-operator) git [ed872ba1](https://github.com/openshift/service-ca-operator/commit/ed872ba14b615ca5726ae90e987268877a0b0b20) `sha256:ea0606f151ef642c2192a6ac56fc590c65cb7c6a94d90649468edd1be030a13a`
* [thanos](https://github.com/openshift/thanos) git [75fa632b](https://github.com/openshift/thanos/commit/75fa632b483716e53aec19f6adf7d4c4652a4453) `sha256:e49868d2ab1440b25b9440467111ace819a9a5de54b5b5227076c5ffcd80102d`
* [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator) git [ee9cd7ab](https://github.com/openshift/volume-data-source-validator/commit/ee9cd7aba4e096a9a957386ef20777e8950df352) `sha256:1bb452adc60679d2e8a337a76b18b0a571cfcb70872dde812d097318c180f1b1`
* [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere) git [eb29de19](https://github.com/openshift/cloud-provider-vsphere/commit/eb29de194594bad8e5bc572102f1008cb26655a7) `sha256:0b065f31ea999a5d0035140efe751c52a09b0c94643c8cfc723fb3faf2c88c26`
* [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere) git [557fdf1a](https://github.com/openshift/cluster-api-provider-vsphere/commit/557fdf1a9a3540d9aa8f3a81e4a950673a416a80) `sha256:c0065cfa36ef801a23fc508b65424b69b0fbf3616897ccdd540f87d527955e96`
* [vsphere-csi-driver](https://github.com/openshift/vmware-vsphere-csi-driver) git [6b18bb29](https://github.com/openshift/vmware-vsphere-csi-driver/commit/6b18bb29fc45383c21aa6c7513d151e443aa305e) `sha256:0c44978fc169a83b1619e76514de16f35606fc63635226737b7416d24588f755`
* [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator) git [aa279467](https://github.com/openshift/vmware-vsphere-csi-driver-operator/commit/aa27946700642a9c8e518e130673097b38a2f8bb) `sha256:c64e5200bdfa8caa97c60c770acc1b3846a58b2479c289a019552d3b0d016d2b`
* [vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver) git [6b18bb29](https://github.com/openshift/vmware-vsphere-csi-driver/commit/6b18bb29fc45383c21aa6c7513d151e443aa305e) `sha256:ea27b86db373a20889994e5e5f9960a10c18c4a5de6674f0d0a2d57743c1b732`
* [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector) git [14a2d338](https://github.com/openshift/vsphere-problem-detector/commit/14a2d33817c1ddd1d753cc76decea059376e30c9) `sha256:6b738dba61a190ef0038b9d0e65d37fe23b06cbfdfbc6340c3013cde818296d6`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/d13116d7889481aa2d3c2f46f2449611f5a90356)
* [MGMT-25139](https://issues.redhat.com/browse/MGMT-25139): Allow setting os-stream on both clusters and infraenvs [#10742](https://github.com/openshift/assisted-service/pull/10742)
* [MGMT-20398](https://issues.redhat.com/browse/MGMT-20398): Force status on bmh after install [#10606](https://github.com/openshift/assisted-service/pull/10606)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10884](https://github.com/openshift/assisted-service/pull/10884)
* [MGMT-24877](https://issues.redhat.com/browse/MGMT-24877): Improve sensitive credential redaction [#10857](https://github.com/openshift/assisted-service/pull/10857)
* [OCPBUGS-29975](https://issues.redhat.com/browse/OCPBUGS-29975): Allow multiple machine networks for UMN clusters [#10817](https://github.com/openshift/assisted-service/pull/10817)
* [MGMT-21334](https://issues.redhat.com/browse/MGMT-21334): Don't check ImageSetRef for installed clusters [#10854](https://github.com/openshift/assisted-service/pull/10854)
* NO-ISSUE: Add missing Close() [#10856](https://github.com/openshift/assisted-service/pull/10856)
* [MGMT-24693](https://issues.redhat.com/browse/MGMT-24693): fix e2e-ai-operator-disconnected-capi [#10806](https://github.com/openshift/assisted-service/pull/10806)
* [ACM-42573](https://issues.redhat.com/browse/ACM-42573): Assisted services' networkpolicy doesn't work for external image service and local image registry in disconnected environment [#10850](https://github.com/openshift/assisted-service/pull/10850)
* [MGMT-25066](https://issues.redhat.com/browse/MGMT-25066): Add continuous node label reconciliation in InfraEnv controller [#10813](https://github.com/openshift/assisted-service/pull/10813)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10829](https://github.com/openshift/assisted-service/pull/10829)
* [MGMT-25065](https://issues.redhat.com/browse/MGMT-25065): Add InfraEnv to Agent node label propagation [#10812](https://github.com/openshift/assisted-service/pull/10812)
* NO-ISSUE: Add same-namespace egress for image-service to assisted-service [#10816](https://github.com/openshift/assisted-service/pull/10816)
* NO-ISSUE: [master] Bump OCP versions: 4.21, 4.17, 4.22, 4.19, 4.18, 4.14, 4.16, 4.20 [#10804](https://github.com/openshift/assisted-service/pull/10804)
* [ACM-40452](https://issues.redhat.com/browse/ACM-40452): CVE-2026-33815 Bump github.com/jackc/pgx/v5 to v5.9.0 [#10783](https://github.com/openshift/assisted-service/pull/10783)
* [ACM-40510](https://issues.redhat.com/browse/ACM-40510): Fix infrastructure-operator NetworkPolicy egress to kubernetes API [#10792](https://github.com/openshift/assisted-service/pull/10792)
* NO-ISSUE: Update oc-mirror locations to CGW following openshift release decoupling [#10601](https://github.com/openshift/assisted-service/pull/10601)
* [ACM-40436](https://issues.redhat.com/browse/ACM-40436): Bump Go toolchain to go1.26.5 to fix stdlib CVEs [#10770](https://github.com/openshift/assisted-service/pull/10770)
* [Full changelog](https://github.com/openshift/assisted-service/compare/90c28e0308dcbc321654cdbcb4cb958550037240...d13116d7889481aa2d3c2f46f2449611f5a90356)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/87d1f289e17ea079cb8baf3ec897f9101ec65b00)
* NO-ISSUE: Add approver bluesort [#2286](https://github.com/openshift/assisted-installer/pull/2286)
* NO-ISSUE: Modify Konflux YAMLs to ocm-5.1 [#2281](https://github.com/openshift/assisted-installer/pull/2281)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.2 [#2285](https://github.com/openshift/assisted-installer/pull/2285)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.1 [#2273](https://github.com/openshift/assisted-installer/pull/2273)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.0 [#2271](https://github.com/openshift/assisted-installer/pull/2271)
* [OCPBUGS-101647](https://issues.redhat.com/browse/OCPBUGS-101647): Bump golang.org/x/net to v0.56.0 [#2251](https://github.com/openshift/assisted-installer/pull/2251)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/02d30997f8496c348ea45c4f950f360574178e45...87d1f289e17ea079cb8baf3ec897f9101ec65b00)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/a909d424d5bc542e7591b6a05cc817e46cf14ee9)
* [MGMT-20398](https://issues.redhat.com/browse/MGMT-20398): Don't start main agent until ironic reports it's ready [#1518](https://github.com/openshift/assisted-installer-agent/pull/1518)
* NO-ISSUE: Modify Konflux YAMLs to ocm-5.1 [#1602](https://github.com/openshift/assisted-installer-agent/pull/1602)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.1 [#1600](https://github.com/openshift/assisted-installer-agent/pull/1600)
* NO-ISSUE: Update module github.com/golangci/golangci-lint to v2.13.0 [#1597](https://github.com/openshift/assisted-installer-agent/pull/1597)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/aeec165131a4c528174a58a011d1c3c31cfd7cc1...a909d424d5bc542e7591b6a05cc817e46cf14ee9)
### [agent-installer-ui](https://github.com/openshift-assisted/assisted-installer-ui/tree/334b4c7dddb57092420af626e92e6a750d6c2afb)
* Add LVM as an operator for OVE (#4001) [#4001](https://github.com/openshift-assisted/assisted-installer-ui/pull/4001)
* Allow LSO to be selected as a standalone operator (#4000) [#4000](https://github.com/openshift-assisted/assisted-installer-ui/pull/4000)
* chore(deps): update dependency yup to ^1.7.1 (#3999) [#3999](https://github.com/openshift-assisted/assisted-installer-ui/pull/3999)
* chore(deps): update dependency js-cookie to ^3.0.8 (#3998) [#3998](https://github.com/openshift-assisted/assisted-installer-ui/pull/3998)
* Update OWNERS file (#3989) [#3989](https://github.com/openshift-assisted/assisted-installer-ui/pull/3989)
* NO-ISSUE: Add Yarn resolutions for js-cookie and basic-ftp (#3985) [#3985](https://github.com/openshift-assisted/assisted-installer-ui/pull/3985)
* Tweak boot instructions for disconnected (#3968) [#3968](https://github.com/openshift-assisted/assisted-installer-ui/pull/3968)
* [MGMT-24639](https://issues.redhat.com/browse/MGMT-24639): Choosing 5 masters on hosts page instead of 3 that was configured on cluster details causing the Hosts page stuck with no error/warning (#3942) [#3942](https://github.com/openshift-assisted/assisted-installer-ui/pull/3942)
* Hardcode OVE openshift version from 4.21 to 4.21.27 (#3976) [#3976](https://github.com/openshift-assisted/assisted-installer-ui/pull/3976)
* Resolve console warnings/errors (#3967) [#3967](https://github.com/openshift-assisted/assisted-installer-ui/pull/3967)
* Add rule for creating/editing forms (#3962) [#3962](https://github.com/openshift-assisted/assisted-installer-ui/pull/3962)
* chore(deps): update dependency ws to ^8.21.3 (#3974) [#3974](https://github.com/openshift-assisted/assisted-installer-ui/pull/3974)
* chore(deps): update dependency dompurify to ^3.4.14 (#3973) [#3973](https://github.com/openshift-assisted/assisted-installer-ui/pull/3973)
* Resolve duplicate 'useFeature' issue (#3969) [#3969](https://github.com/openshift-assisted/assisted-installer-ui/pull/3969)
* [MGMT-24493](https://issues.redhat.com/browse/MGMT-24493): Allow HTTPS proxy for Discovery ISO (#3777) [#3777](https://github.com/openshift-assisted/assisted-installer-ui/pull/3777)
* [MGMT-24494](https://issues.redhat.com/browse/MGMT-24494): Add exclusive NTP sources to the Add hosts discovery ISO … (#3934) [#3934](https://github.com/openshift-assisted/assisted-installer-ui/pull/3934)
* MGMT-24202 | [Staging] [UI] - Air-gapped -Technology Preview badge placement is inconsistent (should appear at end of line) (#3965) [#3965](https://github.com/openshift-assisted/assisted-installer-ui/pull/3965)
* Fix BasicStep Form import (#3966) [#3966](https://github.com/openshift-assisted/assisted-installer-ui/pull/3966)
* NO-ISSUE: Improve the /ocm folder structure (#3817) [#3817](https://github.com/openshift-assisted/assisted-installer-ui/pull/3817)
* chore(deps): update dependency postcss to ^8.5.26 (#3963) [#3963](https://github.com/openshift-assisted/assisted-installer-ui/pull/3963)
* chore(deps): update dependency sanitize-html to ^2.17.7 (#3964) [#3964](https://github.com/openshift-assisted/assisted-installer-ui/pull/3964)
* [OCPBUGS-104439](https://issues.redhat.com/browse/OCPBUGS-104439): pin postcss resolution to >=8.5.23 (CVE-2026-69153) (#3957) [#3957](https://github.com/openshift-assisted/assisted-installer-ui/pull/3957)
* [AGENT-1570](https://issues.redhat.com/browse/AGENT-1570): Remove CustomNoUpgrade featureSet and NoRegistryClusterInstall feature gate (#3954) [#3954](https://github.com/openshift-assisted/assisted-installer-ui/pull/3954)
* Bump js-yaml from 3.14.1 to 4.3.1 (#3951) [#3951](https://github.com/openshift-assisted/assisted-installer-ui/pull/3951)
* Bump js-yaml from 4.3.0 to 4.3.1 (#3947) [#3947](https://github.com/openshift-assisted/assisted-installer-ui/pull/3947)
* chore(deps): update dependency ws to ^8.21.2 (#3950) [#3950](https://github.com/openshift-assisted/assisted-installer-ui/pull/3950)
* chore(deps): update dependency dompurify to ^3.4.13 (#3949) [#3949](https://github.com/openshift-assisted/assisted-installer-ui/pull/3949)
* chore(deps): update konflux references (#3946) [#3946](https://github.com/openshift-assisted/assisted-installer-ui/pull/3946)
* [Full changelog](https://github.com/openshift-assisted/assisted-installer-ui/compare/f3eac984fdaf36f3705bb88e90975d34031b3639...334b4c7dddb57092420af626e92e6a750d6c2afb)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/49322a1138a1a5cbcf7cbe58d78852b22a055fdd)
* [AGENT-1577](https://issues.redhat.com/browse/AGENT-1577): Use master branch of appliance as image builder [#333](https://github.com/openshift/agent-installer-utils/pull/333)
* [OCPBUGS-114020](https://issues.redhat.com/browse/OCPBUGS-114020): Use branch 5.1 for Konflux builds [#344](https://github.com/openshift/agent-installer-utils/pull/344)
* [AGENT-1573](https://issues.redhat.com/browse/AGENT-1573): Add release-5.1 config for ISOBuilder [#327](https://github.com/openshift/agent-installer-utils/pull/327)
* [OCPBUGS-105450](https://issues.redhat.com/browse/OCPBUGS-105450): Update Konflux references [#334](https://github.com/openshift/agent-installer-utils/pull/334)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/c031572a47209d362aec8f775cdbef7d0ae4a172...49322a1138a1a5cbcf7cbe58d78852b22a055fdd)
### [agentic-skills](https://github.com/openshift/agentic-skills/tree/7aca4bee317cd70a4204795db6b1d7b9eb78f48c)
* NO-JIRA: resolve skill-scanner findings for CI eval job [#49](https://github.com/openshift/agentic-skills/pull/49)
* NO-ISSUE: fix: add compatibility attribute to the product-lifecycle skill [#50](https://github.com/openshift/agentic-skills/pull/50)
* [OBSINTA-1609](https://issues.redhat.com/browse/OBSINTA-1609): cluster-troubleshoot skill rename tools to scripts [#46](https://github.com/openshift/agentic-skills/pull/46)
* [OTA-2024](https://issues.redhat.com/browse/OTA-2024), [OTA-2070](https://issues.redhat.com/browse/OTA-2070): Add eval test cases for cluster-update skills [#34](https://github.com/openshift/agentic-skills/pull/34)
* NO-ISSUE: cluster-update: Set 'license' header on both skills [#48](https://github.com/openshift/agentic-skills/pull/48)
* NO-ISSUE: cluster-update/cluster-update-advisor: Rename to match skill name [#47](https://github.com/openshift/agentic-skills/pull/47)
* [Full changelog](https://github.com/openshift/agentic-skills/compare/39429747952afd5e3c56fd86299f8a7614d27a79...7aca4bee317cd70a4204795db6b1d7b9eb78f48c)
### [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy/tree/d6ec9243d24050d7d7ad7f939e45f821171f000e)
* NO-JIRA: Merge https://github.com/kubernetes-sigs/apiserver-network-proxy:master (cc6bc61) into main [#114](https://github.com/openshift/apiserver-network-proxy/pull/114)
* [Full changelog](https://github.com/openshift/apiserver-network-proxy/compare/8264c02deda9abb6cd9a6a5c23305428431473c2...d6ec9243d24050d7d7ad7f939e45f821171f000e)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/e345a83efda50037cd59ae0741a62cf7169f5def)
* ✨ OCPCLOUD-3513: feat: add gh-summary target to download manifests from GitHub [#617](https://github.com/openshift/cluster-api-provider-aws/pull/617)
* ✨ OCPCLOUD-3513: add a tool to generate manifests-summary [#616](https://github.com/openshift/cluster-api-provider-aws/pull/616)
* 🐛OCPBUGS-104496: UPSTREAM: <carry>: Add projected bound SA token volume for OpenShift [#624](https://github.com/openshift/cluster-api-provider-aws/pull/624)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/1f5b17cc6969d6013a1abc5c6c62f00add809ceb...e345a83efda50037cd59ae0741a62cf7169f5def)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, csi-driver-manila-operator, gcp-pd-csi-driver-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/857bbb16fa89b0b531e27ed0fc0eaa1e94efecb6)
* [OCPBUGS-105410](https://issues.redhat.com/browse/OCPBUGS-105410): Remove MutableCSINodeAllocatableCount featuregate [#600](https://github.com/openshift/csi-operator/pull/600)
* [GCP-1074](https://issues.redhat.com/browse/GCP-1074): feat(gcp-pd): enable HyperShift support for GCP PD CSI driver operator [#601](https://github.com/openshift/csi-operator/pull/601)
* [OCPBUGS-111088](https://issues.redhat.com/browse/OCPBUGS-111088): Replace deprecated pod.spec.service account [#604](https://github.com/openshift/csi-operator/pull/604)
* [OCPBUGS-105392](https://issues.redhat.com/browse/OCPBUGS-105392): Add proxy hook for HyperShift CSI driver controller deployments [#594](https://github.com/openshift/csi-operator/pull/594)
* [OCPBUGS-100071](https://issues.redhat.com/browse/OCPBUGS-100071): csi-driver-smb: DeleteVolume call fails to mkdir under /tmp [#593](https://github.com/openshift/csi-operator/pull/593)
* [Full changelog](https://github.com/openshift/csi-operator/compare/756f6b8bb00400e3d72437876a820a950c393eb3...857bbb16fa89b0b531e27ed0fc0eaa1e94efecb6)
### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/c5e303bb0c6a55332637d7a583cfceec1a3a900b)
* [OCPBUGS-101779](https://issues.redhat.com/browse/OCPBUGS-101779): UPSTREAM: 3756: fix: optionally skip reading the config from the API server [#159](https://github.com/openshift/azure-disk-csi-driver/pull/159)
* [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/ebcd88eeaeb1a3ef5e961792eb6d8991a25a1ce8...c5e303bb0c6a55332637d7a583cfceec1a3a900b)
