What microsoft/retina shipped
Written by FoxPlug from public releases; not affiliated with Retina. An automatic summary of the public release, pull request and commit data of github.com/microsoft/retina. Retina did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- v1.2.9 released with dependency updates and CI workflow improvements. Release
- Retina OSS image vulnerabilities remediated by updating Azure Linux base images and OS package versions. Pull request #2807
- kubectl-retina image vulnerabilities fixed by updating runtime images, Cilium, golang.org/x/crypto, and gRPC. Pull request #2803
- No-wait captures now surface Pod admission failures instead of exiting with success when admission control rejects the Pod. Pull request #2801
- RetinaEndpoint objects are now automatically garbage collected when their tracked Pods are deleted via owner references. Pull request #2707
- Windows eBPF plugin updated to use bypassLookupIPOfInterest flag for advanced event filtering, matching Linux behavior. Pull request #2794
- Documentation added for cluster RBAC and admission policy prerequisites for running packet captures via CLI and CRD. Pull request #2768
- Full Go unit test suite now runs on Windows CI to expose and catch cross-platform issues. Pull request #2793
- OneBranch pipeline restored with separate fork PR builds to comply with fork validation requirements. Pull request #2779
- Redundant image and merge-queue perf workflows removed to reduce CI runner load. Pull request #2802
Why it matters
Security updates across Retina OSS and kubectl-retina images address vulnerabilities, while fixes for capture admission failures and RetinaEndpoint garbage collection improve reliability. Windows testing expansion ensures cross-platform stability, and documentation clarifies cluster prerequisites for users running captures.
Changelog entry
- v1.2.9 released Release
- fix(images): remediate Retina OSS image vulnerabilities by updating Azure Linux base images and OS packages Pull request #2807
- fix(cli): remediate kubectl-retina vulnerabilities with updated runtime images, Cilium, golang.org/x/crypto, and gRPC Pull request #2803
- fix(cli): surface capture Pod admission failures for no-wait captures Pull request #2801
- fix(operator): set Pod owner reference on RetinaEndpoints for garbage collection Pull request #2707
- fix(ebpfwindows): gate advanced event filtering with bypass flag to match Linux behavior Pull request #2794
- docs(capture): document cluster RBAC and admission policy prerequisites Pull request #2768
- test(ci): run full unit test suite on Windows Pull request #2793
- fix(ci): restore OneBranch pipeline and build fork PRs separately Pull request #2779
- chore(ci): remove redundant image and merge-queue perf workflows Pull request #2802
v1.2.9 is out: fixed image vulnerabilities, improved no-wait capture error reporting, added automatic RetinaEndpoint garbage collection, and expanded Windows testing.
v1.2.9 shipped this week with critical security and reliability improvements. Image vulnerabilities across Retina OSS and kubectl-retina are remediated. No-wait captures now properly surface Pod admission failures. RetinaEndpoints are automatically garbage collected when Pods are deleted. Windows CI now runs the full unit test suite to catch cross-platform issues. Documentation clarifies cluster RBAC and admission policy prerequisites.
Week of September 14, 2026
What shipped
- Restricted pprof endpoints to loopback interface to prevent unauthorized access to CPU profiles and memory dumps from remote peers. Pull request #2718
- Fixed Capture resources to resolve podSelector and podNames targets to their own namespace instead of the hardcoded default namespace. Pull request #2758
- Enabled E2E job as a mandatory PR check by fixing conditions to properly skip actual test execution when prerequisites are unavailable. Pull request #2775
- Removed test file that was inadvertently added by a previous pull request. Pull request #2764
- Reverted CI pipeline configuration to run on OneBranch pool to support execution from forked repositories. Pull request #2765
Why it matters
This week's changes address security, namespace scoping, and CI/CD reliability. The pprof restriction prevents unauthorized access to sensitive debugging information, while the Capture namespace fix ensures resources correctly target pods in their intended namespaces. These fixes improve both security posture and correctness of pod targeting.
Changelog entry
- fix(server): restrict pprof endpoints to loopback - prevents unauthorized remote access to CPU profiles and memory dumps Pull request #2718
- fix(capture): scope podSelector/podNames targets to the Capture's own namespace Pull request #2758
- fix(ci): report e2e status when prerequisites are skipped - enables E2E as mandatory PR check Pull request #2775
- fix(revert): run the ADO CI pipeline on the OneBranch pool to support forked repositories Pull request #2765
- fix(test-file): remove test file from Hubble CLI PR Pull request #2764
This week: secured pprof endpoints to loopback, fixed Capture namespace scoping for pod selection, improved E2E CI checks, and restored forked repo CI support.
Retina improvements this week focus on security and correctness. We restricted pprof endpoints to loopback to prevent unauthorized access to debugging data, fixed Capture resources to properly scope pod selection to their own namespace, enhanced E2E testing in CI, and restored support for running CI pipelines from forked repositories.