Cluster add-ons

KEDA: what changed

In the last 90 days, 2 summarized changes: 1 security advisories, 1 fixes. Stackdiff reads KEDA's own feeds (keda.sh) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

2.20.0Securitymedium
GHSA-6w3m-4hhp-775q: KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

2.20.2Fix
v2.20.2
2.20.0Securitymedium
GHSA-6w3m-4hhp-775q: KEDA has PostgreSQL connection string parameter injection via incomplete whitespace escaping
2.20.1Fix
v2.20.1
2.20.0Release
v2.20.0
2.19.0Release
v2.19.0
2.18.3Securitymedium
v2.18.3
2.17.3Securitymedium
GHSA-c4p6-qg4m-9jmr: KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential
2.17.3Securitymedium
v2.17.3
2.18.2Fix
v2.18.2
2.18.1Fix
v2.18.1
2.18.0Breakinghigh
v2.18.0
2.17.2Fix
v2.17.2

Where Stackdiff reads KEDA

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get KEDA changes in your Monday brief

Add KEDA and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other cluster add-ons tools