### [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms/tree/21fc3813f6cc12ce6246531891b5ad395e2afaad)
* [OCPSTRAT-3549](https://issues.redhat.com/browse/OCPSTRAT-3549): support sovereign Managed HSM endpoints [#54](https://github.com/openshift/azure-kubernetes-kms/pull/54)
* [CNTRLPLANE-4022](https://issues.redhat.com/browse/CNTRLPLANE-4022): Rebase azure-kubernetes-kms to v0.11.0 for OCP 5.1 [#52](https://github.com/openshift/azure-kubernetes-kms/pull/52)
* [OCPSTRAT-3549](https://issues.redhat.com/browse/OCPSTRAT-3549): Correct Managed HSM endpoints [#51](https://github.com/openshift/azure-kubernetes-kms/pull/51)
* [Full changelog](https://github.com/openshift/azure-kubernetes-kms/compare/ca3d747de321b88a2c606e546851d1841d2fab9f...21fc3813f6cc12ce6246531891b5ad395e2afaad)
### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/4ba9605f3a9af6ddc31afb86a95439454fdd2965)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): refactor: remove AzureWorkloadIdentity feature gate [#207](https://github.com/openshift/machine-api-provider-azure/pull/207)
* [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/4ff6c6b8730c1253918f1f5261b9c12cab2e5903...4ba9605f3a9af6ddc31afb86a95439454fdd2965)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/c8d299965fc1527648ce7aeb368c198a7b28e85d)
* [OCPBUGS-59521](https://issues.redhat.com/browse/OCPBUGS-59521): azure: fixes when setting DiskEncryptionSet on data disks [#10776](https://github.com/openshift/installer/pull/10776)
* [CORS-4550](https://issues.redhat.com/browse/CORS-4550): bump openshift api for gcd feature gate [#10775](https://github.com/openshift/installer/pull/10775)
* [OCPBUGS-59520](https://issues.redhat.com/browse/OCPBUGS-59520): azure: require storageAccountType when managedDisk is specified [#10805](https://github.com/openshift/installer/pull/10805)
* [AGENT-626](https://issues.redhat.com/browse/AGENT-626): Allow UserManaged LoadBalancer on baremetal/vsphere platforms [#10558](https://github.com/openshift/installer/pull/10558)
* [OCPBUGS-59522](https://issues.redhat.com/browse/OCPBUGS-59522): azure: reject securityEncryptionType on data disks [#10777](https://github.com/openshift/installer/pull/10777)
* [OCPBUGS-45804](https://issues.redhat.com/browse/OCPBUGS-45804): Update timeout in GetMarketplaceImage to 5 minutes [#10767](https://github.com/openshift/installer/pull/10767)
* [CORS-4441](https://issues.redhat.com/browse/CORS-4441): Bump Azure Marketplace Images [#10764](https://github.com/openshift/installer/pull/10764)
* [OCPBUGS-105510](https://issues.redhat.com/browse/OCPBUGS-105510): images: add BUILD_VERSION arg [#10781](https://github.com/openshift/installer/pull/10781)
* [CORS-4308](https://issues.redhat.com/browse/CORS-4308): networking: enforce NetworkObservabilityInstall feature gate [#10774](https://github.com/openshift/installer/pull/10774)
* [MULTIARCH-6274](https://issues.redhat.com/browse/MULTIARCH-6274): agent: Enable platform external s390x [#10588](https://github.com/openshift/installer/pull/10588)
* [OCPBUGS-54305](https://issues.redhat.com/browse/OCPBUGS-54305): Power VS: Get permitted network from user [#9607](https://github.com/openshift/installer/pull/9607)
* [OSASINFRA-4359](https://issues.redhat.com/browse/OSASINFRA-4359): Bump CAPO in openshift/installer [#10726](https://github.com/openshift/installer/pull/10726)
* [OCPBUGS-60993](https://issues.redhat.com/browse/OCPBUGS-60993): Enrich IBI config image proxy NoProxy with cluster networks [#10649](https://github.com/openshift/installer/pull/10649)
* [CORS-4308](https://issues.redhat.com/browse/CORS-4308): Enable Network Observability during installation [#10382](https://github.com/openshift/installer/pull/10382)
* [OPNET-781](https://issues.redhat.com/browse/OPNET-781): Add BGP VIP management support [#10718](https://github.com/openshift/installer/pull/10718)
* [CORS-4549](https://issues.redhat.com/browse/CORS-4549): gcp: set universe domain in Infrastructure status for GCD [#10759](https://github.com/openshift/installer/pull/10759)
* [OCPBUGS-105449](https://issues.redhat.com/browse/OCPBUGS-105449): update GCP auth functions & validations [#10694](https://github.com/openshift/installer/pull/10694)
* [OCPBUGS-105456](https://issues.redhat.com/browse/OCPBUGS-105456): fix KMS service agent domain for sovereign clouds [#10752](https://github.com/openshift/installer/pull/10752)
* [OCPBUGS-88511](https://issues.redhat.com/browse/OCPBUGS-88511): Disable apps DNS validation for add-nodes [#10737](https://github.com/openshift/installer/pull/10737)
* NO-JIRA: openstack: pin argcomplete for yq on Python 3.9 [#10757](https://github.com/openshift/installer/pull/10757)
* NO-ISSUE: Render OSImageStream in OKD too [#10730](https://github.com/openshift/installer/pull/10730)
* [OCPBUGS-105407](https://issues.redhat.com/browse/OCPBUGS-105407): Remove VSphereMultiNetworks feature gate [#10760](https://github.com/openshift/installer/pull/10760)
* [OCPBUGS-74510](https://issues.redhat.com/browse/OCPBUGS-74510): vsphere: remove VSphereMultiDisk feature gate references [#10753](https://github.com/openshift/installer/pull/10753)
* no-jira: Update GCD ability to identify project [#10745](https://github.com/openshift/installer/pull/10745)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/installer/compare/1b579f10fb2c89d061112a15c178a1f9e7cfad63...c8d299965fc1527648ce7aeb368c198a7b28e85d)
### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/3057d9978db74dcd5012a293d37d571b524c4e46)
* [OCPBUGS-86571](https://issues.redhat.com/browse/OCPBUGS-86571): node-ip: wait for both address families on dual-stack clusters [#391](https://github.com/openshift/baremetal-runtimecfg/pull/391)
* [OPNET-785](https://issues.redhat.com/browse/OPNET-785): Add FRR peer-file rendering for BGP-based VIP management [#395](https://github.com/openshift/baremetal-runtimecfg/pull/395)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/660073616802e3d1258a036f2e57ca18a7baafa0...3057d9978db74dcd5012a293d37d571b524c4e46)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/2902632b849a20d312215e16f2058233f1713553)
* NO-JIRA: Fix `oc` builds on Mac OS X Apple Silicon machines [#2246](https://github.com/openshift/oc/pull/2246)
* [OTA-1959](https://issues.redhat.com/browse/OTA-1959): oc adm upgrade recommend works with accepted risks [#2370](https://github.com/openshift/oc/pull/2370)
* [OCPBUGS-85019](https://issues.redhat.com/browse/OCPBUGS-85019): oc login: Fix polluting KUBECONFIG file [#2357](https://github.com/openshift/oc/pull/2357)
* [Full changelog](https://github.com/openshift/oc/compare/d436a450e4b65cfba1547d1dddb376bbceca82f3...2902632b849a20d312215e16f2058233f1713553)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/b187feee66f4ce0f992059b21a97a2ae88e4cdd9)
* [CORS-4544](https://issues.redhat.com/browse/CORS-4544): WIF Support on GCD [#1073](https://github.com/openshift/cloud-credential-operator/pull/1073)
* [CCO-848](https://issues.redhat.com/browse/CCO-848): Add tls-min-version and tls-cipher-suites CLI flags to CCO [#1063](https://github.com/openshift/cloud-credential-operator/pull/1063)
* [OCPBUGS-83624](https://issues.redhat.com/browse/OCPBUGS-83624): Embed credentials_request.yaml template in test binary [#1072](https://github.com/openshift/cloud-credential-operator/pull/1072)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/f323f9eb76e4031934c47f2623781f1f15cd5c9e...b187feee66f4ce0f992059b21a97a2ae88e4cdd9)
### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/82bed43e8218e8c22de1b65ccd141096e92685fb)
* [OCPBUGS-112564](https://issues.redhat.com/browse/OCPBUGS-112564): Fix CVE-2026-41178 - bump go.opentelemetry.io/otel to v1.44.0 [#262](https://github.com/openshift/cloud-network-config-controller/pull/262)
* [OCPBUGS-87249](https://issues.redhat.com/browse/OCPBUGS-87249): on AWS, select associated IPv6 CIDR block for egress IP subnet [#228](https://github.com/openshift/cloud-network-config-controller/pull/228)
* [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/dada7547e3d89f301be73b27063ac91f2acb9088...82bed43e8218e8c22de1b65ccd141096e92685fb)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/14c33fae096437e8c703d312156d7adf2a8f7e34)
* NO-JIRA: Bump library-go [#977](https://github.com/openshift/cluster-authentication-operator/pull/977)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire preflight deployer [#975](https://github.com/openshift/cluster-authentication-operator/pull/975)
* NO-JIRA: Update library-go to get latest changes [#976](https://github.com/openshift/cluster-authentication-operator/pull/976)
* NO-JIRA: bump library-go changes [#974](https://github.com/openshift/cluster-authentication-operator/pull/974)
* NO-JIRA: update KMS tests with bump library-go changes [#969](https://github.com/openshift/cluster-authentication-operator/pull/969)
* NO-JIRA: Remove rh-roman from OWNERS [#970](https://github.com/openshift/cluster-authentication-operator/pull/970)
* NO-JIRA: Retry conflict errors on UpdateKMSEncryptionStatus function [#968](https://github.com/openshift/cluster-authentication-operator/pull/968)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms key controller preflight support- #747 [#965](https://github.com/openshift/cluster-authentication-operator/pull/965)
* [CNTRLPLANE-2589](https://issues.redhat.com/browse/CNTRLPLANE-2589): Migrate test/e2e-oidc to OTE + bug fixes(imagestream,scc,Pathological Event Monitor) [#945](https://github.com/openshift/cluster-authentication-operator/pull/945)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/f3df4f5b26043e7c0f2bc724cd3cbc0a2a6d14f7...14c33fae096437e8c703d312156d7adf2a8f7e34)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/e4f426dcd988735d1e49da743240231be6ab6a40)
* [AUTOSCALE-899](https://issues.redhat.com/browse/AUTOSCALE-899): add claude and contributing files [#399](https://github.com/openshift/cluster-autoscaler-operator/pull/399)
* [OCPBUGS-111092](https://issues.redhat.com/browse/OCPBUGS-111092): update version to properly detect errors [#395](https://github.com/openshift/cluster-autoscaler-operator/pull/395)
* [OCPBUGS-105277](https://issues.redhat.com/browse/OCPBUGS-105277): implement startupTaints [#383](https://github.com/openshift/cluster-autoscaler-operator/pull/383)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/e48fe1179ad671757b5a40688e2d125c1f326e8b...e4f426dcd988735d1e49da743240231be6ab6a40)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/bc67262323fe29fe1793bf7f421e214a2500476f)
* [OCPBUGS-114433](https://issues.redhat.com/browse/OCPBUGS-114433): Increase firmware e2e timeouts and add HPE Mellanox NIC bastion mapping [#649](https://github.com/openshift/cluster-baremetal-operator/pull/649)
* [OCPQE-32100](https://issues.redhat.com/browse/OCPQE-32100): Add batched firmware update tests (bmc+bios+nic) [#643](https://github.com/openshift/cluster-baremetal-operator/pull/643)
* [OCPBUGS-105610](https://issues.redhat.com/browse/OCPBUGS-105610): drop IRONIC_INSECURE from BMO [#642](https://github.com/openshift/cluster-baremetal-operator/pull/642)
* [OCPBUGS-105455](https://issues.redhat.com/browse/OCPBUGS-105455): Fix infinite reconciliation loop in EnsureMirrorConfig [#641](https://github.com/openshift/cluster-baremetal-operator/pull/641)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/4ecb36c02378147632acde2fa91aea1d9efc229b...bc67262323fe29fe1793bf7f421e214a2500476f)
### [cluster-capi-controllers](https://github.com/openshift/cluster-api/tree/303d9786a5017d299b6e7fc702bb92f5cb4550cf)
* [OCPCLOUD-3434](https://issues.redhat.com/browse/OCPCLOUD-3434): fix REPO_NAME [#307](https://github.com/openshift/cluster-api/pull/307)
* [OCPCLOUD-3434](https://issues.redhat.com/browse/OCPCLOUD-3434): add gh-summary target to download manifests from GitHub [#306](https://github.com/openshift/cluster-api/pull/306)
* [OCPCLOUD-3434](https://issues.redhat.com/browse/OCPCLOUD-3434): Generating manifests-summary [#305](https://github.com/openshift/cluster-api/pull/305)
* [Full changelog](https://github.com/openshift/cluster-api/compare/8e2d2bddb8f3f17b80d0461cf8eeebc8d833c38b...303d9786a5017d299b6e7fc702bb92f5cb4550cf)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/a134d6fc659a598150e669c6041c925c7036a4a3)
* NO-JIRA: port OTP CAPI tests to OTE framework [#627](https://github.com/openshift/cluster-capi-operator/pull/627)
* [OCPBUGS-105850](https://issues.redhat.com/browse/OCPBUGS-105850): skip Cluster API Machine Management tests on External topology [#646](https://github.com/openshift/cluster-capi-operator/pull/646)
* NO-JIRA: embed transformer YAML so go mod vendor copies it [#657](https://github.com/openshift/cluster-capi-operator/pull/657)
* [OCPCLOUD-3442](https://issues.redhat.com/browse/OCPCLOUD-3442): Migrate four controllers to per-controller condition reporting [#577](https://github.com/openshift/cluster-capi-operator/pull/577)
* NO-JIRA: Fix flaky CI unit tests: reduce parallelism [#645](https://github.com/openshift/cluster-capi-operator/pull/645)
* [OCPBUGS-85063](https://issues.redhat.com/browse/OCPBUGS-85063): Fix CredentialsRequest capability annotations [#630](https://github.com/openshift/cluster-capi-operator/pull/630)
* [OCPBUGS-104496](https://issues.redhat.com/browse/OCPBUGS-104496): aws: use capa-controller-manager as service account [#644](https://github.com/openshift/cluster-capi-operator/pull/644)
* [OCPCLOUD-3513](https://issues.redhat.com/browse/OCPCLOUD-3513): Generate the manifests summary [#643](https://github.com/openshift/cluster-capi-operator/pull/643)
* [OCPCLOUD-2664](https://issues.redhat.com/browse/OCPCLOUD-2664): Aggregate controller statuses in clusteroperator controller [#574](https://github.com/openshift/cluster-capi-operator/pull/574)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/9e2ecb9f5e026953d98980aabd3b0926ac50b261...a134d6fc659a598150e669c6041c925c7036a4a3)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/9ca11878cc35862f4af4c194985b4f3ae3a835fa)
* [OCPBUGS-111416](https://issues.redhat.com/browse/OCPBUGS-111416): Moved node sync job creation from manifest to operator controller [#504](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/504)
* [OCPBUGS-105385](https://issues.redhat.com/browse/OCPBUGS-105385): Bump cloud-provider-aws to fix NLB e2e occasional timeout failures [#503](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/503)
* [CORS-4551](https://issues.redhat.com/browse/CORS-4551): GCP: mount bound sa token volume [#502](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/502)
* [OCPBUGS-100052](https://issues.redhat.com/browse/OCPBUGS-100052): Created new job to update vSphere nodes to have vsphere label [#497](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/497)
* [OCPBUGS-105409](https://issues.redhat.com/browse/OCPBUGS-105409): chore: remove AWSServiceLBNetworkSecurityGroup feature gate references [#500](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/500)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/bc52198c1c3c61099ba3cd20bf5fca80ed7754e7...9ca11878cc35862f4af4c194985b4f3ae3a835fa)
### [cluster-config-api](https://github.com/openshift/api/tree/c7d4aa14a7649477cdb9e7c4a733d61bf70913ea)
* [OCPBUGS-99266](https://issues.redhat.com/browse/OCPBUGS-99266): move empty CRIOCredentialProviderConfig CR to run-level 0000_10 [#3011](https://github.com/openshift/api/pull/3011)
* [OCPBUGS-105399](https://issues.redhat.com/browse/OCPBUGS-105399), [OCPBUGS-105400](https://issues.redhat.com/browse/OCPBUGS-105400): Remove SigstoreImageVerification and SigstoreImageVerificationPKI feature gates [#3000](https://github.com/openshift/api/pull/3000)
* [OCPBUGS-112330](https://issues.redhat.com/browse/OCPBUGS-112330): Fix 'supercede' typos in machineconfiguration types [#2996](https://github.com/openshift/api/pull/2996)
* [SPLAT-2864](https://issues.redhat.com/browse/SPLAT-2864): Promote VSphereMultiVCenterDay2 to GA [#2968](https://github.com/openshift/api/pull/2968)
* [CORS-4550](https://issues.redhat.com/browse/CORS-4550): Promote GCD to Default [#2991](https://github.com/openshift/api/pull/2991)
* [OCPBUGS-105407](https://issues.redhat.com/browse/OCPBUGS-105407): Remove VSphereMultiNetworks feature gate [#2975](https://github.com/openshift/api/pull/2975)
* config/v1: add IBMCloudServiceTransitGateway and IBMCloudServicePowerVS to IBMCloudServiceName [#2959](https://github.com/openshift/api/pull/2959)
* [OCPNODE-4526](https://issues.redhat.com/browse/OCPNODE-4526): Block '..' traversal in StorePath [#2999](https://github.com/openshift/api/pull/2999)
