# 5.1.0-ec.1
Created: 2026-09-28 20:10:28 +0000 UTC
Image Digest: `sha256:f0e04a60033b020f615a2f831453db67995baa33fc8649b709e800c1ddf0757c`
## Changes from 5.1.0-ec.0
### Components
* Kubectl 1.36.2
* Kubernetes upgraded from 1.36.3 to 1.36.4
* Kubernetes Tests 1.36.2
* Red Hat Enterprise Linux CoreOS 10.2 upgraded from 10.2.20260831-0 to 10.2.20260918-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| AzureWorkloadIdentity
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| VolumeGroupSnapshot
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| SELinuxMount
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| TLSAdherence
(0 tests)| Disabled| Disabled| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| DRADeviceTaintRules
(0 tests)| | | | | | | | |
| EgressIPNodeSelector
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| ManagedBootImagesAWSCAPI
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
| OVNKubernetesUplinkMode
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | | |
| VSpherePerComponentScopedCreds
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | | |
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [d6ec9243](https://github.com/openshift/apiserver-network-proxy/commit/d6ec9243d24050d7d7ad7f939e45f821171f000e) `sha256:69fc25ebefd1d2fb8722f019964805cfc358637ac3b58da1df8285862264b394`
* [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider) git [9b18930d](https://github.com/openshift/aws-encryption-provider/commit/9b18930d2db9521a08faa7165488bdcf6482b9cf) `sha256:992a5c8f4db5b13766a96b3cd8ba90187cec0a5432a11188493e26d74e0074b2`
* [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler) git [e4ff2aae](https://github.com/openshift/aws-node-termination-handler/commit/e4ff2aaec292db42de9f3eef4908ba1c421a2a6c) `sha256:78374c23f87f5a7634b915de2321abc5f50daa51dd8abed143c61e951dd50e5b`
* [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms) git [21fc3813](https://github.com/openshift/azure-kubernetes-kms/commit/21fc3813f6cc12ce6246531891b5ad395e2afaad) `sha256:fe6a5d17980bbc8b9af22277a470157c6cd3d78ecb8991f9973dff67a65b7dde`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:ff765ff8fe5a0c037ba152f7b08e9da260845108678859898a0e36b4e0d92ad7`
* [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3) git [ad4f1c2b](https://github.com/openshift/cluster-api-provider-metal3/commit/ad4f1c2bd7b527437496b71b5b93ee1439243d65) `sha256:2914910c2a6cf633e132c58dfff965e94f9e280a016f9bbdfefd28ca61ebf956`
* [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator) git [e4f426dc](https://github.com/openshift/cluster-autoscaler-operator/commit/e4f426dcd988735d1e49da743240231be6ab6a40) `sha256:e0ed730cba5c30c8fdb60b0c702354b269c44dfcf514a20b181204e37c02f320`
* [cluster-capi-controllers](https://github.com/openshift/cluster-api) git [303d9786](https://github.com/openshift/cluster-api/commit/303d9786a5017d299b6e7fc702bb92f5cb4550cf) `sha256:c5b6d84ce9cd881674106e9d5f0c55e03317cafdda95cbcde64ba53978776ba1`
* [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator) git [9ca11878](https://github.com/openshift/cluster-cloud-controller-manager-operator/commit/9ca11878cc35862f4af4c194985b4f3ae3a835fa) `sha256:4953357b89695f26cc2222754bf568c818fdc72726964105da8060cdc4dd4e73`
* [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator) git [81541d53](https://github.com/openshift/cluster-control-plane-machine-set-operator/commit/81541d53f815a4cb25255b0dad33f449762c4609) `sha256:2e4cb5a92fbe49f3430848aedc405a75c9aa57357fdb505950225b74f964796c`
* [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator) git [f5d3bfe6](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/commit/f5d3bfe64bda67ffb8299af01ebf2722287edf04) `sha256:ba5fc184f6bc9e56a86fa2f1fef940426d59e40944bfc3fec5bf41fc8526c9c5`
* [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver) git [c96773c1](https://github.com/openshift/cluster-machine-approver/commit/c96773c19165a46d55007cd6a14d24376ab83d4c) `sha256:567ad2e36480829f0d0eecc1847de68688ed2a4801c8e8824bd20bc171f55ae3`
* [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator) git [a4147d33](https://github.com/openshift/cluster-samples-operator/commit/a4147d3308b2e935f58cf05eac4bf5fa35fa6cf8) `sha256:2625cfb6fb205f86a6e933fb1fff9f8f59888187dffc67d479769394cba5608b`
* [cluster-update-console-plugin](https://github.com/openshift/cluster-update-console-plugin) git [02b220dd](https://github.com/openshift/cluster-update-console-plugin/commit/02b220dd2aef5c1788768178e3ffd8592ccb89b9) `sha256:73af1ed191a3780a2be1fdb799c4285a41be3d12196b3e01c816740d77505c7a`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:8e9d1b35d18ba5e0aab80a02d1bde2f7a53c7db1ae497e993b893b983fc70693`
* [container-networking-plugins](https://github.com/openshift/containernetworking-plugins) git [b0bea6bc](https://github.com/openshift/containernetworking-plugins/commit/b0bea6bcba28cab2ffa15da03cbae98805af7eca) `sha256:85295ac93df93fcd9d818163f0bd65658b48f6dda586d8fb623015652143fc1c`
* [containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins) git [b0bea6bc](https://github.com/openshift/containernetworking-plugins/commit/b0bea6bcba28cab2ffa15da03cbae98805af7eca) `sha256:608ffdac72f0b3124bba8ad6e3e3318338c542bae06509c4869be999dcd976c7`
* [coredns](https://github.com/openshift/coredns) git [37aaba89](https://github.com/openshift/coredns/commit/37aaba896e97f4b9a091aab6d36f2213b8854474) `sha256:e5483ec5ec199523404f6337ca4de918c03f8800fa5a87ff4e8d70d5d4830718`
* [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [3fd668b3](https://github.com/openshift/csi-external-attacher/commit/3fd668b3f07dd382e5c7b6239d50f7988f652e64) `sha256:005cb5679e8e212ddbc325dd56c1d420358fa00170695cd7c2011e65b9a7e5c1`
* [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [7ff338c9](https://github.com/openshift/csi-external-provisioner/commit/7ff338c9d1296f0e5d4d8080a76bb191c8f3be30) `sha256:c00b7abbe244f5879be58d947974b23cff048d75801a518f879f10461f143af3`
* [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [14aa7028](https://github.com/openshift/csi-external-resizer/commit/14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf) `sha256:277d7c520e5a7c452c9676d4afadd9ef19607793d7aa89c3e176b196df8217c9`
* [csi-external-snapshotter](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:87c3f454eb9eb158fde83a52ed19eb90ac39f2383ffcd61eaf2b543f3c5b1bc4`
* [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [5766960d](https://github.com/openshift/csi-node-driver-registrar/commit/5766960d82ffb9ef84d15e903ae57d0a6781ef11) `sha256:3f29bf003750b69a8772e4de835a282709412315777ec0e9c0ad1829af76fa79`
* [csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:b12f544249d00791f44ead83e785e205377284b86090f18c0b08e7607de376c3`
* [docker-registry](https://github.com/openshift/image-registry) git [823010aa](https://github.com/openshift/image-registry/commit/823010aa7b0dcf1da53a26c2ec135d0a32e63d85) `sha256:ce5fbed30c38b48060b7c4eb25df31e44a47737bef03c1498fb1305570a604e5`
* [driver-toolkit](https://github.com/openshift/driver-toolkit) git [b63b175a](https://github.com/openshift/driver-toolkit/commit/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a) `sha256:3c1eae9d28e102e2481eec830a3376bc322954fa556fe3cb56f9bc5a503c7933`
* [driver-toolkit-10](https://github.com/openshift/driver-toolkit) git [b63b175a](https://github.com/openshift/driver-toolkit/commit/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a) `sha256:887538d7a9915439d99ba14ce76b31b3a9250ce373a78b905c8a64f04b0c5c09`
* [egress-router-cni](https://github.com/openshift/egress-router-cni) git [49554e57](https://github.com/openshift/egress-router-cni/commit/49554e572efac19f660a00ecfe2ccbc4e84be1e0) `sha256:b954ebaacc13ee7e210d8d0beda32dd9b8cb08e8ca7edf08752b994298044c70`
* [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp) git [51c32646](https://github.com/openshift/cloud-provider-gcp/commit/51c326465b3160124b8097953b42e44f1056da5a) `sha256:f49d7b8ff75cbda4c18dd7c587a778cf3c09145b5a6c43cdc99db35299f39826`
* [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp) git [5c3d8946](https://github.com/openshift/cluster-api-provider-gcp/commit/5c3d894654ec0316347b26fb586a074bab160b2e) `sha256:0ebb70aaf730d4c260f56f699a852cf569a920386f00226f966e15e082da9081`
* [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp) git [aac3d11b](https://github.com/openshift/machine-api-provider-gcp/commit/aac3d11bb011778fbb4f7717c59c18f617f82ad1) `sha256:91cff3beb9f43d3b546d8e4a045a3e4cd88c25030d010372d9f0111fd45324ba`
* [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver) git [049c0b96](https://github.com/openshift/gcp-pd-csi-driver/commit/049c0b96742c40fdd4384920afe17cefa5fa3d27) `sha256:c0ef6b3d96b1b457808de134d3d2e2e38f6523e92ab7844cae33c577e98388be`
* [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook) git [4501ff2f](https://github.com/openshift/gcp-workload-identity-federation-webhook/commit/4501ff2f53576c31df0511b69444e65e1eeba745) `sha256:0b6703f7e2b7dc70107931900cc22148629df2d8a5de37f22c0fcb7913a2e13e`
* [insights-runtime-exporter](https://github.com/openshift/insights-runtime-extractor) git [ba3de3b9](https://github.com/openshift/insights-runtime-extractor/commit/ba3de3b9777161897b75fc5a88e179dfbe8f6c53) `sha256:dc2878179cc407f5ca2e96194959dbe111c20c551368fbf61b080e5360bcb12b`
* [insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor) git [ba3de3b9](https://github.com/openshift/insights-runtime-extractor/commit/ba3de3b9777161897b75fc5a88e179dfbe8f6c53) `sha256:53d28d2ab90c2fb5d1d80492cc13d985a396e8357fd21809039ab5db944ede1f`
* [keepalived-ipfailover](https://github.com/openshift/images) git [32930575](https://github.com/openshift/images/commit/32930575a2bb3571601a7444becc06d06e901657) `sha256:4889707655b139d9843c8e759745375ab0682d8d37f118a5c4e04c754e9431c3`
* [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server) git [3d2e9cd0](https://github.com/openshift/kubernetes-metrics-server/commit/3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71) `sha256:b418310efa729e4c6ede83797d6071d367c0f5f9d6db7b89a4e2f57194f04dc8`
* [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt) git [5eb884ab](https://github.com/openshift/cloud-provider-kubevirt/commit/5eb884abcd2ff17ae8d7b2691ca12494597c08a6) `sha256:36a3ba73dfb7c9a5d5827e3442cc52b71c9a522ecd5e8848eb5002dc6efb7214`
* [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver) git [7ff99994](https://github.com/openshift/kubevirt-csi-driver/commit/7ff99994ecc3a675fac6f9aa7fa418cdb0dca32b) `sha256:647f6b117aa94ad9be44cfee17e272837744ac5d83d2ade8fa46017e745063b4`
* [multus-cni](https://github.com/openshift/multus-cni) git [f0468266](https://github.com/openshift/multus-cni/commit/f046826640baf19d335411b2116fe8d2124158d3) `sha256:08b3536eaa9ae8655560d58c26477d51a35f6679c618fa487ad03f190e3da182`
* [multus-cni-microshift](https://github.com/openshift/multus-cni) git [f0468266](https://github.com/openshift/multus-cni/commit/f046826640baf19d335411b2116fe8d2124158d3) `sha256:a24b84463ebe26109d99bf499ea929b6ba485b4202adae4d6989a73b3ba4e9c5`
* [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [39e9cccf](https://github.com/openshift/multus-networkpolicy/commit/39e9cccfa32951d0243c99638099da0a84d0d598) `sha256:deb5f6a7f80814961c2a5bfe2cd29696d49392845bd18ba9fae719f37d11d5f4`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [ce65e37e](https://github.com/openshift/route-override-cni/commit/ce65e37e2571101213bb32643316812df311701b) `sha256:7e2a623a4644066fbde3f1188c6f8b86758a15af018faa3bf175d0ab13397921`
* [network-interface-bond-cni](https://github.com/openshift/bond-cni) git [b8723844](https://github.com/openshift/bond-cni/commit/b8723844dc69940f55208cdb265653ab57f959f0) `sha256:b92bd29d81697180a77f70b3348f28375519a46825cfd719000b137703c90bba`
* [openshift-apiserver](https://github.com/openshift/openshift-apiserver) git [ab031522](https://github.com/openshift/openshift-apiserver/commit/ab0315228cde432c8cd62df012b791a66a72c7b3) `sha256:58591ca82a6bec99fd0e2cb57f6ac78a259c317aa1513e933f4064c384b872f5`
* [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager) git [5235418d](https://github.com/openshift/openshift-controller-manager/commit/5235418de7c86e6fae1004f84e55a2fbc1d3ac1c) `sha256:b1f3bf8d76a87568f84bdce975fded79d15cd80c0a4e6e7c8946b63b92d884ce`
* [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:50ac028a244a3adf886a8699cb8c5a5c853d9b0de9c6a5d48a64c602a21250f0`
* [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver) git [cfe345c7](https://github.com/openshift/ibm-powervs-block-csi-driver/commit/cfe345c7dd6e7f817927847690658b199c3d1653) `sha256:6f4c4372547d6fe00b47b00c06598b33d1216455f43b5dac3421907bca3c193d`
* [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator) git [f90431bf](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/commit/f90431bfe8ca93850450b2b24fae152d2385ca08) `sha256:325e27767fe2a05d68d10d3670d95eb37d716eb12dcf193c56194e7c8d0b5602`
* [service-ca-operator](https://github.com/openshift/service-ca-operator) git [ed872ba1](https://github.com/openshift/service-ca-operator/commit/ed872ba14b615ca5726ae90e987268877a0b0b20) `sha256:c4765d1f607169d7a2589089b2da680118167012ce3463d65570944630a1b929`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/db6eaf18787a49decbde2cfd368381cfe528e3cb)
* [MGMT-25431](https://issues.redhat.com/browse/MGMT-25431): CVE-2026-84445 Bump google.golang.org/grpc to v1.82.2 through indirect dependency conversion [#10975](https://github.com/openshift/assisted-service/pull/10975)
* [MGMT-24967](https://issues.redhat.com/browse/MGMT-24967): Static-IP iSCSI Boot-from-SAN Support in Assisted Installer [#10925](https://github.com/openshift/assisted-service/pull/10925)
* [OCPBUGS-115550](https://issues.redhat.com/browse/OCPBUGS-115550): Allow agent-installer invoker to have a suffix [#10968](https://github.com/openshift/assisted-service/pull/10968)
* [MGMT-25123](https://issues.redhat.com/browse/MGMT-25123): create endpoint for listing OVE images [#10933](https://github.com/openshift/assisted-service/pull/10933)
* [MGMT-25355](https://issues.redhat.com/browse/MGMT-25355): Migrate to harness-agnostic agent configuration layout [#10966](https://github.com/openshift/assisted-service/pull/10966)
* [ACM-38075](https://issues.redhat.com/browse/ACM-38075): Assisted Service Agent controller does not approve day-2 CSRs for worker nodes provisioned with pre-existing BMHs via ClusterInstance scale-out [#10944](https://github.com/openshift/assisted-service/pull/10944)
* NO-ISSUE: [master] Bump OCP versions: 4.21, 5.0, 4.16, 4.14, 4.22, 4.20, 4.19 [#10967](https://github.com/openshift/assisted-service/pull/10967)
* [MGMT-24854](https://issues.redhat.com/browse/MGMT-24854): Cilium CNI is not supported on OCP 4.22 [#10819](https://github.com/openshift/assisted-service/pull/10819)
* [MGMT-25367](https://issues.redhat.com/browse/MGMT-25367): consider imageType when selecting OpenShift version [#10917](https://github.com/openshift/assisted-service/pull/10917)
