Skip to content

v3.3.15

Choose a tag to compare

@github-actions github-actions released this 06 Oct 21:35
· 1956 commits to master since this release
a7d718d

Quick Start

Non-HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.15/manifests/install.yaml

HA:

kubectl create namespace argocd
kubectl apply -n argocd --server-side --force-conflicts -f https://raw.githubusercontent.com/argoproj/argo-cd/v3.3.15/manifests/ha/install.yaml

Release Signatures and Provenance

All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.

Release Notes Blog Post

For a detailed breakdown of the key changes and improvements in this release, check out the official blog post

Upgrading

If upgrading from a different minor version, be sure to read the upgrading documentation.

Changelog

Security fixes

  • CRITICAL: A Kustomize remote ref can run commands in the repo-server (GHSA-9v9p-x54c-58gc)
  • CRITICAL: A Kustomize Helm config home can run commands in the repo-server (GHSA-fw5c-w8rc-j7fx)
  • CRITICAL: A Jsonnet import can read files from the repo-server (GHSA-m3vr-7329-44ww)
  • CRITICAL: AppProject restrictions bypassed by PreDelete/PostDelete resource hooks (GHSA-fmxq-cgp8-87wp, CVE-2026-77459)
  • HIGH: Login failure rate limit can be bypassed via concurrent requests (GHSA-4439-h7jw-5cjj, CVE-2025-61560)
  • HIGH: Command injection via a repository proxy URL on SSH Git repositories (GHSA-j6cw-g6p4-7hch, CVE-2026-55797)
  • MODERATE: Extension proxy RBAC ignores application namespace when applications-in-any-namespace is enabled (GHSA-g3ff-q88g-chrj)
  • MODERATE: An oversized OCI manifest can exhaust repo-server memory (GHSA-w996-f2wq-x9c6)

Potentially-breaking changes

  • Kustomize builds that render Helm charts no longer honor helmGlobals.configHome. Ordinary http, https, and oci chart repositories still work. Builds that depended on a Helm plugin registered from that directory will not (GHSA-fw5c-w8rc-j7fx).
  • An OCI manifest larger than 4 MiB is now rejected (GHSA-w996-f2wq-x9c6).

Bug fixes

  • c6e39fd: fix(cmp): clean up tgz stream temporary directories (#29148) (cherry-pick #29156 for 3.3) (#29774) (@argo-cd-cherry-pick-bot[bot])
  • c397ddc: fix(health): a KubeVirt VirtualMachine declared stopped is Healthy (cherry-pick #29664 for 3.3) (#29667) (@argo-cd-cherry-pick-bot[bot])
  • 33ffc7d: fix(health): report suspended FlinkDeployment as healthy (#26818) (cherry-pick #28995 for 3.3) (#29526) (@argo-cd-cherry-pick-bot[bot])
  • 3abe9eb: fix(hydrator): retry notes push on cannot lock ref errors (cherry-pick #28469 for 3.3) (#29906) (@argo-cd-cherry-pick-bot[bot])
  • 990ea56: fix(resource_customizations): Crossplane MRs should report Progressing (not Healthy) whilst provisioning [ISSUE: #29381] (cherry-pick #29382 for 3.3) (#29519) (@argo-cd-cherry-pick-bot[bot])
  • 1149cdc: fix(security): coordinated security fixes (release-3.3) (#30040) (@crenshaw-dev)
  • a050c4f: fix(sync): correctly set operationState values on retry (#26530) (cherry-pick #28778 for 3.3) (#29433) (@omkar619-dev)
  • d5b193b: fix(ui): manifest viewer jumpiness (#29691) (cherry pick 3.3) (#29727) (@crenshaw-dev)
  • 2cffaf5: fix(ui): use hydrateTo branch name when set (cherry-pick #29562 for 3.3) (#29565) (@crenshaw-dev)
  • 0900428: fix: GRPCRoute health check ignores stale observedGeneration conditions (#28086) (cherry-pick #28087 for 3.3) (#29516) (@argo-cd-cherry-pick-bot[bot])
  • ec1fc45: fix: don't degrade Cluster API Cluster health while Ready is False during provisioning (cherry-pick #29237 for 3.3) (#29272) (@argo-cd-cherry-pick-bot[bot])
  • 601f611: fix: handle GrafanaFolder negative-polarity condition (#29395) (cherry-pick #29397 for 3.3) (#29522) (@argo-cd-cherry-pick-bot[bot])

Dependency updates

Full Changelog: v3.3.14...v3.3.15