* [OCPBUGS-74510](https://issues.redhat.com/browse/OCPBUGS-74510): Remove VSphereMultiDisk feature gate [#2973](https://github.com/openshift/api/pull/2973)
* Add printer columns to PodNetworkConnectivityCheck CRD [#2977](https://github.com/openshift/api/pull/2977)
* [NE-2387](https://issues.redhat.com/browse/NE-2387): IngressController AWS NLB Security Group Selection [#2914](https://github.com/openshift/api/pull/2914)
* [OCPBUGS-112479](https://issues.redhat.com/browse/OCPBUGS-112479): Handle Sippy date-only format in featuregate-test-analyzer [#2998](https://github.com/openshift/api/pull/2998)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default for Hypershift [#2993](https://github.com/openshift/api/pull/2993)
* [TRT-2908](https://issues.redhat.com/browse/TRT-2908): Revert "CNTRLPLANE-3871: promote OSStreams feature gate to Default for Hypershift" [#2989](https://github.com/openshift/api/pull/2989)
* [OCPBUGS-105409](https://issues.redhat.com/browse/OCPBUGS-105409): chore: remove AWSServiceLBNetworkSecurityGroup feature gate [#2974](https://github.com/openshift/api/pull/2974)
* [CORS-4529](https://issues.redhat.com/browse/CORS-4529): Azure IL6 Secret Cloud support [#2919](https://github.com/openshift/api/pull/2919)
* [CNTRLPLANE-3609](https://issues.redhat.com/browse/CNTRLPLANE-3609): graduate etcdBackendQuota to GA [#2946](https://github.com/openshift/api/pull/2946)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default for Hypershift [#2950](https://github.com/openshift/api/pull/2950)
* [OCPNODE-4601](https://issues.redhat.com/browse/OCPNODE-4601): Add {system,container}GomaxprocsBehavior field [#2934](https://github.com/openshift/api/pull/2934)
* [MON-4608](https://issues.redhat.com/browse/MON-4608): add interrupts to NodeExporterCollectorConfig CRD types [#2955](https://github.com/openshift/api/pull/2955)
* [STOR-3014](https://issues.redhat.com/browse/STOR-3014): Promote SELinuxMountGAReadiness to GA [#2964](https://github.com/openshift/api/pull/2964)
* Promote ExternalOIDCWithUpstreamParity to Default feature set [#2915](https://github.com/openshift/api/pull/2915)
* [STOR-2959](https://issues.redhat.com/browse/STOR-2959): Promote VolumeGroupSnapshots to GA [#2965](https://github.com/openshift/api/pull/2965)
* Move GCD to TechPreview [#2970](https://github.com/openshift/api/pull/2970)
* [OCPNODE-4521](https://issues.redhat.com/browse/OCPNODE-4521): Promote AdditionalStorageConfig feature gate to Default [#2858](https://github.com/openshift/api/pull/2858)
* [Full changelog](https://github.com/openshift/api/compare/72ae4424ef350e688068890e69da9ced377ea495...c7d4aa14a7649477cdb9e7c4a733d61bf70913ea)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/81541d53f815a4cb25255b0dad33f449762c4609)
* [OCPBUGS-86988](https://issues.redhat.com/browse/OCPBUGS-86988): Guard against empty workspace field on vsphere [#407](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/407)
* [OCPBUGS-105222](https://issues.redhat.com/browse/OCPBUGS-105222): GCP e2e: bump only memory for E2 custom machine types [#417](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/417)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/0a98fb46580fa472b86e1aeaa96821e0db51b741...81541d53f815a4cb25255b0dad33f449762c4609)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/36c44461e9bd3af7c76915058370da87bc2ceb39)
* [OCPBUGS-94106](https://issues.redhat.com/browse/OCPBUGS-94106): fall back to intermediate ciphers during etcd bootstrap [#1689](https://github.com/openshift/cluster-etcd-operator/pull/1689)
* [OCPBUGS-80957](https://issues.redhat.com/browse/OCPBUGS-80957): Reset node status when UID changes [#1687](https://github.com/openshift/cluster-etcd-operator/pull/1687)
* [OCPBUGS-105322](https://issues.redhat.com/browse/OCPBUGS-105322): fix etcdSignerCAExpiration* alert description wording [#1686](https://github.com/openshift/cluster-etcd-operator/pull/1686)
* [CNTRLPLANE-4131](https://issues.redhat.com/browse/CNTRLPLANE-4131): update to latest api to pull in etcd db ga [#1680](https://github.com/openshift/cluster-etcd-operator/pull/1680)
* [OCPBUGS-109740](https://issues.redhat.com/browse/OCPBUGS-109740): Fix tnf_cluster_in_service during per-node maintenance [#1678](https://github.com/openshift/cluster-etcd-operator/pull/1678)
* [OCPBUGS-109743](https://issues.redhat.com/browse/OCPBUGS-109743): Derive console notification docs URL from cluster version [#1676](https://github.com/openshift/cluster-etcd-operator/pull/1676)
* [OCPEDGE-2118](https://issues.redhat.com/browse/OCPEDGE-2118): Fix pcs stderr handling [#1674](https://github.com/openshift/cluster-etcd-operator/pull/1674)
* [CNTRLPLANE-3460](https://issues.redhat.com/browse/CNTRLPLANE-3460): Refactor defrag controller to lower impact of defrag [#1618](https://github.com/openshift/cluster-etcd-operator/pull/1618)
* [OCPBUGS-81500](https://issues.redhat.com/browse/OCPBUGS-81500): fix: udpate healthcheck previous state only after successful operator status update [#1614](https://github.com/openshift/cluster-etcd-operator/pull/1614)
* [OCPBUGS-105357](https://issues.redhat.com/browse/OCPBUGS-105357): Fix TNF fencing skip for IPv6 bracketed stonith IPs. [#1669](https://github.com/openshift/cluster-etcd-operator/pull/1669)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/2f256f2638e892af38c274c62131565ec8df6dff...36c44461e9bd3af7c76915058370da87bc2ceb39)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/f9c7439f0924147bc02f2bf74ad403ebe105408d)
* [OCPBUGS-86308](https://issues.redhat.com/browse/OCPBUGS-86308): do not report progressing during cluster scale up [#1361](https://github.com/openshift/cluster-image-registry-operator/pull/1361)
* [OCPBUGS-113705](https://issues.redhat.com/browse/OCPBUGS-113705): CNTRLPLANE-3779: Migrated go standard cases to ote [#1343](https://github.com/openshift/cluster-image-registry-operator/pull/1343)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/94cd22d000c8b8eef24dd43cd05d06544df24930...f9c7439f0924147bc02f2bf74ad403ebe105408d)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/5bf72fcc4534d9ba2c4d65d29cdb8b01c83cf550)
* [OCPBUGS-91026](https://issues.redhat.com/browse/OCPBUGS-91026): Add missing KAS-defaulted fields to ValidatingAdmissionPolicy manifest [#1560](https://github.com/openshift/cluster-ingress-operator/pull/1560)
* [OCPBUGS-112280](https://issues.redhat.com/browse/OCPBUGS-112280): Preserve server-defaulted fields on init containers and volumes [#1557](https://github.com/openshift/cluster-ingress-operator/pull/1557)
* [NE-2856](https://issues.redhat.com/browse/NE-2856): Fix staticcheck warnings across multiple packages [#1553](https://github.com/openshift/cluster-ingress-operator/pull/1553)
* [NE-2032](https://issues.redhat.com/browse/NE-2032): e2e: Signal service deprovisioning issues during Gateway DNS test [#1220](https://github.com/openshift/cluster-ingress-operator/pull/1220)
* [OCPBUGS-101783](https://issues.redhat.com/browse/OCPBUGS-101783): reconcile canary certificate on dependency creation [#1538](https://github.com/openshift/cluster-ingress-operator/pull/1538)
* [OCPBUGS-100074](https://issues.redhat.com/browse/OCPBUGS-100074): Use /healthz for router startup probe [#1528](https://github.com/openshift/cluster-ingress-operator/pull/1528)
* [OCPBUGS-86841](https://issues.redhat.com/browse/OCPBUGS-86841): Add BackendTLSPolicy and ReferenceGrant e2e test coverage helpers [#1467](https://github.com/openshift/cluster-ingress-operator/pull/1467)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/acca9642a81370bc1a587155f7e1e7998b7c5489...5bf72fcc4534d9ba2c4d65d29cdb8b01c83cf550)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/2fa5365f29eff19a528856740274fe0c37b18b68)
* NO-JIRA: Bump library-go [#2286](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2286)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire preflight deployer [#2276](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2276)
* NO-JIRA: Update library-go to get latest changes [#2280](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2280)
* [OCPBUGS-80958](https://issues.redhat.com/browse/OCPBUGS-80958): Kube apiserver node replace [#2199](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2199)
* NO-JIRA: bump library-go changes [#2270](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2270)
* [OCPBUGS-38661](https://issues.redhat.com/browse/OCPBUGS-38661): Use 10min inertia for GuardControllerDegraded [#2273](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2273)
* [OCPBUGS-85183](https://issues.redhat.com/browse/OCPBUGS-85183): Add kind-aware staleness detection for runtime-config entries [#2179](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2179)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2430 [#2271](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2271)
* NO-JIRA:Remove old perf tests and update Makefile [#2269](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2269)
* [CNTRLPLANE-4110](https://issues.redhat.com/browse/CNTRLPLANE-4110): Migrate e2e encryption perf cases to ote [#2256](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2256)
* NO-JIRA: update KMS tests with bump library-go changes [#2264](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2264)
* [OCPBUGS-85181](https://issues.redhat.com/browse/OCPBUGS-85181): Remove MutatingAdmissionPolicy from defaultGroupVersionsByFeatureGate [#2141](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2141)
* NO-JIRA: Retry conflict errors on UpdateKMSEncryptionStatus function [#2265](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2265)
* NO-JIRA: Update KMStoKMS scenario to multi provider [#2261](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2261)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/238179f3e2a5a2daa639fa0260972e787dca7661...2fa5365f29eff19a528856740274fe0c37b18b68)
### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/330fe4a6ed1a15ae1c2b572138d596fd5780d318)
* [OCPBUGS-107974](https://issues.redhat.com/browse/OCPBUGS-107974): fix CVE-2026-41178 [#955](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/955)
* [OCPBUGS-38662](https://issues.redhat.com/browse/OCPBUGS-38662): Use 10min inertia for GuardControllerDegraded [#956](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/956)
* [OCPBUGS-99770](https://issues.redhat.com/browse/OCPBUGS-99770): Remove unnecessary namespace informers from kubeInformersForNamespaces [#950](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/950)
* [OCPBUGS-99770](https://issues.redhat.com/browse/OCPBUGS-99770): remove duplicate wrappings of core_getters [#952](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/952)
* [CNTRLPLANE-3778](https://issues.redhat.com/browse/CNTRLPLANE-3778): Migrate openshift-test-private kcm cases to OTE [#943](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/943)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/4e72164b8bc505033ad565ab01d57963e7c9688e...330fe4a6ed1a15ae1c2b572138d596fd5780d318)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/6a750a9fd626675a2bc35b43b75dbc182ce3d8e9)
* [OCPBUGS-107969](https://issues.redhat.com/browse/OCPBUGS-107969): bump otel to v1.44.0 to fix CVE-2026-41178 [#662](https://github.com/openshift/cluster-kube-scheduler-operator/pull/662)
* [OCPBUGS-38663](https://issues.redhat.com/browse/OCPBUGS-38663): Use 10min inertia for GuardControllerDegraded [#661](https://github.com/openshift/cluster-kube-scheduler-operator/pull/661)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3...6a750a9fd626675a2bc35b43b75dbc182ce3d8e9)
### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/c96773c19165a46d55007cd6a14d24376ab83d4c)
* [OCPBUGS-57437](https://issues.redhat.com/browse/OCPBUGS-57437): Always validate EgressIPs [#309](https://github.com/openshift/cluster-machine-approver/pull/309)
* [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/cdf27353008200166f1ad754c4ade033370077ae...c96773c19165a46d55007cd6a14d24376ab83d4c)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/f581865b41267ff23bbf1cb30fbdd2e02cecd42f)
* NO-JIRA: Fix staticcheck warnings across multiple packages [#3059](https://github.com/openshift/cluster-monitoring-operator/pull/3059)
* NO-JIRA: test: produce JUnit XML from e2e runs in CI [#3054](https://github.com/openshift/cluster-monitoring-operator/pull/3054)
* NO-JIRA: Makefile: version-stamp golangci-lint binary to prevent stale linter - #3057#3057 [#3057](https://github.com/openshift/cluster-monitoring-operator/pull/3057)
* [OCPBUGS-99769](https://issues.redhat.com/browse/OCPBUGS-99769): wrap library-go resourceCache with mutex for thread safety [#3040](https://github.com/openshift/cluster-monitoring-operator/pull/3040)
* NO-JIRA: hack/tools: remove unused vendor directory [#3055](https://github.com/openshift/cluster-monitoring-operator/pull/3055)
* [MON-4548](https://issues.redhat.com/browse/MON-4548), [MON-4549](https://issues.redhat.com/browse/MON-4549), [MON-4550](https://issues.redhat.com/browse/MON-4550), [MON-4551](https://issues.redhat.com/browse/MON-4551): Enforce Thanos grpc tls parameters [#3018](https://github.com/openshift/cluster-monitoring-operator/pull/3018)
* [MON-4612](https://issues.redhat.com/browse/MON-4612): log Phase 1 dual ConfigMap/CRD configuration notice [#2995](https://github.com/openshift/cluster-monitoring-operator/pull/2995)
* [MON-4559](https://issues.redhat.com/browse/MON-4559): enable interrupts node-exporter collector via config [#2888](https://github.com/openshift/cluster-monitoring-operator/pull/2888)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3049](https://github.com/openshift/cluster-monitoring-operator/pull/3049)
* [MON-4629](https://issues.redhat.com/browse/MON-4629): support the nvmesubsystem collector in the config CRD [#3046](https://github.com/openshift/cluster-monitoring-operator/pull/3046)
* NO-JIRA: update OWNERS [#3050](https://github.com/openshift/cluster-monitoring-operator/pull/3050)
* NO-JIRA: feat: validate systemd units [#3048](https://github.com/openshift/cluster-monitoring-operator/pull/3048)
* [OCPBUGS-105438](https://issues.redhat.com/browse/OCPBUGS-105438): feat: support ogx api adoption metrics [#2984](https://github.com/openshift/cluster-monitoring-operator/pull/2984)
* [OCPBUGS-105389](https://issues.redhat.com/browse/OCPBUGS-105389): enable read-only rootfs for all containers [#3039](https://github.com/openshift/cluster-monitoring-operator/pull/3039)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/c68fc0aba966f39fcd91e725017811b7fee08f5b...f581865b41267ff23bbf1cb30fbdd2e02cecd42f)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/31a6ffd3e4c2b466607c21bed423d33b1f7e77e6)
* [OCPBUGS-112278](https://issues.redhat.com/browse/OCPBUGS-112278): Add ConfigMap hash annotation to networking console plugin deployment [#3131](https://github.com/openshift/cluster-network-operator/pull/3131)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Install NOO using OLMv0 instead of OLMv1 [#3115](https://github.com/openshift/cluster-network-operator/pull/3115)
* [OCPBUGS-64582](https://issues.redhat.com/browse/OCPBUGS-64582): Drop strategy.rollingUpdate and switch strategy.type to Recreate via pre-patch in frr-k8s-statuscleaner deployments on SNO [#3121](https://github.com/openshift/cluster-network-operator/pull/3121)
* [OCPBUGS-105887](https://issues.redhat.com/browse/OCPBUGS-105887): Filter unsupported cipher suites to prevent ovnkube-identity crash [#3119](https://github.com/openshift/cluster-network-operator/pull/3119)
* NO-ISSUE: modernise the codebase using go fix [#3113](https://github.com/openshift/cluster-network-operator/pull/3113)
* [CORENET-7330](https://issues.redhat.com/browse/CORENET-7330): Allow per-node OVN encap IP override via env-overrides [#2998](https://github.com/openshift/cluster-network-operator/pull/2998)
* NO-ISSUE: Drop github.com/pkg/errors [#3112](https://github.com/openshift/cluster-network-operator/pull/3112)
* [OCPBUGS-64582](https://issues.redhat.com/browse/OCPBUGS-64582): frr-k8s: use Recreate strategy for statuscleaner deployment [#3104](https://github.com/openshift/cluster-network-operator/pull/3104)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/a0ebeb0c4d6d5baa353f1e123553dfecf7092eda...31a6ffd3e4c2b466607c21bed423d33b1f7e77e6)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/246b707a99945e3c23291d7776446358ec3b7511)
* [OCPBUGS-113651](https://issues.redhat.com/browse/OCPBUGS-113651): Disable timer.migration on RHCOS 10 [#1614](https://github.com/openshift/cluster-node-tuning-operator/pull/1614)
