# 5.0.0-ec.6
Created: 2026-08-14 09:13:04 +0000 UTC
Image Digest: `sha256:99dd09ec333719ac6ea8193c5abe3bdd2802cf8af021435a4bf05a956c901d83`
## Changes from 5.0.0-ec.5
### Components
* Kubectl 1.36.2
* Kubernetes 1.36.2
* Kubernetes Tests upgraded from 1.35.1 to 1.36.2
* Red Hat Enterprise Linux CoreOS 10.2 upgraded from 10.2.20260724-0 to 10.2.20260808-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| NewOLMPreflightPermissionChecks
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| RouteExternalCertificate
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| AWSDualStackInstall
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| IngressControllerMultipleHAProxyVersions
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| IrreconcilableMachineConfig
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| CRIOCredentialProviderConfig
(0 tests)| Disabled| Enabled
(Changed)| Disabled
(Changed)| Enabled| Disabled| Enabled
(Changed)| Disabled
(Changed)| Enabled |
| NoRegistryClusterInstall
(0 tests)| Disabled| Enabled
(Changed)| Disabled| Enabled| Disabled| Enabled
(Changed)| Disabled| Enabled |
| GatewayAPIManagementMode
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
### New images
* [agentic-skills](https://github.com/openshift/agentic-skills) git [39429747](https://github.com/openshift/agentic-skills/commit/39429747952afd5e3c56fd86299f8a7614d27a79) `sha256:9d2dde515af64e251ace63c2d09c18cc78447ef7860850928ac837ba17ca639c`
* [oc-mirror](https://github.com/openshift/oc-mirror) git [9054b9a9](https://github.com/openshift/oc-mirror/commit/9054b9a94cf71f27d141c72807928ded09dadb8e) `sha256:d1a1647ad0e04e003fe04c216d6a13fd6692a6a2b97fea1b248880cfaee9ec1c`
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [8264c02d](https://github.com/openshift/apiserver-network-proxy/commit/8264c02deda9abb6cd9a6a5c23305428431473c2) `sha256:f259deb698f822371718223e8d9e8ed5b717cec8cf3e9fa7bcd8b615de2ffedb`
* [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [8b8c4cef](https://github.com/openshift/aws-ebs-csi-driver/commit/8b8c4cef02ec9b670e2709f2aacc0ed72420be90) `sha256:3ef8409a07dd112ae38dc820062a6dc06fccb5bb993b55a45a16ea100d6ca782`
* [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler) git [e4ff2aae](https://github.com/openshift/aws-node-termination-handler/commit/e4ff2aaec292db42de9f3eef4908ba1c421a2a6c) `sha256:43ea7d038395e04140d2cf09677d8d08f99ffe6af77f6fac7b4a4bda35799f16`
* [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [0d33a459](https://github.com/openshift/aws-pod-identity-webhook/commit/0d33a4596e2a22d188fe74c4a6497c37c2528c1f) `sha256:f63fba3f9aa716cca7df3c0f834f1dd526742963ceeba18cda18ad119e1d90df`
* [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure) git [63731729](https://github.com/openshift/cluster-api-provider-azure/commit/63731729974bff3be90ae2206c53d760572499d1) `sha256:0babe3b52b09eb54ba72e76b2930bc9b5ba90dc95e6ba2790a38f01392033e9a`
* [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms) git [ca3d747d](https://github.com/openshift/azure-kubernetes-kms/commit/ca3d747de321b88a2c606e546851d1841d2fab9f) `sha256:8ca99ff781d67a70b908894ff1a2d75d9f7ff639a3e7608c6b4503b0c5ce8cbc`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:7997e68a46ed32769720bce3be5336469565ca9cbfe3d012978322445d57849b`
* [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity) git [2b4705c5](https://github.com/openshift/azure-workload-identity/commit/2b4705c5d999339ce17d47a9b2a637d238891dae) `sha256:a2022593a7651ed7b790e31f11a3f777523e415065550e210746a31621444b5b`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [f2b0db19](https://github.com/openshift/cluster-api-provider-baremetal/commit/f2b0db1919fff1344bc68948894c6775c0bf24a3) `sha256:1351657d5ca3294e99f098464a3edc3e355bb0a32381f121fa703baf839021f4`
* [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg) git [66007361](https://github.com/openshift/baremetal-runtimecfg/commit/660073616802e3d1258a036f2e57ca18a7baafa0) `sha256:6c6566ff8b3ff7dd6d5cb3509ec5576dccf91b8f847342442ccc0bb41d783c50`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [7b1593a4](https://github.com/openshift/cluster-bootstrap/commit/7b1593a47898b6a97dc457efaca464624e9f2afa) `sha256:68dc4f99b404bc14d07c1ad9c2d348b5ec8a4b441cc5c76c35dc8fd16048f033`
* [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator) git [4e72164b](https://github.com/openshift/cluster-kube-controller-manager-operator/commit/4e72164b8bc505033ad565ab01d57963e7c9688e) `sha256:c94b4bc7b5bfef164d98e3b354852761547c611afd744123ba9a8ad75bdbdb4b`
* [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator) git [56fa3254](https://github.com/openshift/cluster-kube-scheduler-operator/commit/56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3) `sha256:473eb6d62a082ef65963b23d7d133d80af1dcf360c045eda2087650ae163a9bd`
* [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator) git [f5d3bfe6](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/commit/f5d3bfe64bda67ffb8299af01ebf2722287edf04) `sha256:db1110171df7bc52d4cab8b4a67e1e0107b12182875bcbed2ebc55c7908940d6`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [34f95b07](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/34f95b07f4afbc47558e54e4fa2710fd692e615e) `sha256:a8f81994d369e440a8a9e1557e35e042df5e9bf8122ee8598ad955b2aba072e7`
* [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller) git [01afc4aa](https://github.com/openshift/cluster-policy-controller/commit/01afc4aac71a8e8be26383a0421bed7673391750) `sha256:6aa029b3255ea5a58b5738cf79090de61288f88b40d55d8919998f9a4857d3ad`
* [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator) git [eee95bab](https://github.com/openshift/cluster-samples-operator/commit/eee95babd52053191e29355108f7daf149dfbf8f) `sha256:3280855fd9d3da50cf35abfb2ec0b35bdf5c8c0106c5bd79163f42006e0a4183`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:6d0827b6a613cad6beb4492cf0d39793fbd63b055429ce7a64b58739b6646220`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [ce80869a](https://github.com/openshift/configmap-reload/commit/ce80869a83b55ebbdc21a5550ec5747645203bd2) `sha256:2e6cf6d3fad813a678d4dc00e331e16a6880ed8d102573e0ff6dacb4b567a844`
