v0.5.2

Security Fixes

  • fixed high severity vulnerabilities: CVE-2026-39821, CVE-2026-46600
  • fixed unrated vulnerabilities: CVE-2026-33818, CVE-2026-56853, CVE-2026-56858, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865

v0.5.1

Security Fixes

  • fixed high severity vulnerabilities: CVE-2026-25681, CVE-2026-27136, CVE-2026-39821, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, CVE-2026-50151, CVE-2026-50163, CVE-2026-53488, CVE-2026-56852
  • fixed medium severity vulnerabilities: CVE-2026-25680, CVE-2026-39827, CVE-2026-39833, CVE-2026-39834, CVE-2026-42502, CVE-2026-42506, CVE-2026-46598, CVE-2026-47262, CVE-2026-50162, GHSA-vh4v-2xq2-g5cg
  • fixed low severity vulnerability: CVE-2026-48978
  • fixed unrated vulnerabilities: CVE-2026-39824, CVE-2026-46600, GO-2026-5932

v0.5.0

New Features

  • enforced restricted pss policy with action deny

Security Fixes

  • fixed GHSA-hrxh-6v49-42gf GHSA-gcjh-h69q-9w9g

Chore

  • migrate module documentation to DKP guides section

v0.4.17

Security Fixes

  • fixed all cves
  • marked golang.org/x/crypto/openpgp as vulnerable_code_not_in_execute_path

v0.4.16

Chore

  • added subsystems to module.yaml

v0.4.15

Security Fixes

  • fixed all cves
  • updated vex files
  • fixed all critical svace detects

Chore

  • added template for vex attestation

v0.4.14

Bug Fixes

  • fixed missing binaries

v0.4.13

Bug Fixes

  • resolved issue with dex authentification

v0.4.12

Security Fixes

  • fixed vex files

Chore

  • updated templates for cse edition

v0.4.11

New Features

  • upgraded argocd-operator to v0.18.0

Bug Fixes

  • updated imageupdater crd to actual version

Security Fixes

  • fixed critical CVE-2026-42880
  • updated vex files

Chore

  • moved CRD files to root crds directory and update threat model
  • updated base images
  • fixed git error while building argocd image
  • added namespace template for d8-operator-argo
  • updated go hooks

v0.4.10

New Features

  • extend default resource exclusion list to minimize kubeapi load in the case of SDS module usage

v0.4.9

New Features

  • updated argo-cd version to v3.3.9

Security Fixes

  • fixed CVE-2026-42880

v0.4.8

Bug Fixes

  • added missing clusterDomain

Security Fixes

  • fixed critical CVE-2026-33186
  • added vex for CVE-2025-15558
  • fixed CVE-2026-39883 CVE-2026-24051 CVE-2026-34986

v0.4.7

Bug Fixes

  • migrate argocd instances’ service monitors to d8-operator-argo namespace
  • added heritage deckhouse labels to d8-operator-argo namespace

Security Fixes

  • fixed critical CVE-2026-33186

v0.4.6

New Features

  • expose metrics to the platform Prometheus instance automatically

Bug Fixes

  • correct CRD CA certificate injection
  • correct Go hooks certificate injection logic
  • removed stale ensure-CRD hook

Chore

  • updated CRDs
  • added examples for creating local Argo CD users
  • added examples for Argo CD RBAC policies
  • added ingressClassName to Argo CD examples
  • added examples of using a self-signed certificate for Dex
  • moved imagePullSecret from Deployment to ServiceAccount

v0.4.5

Security Fixes

  • fixed critical CVE-2025-68121
  • fixed CVE-2025-68121 CVE-2025-61728 CVE-2025-61729 CVE-2025-61730 CVE-2025-68121 CVE-2025-68156 CVE-2025-61726
  • added vex for CVE-2026-25934

Chore

  • updated base images
  • rewrite python hooks on go
  • fixed dmt lint issues

v0.4.4

Bug Fixes

  • fixed missing ssh

v0.4.3

Bug Fixes

  • fixed missing entrypoint.sh

v0.4.2

Bug Fixes

  • fixed ArgoCD repo-server runtime issues in distroless image (cp, uid_entrypoint.sh, ssh known_hosts)

v0.4.1

Security Fixes

  • resolved multiple license vulnerabilities

Chore

  • updated base images to distroless
  • refactor ArgoCD authentication documentation

v0.4.0

New Features

  • added HA

Chore

  • updated examples in docs

v0.3.14

Chore

  • fixed changelog
  • added SE+ edition

v0.3.13

Security Fixes

  • fixed vulnerabilites CVE-2025-47933, CVE-2025-55190, CVE-2024-25621, CVE-2025-64329, CVE-2025-5187, CVE-2025-47912, CVE-2025-58183, CVE-2025-58186, CVE-2025-58187, CVE-2025-58188, CVE-2025-61724, CVE-2025-58185, CVE-2025-58189, CVE-2025-61723, CVE-2025-61725, CVE-2025-47914, CVE-2025-58181

Chore

  • updated base images