* [CNF-26060](https://issues.redhat.com/browse/CNF-26060): add optional --ovs-dpdk-cpu-count flag (default 0) [#1590](https://github.com/openshift/cluster-node-tuning-operator/pull/1590)
* NO-JIRA: Bump Kubernetes, OpenShift and other dependencies [#1615](https://github.com/openshift/cluster-node-tuning-operator/pull/1615)
* [OCPBUGS-113647](https://issues.redhat.com/browse/OCPBUGS-113647): E2E: Minor fixes to Memory Manager and hugepages split tests [#1578](https://github.com/openshift/cluster-node-tuning-operator/pull/1578)
* [OCPBUGS-112537](https://issues.redhat.com/browse/OCPBUGS-112537): E2E: Fix ovs dynamic pinning, kubelet and mustgather tests [#1565](https://github.com/openshift/cluster-node-tuning-operator/pull/1565)
* [CNF-26497](https://issues.redhat.com/browse/CNF-26497): unconditionally disable fwupd-refresh.timer [#1591](https://github.com/openshift/cluster-node-tuning-operator/pull/1591)
* [OCPBUGS-112025](https://issues.redhat.com/browse/OCPBUGS-112025): Bump golang.org/x/net [#1593](https://github.com/openshift/cluster-node-tuning-operator/pull/1593)
* [OCPBUGS-105476](https://issues.redhat.com/browse/OCPBUGS-105476): Update PPC help description [#1582](https://github.com/openshift/cluster-node-tuning-operator/pull/1582)
* [OCPBUGS-105458](https://issues.redhat.com/browse/OCPBUGS-105458): Use Add() instead of AddRateLimited() for routine Profile enqueues [#1584](https://github.com/openshift/cluster-node-tuning-operator/pull/1584)
* NO-JIRA: ci: disable smt alignment for ovsDpdk tests [#1589](https://github.com/openshift/cluster-node-tuning-operator/pull/1589)
* [CNF-26546](https://issues.redhat.com/browse/CNF-26546): tuned:irqs: set `default_smp_affinity` using `irqaffinity=` [#1572](https://github.com/openshift/cluster-node-tuning-operator/pull/1572)
* [CNF-20633](https://issues.redhat.com/browse/CNF-20633): Enable nohz_full and skew_tick by default [#1564](https://github.com/openshift/cluster-node-tuning-operator/pull/1564)
* [OCPBUGS-98060](https://issues.redhat.com/browse/OCPBUGS-98060): BUG-FIX Latency Test [#1566](https://github.com/openshift/cluster-node-tuning-operator/pull/1566)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/837ae9f6da1c7a5ff24718c8210047571a3909a3...246b707a99945e3c23291d7776446358ec3b7511)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/addad7cab1b1cb0854349c8404c08128fe420402)
* NO-ISSUE: Bump the k8s-dependencies group across 1 directory with 5 updates [#237](https://github.com/openshift/cluster-olm-operator/pull/237)
* NO-ISSUE: Bump golang.org/x/text from 0.40.0 to 0.41.0 [#234](https://github.com/openshift/cluster-olm-operator/pull/234)
* NO-ISSUE: Bump github.com/stretchr/testify from 1.11.1 to 1.12.1 [#236](https://github.com/openshift/cluster-olm-operator/pull/236)
* NO-ISSUE: Bump the k8s-dependencies group across 1 directory with 5 updates [#227](https://github.com/openshift/cluster-olm-operator/pull/227)
* NO-ISSUE: Bump github.com/operator-framework/operator-controller from 1.5.1 to 1.11.0 [#228](https://github.com/openshift/cluster-olm-operator/pull/228)
* NO-ISSUE: Update dependabot config with NO-ISSUE prefix [#232](https://github.com/openshift/cluster-olm-operator/pull/232)
* NO-ISSUE: Bump github.com/go-logr/logr from 1.4.3 to 1.4.4 [#231](https://github.com/openshift/cluster-olm-operator/pull/231)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/228ec940921e4443b2724ef512c0d211d4a38ba7...addad7cab1b1cb0854349c8404c08128fe420402)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/c7cea84d7f74b5aca7ea27e49fc2be814d744e60)
* NO-JIRA: Bump library-go [#760](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/760)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire preflight deployer [#758](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/758)
* NO-JIRA: Update library-go to get latest changes [#759](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/759)
* NO-JIRA: Update KMS cases and bump library-go [#756](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/756)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2430 [#754](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/754)
* [OCPBUGS-105786](https://issues.redhat.com/browse/OCPBUGS-105786): Revert "Revert "NO-JIRA: Disable WatchList feature gate due to the missing support of Project watch"" [#751](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/751)
* NO-JIRA: update KMS tests changes with latest library-go bump [#753](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/753)
* NO-JIRA: Retry conflict errors on UpdateKMSEncryptionStatus function [#752](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/752)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/f730b48c7dbd76b3125fa7508c80c6a083d364f8...c7cea84d7f74b5aca7ea27e49fc2be814d744e60)
### [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator/tree/ca4d2061fba488b34c042e7a16946157db595599)
* [CNTRLPLANE-3895](https://issues.redhat.com/browse/CNTRLPLANE-3895): Bump kubernetes dependencies to v1.36 [#441](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/441)
* [Full changelog](https://github.com/openshift/cluster-openshift-controller-manager-operator/compare/34f95b07f4afbc47558e54e4fa2710fd692e615e...ca4d2061fba488b34c042e7a16946157db595599)
### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/469bbf211d35eee0df4422bda7e9e600b080f0f2)
* [OCPBUGS-87476](https://issues.redhat.com/browse/OCPBUGS-87476): Updating ose-cluster-policy-controller-container image to be consistent with ART for 5.0 [#188](https://github.com/openshift/cluster-policy-controller/pull/188)
* [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/01afc4aac71a8e8be26383a0421bed7673391750...469bbf211d35eee0df4422bda7e9e600b080f0f2)
### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/a4147d3308b2e935f58cf05eac4bf5fa35fa6cf8)
* [OKD-425](https://issues.redhat.com/browse/OKD-425): Revert openliberty back to 26.0.0.6 [#709](https://github.com/openshift/cluster-samples-operator/pull/709)
* [TRT-2905](https://issues.redhat.com/browse/TRT-2905): Fix python:latest and nodejs template references after UBI 8 tag removal [#706](https://github.com/openshift/cluster-samples-operator/pull/706)
* [OCPBUGS-106188](https://issues.redhat.com/browse/OCPBUGS-106188): Periodic sync of supported OCP samples [#695](https://github.com/openshift/cluster-samples-operator/pull/695)
* [OCPBUGS-106187](https://issues.redhat.com/browse/OCPBUGS-106187): Periodic sync of OKD samples [#683](https://github.com/openshift/cluster-samples-operator/pull/683)
* [OCPSTRAT-3578](https://issues.redhat.com/browse/OCPSTRAT-3578): Add NetworkPolicy manifests for openshift-cluster-samples-operator namespace [#703](https://github.com/openshift/cluster-samples-operator/pull/703)
* [OCPBUGS-105319](https://issues.redhat.com/browse/OCPBUGS-105319): update kubernetes api to v0.36.3 [#704](https://github.com/openshift/cluster-samples-operator/pull/704)
* [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/eee95babd52053191e29355108f7daf149dfbf8f...a4147d3308b2e935f58cf05eac4bf5fa35fa6cf8)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/6b031ec699a65512557b70eabedd85a95c238bbb)
* [OCPBUGS-112710](https://issues.redhat.com/browse/OCPBUGS-112710): clusterrole/openshift-csi-main-snapshotter-role needs volume group snapshot rules [#727](https://github.com/openshift/cluster-storage-operator/pull/727)
* [OCPBUGS-91027](https://issues.redhat.com/browse/OCPBUGS-91027): Add KAS-defaulted fields to storage-operator ValidatingAdmissionPolicy manifests [#726](https://github.com/openshift/cluster-storage-operator/pull/726)
* [OCPBUGS-105391](https://issues.redhat.com/browse/OCPBUGS-105391): Pass management cluster proxy env vars to CSI driver operator deployments [#723](https://github.com/openshift/cluster-storage-operator/pull/723)
* [STOR-3011](https://issues.redhat.com/browse/STOR-3011): Implement CSO upgrade check and Prometheus alerts for SELnuxMount readiness, updated runbook URL [#724](https://github.com/openshift/cluster-storage-operator/pull/724)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/bb8d2fd11a18ce59cf84a2982189d9ca2c23599e...6b031ec699a65512557b70eabedd85a95c238bbb)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/697ea9314e3e5c39b218b8781b32813b0e4ae84c)
* [OTA-2110](https://issues.redhat.com/browse/OTA-2110): remove cluster_id from LLM-bound readiness payload [#1451](https://github.com/openshift/cluster-version-operator/pull/1451)
* [OTA-2111](https://issues.redhat.com/browse/OTA-2111): set readOnlyRootFilesystem on console plugin container [#1452](https://github.com/openshift/cluster-version-operator/pull/1452)
* [OTA-2108](https://issues.redhat.com/browse/OTA-2108): restrict console plugin NetworkPolicy to openshift-console namespace [#1450](https://github.com/openshift/cluster-version-operator/pull/1450)
* [OTA-2106](https://issues.redhat.com/browse/OTA-2106): drop NetworkCheck (SDN gone, proxy data unused) [#1442](https://github.com/openshift/cluster-version-operator/pull/1442)
* NO-ISSUE: pkg/readiness/cluster_conditions: Conditionally include Upgradeable [#1463](https://github.com/openshift/cluster-version-operator/pull/1463)
* [OCPBUGS-54864](https://issues.redhat.com/browse/OCPBUGS-54864): reduce verbosity of skipping metrics log messages [#1439](https://github.com/openshift/cluster-version-operator/pull/1439)
* NO-ISSUE: OWNERS: Pratik is no longer at Red Hat :( [#1449](https://github.com/openshift/cluster-version-operator/pull/1449)
* [OCPBUGS-80925](https://issues.redhat.com/browse/OCPBUGS-80925): Remove the CRB for the default openshift-cluster-version SA [#1366](https://github.com/openshift/cluster-version-operator/pull/1366)
* [OCPBUGS-110322](https://issues.redhat.com/browse/OCPBUGS-110322): pkg/agenticrun/controller: Pivot to cluster-update-advisor directory [#1446](https://github.com/openshift/cluster-version-operator/pull/1446)
* "OTA-2107: Harden AgenticRun against indirect prompt injection" [#1443](https://github.com/openshift/cluster-version-operator/pull/1443)
* [OCPBUGS-14392](https://issues.redhat.com/browse/OCPBUGS-14392): make sync status Failure logs human-readable [#1440](https://github.com/openshift/cluster-version-operator/pull/1440)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/97ee3b743cc3eadf2e53252910a5d54c207c6d49...697ea9314e3e5c39b218b8781b32813b0e4ae84c)
### [console](https://github.com/openshift/console/tree/a5af6d5d69b83b6165b50ab42b8c9df4548c87d2)
* [OCPBUGS-109632](https://issues.redhat.com/browse/OCPBUGS-109632): Fix webhook creation in Git for PAC [#17078](https://github.com/openshift/console/pull/17078)
* NO-JIRA: fix session-persistence tests failing due to pre-loaded storageState [#17121](https://github.com/openshift/console/pull/17121)
* [CONSOLE-5002](https://issues.redhat.com/browse/CONSOLE-5002): re-render user preferences only when a listened key changes [#17104](https://github.com/openshift/console/pull/17104)
* [OCPBUGS-114052](https://issues.redhat.com/browse/OCPBUGS-114052): move yarn install to prow scripts [#17119](https://github.com/openshift/console/pull/17119)
* [OCPBUGS-115128](https://issues.redhat.com/browse/OCPBUGS-115128): Upgrade grpc to v1.83.2 and x/net to v0.58.0 [#17120](https://github.com/openshift/console/pull/17120)
* [RFE-9146](https://issues.redhat.com/browse/RFE-9146): Docs followup for service account impersonation [#17093](https://github.com/openshift/console/pull/17093)
* [CONSOLE-5000](https://issues.redhat.com/browse/CONSOLE-5000): Remove Redux activeNamespace in favor of NamespaceContext [#17102](https://github.com/openshift/console/pull/17102)
* NO-JIRA: Improve readability of `test-frontend` output [#17080](https://github.com/openshift/console/pull/17080)
* [OCPBUGS-112809](https://issues.redhat.com/browse/OCPBUGS-112809): Restore panic on Helm test infrastructure failure [#17077](https://github.com/openshift/console/pull/17077)
* [OCPBUGS-85646](https://issues.redhat.com/browse/OCPBUGS-85646): display operators in catalog when Tech Preview enabled [#16976](https://github.com/openshift/console/pull/16976)
* [OCPBUGS-95590](https://issues.redhat.com/browse/OCPBUGS-95590): Hide Builds nav section when Build capability is disabled [#16891](https://github.com/openshift/console/pull/16891)
* [CONSOLE-5001](https://issues.redhat.com/browse/CONSOLE-5001): Remove ImmutableJS [#17024](https://github.com/openshift/console/pull/17024)
* [OCPBUGS-105603](https://issues.redhat.com/browse/OCPBUGS-105603): Strip version tag from OCI chart URL to prevent doubl… [#16999](https://github.com/openshift/console/pull/16999)
* [OCPBUGS-99884](https://issues.redhat.com/browse/OCPBUGS-99884): Fix "Set as default" StorageClass action [#17066](https://github.com/openshift/console/pull/17066)
* [OCPBUGS-112462](https://issues.redhat.com/browse/OCPBUGS-112462): Remove empty integration-tests package from CI [#17064](https://github.com/openshift/console/pull/17064)
* [OCPBUGS-52186](https://issues.redhat.com/browse/OCPBUGS-52186): Show CPU/Memory metrics for non-admin users on Projects page [#17001](https://github.com/openshift/console/pull/17001)
* [OCPBUGS-111698](https://issues.redhat.com/browse/OCPBUGS-111698): Migrate app/ Cypress e2e tests to Playwright [#17015](https://github.com/openshift/console/pull/17015)
* [OCPBUGS-112046](https://issues.redhat.com/browse/OCPBUGS-112046): fix Helm test flake by detecting dead processes early [#17039](https://github.com/openshift/console/pull/17039)
* [CONSOLE-5463](https://issues.redhat.com/browse/CONSOLE-5463): Turn on react compiler linting rules [#17032](https://github.com/openshift/console/pull/17032)
* [OCPBUGS-75963](https://issues.redhat.com/browse/OCPBUGS-75963): Fix Edit Machine count action on MachineSet details page [#17038](https://github.com/openshift/console/pull/17038)
* [OCPBUGS-95597](https://issues.redhat.com/browse/OCPBUGS-95597): Fix UI validation for private Bitbucket repositories [#17028](https://github.com/openshift/console/pull/17028)
* [OCPBUGS-111634](https://issues.redhat.com/browse/OCPBUGS-111634): Keep OLS cluster-update prompts within OpenAI 32k limit [#17018](https://github.com/openshift/console/pull/17018)
* [OCPBUGS-111699](https://issues.redhat.com/browse/OCPBUGS-111699): Migrate secrets e2e tests from Cypress to Playwright [#17006](https://github.com/openshift/console/pull/17006)
* [CONSOLE-5159](https://issues.redhat.com/browse/CONSOLE-5159), [OCPBUGS-95606](https://issues.redhat.com/browse/OCPBUGS-95606): Replace deprecated Node10 moduleResolution with Bundler for TS6 compatibility [#16259](https://github.com/openshift/console/pull/16259)
* [OCPBUGS-111929](https://issues.redhat.com/browse/OCPBUGS-111929): Fix plugin entrypoint failing to load [#17027](https://github.com/openshift/console/pull/17027)
* [HELM-827](https://issues.redhat.com/browse/HELM-827): Add RTL unit tests for 9 critical Helm plugin components [#16909](https://github.com/openshift/console/pull/16909)
* NO-JIRA: add myself to owners and add frontend owners to .claude [#17025](https://github.com/openshift/console/pull/17025)
* [OCPBUGS-86298](https://issues.redhat.com/browse/OCPBUGS-86298): Fix missing Impersonate action on RoleBinding detail page [#16783](https://github.com/openshift/console/pull/16783)
* [OCPBUGS-86294](https://issues.redhat.com/browse/OCPBUGS-86294): Fix MachineAutoscaler modal crash when opened from detail page [#16781](https://github.com/openshift/console/pull/16781)
* [OCPBUGS-86511](https://issues.redhat.com/browse/OCPBUGS-86511): Fix flaky TestAsyncCache backend test [#17009](https://github.com/openshift/console/pull/17009)
* [OCPBUGS-111644](https://issues.redhat.com/browse/OCPBUGS-111644): Shared Playwright e2e context and test generation skill [#16986](https://github.com/openshift/console/pull/16986)
* [CONSOLE-5003](https://issues.redhat.com/browse/CONSOLE-5003): reimplement and enable jest linting [#17019](https://github.com/openshift/console/pull/17019)
* [OCPBUGS-95594](https://issues.redhat.com/browse/OCPBUGS-95594): make cloud provider fields optional during operator install [#16927](https://github.com/openshift/console/pull/16927)
* [OCPBUGS-14473](https://issues.redhat.com/browse/OCPBUGS-14473): Guard against undefined data in dashboard charts [#16952](https://github.com/openshift/console/pull/16952)
* Fix for OCPBUGS-104441: CVE-2026-69152 [#16937](https://github.com/openshift/console/pull/16937)
* [CONSOLE-5040](https://issues.redhat.com/browse/CONSOLE-5040): Detangle TableColumn and ConsoleDataViewColumn [#16984](https://github.com/openshift/console/pull/16984)