* [MGMT-25406](https://issues.redhat.com/browse/MGMT-25406): Add OpenShift-compatible CIDR length validation [#10948](https://github.com/openshift/assisted-service/pull/10948)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10946](https://github.com/openshift/assisted-service/pull/10946)
* NO-ISSUE: [master] Bump OCP versions: 4.21, 4.22, 4.20 [#10942](https://github.com/openshift/assisted-service/pull/10942)
* [ACM-41555](https://issues.redhat.com/browse/ACM-41555): Enable PQC in Dockerfiles [#10901](https://github.com/openshift/assisted-service/pull/10901)
* [MGMT-25131](https://issues.redhat.com/browse/MGMT-25131): When getting the release image for a cluster we should always prioritize cluster.OcpReleaseImage if it's set [#10938](https://github.com/openshift/assisted-service/pull/10938)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10941](https://github.com/openshift/assisted-service/pull/10941)
* NO-ISSUE: [master] Bump OCP versions: 5.0 [#10937](https://github.com/openshift/assisted-service/pull/10937)
* [APPSRE-14688](https://issues.redhat.com/browse/APPSRE-14688): remove legacy monitoring.coreos.com/v1 ServiceMonitors [#10931](https://github.com/openshift/assisted-service/pull/10931)
* NO-ISSUE: [master] Bump OCP versions: 4.17, 5.0 [#10924](https://github.com/openshift/assisted-service/pull/10924)
* [OCPBUGS-120683](https://issues.redhat.com/browse/OCPBUGS-120683): Fix NUMAResourcesOperator CR name so it can be applied [#10910](https://github.com/openshift/assisted-service/pull/10910)
* NO-ISSUE: Update operator bundle channel to ocm-5.1 [#10867](https://github.com/openshift/assisted-service/pull/10867)
* [OCPBUGS-120675](https://issues.redhat.com/browse/OCPBUGS-120675): added missing subscription name for lvms-operator [#10909](https://github.com/openshift/assisted-service/pull/10909)
* [AGENT-1529](https://issues.redhat.com/browse/AGENT-1529): Add ovnKubernetesConfig to install-config definition [#10430](https://github.com/openshift/assisted-service/pull/10430)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#10912](https://github.com/openshift/assisted-service/pull/10912)
* NO-ISSUE: [master] Bump OCP versions: 4.17, 4.19, 4.20, 4.16, 4.21 [#10907](https://github.com/openshift/assisted-service/pull/10907)
* NO-ISSUE:Bump go.opentelemetry.io/otel to v1.44.0 in master [#10869](https://github.com/openshift/assisted-service/pull/10869)
* [MGMT-25130](https://issues.redhat.com/browse/MGMT-25130): assisted-service and assisted-image-service NetworkPolicy ingress has no source restriction (any pod in any namespace can reach them directly) [#10906](https://github.com/openshift/assisted-service/pull/10906)
* NO-ISSUE: Modify Konflux YAMLs to ocm-5.1 [#10874](https://github.com/openshift/assisted-service/pull/10874)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/assisted-service/compare/d13116d7889481aa2d3c2f46f2449611f5a90356...db6eaf18787a49decbde2cfd368381cfe528e3cb)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/4282317d91570e00028984d6f22da3a17ad5513f)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#2339](https://github.com/openshift/assisted-installer/pull/2339)
* [OCPBUGS-115550](https://issues.redhat.com/browse/OCPBUGS-115550): Allow agent-installer invoker to have a suffix [#2341](https://github.com/openshift/assisted-installer/pull/2341)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#2326](https://github.com/openshift/assisted-installer/pull/2326)
* [ACM-41555](https://issues.redhat.com/browse/ACM-41555): Enable PQC in Dockerfiles [#2307](https://github.com/openshift/assisted-installer/pull/2307)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#2309](https://github.com/openshift/assisted-installer/pull/2309)
* NO-ISSUE: Refresh RPM lockfiles [SECURITY] [#2304](https://github.com/openshift/assisted-installer/pull/2304)
* [MGMT-24885](https://issues.redhat.com/browse/MGMT-24885): Harden command construction and credential handling [#2275](https://github.com/openshift/assisted-installer/pull/2275)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/87d1f289e17ea079cb8baf3ec897f9101ec65b00...4282317d91570e00028984d6f22da3a17ad5513f)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/234004589633185edd5b6c80504d7ddb81c291c7)
* [OCPBUGS-106189](https://issues.redhat.com/browse/OCPBUGS-106189): Assisted installer fails to disambiguate machines [#1625](https://github.com/openshift/assisted-installer-agent/pull/1625)
* [ACM-41555](https://issues.redhat.com/browse/ACM-41555): Enable PQC in Dockerfiles [#1622](https://github.com/openshift/assisted-installer-agent/pull/1622)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/a909d424d5bc542e7591b6a05cc817e46cf14ee9...234004589633185edd5b6c80504d7ddb81c291c7)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/cd6b338387fa652ffd1c23fc0ebb939486afe83b)
* [OCPBUGS-111479](https://issues.redhat.com/browse/OCPBUGS-111479): Quote variable expansion in `skopeo inspect` invocation [#348](https://github.com/openshift/agent-installer-utils/pull/348)
* [OCPBUGS-63475](https://issues.redhat.com/browse/OCPBUGS-63475): Refresh rendezvous IP selection list [#345](https://github.com/openshift/agent-installer-utils/pull/345)
* [OCPBUGS-123720](https://issues.redhat.com/browse/OCPBUGS-123720): Fix agent TUI timeout [#346](https://github.com/openshift/agent-installer-utils/pull/346)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/49322a1138a1a5cbcf7cbe58d78852b22a055fdd...cd6b338387fa652ffd1c23fc0ebb939486afe83b)
### [agentic-skills](https://github.com/openshift/agentic-skills/tree/6968f9025f62487cab799b5ad7e675ad13fa1f5a)
* [GITOPS-10499](https://issues.redhat.com/browse/GITOPS-10499): Add Argo knowledge skill [#38](https://github.com/openshift/agentic-skills/pull/38)
* [Full changelog](https://github.com/openshift/agentic-skills/compare/7aca4bee317cd70a4204795db6b1d7b9eb78f48c...6968f9025f62487cab799b5ad7e675ad13fa1f5a)
### [aws-cloud-controller-manager, aws-cluster-api-controllers, aws-ebs-csi-driver, aws-ebs-csi-driver-operator, aws-machine-controllers, aws-pod-identity-webhook, azure-cloud-controller-manager, azure-cloud-node-manager, azure-cluster-api-controllers, azure-disk-csi-driver, azure-disk-csi-driver-operator, azure-file-csi-driver, azure-file-csi-driver-operator, azure-machine-controllers, azure-workload-identity-webhook, hyperkube, ibm-cloud-controller-manager, ibm-vpc-block-csi-driver, ibm-vpc-block-csi-driver-operator, ibmcloud-machine-controllers, ironic, ironic-agent, ironic-machine-os-downloader, ironic-static-ip-manager, kube-proxy, machine-image-customization-controller, nutanix-cloud-controller-manager, nutanix-machine-controllers, pod, vsphere-cloud-controller-manager, vsphere-cluster-api-controllers, vsphere-csi-driver, vsphere-csi-driver-operator, vsphere-csi-driver-syncer, vsphere-problem-detector](https://github.com/openshift/kubernetes/tree/7cb7f330df454d8581b579ad835ad6b263533126)
* NO-JIRA: Rebase master to Kubernetes v1.36.4 [#2777](https://github.com/openshift/kubernetes/pull/2777)
* NO-JIRA: Skip SELinuxMountReadWriteOncePodOnly tests now that SELinuxMount is GA [#2782](https://github.com/openshift/kubernetes/pull/2782)
* [OCPBUGS-104846](https://issues.redhat.com/browse/OCPBUGS-104846): UPSTREAM: 141358: Enable group snapshot tests in all configurations [#2747](https://github.com/openshift/kubernetes/pull/2747)
* [Full changelog](https://github.com/openshift/kubernetes/compare/fb553cd105957b64651b393cb1a42f59faab190e...7cb7f330df454d8581b579ad835ad6b263533126)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/27c9527374d3d714ade3988f18cdc6eb46bc8262)
* [OCPBUGS-85090](https://issues.redhat.com/browse/OCPBUGS-85090): Align simulated with actual allocatable resources [#46](https://github.com/openshift/aws-karpenter-provider-aws/pull/46)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#44](https://github.com/openshift/aws-karpenter-provider-aws/pull/44)
* [AUTOSCALE-904](https://issues.redhat.com/browse/AUTOSCALE-904): Add agentic SDLC artifacts to aws-karpenter-provider-aws [#41](https://github.com/openshift/aws-karpenter-provider-aws/pull/41)
* [OCPBUGS-85085](https://issues.redhat.com/browse/OCPBUGS-85085): default max-pods to 250 for Custom AMI family [#40](https://github.com/openshift/aws-karpenter-provider-aws/pull/40)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/dc822233cc526b6cc55f20009a4c1b034f245133...27c9527374d3d714ade3988f18cdc6eb46bc8262)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/987d45178f07740138e98234ff2cbc5571d4b7a5)
* [OCPBUGS-115550](https://issues.redhat.com/browse/OCPBUGS-115550): use different INSTALL_INVOKER for unconfigured ignition [#10848](https://github.com/openshift/installer/pull/10848)
* [OCPBUGS-99762](https://issues.redhat.com/browse/OCPBUGS-99762): retry Azure bootstrap ignition upload [#10835](https://github.com/openshift/installer/pull/10835)
* [OCPBUGS-90536](https://issues.redhat.com/browse/OCPBUGS-90536): openstack: Guard network resource names on `os_net_id` being defined [#10639](https://github.com/openshift/installer/pull/10639)
* [OCPBUGS-123770](https://issues.redhat.com/browse/OCPBUGS-123770): Inject the pull-secret as podman secret in the agent-installer-ui container [#10882](https://github.com/openshift/installer/pull/10882)
* [OCPBUGS-112483](https://issues.redhat.com/browse/OCPBUGS-112483): use api-int record for ignition host when using externally managed LB and DNS [#10860](https://github.com/openshift/installer/pull/10860)
* no-jira: aws: fetch instance type on demand instead of listing all [#10851](https://github.com/openshift/installer/pull/10851)
* [OCPBUGS-61892](https://issues.redhat.com/browse/OCPBUGS-61892): fix swap disk nil-panic and block swap on control plane [#10859](https://github.com/openshift/installer/pull/10859)
* [OCPBUGS-59743](https://issues.redhat.com/browse/OCPBUGS-59743): azure: reject data disks on Azure Stack Hub [#10823](https://github.com/openshift/installer/pull/10823)
* [OCPBUGS-86133](https://issues.redhat.com/browse/OCPBUGS-86133): dont allow duplicate failure domains and fields [#10741](https://github.com/openshift/installer/pull/10741)
* [OCPBUGS-91640](https://issues.redhat.com/browse/OCPBUGS-91640): Warn about ignored install-config fields in ABI [#10646](https://github.com/openshift/installer/pull/10646)
* [OCPBUGS-114375](https://issues.redhat.com/browse/OCPBUGS-114375): azure: skip AppendVarPartition when DiskSetup provides a user-defined /var mount [#10818](https://github.com/openshift/installer/pull/10818)
* [OCPBUGS-115187](https://issues.redhat.com/browse/OCPBUGS-115187): Gather master only from primary IP on baremetal [#10838](https://github.com/openshift/installer/pull/10838)
* [OCPBUGS-114882](https://issues.redhat.com/browse/OCPBUGS-114882): OCPBUGS-112662: GCD load balancer health-check firewall ranges [#10850](https://github.com/openshift/installer/pull/10850)
* [SPLAT-2923](https://issues.redhat.com/browse/SPLAT-2923): vsphere: retry and throttle vCenter lookups during UPI VM creation [#10847](https://github.com/openshift/installer/pull/10847)
* [Full changelog](https://github.com/openshift/installer/compare/c8d299965fc1527648ce7aeb368c198a7b28e85d...987d45178f07740138e98234ff2cbc5571d4b7a5)
### [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal/tree/20e143749b9bdb4b0cb8387bacae2ad5feece6bf)
* [OCPBUGS-123730](https://issues.redhat.com/browse/OCPBUGS-123730): Bump golang.org/x/net to v0.58.0 to address CVE-2026-33814 [#279](https://github.com/openshift/cluster-api-provider-baremetal/pull/279)
* [OCPBUGS-112338](https://issues.redhat.com/browse/OCPBUGS-112338): Fix race that can provision multiple hosts [#275](https://github.com/openshift/cluster-api-provider-baremetal/pull/275)
* [Full changelog](https://github.com/openshift/cluster-api-provider-baremetal/compare/f2b0db1919fff1344bc68948894c6775c0bf24a3...20e143749b9bdb4b0cb8387bacae2ad5feece6bf)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/8511455cfcf63d7daa377b4db8050e99ce0e7603)
* [OCPBUGS-121877](https://issues.redhat.com/browse/OCPBUGS-121877): pull in gophercloud fix for fast inspection [#525](https://github.com/openshift/baremetal-operator/pull/525)
* [OCPBUGS-122043](https://issues.redhat.com/browse/OCPBUGS-122043), [OCPBUGS-91736](https://issues.redhat.com/browse/OCPBUGS-91736): Merge upstream [#524](https://github.com/openshift/baremetal-operator/pull/524)
* NO-ISSUE: Merge upstream 2026-09-03 [#523](https://github.com/openshift/baremetal-operator/pull/523)
* NO-ISSUE: Restore .golangci.yaml downstream [#522](https://github.com/openshift/baremetal-operator/pull/522)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/34bbeb376836bf01793d4e70d29065d619ebcaa1...8511455cfcf63d7daa377b4db8050e99ce0e7603)
### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/3a0594b2c808b056d037e82093f0ca2268832792)
* [OCPBUGS-98258](https://issues.redhat.com/browse/OCPBUGS-98258): Cloud Platforms: Filter out node's own IP from Upstreams [#399](https://github.com/openshift/baremetal-runtimecfg/pull/399)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/3057d9978db74dcd5012a293d37d571b524c4e46...3a0594b2c808b056d037e82093f0ca2268832792)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/75a043dda6d517af6f40fcf77f371be33e80b59a)
* [OCPBUGS-126457](https://issues.redhat.com/browse/OCPBUGS-126457): [oc create route edge --help] Typo in WildcardPolicy option description [#2409](https://github.com/openshift/oc/pull/2409)
* [OCPBUGS-122354](https://issues.redhat.com/browse/OCPBUGS-122354): Fix inconsistent terminology in oc set probe help example [#2404](https://github.com/openshift/oc/pull/2404)
* [OCPBUGS-122036](https://issues.redhat.com/browse/OCPBUGS-122036): docs(env): add deployment example for configmap import in oc set env help [#2401](https://github.com/openshift/oc/pull/2401)
* NO-JIRA: README: Mention gcc as an oc dependency [#2402](https://github.com/openshift/oc/pull/2402)
* [OCPBUGS-122005](https://issues.redhat.com/browse/OCPBUGS-122005): Add IDMS support to `oc image info` [#2397](https://github.com/openshift/oc/pull/2397)
* [OCPBUGS-114015](https://issues.redhat.com/browse/OCPBUGS-114015): Added deployment example to oc set env help command [#2389](https://github.com/openshift/oc/pull/2389)
* NO-JIRA: Move to openshift/osincli [#2386](https://github.com/openshift/oc/pull/2386)
* [Full changelog](https://github.com/openshift/oc/compare/2902632b849a20d312215e16f2058233f1713553...75a043dda6d517af6f40fcf77f371be33e80b59a)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/5c4a3963b75cd85a180c2680d9ae77f5a98c5019)
* [CCO-771](https://issues.redhat.com/browse/CCO-771): Add ccoctl apply secrets command for AWS, Azure and GCP [#1095](https://github.com/openshift/cloud-credential-operator/pull/1095)
* [OCPBUGS-17664](https://issues.redhat.com/browse/OCPBUGS-17664): Improve error messages for SCP-denied IAM operations [#1084](https://github.com/openshift/cloud-credential-operator/pull/1084)
* [CCO-849](https://issues.redhat.com/browse/CCO-849): bump go toolchain to 1.26.5 to resolve snyk complaints [#1065](https://github.com/openshift/cloud-credential-operator/pull/1065)