* [container-networking-plugins](https://github.com/openshift/containernetworking-plugins) git [d6f73950](https://github.com/openshift/containernetworking-plugins/commit/d6f73950658d258e0ddbf2a4ac92e13ac840158b) `sha256:c8d51d9ac763bf6b4a830ada295004cd9c7e8386d637833138ea34396adefb01`
* [containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins) git [d6f73950](https://github.com/openshift/containernetworking-plugins/commit/d6f73950658d258e0ddbf2a4ac92e13ac840158b) `sha256:65ab2af3ac188bd043ae6a866432d92547fd2b9df6df8e084f003747507aee29`
* [coredns](https://github.com/openshift/coredns) git [37aaba89](https://github.com/openshift/coredns/commit/37aaba896e97f4b9a091aab6d36f2213b8854474) `sha256:3717fd8229f8f8bc9db680670ac94e3a76c72cf65c5072baca5720ea7ba9434a`
* [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata) git [239703c6](https://github.com/openshift/csi-external-snapshot-metadata/commit/239703c637e005cf785892d214d219add70e3533) `sha256:5c1cb85f91850b49d35e052d4da82603c8bab7f2b1478f30d1b8cf74d5c5acc2`
* [docker-builder](https://github.com/openshift/builder) git [2cda03a9](https://github.com/openshift/builder/commit/2cda03a93696d4620703848471b3b873b0b2fa1e) `sha256:b74cf6de71cc4b687f7e9e593114c5fc796360a7362eba107f03e95ca6c71ed8`
* [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver) git [2dad9ff8](https://github.com/openshift/gcp-pd-csi-driver/commit/2dad9ff88511cc4e82a777c49ec55cbed2e3a057) `sha256:7013f99926e3c11fd253c825da09f78de976f2f673b8c5b6f9c31cc13d27ae81`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [f8e41b2e](https://github.com/openshift/ironic-rhcos-downloader/commit/f8e41b2ed8915474a99e3eb34b54692afb0611da) `sha256:de13df6a3232b2a9e20bdfdf0fe9734c0876e99bdc7d5ee70e5c8664210a7667`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [486a0418](https://github.com/openshift/ironic-static-ip-manager/commit/486a041897d703d55ef59c98e2b20a01588a0b4c) `sha256:7c9bdcdc0ff89a41e370b66e4dfcc931ab9148520539035062a8b385d302a382`
* [keepalived-ipfailover](https://github.com/openshift/images) git [13118bff](https://github.com/openshift/images/commit/13118bff15103b31a6528bf8de2d0d6de05f4742) `sha256:4bd87bed563f081c2965a4717881e06c811deff1a63c4188d3f0fbe7432c7ac0`
* [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [43c114bc](https://github.com/openshift/kube-rbac-proxy/commit/43c114bc124f59e2fc3223dea8e0a8f4cdeed18d) `sha256:ebba4aaab37783e02e0181907509c61adf019b236ff6523a170778ecb6cab444`
* [kube-state-metrics](https://github.com/openshift/kube-state-metrics) git [019ecc7d](https://github.com/openshift/kube-state-metrics/commit/019ecc7d533333dfd3bf8893e78cd7ec6e282f01) `sha256:46daaf7128a5cfc76d56de4fb34f3d55729332e3d49e7a4aefeb28aed37ff47a`
* [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [72835e43](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/72835e43c7754356645e41031f3a99926b4d42e6) `sha256:f3a065cd1fd4452557d6983203f02d04bc352efadaf2a010f7b996daf8002c65`
* [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt) git [5eb884ab](https://github.com/openshift/cloud-provider-kubevirt/commit/5eb884abcd2ff17ae8d7b2691ca12494597c08a6) `sha256:46841ae828680787191e7d98d56f939b3fb1816a299f43d8b5a6cf967adb1dc9`
* [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver) git [7ff99994](https://github.com/openshift/kubevirt-csi-driver/commit/7ff99994ecc3a675fac6f9aa7fa418cdb0dca32b) `sha256:48393e4ea2997518669beee5aad3ddadf8ad5c4f9b679e0aa1e0800e6943c32e`
* [multus-admission-controller](https://github.com/openshift/multus-admission-controller) git [4bb2e206](https://github.com/openshift/multus-admission-controller/commit/4bb2e2069c3e4f11fbc4c1befd6dc1c41fa802b7) `sha256:801269ba3b4c73f60a09429d3e0a2ea780b00999e7b4457334a9cd2177f0a1d6`
* [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [932bdaa4](https://github.com/openshift/multus-networkpolicy/commit/932bdaa4250d0a1db41a1a1fcac8192f2757211c) `sha256:7255fe8db66b3c29d6b0ab9b1fb8a99e7e19e6f0962df2656f8735f49ad6c4d0`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [08af4127](https://github.com/openshift/route-override-cni/commit/08af4127c77976510cad1c096d9aca977d8ae5af) `sha256:d925133fd4ed3092d69529c8cd8c07ad226f3e6af2fe6d7b7dacdb7f311e0cfb`
* [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni) git [d918bda2](https://github.com/openshift/whereabouts-cni/commit/d918bda28ad3d0200b6e4f2ef2801556764762e5) `sha256:529c2eda98ed64a4d66f4b5150d3f40f886380c164189a550872dea0b162d0f4`
* [network-interface-bond-cni](https://github.com/openshift/bond-cni) git [19d390fd](https://github.com/openshift/bond-cni/commit/19d390fd4d353619fdfb5e0070962d2ddf54b5bb) `sha256:6175ddf11c8b7bf4b51eb0dea8ee607bd5c3753fc42c521c2e208680c139552c`
* [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon) git [e0fc86da](https://github.com/openshift/network-metrics-daemon/commit/e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844) `sha256:0e9b3bdb73d02e0367298b1d016370b0d96541e61d1fd682bf77eb3071737dbf`
* [network-tools](https://github.com/openshift/network-tools) git [0b53ac3d](https://github.com/openshift/network-tools/commit/0b53ac3dccf59cd169555bf18c207122374bf003) `sha256:e63f4c10a0d4fbc40080de2e25c78e344ea9fcb4f9fa102b5344cf7d9062eab9`
* [oauth-apiserver](https://github.com/openshift/oauth-apiserver) git [688f57b5](https://github.com/openshift/oauth-apiserver/commit/688f57b5af12182644b33b770151352b1d54df3a) `sha256:43eba4f88787827d2f9b3094b06282452b9d2c6df5072be17ba756d357d50c80`
* [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager) git [5631cf49](https://github.com/openshift/openshift-controller-manager/commit/5631cf493b006cbc72a8600a7435813272d71940) `sha256:d9314c2af51bf889041f4720645d3657a2bed9e93623491b287a8c0fe596a46e`
* [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [0e12f5d6](https://github.com/openshift/openshift-state-metrics/commit/0e12f5d6df02b37b0353a747d144e8069c3d0c2a) `sha256:c23ba0ac322ea5a0f63a32ff372279cb7aa9d7e865d1efc579a67156a6d45b8c`