* [CONSOLE-5451](https://issues.redhat.com/browse/CONSOLE-5451): Display projected volume sources with navigable links in Volumes table [#16924](https://github.com/openshift/console/pull/16924)
* [OCPBUGS-109592](https://issues.redhat.com/browse/OCPBUGS-109592): Bump to @rspack/core 2.1.10 [#16978](https://github.com/openshift/console/pull/16978)
* [CONSOLE-5132](https://issues.redhat.com/browse/CONSOLE-5132): Migrate console plugins table to DataView [#16942](https://github.com/openshift/console/pull/16942)
* [OCPBUGS-106132](https://issues.redhat.com/browse/OCPBUGS-106132): fix gap in data view checkbox col [#16964](https://github.com/openshift/console/pull/16964)
* [CONSOLE-5438](https://issues.redhat.com/browse/CONSOLE-5438): Expose `ResourceYAMLEditor` `onCancel` to the SDK [#16941](https://github.com/openshift/console/pull/16941)
* [OCPBUGS-105598](https://issues.redhat.com/browse/OCPBUGS-105598): Bump to @rspack/core 2.1.9 and drop "megahard" packages [#16950](https://github.com/openshift/console/pull/16950)
* [OCPBUGS-70112](https://issues.redhat.com/browse/OCPBUGS-70112): Add Cache-Control headers to console responses [#16923](https://github.com/openshift/console/pull/16923)
* [OCPBUGS-105519](https://issues.redhat.com/browse/OCPBUGS-105519): Fix flaky e2e tests missing warmupSPA [#16939](https://github.com/openshift/console/pull/16939)
* [OCPBUGS-98943](https://issues.redhat.com/browse/OCPBUGS-98943): Make developerCatalog.types matching case-insensitive [#16876](https://github.com/openshift/console/pull/16876)
* [OCPBUGS-105517](https://issues.redhat.com/browse/OCPBUGS-105517): Fix flaky search.spec.ts Playwright e2e tests [#16938](https://github.com/openshift/console/pull/16938)
* [OCPBUGS-95592](https://issues.redhat.com/browse/OCPBUGS-95592): Humanize memory and storage values in ResourceQuota display [#16874](https://github.com/openshift/console/pull/16874)
* [CONSOLE-5428](https://issues.redhat.com/browse/CONSOLE-5428): follow up la migration du i18next-cli [#16926](https://github.com/openshift/console/pull/16926)
* [OCPBUGS-67295](https://issues.redhat.com/browse/OCPBUGS-67295): Fix icon display for duplicate operator names from different catalogs [#16898](https://github.com/openshift/console/pull/16898)
* [OCPBUGS-81511](https://issues.redhat.com/browse/OCPBUGS-81511): Remove unscoped CSV watch from ClusterNotUpgradeableAlert [#16904](https://github.com/openshift/console/pull/16904)
* NO-JIRA: Add ReadWriteOncePod support for Cinder CSI driver [#16870](https://github.com/openshift/console/pull/16870)
* And 12 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/1fbc1a87fdfe55253664dce9a37021dbb8c18284...a5af6d5d69b83b6165b50ab42b8c9df4548c87d2)
### [console-operator](https://github.com/openshift/console-operator/tree/c285c672c5928a66775051de5cc0b99c90cfac41)
* [OCPBUGS-71237](https://issues.redhat.com/browse/OCPBUGS-71237): Generate session-secret for all auth types [#1204](https://github.com/openshift/console-operator/pull/1204)
* [OCPBUGS-58422](https://issues.redhat.com/browse/OCPBUGS-58422): Handle disabled Ingress capability in HyperShift [#1182](https://github.com/openshift/console-operator/pull/1182)
* [OCPBUGS-92204](https://issues.redhat.com/browse/OCPBUGS-92204): Clear stale OIDC degraded condition on auth type change [#1212](https://github.com/openshift/console-operator/pull/1212)
* [CNF-23047](https://issues.redhat.com/browse/CNF-23047): Migrate away from deprecated ioutil [#1072](https://github.com/openshift/console-operator/pull/1072)
* [OCPBUGS-104854](https://issues.redhat.com/browse/OCPBUGS-104854): Fix excessive DeploymentUpdated events via content hash [#1210](https://github.com/openshift/console-operator/pull/1210)
* [OCPBUGS-109670](https://issues.redhat.com/browse/OCPBUGS-109670): Derive documentationBaseURL dynamically from OPERATOR_IMAGE_VERSION [#1209](https://github.com/openshift/console-operator/pull/1209)
* [OCPBUGS-109419](https://issues.redhat.com/browse/OCPBUGS-109419): Bump documentationBaseURL to 5.0 [#1207](https://github.com/openshift/console-operator/pull/1207)
* [OCPBUGS-77026](https://issues.redhat.com/browse/OCPBUGS-77026): DNS optimization, add trailing dots [#1112](https://github.com/openshift/console-operator/pull/1112)
* [OCPBUGS-95602](https://issues.redhat.com/browse/OCPBUGS-95602): Add OpenShift Quickstart for JBoss EAP 8 [#932](https://github.com/openshift/console-operator/pull/932)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console-operator/compare/684157180b1dfeb4a5106c669da1ac42258372ec...c285c672c5928a66775051de5cc0b99c90cfac41)
### [container-networking-plugins, containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins/tree/b0bea6bcba28cab2ffa15da03cbae98805af7eca)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#228](https://github.com/openshift/containernetworking-plugins/pull/228)
* [Full changelog](https://github.com/openshift/containernetworking-plugins/compare/d6f73950658d258e0ddbf2a4ac92e13ac840158b...b0bea6bcba28cab2ffa15da03cbae98805af7eca)
### [docker-registry](https://github.com/openshift/image-registry/tree/823010aa7b0dcf1da53a26c2ec135d0a32e63d85)
* [OCPBUGS-99398](https://issues.redhat.com/browse/OCPBUGS-99398): Fix resolveUpstreamRef to properly propagate not-found errors [#475](https://github.com/openshift/image-registry/pull/475)
* [Full changelog](https://github.com/openshift/image-registry/compare/a91ce6edf2c5cc08aa184c47dff79e842079c533...823010aa7b0dcf1da53a26c2ec135d0a32e63d85)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/49554e572efac19f660a00ecfe2ccbc4e84be1e0)
* [OCPBUGS-105251](https://issues.redhat.com/browse/OCPBUGS-105251): Update Dockerfiles [#111](https://github.com/openshift/egress-router-cni/pull/111)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/7b9f54aff1a90ba59242b305fb628db9f20d1d2c...49554e572efac19f660a00ecfe2ccbc4e84be1e0)
### [etcd](https://github.com/openshift/etcd/tree/609b11ed8fc404fb95572d7c87e3243a1206cdb7)
* DOWNSTREAM: carry: OCPBUGS-103516: Replace bbolt with patched fork to remove MADV_RANDOM [#395](https://github.com/openshift/etcd/pull/395)
* [Full changelog](https://github.com/openshift/etcd/compare/3688f53af36d9412ab3d99c86d66aafbfb711e7f...609b11ed8fc404fb95572d7c87e3243a1206cdb7)
### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/5c3d894654ec0316347b26fb586a074bab160b2e)
* UPSTREAM-SYNC: Merge https://github.com/kubernetes-sigs/cluster-api-provider-gcp:v1.13.1 (8198b8b) into main [#302](https://github.com/openshift/cluster-api-provider-gcp/pull/302)
* [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/dbcbfe70efa75f192309f2d0f8daae2c6a441e90...5c3d894654ec0316347b26fb586a074bab160b2e)
### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/aac3d11bb011778fbb4f7717c59c18f617f82ad1)
* [OCPBUGS-82191](https://issues.redhat.com/browse/OCPBUGS-82191): Wait for RUNNING before providerID; retry stockout [#160](https://github.com/openshift/machine-api-provider-gcp/pull/160)
* [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/91033fc5b42f58acdad7be8c89a0012f5f2c9b5b...aac3d11bb011778fbb4f7717c59c18f617f82ad1)
### [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver/tree/049c0b96742c40fdd4384920afe17cefa5fa3d27)
* [STOR-3064](https://issues.redhat.com/browse/STOR-3064): Add Universe Domain Support (for Google Cloud Dedicated) [#126](https://github.com/openshift/gcp-pd-csi-driver/pull/126)
* [Full changelog](https://github.com/openshift/gcp-pd-csi-driver/compare/2dad9ff88511cc4e82a777c49ec55cbed2e3a057...049c0b96742c40fdd4384920afe17cefa5fa3d27)
### [haproxy-router, haproxy-router-haproxy28, haproxy-router-haproxy32](https://github.com/openshift/router/tree/3381229146657d2e6bd94115dda0885f25cb3bed)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Make external cert validation asynchronous (v3 — fix re-admission after secret deletion) [#828](https://github.com/openshift/router/pull/828)
* [Full changelog](https://github.com/openshift/router/compare/4b401a86dccc657a8a5254c2794a312241f40e87...3381229146657d2e6bd94115dda0885f25cb3bed)
### [hyperkube, kube-proxy, pod](https://github.com/openshift/kubernetes/tree/fb553cd105957b64651b393cb1a42f59faab190e)
* NO-JIRA: Make graceful-termination-duration flag required for the watch-termination command [#2761](https://github.com/openshift/kubernetes/pull/2761)
* [OCPBUGS-100170](https://issues.redhat.com/browse/OCPBUGS-100170): Rebase master to v1.36.3 [#2746](https://github.com/openshift/kubernetes/pull/2746)
* [OCPBUGS-64847](https://issues.redhat.com/browse/OCPBUGS-64847): kubelet: don't use non-admitted pods in calculation [#2667](https://github.com/openshift/kubernetes/pull/2667)
* [Full changelog](https://github.com/openshift/kubernetes/compare/e63ab41237b34f2a457e76900f6162184420cf96...fb553cd105957b64651b393cb1a42f59faab190e)
### [hypershift](https://github.com/openshift/hypershift/tree/813b57efa2caeb867d8ff3b9f3f0603651402dff)
* NO-JIRA: Migrate hypershift-ci-python and contrib/oidc to uv for managing python deps [#9442](https://github.com/openshift/hypershift/pull/9442)
* [GCP-421](https://issues.redhat.com/browse/GCP-421): feat(install): bump external-dns to 1.3.5 and bundle DNSEndpoint CRD [#9433](https://github.com/openshift/hypershift/pull/9433)
* NO-JIRA: test(e2e/v2): add upsert desired-state-hash E2E tests [#9257](https://github.com/openshift/hypershift/pull/9257)
* [RFE-9138](https://issues.redhat.com/browse/RFE-9138): feat: label some hosted control plane services [#8298](https://github.com/openshift/hypershift/pull/8298)
* [OCPBUGS-109595](https://issues.redhat.com/browse/OCPBUGS-109595): use RetryWatcher and TCP keepalive for create-guests watch resilience [#9435](https://github.com/openshift/hypershift/pull/9435)
* [OCPBUGS-95614](https://issues.redhat.com/browse/OCPBUGS-95614): fix(cpo): include unavailable components in KASLoadBalancerNotReachable message [#9232](https://github.com/openshift/hypershift/pull/9232)
* [OCPBUGS-114014](https://issues.redhat.com/browse/OCPBUGS-114014): add Agent CAPI pause step to cross-cluster migration [#9416](https://github.com/openshift/hypershift/pull/9416)
* [CNTRLPLANE-4216](https://issues.redhat.com/browse/CNTRLPLANE-4216): Migrate Azure VM instance families to Dsv5 [#9423](https://github.com/openshift/hypershift/pull/9423)
* [CNTRLPLANE-4006](https://issues.redhat.com/browse/CNTRLPLANE-4006): fix(e2e) disable client-side rate limiting and increase NodePool config timeout [#9331](https://github.com/openshift/hypershift/pull/9331)
* [CNTRLPLANE-4004](https://issues.redhat.com/browse/CNTRLPLANE-4004): test(envtest): add CEL validation tests for AWS resource tag types [#9375](https://github.com/openshift/hypershift/pull/9375)
* [OCPBUGS-86669](https://issues.redhat.com/browse/OCPBUGS-86669): fix(cli): make deleteCLISecrets non-fatal during cluster destroy [#8787](https://github.com/openshift/hypershift/pull/8787)
* [CNTRLPLANE-3999](https://issues.redhat.com/browse/CNTRLPLANE-3999): add declarative TestPlan for composing v2 cluster variants and test matrices [#9420](https://github.com/openshift/hypershift/pull/9420)
* NO-JIRA: test(e2e): allow more time for control plane pod restarts [#9422](https://github.com/openshift/hypershift/pull/9422)
* [OCPBUGS-113580](https://issues.redhat.com/browse/OCPBUGS-113580): Bound NodePool metrics cache reads [#9389](https://github.com/openshift/hypershift/pull/9389)
* NO-JIRA: Makefile: fix PULL_BASE_SHA leading space breaking local verify [#9395](https://github.com/openshift/hypershift/pull/9395)
* [OCPBUGS-97811](https://issues.redhat.com/browse/OCPBUGS-97811): fix Tenant API downtime during a management worker node [#9279](https://github.com/openshift/hypershift/pull/9279)
* NO-JIRA: Run lint and vet against all build tags [#9427](https://github.com/openshift/hypershift/pull/9427)
* [OCPBUGS-114265](https://issues.redhat.com/browse/OCPBUGS-114265): Use managemet cluster kubeconfig for CAPI migration test [#9412](https://github.com/openshift/hypershift/pull/9412)
* [OCPBUGS-100142](https://issues.redhat.com/browse/OCPBUGS-100142): fix(konnectivity): fallback to alternative DNS-resolved IPs on connection failure [#9181](https://github.com/openshift/hypershift/pull/9181)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): migrate CPO status patches to statuspatching helpers [#8966](https://github.com/openshift/hypershift/pull/8966)
* [OCPSTRAT-3686](https://issues.redhat.com/browse/OCPSTRAT-3686): Add pipeline for nightly release tag process [#9371](https://github.com/openshift/hypershift/pull/9371)
* [OCPBUGS-111601](https://issues.redhat.com/browse/OCPBUGS-111601): Fix v2 control plane upgrade rollout race [#9384](https://github.com/openshift/hypershift/pull/9384)
* [CNTRLPLANE-2883](https://issues.redhat.com/browse/CNTRLPLANE-2883): Migrate ARM64 NodePool creation test to v2 [#8926](https://github.com/openshift/hypershift/pull/8926)
* [CNTRLPLANE-4115](https://issues.redhat.com/browse/CNTRLPLANE-4115): fix(ci): report actionable cause when /rebase push hits workflow files [#9358](https://github.com/openshift/hypershift/pull/9358)
* [OCPBUGS-113991](https://issues.redhat.com/browse/OCPBUGS-113991): Scope forced NodePool cleanup to the target cluster [#9398](https://github.com/openshift/hypershift/pull/9398)
* [CNTRLPLANE-1831](https://issues.redhat.com/browse/CNTRLPLANE-1831): address review feedback on DR documentation [#9407](https://github.com/openshift/hypershift/pull/9407)
* [OCPBUGS-98467](https://issues.redhat.com/browse/OCPBUGS-98467): fix(konnectivity): enable --sync-forever to restore lost agent-server tunnels [#9260](https://github.com/openshift/hypershift/pull/9260)
* [CNTRLPLANE-3616](https://issues.redhat.com/browse/CNTRLPLANE-3616): e2e tests for TLS profile change of konnectivity-server [#8886](https://github.com/openshift/hypershift/pull/8886)
* [CNTRLPLANE-3626](https://issues.redhat.com/browse/CNTRLPLANE-3626): feat(ignition-server, ignition-server-proxy): inject centralized TLS configuration [#8910](https://github.com/openshift/hypershift/pull/8910)
* [OCPBUGS-112450](https://issues.redhat.com/browse/OCPBUGS-112450): introduce e2e v2 linting rules and enforcement [#9357](https://github.com/openshift/hypershift/pull/9357)
* [CNTRLPLANE-1831](https://issues.redhat.com/browse/CNTRLPLANE-1831): restructure backup/restore disaster recovery documentation [#9382](https://github.com/openshift/hypershift/pull/9382)
* [ACM-42704](https://issues.redhat.com/browse/ACM-42704): Add Konflux MCE 5.1 pipelines for hypershift CLI and operator [#9396](https://github.com/openshift/hypershift/pull/9396)
* [OCPBUGS-111601](https://issues.redhat.com/browse/OCPBUGS-111601): Prevent conversion webhook startup deadlock [#9387](https://github.com/openshift/hypershift/pull/9387)
* [ROSAENG-14082](https://issues.redhat.com/browse/ROSAENG-14082): --dump-guest-cluster option can now optionally be supplied with policies [#8882](https://github.com/openshift/hypershift/pull/8882)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): port core karpenter autonode e2e tests to v2 framework [#9292](https://github.com/openshift/hypershift/pull/9292)
* [GCP-916](https://issues.redhat.com/browse/GCP-916): allow goog-partner-solution label key in GCP resourceLabels [#9267](https://github.com/openshift/hypershift/pull/9267)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default [#9328](https://github.com/openshift/hypershift/pull/9328)
* [CNTRLPLANE-3903](https://issues.redhat.com/browse/CNTRLPLANE-3903): Add unit test for hcp version command [#9218](https://github.com/openshift/hypershift/pull/9218)
* [OCPBUGS-111985](https://issues.redhat.com/browse/OCPBUGS-111985), [OCPBUGS-111986](https://issues.redhat.com/browse/OCPBUGS-111986): bump haproxy to 3.0.5-6.el10_2.2 to fix CVE-2026-55203 and CVE-2026-55204 [#9333](https://github.com/openshift/hypershift/pull/9333)
* [OCPBUGS-112328](https://issues.redhat.com/browse/OCPBUGS-112328): Clear SSHKey from HCP and delete synced secret when HC SSHKey is removed [#9374](https://github.com/openshift/hypershift/pull/9374)
* [CNTRLPLANE-4169](https://issues.redhat.com/browse/CNTRLPLANE-4169): Add GHA envtest jobs for Kubernetes 1.36 [#9353](https://github.com/openshift/hypershift/pull/9353)
* [CNTRLPLANE-3604](https://issues.redhat.com/browse/CNTRLPLANE-3604): Capi v1beta2 storage migration [#8938](https://github.com/openshift/hypershift/pull/8938)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): migrate HO karpenter status patch to statuspatching helper [#8968](https://github.com/openshift/hypershift/pull/8968)
* no-jira: add karpenter-operator dev image override annotation [#9295](https://github.com/openshift/hypershift/pull/9295)
