megachangelog
Security3.6.13

v3.6.13

Patch release addressing multiple security vulnerabilities including critical fluentd dependency update, Go version bump to 1.26.5, gRPC and networking library updates, and GCS object store fix.

3.6.13 (2026-07-23)

Bug Fixes

  • ci: Fix zizmor findings for operator-images in Loki 3.6 (#22821) (050f742)
  • ci: Helm CI warning fix (#22606) (4bc2586)
  • security/CRITICAL/clients/cmd/fluentd/docker: Update dependency fluentd to v1.19.3 [SECURITY] (release-3.6.x) (#22694) (692f2b1)
  • security/HIGH/: Bump Go to 1.26.5 to address CVE-2026-39822 and CVE-2026-42505 [SECURITY] (#23398) (fc478e1)
  • security/HIGH/pkg/push: Update module google.golang.org/grpc to v1.82.1 [SECURITY] (70f75b7)
  • security/HIGH/: Update golang.org/x/net, golang.org/x/text and google.golang.org/grpc [SECURITY] (70f75b7)
  • security/UNKNOWN/cmd/chunks-inspect: Update go toolchain directive to v1.25.12 [SECURITY] (release-3.6.x) (#23131) (b327439)
  • security/UNKNOWN/pkg/push: Update module golang.org/x/net to v0.56.0 [SECURITY] (70f75b7)
  • security/UNKNOWN/pkg/push: Update module golang.org/x/text to v0.39.0 [SECURITY] (70f75b7)
  • security/UNKNOWN/: Update module github.com/containerd/containerd/v2 to v2.0.10 [SECURITY] (release-3.6.x) (#22479) (697bd83)
  • security: Backport security updates to release-3.6.x (#23403) (70f75b7)
  • Update objstore to include fix for GCS Exists (#23381) (87383d8)
securitydependenciesbug-fixesgcsgrpc

Source: original entry ↗