* [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:16b28ee907809b349756e61c32b27f6adc5cc3ca2130eac31510ad47c49e83e2`
* [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller) git [58dbc048](https://github.com/openshift/openstack-resource-controller/commit/58dbc0482c144c21effee2476947889122a518eb) `sha256:1318eb3ff4290b3e44b188a76182dad64f3b23470a46447831ce4d6136419920`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [4ab9ff73](https://github.com/openshift/prom-label-proxy/commit/4ab9ff73c665319352288fe0b9b9e1df71832525) `sha256:9750feceefe7d99852080e379618dd1d4b89bba3816813aec8c72b9e54dbcc46`
* [route-controller-manager](https://github.com/openshift/route-controller-manager) git [59697cf7](https://github.com/openshift/route-controller-manager/commit/59697cf7af4517dd44e28179a57f7f35b6ea0e22) `sha256:ade0d9b617b3a5561dc2e975c43b47bdde71c8196ae8ed9259c7a33ba77cb43e`
* [telemeter](https://github.com/openshift/telemeter) git [22ba1701](https://github.com/openshift/telemeter/commit/22ba1701333f3fd26490cc15b89ddf21df3f67f6) `sha256:886dc0bb6bd742effb9f3e2a0908816d20974c05ebb0b84dcfb450e074c7d986`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/90c28e0308dcbc321654cdbcb4cb958550037240)
* [OCPBUGS-93750](https://issues.redhat.com/browse/OCPBUGS-93750): Bump github.com/moby/moby to v28.5.2 [#10680](https://github.com/openshift/assisted-service/pull/10680)
* [MGMT-24827](https://issues.redhat.com/browse/MGMT-24827): Resource-scoped auth for urlAuth endpoints [#10667](https://github.com/openshift/assisted-service/pull/10667)
* [MGMT-24831](https://issues.redhat.com/browse/MGMT-24831): Add ntpSources field to InfraEnv and AgentClusterInstall CRDs [#10756](https://github.com/openshift/assisted-service/pull/10756)
* [ACM-30180](https://issues.redhat.com/browse/ACM-30180): Honor cluster TLS security profile in Infrastructure Operator [#10734](https://github.com/openshift/assisted-service/pull/10734)
* NO-ISSUE: [master] Bump OCP versions: 4.22 [#10735](https://github.com/openshift/assisted-service/pull/10735)
* [MGMT-24939](https://issues.redhat.com/browse/MGMT-24939): (assisted-service) Upgrade operator-sdk from v1.10.1 to v1.42.3 (kubebuilder v3→v4 migration) [#10716](https://github.com/openshift/assisted-service/pull/10716)
* NO-ISSUE: [master] Bump OCP versions: 4.16, 4.14, 5.0 [#10733](https://github.com/openshift/assisted-service/pull/10733)
* [MGMT-24903](https://issues.redhat.com/browse/MGMT-24903): Fall back to CoreOS image from worker ignition for day-2 persistent-boot [#10717](https://github.com/openshift/assisted-service/pull/10717)
* [MULTIARCH-6274](https://issues.redhat.com/browse/MULTIARCH-6274): agent: Enable platform external s390x [#10424](https://github.com/openshift/assisted-service/pull/10424)
* [MGMT-24352](https://issues.redhat.com/browse/MGMT-24352): Reset finalizing timeout on transition from installing-pending-user-action [#10293](https://github.com/openshift/assisted-service/pull/10293)
* [OCPBUGS-97919](https://issues.redhat.com/browse/OCPBUGS-97919): fix: use typed credentials key to support MAC-based fencing in ABI flow [#10477](https://github.com/openshift/assisted-service/pull/10477)
* [ACM-38238](https://issues.redhat.com/browse/ACM-38238): Assisted-installer repos: Set Up Set up Renovate configuration to automatically create Hive API Synchronization PRs [#10711](https://github.com/openshift/assisted-service/pull/10711)
* [OCPBUGS-91733](https://issues.redhat.com/browse/OCPBUGS-91733): manifest_generator add a label to LUKS root [#10676](https://github.com/openshift/assisted-service/pull/10676)
* NO-ISSUE: [master] Bump OCP versions: 4.18, 4.19 [#10724](https://github.com/openshift/assisted-service/pull/10724)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [SECURITY] [#10718](https://github.com/openshift/assisted-service/pull/10718)
* NO-ISSUE: [master] Bump OCP versions: 4.20, 4.21, 4.22 [#10715](https://github.com/openshift/assisted-service/pull/10715)
* And 4 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/assisted-service/compare/f46558c1df1388bc21448ae7fd3b249febb29798...90c28e0308dcbc321654cdbcb4cb958550037240)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/02d30997f8496c348ea45c4f950f360574178e45)
* [MGMT-24598](https://issues.redhat.com/browse/MGMT-24598): CVE-2026-42306 Bump assisted-service dep to pick up docker v28.5.2 [#2219](https://github.com/openshift/assisted-installer/pull/2219)
* [OCPBUGS-96799](https://issues.redhat.com/browse/OCPBUGS-96799): Bump golang.org/x/net from v0.48.0 to v0.55.0 [#2244](https://github.com/openshift/assisted-installer/pull/2244)
* [OCPBUGS-96696](https://issues.redhat.com/browse/OCPBUGS-96696): Wait for all nodes to join before exiting for ABI [#2230](https://github.com/openshift/assisted-installer/pull/2230)
* [ACM-38238](https://issues.redhat.com/browse/ACM-38238): Assisted-installer repos: Set Up Set up Renovate configuration to automatically create Hive API Synchronization PRs [#2224](https://github.com/openshift/assisted-installer/pull/2224)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/e4afa401ce7d4f8a24a857fd2edf3338fef1556e...02d30997f8496c348ea45c4f950f360574178e45)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/aeec165131a4c528174a58a011d1c3c31cfd7cc1)
* [MGMT-24597](https://issues.redhat.com/browse/MGMT-24597): CVE-2026-42306 Bump assisted-service dep to pick up docker v28.5.2 [#1560](https://github.com/openshift/assisted-installer-agent/pull/1560)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [#1578](https://github.com/openshift/assisted-installer-agent/pull/1578)
* [MGMT-24903](https://issues.redhat.com/browse/MGMT-24903): Preserve encapsulated MachineConfig in filtered ignition [#1568](https://github.com/openshift/assisted-installer-agent/pull/1568)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/bfa655c8a4905031aab68000b84535674413f3b4...aeec165131a4c528174a58a011d1c3c31cfd7cc1)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/c031572a47209d362aec8f775cdbef7d0ae4a172)