* [OCPBUGS-112282](https://issues.redhat.com/browse/OCPBUGS-112282): In testing skip pod-identity-webhook checks on external platform [#1085](https://github.com/openshift/cloud-credential-operator/pull/1085)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/b187feee66f4ce0f992059b21a97a2ae88e4cdd9...5c4a3963b75cd85a180c2680d9ae77f5a98c5019)
### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/d3b5de705d133ad568e37b8ccf027d5ccd5e7d38)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): refactor: remove Azure workload identity feature gate [#266](https://github.com/openshift/cloud-network-config-controller/pull/266)
* [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/82bed43e8218e8c22de1b65ccd141096e92685fb...d3b5de705d133ad568e37b8ccf027d5ccd5e7d38)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/e5d042008d9aab23414c4be66fcfbd430d0f996d)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2463 [#997](https://github.com/openshift/cluster-authentication-operator/pull/997)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#991](https://github.com/openshift/cluster-authentication-operator/pull/991)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2439 [#987](https://github.com/openshift/cluster-authentication-operator/pull/987)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pick https://github.com/openshift/library-go/pull/2449- #2287 [#985](https://github.com/openshift/cluster-authentication-operator/pull/985)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2451 [#984](https://github.com/openshift/cluster-authentication-operator/pull/984)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire EncryptionConfigurationComputer into encryption controllers [#983](https://github.com/openshift/cluster-authentication-operator/pull/983)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/14c33fae096437e8c703d312156d7adf2a8f7e34...e5d042008d9aab23414c4be66fcfbd430d0f996d)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/a819db459f3e0a88becba4c58bf053c6dbda28f2)
* [AUTOSCALE-898](https://issues.redhat.com/browse/AUTOSCALE-898): Add agentic SDLC files [#437](https://github.com/openshift/kubernetes-autoscaler/pull/437)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/f393f54229e6c3ae74c35ae72012af92d31c03d3...a819db459f3e0a88becba4c58bf053c6dbda28f2)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/e1eabae06e1c08f4becfa99e56ca9f707fa10abd)
* Metal-1833: Add attach_non_bootable_iso OTE test [#617](https://github.com/openshift/cluster-baremetal-operator/pull/617)
* [OCPBUGS-115207](https://issues.redhat.com/browse/OCPBUGS-115207): Make HostPath VolumeMounts ReadOnly for image customization container [#658](https://github.com/openshift/cluster-baremetal-operator/pull/658)
* [OCPBUGS-86888](https://issues.redhat.com/browse/OCPBUGS-86888): Fix IDMS YAML serialization for oc image extract [#645](https://github.com/openshift/cluster-baremetal-operator/pull/645)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add bmo_validations and ncsi_reject_poweroff OTE test [#618](https://github.com/openshift/cluster-baremetal-operator/pull/618)
* [OCPBUGS-115067](https://issues.redhat.com/browse/OCPBUGS-115067): Use bcrypt DefaultCost for Ironic passwords [#650](https://github.com/openshift/cluster-baremetal-operator/pull/650)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/bc67262323fe29fe1793bf7f421e214a2500476f...e1eabae06e1c08f4becfa99e56ca9f707fa10abd)
### [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap/tree/86a2349618a095e9558a008130f64ebb16ee8c30)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#146](https://github.com/openshift/cluster-bootstrap/pull/146)
* [CNTRLPLANE-3717](https://issues.redhat.com/browse/CNTRLPLANE-3717): Add Agentic SDLC context files [#133](https://github.com/openshift/cluster-bootstrap/pull/133)
* [CNF-23048](https://issues.redhat.com/browse/CNF-23048): Migrate away from deprecated ioutil [#123](https://github.com/openshift/cluster-bootstrap/pull/123)
* [Full changelog](https://github.com/openshift/cluster-bootstrap/compare/7b1593a47898b6a97dc457efaca464624e9f2afa...86a2349618a095e9558a008130f64ebb16ee8c30)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/02013fdb38814f1ddc8ac46e568d7369e6ec687b)
* [OCPBUGS-100155](https://issues.redhat.com/browse/OCPBUGS-100155): fix flaky MachineSet sync test by atomically verifying InfraTemplate [#647](https://github.com/openshift/cluster-capi-operator/pull/647)
* [OCPBUGS-114670](https://issues.redhat.com/browse/OCPBUGS-114670): fix(capi2mapi): normalize empty SSHKeyName to nil for MAPI AWS conversion [#659](https://github.com/openshift/cluster-capi-operator/pull/659)
* [OCPBUGS-115197](https://issues.redhat.com/browse/OCPBUGS-115197): machinesync: preserve Synchronized condition lastTransitionTime in CAPI-to-MAPI sync [#656](https://github.com/openshift/cluster-capi-operator/pull/656)
* NO-JIRA: Skip CAPI IPAM test on MicroShift [#661](https://github.com/openshift/cluster-capi-operator/pull/661)
* [OCPCLOUD-3557](https://issues.redhat.com/browse/OCPCLOUD-3557): split capi-controllers and machine-api-migration [#622](https://github.com/openshift/cluster-capi-operator/pull/622)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/a134d6fc659a598150e669c6041c925c7036a4a3...02013fdb38814f1ddc8ac46e568d7369e6ec687b)
### [cluster-config-api](https://github.com/openshift/api/tree/9fb49bfd35acae3aad6414514f669568ada12ada)
* NO-JIRA: Fix codegen diagnostic formatting [#3049](https://github.com/openshift/api/pull/3049)
* operator: Add an option to configure OVN-Kubernetes GatewayConfig without an uplink specified. [#3009](https://github.com/openshift/api/pull/3009)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): chore: remove AzureWorkloadIdentity feature gate [#3018](https://github.com/openshift/api/pull/3018)
* [OPRUN-4768](https://issues.redhat.com/browse/OPRUN-4768): Add serving TLS curve preferences [#3044](https://github.com/openshift/api/pull/3044)
* Remove feature gate VolumeGroupSnapshot [#3027](https://github.com/openshift/api/pull/3027)
* [STOR-3089](https://issues.redhat.com/browse/STOR-3089): Graduate SELinuxMount to GA [#3023](https://github.com/openshift/api/pull/3023)
* [OCPBUGS-112638](https://issues.redhat.com/browse/OCPBUGS-112638): register DRADeviceTaintRules in TPNU [#3004](https://github.com/openshift/api/pull/3004)
* Fix validation pattern for machine/vsphereprovider [#3033](https://github.com/openshift/api/pull/3033)
* features: enable TLSAdherence feature gate for OKD featureset [#3021](https://github.com/openshift/api/pull/3021)
* [CORENET-7538](https://issues.redhat.com/browse/CORENET-7538): Add EgressIPNodeSelector feature gate [#3032](https://github.com/openshift/api/pull/3032)
* [SPLAT-2890](https://issues.redhat.com/browse/SPLAT-2890): Add VSphereScopedCredentials feature gate [#2988](https://github.com/openshift/api/pull/2988)
* [MCO-2332](https://issues.redhat.com/browse/MCO-2332): MCO-2333: Introduce CAPI resource types to boot image update API [#2990](https://github.com/openshift/api/pull/2990)
* [Full changelog](https://github.com/openshift/api/compare/c7d4aa14a7649477cdb9e7c4a733d61bf70913ea...9fb49bfd35acae3aad6414514f669568ada12ada)
### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/6a4d4a58182fa4e810c9c6bf66d14eea4cfe37bb)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#504](https://github.com/openshift/cluster-config-operator/pull/504)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#500](https://github.com/openshift/cluster-config-operator/pull/500)
* [OCPEDGE-2747](https://issues.redhat.com/browse/OCPEDGE-2747): feat: add topology transition controller for day-2 SNO to HA transitions [#495](https://github.com/openshift/cluster-config-operator/pull/495)
* [Full changelog](https://github.com/openshift/cluster-config-operator/compare/9f787f73f5fffca5cd511ef2c2e704afc14f68ce...6a4d4a58182fa4e810c9c6bf66d14eea4cfe37bb)
### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/03b68fd87ae423f78b2a31174d6c432acad47eb5)
* [OCPBUGS-104846](https://issues.redhat.com/browse/OCPBUGS-104846): Remove VolumeGroupSnapshot feature gate [#297](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/297)
* [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/35ec0224eb0e5219d5eae012fb703223a6f3e1f7...03b68fd87ae423f78b2a31174d6c432acad47eb5)
### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/c480e21c16d3383a7c09752f8dea61743c765cfa)
* [ART-23537](https://issues.redhat.com/browse/ART-23537): Fix hermetic build failure by removing update-bindata from build target [#489](https://github.com/openshift/cluster-dns-operator/pull/489)
* [NE-2880](https://issues.redhat.com/browse/NE-2880): Update GitHub issue template URLs [#487](https://github.com/openshift/cluster-dns-operator/pull/487)
* [NE-2126](https://issues.redhat.com/browse/NE-2126): Migrating DNS operator test cases from QE repo [#485](https://github.com/openshift/cluster-dns-operator/pull/485)
* [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/c0ed09e329e9001629518604a58205e3fbe8284a...c480e21c16d3383a7c09752f8dea61743c765cfa)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/891802de59125027f63e4e15d153ca9f4301744f)
* [CNTRLPLANE-4414](https://issues.redhat.com/browse/CNTRLPLANE-4414): allow TLS 1.3 profiles without ciphers [#1710](https://github.com/openshift/cluster-etcd-operator/pull/1710)
* NO-JIRA: refactor: remove unused cert-watcher daemonset manifest [#1711](https://github.com/openshift/cluster-etcd-operator/pull/1711)
* [OCPBUGS-123168](https://issues.redhat.com/browse/OCPBUGS-123168): fix: add missing workload paritioning annotation on cert-watcher daemonset [#1706](https://github.com/openshift/cluster-etcd-operator/pull/1706)
* [OCPBUGS-104851](https://issues.redhat.com/browse/OCPBUGS-104851): feat: add cert-watcher DaemonSet to restart etcd on CA bundle rotation [#1675](https://github.com/openshift/cluster-etcd-operator/pull/1675)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/36c44461e9bd3af7c76915058370da87bc2ceb39...891802de59125027f63e4e15d153ca9f4301744f)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/7c198c202079bc9dc76debab40dcf5610bcf8707)
* [OCPBUGS-114531](https://issues.redhat.com/browse/OCPBUGS-114531): Add 2m degraded inertia to ImagePrunerController [#1365](https://github.com/openshift/cluster-image-registry-operator/pull/1365)
* [OCPBUGS-112551](https://issues.redhat.com/browse/OCPBUGS-112551): imageconfig: Preserve ImageStreamImportMode during upgrade race [#1363](https://github.com/openshift/cluster-image-registry-operator/pull/1363)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/f9c7439f0924147bc02f2bf74ad403ebe105408d...7c198c202079bc9dc76debab40dcf5610bcf8707)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/a373f6b0e8b36ed26c84e2d0f1dee64dd81351d4)
* [OCPBUGS-122346](https://issues.redhat.com/browse/OCPBUGS-122346): Fix GatewayClass index registration retries during bootstrap [#1588](https://github.com/openshift/cluster-ingress-operator/pull/1588)
* [OCPBUGS-105442](https://issues.redhat.com/browse/OCPBUGS-105442): Remove escalate/bind from Sail Library ClusterRole [#1548](https://github.com/openshift/cluster-ingress-operator/pull/1548)
* [NE-2909](https://issues.redhat.com/browse/NE-2909): Address Gateway API management-mode follow-ups [#1595](https://github.com/openshift/cluster-ingress-operator/pull/1595)
* [OCPBUGS-105317](https://issues.redhat.com/browse/OCPBUGS-105317): Bump to OSSM 3.4.2 and istio 1.30.4 [#1576](https://github.com/openshift/cluster-ingress-operator/pull/1576)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): docs: clarify Azure workload identity token file [#1586](https://github.com/openshift/cluster-ingress-operator/pull/1586)
* NO-JIRA: Add pedjak to OWNERS [#1596](https://github.com/openshift/cluster-ingress-operator/pull/1596)
* [NE-2388](https://issues.redhat.com/browse/NE-2388): aws nlb security groups [#1500](https://github.com/openshift/cluster-ingress-operator/pull/1500)
* [NE-2779](https://issues.redhat.com/browse/NE-2779): Implement Gateway API management mode [#1547](https://github.com/openshift/cluster-ingress-operator/pull/1547)
* [OCPBUGS-86050](https://issues.redhat.com/browse/OCPBUGS-86050): Update ROUTER_CURVES environment variable for go 1.26 [#1542](https://github.com/openshift/cluster-ingress-operator/pull/1542)
* [OCPBUGS-6718](https://issues.redhat.com/browse/OCPBUGS-6718): minimize wildcard RBAC permissions [#1579](https://github.com/openshift/cluster-ingress-operator/pull/1579)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): refactor: remove Azure workload identity feature gate [#1575](https://github.com/openshift/cluster-ingress-operator/pull/1575)
* [NE-2491](https://issues.redhat.com/browse/NE-2491): Delete the CRL controller [#1536](https://github.com/openshift/cluster-ingress-operator/pull/1536)
* [WAF-3](https://issues.redhat.com/browse/WAF-3): Implement extension provider capability for WAF [#1555](https://github.com/openshift/cluster-ingress-operator/pull/1555)
* [OCPBUGS-62627](https://issues.redhat.com/browse/OCPBUGS-62627): Suppress Progressing during infrastructure-driven ingress unavailability [#1496](https://github.com/openshift/cluster-ingress-operator/pull/1496)
* [OCPBUGS-92835](https://issues.redhat.com/browse/OCPBUGS-92835): add grace period to Available condition for deployment… [#1544](https://github.com/openshift/cluster-ingress-operator/pull/1544)
* [OCPBUGS-109582](https://issues.redhat.com/browse/OCPBUGS-109582): Normalize malformed CIDRs to avoid upgrade disruptions [#1549](https://github.com/openshift/cluster-ingress-operator/pull/1549)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/5bf72fcc4534d9ba2c4d65d29cdb8b01c83cf550...a373f6b0e8b36ed26c84e2d0f1dee64dd81351d4)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/ae7f3ea3f0fb68b2eafb247049835d5d8543923e)
* [OPRUN-4768](https://issues.redhat.com/browse/OPRUN-4768): bump openshift/api [#2316](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2316)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2463 [#2309](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2309)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#2307](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2307)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2439 [#2282](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2282)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pick https://github.com/openshift/library-go/pull/2449 [#2287](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2287)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2451 [#2289](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2289)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire EncryptionConfigurationComputer into encryption controllers [#2292](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2292)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/2fa5365f29eff19a528856740274fe0c37b18b68...ae7f3ea3f0fb68b2eafb247049835d5d8543923e)
### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/416af3a20bd39d33d7506f04a6c483528aa9e6dc)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#967](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/967)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/330fe4a6ed1a15ae1c2b572138d596fd5780d318...416af3a20bd39d33d7506f04a6c483528aa9e6dc)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/7d896ecefe171028a01f6b7cfdbf30bc5828b414)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#676](https://github.com/openshift/cluster-kube-scheduler-operator/pull/676)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/6a750a9fd626675a2bc35b43b75dbc182ce3d8e9...7d896ecefe171028a01f6b7cfdbf30bc5828b414)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/ffa52202be7ea5a7b313d10ed1cc9af8f97ed968)
* [MON-4689](https://issues.redhat.com/browse/MON-4689), [OCPBUGS-123539](https://issues.redhat.com/browse/OCPBUGS-123539): Bump prometheus-operator jsonnet and libs to v0.94.0 [#3083](https://github.com/openshift/cluster-monitoring-operator/pull/3083)
* [OCPBUGS-123792](https://issues.redhat.com/browse/OCPBUGS-123792): restore node-exporter textfile metrics with read-only rootfs [#3088](https://github.com/openshift/cluster-monitoring-operator/pull/3088)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3089](https://github.com/openshift/cluster-monitoring-operator/pull/3089)
* NO-JIRA: Skip flaky TestTelemetryReport/rate_issues subtest [#3087](https://github.com/openshift/cluster-monitoring-operator/pull/3087)
* [OCPBUGS-83375](https://issues.redhat.com/browse/OCPBUGS-83375): Create alerting rule for metrics-server failing to scrape kubelet [#2933](https://github.com/openshift/cluster-monitoring-operator/pull/2933)
* [MON-4638](https://issues.redhat.com/browse/MON-4638): align ThanosQueryOverload description with for=1h [#3062](https://github.com/openshift/cluster-monitoring-operator/pull/3062)
* [MON-4665](https://issues.redhat.com/browse/MON-4665): wire zoneinfo node-exporter collector from ClusterMonitorin… [#3063](https://github.com/openshift/cluster-monitoring-operator/pull/3063)
* NO-JIRA: Makefile: ensure JUnit test name prefix is applied even on test failure [#3079](https://github.com/openshift/cluster-monitoring-operator/pull/3079)
* NO-ISSUE: update jsonnet dependencies [#3077](https://github.com/openshift/cluster-monitoring-operator/pull/3077)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3076](https://github.com/openshift/cluster-monitoring-operator/pull/3076)
* [MON-4560](https://issues.redhat.com/browse/MON-4560): implement merge logic in CMO for the new field in the ClusterMonitoring CRD [#3056](https://github.com/openshift/cluster-monitoring-operator/pull/3056)
* [MON-4632](https://issues.redhat.com/browse/MON-4632), [MON-4633](https://issues.redhat.com/browse/MON-4633): Send metrics ramen:dr_policy_type:max and ramen:dr_protected_apps:max via Telemetry [#3074](https://github.com/openshift/cluster-monitoring-operator/pull/3074)
* [MON-4617](https://issues.redhat.com/browse/MON-4617): Update kube-prometheus and add resourceMetricsAPI field [#3069](https://github.com/openshift/cluster-monitoring-operator/pull/3069)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3068](https://github.com/openshift/cluster-monitoring-operator/pull/3068)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/f581865b41267ff23bbf1cb30fbdd2e02cecd42f...ffa52202be7ea5a7b313d10ed1cc9af8f97ed968)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/61de77e4d4c4f65cd5b3d73e00308bfe837c1066)
* NO-JIRA: fix(ovn-kubernetes): disable local DB probes [#3163](https://github.com/openshift/cluster-network-operator/pull/3163)
* [CORENET-7275](https://issues.redhat.com/browse/CORENET-7275): Add AGENTS.md, point CodeRabbit knowledge base at it [#3146](https://github.com/openshift/cluster-network-operator/pull/3146)
* [CORENET-7479](https://issues.redhat.com/browse/CORENET-7479): Add status.vrfName and shortNames to UDN/CUDN CRDs [#3145](https://github.com/openshift/cluster-network-operator/pull/3145)
* [OCPBUGS-113591](https://issues.redhat.com/browse/OCPBUGS-113591): golangci-lint: enable ContextTodo/ContextBackground in usetesting [#3138](https://github.com/openshift/cluster-network-operator/pull/3138)
* [OCPBUGS-92080](https://issues.redhat.com/browse/OCPBUGS-92080): Adds rendering of enable-multi-network-policy in ovnkube-node [#3084](https://github.com/openshift/cluster-network-operator/pull/3084)
* [OCPBUGS-112562](https://issues.redhat.com/browse/OCPBUGS-112562): CVE-2026-41178 - bump go.opentelemetry.io/otel to v1.44.0 [#3132](https://github.com/openshift/cluster-network-operator/pull/3132)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/31a6ffd3e4c2b466607c21bed423d33b1f7e77e6...61de77e4d4c4f65cd5b3d73e00308bfe837c1066)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/b4c215b68874838b91ee73dcd2fc63897add46f6)
* [OCPBUGS-112336](https://issues.redhat.com/browse/OCPBUGS-112336): apis: add missing fields to apis v1 [#1597](https://github.com/openshift/cluster-node-tuning-operator/pull/1597)
* NO-JIRA: Fix CentOS Stream image build failing in dnf history undo [#1633](https://github.com/openshift/cluster-node-tuning-operator/pull/1633)
* [CNF-23698](https://issues.redhat.com/browse/CNF-23698): e2e: make OVS dynamic pinning tests compatible with ovsDpdk CPUs [#1598](https://github.com/openshift/cluster-node-tuning-operator/pull/1598)
* [CNF-25173](https://issues.redhat.com/browse/CNF-25173): e2e: resolve primary MCP from profile in test 32364 [#1624](https://github.com/openshift/cluster-node-tuning-operator/pull/1624)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/246b707a99945e3c23291d7776446358ec3b7511...b4c215b68874838b91ee73dcd2fc63897add46f6)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/9afc2cacd8fcb69af291396d387b52d3ca140eb1)
* [OCPBUGS-105876](https://issues.redhat.com/browse/OCPBUGS-105876): Wire availableInertia into the olm StatusSyncer [#233](https://github.com/openshift/cluster-olm-operator/pull/233)
* [OPRUN-4645](https://issues.redhat.com/browse/OPRUN-4645): observe and apply TLS curve preferences to operand deployments [#226](https://github.com/openshift/cluster-olm-operator/pull/226)
* NO-ISSUE: Bump helm.sh/helm/v3 from 3.21.3 to 3.21.4 [#235](https://github.com/openshift/cluster-olm-operator/pull/235)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/addad7cab1b1cb0854349c8404c08128fe420402...9afc2cacd8fcb69af291396d387b52d3ca140eb1)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/4978130a0b2ed26971dca5e7758d6310d1b5a2b1)
* [OPRUN-4768](https://issues.redhat.com/browse/OPRUN-4768): bump openshift/api [#782](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/782)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2463- #2309 [#770](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/770)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#768](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/768)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2439 [#767](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/767)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pick https://github.com/openshift/library-go/pull/2449- #2287 [#764](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/764)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): pull https://github.com/openshift/library-go/pull/2451 [#763](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/763)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms: wire EncryptionConfigurationComputer into encryption controllers [#762](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/762)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/c7cea84d7f74b5aca7ea27e49fc2be814d744e60...4978130a0b2ed26971dca5e7758d6310d1b5a2b1)
### [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator/tree/8da2f1fcb1e76e8b1b97b16ca7bbfa7116287eb8)
* [OCPBUGS-112448](https://issues.redhat.com/browse/OCPBUGS-112448): Bump kubernetes dependencies to v1.36 [#444](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/444)
* [Full changelog](https://github.com/openshift/cluster-openshift-controller-manager-operator/compare/ca4d2061fba488b34c042e7a16946157db595599...8da2f1fcb1e76e8b1b97b16ca7bbfa7116287eb8)
### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/c9e9a348260921c9e788e33a51e904502cbe2d13)
* [CNTRLPLANE-3731](https://issues.redhat.com/browse/CNTRLPLANE-3731): Add Agentic SDLC context files to cluster-policy-controller [#191](https://github.com/openshift/cluster-policy-controller/pull/191)
* [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/469bbf211d35eee0df4422bda7e9e600b080f0f2...c9e9a348260921c9e788e33a51e904502cbe2d13)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/da41a216e9cdc764fb8e2fd0447029e68893e1ee)
* [GCP-958](https://issues.redhat.com/browse/GCP-958): re-enable GCP PD CSI driver in HyperShift path [#742](https://github.com/openshift/cluster-storage-operator/pull/742)
* [GCP-958](https://issues.redhat.com/browse/GCP-958): temporarily disable GCP PD CSI driver in HyperShift path [#739](https://github.com/openshift/cluster-storage-operator/pull/739)
* [GCP-1075](https://issues.redhat.com/browse/GCP-1075): feat(gcp-pd): enable HyperShift support for GCP PD CSI driver operator [#728](https://github.com/openshift/cluster-storage-operator/pull/728)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/6b031ec699a65512557b70eabedd85a95c238bbb...da41a216e9cdc764fb8e2fd0447029e68893e1ee)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/882fd242b69c14e475f5671294712cec88c62c7f)
* [OKD-194](https://issues.redhat.com/browse/OKD-194): Add OKD cincinnati as the default update service for OKD [#1466](https://github.com/openshift/cluster-version-operator/pull/1466)
* [OTA-2109](https://issues.redhat.com/browse/OTA-2109): harden console plugin nginx TLS configuration [#1453](https://github.com/openshift/cluster-version-operator/pull/1453)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/697ea9314e3e5c39b218b8781b32813b0e4ae84c...882fd242b69c14e475f5671294712cec88c62c7f)
### [configmap-reloader](https://github.com/openshift/configmap-reload/tree/596569055fdaa7f01d0ecdd5a29579d5f9196328)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#84](https://github.com/openshift/configmap-reload/pull/84)
* [Full changelog](https://github.com/openshift/configmap-reload/compare/ce80869a83b55ebbdc21a5550ec5747645203bd2...596569055fdaa7f01d0ecdd5a29579d5f9196328)
### [console](https://github.com/openshift/console/tree/afe3510f5b5737edb0ab93a584db5d0d85c49f73)
* [OCPBUGS-126807](https://issues.redhat.com/browse/OCPBUGS-126807): Post qa-verify evidence via gh's native --attach instead of base64 [#17193](https://github.com/openshift/console/pull/17193)
* [OCPBUGS-125223](https://issues.redhat.com/browse/OCPBUGS-125223): restore some old test-prow-e2e scenarios [#17187](https://github.com/openshift/console/pull/17187)
* [OCPBUGS-126219](https://issues.redhat.com/browse/OCPBUGS-126219): i18n upload/download routine task - version 4.23/5.0 (Additional) [#17190](https://github.com/openshift/console/pull/17190)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#17176](https://github.com/openshift/console/pull/17176)
* [OCPBUGS-90834](https://issues.redhat.com/browse/OCPBUGS-90834): Fix empty vSphere connection details after upgrade [#17020](https://github.com/openshift/console/pull/17020)
* [OCPBUGS-123141](https://issues.redhat.com/browse/OCPBUGS-123141): i18n upload/download routine task - version 4.23/5.0 [#17165](https://github.com/openshift/console/pull/17165)
* [CONSOLE-4998](https://issues.redhat.com/browse/CONSOLE-4998): Add types for serverless resources [#17152](https://github.com/openshift/console/pull/17152)
* [OCPBUGS-121263](https://issues.redhat.com/browse/OCPBUGS-121263): bump go-git to 5.19.2 [#17148](https://github.com/openshift/console/pull/17148)
* [OCPBUGS-115458](https://issues.redhat.com/browse/OCPBUGS-115458): CVE-2026-84375 bump js-yaml to 3.15.2/4.3.2 [#17133](https://github.com/openshift/console/pull/17133)
* [OCPBUGS-115318](https://issues.redhat.com/browse/OCPBUGS-115318): fix Helm test flake by replacing pkill with PID-file cleanup [#17128](https://github.com/openshift/console/pull/17128)
* [OCPBUGS-120684](https://issues.redhat.com/browse/OCPBUGS-120684): Update stale comment [#17141](https://github.com/openshift/console/pull/17141)
* NO-JIRA: add prettier to playwright folder [#17137](https://github.com/openshift/console/pull/17137)
* [OCPBUGS-115300](https://issues.redhat.com/browse/OCPBUGS-115300): Stabilize topology, node-groups, and debug-pod e2e [#17134](https://github.com/openshift/console/pull/17134)
* [OCPBUGS-115300](https://issues.redhat.com/browse/OCPBUGS-115300): Fix Playwright login helper idempotency and session recovery [#17126](https://github.com/openshift/console/pull/17126)
* [HELM-480](https://issues.redhat.com/browse/HELM-480): Change handler return code [#17042](https://github.com/openshift/console/pull/17042)
* [OCPBUGS-115298](https://issues.redhat.com/browse/OCPBUGS-115298): Rename e2e scripts so playwright is the main one [#17127](https://github.com/openshift/console/pull/17127)
* [CONSOLE-5002](https://issues.redhat.com/browse/CONSOLE-5002): `UserPreferenceContext`and linting follow up [#17124](https://github.com/openshift/console/pull/17124)
* And 13 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/a5af6d5d69b83b6165b50ab42b8c9df4548c87d2...afe3510f5b5737edb0ab93a584db5d0d85c49f73)
### [console-operator](https://github.com/openshift/console-operator/tree/b8447d3ef1eb621046ebdce84efb8ceb736dabdb)
* [CONSOLE-5405](https://issues.redhat.com/browse/CONSOLE-5405): Update console-operator to Kubernetes 1.36 [#1211](https://github.com/openshift/console-operator/pull/1211)
* [OCPBUGS-104500](https://issues.redhat.com/browse/OCPBUGS-104500): Use content hash for ConfigMap deployment annotations [#1217](https://github.com/openshift/console-operator/pull/1217)
* [Full changelog](https://github.com/openshift/console-operator/compare/c285c672c5928a66775051de5cc0b99c90cfac41...b8447d3ef1eb621046ebdce84efb8ceb736dabdb)
### [csi-driver-manila, openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/fb1be731410a5d4eb6b3a3692c9081856df72c10)
* [OCPBUGS-98116](https://issues.redhat.com/browse/OCPBUGS-98116): Bump golang.org/x/crypto to v0.52.0 [#410](https://github.com/openshift/cloud-provider-openstack/pull/410)
* [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/aa9a8100e87ff13abf4dd6343c84c9f4948debef...fb1be731410a5d4eb6b3a3692c9081856df72c10)
### [csi-driver-manila-operator, gcp-pd-csi-driver-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/773340ccc6a7dc3657fe222c7ebd2fcc19adcd56)
* [STOR-3074](https://issues.redhat.com/browse/STOR-3074): Bump OLM metadata to 5.1 [#627](https://github.com/openshift/csi-operator/pull/627)
* [OCPBUGS-112272](https://issues.redhat.com/browse/OCPBUGS-112272): node ServiceMonitor serverName uses guest namespace on HyperShift [#603](https://github.com/openshift/csi-operator/pull/603)
* [OCPBUGS-115269](https://issues.redhat.com/browse/OCPBUGS-115269): openstack-manila: Consume CA cert from CCO secret [#617](https://github.com/openshift/csi-operator/pull/617)
