Cluster add-ons
Velero: what changed
In the last 90 days, 7 summarized changes: 2 security advisories, 5 fixes. Stackdiff reads Velero's own feeds (velero.io) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .
Needs attention
Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.
1.18.1Securitymedium
GO-2026-6259: Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
1.18.1Securitymedium
GHSA-j2g6-362q-6qc6: Velero vulnerable to file path traversal when extracting from backup's tarball
Latest changes
Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.
1.18.1Securitymedium
GO-2026-6259: Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
1.18.1Securitymedium
GHSA-j2g6-362q-6qc6: Velero vulnerable to file path traversal when extracting from backup's tarball
Where Stackdiff reads Velero
- GitHub releases · vmware-tanzu/velero
- Hacker News
- OSV advisories · github.com/vmware-tanzu/velero
Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.
Get Velero changes in your Monday brief
Add Velero and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.
Get your first brief →