Cluster add-ons

Velero: what changed

In the last 90 days, 7 summarized changes: 2 security advisories, 5 fixes. Stackdiff reads Velero's own feeds (velero.io) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

1.18.1Securitymedium
GO-2026-6259: Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
1.18.1Securitymedium
GHSA-j2g6-362q-6qc6: Velero vulnerable to file path traversal when extracting from backup's tarball

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

1.18.3-rc.2Fix
v1.18.3-rc.2
1.18.3-rc.1Fix
v1.18.3-rc.1
1.18.1Securitymedium
GO-2026-6259: Velero vulnerable to file path traversal when extracting from backup's tarball in github.com/vmware-tanzu/velero
1.18.1Securitymedium
GHSA-j2g6-362q-6qc6: Velero vulnerable to file path traversal when extracting from backup's tarball
1.18.2Fix
v1.18.2
1.18.2-rc.2Fix
v1.18.2-rc.2
1.18.2-rc.1Fix
v1.18.2-rc.1
1.18.1Fix
v1.18.1
1.18.1-rc.2Fix
v1.18.1-rc.2
1.18.1-rc.1Fix
v1.18.1-rc.1
1.18.0Release
v1.18.0
1.18.0-rc.2Release
v1.18.0-rc.2

Where Stackdiff reads Velero

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get Velero changes in your Monday brief

Add Velero and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other cluster add-ons tools