* NO-JIRA: Add reference to cluster-storage-operator in AGENTS.md [#616](https://github.com/openshift/csi-operator/pull/616)
* [STOR-3090](https://issues.redhat.com/browse/STOR-3090): Enable pod-delete-after-umount CSI suite for driver OCP manifests [#596](https://github.com/openshift/csi-operator/pull/596)
* [OCPBUGS-120667](https://issues.redhat.com/browse/OCPBUGS-120667): fix(gcp-pd): don't apply guest-cluster resources against the management cluster on HyperShift [#618](https://github.com/openshift/csi-operator/pull/618)
* [Full changelog](https://github.com/openshift/csi-operator/compare/857bbb16fa89b0b531e27ed0fc0eaa1e94efecb6...773340ccc6a7dc3657fe222c7ebd2fcc19adcd56)
### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/69f816f69e1273868bc19cb13fe6dbd9a7a9ff5f)
* UPSTREAM-SYNC: Merge https://github.com/kubernetes-csi/csi-driver-nfs:master (f12e133) into main [#199](https://github.com/openshift/csi-driver-nfs/pull/199)
* [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa...69f816f69e1273868bc19cb13fe6dbd9a7a9ff5f)
### [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata/tree/e8f0f2a3e9e358061148f90dc41f97cfb0bc5a54)
* NO-ISSUE: Bump golang.org/x/net to v0.53.0 and Go to 1.25.10 [#22](https://github.com/openshift/csi-external-snapshot-metadata/pull/22)
* [Full changelog](https://github.com/openshift/csi-external-snapshot-metadata/compare/239703c637e005cf785892d214d219add70e3533...e8f0f2a3e9e358061148f90dc41f97cfb0bc5a54)
### [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe/tree/4d22ba873038484dcd7fa67553d00ae01d20428a)
* [OCPBUGS-122222](https://issues.redhat.com/browse/OCPBUGS-122222): Bump go.opentelemetry.io/otel to v1.44.0 to address CVE-2026-41178 [#96](https://github.com/openshift/csi-livenessprobe/pull/96)
* [Full changelog](https://github.com/openshift/csi-livenessprobe/compare/463dc553ebb04df192d573c5a1612dcb50cb1f52...4d22ba873038484dcd7fa67553d00ae01d20428a)
### [docker-builder](https://github.com/openshift/builder/tree/c71e860460d9a120f29202dfc8a8eb30cb2ca30f)
* NO-JIRA: Bump golang.org/x/crypto, update CI builder images and go directive to go1.26 [#555](https://github.com/openshift/builder/pull/555)
* [Full changelog](https://github.com/openshift/builder/compare/2cda03a93696d4620703848471b3b873b0b2fa1e...c71e860460d9a120f29202dfc8a8eb30cb2ca30f)
### [etcd](https://github.com/openshift/etcd/tree/24fb7ef2afe9c4e4ca179f70b101d8ac2a0daeab)
* [CNTRLPLANE-3724](https://issues.redhat.com/browse/CNTRLPLANE-3724): add agentic context docs for the openshift/etcd fork [#411](https://github.com/openshift/etcd/pull/411)
* [Full changelog](https://github.com/openshift/etcd/compare/609b11ed8fc404fb95572d7c87e3243a1206cdb7...24fb7ef2afe9c4e4ca179f70b101d8ac2a0daeab)
### [haproxy-router, haproxy-router-haproxy28, haproxy-router-haproxy32](https://github.com/openshift/router/tree/d5cf9f2aa0bdd024f51a208f12558da9bac5ed38)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Lock DeleteFunc to stop SARCompleted overwriting rejection [#840](https://github.com/openshift/router/pull/840)
* [Full changelog](https://github.com/openshift/router/compare/3381229146657d2e6bd94115dda0885f25cb3bed...d5cf9f2aa0bdd024f51a208f12558da9bac5ed38)
### [hypershift](https://github.com/openshift/hypershift/tree/2e7d902422a7dd111801a917ba75935b97dced71)
* [AUTOSCALE-873](https://issues.redhat.com/browse/AUTOSCALE-873): Add sidecar to standalone karpenter-operator [#9565](https://github.com/openshift/hypershift/pull/9565)
* [CNTRLPLANE-4090](https://issues.redhat.com/browse/CNTRLPLANE-4090): Move CPO, HCCO and etcd recovery manifest constructors to shared packages [#9592](https://github.com/openshift/hypershift/pull/9592)
* [OCPBUGS-113995](https://issues.redhat.com/browse/OCPBUGS-113995): classify WebIdentityErr by cause to prevent false invalid creds [#9406](https://github.com/openshift/hypershift/pull/9406)
* [OCPBUGS-115468](https://issues.redhat.com/browse/OCPBUGS-115468): fix NodePool: truncate oversized machine messages instead of dropping them [#9567](https://github.com/openshift/hypershift/pull/9567)
* feat(kubevirt): OCPBUGS-55974: add CPU model configuration for NodePool VMs [#7431](https://github.com/openshift/hypershift/pull/7431)
* [CNTRLPLANE-4209](https://issues.redhat.com/browse/CNTRLPLANE-4209): Consolidate Azure lifecycle test lanes [#9572](https://github.com/openshift/hypershift/pull/9572)
* [GCP-510](https://issues.redhat.com/browse/GCP-510): Implement GCP NodePool CLI Commands [#9466](https://github.com/openshift/hypershift/pull/9466)
* [OCPBUGS-84562](https://issues.redhat.com/browse/OCPBUGS-84562): Configure AWS CCM region directly [#9602](https://github.com/openshift/hypershift/pull/9602)
* NO-JIRA: ci(deps): bump astral-sh/setup-uv from 6.1.0 to 10.1.0 [#9682](https://github.com/openshift/hypershift/pull/9682)
* NO-JIRA: chore(owners): add core approvers [#9651](https://github.com/openshift/hypershift/pull/9651)
* [CNTRLPLANE-4090](https://issues.redhat.com/browse/CNTRLPLANE-4090): Move metric name constants to shared packages [#9540](https://github.com/openshift/hypershift/pull/9540)
* [OCPBUGS-125803](https://issues.redhat.com/browse/OCPBUGS-125803): skip TLS flag propagation tests for older operator versions [#9641](https://github.com/openshift/hypershift/pull/9641)
* [CNTRLPLANE-4453](https://issues.redhat.com/browse/CNTRLPLANE-4453): clarify private Key Vault validation comments [#9645](https://github.com/openshift/hypershift/pull/9645)
* [CNTRLPLANE-4209](https://issues.redhat.com/browse/CNTRLPLANE-4209): Update Azure lifecycle test-flow documentation [#9573](https://github.com/openshift/hypershift/pull/9573)
* [CNTRLPLANE-4456](https://issues.redhat.com/browse/CNTRLPLANE-4456): Run envtests for release-5.0 [#9649](https://github.com/openshift/hypershift/pull/9649)
* [AUTOSCALE-974](https://issues.redhat.com/browse/AUTOSCALE-974), [AUTOSCALE-980](https://issues.redhat.com/browse/AUTOSCALE-980): allow Karpenter to be deployed on Azure [#9545](https://github.com/openshift/hypershift/pull/9545)
* [OCPBUGS-123512](https://issues.redhat.com/browse/OCPBUGS-123512): fix(e2e): derive node runtimes from upgraded NodePool state [#9611](https://github.com/openshift/hypershift/pull/9611)
* [OCPBUGS-122236](https://issues.redhat.com/browse/OCPBUGS-122236): stabilize JUnit test identities [#9580](https://github.com/openshift/hypershift/pull/9580)
* chore(renovate): enable supported release branches [#9631](https://github.com/openshift/hypershift/pull/9631)
* [CNTRLPLANE-4209](https://issues.redhat.com/browse/CNTRLPLANE-4209): Reject shared variants in concurrent e2e lanes [#9571](https://github.com/openshift/hypershift/pull/9571)
* [OCPBUGS-109672](https://issues.redhat.com/browse/OCPBUGS-109672): fix(cpo) wait for etcd health, not just DNS [#9460](https://github.com/openshift/hypershift/pull/9460)
* [OCPBUGS-123645](https://issues.redhat.com/browse/OCPBUGS-123645): add missing Azure v2 matrix coverage [#9616](https://github.com/openshift/hypershift/pull/9616)
* NO-JIRA: fix(e2e): restore Eventually retry for post-upgrade health condition check [#9632](https://github.com/openshift/hypershift/pull/9632)
* [OCPBUGS-89689](https://issues.redhat.com/browse/OCPBUGS-89689): karpenter control plane upgrade premature drift fix [#9234](https://github.com/openshift/hypershift/pull/9234)
* [CNTRLPLANE-3880](https://issues.redhat.com/browse/CNTRLPLANE-3880): Add E2E test for etcd snapshot restore to prevent split brain regression [#9356](https://github.com/openshift/hypershift/pull/9356)
* NO-JIRA: Bump envtest workflow timeout to 20 minutes [#9630](https://github.com/openshift/hypershift/pull/9630)
* [CNTRLPLANE-4090](https://issues.redhat.com/browse/CNTRLPLANE-4090): Move labels, taints, scheduler, VAP and misc constants to shared packages [#9544](https://github.com/openshift/hypershift/pull/9544)
* NO-JIRA: Fix CONTRIBUTING.md link path and remove trailing blank lines [#9621](https://github.com/openshift/hypershift/pull/9621)
* [OCPBUGS-122011](https://issues.redhat.com/browse/OCPBUGS-122011): fix(e2e): Make `InstallHyperShiftOperator` platform aware [#9555](https://github.com/openshift/hypershift/pull/9555)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): Enable HC and HCP status-write linting [#9563](https://github.com/openshift/hypershift/pull/9563)
* [CNTRLPLANE-3608](https://issues.redhat.com/browse/CNTRLPLANE-3608): Add nested virtualization support for AWS EC2 NodePools [#8681](https://github.com/openshift/hypershift/pull/8681)
* [GCP-1122](https://issues.redhat.com/browse/GCP-1122): chore: add pvasant to gcp-reviewers alias [#9465](https://github.com/openshift/hypershift/pull/9465)
* [CNTRLPLANE-4393](https://issues.redhat.com/browse/CNTRLPLANE-4393): document CAPI provider image override mechanisms [#9482](https://github.com/openshift/hypershift/pull/9482)
* [CNTRLPLANE-3277](https://issues.redhat.com/browse/CNTRLPLANE-3277): Add Azure OAuth LoadBalancer private topology e2e test [#8584](https://github.com/openshift/hypershift/pull/8584)
* [OCPBUGS-122232](https://issues.redhat.com/browse/OCPBUGS-122232): Gate CAPI API version by management release [#9587](https://github.com/openshift/hypershift/pull/9587)
* [CNTRLPLANE-4093](https://issues.redhat.com/browse/CNTRLPLANE-4093): Move shared label constants to api/hypershift/v1beta1 [#9415](https://github.com/openshift/hypershift/pull/9415)
* [CNTRLPLANE-4207](https://issues.redhat.com/browse/CNTRLPLANE-4207): document Azure lifecycle test sharding [#9504](https://github.com/openshift/hypershift/pull/9504)
* [GCP-958](https://issues.redhat.com/browse/GCP-958): test(e2e/v2): register gcp-pd-csi-driver control plane workloads [#9589](https://github.com/openshift/hypershift/pull/9589)
* [OCPBUGS-97942](https://issues.redhat.com/browse/OCPBUGS-97942): fix(cli): add --service-publishing-strategy flag to hcp create cluster agent [#8985](https://github.com/openshift/hypershift/pull/8985)
* NO-JIRA: build(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 [#9546](https://github.com/openshift/hypershift/pull/9546)
* [CNTRLPLANE-4094](https://issues.redhat.com/browse/CNTRLPLANE-4094): Move ExternalDNSLBPort and KASRouteHostname to support/netutil [#9414](https://github.com/openshift/hypershift/pull/9414)
* NO-JIRA: fix(ci): use --target for pip install on ARC runner [#9531](https://github.com/openshift/hypershift/pull/9531)
* [CNTRLPLANE-4150](https://issues.redhat.com/browse/CNTRLPLANE-4150): feat: Maintain ingress serving cert for HostedCluster ingress [#9132](https://github.com/openshift/hypershift/pull/9132)
* [CNTRLPLANE-4207](https://issues.redhat.com/browse/CNTRLPLANE-4207): update v2 test flow documentation [#9569](https://github.com/openshift/hypershift/pull/9569)
* [CNTRLPLANE-4369](https://issues.redhat.com/browse/CNTRLPLANE-4369): add prow job id tag to e2e v2 aws resources [#9542](https://github.com/openshift/hypershift/pull/9542)
* NO-JIRA: fix(managed-azure): continue resource group cleanup when HC destroy fails [#9404](https://github.com/openshift/hypershift/pull/9404)
* [ACM-41684](https://issues.redhat.com/browse/ACM-41684): Switch hypershift-operator runtime to PQC base image [#9453](https://github.com/openshift/hypershift/pull/9453)
* NO-JIRA: fix(install): increase WaitUntilAvailable timeout from 5m to 10m [#9306](https://github.com/openshift/hypershift/pull/9306)
* [OCPBUGS-87991](https://issues.redhat.com/browse/OCPBUGS-87991): validate additionalNetworks name format in KubeVirt NodePools [#8710](https://github.com/openshift/hypershift/pull/8710)
* NO-JIRA: feat(azure): Add scripts to setup credentials and check resources [#9446](https://github.com/openshift/hypershift/pull/9446)
* [CNTRLPLANE-4005](https://issues.redhat.com/browse/CNTRLPLANE-4005): Skip CDI importer pods from custom labels and tolerations checks [#9240](https://github.com/openshift/hypershift/pull/9240)
* [OCPBUGS-109724](https://issues.redhat.com/browse/OCPBUGS-109724): fix KubeVirt custom baseDomain ingress documentation [#9318](https://github.com/openshift/hypershift/pull/9318)
* NO-JIRA: spread AKS nodes across availability zones [#9449](https://github.com/openshift/hypershift/pull/9449)
* [CNTRLPLANE-4370](https://issues.redhat.com/browse/CNTRLPLANE-4370): Revert "Merge pull request #9543 from ironcladlou/e2e-promotion" [#9574](https://github.com/openshift/hypershift/pull/9574)
* [OCPBUGS-114415](https://issues.redhat.com/browse/OCPBUGS-114415): Increase relay timeouts to prevent intermittent test failures [#9459](https://github.com/openshift/hypershift/pull/9459)
* NO-JIRA: Gate GCP credential validation by control plane version [#9562](https://github.com/openshift/hypershift/pull/9562)
* [OCPBUGS-120840](https://issues.redhat.com/browse/OCPBUGS-120840): remove TechPreviewNoUpgrade from AWS cluster creation args [#9535](https://github.com/openshift/hypershift/pull/9535)
* [OCPBUGS-121208](https://issues.redhat.com/browse/OCPBUGS-121208): filter AWS-reserved tag keys before calling DeleteTags [#9538](https://github.com/openshift/hypershift/pull/9538)
* [GCP-883](https://issues.redhat.com/browse/GCP-883): Optimize GCP PSC NAT allocation [#9472](https://github.com/openshift/hypershift/pull/9472)
* [CNTRLPLANE-3603](https://issues.redhat.com/browse/CNTRLPLANE-3603): Migrate clients from CAPI v1beta1 to v1beta2 [#8717](https://github.com/openshift/hypershift/pull/8717)
* NO-JIRA: remove duplicate e2e v2 test flow doc [#9553](https://github.com/openshift/hypershift/pull/9553)
* [CNTRLPLANE-4370](https://issues.redhat.com/browse/CNTRLPLANE-4370): enforce explicit blocking/informing labels on all v2 e2e tests [#9543](https://github.com/openshift/hypershift/pull/9543)
* NO-JIRA: ci(deps): bump actions/actions-runner from 2.336.0 to 2.337.0- #9513 [#9513](https://github.com/openshift/hypershift/pull/9513)
* [CNTRLPLANE-3998](https://issues.redhat.com/browse/CNTRLPLANE-3998): warn when deprecated kube-apiserver verbosity annotation is set [#9461](https://github.com/openshift/hypershift/pull/9461)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): migrate HCCO/route status patches to statuspatching [#9385](https://github.com/openshift/hypershift/pull/9385)
* [OCPBUGS-99534](https://issues.redhat.com/browse/OCPBUGS-99534): etcd initialization bugs after etcdctl snapshot restore [#9048](https://github.com/openshift/hypershift/pull/9048)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): increase e2e v2 control plane upgrade coverage for v1 parity [#9491](https://github.com/openshift/hypershift/pull/9491)
* [OCPBUGS-120685](https://issues.redhat.com/browse/OCPBUGS-120685): fix(e2e): select a live NodePool for osImageStream node OS verification [#9506](https://github.com/openshift/hypershift/pull/9506)
* [ROSAENG-63186](https://issues.redhat.com/browse/ROSAENG-63186): fix(hcco): Add VAP to protect kas-bootstrap RBAC bindings from deletion [#9203](https://github.com/openshift/hypershift/pull/9203)
* NO-JIRA: remove unsafe v1 framework usage from karpenter upgrade test [#9522](https://github.com/openshift/hypershift/pull/9522)