* [OCPBUGS-101759](https://issues.redhat.com/browse/OCPBUGS-101759): Update Konflux references [#331](https://github.com/openshift/agent-installer-utils/pull/331)
* [OCPBUGS-99905](https://issues.redhat.com/browse/OCPBUGS-99905): Update Konflux references [#303](https://github.com/openshift/agent-installer-utils/pull/303)
* [OCPBUGS-99745](https://issues.redhat.com/browse/OCPBUGS-99745): Use Operator catalog in 4.22 for OVE [#323](https://github.com/openshift/agent-installer-utils/pull/323)
* [OCPBUGS-87367](https://issues.redhat.com/browse/OCPBUGS-87367): Updating ose-agent-installer-utils-container image to be consistent with ART for 5.0 [#308](https://github.com/openshift/agent-installer-utils/pull/308)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/4c1ca15266d79b638bb0bc376b9536522f302025...c031572a47209d362aec8f775cdbef7d0ae4a172)
### [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws/tree/278e8c07a72a50e7d3f28fc743c38c64f008f5aa)
* [OCPCLOUD-3643](https://issues.redhat.com/browse/OCPCLOUD-3643): Merge https://github.com/kubernetes/cloud-provider-aws:master (63ec440) into main [#160](https://github.com/openshift/cloud-provider-aws/pull/160)
* [Full changelog](https://github.com/openshift/cloud-provider-aws/compare/5060934bc9ff325acf4bd0728bf37166255a501f...278e8c07a72a50e7d3f28fc743c38c64f008f5aa)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/1f5b17cc6969d6013a1abc5c6c62f00add809ceb)
* ✨ OCPCLOUD-3538,OCPCLOUD-3556: Exclude unsupported CAPI CRDs and scope ClusterRole [#618](https://github.com/openshift/cluster-api-provider-aws/pull/618)
* 🌱 OCPCLOUD-3599: Merge https://github.com/kubernetes-sigs/cluster-api-provider-aws:v2.13.0 (a84670f) into main [#623](https://github.com/openshift/cluster-api-provider-aws/pull/623)
* :seedling: OCPBUGS-95028: bump golang.org/x/net to v0.55.0 for CVE-2026-25681 [#622](https://github.com/openshift/cluster-api-provider-aws/pull/622)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/902df006f6c3a37aaeed7e09fa6f892788e36d00...1f5b17cc6969d6013a1abc5c6c62f00add809ceb)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, gcp-pd-csi-driver-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/756f6b8bb00400e3d72437876a820a950c393eb3)
* [STOR-2998](https://issues.redhat.com/browse/STOR-2998): Remove legacy gcp-pd-csi-driver-operator [#592](https://github.com/openshift/csi-operator/pull/592)
* [STOR-3060](https://issues.redhat.com/browse/STOR-3060), [STOR-3061](https://issues.redhat.com/browse/STOR-3061): implement TLS adherence for AWS EFS and SMB CSI driver operator [#587](https://github.com/openshift/csi-operator/pull/587)
* [STOR-2998](https://issues.redhat.com/browse/STOR-2998): Copy the test manifests from the `legacy` dir to a top-level `test` dir [#589](https://github.com/openshift/csi-operator/pull/589)
* [STOR-2997](https://issues.redhat.com/browse/STOR-2997): Auto generate assets for gcp pd csi driver [#585](https://github.com/openshift/csi-operator/pull/585)
* [OCPBUGS-99199](https://issues.redhat.com/browse/OCPBUGS-99199): Add networking.k8s.io group policy [#579](https://github.com/openshift/csi-operator/pull/579)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#582](https://github.com/openshift/csi-operator/pull/582)
* [Full changelog](https://github.com/openshift/csi-operator/compare/50f79e773ab432a91299a06003191a1fc2535746...756f6b8bb00400e3d72437876a820a950c393eb3)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/dc822233cc526b6cc55f20009a4c1b034f245133)
* [OCPBUGS-100043](https://issues.redhat.com/browse/OCPBUGS-100043): Updating aws-karpenter-provider-aws-container image to be consistent with ART for 5.0 [#34](https://github.com/openshift/aws-karpenter-provider-aws/pull/34)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/abcf7d1e34173037a13fc47317f313cb6ac2f667...dc822233cc526b6cc55f20009a4c1b034f245133)
### [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider/tree/9b18930d2db9521a08faa7165488bdcf6482b9cf)
* [CNTRLPLANE-4011](https://issues.redhat.com/browse/CNTRLPLANE-4011): Rebase aws-encryption-provider repo to upstream/master (8c16f8c) for OCP 5.0 [#52](https://github.com/openshift/aws-encryption-provider/pull/52)
* [Full changelog](https://github.com/openshift/aws-encryption-provider/compare/6ca6eea2f3a9d0b090ff63ba5b8e342d5686c9a8...9b18930d2db9521a08faa7165488bdcf6482b9cf)
### [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws/tree/9f2e9b3c46b391c7219257a426ad80ca8a296af0)
* [OCPCLOUD-3615](https://issues.redhat.com/browse/OCPCLOUD-3615): Bump k8s to 1.36 and Go to 1.26 [#197](https://github.com/openshift/machine-api-provider-aws/pull/197)
* [OCPBUGS-47508](https://issues.redhat.com/browse/OCPBUGS-47508): Add max-concurrent-reconciles flag to machine actuator [#195](https://github.com/openshift/machine-api-provider-aws/pull/195)
* NO-JIRA: Bump golang.org/x/crypto to fix CVE [#194](https://github.com/openshift/machine-api-provider-aws/pull/194)
* [Full changelog](https://github.com/openshift/machine-api-provider-aws/compare/10718580c265686b6af85caab68eed263eee2a41...9f2e9b3c46b391c7219257a426ad80ca8a296af0)
### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/b99e4ce4ff5c2665b273384b0673824833c40ce5)
* [OCPBUGS-100185](https://issues.redhat.com/browse/OCPBUGS-100185): fix: use PATCH when refreshing failed VMs [#201](https://github.com/openshift/cloud-provider-azure/pull/201)
* [OCPCLOUD-3591](https://issues.redhat.com/browse/OCPCLOUD-3591): Merge https://github.com/kubernetes-sigs/cloud-provider-azure:master (4128235) into main [#164](https://github.com/openshift/cloud-provider-azure/pull/164)
* [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/d04449b95a54a9f41669d701ed63153575cced1e...b99e4ce4ff5c2665b273384b0673824833c40ce5)
### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/ebcd88eeaeb1a3ef5e961792eb6d8991a25a1ce8)
* [OCPBUGS-96820](https://issues.redhat.com/browse/OCPBUGS-96820): Bump golang.org/x/net from v0.52.0 to v0.55.0 [#156](https://github.com/openshift/azure-disk-csi-driver/pull/156)
