CI/CD

Argo Workflows: what changed

In the last 90 days, 12 summarized changes: 10 breaking changes, 2 security advisories. Stackdiff reads Argo Workflows's own feeds (github.com) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

4.0.11Breakinghigh
v4.0.11
4.1.3Breakinghigh
v4.1.3
4.1.2Breakinghigh
v4.1.2
4.0.10Breakinghigh
v4.0.10
4.1.1Breakinghigh
v4.1.1
4.0.9Breakinghigh
v4.0.9
3.7.18Breakinghigh
v3.7.18
4.1.0Breakinghigh
4.1.0
4.1.0-rc2Breakinghigh
v4.1.0-rc2
4.1.0-rc1Breakinghigh
v4.1.0-rc1
3.7.15Securitymedium
GO-2026-6223: Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
3.7.15Securitymedium
GHSA-48p8-g2fx-3wwm: Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

4.0.11Breakinghigh
v4.0.11
4.1.3Breakinghigh
v4.1.3
4.1.2Breakinghigh
v4.1.2
4.0.10Breakinghigh
v4.0.10
3.7.15Securitymedium
GO-2026-6223: Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) in github.com/argoproj/argo-workflows
4.1.1Breakinghigh
v4.1.1
4.0.9Breakinghigh
v4.0.9
3.7.18Breakinghigh
v3.7.18
3.7.15Securitymedium
GHSA-48p8-g2fx-3wwm: Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892)
4.1.0Breakinghigh
4.1.0
4.1.0-rc2Breakinghigh
v4.1.0-rc2
4.1.0-rc1Breakinghigh
v4.1.0-rc1
3.7.14Securitymedium
GHSA-5jv8-h7qh-rf5p: Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo Workflows Controller
3.7.11Securitymedium
GHSA-3wf5-g532-rcrr: Argo Workflows: WorkflowTemplate Security Bypass via podSpecPatch in Strict/Secure Reference Mode
3.7.11Securitymedium
GHSA-56px-hm34-xqj5: Unauthorized access to Argo Workflows Template
3.6.17Securitymedium
GHSA-cv78-6m8q-ph82: Argo Workflows affected by stored XSS in the artifact directory listing
3.6.14Securitymedium
GHSA-xrqc-7xgx-c9vh: RCE via ZipSlip and symbolic links in argoproj/argo-workflows
3.6.12Securitymedium
GHSA-c2hv-4pfj-mm2r: Argo Workflow may expose artifact repository credentials
3.6.12Securitymedium
GHSA-p84v-gxvw-73pf: Argo Workflow has a Zipslip Vulnerability
3.5.13Securitymedium
GHSA-h36c-m3rf-34h9: Access to Archived Argo Workflows with Fake Token in `client` mode
3.2.11Securitymedium
GHSA-cmv8-6362-r5w9: Malicious HTML+XHR Artifact Privilege Escalation in Argo Workflows

Where Stackdiff reads Argo Workflows

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get Argo Workflows changes in your Monday brief

Add Argo Workflows and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other ci/cd tools