Repository navigation
v3.3.15
·
1956 commits
to master
since this release
Quick Start
Non-HA:
kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.15/manifests/install.yamlHA:
kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.15/manifests/ha/install.yamlRelease Signatures and Provenance
All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.
Release Notes Blog Post
For a detailed breakdown of the key changes and improvements in this release, check out the official blog post
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changelog
Security fixes
- CRITICAL: A Kustomize remote ref can run commands in the repo-server (GHSA-9v9p-x54c-58gc)
- CRITICAL: A Kustomize Helm config home can run commands in the repo-server (GHSA-fw5c-w8rc-j7fx)
- CRITICAL: A Jsonnet import can read files from the repo-server (GHSA-m3vr-7329-44ww)
- CRITICAL: AppProject restrictions bypassed by PreDelete/PostDelete resource hooks (GHSA-fmxq-cgp8-87wp, CVE-2026-77459)
- HIGH: Login failure rate limit can be bypassed via concurrent requests (GHSA-4439-h7jw-5cjj, CVE-2025-61560)
- HIGH: Command injection via a repository proxy URL on SSH Git repositories (GHSA-j6cw-g6p4-7hch, CVE-2026-55797)
- MODERATE: Extension proxy RBAC ignores application namespace when applications-in-any-namespace is enabled (GHSA-g3ff-q88g-chrj)
- MODERATE: An oversized OCI manifest can exhaust repo-server memory (GHSA-w996-f2wq-x9c6)
Potentially-breaking changes
- Kustomize builds that render Helm charts no longer honor
helmGlobals.configHome. Ordinaryhttp,https, andocichart repositories still work. Builds that depended on a Helm plugin registered from that directory will not (GHSA-fw5c-w8rc-j7fx). - An OCI manifest larger than 4 MiB is now rejected (GHSA-w996-f2wq-x9c6).
Bug fixes
- c6e39fd: fix(cmp): clean up tgz stream temporary directories (#29148) (cherry-pick #29156 for 3.3) (#29774) (@argo-cd-cherry-pick-bot[bot])
- c397ddc: fix(health): a KubeVirt VirtualMachine declared stopped is Healthy (cherry-pick #29664 for 3.3) (#29667) (@argo-cd-cherry-pick-bot[bot])
- 33ffc7d: fix(health): report suspended FlinkDeployment as healthy (#26818) (cherry-pick #28995 for 3.3) (#29526) (@argo-cd-cherry-pick-bot[bot])
- 3abe9eb: fix(hydrator): retry notes push on cannot lock ref errors (cherry-pick #28469 for 3.3) (#29906) (@argo-cd-cherry-pick-bot[bot])
- 990ea56: fix(resource_customizations): Crossplane MRs should report Progressing (not Healthy) whilst provisioning [ISSUE: #29381] (cherry-pick #29382 for 3.3) (#29519) (@argo-cd-cherry-pick-bot[bot])
- 1149cdc: fix(security): coordinated security fixes (release-3.3) (#30040) (@crenshaw-dev)
- a050c4f: fix(sync): correctly set operationState values on retry (#26530) (cherry-pick #28778 for 3.3) (#29433) (@omkar619-dev)
- d5b193b: fix(ui): manifest viewer jumpiness (#29691) (cherry pick 3.3) (#29727) (@crenshaw-dev)
- 2cffaf5: fix(ui): use hydrateTo branch name when set (cherry-pick #29562 for 3.3) (#29565) (@crenshaw-dev)
- 0900428: fix: GRPCRoute health check ignores stale observedGeneration conditions (#28086) (cherry-pick #28087 for 3.3) (#29516) (@argo-cd-cherry-pick-bot[bot])
- ec1fc45: fix: don't degrade Cluster API Cluster health while Ready is False during provisioning (cherry-pick #29237 for 3.3) (#29272) (@argo-cd-cherry-pick-bot[bot])
- 601f611: fix: handle GrafanaFolder negative-polarity condition (#29395) (cherry-pick #29397 for 3.3) (#29522) (@argo-cd-cherry-pick-bot[bot])
Dependency updates
- 3249c5c: chore(deps): bump go.opentelemetry.io/otel from 1.43 to 1.44 (release-3.3) (#29763) (@nmirasch)
- 874a17c: chore(deps): bump golang.org/x/crypto to 0.55.0 (release-3.3) (#29824) (@akhilnittala)
- d697764: chore(deps): bump js-yaml to 4.3.1 in /ui for CVE-2026-59869 (release-3.3) (#29386) (@aali309)
Full Changelog: v3.3.14...v3.3.15