* [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/e87f776402d402a3e291e24fa737fe4e5e9617aa...ebcd88eeaeb1a3ef5e961792eb6d8991a25a1ce8)
### [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver/tree/9689f03011ce700b3bffc32791af839e80d0e0ab)
* [STOR-2928](https://issues.redhat.com/browse/STOR-2928): Rebase to v1.35.5 for OCP 5.0 [#143](https://github.com/openshift/azure-file-csi-driver/pull/143)
* [Full changelog](https://github.com/openshift/azure-file-csi-driver/compare/f7724fbf3ad694f957bd99fafa2fa7b658462624...9689f03011ce700b3bffc32791af839e80d0e0ab)
### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/4ff6c6b8730c1253918f1f5261b9c12cab2e5903)
* [OCPCLOUD-3616](https://issues.redhat.com/browse/OCPCLOUD-3616): Bump k8s to 1.36 and Go to 1.26 [#206](https://github.com/openshift/machine-api-provider-azure/pull/206)
* [OCPBUGS-92024](https://issues.redhat.com/browse/OCPBUGS-92024), [OCPBUGS-98075](https://issues.redhat.com/browse/OCPBUGS-98075): bump golang.org/x/crypto to v0.54.0 to fix CVEs [#203](https://github.com/openshift/machine-api-provider-azure/pull/203)
* [OCPBUGS-96854](https://issues.redhat.com/browse/OCPBUGS-96854): bump golang.org/x/net to v0.55.0 [#204](https://github.com/openshift/machine-api-provider-azure/pull/204)
* [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/bb01d0dfee4abfe7274ff96cba280ad81ad99936...4ff6c6b8730c1253918f1f5261b9c12cab2e5903)
### [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3/tree/ad4f1c2bd7b527437496b71b5b93ee1439243d65)
* [OCPBUGS-98546](https://issues.redhat.com/browse/OCPBUGS-98546): Remove dangling symlink [#87](https://github.com/openshift/cluster-api-provider-metal3/pull/87)
* [Full changelog](https://github.com/openshift/cluster-api-provider-metal3/compare/0afcbf370086fe550560784f9cbf7182a9e8b72e...ad4f1c2bd7b527437496b71b5b93ee1439243d65)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/1b579f10fb2c89d061112a15c178a1f9e7cfad63)
* no-jira: vendor: update o/api to the latest after several Feature promotions to default [#10746](https://github.com/openshift/installer/pull/10746)
* [OCPBUGS-101695](https://issues.redhat.com/browse/OCPBUGS-101695): bump golang.org/x/net to v0.56.0 [#10749](https://github.com/openshift/installer/pull/10749)
* [OCPBUGS-85296](https://issues.redhat.com/browse/OCPBUGS-85296): export Azure Metadata.Region for state file serialization [#10736](https://github.com/openshift/installer/pull/10736)
* [CORS-4406](https://issues.redhat.com/browse/CORS-4406): CORS-4407: CORS-4408: CORS-4410: CORS-4411: CORS-4413: Installer use customer managed kms keys to encrypt S3 for Ignition and Internal Registry [#10553](https://github.com/openshift/installer/pull/10553)
* [OCPBUGS-100189](https://issues.redhat.com/browse/OCPBUGS-100189): Patch GCP Load Balancer Health Checks [#10731](https://github.com/openshift/installer/pull/10731)
* [OCPBUGS-98700](https://issues.redhat.com/browse/OCPBUGS-98700): Azure: delete bootstrap ignition storage during bootstrap destroy [#10701](https://github.com/openshift/installer/pull/10701)
* [OCPBUGS-78995](https://issues.redhat.com/browse/OCPBUGS-78995): Azure Machines: Accept explicit image ID [#10712](https://github.com/openshift/installer/pull/10712)
* [OCPBUGS-104455](https://issues.redhat.com/browse/OCPBUGS-104455): Add a 10sec restart interval for ICC service, so that there is enough time for CRDs to become available [#10739](https://github.com/openshift/installer/pull/10739)
* no-jira: Update hack scripts to set min go version to 1.26 [#10738](https://github.com/openshift/installer/pull/10738)
* [CORS-4516](https://issues.redhat.com/browse/CORS-4516): GCP: Configure cloud provider to use mounted creds [#10733](https://github.com/openshift/installer/pull/10733)
* [OCPBUGS-98102](https://issues.redhat.com/browse/OCPBUGS-98102): Add validations Azure Dualstack [#10677](https://github.com/openshift/installer/pull/10677)
* [CORS-4537](https://issues.redhat.com/browse/CORS-4537): GCP: gracefully handle 503 in disk type check [#10732](https://github.com/openshift/installer/pull/10732)
* [CORS-3898](https://issues.redhat.com/browse/CORS-3898): azure: Fix the dualstack errors [#10656](https://github.com/openshift/installer/pull/10656)
* [OCPEDGE-2788](https://issues.redhat.com/browse/OCPEDGE-2788): agent: split fencing credentials placement by identification key [#10684](https://github.com/openshift/installer/pull/10684)
* [OCPBUGS-99164](https://issues.redhat.com/browse/OCPBUGS-99164): bootstrap: replace envsubst with sed in konnectivity.sh [#10728](https://github.com/openshift/installer/pull/10728)
* [CORS-4542](https://issues.redhat.com/browse/CORS-4542): restrict ClusterAPI machine management to only supported platforms [#10717](https://github.com/openshift/installer/pull/10717)
* [CORS-4425](https://issues.redhat.com/browse/CORS-4425): gcp: add OS image validation for sovereign clouds [#10709](https://github.com/openshift/installer/pull/10709)
* [CNTRLPLANE-2012](https://issues.redhat.com/browse/CNTRLPLANE-2012): Wire signer certs to read PKI config via SignerKeyParams [#10595](https://github.com/openshift/installer/pull/10595)
* [OCPBUGS-63133](https://issues.redhat.com/browse/OCPBUGS-63133): PowerVS: Error out if VPC does not exist [#10137](https://github.com/openshift/installer/pull/10137)
* [OCPBUGS-98696](https://issues.redhat.com/browse/OCPBUGS-98696): baremetal: fix provisioning ISO kernel arguments [#10702](https://github.com/openshift/installer/pull/10702)
* no-jira: bump k8s packages to v0.36 [#10713](https://github.com/openshift/installer/pull/10713)
* [CORS-4428](https://issues.redhat.com/browse/CORS-4428): gcp: reject PSC endpoint overrides for sovereign clouds [#10708](https://github.com/openshift/installer/pull/10708)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/installer/compare/d8f6a96a1c18ee540099ff73789fde54cc9b12cd...1b579f10fb2c89d061112a15c178a1f9e7cfad63)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/34bbeb376836bf01793d4e70d29065d619ebcaa1)
* NO-ISSUE: Merge upstream 2026-07-30 [#516](https://github.com/openshift/baremetal-operator/pull/516)