* [CNTRLPLANE-4025](https://issues.redhat.com/browse/CNTRLPLANE-4025): feat(azure): support managed HSM for KMS encryption [#9199](https://github.com/openshift/hypershift/pull/9199)
* [OCPBUGS-44164](https://issues.redhat.com/browse/OCPBUGS-44164): Fix TestNodePoolReplaceUpgrade flaky timeout on OpenStack [#8749](https://github.com/openshift/hypershift/pull/8749)
* revert: OCPBUGS-112478: fix(cpo): handle service-ca generation errors in CSI serving cert reconciliation [#9365](https://github.com/openshift/hypershift/pull/9365)
* [CNTRLPLANE-3954](https://issues.redhat.com/browse/CNTRLPLANE-3954): add kube-scheduler metrics endpoint e2e coverage [#9159](https://github.com/openshift/hypershift/pull/9159)
* NO-JIRA: align aws_test.go test case names with testcasename linter [#9367](https://github.com/openshift/hypershift/pull/9367)
* [CNTRLPLANE-4003](https://issues.redhat.com/browse/CNTRLPLANE-4003): Add per-tag override field for AWS resource tag precedence [#9152](https://github.com/openshift/hypershift/pull/9152)
* [OCPBUGS-97705](https://issues.redhat.com/browse/OCPBUGS-97705): fix(azure): skip KMS validation for private Key Vaults on ARO HCP [#8965](https://github.com/openshift/hypershift/pull/8965)
* chore: add .pi symlink for Claude Code skill discovery [#9361](https://github.com/openshift/hypershift/pull/9361)
* [OCPBUGS-85182](https://issues.redhat.com/browse/OCPBUGS-85182): Remove MutatingAdmissionPolicy runtime-config from KAS [#9350](https://github.com/openshift/hypershift/pull/9350)
* [OCPBUGS-86771](https://issues.redhat.com/browse/OCPBUGS-86771): docs(api): document issuerURL immutability and serviceAccountIssuer override [#8916](https://github.com/openshift/hypershift/pull/8916)
* NO-JIRA: chore(owners): add members to core-reviewers [#9352](https://github.com/openshift/hypershift/pull/9352)
* [OCPBUGS-85065](https://issues.redhat.com/browse/OCPBUGS-85065): Fix repeated CPO Deployment churn due to OPENSHIFT_IMG_OVERRIDES reordering [#8656](https://github.com/openshift/hypershift/pull/8656)
* NO-JIRA: align GCP creds metric test case names with testcasename linter [#9351](https://github.com/openshift/hypershift/pull/9351)
* [GCP-959](https://issues.redhat.com/browse/GCP-959): Add GCP PSC conditions to metrics and add platform-specific gauges [#9258](https://github.com/openshift/hypershift/pull/9258)
* [CNTRLPLANE-3899](https://issues.redhat.com/browse/CNTRLPLANE-3899): Add shared cmd/ unit tests for create nodepool agent [#9162](https://github.com/openshift/hypershift/pull/9162)
* [CNTRLPLANE-4008](https://issues.redhat.com/browse/CNTRLPLANE-4008): enable hypershiftlinter and fix test naming [#9271](https://github.com/openshift/hypershift/pull/9271)
* [OCPBUGS-86670](https://issues.redhat.com/browse/OCPBUGS-86670): fix(cpo): handle service-ca generation errors in CSI serving cert reconciliation [#8622](https://github.com/openshift/hypershift/pull/8622)
* [OCPBUGS-105194](https://issues.redhat.com/browse/OCPBUGS-105194): Add retry with exponential back-off for transient dump errors [#9303](https://github.com/openshift/hypershift/pull/9303)
* [CNTRLPLANE-4041](https://issues.redhat.com/browse/CNTRLPLANE-4041): fix(build): bump missed second-stage base image in Dockerfile.e2e to 5.1 [#9345](https://github.com/openshift/hypershift/pull/9345)
* [CNTRLPLANE-4026](https://issues.redhat.com/browse/CNTRLPLANE-4026): fix(ci): Enable Dependabot to track and automate GHA runner image updates [#9330](https://github.com/openshift/hypershift/pull/9330)
* [CNTRLPLANE-4041](https://issues.redhat.com/browse/CNTRLPLANE-4041): bump base images in dockerfiles to 5.1 [#9325](https://github.com/openshift/hypershift/pull/9325)
* NO-JIRA: fix(ci): update restructure-commits workflow path after skills migration [#9335](https://github.com/openshift/hypershift/pull/9335)
* [CNTRLPLANE-4115](https://issues.redhat.com/browse/CNTRLPLANE-4115): Revert invalid workflows permission from rebase.yaml [#9329](https://github.com/openshift/hypershift/pull/9329)
* [OCPBUGS-99550](https://issues.redhat.com/browse/OCPBUGS-99550): Managed Azure setup_aks_cluster.sh fails to run with "--kubernetes-version 1.33.0" flag [#9080](https://github.com/openshift/hypershift/pull/9080)
* [OCPBUGS-105282](https://issues.redhat.com/browse/OCPBUGS-105282): Add proxy env vars to cluster-storage-operator deployment [#9256](https://github.com/openshift/hypershift/pull/9256)
* [CNTRLPLANE-4115](https://issues.redhat.com/browse/CNTRLPLANE-4115): Fix /rebase workflow: add missing workflows permission [#9323](https://github.com/openshift/hypershift/pull/9323)
* NO-JIRA: Convert Claude commands to agentskills.io skill format for harness portability [#9062](https://github.com/openshift/hypershift/pull/9062)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): add [FeatureGate:OSStreams] tag for FG promotion tracking [#9297](https://github.com/openshift/hypershift/pull/9297)
* [OCPBUGS-83564](https://issues.redhat.com/browse/OCPBUGS-83564): Apply registry overrides to release image pullspec before fetching [#9108](https://github.com/openshift/hypershift/pull/9108)
* [CNTRLPLANE-4008](https://issues.redhat.com/browse/CNTRLPLANE-4008): feat: add hypershiftlinter golangci-lint plugin [#9237](https://github.com/openshift/hypershift/pull/9237)
* [OCPBUGS-105875](https://issues.redhat.com/browse/OCPBUGS-105875): fix(hcco): run kas-connection-checker as non-root [#9296](https://github.com/openshift/hypershift/pull/9296)
* [ARO-26896](https://issues.redhat.com/browse/ARO-26896): feat: hardcode ETCD_METRICS=extensive in etcd StatefulSet template [#9192](https://github.com/openshift/hypershift/pull/9192)
* [OCPBUGS-105802](https://issues.redhat.com/browse/OCPBUGS-105802): Use the correct v1 mcfg api for OSImageStream during ignition [#9283](https://github.com/openshift/hypershift/pull/9283)
* [CNTRLPLANE-4043](https://issues.redhat.com/browse/CNTRLPLANE-4043): ci(e2e): add CI workflow to verify e2e compilation on PRs [#9305](https://github.com/openshift/hypershift/pull/9305)
* [OCPBUGS-108268](https://issues.redhat.com/browse/OCPBUGS-108268): Rebase container images from 9.7 to 9.8 to fix gnutls CVEs [#9307](https://github.com/openshift/hypershift/pull/9307)
* [CNTRLPLANE-4097](https://issues.redhat.com/browse/CNTRLPLANE-4097): Add clebs to core-approvers [#9316](https://github.com/openshift/hypershift/pull/9316)
* [OCPBUGS-109581](https://issues.redhat.com/browse/OCPBUGS-109581): Add CVO and CNO to podCrashTolerations [#9302](https://github.com/openshift/hypershift/pull/9302)
* [OCPBUGS-99898](https://issues.redhat.com/browse/OCPBUGS-99898): Add unit test for aggregateMachineMessages truncation logic [#9128](https://github.com/openshift/hypershift/pull/9128)
* [OCPBUGS-98460](https://issues.redhat.com/browse/OCPBUGS-98460): Harden leader election failure detection in EnsureNoCrashingPods [#9129](https://github.com/openshift/hypershift/pull/9129)
* [CNTRLPLANE-3772](https://issues.redhat.com/browse/CNTRLPLANE-3772): promote ExternalOIDCWithUpstreamParity to Default [#8952](https://github.com/openshift/hypershift/pull/8952)
* NO-JIRA: Update Konflux Tekton task bundle digests [#9300](https://github.com/openshift/hypershift/pull/9300)
* [CNTRLPLANE-3202](https://issues.redhat.com/browse/CNTRLPLANE-3202): add restore, OADP, and limitations docs for self-managed Azure DR [#9160](https://github.com/openshift/hypershift/pull/9160)
* [CNTRLPLANE-4038](https://issues.redhat.com/browse/CNTRLPLANE-4038): feat(supportedversion): bump latest supported OCP version to 5.1 [#9288](https://github.com/openshift/hypershift/pull/9288)
* [OCPBUGS-105865](https://issues.redhat.com/browse/OCPBUGS-105865): fix(nodepool): include only TLSSecurityProfile in config hash instead of full APIServer [#9287](https://github.com/openshift/hypershift/pull/9287)
* [AUTOSCALE-871](https://issues.redhat.com/browse/AUTOSCALE-871): add deployment path for standalone karpenter-operator [#9245](https://github.com/openshift/hypershift/pull/9245)
* [GCP-986](https://issues.redhat.com/browse/GCP-986): chore: add acwalczyk to gcp-reviewers alias [#9222](https://github.com/openshift/hypershift/pull/9222)
* NO-JIRA: Disable repo_gpgcheck for Microsoft repo in Dockerfile.e2e [#9290](https://github.com/openshift/hypershift/pull/9290)
* [CNTRLPLANE-3863](https://issues.redhat.com/browse/CNTRLPLANE-3863): improve v2 test isolation [#9229](https://github.com/openshift/hypershift/pull/9229)
* NO-JIRA: feat(ci): split CI report into ARO HCP, KubeVirt, and Azure Self-Managed categories [#9282](https://github.com/openshift/hypershift/pull/9282)
* [OCPBUGS-101766](https://issues.redhat.com/browse/OCPBUGS-101766): enable TLSAdherence feature gate part on TechPreviewNoUpgrade [#9213](https://github.com/openshift/hypershift/pull/9213)
* [OCPBUGS-96908](https://issues.redhat.com/browse/OCPBUGS-96908): remove redhat-marketplace catalog from HyperShift [#8958](https://github.com/openshift/hypershift/pull/8958)
* [OCPBUGS-105555](https://issues.redhat.com/browse/OCPBUGS-105555): Update ubi-minimal base image to fix glib2 CVEs (CVE-2025-14087, CVE-2025-14512) [#9276](https://github.com/openshift/hypershift/pull/9276)
* [OCPBUGS-98065](https://issues.redhat.com/browse/OCPBUGS-98065): Prevent infraID and clusterID removal via parent-level CEL rules [#9102](https://github.com/openshift/hypershift/pull/9102)
* [OCPBUGS-105849](https://issues.redhat.com/browse/OCPBUGS-105849): Remove docs/compare tooling to fix Snyk security scan [#9285](https://github.com/openshift/hypershift/pull/9285)
* [CNTRLPLANE-3945](https://issues.redhat.com/browse/CNTRLPLANE-3945): fix(docs): set writable uv cache path for arc-runner-set [#9281](https://github.com/openshift/hypershift/pull/9281)
* [CNTRLPLANE-3945](https://issues.redhat.com/browse/CNTRLPLANE-3945): Migrate documentation tooling from mkdocs-material to zensical [#9139](https://github.com/openshift/hypershift/pull/9139)
* NO-JIRA: fix: separate gci-only pre-commit hooks from full lint-fix targets [#9272](https://github.com/openshift/hypershift/pull/9272)
* [CNTRLPLANE-3625](https://issues.redhat.com/browse/CNTRLPLANE-3625): Add aws-pod-identity-webhook e2e tls cases [#8953](https://github.com/openshift/hypershift/pull/8953)
* [OCPBUGS-105602](https://issues.redhat.com/browse/OCPBUGS-105602): fix broken relative reference [#9277](https://github.com/openshift/hypershift/pull/9277)
* [OCPBUGS-105597](https://issues.redhat.com/browse/OCPBUGS-105597): fix(ci): update GHA runner base image to unblock CI [#9275](https://github.com/openshift/hypershift/pull/9275)
* [OCPCLOUD-3261](https://issues.redhat.com/browse/OCPCLOUD-3261): feat(cloud providers): inject centralized TLS configuration [#8864](https://github.com/openshift/hypershift/pull/8864)
* [CNTRLPLANE-3959](https://issues.redhat.com/browse/CNTRLPLANE-3959): wire apiserver config through ignition server [#9136](https://github.com/openshift/hypershift/pull/9136)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/hypershift/compare/a26a7a40e5993ceaee71154720f5bf53fe677169...813b57efa2caeb867d8ff3b9f3f0603651402dff)
### [insights-operator](https://github.com/openshift/insights-operator/tree/9bf68c79ce211fb1e16050cc20552166a89b3f34)
* [CCXDEV-16041](https://issues.redhat.com/browse/CCXDEV-16041): multiclusterhub gatherer [#1343](https://github.com/openshift/insights-operator/pull/1343)
* NO-JIRA: improve create-gatherer skill [#1348](https://github.com/openshift/insights-operator/pull/1348)
* [CCXDEV-16040](https://issues.redhat.com/browse/CCXDEV-16040): Add multicluster gatherer [#1337](https://github.com/openshift/insights-operator/pull/1337)
* [CCXDEV-16594](https://issues.redhat.com/browse/CCXDEV-16594): add custom proxy field to insights config [#1329](https://github.com/openshift/insights-operator/pull/1329)
* [Full changelog](https://github.com/openshift/insights-operator/compare/8494b69b8075fd1e8eac49db77bcda7588078155...9bf68c79ce211fb1e16050cc20552166a89b3f34)
### [insights-runtime-exporter, insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor/tree/ba3de3b9777161897b75fc5a88e179dfbe8f6c53)
* NO-JIRA: chore: add slashpai to owner list [#91](https://github.com/openshift/insights-runtime-extractor/pull/91)
* [CCXDEV-16674](https://issues.redhat.com/browse/CCXDEV-16674): chore: add clippy linting [#87](https://github.com/openshift/insights-runtime-extractor/pull/87)
* [Full changelog](https://github.com/openshift/insights-runtime-extractor/compare/d70c566bcd4a2af3825fe5cfa6383d73530d6a0f...ba3de3b9777161897b75fc5a88e179dfbe8f6c53)
### [ironic](https://github.com/openshift/ironic-image/tree/b7df7f3cb23d87efb18608919f21684b3f942297)
* [METAL-1931](https://issues.redhat.com/browse/METAL-1931): Add cargo for bcrypt rust extensions [#895](https://github.com/openshift/ironic-image/pull/895)
* [METAL-1929](https://issues.redhat.com/browse/METAL-1929): Merge upstream 2026 07 31 [#875](https://github.com/openshift/ironic-image/pull/875)
* [OKD-421](https://issues.redhat.com/browse/OKD-421): Fix Dockerfile.scos crypto-policies PQ failure on CentOS Stream 10 [#886](https://github.com/openshift/ironic-image/pull/886)
* [Full changelog](https://github.com/openshift/ironic-image/compare/e66245ac7cb2569be6e5fa67b27fad8e8c8a1ae9...b7df7f3cb23d87efb18608919f21684b3f942297)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/fa214e73446c76ea2f10470beb31028dd035d909)
* [METAL-1931](https://issues.redhat.com/browse/METAL-1931): Add cargo for bcrypt rust extensions [#303](https://github.com/openshift/ironic-agent-image/pull/303)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#300](https://github.com/openshift/ironic-agent-image/pull/300)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#299](https://github.com/openshift/ironic-agent-image/pull/299)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/6bc9a57af3931a6d5ef5e96b766c9fabcf2829b4...fa214e73446c76ea2f10470beb31028dd035d909)
### [karpenter-operator](https://github.com/openshift/karpenter-operator/tree/892b17c079251b141ee8142501798227dfa58359)
* [AUTOSCALE-998](https://issues.redhat.com/browse/AUTOSCALE-998): deploy karpenter-provider-aws on HCP [#26](https://github.com/openshift/karpenter-operator/pull/26)
* [AUTOSCALE-968](https://issues.redhat.com/browse/AUTOSCALE-968): sync AKSNodeClass CRD and add Azure cloud provider [#28](https://github.com/openshift/karpenter-operator/pull/28)
* [AUTOSCALE-906](https://issues.redhat.com/browse/AUTOSCALE-906): add agentic SDLC context files [#27](https://github.com/openshift/karpenter-operator/pull/27)
* [AUTOSCALE-976](https://issues.redhat.com/browse/AUTOSCALE-976): enable CRD controller for management cluster mode [#24](https://github.com/openshift/karpenter-operator/pull/24)
* [AUTOSCALE-872](https://issues.redhat.com/browse/AUTOSCALE-872): Implement OpenshiftEC2NodeClass objects [#25](https://github.com/openshift/karpenter-operator/pull/25)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): Apply NodeOverlay to hostedcluster during karpenter-core e2e for AWS HCP AutoNode [#22](https://github.com/openshift/karpenter-operator/pull/22)
* [AUTOSCALE-945](https://issues.redhat.com/browse/AUTOSCALE-945): add support for hosted cluster client via --target-kubeconfig [#23](https://github.com/openshift/karpenter-operator/pull/23)
* no-jira: rename guest kubeconfig back to target kubeconfig [#21](https://github.com/openshift/karpenter-operator/pull/21)
* [Full changelog](https://github.com/openshift/karpenter-operator/compare/560232d2b6962e041dc332f08026adda14552d41...892b17c079251b141ee8142501798227dfa58359)
### [keepalived-ipfailover](https://github.com/openshift/images/tree/32930575a2bb3571601a7444becc06d06e901657)
* [NE-2126](https://issues.redhat.com/browse/NE-2126): Migrating Ipfailover test cases to images repo [#245](https://github.com/openshift/images/pull/245)
* [Full changelog](https://github.com/openshift/images/compare/13118bff15103b31a6528bf8de2d0d6de05f4742...32930575a2bb3571601a7444becc06d06e901657)
### [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy/tree/0f9a53a85f8436587adbbdc58caaf89e500cd8db)
* NO-JIRA: update OWNERS [#147](https://github.com/openshift/kube-rbac-proxy/pull/147)
* NO-JIRA: Merge upstream v0.22.1 [#146](https://github.com/openshift/kube-rbac-proxy/pull/146)
* [Full changelog](https://github.com/openshift/kube-rbac-proxy/compare/43c114bc124f59e2fc3223dea8e0a8f4cdeed18d...0f9a53a85f8436587adbbdc58caaf89e500cd8db)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/08e31544b6e3af6b5e5c8dcf9b7dad2840318958)
* [SPLAT-2826](https://issues.redhat.com/browse/SPLAT-2826): Compare against oldObject in vSphere failure-domain VAPs [#1536](https://github.com/openshift/machine-api-operator/pull/1536)