* [CNTRLPLANE-2007](https://issues.redhat.com/browse/CNTRLPLANE-2007): KubeVirt default ingress passthrough with HostNetwork endpoint publishing strategy [#9514](https://github.com/openshift/hypershift/pull/9514)
* [CNTRLPLANE-4207](https://issues.redhat.com/browse/CNTRLPLANE-4207): Balance Azure v2 lifecycle test shards [#9419](https://github.com/openshift/hypershift/pull/9419)
* [CNTRLPLANE-3532](https://issues.redhat.com/browse/CNTRLPLANE-3532): add hcpstatuspatch linter and status-patching AGENTS.md guidance [#9388](https://github.com/openshift/hypershift/pull/9388)
* [OCPBUGS-114459](https://issues.redhat.com/browse/OCPBUGS-114459): recognize domain-specific test fields [#9454](https://github.com/openshift/hypershift/pull/9454)
* [GCP-503](https://issues.redhat.com/browse/GCP-503): feat(gcp): Implement OrphanDeleter [#8884](https://github.com/openshift/hypershift/pull/8884)
* [OCPBUGS-115269](https://issues.redhat.com/browse/OCPBUGS-115269): openstack: Start populating cacert in clouds.yaml [#9467](https://github.com/openshift/hypershift/pull/9467)
* [CNTRLPLANE-3951](https://issues.redhat.com/browse/CNTRLPLANE-3951): fix(e2e): accept node deletion as success in TestSpotTerminationHandler [#9428](https://github.com/openshift/hypershift/pull/9428)
* [OCPBUGS-74960](https://issues.redhat.com/browse/OCPBUGS-74960): fix orphaned security group during VPC endpoint deletion [#9517](https://github.com/openshift/hypershift/pull/9517)
* NO-JIRA: test(backuprestore): enable SnapshotMoveData in backup configurations [#9429](https://github.com/openshift/hypershift/pull/9429)
* [GCP-958](https://issues.redhat.com/browse/GCP-958): feat(gcp): complete GCP PD CSI driver wiring in HyperShift [#9450](https://github.com/openshift/hypershift/pull/9450)
* [RHOBS-1707](https://issues.redhat.com/browse/RHOBS-1707): Add OpenTelemetry SDK tracing to hypershift-operator [#9390](https://github.com/openshift/hypershift/pull/9390)
* [OCPBUGS-105464](https://issues.redhat.com/browse/OCPBUGS-105464): fix(nodepool): inject default worker SG by status ID, not fail-open capability flag [#9456](https://github.com/openshift/hypershift/pull/9456)
* [OCPBUGS-84368](https://issues.redhat.com/browse/OCPBUGS-84368): add safe-to-evict annotation and remove tolerations to fix autoscaler scale-down and drain loop [#8338](https://github.com/openshift/hypershift/pull/8338)
* [AUTOSCALE-998](https://issues.redhat.com/browse/AUTOSCALE-998): inject token-minter image to standalone karpenter-operator [#9492](https://github.com/openshift/hypershift/pull/9492)
* [OCPBUGS-120685](https://issues.redhat.com/browse/OCPBUGS-120685): fix(e2e): label flaking nodepool osImageStream test informing [#9505](https://github.com/openshift/hypershift/pull/9505)
* NO-JIRA: feat(chaibot): add per-platform Slack handle pings to CI health report [#9478](https://github.com/openshift/hypershift/pull/9478)
* build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 in /hack/tools [#9479](https://github.com/openshift/hypershift/pull/9479)
* build(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 [#9480](https://github.com/openshift/hypershift/pull/9480)
* [OCPBUGS-114408](https://issues.redhat.com/browse/OCPBUGS-114408): fix(api): allow spaces in AWS resource tag keys and values [#9425](https://github.com/openshift/hypershift/pull/9425)
* [GCP-1113](https://issues.redhat.com/browse/GCP-1113): retry transient network errors in hypershift create iam gcp [#9436](https://github.com/openshift/hypershift/pull/9436)
* [OCPBUGS-115542](https://issues.redhat.com/browse/OCPBUGS-115542): fix(e2e): poll for etcd-init completion before reading restore logs [#9481](https://github.com/openshift/hypershift/pull/9481)
* [OCPBUGS-114368](https://issues.redhat.com/browse/OCPBUGS-114368): Retry Microsoft Graph transport failures [#9421](https://github.com/openshift/hypershift/pull/9421)
* [OCPBUGS-86690](https://issues.redhat.com/browse/OCPBUGS-86690): fix Azure cluster deletion hanging when resource groups are already deleted [#8682](https://github.com/openshift/hypershift/pull/8682)
* [CNTRLPLANE-4041](https://issues.redhat.com/browse/CNTRLPLANE-4041): add new release branches to renovate config [#9470](https://github.com/openshift/hypershift/pull/9470)
* [OCPBUGS-77781](https://issues.redhat.com/browse/OCPBUGS-77781): fix(certs): normalize IP SANs to stop dual-stack KAS cert churn [#9286](https://github.com/openshift/hypershift/pull/9286)
* [CNTRLPLANE-4205](https://issues.redhat.com/browse/CNTRLPLANE-4205): document OSImageStream behaviour deviations [#9486](https://github.com/openshift/hypershift/pull/9486)
* [CNTRLPLANE-3755](https://issues.redhat.com/browse/CNTRLPLANE-3755): fix(e2e): add version gating to EnsureCAPIFinalizers tests [#9443](https://github.com/openshift/hypershift/pull/9443)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): enable e2e v2 aws control plane upgrade tests [#9474](https://github.com/openshift/hypershift/pull/9474)
* [OCPBUGS-115403](https://issues.redhat.com/browse/OCPBUGS-115403): ensure informing junit files are unique across test groups [#9473](https://github.com/openshift/hypershift/pull/9473)
* [ACM-41685](https://issues.redhat.com/browse/ACM-41685): Enable PQC crypto policy in hypershift-cli image [#9463](https://github.com/openshift/hypershift/pull/9463)
* [OCPBUGS-113712](https://issues.redhat.com/browse/OCPBUGS-113712): preserve immutable AWS load balancer annotations [#9469](https://github.com/openshift/hypershift/pull/9469)
* NO-JIRA: chore(konflux): update Tekton task bundles to latest versions [#9483](https://github.com/openshift/hypershift/pull/9483)
* [CNTRLPLANE-4204](https://issues.redhat.com/browse/CNTRLPLANE-4204): reorganize OSImageStream e2e tests after graduation [#9418](https://github.com/openshift/hypershift/pull/9418)
* [CNTRLPLANE-3201](https://issues.redhat.com/browse/CNTRLPLANE-3201): feat(e2e): enable etcd snapshot backup test on Azure [#9226](https://github.com/openshift/hypershift/pull/9226)
* [CNTRLPLANE-2029](https://issues.redhat.com/browse/CNTRLPLANE-2029): docs(backuprestore): add Agent and KubeVirt platform prerequisites [#9072](https://github.com/openshift/hypershift/pull/9072)
* [CNTRLPLANE-3950](https://issues.redhat.com/browse/CNTRLPLANE-3950): fix flaky TestKMSRootVolumeEncryption race condition. [#9304](https://github.com/openshift/hypershift/pull/9304)
* [CNTRLPLANE-4208](https://issues.redhat.com/browse/CNTRLPLANE-4208): Right-size Azure v2 e2e worker counts [#9426](https://github.com/openshift/hypershift/pull/9426)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): port karpenter upgrade test to v2 [#9397](https://github.com/openshift/hypershift/pull/9397)
* NO-JIRA: fix(azure): orphan AzureMachines when capi-provider cannot run [#9403](https://github.com/openshift/hypershift/pull/9403)
* [OCPBUGS-99021](https://issues.redhat.com/browse/OCPBUGS-99021): Use separate certificate signers for konnectivity [#9098](https://github.com/openshift/hypershift/pull/9098)
* [OCPBUGS-99329](https://issues.redhat.com/browse/OCPBUGS-99329): avoid cache miss false-negative on credential Secret lookup [#9074](https://github.com/openshift/hypershift/pull/9074)
* NO-JIRA: group ChaiBot health report by OCP version [#9447](https://github.com/openshift/hypershift/pull/9447)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/hypershift/compare/813b57efa2caeb867d8ff3b9f3f0603651402dff...2e7d902422a7dd111801a917ba75935b97dced71)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/edb8427aa57d4c223d1915ebd90d4034f8fb5f24)
* [OCPBUGS-114006](https://issues.redhat.com/browse/OCPBUGS-114006): UPSTREAM: 2933: Bump all go.opentelemetry.io/otel modules to v1.44.0 [#165](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/165)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/286dd2de7957e9c2897e152417f16907d324d819...edb8427aa57d4c223d1915ebd90d4034f8fb5f24)
### [insights-operator](https://github.com/openshift/insights-operator/tree/8f15e3157ff09f54ab22801f5b21da35a195cc6d)
* [CCXDEV-16666](https://issues.redhat.com/browse/CCXDEV-16666): gather InferenceService from the KServe operator [#1345](https://github.com/openshift/insights-operator/pull/1345)
* [OCPBUGS-97968](https://issues.redhat.com/browse/OCPBUGS-97968): add insights-runtime-extractor-scc missing fields [#1359](https://github.com/openshift/insights-operator/pull/1359)
* [Full changelog](https://github.com/openshift/insights-operator/compare/9bf68c79ce211fb1e16050cc20552166a89b3f34...8f15e3157ff09f54ab22801f5b21da35a195cc6d)
### [karpenter-operator](https://github.com/openshift/karpenter-operator/tree/69615069919bf76e68d485681f0fda1bbab4e1c0)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): Add minimum instance size requirements [#36](https://github.com/openshift/karpenter-operator/pull/36)
* NO-JIRA: fixup OWNERS_ALIASES [#35](https://github.com/openshift/karpenter-operator/pull/35)
* NO-JIRA: chore: update build tool versions [#34](https://github.com/openshift/karpenter-operator/pull/34)
* [AUTOSCALE-873](https://issues.redhat.com/browse/AUTOSCALE-873): fix: apply OpenShift Karpenter CRD adjustments [#33](https://github.com/openshift/karpenter-operator/pull/33)
* [AUTOSCALE-974](https://issues.redhat.com/browse/AUTOSCALE-974): deploy karpenter-provider-azure on HCP [#32](https://github.com/openshift/karpenter-operator/pull/32)
* [AUTOSCALE-946](https://issues.redhat.com/browse/AUTOSCALE-946): migrate approver for node CSRs [#29](https://github.com/openshift/karpenter-operator/pull/29)
* no-jira: remove aggregate cluster role [#30](https://github.com/openshift/karpenter-operator/pull/30)
* [Full changelog](https://github.com/openshift/karpenter-operator/compare/892b17c079251b141ee8142501798227dfa58359...69615069919bf76e68d485681f0fda1bbab4e1c0)
### [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy/tree/15f06dc655748d92897ba0d37cb8a0c40fb5d6fa)
* [CNTRLPLANE-3685](https://issues.redhat.com/browse/CNTRLPLANE-3685): docs - add Agentic SDLC context files [#144](https://github.com/openshift/kube-rbac-proxy/pull/144)
* [Full changelog](https://github.com/openshift/kube-rbac-proxy/compare/0f9a53a85f8436587adbbdc58caaf89e500cd8db...15f06dc655748d92897ba0d37cb8a0c40fb5d6fa)
### [kube-state-metrics](https://github.com/openshift/kube-state-metrics/tree/4fcfe28da069857ca4afdcba3a7f167753f4ade8)
* NO-ISSUE: [bot] Bump openshift/kube-state-metrics to v2.20.0 [#155](https://github.com/openshift/kube-state-metrics/pull/155)
* [Full changelog](https://github.com/openshift/kube-state-metrics/compare/019ecc7d533333dfd3bf8893e78cd7ec6e282f01...4fcfe28da069857ca4afdcba3a7f167753f4ade8)
### [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator/tree/3f74baced64e1be5ec9ca16e3a682cd4eca67c06)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#262](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/262)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#259](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/259)
* [Full changelog](https://github.com/openshift/kubernetes-kube-storage-version-migrator/compare/72835e43c7754356645e41031f3a99926b4d42e6...3f74baced64e1be5ec9ca16e3a682cd4eca67c06)
### [kube-vip](https://github.com/openshift/kube-vip/tree/b272a7342833dad64574158101decb94ebe703d0)
* NO-JIRA: Merge https://github.com/kube-vip/kube-vip:main (https://github.com/openshift/kube-vip/commit/6cbf5aaeda356be0ee3fc5d8482d483c28bb4103) into main [#19](https://github.com/openshift/kube-vip/pull/19)
* [Full changelog](https://github.com/openshift/kube-vip/compare/3aaf76bd7be6d066b87f85eb30ba77edc0a57dcd...b272a7342833dad64574158101decb94ebe703d0)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/26d7767bee99ff544430fd138571989f52d67c00)
* [OCPCLOUD-3438](https://issues.redhat.com/browse/OCPCLOUD-3438): Bump govmomi to 0.53.0 [#1498](https://github.com/openshift/machine-api-operator/pull/1498)
* NO-ISSUE: Add opt-in kube-rbac-proxy sidecar for pprof endpoint (AWS) [#1502](https://github.com/openshift/machine-api-operator/pull/1502)
* [OCPBUGS-47508](https://issues.redhat.com/browse/OCPBUGS-47508): Set --max-concurrent-reconciles=10 for AWS machine controller [#1521](https://github.com/openshift/machine-api-operator/pull/1521)
* [SPLAT-2825](https://issues.redhat.com/browse/SPLAT-2825): Moved OTE machine tests to openshift/disruptive-longrunning [#1539](https://github.com/openshift/machine-api-operator/pull/1539)
* [OCPBUGS-105398](https://issues.redhat.com/browse/OCPBUGS-105398): refactor: remove AzureWorkloadIdentity feature gate [#1537](https://github.com/openshift/machine-api-operator/pull/1537)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/08e31544b6e3af6b5e5c8dcf9b7dad2840318958...26d7767bee99ff544430fd138571989f52d67c00)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/86eb9d92e9cfc578224b86467ae45e86485a63b1)
* [OCPBUGS-63048](https://issues.redhat.com/browse/OCPBUGS-63048): Kube object asserts do not handle case where object is replaced [#6059](https://github.com/openshift/machine-config-operator/pull/6059)
* [OCPBUGS-100366](https://issues.redhat.com/browse/OCPBUGS-100366): Re-queue ContainerRuntimeConfig on status update failure [#6415](https://github.com/openshift/machine-config-operator/pull/6415)
* [OCPBUGS-90502](https://issues.redhat.com/browse/OCPBUGS-90502): Run nmstatectl format in nmstate-configuration [#6209](https://github.com/openshift/machine-config-operator/pull/6209)
* [OCPBUGS-115002](https://issues.redhat.com/browse/OCPBUGS-115002): Remove BootImageSkewEnforcement references to gate component from MCO [#6522](https://github.com/openshift/machine-config-operator/pull/6522)
* [OCPBUGS-114882](https://issues.redhat.com/browse/OCPBUGS-114882): drop GCD health-check ranges in openshift-gcp-routes [#6501](https://github.com/openshift/machine-config-operator/pull/6501)
* [OPNET-801](https://issues.redhat.com/browse/OPNET-801): Switch on-prem HAProxy pods to haproxy-router-haproxy32 image [#6502](https://github.com/openshift/machine-config-operator/pull/6502)
* [OCPBUGS-122237](https://issues.redhat.com/browse/OCPBUGS-122237): [TNF] Add infinite retry on untaint systemd unit [#6535](https://github.com/openshift/machine-config-operator/pull/6535)
* [OCPBUGS-116491](https://issues.redhat.com/browse/OCPBUGS-116491): Correctly handle MC deletion in image mode when no new build is required [#6528](https://github.com/openshift/machine-config-operator/pull/6528)
* [OCPBUGS-121353](https://issues.redhat.com/browse/OCPBUGS-121353): Pass missing proxy vars to bootstrap MCC [#6526](https://github.com/openshift/machine-config-operator/pull/6526)
* [MCO-2575](https://issues.redhat.com/browse/MCO-2575): Refactor verification functions for `calculateStatus` test cases [#6543](https://github.com/openshift/machine-config-operator/pull/6543)
* [MCO-2570](https://issues.redhat.com/browse/MCO-2570): remove poll methods [#6532](https://github.com/openshift/machine-config-operator/pull/6532)
* [OCPBUGS-114737](https://issues.redhat.com/browse/OCPBUGS-114737): updateLayeredOS deploy-from-self when skopeo < 1.22.2 [#6475](https://github.com/openshift/machine-config-operator/pull/6475)