* NO-ISSUE: Merge upstream 2026-07-25 [#513](https://github.com/openshift/baremetal-operator/pull/513)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/775d84f5afecf432c7a0330bfaadd669b4a68ab0...34bbeb376836bf01793d4e70d29065d619ebcaa1)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/d436a450e4b65cfba1547d1dddb376bbceca82f3)
* NO-JIRA: Fix issues collection when CVO handles the risks [#2352](https://github.com/openshift/oc/pull/2352)
* [OCPBUGS-99013](https://issues.redhat.com/browse/OCPBUGS-99013): inspect: Redact OAuthClient secrets [#2354](https://github.com/openshift/oc/pull/2354)
* [OTA-1959](https://issues.redhat.com/browse/OTA-1959): Case 1 - `oc adm upgrade recommend` shows both Cincinnati-sourced and alert-sourced risks in output [#2349](https://github.com/openshift/oc/pull/2349)
* NO-JIRA: Update docs.openshift.com base URL to point to OCP docs [#2353](https://github.com/openshift/oc/pull/2353)
* [OCPBUGS-101781](https://issues.redhat.com/browse/OCPBUGS-101781): Isolate OCP-42982 kubeconfig writes [#2337](https://github.com/openshift/oc/pull/2337)
* [OTA-1814](https://issues.redhat.com/browse/OTA-1814): Handle accept risks with different commands [#2336](https://github.com/openshift/oc/pull/2336)
* [OCPBUGS-100310](https://issues.redhat.com/browse/OCPBUGS-100310): oc login --exec-plugin oc-oidc fails to refresh expired token against Microsoft Entra ID [#2332](https://github.com/openshift/oc/pull/2332)
* Revert "TRT-2817: Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning"" [#2322](https://github.com/openshift/oc/pull/2322)
* [OCPBUGS-99757](https://issues.redhat.com/browse/OCPBUGS-99757): Include extra scopes in OIDC token cache key [#2323](https://github.com/openshift/oc/pull/2323)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/oc/compare/a88e785e90aa96ac96da93359bacf3ea5c174733...d436a450e4b65cfba1547d1dddb376bbceca82f3)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/f323f9eb76e4031934c47f2623781f1f15cd5c9e)
* [CCO-837](https://issues.redhat.com/browse/CCO-837): Replace deprecated golang/mock with go.uber.org/mock [#1069](https://github.com/openshift/cloud-credential-operator/pull/1069)
* NO-ISSUE: Add patrickdillon to OWNERS [#1071](https://github.com/openshift/cloud-credential-operator/pull/1071)
* [CCO-834](https://issues.redhat.com/browse/CCO-834), [CCO-835](https://issues.redhat.com/browse/CCO-835), [CCO-836](https://issues.redhat.com/browse/CCO-836): Upgrade to Kubernetes 1.36 with CI and e2e tests [#1066](https://github.com/openshift/cloud-credential-operator/pull/1066)
* [CORS-4524](https://issues.redhat.com/browse/CORS-4524): Enable GCP custom universe domain support for CCO [#1068](https://github.com/openshift/cloud-credential-operator/pull/1068)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/672b790022dbea667460b1a0467b6a0bc39c544b...f323f9eb76e4031934c47f2623781f1f15cd5c9e)
### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/dada7547e3d89f301be73b27063ac91f2acb9088)
* [CORS-4523](https://issues.redhat.com/browse/CORS-4523): support GCP custom universe domain [#249](https://github.com/openshift/cloud-network-config-controller/pull/249)
* NO-JIRA: Update OWNERS file [#229](https://github.com/openshift/cloud-network-config-controller/pull/229)
* [CORENET-7047](https://issues.redhat.com/browse/CORENET-7047): CNCC K8s rebase to 1.36.2 [#223](https://github.com/openshift/cloud-network-config-controller/pull/223)
* [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/0b49df2bc4b10110463f1aa2a5fc475ebaeef9ab...dada7547e3d89f301be73b27063ac91f2acb9088)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/f3df4f5b26043e7c0f2bc724cd3cbc0a2a6d14f7)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Watch openshift-config ConfigMaps in OAuth route health check controller [#964](https://github.com/openshift/cluster-authentication-operator/pull/964)
* NO-JIRA: bump library-go api and client-go [#963](https://github.com/openshift/cluster-authentication-operator/pull/963)
* NO-JIRA: Bump library-go [#962](https://github.com/openshift/cluster-authentication-operator/pull/962)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Include system cert pool in proxy resolver transport [#961](https://github.com/openshift/cluster-authentication-operator/pull/961)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Clear IdP validation hash when all identity providers are removed [#960](https://github.com/openshift/cluster-authentication-operator/pull/960)
* NO-JIRA: Update openshift/* [#959](https://github.com/openshift/cluster-authentication-operator/pull/959)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Add support for component-scoped proxy [#946](https://github.com/openshift/cluster-authentication-operator/pull/946)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client- #741 [#958](https://github.com/openshift/cluster-authentication-operator/pull/958)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#956](https://github.com/openshift/cluster-authentication-operator/pull/956)
* [CNTRLPLANE-3375](https://issues.redhat.com/browse/CNTRLPLANE-3375): bugfix: make switched controller clear status conditions on delegate controller shutdown [#955](https://github.com/openshift/cluster-authentication-operator/pull/955)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/482d82f81fc7b460eb3f4024c7fcb4c4a841aecd...f3df4f5b26043e7c0f2bc724cd3cbc0a2a6d14f7)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/f393f54229e6c3ae74c35ae72012af92d31c03d3)
* [OCPBUGS-99660](https://issues.redhat.com/browse/OCPBUGS-99660): Fix VPA checkpoint overwrite bug [#433](https://github.com/openshift/kubernetes-autoscaler/pull/433)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/70920d3c6f5ff55d0eb72368767a81aea1a62abb...f393f54229e6c3ae74c35ae72012af92d31c03d3)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/e48fe1179ad671757b5a40688e2d125c1f326e8b)
* NO-JIRA: Add /release-chores chore cycle skill [#382](https://github.com/openshift/cluster-autoscaler-operator/pull/382)