* [OCPBUGS-74510](https://issues.redhat.com/browse/OCPBUGS-74510): Removed VSphereMultiDisk feature gate [#1532](https://github.com/openshift/machine-api-operator/pull/1532)
* [OCPBUGS-105407](https://issues.redhat.com/browse/OCPBUGS-105407): Remove VSphereMultiNetworks feature gate from e2e test [#1533](https://github.com/openshift/machine-api-operator/pull/1533)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/0db39ee372bf7b75f56898fd2df555e063d32952...08e31544b6e3af6b5e5c8dcf9b7dad2840318958)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/e7e6abbd38052da7edbb1a01bf0548d2bb03468b)
* [OCPBUGS-109659](https://issues.redhat.com/browse/OCPBUGS-109659): Check conddegraded nil before dereference in TestCalculateStatus [#6462](https://github.com/openshift/machine-config-operator/pull/6462)
* [OCPBUGS-69681](https://issues.redhat.com/browse/OCPBUGS-69681): limit ContainerRuntimeConfig status condition to 3 [#6434](https://github.com/openshift/machine-config-operator/pull/6434)
* [OCPBUGS-111648](https://issues.redhat.com/browse/OCPBUGS-111648): crio: drop restore support [#6412](https://github.com/openshift/machine-config-operator/pull/6412)
* [OCPBUGS-112043](https://issues.redhat.com/browse/OCPBUGS-112043): Preserve proxy environment vars [#6424](https://github.com/openshift/machine-config-operator/pull/6424)
* [OPNET-679](https://issues.redhat.com/browse/OPNET-679): grant NET_ADMIN capability to coredns-monitor [#6449](https://github.com/openshift/machine-config-operator/pull/6449)
* [OCPEDGE-2984](https://issues.redhat.com/browse/OCPEDGE-2984): fix: adjust fencing validator to match MAC-address based credential secrets [#6450](https://github.com/openshift/machine-config-operator/pull/6450)
* [OCPBUGS-112465](https://issues.redhat.com/browse/OCPBUGS-112465): Update the MachineOSBuild event and condition functionality to more clearly handle pod failures with retries [#6431](https://github.com/openshift/machine-config-operator/pull/6431)
* [OCPBUGS-112784](https://issues.redhat.com/browse/OCPBUGS-112784): Revert TNF Graceful node shutdown [#6442](https://github.com/openshift/machine-config-operator/pull/6442)
* [OCPBUGS-105399](https://issues.redhat.com/browse/OCPBUGS-105399): Remove SigstoreImageVerification feature gate references [#6445](https://github.com/openshift/machine-config-operator/pull/6445)
* [OCPBUGS-64623](https://issues.redhat.com/browse/OCPBUGS-64623): Use kubernetes scheme in drain controller event recorder [#6446](https://github.com/openshift/machine-config-operator/pull/6446)
* [OCPNODE-4526](https://issues.redhat.com/browse/OCPNODE-4526): Add '..' block, max-length, and cross-store uniqueness [#6433](https://github.com/openshift/machine-config-operator/pull/6433)
* [OCPBUGS-100065](https://issues.redhat.com/browse/OCPBUGS-100065): on-prem: tune API VIP haproxy health checks [#6400](https://github.com/openshift/machine-config-operator/pull/6400)
* [OCPBUGS-109746](https://issues.redhat.com/browse/OCPBUGS-109746): OCPBUGS-112085: CORS-4441: Bootimage controller should gracefully handle Azure gen1 image removal [#6404](https://github.com/openshift/machine-config-operator/pull/6404)
* NO-ISSUE: Extend timeout for waiting for `UpdatePrepared` MCN condition for SNO resiliency [#6428](https://github.com/openshift/machine-config-operator/pull/6428)
* [OCPBUGS-98258](https://issues.redhat.com/browse/OCPBUGS-98258): Fix upstreams for CoreDNS pods on Cloud platforms [#6383](https://github.com/openshift/machine-config-operator/pull/6383)
* NO-JIRA: Skip OVN-K VRFs in ofport-request dispatcher script [#6398](https://github.com/openshift/machine-config-operator/pull/6398)
* [OCPBUGS-109739](https://issues.redhat.com/browse/OCPBUGS-109739): Increase rpm-ostree rebase retry backoff and preserve error [#6413](https://github.com/openshift/machine-config-operator/pull/6413)
* [OCPBUGS-112075](https://issues.redhat.com/browse/OCPBUGS-112075): skip proxy for OSImageStream discovery in HyperShift [#6420](https://github.com/openshift/machine-config-operator/pull/6420)
* [OCPBUGS-65504](https://issues.redhat.com/browse/OCPBUGS-65504): machine-config ClusterOperator relatedObjects missing ClusterRoleBinding [#6369](https://github.com/openshift/machine-config-operator/pull/6369)
* [AGENT-1570](https://issues.redhat.com/browse/AGENT-1570): Remove all NoRegistryClusterInstall feature gate check [#6396](https://github.com/openshift/machine-config-operator/pull/6396)
* [MCO-2411](https://issues.redhat.com/browse/MCO-2411): Add AWS marketplace AMI band check target [#6365](https://github.com/openshift/machine-config-operator/pull/6365)
* [OCPBUGS-105426](https://issues.redhat.com/browse/OCPBUGS-105426): OCPBUGS-105430: OCPBUGS-105431: OCPBUGS-105315: Fix duplicate template error and e2es [#6387](https://github.com/openshift/machine-config-operator/pull/6387)
* [OCPBUGS-59197](https://issues.redhat.com/browse/OCPBUGS-59197): Fix MOSB image deletion race during MOSC removal [#6348](https://github.com/openshift/machine-config-operator/pull/6348)
* [OCPBUGS-83562](https://issues.redhat.com/browse/OCPBUGS-83562): Bump kubensmnt dependency and service to v1.3.0 [#6051](https://github.com/openshift/machine-config-operator/pull/6051)
* NO-ISSUE: Add fix TC 63866 failing in CI job [#6380](https://github.com/openshift/machine-config-operator/pull/6380)
* [MCO-2256](https://issues.redhat.com/browse/MCO-2256): Drop RHEL8 support [#6130](https://github.com/openshift/machine-config-operator/pull/6130)
* [AGENT-1570](https://issues.redhat.com/browse/AGENT-1570): update dependencies to the latest after several Feature promotions to default [#6393](https://github.com/openshift/machine-config-operator/pull/6393)
* [OKD-419](https://issues.redhat.com/browse/OKD-419): Add missing variant check for SCOS [#6371](https://github.com/openshift/machine-config-operator/pull/6371)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/84999756cf4ca5b20cc0b1f3b20cfda9bd22fdd6...e7e6abbd38052da7edbb1a01bf0548d2bb03468b)
### [machine-image-customization-controller](https://github.com/openshift/image-customization-controller/tree/87f4774be1fc58b6b3868c57326a80f95bd81594)
* [OCPBUGS-112616](https://issues.redhat.com/browse/OCPBUGS-112616): Update xz and ignition/v2 with known vulnerabilities [#185](https://github.com/openshift/image-customization-controller/pull/185)
* [OCPBUGS-112617](https://issues.redhat.com/browse/OCPBUGS-112617): Stop accepting IRONIC_AGENT_PULL_SECRET from the envi… [#186](https://github.com/openshift/image-customization-controller/pull/186)
* [Full changelog](https://github.com/openshift/image-customization-controller/compare/e49b096880f17296d42a77443dc14d732683333d...87f4774be1fc58b6b3868c57326a80f95bd81594)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/1d6a7d787cc8d1f8570b3310a764be493071c8eb)
* [TRT-2935](https://issues.redhat.com/browse/TRT-2935): Revert machine-os-images PR #110 — fatal aarch64 ISO check crashes metal3 init-container [#112](https://github.com/openshift/machine-os-images/pull/112)
* [OKD-429](https://issues.redhat.com/browse/OKD-429): Fix OKD/SCOS builds to use centos CoreOS streams [#109](https://github.com/openshift/machine-os-images/pull/109)
* [OCPBUGS-112613](https://issues.redhat.com/browse/OCPBUGS-112613): Validate aarch64 ISO checksum after cross-arch extraction [#110](https://github.com/openshift/machine-os-images/pull/110)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/bf618aac93c71a56e8249669c579f0a782742e2e...1d6a7d787cc8d1f8570b3310a764be493071c8eb)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/525bbd1556c5af07906360bac2e91c6d70959b65)
* [OCPBUGS-114776](https://issues.redhat.com/browse/OCPBUGS-114776), [OCPBUGS-114795](https://issues.redhat.com/browse/OCPBUGS-114795): fix: upgrade vulnerable dompurify dependency [#1199](https://github.com/openshift/monitoring-plugin/pull/1199)
* [OU-1423](https://issues.redhat.com/browse/OU-1423): fix: adjust perses mui theme to patternfly glass mode [#1195](https://github.com/openshift/monitoring-plugin/pull/1195)
* NO-JIRA: swap perses to ols specific tag for ols testing run [#1194](https://github.com/openshift/monitoring-plugin/pull/1194)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): include the legal disclaimer in the alert actions to agentic runs [#1188](https://github.com/openshift/monitoring-plugin/pull/1188)
* [OU-1417](https://issues.redhat.com/browse/OU-1417): Fix Perses tooltips background color in OCP 5 [#1178](https://github.com/openshift/monitoring-plugin/pull/1178)
* [OLS-3921](https://issues.redhat.com/browse/OLS-3921): disable button shrink [#1186](https://github.com/openshift/monitoring-plugin/pull/1186)
* [OU-1422](https://issues.redhat.com/browse/OU-1422): feat: update perses dependecies to allow to tag the OLS contributed panels [#1045](https://github.com/openshift/monitoring-plugin/pull/1045)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): rename tags to be the same as backend features [#1128](https://github.com/openshift/monitoring-plugin/pull/1128)
* [OU-1471](https://issues.redhat.com/browse/OU-1471): don't throw when listing globaldatasource for fallback [#1153](https://github.com/openshift/monitoring-plugin/pull/1153)
* [OU-1514](https://issues.redhat.com/browse/OU-1514): update useFeatures hook to feature driven backend [#1151](https://github.com/openshift/monitoring-plugin/pull/1151)
* NO-JIRA: chore: organize dev dependencies and avoid cypress binary install [#1148](https://github.com/openshift/monitoring-plugin/pull/1148)
* NO-JIRA: feat: replace outdated react-linkify dependency [#1144](https://github.com/openshift/monitoring-plugin/pull/1144)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): remove incidents feature from backend and tests [#1127](https://github.com/openshift/monitoring-plugin/pull/1127)
* [OU-1107](https://issues.redhat.com/browse/OU-1107), [OU-1108](https://issues.redhat.com/browse/OU-1108): ACM alerting UI with alerts and perses [#1105](https://github.com/openshift/monitoring-plugin/pull/1105)
* [OBSINTA-1505](https://issues.redhat.com/browse/OBSINTA-1505): improve OLS timeseries Cypress test stability [#1122](https://github.com/openshift/monitoring-plugin/pull/1122)
* NO-JIRA: remove helm chart [#1126](https://github.com/openshift/monitoring-plugin/pull/1126)
* [OU-1486](https://issues.redhat.com/browse/OU-1486): feat: add art dockerfile [#1117](https://github.com/openshift/monitoring-plugin/pull/1117)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/2abd16ff885db25f1211cc9daf591c8c35e399b7...525bbd1556c5af07906360bac2e91c6d70959b65)
### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/6d9df61378321846c00a32f0c42b6688daacd649)
* NO-JIRA: Remove TLS min version validation for OpenShift profile compatibility [#122](https://github.com/openshift/multus-admission-controller/pull/122)
* [Full changelog](https://github.com/openshift/multus-admission-controller/compare/4bb2e2069c3e4f11fbc4c1befd6dc1c41fa802b7...6d9df61378321846c00a32f0c42b6688daacd649)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/f046826640baf19d335411b2116fe8d2124158d3)
* [OCPBUGS-114000](https://issues.redhat.com/browse/OCPBUGS-114000): DS Merge 08/27/2026 [#344](https://github.com/openshift/multus-cni/pull/344)
* [Full changelog](https://github.com/openshift/multus-cni/compare/f099946680e376f722674e684aec96a73c58e919...f046826640baf19d335411b2116fe8d2124158d3)
### [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy/tree/39e9cccfa32951d0243c99638099da0a84d0d598)
* NO-JIRA: Downstream merge 20260826 [#120](https://github.com/openshift/multus-networkpolicy/pull/120)
* [CORENET-7235](https://issues.redhat.com/browse/CORENET-7235): Update OWNERS file [#116](https://github.com/openshift/multus-networkpolicy/pull/116)
* [Full changelog](https://github.com/openshift/multus-networkpolicy/compare/932bdaa4250d0a1db41a1a1fcac8192f2757211c...39e9cccfa32951d0243c99638099da0a84d0d598)
### [multus-route-override-cni](https://github.com/openshift/route-override-cni/tree/ce65e37e2571101213bb32643316812df311701b)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#66](https://github.com/openshift/route-override-cni/pull/66)
* [Full changelog](https://github.com/openshift/route-override-cni/compare/08af4127c77976510cad1c096d9aca977d8ae5af...ce65e37e2571101213bb32643316812df311701b)
### [must-gather](https://github.com/openshift/must-gather/tree/1e5c2ec841c1ed29110febaf8a448936842a2f4d)
* [MG-234](https://issues.redhat.com/browse/MG-234): REDUCE_LOGS=compress_logs compresses large must-gather logs before rsync (#559) [#559](https://github.com/openshift/must-gather/pull/559)
* [Full changelog](https://github.com/openshift/must-gather/compare/fd47ab2c1d183a1e66a1a74fe30cf6a26f433409...1e5c2ec841c1ed29110febaf8a448936842a2f4d)
### [network-interface-bond-cni](https://github.com/openshift/bond-cni/tree/b8723844dc69940f55208cdb265653ab57f959f0)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#113](https://github.com/openshift/bond-cni/pull/113)
* [Full changelog](https://github.com/openshift/bond-cni/compare/19d390fd4d353619fdfb5e0070962d2ddf54b5bb...b8723844dc69940f55208cdb265653ab57f959f0)
### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/80fc3abc785d2b4d8275ba316c579de43416148d)
* [OCPBUGS-112553](https://issues.redhat.com/browse/OCPBUGS-112553), [OCPBUGS-112568](https://issues.redhat.com/browse/OCPBUGS-112568): Fix CVE for ose-network-metrics-daemon [#147](https://github.com/openshift/network-metrics-daemon/pull/147)
* [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844...80fc3abc785d2b4d8275ba316c579de43416148d)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/881e2f26370d07c2c5e6240e478000da34cf15a6)
* [OCPNETUI-66](https://issues.redhat.com/browse/OCPNETUI-66): Drop unused devcontainer config [#474](https://github.com/openshift/networking-console-plugin/pull/474)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add Cypress test specs and runner scripts [#470](https://github.com/openshift/networking-console-plugin/pull/470)
* [OCPBUGS-113967](https://issues.redhat.com/browse/OCPBUGS-113967): Fix 404 error on MultiNetworkPolicy page when "All projects" is selected [#483](https://github.com/openshift/networking-console-plugin/pull/483)
* [OCPBUGS-91643](https://issues.redhat.com/browse/OCPBUGS-91643): Fixed IP sorting in service overview [#482](https://github.com/openshift/networking-console-plugin/pull/482)
* [OCPBUGS-112660](https://issues.redhat.com/browse/OCPBUGS-112660): Marked strings for i18n in NetworkPolicies list page [#478](https://github.com/openshift/networking-console-plugin/pull/478)
* [OCPBUGS-86249](https://issues.redhat.com/browse/OCPBUGS-86249): fixed edit pod selector [#476](https://github.com/openshift/networking-console-plugin/pull/476)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add Cypress E2E framework config and support files [#468](https://github.com/openshift/networking-console-plugin/pull/468)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add Cypress page objects and test constants [#469](https://github.com/openshift/networking-console-plugin/pull/469)
* chore(i18n): update Sprint 1 translations and Memsource CLI skill docs [#471](https://github.com/openshift/networking-console-plugin/pull/471)
* chore(i18n): add Cursor Memsource skill and peer usage guide [#466](https://github.com/openshift/networking-console-plugin/pull/466)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/33788405f30ef023250fd8fab71caeab57ec6b90...881e2f26370d07c2c5e6240e478000da34cf15a6)
### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/81d5261594cba423b2519b8bc171e7967b987e36)
* [CNTRLPLANE-2260](https://issues.redhat.com/browse/CNTRLPLANE-2260): test migration of tokenreview tests to OTE [#212](https://github.com/openshift/oauth-apiserver/pull/212)
* NO-JIRA: Remove cluster profile directory authentication as it is no longer injected in CI [#217](https://github.com/openshift/oauth-apiserver/pull/217)
* [CNTRLPLANE-3947](https://issues.redhat.com/browse/CNTRLPLANE-3947): Bump to 1.36.2 [#213](https://github.com/openshift/oauth-apiserver/pull/213)
* [CNTRLPLANE-3947](https://issues.redhat.com/browse/CNTRLPLANE-3947): hack/update-openapi-spec: add image resolution and registry auth [#214](https://github.com/openshift/oauth-apiserver/pull/214)
* [Full changelog](https://github.com/openshift/oauth-apiserver/compare/688f57b5af12182644b33b770151352b1d54df3a...81d5261594cba423b2519b8bc171e7967b987e36)
### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/63a61bf10cbf46145a127246216540a38b50a018)
