What crossplane/crossplane shipped
Written by FoxPlug from public releases; not affiliated with Crossplane. An automatic summary of the public release, pull request and commit data of github.com/crossplane/crossplane. Crossplane did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Crossplane v2.4.2 patch release fixes a bug where ownership of ServiceAccounts was not correctly transferred to newly active package revisions [3]. Release
- Fixed issue where old revision controller ownerReferences for ServiceAccounts were not properly demoted during upgrades [6]. Pull request #7839
- Usage webhook failurePolicy is now configurable and gated on Usages to prevent AKS stop/start failures on clusters running Crossplane [2]. Pull request #7784
- Fixed claim reconciler to fail closed when unable to list its XRD instead of incorrectly treating list errors as no enforced composition [5]. Pull request #7789
- Fixed e2e tests broken by provider-nop v0.5.0 bump that made NopResource namespaced and moved cluster-scoped kind to ClusterNopResource [0]. Pull request #7865
- Updated e2e test TestConfigurationPullFromPrivateRegistry to use xpkg.upbound.io registry instead of GCR with expired credentials [1]. Pull request #7866
Why it matters
v2.4.2 addresses critical upgrade and reconciliation issues affecting production users. The ServiceAccount ownership fix and webhook configuration improvements prevent cluster disruptions during upgrades and cloud platform operations.
Changelog entry
- Fixed bug where ownership of ServiceAccounts was not correctly transferred to newly active package revisions [3] Release
- Fixed demote of old revision controller ownerReference for ServiceAccounts during upgrades [6] Pull request #7839
- Made Usage webhook failurePolicy configurable and gated it on Usages to prevent AKS conflicts [2] Pull request #7784
- Fixed claim reconciler to fail closed when unable to list its XRD instead of assuming no enforced composition [5] Pull request #7789
Crossplane v2.4.2 is out with fixes for ServiceAccount ownership transfer during upgrades and configurable webhook policies to prevent AKS stop/start failures.
Crossplane v2.4.2 patch release is available. This release fixes a bug where ServiceAccount ownership was not correctly transferred to newly active package revisions during upgrades. It also makes the Usage webhook failurePolicy configurable to prevent issues with AKS stop/start operations, and fixes the claim reconciler to properly fail when unable to list its XRD.
Week of September 14, 2026
What shipped
- Crossplane v2.4.1 patch release fixes user-reported issues and security vulnerabilities in Crossplane and its dependencies, with package revisions now taking control of established objects from replaced revisions. Release
- Crossplane v2.3.6 patch release addresses user-reported issues and security vulnerabilities in Crossplane and its dependencies, with package revisions now taking control of established objects from replaced revisions. Release
- Crossplane v2.2.6 patch release fixes user-reported issues and security vulnerabilities in Crossplane and its dependencies, with package revisions now taking control of established objects from replaced revisions. Release
- Crossplane v1.20.13 patch release updates Go toolchain to 1.26.7 and google.golang.org/grpc to v1.83.2 plus other vulnerable dependency updates to address security issues. Release
- Crossplane APIs v2.4.1 release published. Release
- Crossplane APIs v2.3.6 release published. Release
Why it matters
Multiple patch releases across supported versions address security vulnerabilities in dependencies and fix issues reported by users. The package revision control improvement ensures smoother transitions when updating package revisions.
Changelog entry
- v2.4.1: patch release for bug fixes and security updates Release
- v2.3.6: patch release for bug fixes and security updates Release
- v2.2.6: patch release for bug fixes and security updates Release
- v1.20.13: Go toolchain bumped to 1.26.7, google.golang.org/grpc updated to v1.83.2 Release
Crossplane v2.4.1, v2.3.6, v2.2.6, and v1.20.13 are now available. These patch releases include security updates and dependency fixes. v2.4.1, v2.3.6, and v2.2.6 improve package revision control handling.
We've released patch versions across multiple Crossplane lines: v2.4.1, v2.3.6, v2.2.6, and v1.20.13. These releases address security vulnerabilities in dependencies and fix issues from user reports. A key improvement in v2.4.1, v2.3.6, and v2.2.6 enhances how package revisions take control of established objects during upgrades.