* [OCPBUGS-100034](https://issues.redhat.com/browse/OCPBUGS-100034): Dump kube RBAC proxy and do metrics endpoint authn & authz in process [#381](https://github.com/openshift/cluster-autoscaler-operator/pull/381)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/4eba1788615dcaf77498d063f51812d5d4b2281a...e48fe1179ad671757b5a40688e2d125c1f326e8b)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/4ecb36c02378147632acde2fa91aea1d9efc229b)
* [OCPBUGS-86888](https://issues.redhat.com/browse/OCPBUGS-86888): Mount IDMS mirror config into machine-os-images init container [#636](https://github.com/openshift/cluster-baremetal-operator/pull/636)
* [OCPBUGS-100033](https://issues.redhat.com/browse/OCPBUGS-100033): Migrate metrics from kube-rbac-proxy sidecar to controller-runtime's SecureServing [#638](https://github.com/openshift/cluster-baremetal-operator/pull/638)
* [OCPBUGS-66101](https://issues.redhat.com/browse/OCPBUGS-66101): set Progressing=True during cluster update [#599](https://github.com/openshift/cluster-baremetal-operator/pull/599)
* [OCPQE-32094](https://issues.redhat.com/browse/OCPQE-32094): Address review feedback from PR #622 [#637](https://github.com/openshift/cluster-baremetal-operator/pull/637)
* [METAL-1922](https://issues.redhat.com/browse/METAL-1922): Bump BMO to latest downstream main branch, update the supported TLS groups for BMO [#639](https://github.com/openshift/cluster-baremetal-operator/pull/639)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add host_fw_components tests to CBO test extension [#622](https://github.com/openshift/cluster-baremetal-operator/pull/622)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/fd483524f88dd685d663aa46b21803b7a24c5c69...4ecb36c02378147632acde2fa91aea1d9efc229b)
### [cluster-capi-controllers](https://github.com/openshift/cluster-api/tree/8e2d2bddb8f3f17b80d0461cf8eeebc8d833c38b)
* [OCPCLOUD-3434](https://issues.redhat.com/browse/OCPCLOUD-3434), [OCPCLOUD-3556](https://issues.redhat.com/browse/OCPCLOUD-3556): Exclude unsupported CAPI CRDs and scope ClusterRole [#304](https://github.com/openshift/cluster-api/pull/304)
* [Full changelog](https://github.com/openshift/cluster-api/compare/16b6909b3c73d84fe1fbda0d12f9be80aaae00db...8e2d2bddb8f3f17b80d0461cf8eeebc8d833c38b)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/9e2ecb9f5e026953d98980aabd3b0926ac50b261)
* [OCPCLOUD-3647](https://issues.redhat.com/browse/OCPCLOUD-3647): Consolidate install-time object processing in toBoxcutterRevision [#633](https://github.com/openshift/cluster-capi-operator/pull/633)
* NO-JIRA: resolve placeholder version for k8s.io/autoscaler APIs [#642](https://github.com/openshift/cluster-capi-operator/pull/642)
* [OCPBUGS-100143](https://issues.redhat.com/browse/OCPBUGS-100143): e2e: skip CRD Compatibility Checker tests on External topology clusters [#638](https://github.com/openshift/cluster-capi-operator/pull/638)
* NO-JIRA: go.mod: pin k8s.io/cri-streaming to v0.36.2 [#639](https://github.com/openshift/cluster-capi-operator/pull/639)
* [OCPBUGS-100246](https://issues.redhat.com/browse/OCPBUGS-100246): Fix e2es on CAPI-native clusters [#641](https://github.com/openshift/cluster-capi-operator/pull/641)
* [OCPCLOUD-3571](https://issues.redhat.com/browse/OCPCLOUD-3571): Add OTE e2e tests for ClusterAPIMachineManagementAWS feature gate [#613](https://github.com/openshift/cluster-capi-operator/pull/613)
* [OCPCLOUD-3538](https://issues.redhat.com/browse/OCPCLOUD-3538), [OCPCLOUD-3556](https://issues.redhat.com/browse/OCPCLOUD-3556): manifests-gen: enable KRM plugins and add exclude/rename-resources transformers [#621](https://github.com/openshift/cluster-capi-operator/pull/621)
* [OCPBUGS-84321](https://issues.redhat.com/browse/OCPBUGS-84321): ClusterAPIMachineManagement: capi-controllers: excessive restarts of during cluster installation [#614](https://github.com/openshift/cluster-capi-operator/pull/614)
* [OCPCLOUD-3507](https://issues.redhat.com/browse/OCPCLOUD-3507): Add OTE e2e tests for ClusterAPIMachineManagement feature gate [#606](https://github.com/openshift/cluster-capi-operator/pull/606)
* NO-JIRA: Fix buildComponentList godoc [#632](https://github.com/openshift/cluster-capi-operator/pull/632)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/5767be9caecedf9dbbd2bdfd04633514b34b408f...9e2ecb9f5e026953d98980aabd3b0926ac50b261)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/bc52198c1c3c61099ba3cd20bf5fca80ed7754e7)
* [CORS-4516](https://issues.redhat.com/browse/CORS-4516): GCP: Update Required Permissions [#493](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/493)
* [OCPCLOUD-3610](https://issues.redhat.com/browse/OCPCLOUD-3610): Update to K8s 1.36.3 dependencies [#496](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/496)
* [OCPBUGS-99755](https://issues.redhat.com/browse/OCPBUGS-99755): OTE: fix AWS endpoint resolution for non-standard partitions [#494](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/494)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/38f5e00cbd0085f6b62b98cd9ed044f54c89ad07...bc52198c1c3c61099ba3cd20bf5fca80ed7754e7)
### [cluster-config-api](https://github.com/openshift/api/tree/72ae4424ef350e688068890e69da9ced377ea495)
* [MON-4625](https://issues.redhat.com/browse/MON-4625): add support for the nvmesubsystem collector [#2960](https://github.com/openshift/api/pull/2960)
* Promote IrreconcilableMachineConfig to GA [#2929](https://github.com/openshift/api/pull/2929)
* [NE-2777](https://issues.redhat.com/browse/NE-2777), [NE-2778](https://issues.redhat.com/browse/NE-2778): Implement Gateway API management knob [#2890](https://github.com/openshift/api/pull/2890)
* Use regex instead of format help for KMS secret name validation [#2966](https://github.com/openshift/api/pull/2966)
* [OCPBUGS-74511](https://issues.redhat.com/browse/OCPBUGS-74511): Remove RouteExternalCertificate feature gate [#2962](https://github.com/openshift/api/pull/2962)
* [MON-4607](https://issues.redhat.com/browse/MON-4607): add zoneinfo to NodeExporterCollectorConfig CRD types [#2948](https://github.com/openshift/api/pull/2948)