* NO-JIRA: Add control-plane-approvers to OWNERS [#373](https://github.com/openshift/oauth-proxy/pull/373)
* [Full changelog](https://github.com/openshift/oauth-proxy/compare/e9046946c11e46d310c83830687eb3284cb53525...63a61bf10cbf46145a127246216540a38b50a018)
### [oauth-server](https://github.com/openshift/oauth-server/tree/1600eafd18f46d54ad0a9ff70fa03a085f6f6218)
* [CNTRLPLANE-3948](https://issues.redhat.com/browse/CNTRLPLANE-3948): Bump to 1.36.2 [#248](https://github.com/openshift/oauth-server/pull/248)
* [Full changelog](https://github.com/openshift/oauth-server/compare/ffad196a95584670d3a2e20e270cb23a64e6a327...1600eafd18f46d54ad0a9ff70fa03a085f6f6218)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/19afc52f9d237c9cf1a2406ec228c363ebe1c677)
* NO-ISSUE: Synchronize From Upstream Repositories [#790](https://github.com/openshift/operator-framework-operator-controller/pull/790)
* NO-ISSUE: Synchronize From Upstream Repositories [#788](https://github.com/openshift/operator-framework-operator-controller/pull/788)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/cf65286ba31b6e4eda0ecb03ae10581a7e1ac688...19afc52f9d237c9cf1a2406ec228c363ebe1c677)
### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/ab0315228cde432c8cd62df012b791a66a72c7b3)
* [OCPBUGS-85429](https://issues.redhat.com/browse/OCPBUGS-85429): Bump to 1.36.2 [#666](https://github.com/openshift/openshift-apiserver/pull/666)
* NO-JIRA: Remove cluster profile directory authentication as it is no longer injected in CI [#674](https://github.com/openshift/openshift-apiserver/pull/674)
* [OCPBUGS-85429](https://issues.redhat.com/browse/OCPBUGS-85429): hack/update-openapi-spec: add image resolution and registry auth [#667](https://github.com/openshift/openshift-apiserver/pull/667)
* [OCPBUGS-94042](https://issues.redhat.com/browse/OCPBUGS-94042): Return proper 404 when deleting a non-existent project [#671](https://github.com/openshift/openshift-apiserver/pull/671)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/58298ec3f0772b16598ca8df5ce29c0a3e5f022c...ab0315228cde432c8cd62df012b791a66a72c7b3)
### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/5235418de7c86e6fae1004f84e55a2fbc1d3ac1c)
* [CNTRLPLANE-3878](https://issues.redhat.com/browse/CNTRLPLANE-3878): bump(k8s.io): 1.36.3 [#451](https://github.com/openshift/openshift-controller-manager/pull/451)
* [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/5631cf493b006cbc72a8600a7435813272d71940...5235418de7c86e6fae1004f84e55a2fbc1d3ac1c)
### [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics/tree/3b4ea3e753d97fea66e0f52c8282a711358b4ff7)
* NO-JIRA: update Go dependencies [#135](https://github.com/openshift/openshift-state-metrics/pull/135)
* [Full changelog](https://github.com/openshift/openshift-state-metrics/compare/0e12f5d6df02b37b0353a747d144e8069c3d0c2a...3b4ea3e753d97fea66e0f52c8282a711358b4ff7)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/8fcaaaa900a4fd24fd53dab2c7c44c91bbf5a9c6)
* Fix rebasebot post-rebase hook helper path lookup [#432](https://github.com/openshift/cluster-api-provider-openstack/pull/432)
* Fix rebasebot merge-bot by removing stale API version artifacts [#431](https://github.com/openshift/cluster-api-provider-openstack/pull/431)
* Bug: Fix make merge-bot after rebasebot by cleaning stale openshift artifacts [#430](https://github.com/openshift/cluster-api-provider-openstack/pull/430)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/4f65df9309c97435fc53c05f6ea4b6135b243166...8fcaaaa900a4fd24fd53dab2c7c44c91bbf5a9c6)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/cfe91e367d56b3bd96331942e3c7c7d434fd9c0d)
* [OCPBUGS-83412](https://issues.redhat.com/browse/OCPBUGS-83412): set catalogsource spec.grpcpodconfig.scc: restricted for all non-legacy cases [#1359](https://github.com/openshift/operator-framework-olm/pull/1359)
* [OCPBUGS-104542](https://issues.redhat.com/browse/OCPBUGS-104542): force node arch for opm and catalogsource pod for multiarch tests; fix test failure [#1357](https://github.com/openshift/operator-framework-olm/pull/1357)
* [OCPBUGS-23954](https://issues.redhat.com/browse/OCPBUGS-23954), [OCPBUGS-78095](https://issues.redhat.com/browse/OCPBUGS-78095): Synchronize From Upstream Repositories [#1355](https://github.com/openshift/operator-framework-olm/pull/1355)
* Revert "OCPBUGS-104542: force same arch for opm and catalogsource pod for multiarch tests" [#1349](https://github.com/openshift/operator-framework-olm/pull/1349)
* [OCPBUGS-74905](https://issues.redhat.com/browse/OCPBUGS-74905): Synchronize From Upstream Repositories [#1346](https://github.com/openshift/operator-framework-olm/pull/1346)
* [OCPBUGS-104542](https://issues.redhat.com/browse/OCPBUGS-104542): force same arch for opm and catalogsource pod for multiarch tests [#1344](https://github.com/openshift/operator-framework-olm/pull/1344)
* [OCPBUGS-86895](https://issues.redhat.com/browse/OCPBUGS-86895): Ensure packageserver pod seccompProfile is always set [#1341](https://github.com/openshift/operator-framework-olm/pull/1341)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/ebb46755980dd2c08d186e79cd7e98029a5adc2a...cfe91e367d56b3bd96331942e3c7c7d434fd9c0d)
### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/f421eb0250c49687b08ea405e64fdbbb5509a9b7)
* NO-ISSUE: Bump the k8s-dependencies group across 1 directory with 3 updates [#776](https://github.com/operator-framework/operator-marketplace/pull/776)
* NO-ISSUE: Bump github.com/sirupsen/logrus from 1.10.0 to 1.10.1 [#778](https://github.com/operator-framework/operator-marketplace/pull/778)
* NO-ISSUE: Bump github.com/sirupsen/logrus from 1.9.4 to 1.10.0 [#774](https://github.com/operator-framework/operator-marketplace/pull/774)
* NO-ISSUE: Bump github.com/onsi/ginkgo/v2 from 2.32.0 to 2.32.1 [#773](https://github.com/operator-framework/operator-marketplace/pull/773)
* NO-ISSUE: Bump the k8s-dependencies group across 1 directory with 3 updates [#769](https://github.com/operator-framework/operator-marketplace/pull/769)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/089b758a29524877a831d3b91a0655bfa5b72424...f421eb0250c49687b08ea405e64fdbbb5509a9b7)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/2f9add8106687de6dba052689b97a189f92439f9)
* NO-JIRA: DownStream Merge [08-17-2026] [#3402](https://github.com/openshift/ovn-kubernetes/pull/3402)
* [OCPBUGS-105440](https://issues.redhat.com/browse/OCPBUGS-105440): DownStream Merge [08-13-2026] [#3395](https://github.com/openshift/ovn-kubernetes/pull/3395)
* NO-JIRA: DownStream Merge [08-11-2026] [#3383](https://github.com/openshift/ovn-kubernetes/pull/3383)
* [OCPBUGS-100275](https://issues.redhat.com/browse/OCPBUGS-100275), [OCPBUGS-85627](https://issues.redhat.com/browse/OCPBUGS-85627): DownStream Merge [08-10-2026] [#3361](https://github.com/openshift/ovn-kubernetes/pull/3361)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/7ef6640e2f19f9fa01aa4e24b3c831a08004ea28...2f9add8106687de6dba052689b97a189f92439f9)
### [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver/tree/cfe345c7dd6e7f817927847690658b199c3d1653)
* [MULTIARCH-6346](https://issues.redhat.com/browse/MULTIARCH-6346): Rebase with upstream - go modules updates and code changes [#138](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/138)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver/compare/e7c2c09bd0507f8bd5a6dc3921024a379f4a8af0...cfe345c7dd6e7f817927847690658b199c3d1653)
### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/67895c7c968f42e97efec58f4140fffae4832028)
* NO-ISSUE: [bot] Bump openshift/prometheus-operator to v0.93.1 [#391](https://github.com/openshift/prometheus-operator/pull/391)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/49894fa3421065dfd2378f664240d07f5bd208cd...67895c7c968f42e97efec58f4140fffae4832028)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/ff8cca07e946d00683527a18203def8b5f8e7380)
* [OCPBUGS-100376](https://issues.redhat.com/browse/OCPBUGS-100376): cherry-pick 24c6dce279c418bcb911824e8c8be1c81a1e832b - Fix fibrechannel_linux for ppc64le (#3769) [#184](https://github.com/openshift/node_exporter/pull/184)
* [Full changelog](https://github.com/openshift/node_exporter/compare/4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07...ff8cca07e946d00683527a18203def8b5f8e7380)
### [rhel-coreos, rhel-coreos-10, rhel-coreos-10-extensions, rhel-coreos-extensions](https://github.com/openshift/os/tree/d2f3751e77c4b79b1553d18758c2ea91f06f51fc)
* NO-JIRA: Use --nobest when installing node packages [#1958](https://github.com/openshift/os/pull/1958)
* [Full changelog](https://github.com/openshift/os/compare/bf90b219ae4ba42e07bf8c010b725401b5402cc8...d2f3751e77c4b79b1553d18758c2ea91f06f51fc)
### [telemeter](https://github.com/openshift/telemeter/tree/a47a32bd9e52b1c86a4e1eaeb9d55f7956b6a583)
* [BIZ-794](https://issues.redhat.com/browse/BIZ-794): separte managed and self-managed ACM capacity [#612](https://github.com/openshift/telemeter/pull/612)
* [Full changelog](https://github.com/openshift/telemeter/compare/22ba1701333f3fd26490cc15b89ddf21df3f67f6...a47a32bd9e52b1c86a4e1eaeb9d55f7956b6a583)
### [tests](https://github.com/openshift/origin/tree/42b963ac884b41db0af70e2dcfc78b17d262b496)
* [OCPNODE-4470](https://issues.redhat.com/browse/OCPNODE-4470): Add DRA consumable capacity e2e tests [#31448](https://github.com/openshift/origin/pull/31448)
* [OCPBUGS-112390](https://issues.redhat.com/browse/OCPBUGS-112390): Fix node replacement test timestamp filter and allow job retry [#31492](https://github.com/openshift/origin/pull/31492)
* [TRT-2930](https://issues.redhat.com/browse/TRT-2930): skip regional-PD e2e on GCP families without pd-standard [#31572](https://github.com/openshift/origin/pull/31572)
* [ROSAENG-391](https://issues.redhat.com/browse/ROSAENG-391): Add CustomResourcePublishOpenAPI conformance test to retry allowlist [#31552](https://github.com/openshift/origin/pull/31552)
* [OCPBUGS-114341](https://issues.redhat.com/browse/OCPBUGS-114341): Allow KubeDaemonSetRolloutStuck alert on external platform clusters [#31564](https://github.com/openshift/origin/pull/31564)
* [OCPBUGS-111581](https://issues.redhat.com/browse/OCPBUGS-111581): Fix probe termination test to use pod status instead of kubelet event text [#31528](https://github.com/openshift/origin/pull/31528)
* [OCPBUGS-112283](https://issues.redhat.com/browse/OCPBUGS-112283): Allow KubeDaemonSetMisScheduled alert on external platform clusters [#31556](https://github.com/openshift/origin/pull/31556)
* [OCPBUGS-99536](https://issues.redhat.com/browse/OCPBUGS-99536): Raise status polling timeout and write bound [#31534](https://github.com/openshift/origin/pull/31534)
* [OCPBUGS-86257](https://issues.redhat.com/browse/OCPBUGS-86257): Fix pathological events [#31543](https://github.com/openshift/origin/pull/31543)
* [OCPBUGS-105399](https://issues.redhat.com/browse/OCPBUGS-105399), [OCPBUGS-105400](https://issues.redhat.com/browse/OCPBUGS-105400): Remove TechPreview skips and event matchers from sigstore imagepolicy tests [#31521](https://github.com/openshift/origin/pull/31521)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): e2e TLS test for service-operator-ca [#31480](https://github.com/openshift/origin/pull/31480)
* [OCPBUGS-112470](https://issues.redhat.com/browse/OCPBUGS-112470): fix duplicate destination tags in openshift-tests images output [#31542](https://github.com/openshift/origin/pull/31542)
* [OCPBUGS-84517](https://issues.redhat.com/browse/OCPBUGS-84517): Remove stale openshift-marketplace terminationMessagePolicy exemption [#31355](https://github.com/openshift/origin/pull/31355)
* [CONSOLE-5188](https://issues.redhat.com/browse/CONSOLE-5188): remove console exceptions [#31280](https://github.com/openshift/origin/pull/31280)
* [OCPBUGS-100298](https://issues.redhat.com/browse/OCPBUGS-100298): pin internal-lb-monitor pollers to worker nodes [#31466](https://github.com/openshift/origin/pull/31466)
* [OCPBUGS-84513](https://issues.redhat.com/browse/OCPBUGS-84513): remove openshift-cluster-version terminationMessagePolicy exemption [#31359](https://github.com/openshift/origin/pull/31359)
* [OCPBUGS-105461](https://issues.redhat.com/browse/OCPBUGS-105461): allow baremetal to progress while MCO does [#31511](https://github.com/openshift/origin/pull/31511)
* [OCPBUGS-105874](https://issues.redhat.com/browse/OCPBUGS-105874): Avoid TLS port-forward to stale endpoints on degraded TNF clusters. [#31502](https://github.com/openshift/origin/pull/31502)
* [OCPBUGS-111704](https://issues.redhat.com/browse/OCPBUGS-111704): router/metrics: enable proxy protocol for client on AWS clusters [#31526](https://github.com/openshift/origin/pull/31526)
* [OCPBUGS-109671](https://issues.redhat.com/browse/OCPBUGS-109671): monitortests: allow image-registry node-ca Progressing on DualReplica [#31517](https://github.com/openshift/origin/pull/31517)
* [CNTRLPLANE-1739](https://issues.redhat.com/browse/CNTRLPLANE-1739): e2e additional tests for pki config [#31491](https://github.com/openshift/origin/pull/31491)
* [OCPBUGS-104561](https://issues.redhat.com/browse/OCPBUGS-104561): test: exclude NTO debug pods from best-effort QoS invariant [#31472](https://github.com/openshift/origin/pull/31472)
* [OCPBUGS-105876](https://issues.redhat.com/browse/OCPBUGS-105876): tolerate brief olm Available=False during upgrades [#31518](https://github.com/openshift/origin/pull/31518)
* NO-JIRA: Remove exception OCPBUGS-66225 [#31471](https://github.com/openshift/origin/pull/31471)
* NO-JIRA: Remove exception OCPBUGS-86009 [#31470](https://github.com/openshift/origin/pull/31470)
* [OCPCLOUD-3420](https://issues.redhat.com/browse/OCPCLOUD-3420): Remove exceptions OCPBUGS-42837 and OCPBUGS-64852 [#31469](https://github.com/openshift/origin/pull/31469)
* [MON-4471](https://issues.redhat.com/browse/MON-4471): test/extended/prometheus: move alert tests to "Test Framework" [#30703](https://github.com/openshift/origin/pull/30703)
* [OCPBUGS-106190](https://issues.redhat.com/browse/OCPBUGS-106190): Make oc rsh test resilient [#31515](https://github.com/openshift/origin/pull/31515)
* [TRT-2898](https://issues.redhat.com/browse/TRT-2898): Fix leaked ClusterRoleBinding in pull_secrets test [#31514](https://github.com/openshift/origin/pull/31514)
* [OCPQE-32064](https://issues.redhat.com/browse/OCPQE-32064): Reduce monitortest sensitivity for upcoming spot check jobs, use etcd-scaling job as early example [#31212](https://github.com/openshift/origin/pull/31212)
* [OCPBUGS-105606](https://issues.redhat.com/browse/OCPBUGS-105606): Allow DualReplica stable-system CVO Available blips from NoExecuteTaintManager [#31501](https://github.com/openshift/origin/pull/31501)
* NO-ISSUE: Update agnhost image to 2.63.0 (mirrored version) [#31498](https://github.com/openshift/origin/pull/31498)
* [CNTRLPLANE-2157](https://issues.redhat.com/browse/CNTRLPLANE-2157): Migrate OTE for Pull Secrets, Feature Gates and Webhooks [#31382](https://github.com/openshift/origin/pull/31382)
* [OCPBUGS-105768](https://issues.redhat.com/browse/OCPBUGS-105768): Update s2i_images test for OCP samples sync [#31504](https://github.com/openshift/origin/pull/31504)
* [OCPBUGS-98719](https://issues.redhat.com/browse/OCPBUGS-98719): retry GetVotingMemberNames on transient etcd client fails [#31445](https://github.com/openshift/origin/pull/31445)
* [OCPBUGS-105466](https://issues.redhat.com/browse/OCPBUGS-105466): monitortests: recognize PascalCase TNF JobRunning CO reasons [#31499](https://github.com/openshift/origin/pull/31499)
* [OCPEDGE-2700](https://issues.redhat.com/browse/OCPEDGE-2700): fix flaky etcd disruption tests and remove unreliable is_standalone test [#31276](https://github.com/openshift/origin/pull/31276)
* [OCPNODE-4623](https://issues.redhat.com/browse/OCPNODE-4623): e2e for Block runc on RHEL 10 via OSImageURL stream class inspection [#31433](https://github.com/openshift/origin/pull/31433)
* [OCPBUGS-104544](https://issues.redhat.com/browse/OCPBUGS-104544): tolerate one NotReady CP node in EnsureNodesReady for degraded TNF [#31442](https://github.com/openshift/origin/pull/31442)
* [OCPNODE-4521](https://issues.redhat.com/browse/OCPNODE-4521): Use programmatic skip for single-node instead of test name tag [#31486](https://github.com/openshift/origin/pull/31486)
* NO-ISSUE: Consider centos-10 stream for OKD clusters [#31487](https://github.com/openshift/origin/pull/31487)
* And 2 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/origin/compare/a302321dc817cc65ea1806e167da941ba17d8908...42b963ac884b41db0af70e2dcfc78b17d262b496)