* [OCPBUGS-122209](https://issues.redhat.com/browse/OCPBUGS-122209): Fix IsBootImageUpdateSupported to include vSphere and Azure platforms [#6523](https://github.com/openshift/machine-config-operator/pull/6523)
* [OCPBUGS-105283](https://issues.redhat.com/browse/OCPBUGS-105283): Mount /etc/container in mosb [#6451](https://github.com/openshift/machine-config-operator/pull/6451)
* [OCPBUGS-95238](https://issues.redhat.com/browse/OCPBUGS-95238): Dump compact cache to CM for persistence [#6379](https://github.com/openshift/machine-config-operator/pull/6379)
* [OCPBUGS-114664](https://issues.redhat.com/browse/OCPBUGS-114664): Fix CVE-2026-15792: Upgrade BuildKit to v0.31.2 [#6472](https://github.com/openshift/machine-config-operator/pull/6472)
* [OCPBUGS-120711](https://issues.redhat.com/browse/OCPBUGS-120711): Fix vsphere network absolute paths [#6497](https://github.com/openshift/machine-config-operator/pull/6497)
* [OCPBUGS-112721](https://issues.redhat.com/browse/OCPBUGS-112721): Retry on conflict in syncMachineConfigNodes [#6496](https://github.com/openshift/machine-config-operator/pull/6496)
* [OCPBUGS-116490](https://issues.redhat.com/browse/OCPBUGS-116490): remove nft chains before checking the ignition config [#6485](https://github.com/openshift/machine-config-operator/pull/6485)
* NO-ISSUE: check mosb failed message in test 85980 [#6500](https://github.com/openshift/machine-config-operator/pull/6500)
* [OCPBUGS-109657](https://issues.redhat.com/browse/OCPBUGS-109657): Assert errors in TestGetPrimaryPoolForNode [#6482](https://github.com/openshift/machine-config-operator/pull/6482)
* [OCPBUGS-115123](https://issues.redhat.com/browse/OCPBUGS-115123): Replace wildcard permissions with explicit verbs in MachineConfigServer ClusterRole [#6470](https://github.com/openshift/machine-config-operator/pull/6470)
* [OCPBUGS-112348](https://issues.redhat.com/browse/OCPBUGS-112348): Increase TC-74751 Eventually timeout for vSphere OVA upload [#6481](https://github.com/openshift/machine-config-operator/pull/6481)
* [OCPBUGS-115158](https://issues.redhat.com/browse/OCPBUGS-115158): Update AMI Whitelist [#6474](https://github.com/openshift/machine-config-operator/pull/6474)
* [OCPBUGS-115203](https://issues.redhat.com/browse/OCPBUGS-115203): Skip vsphere fd-unmatched machinesets for bootimage updates [#6477](https://github.com/openshift/machine-config-operator/pull/6477)
* [MCO-2530](https://issues.redhat.com/browse/MCO-2530): Remove unused functions, constants, parameters, and returns throughout the codebase [#6403](https://github.com/openshift/machine-config-operator/pull/6403)
* [MCO-2427](https://issues.redhat.com/browse/MCO-2427): Move OCB and OSStreams tests to longduration suite [#6454](https://github.com/openshift/machine-config-operator/pull/6454)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/e7e6abbd38052da7edbb1a01bf0548d2bb03468b...86eb9d92e9cfc578224b86467ae45e86485a63b1)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/2910fb3fef2f907bcb7863471240ba0289621ea6)
* [OCPBUGS-112613](https://issues.redhat.com/browse/OCPBUGS-112613): Validate aarch64 ISO checksum after cross-arch extraction [#113](https://github.com/openshift/machine-os-images/pull/113)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/1d6a7d787cc8d1f8570b3310a764be493071c8eb...2910fb3fef2f907bcb7863471240ba0289621ea6)
### [metallb-frr](https://github.com/openshift/frr/tree/4eebe4a1e50697ea070eec07c7ff022313ef3a8e)
* [OKD-453](https://issues.redhat.com/browse/OKD-453): Dockerfile.openshift: conditionally install frr or frr10 based on OS version [#137](https://github.com/openshift/frr/pull/137)
* [Full changelog](https://github.com/openshift/frr/compare/54a6ea48902d81460536b81ea6bdceb89c12e622...4eebe4a1e50697ea070eec07c7ff022313ef3a8e)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/b5465f7ec7b9a2139c0299f474779ccc3fd109de)
* NO-JIRA: sanitize runbook_url [#1255](https://github.com/openshift/monitoring-plugin/pull/1255)
* [OU-1150](https://issues.redhat.com/browse/OU-1150): more refactors [#1286](https://github.com/openshift/monitoring-plugin/pull/1286)
* NO-JIRA: duplicate dashboard creates perses project [#1258](https://github.com/openshift/monitoring-plugin/pull/1258)
* [OCPBUGS-123668](https://issues.redhat.com/browse/OCPBUGS-123668): patch adm-zip vulnerable version [#1274](https://github.com/openshift/monitoring-plugin/pull/1274)
* NO-JIRA: feat: migrate to vitest [#1237](https://github.com/openshift/monitoring-plugin/pull/1237)
* [OU-1220](https://issues.redhat.com/browse/OU-1220): Add column to display dashboard id in perses dashboard list page [#1257](https://github.com/openshift/monitoring-plugin/pull/1257)
* [OU-791](https://issues.redhat.com/browse/OU-791): hide Export as CSV link on empty Alerts page [#1251](https://github.com/openshift/monitoring-plugin/pull/1251)
* NO-JIRA: fix(metrics): sync query-browser URL into Redux after navigation [#1238](https://github.com/openshift/monitoring-plugin/pull/1238)
* [OU-1344](https://issues.redhat.com/browse/OU-1344): Add granular permission checks [#1185](https://github.com/openshift/monitoring-plugin/pull/1185)
* NO-JIRA: Pin node 22 and migrate deprecated i18next-parser [#1235](https://github.com/openshift/monitoring-plugin/pull/1235)
* NO-JIRA: use existing env var as a dashboard project in the OLS show time… [#1236](https://github.com/openshift/monitoring-plugin/pull/1236)
* [OU-1147](https://issues.redhat.com/browse/OU-1147): Perses UI Customization. Allow semantic tokens to map correctly with PatternFly themes and modes [#1226](https://github.com/openshift/monitoring-plugin/pull/1226)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): refactor variables [#1224](https://github.com/openshift/monitoring-plugin/pull/1224)
* [OCPBUGS-119714](https://issues.redhat.com/browse/OCPBUGS-119714), [OCPBUGS-119717](https://issues.redhat.com/browse/OCPBUGS-119717): fix: upgrade fast-uri to 3.1.7 [#1234](https://github.com/openshift/monitoring-plugin/pull/1234)
* [OCPBUGS-115456](https://issues.redhat.com/browse/OCPBUGS-115456): fix: upgrade vulnerable dependencies [#1233](https://github.com/openshift/monitoring-plugin/pull/1233)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): lint tags [#1221](https://github.com/openshift/monitoring-plugin/pull/1221)
* [OU-1472](https://issues.redhat.com/browse/OU-1472): perses version upgrade fixes [#1228](https://github.com/openshift/monitoring-plugin/pull/1228)
* [OCPBUGS-114786](https://issues.redhat.com/browse/OCPBUGS-114786), [OCPBUGS-114789](https://issues.redhat.com/browse/OCPBUGS-114789), [OCPBUGS-114792](https://issues.redhat.com/browse/OCPBUGS-114792): fix: upgrade vulnerable fast-uri dependency [#1200](https://github.com/openshift/monitoring-plugin/pull/1200)
* NO-JIRA: Add dchromik to observability-ui aliases [#1230](https://github.com/openshift/monitoring-plugin/pull/1230)
* NO-JIRA: upgrade webpack [#1213](https://github.com/openshift/monitoring-plugin/pull/1213)
* And 2 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/525bbd1556c5af07906360bac2e91c6d70959b65...b5465f7ec7b9a2139c0299f474779ccc3fd109de)
### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/5429edee2dc087ba0c4595c11bdd5f6d2e52436e)
* [CORENET-7375](https://issues.redhat.com/browse/CORENET-7375): d/s merge Bump Kubernetes to 1.36.2 and Go to 1.26 [#123](https://github.com/openshift/multus-admission-controller/pull/123)
* [OCPBUGS-112557](https://issues.redhat.com/browse/OCPBUGS-112557): Bump golang.org/x/net to 0.57.0 to fix CVE-2026-33814 [#125](https://github.com/openshift/multus-admission-controller/pull/125)
* [Full changelog](https://github.com/openshift/multus-admission-controller/compare/6d9df61378321846c00a32f0c42b6688daacd649...5429edee2dc087ba0c4595c11bdd5f6d2e52436e)
### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/40982ea3951b3713e3bb3e1bb75657a325499c54)
* [OCPBUGS-112555](https://issues.redhat.com/browse/OCPBUGS-112555): Fix for CVE-2026-33814 [#418](https://github.com/openshift/whereabouts-cni/pull/418)
* [Full changelog](https://github.com/openshift/whereabouts-cni/compare/d918bda28ad3d0200b6e4f2ef2801556764762e5...40982ea3951b3713e3bb3e1bb75657a325499c54)
### [must-gather](https://github.com/openshift/must-gather/tree/521d3451f4918c2bd058bde62d642d9b227a5d65)
* [WINC-2092](https://issues.redhat.com/browse/WINC-2092): Add windows_exporter log collection [#560](https://github.com/openshift/must-gather/pull/560)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#563](https://github.com/openshift/must-gather/pull/563)
* [Full changelog](https://github.com/openshift/must-gather/compare/1e5c2ec841c1ed29110febaf8a448936842a2f4d...521d3451f4918c2bd058bde62d642d9b227a5d65)
### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/e8830cdeabf085090c13ee68cd19a81ef6fd2adf)
* [CORENET-7238](https://issues.redhat.com/browse/CORENET-7238): Update OWNERS file [#145](https://github.com/openshift/network-metrics-daemon/pull/145)
* [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/80fc3abc785d2b4d8275ba316c579de43416148d...e8830cdeabf085090c13ee68cd19a81ef6fd2adf)
### [network-tools](https://github.com/openshift/network-tools/tree/03ae0e816cbf7608e6a326ac71a0a00619941e08)
* NO-JIRA: Added iperf3 [#189](https://github.com/openshift/network-tools/pull/189)
* [Full changelog](https://github.com/openshift/network-tools/compare/0b53ac3dccf59cd169555bf18c207122374bf003...03ae0e816cbf7608e6a326ac71a0a00619941e08)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/943fc215c1b8dfb4c5a8c5645dbe94cad6402126)
* [OCPNETUI-65](https://issues.redhat.com/browse/OCPNETUI-65): Enable dependabot updates on release-5.0 [#524](https://github.com/openshift/networking-console-plugin/pull/524)
* [OCPBUGS-86053](https://issues.redhat.com/browse/OCPBUGS-86053): Fix MultiNetworkPolicy list crash when spec is missing [#523](https://github.com/openshift/networking-console-plugin/pull/523)
* [OCPNETUI-78](https://issues.redhat.com/browse/OCPNETUI-78): Remove unused Dockerfile.art [#516](https://github.com/openshift/networking-console-plugin/pull/516)
* [OCPNETUI-63](https://issues.redhat.com/browse/OCPNETUI-63): Drop unused Helm charts [#473](https://github.com/openshift/networking-console-plugin/pull/473)
* [OCPNETUI-14](https://issues.redhat.com/browse/OCPNETUI-14): Add Cypress E2E tests for network-to-VM cross-navigation [#493](https://github.com/openshift/networking-console-plugin/pull/493)
* [OCPNETUI-65](https://issues.redhat.com/browse/OCPNETUI-65): Add multi-branch dependabot config [#487](https://github.com/openshift/networking-console-plugin/pull/487)
* [CNV-67257](https://issues.redhat.com/browse/CNV-67257): Set physicalNetworkName on OVN localnet NADs created from the console [#477](https://github.com/openshift/networking-console-plugin/pull/477)
* [OCPBUGS-105358](https://issues.redhat.com/browse/OCPBUGS-105358): Fix NAD config generated in form for OVN K8s secondary localnet networks [#496](https://github.com/openshift/networking-console-plugin/pull/496)
* [OCPNETUI-81](https://issues.redhat.com/browse/OCPNETUI-81): Retry fetching from npm registry to unblock OKD build [#494](https://github.com/openshift/networking-console-plugin/pull/494)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add CI scripts for hot-cluster E2E infrastructure [#489](https://github.com/openshift/networking-console-plugin/pull/489)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add ci-env-controller Helm chart for test environment lifecycle [#491](https://github.com/openshift/networking-console-plugin/pull/491)
* [OCPNETUI-56](https://issues.redhat.com/browse/OCPNETUI-56): Add ci-test-stack Helm chart for E2E test environments [#490](https://github.com/openshift/networking-console-plugin/pull/490)
* [OCPNETUI-22](https://issues.redhat.com/browse/OCPNETUI-22): Add Cypress E2E tests for Service create and edit form [#480](https://github.com/openshift/networking-console-plugin/pull/480)
* [OCPNETUI-78](https://issues.redhat.com/browse/OCPNETUI-78): Sync Dockerfile and Dockerfile.art [#485](https://github.com/openshift/networking-console-plugin/pull/485)
* [OCPNETUI-59](https://issues.redhat.com/browse/OCPNETUI-59): Add Cypress E2E tests for Service and Route endpoint health [#481](https://github.com/openshift/networking-console-plugin/pull/481)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/881e2f26370d07c2c5e6240e478000da34cf15a6...943fc215c1b8dfb4c5a8c5645dbe94cad6402126)
### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/dd82b4a7e06ef4c0ad5abc2a7fbbb2882d765b41)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#228](https://github.com/openshift/oauth-apiserver/pull/228)
* [OCPBUGS-108041](https://issues.redhat.com/browse/OCPBUGS-108041): fix CVE-2026-41178 by bumping otel to v1.44.0 [#219](https://github.com/openshift/oauth-apiserver/pull/219)
* [Full changelog](https://github.com/openshift/oauth-apiserver/compare/81d5261594cba423b2519b8bc171e7967b987e36...dd82b4a7e06ef4c0ad5abc2a7fbbb2882d765b41)
### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/fa3b694f10331ec3ffd8c6c20b7933cb8ded0111)
* [ACM-37203](https://issues.redhat.com/browse/ACM-37203): Add support for configurable TLS profiles [#372](https://github.com/openshift/oauth-proxy/pull/372)
* [OCPBUGS-115305](https://issues.redhat.com/browse/OCPBUGS-115305): bugfix: rewrite open redirect strings to '/' [#374](https://github.com/openshift/oauth-proxy/pull/374)
* [Full changelog](https://github.com/openshift/oauth-proxy/compare/63a61bf10cbf46145a127246216540a38b50a018...fa3b694f10331ec3ffd8c6c20b7933cb8ded0111)
### [oauth-server](https://github.com/openshift/oauth-server/tree/5d2515f56de6fab67875c72bc98fad6a43100a16)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Update build-machinery-go vendor dependency [#260](https://github.com/openshift/oauth-server/pull/260)
* [OCPBUGS-115307](https://issues.redhat.com/browse/OCPBUGS-115307): bugfix: default to english when Accept-Language header contains more than 1000 underscores [#253](https://github.com/openshift/oauth-server/pull/253)
* [Full changelog](https://github.com/openshift/oauth-server/compare/1600eafd18f46d54ad0a9ff70fa03a085f6f6218...5d2515f56de6fab67875c72bc98fad6a43100a16)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/0c85f963ea84d2eba058c4217921ac51e9643093)
* NO-ISSUE: Synchronize From Upstream Repositories [#791](https://github.com/openshift/operator-framework-operator-controller/pull/791)
* [OCPBUGS-83515](https://issues.redhat.com/browse/OCPBUGS-83515): UPSTREAM: <carry>: use internal shell image for catalog FBC curl Job [#792](https://github.com/openshift/operator-framework-operator-controller/pull/792)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/19afc52f9d237c9cf1a2406ec228c363ebe1c677...0c85f963ea84d2eba058c4217921ac51e9643093)
### [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics/tree/5322ac5a46da4c11c310dc13ae41e6f80045379e)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#139](https://github.com/openshift/openshift-state-metrics/pull/139)
* [Full changelog](https://github.com/openshift/openshift-state-metrics/compare/3b4ea3e753d97fea66e0f52c8282a711358b4ff7...5322ac5a46da4c11c310dc13ae41e6f80045379e)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/eaa0992898ac0984f25d2fced6b69a1f8db54c7d)
* Fix release 0.14 sync: incomplete vendoring in hack/tools [#433](https://github.com/openshift/cluster-api-provider-openstack/pull/433)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/8fcaaaa900a4fd24fd53dab2c7c44c91bbf5a9c6...eaa0992898ac0984f25d2fced6b69a1f8db54c7d)
### [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller/tree/642037113b21f8b553ae449ed79888afd46cd006)
* UPSTREAM-SYNC: Merge https://github.com/k-orc/openstack-resource-controller:release-2.0 into main [#40](https://github.com/openshift/openstack-resource-controller/pull/40)
* [Full changelog](https://github.com/openshift/openstack-resource-controller/compare/58dbc0482c144c21effee2476947889122a518eb...642037113b21f8b553ae449ed79888afd46cd006)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/031c587813b3542c17ec1e861ec3dc37dacccfec)
* [OCPBUGS-122255](https://issues.redhat.com/browse/OCPBUGS-122255): tests-extension: fix PolarionID:68521 and Polarion:27680 [#1376](https://github.com/openshift/operator-framework-olm/pull/1376)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/cfe91e367d56b3bd96331942e3c7c7d434fd9c0d...031c587813b3542c17ec1e861ec3dc37dacccfec)
### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/6f413fbbfad17b2cfdf94d9f5b6f34da5028a763)
* NO-ISSUE: Bump github.com/onsi/ginkgo/v2 from 2.32.1 to 2.32.2 [#794](https://github.com/operator-framework/operator-marketplace/pull/794)
* NO-ISSUE: Bump github.com/onsi/gomega from 1.42.1 to 1.43.0 [#781](https://github.com/operator-framework/operator-marketplace/pull/781)
* NO-ISSUE: Bump github.com/sirupsen/logrus from 1.10.1 to 1.10.2 [#779](https://github.com/operator-framework/operator-marketplace/pull/779)
* NO-ISSUE: Bump github.com/stretchr/testify from 1.12.0 to 1.12.1 [#777](https://github.com/operator-framework/operator-marketplace/pull/777)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/f421eb0250c49687b08ea405e64fdbbb5509a9b7...6f413fbbfad17b2cfdf94d9f5b6f34da5028a763)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/dc48a3f1faa7ad835c3e412611452d2385f0dd90)
* [CORENET-7562](https://issues.redhat.com/browse/CORENET-7562), [OCPBUGS-98726](https://issues.redhat.com/browse/OCPBUGS-98726), [OCPBUGS-99645](https://issues.redhat.com/browse/OCPBUGS-99645): DownStream Merge [09-11-2026] [#3439](https://github.com/openshift/ovn-kubernetes/pull/3439)
* [OCPBUGS-112563](https://issues.redhat.com/browse/OCPBUGS-112563), [OCPBUGS-99451](https://issues.redhat.com/browse/OCPBUGS-99451): DownStream Merge [08-31-2026] [#3434](https://github.com/openshift/ovn-kubernetes/pull/3434)
* [CORENET-7467](https://issues.redhat.com/browse/CORENET-7467): run OTE tests only in ovn-kubernetes conformance suites [#3416](https://github.com/openshift/ovn-kubernetes/pull/3416)
* [OCPBUGS-112470](https://issues.redhat.com/browse/OCPBUGS-112470): Register test images using tests extension [#3363](https://github.com/openshift/ovn-kubernetes/pull/3363)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/2f9add8106687de6dba052689b97a189f92439f9...dc48a3f1faa7ad835c3e412611452d2385f0dd90)
### [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs/tree/f89ff660316e922f2f232379c3a03d8ad8d54a30)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#109](https://github.com/openshift/cloud-provider-powervs/pull/109)
* No-Jira: Update packages in go.mod [#108](https://github.com/openshift/cloud-provider-powervs/pull/108)
* [Full changelog](https://github.com/openshift/cloud-provider-powervs/compare/18eb5238fb2c86632edb24175f536d815f28ddf6...f89ff660316e922f2f232379c3a03d8ad8d54a30)
### [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs/tree/28c928ff78def160837170991f084b0fe71ca9be)
* [OCPBUGS-87523](https://issues.redhat.com/browse/OCPBUGS-87523): Updating ose-powervs-machine-controllers-container image to be consistent with ART for 5.0 [#144](https://github.com/openshift/machine-api-provider-powervs/pull/144)
* [Full changelog](https://github.com/openshift/machine-api-provider-powervs/compare/e88cf81dd9ad174f395b86f9cdc40fa30cb06bf4...28c928ff78def160837170991f084b0fe71ca9be)
### [prom-label-proxy](https://github.com/openshift/prom-label-proxy/tree/23e6f4a0c6b58930e7509fd063d7924025a69594)
* NO-ISSUE: [bot] Bump openshift/prom-label-proxy to v0.15.1 [#399](https://github.com/openshift/prom-label-proxy/pull/399)
* [Full changelog](https://github.com/openshift/prom-label-proxy/compare/4ab9ff73c665319352288fe0b9b9e1df71832525...23e6f4a0c6b58930e7509fd063d7924025a69594)
### [prometheus](https://github.com/openshift/prometheus/tree/c2c48fe1a4c9d2c0b6bc9f1fa9a41d669eac35f4)
* NO-JIRA: [bot] Bump openshift/prometheus to v3.14.0 [#363](https://github.com/openshift/prometheus/pull/363)
* NO-ISSUE: [bot] Bump openshift/prometheus to v3.14.0 [#361](https://github.com/openshift/prometheus/pull/361)
* [Full changelog](https://github.com/openshift/prometheus/compare/01d8335673aa6f88f5742ef510e133efee88a7bf...c2c48fe1a4c9d2c0b6bc9f1fa9a41d669eac35f4)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/6636dd048c835df8496f7e8fc878a0983bce0d9f)
* Bump openshift/prometheus-alertmanager to v0.34.1 [#177](https://github.com/openshift/prometheus-alertmanager/pull/177)
* Bump openshift/prometheus-alertmanager to v0.34.0 [#168](https://github.com/openshift/prometheus-alertmanager/pull/168)
* NO-ISSUE: Remove unused upstream .github/workflows [#167](https://github.com/openshift/prometheus-alertmanager/pull/167)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce...6636dd048c835df8496f7e8fc878a0983bce0d9f)
### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/64fea598a4ac46a0976ecb75bfe5dbef01416630)
* [MON-4689](https://issues.redhat.com/browse/MON-4689): Bump openshift/prometheus-operator to v0.94.0 [#400](https://github.com/openshift/prometheus-operator/pull/400)
* NO-ISSUE: [bot] Bump openshift/prometheus-operator to v0.93.1 [#393](https://github.com/openshift/prometheus-operator/pull/393)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/67895c7c968f42e97efec58f4140fffae4832028...64fea598a4ac46a0976ecb75bfe5dbef01416630)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/df6c312185d3c8f2fbd7f6f66dc410165bb65682)
* NO-ISSUE: [bot] Bump openshift/node_exporter to v1.12.1 [#186](https://github.com/openshift/node_exporter/pull/186)
* [Full changelog](https://github.com/openshift/node_exporter/compare/ff8cca07e946d00683527a18203def8b5f8e7380...df6c312185d3c8f2fbd7f6f66dc410165bb65682)
### [rhel-coreos, rhel-coreos-10, rhel-coreos-10-extensions, rhel-coreos-extensions](https://github.com/openshift/os/tree/7324ccd30e5b2b3146639cb610bfe92c743c91a1)
* [OCPBUGS-115309](https://issues.redhat.com/browse/OCPBUGS-115309): Re-enable sandboxed-containers extension for 5.0 [#1965](https://github.com/openshift/os/pull/1965)
* [Full changelog](https://github.com/openshift/os/compare/d2f3751e77c4b79b1553d18758c2ea91f06f51fc...7324ccd30e5b2b3146639cb610bfe92c743c91a1)
### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/a158fff7ce3826058bd2d7338b206cdd600d0d40)
* [OCPBUGS-104856](https://issues.redhat.com/browse/OCPBUGS-104856): clear unmanaged-route metric when the route is removed [#102](https://github.com/openshift/route-controller-manager/pull/102)
* [Full changelog](https://github.com/openshift/route-controller-manager/compare/59697cf7af4517dd44e28179a57f7f35b6ea0e22...a158fff7ce3826058bd2d7338b206cdd600d0d40)
### [telemeter](https://github.com/openshift/telemeter/tree/562e12c31ded836d7891a3b3138ad604070b9c5a)
* [OCPBUGS-114428](https://issues.redhat.com/browse/OCPBUGS-114428): Bump google.golang.org/protobuf to v1.36.12 [#615](https://github.com/openshift/telemeter/pull/615)
* [OCPBUGS-115550](https://issues.redhat.com/browse/OCPBUGS-115550): Add 'agent-installer-postconfig' install_type [#616](https://github.com/openshift/telemeter/pull/616)
* [Full changelog](https://github.com/openshift/telemeter/compare/a47a32bd9e52b1c86a4e1eaeb9d55f7956b6a583...562e12c31ded836d7891a3b3138ad604070b9c5a)
### [tests](https://github.com/openshift/origin/tree/3c85f767a0988a90bba4cc7ebaff609331c4c7ea)
* [OCPBUGS-112722](https://issues.redhat.com/browse/OCPBUGS-112722): make webhook build resolution wait phase-independent [#31655](https://github.com/openshift/origin/pull/31655)
* [OCPBUGS-121385](https://issues.redhat.com/browse/OCPBUGS-121385): Resolve Additional Storage agnhost image through mirror [#31618](https://github.com/openshift/origin/pull/31618)
* [NE-2750](https://issues.redhat.com/browse/NE-2750): implement feature test for GatewayAPIManagementMode [#31503](https://github.com/openshift/origin/pull/31503)
* [OCPEDGE-3076](https://issues.redhat.com/browse/OCPEDGE-3076): Fix TNF kubelet disruption test race condition [#31650](https://github.com/openshift/origin/pull/31650)
* [OCPSTRAT-3661](https://issues.redhat.com/browse/OCPSTRAT-3661): Always emit passing cases for found issues in RBAC monitor test [#31639](https://github.com/openshift/origin/pull/31639)
* NO-ISSUE: Automated - Update synthetic test data [#31607](https://github.com/openshift/origin/pull/31607)
* NO-JIRA: Add a new test for mass DNS disruption [#31625](https://github.com/openshift/origin/pull/31625)
* [OCPBUGS-114022](https://issues.redhat.com/browse/OCPBUGS-114022): Avoid polling skipped Prometheus target namespaces [#31563](https://github.com/openshift/origin/pull/31563)
* [TRT-2830](https://issues.redhat.com/browse/TRT-2830): add REVIEW.md for agentic review responses [#31637](https://github.com/openshift/origin/pull/31637)
* [OCPSTRAT-3661](https://issues.redhat.com/browse/OCPSTRAT-3661): Add Sippy discovered exceptions for RBAC monitor test [#31616](https://github.com/openshift/origin/pull/31616)
* [OCPBUGS-104846](https://issues.redhat.com/browse/OCPBUGS-104846): Filter both [FeatureGate:] and [OCPFeatureGate:] [#31623](https://github.com/openshift/origin/pull/31623)
* [OCPBUGS-121384](https://issues.redhat.com/browse/OCPBUGS-121384): Isolate KubeletEnsureSecretPulledImages test setup [#31619](https://github.com/openshift/origin/pull/31619)
* [OKD-454](https://issues.redhat.com/browse/OKD-454): Skip OKD job name check for cluster-bot launch jobs [#31628](https://github.com/openshift/origin/pull/31628)
* [OCPBUGS-92837](https://issues.redhat.com/browse/OCPBUGS-92837): test/router: wait for all per-route metrics before asserting [#31344](https://github.com/openshift/origin/pull/31344)
* [CORENET-6746](https://issues.redhat.com/browse/CORENET-6746): Allow EgressIP NoMatchingNodeFound events to repeat pathologically [#31614](https://github.com/openshift/origin/pull/31614)
* [OCPBUGS-86789](https://issues.redhat.com/browse/OCPBUGS-86789): Bump network config timeout to 25 minutes [#31599](https://github.com/openshift/origin/pull/31599)
* [CNTRLPLANE-3789](https://issues.redhat.com/browse/CNTRLPLANE-3789): Add e2e tests for authentication component proxy [#31446](https://github.com/openshift/origin/pull/31446)
* [OCPBUGS-84250](https://issues.redhat.com/browse/OCPBUGS-84250): Increase router verbosity in DCM tests [#31555](https://github.com/openshift/origin/pull/31555)
* NO-JIRA: test: poll final EgressFirewall DNS deny assertion [#31473](https://github.com/openshift/origin/pull/31473)
* [OCPBUGS-66213](https://issues.redhat.com/browse/OCPBUGS-66213): add link to jira card [#31609](https://github.com/openshift/origin/pull/31609)
* [NE-2839](https://issues.redhat.com/browse/NE-2839): Add HAProxy version upgrade tests [#31602](https://github.com/openshift/origin/pull/31602)
* [CORENET-7243](https://issues.redhat.com/browse/CORENET-7243): Add TLS Profile Compliance tests for networking components [#31500](https://github.com/openshift/origin/pull/31500)
* [OCPSTRAT-3618](https://issues.redhat.com/browse/OCPSTRAT-3618): Fix check in auth test for 1.37 given new NamedAuthorizer behavior [#31574](https://github.com/openshift/origin/pull/31574)
* [OCPSTRAT-3618](https://issues.redhat.com/browse/OCPSTRAT-3618): Update etcd test data for k8s 1.37 release [#31605](https://github.com/openshift/origin/pull/31605)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Register cluster-baremetal-tests-ext in extension registry [#31197](https://github.com/openshift/origin/pull/31197)
* [OCPSTRAT-3661](https://issues.redhat.com/browse/OCPSTRAT-3661): Add monitortest to verify possible Cluster Admin escalation paths [#31536](https://github.com/openshift/origin/pull/31536)
* [OCPBUGS-66213](https://issues.redhat.com/browse/OCPBUGS-66213): image registry single replica exceptions [#31544](https://github.com/openshift/origin/pull/31544)
* [OCPBUGS-111997](https://issues.redhat.com/browse/OCPBUGS-111997): Add Degraded=True exception for authentication operator during upgrade [#31535](https://github.com/openshift/origin/pull/31535)
* [TRT-2939](https://issues.redhat.com/browse/TRT-2939): Revert "Merge pull request #31495 from jcmoraisjr/NE-2839-haproxy-version-upgrade-tests" [#31598](https://github.com/openshift/origin/pull/31598)
* [OCPBUGS-77283](https://issues.redhat.com/browse/OCPBUGS-77283): bump kubevirt fedora containerDisk to multi-arch v1.8.2 + permanent exception [#31284](https://github.com/openshift/origin/pull/31284)
* [OCPBUGS-112662](https://issues.redhat.com/browse/OCPBUGS-112662): Fix the number of requests in repeated exec [#31548](https://github.com/openshift/origin/pull/31548)
* [OCPBUGS-115153](https://issues.redhat.com/browse/OCPBUGS-115153): Make extension test-binary extraction architecture-aware [#31579](https://github.com/openshift/origin/pull/31579)
* NO-ISSUE: Automated - Update synthetic test data [#31581](https://github.com/openshift/origin/pull/31581)
* [NE-2839](https://issues.redhat.com/browse/NE-2839): Add HAProxy version upgrade tests [#31495](https://github.com/openshift/origin/pull/31495)
* [OCPBUGS-111643](https://issues.redhat.com/browse/OCPBUGS-111643): Fixed Flakiness of Webhook test - ClusterResourceQuota validation [#31531](https://github.com/openshift/origin/pull/31531)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/origin/compare/42b963ac884b41db0af70e2dcfc78b17d262b496...3c85f767a0988a90bba4cc7ebaff609331c4c7ea)
### [thanos](https://github.com/openshift/thanos/tree/6caa7c9cad471582053356a0854cc86b152546fb)
* [OCPBUGS-120744](https://issues.redhat.com/browse/OCPBUGS-120744): bump go.opentelemetry.io/otel to fix CVE-2026-41178 [#204](https://github.com/openshift/thanos/pull/204)
* [Full changelog](https://github.com/openshift/thanos/compare/75fa632b483716e53aec19f6adf7d4c4652a4453...6caa7c9cad471582053356a0854cc86b152546fb)
### [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator/tree/845636b46d1c4fb1f30fcf5332276573aafeee19)
* [OCPBUGS-127004](https://issues.redhat.com/browse/OCPBUGS-127004): Bump golang.org/x/net to version 0.57.0 that fixes CVE-2026-33814 [#17](https://github.com/openshift/volume-data-source-validator/pull/17)
* [Full changelog](https://github.com/openshift/volume-data-source-validator/compare/ee9cd7aba4e096a9a957386ef20777e8950df352...845636b46d1c4fb1f30fcf5332276573aafeee19)