* [AGENT-1493](https://issues.redhat.com/browse/AGENT-1493): Promote NoRegistryClusterInstall Feature to Default [#2859](https://github.com/openshift/api/pull/2859)
* [MON-4620](https://issues.redhat.com/browse/MON-4620): expose remote-write protocol version [#2958](https://github.com/openshift/api/pull/2958)
* [CORS-4417](https://issues.redhat.com/browse/CORS-4417): Add UniverseDomain field to GCPPlatformStatus [#2963](https://github.com/openshift/api/pull/2963)
* [OCPNODE-4622](https://issues.redhat.com/browse/OCPNODE-4622): Promote CRIOCredentialProviderConfig feature gate Default [#2844](https://github.com/openshift/api/pull/2844)
* [NE-2823](https://issues.redhat.com/browse/NE-2823): Promote Multi HAProxy Versions feature to default [#2947](https://github.com/openshift/api/pull/2947)
* [MON-4616](https://issues.redhat.com/browse/MON-4616): add support for dmmultipath collector [#2956](https://github.com/openshift/api/pull/2956)
* [CORS-4387](https://issues.redhat.com/browse/CORS-4387): Promote AWS DualStack to Default [#2797](https://github.com/openshift/api/pull/2797)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): Kms plugin health report clean up [#2931](https://github.com/openshift/api/pull/2931)
* [OPRUN-4705](https://issues.redhat.com/browse/OPRUN-4705): Remove NewOLMPreflightPermissionChecks FeatureGate [#2957](https://github.com/openshift/api/pull/2957)
* [SPLAT-2827](https://issues.redhat.com/browse/SPLAT-2827): Added vSphere failure domain to vcenter check [#2932](https://github.com/openshift/api/pull/2932)
* [Full changelog](https://github.com/openshift/api/compare/9bcaa16cb258e544dd76b78ff2dc3f89af840f76...72ae4424ef350e688068890e69da9ced377ea495)
### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/9f787f73f5fffca5cd511ef2c2e704afc14f68ce)
* [OCPBUGS-104562](https://issues.redhat.com/browse/OCPBUGS-104562): Mark kube-cloud-config recreation test disruptive [#497](https://github.com/openshift/cluster-config-operator/pull/497)
* [MON-4499](https://issues.redhat.com/browse/MON-4499): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#468](https://github.com/openshift/cluster-config-operator/pull/468)
* [Full changelog](https://github.com/openshift/cluster-config-operator/compare/a02c879931c6108326c0a514df0ce2e390f3536c...9f787f73f5fffca5cd511ef2c2e704afc14f68ce)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/0a98fb46580fa472b86e1aeaa96821e0db51b741)
* NO-JIRA: Fix flaky unit-test harness races and tight timeouts [#416](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/416)
* [OCPCLOUD-3611](https://issues.redhat.com/browse/OCPCLOUD-3611): Bump Kubernetes dependencies to 1.36 [#414](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/414)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/452cee8c1f4efb683fb6bcb15b61366695d98e1e...0a98fb46580fa472b86e1aeaa96821e0db51b741)
### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/35ec0224eb0e5219d5eae012fb703223a6f3e1f7)
* [STOR-3005](https://issues.redhat.com/browse/STOR-3005): Remove v1beta2 group snapshot API [#283](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/283)
* [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/67648d56d6b312e661714f8e7bf0e9be1d532c1c...35ec0224eb0e5219d5eae012fb703223a6f3e1f7)
### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/c0ed09e329e9001629518604a58205e3fbe8284a)
* [OCPBUGS-86009](https://issues.redhat.com/browse/OCPBUGS-86009): Fix dns operator reporting Progressing=True on scale up [#477](https://github.com/openshift/cluster-dns-operator/pull/477)
* [NE-2817](https://issues.redhat.com/browse/NE-2817): Gate operator metrics TLS on tlsAdherence via ShouldHonorClusterTLSProfile [#484](https://github.com/openshift/cluster-dns-operator/pull/484)
* [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/4b8ae49940eefc50fa48da5179e735dd6ccd42d9...c0ed09e329e9001629518604a58205e3fbe8284a)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/2f256f2638e892af38c274c62131565ec8df6dff)
* [CNTRLPLANE-3403](https://issues.redhat.com/browse/CNTRLPLANE-3403): reduce default snapshot-count to 5000 [#1666](https://github.com/openshift/cluster-etcd-operator/pull/1666)
* [OCPBUGS-84695](https://issues.redhat.com/browse/OCPBUGS-84695): feat(tnf): TNF job controller framework and lifecycle management [#1655](https://github.com/openshift/cluster-etcd-operator/pull/1655)
* NO-JIRA: add ceo disruptive suite to sippy's disruptive [#1667](https://github.com/openshift/cluster-etcd-operator/pull/1667)
* [OCPBUGS-100294](https://issues.redhat.com/browse/OCPBUGS-100294): fix TNFNodeInMaintenance PromQL label mismatch [#1664](https://github.com/openshift/cluster-etcd-operator/pull/1664)
* [OCPBUGS-94106](https://issues.redhat.com/browse/OCPBUGS-94106): Add APIServer informer to EnvVarController cache sync [#1659](https://github.com/openshift/cluster-etcd-operator/pull/1659)
* [OCPBUGS-100072](https://issues.redhat.com/browse/OCPBUGS-100072): Revert 'OCPBUGS-88490: fix etcd operator deadlock when etcd-endpoints configmap is stale' [#1660](https://github.com/openshift/cluster-etcd-operator/pull/1660)
* [OCPEDGE-2094](https://issues.redhat.com/browse/OCPEDGE-2094): Add console notifications for pacemaker health events [#1654](https://github.com/openshift/cluster-etcd-operator/pull/1654)
* [CNTRLPLANE-3609](https://issues.redhat.com/browse/CNTRLPLANE-3609): update TestEtcdDBScaling to also include the validation check for BackendQuotaGiB [#1656](https://github.com/openshift/cluster-etcd-operator/pull/1656)
* [OCPEDGE-2118](https://issues.redhat.com/browse/OCPEDGE-2118): Record Kubernetes events for etcd transition lifecycle [#1653](https://github.com/openshift/cluster-etcd-operator/pull/1653)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/ebea15aeb57ecaca4ff8e8fdf5aa28d5a4469d12...2f256f2638e892af38c274c62131565ec8df6dff)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/94cd22d000c8b8eef24dd43cd05d06544df24930)
* [CORS-4520](https://issues.redhat.com/browse/CORS-4520): GCP Universe Domain Support [#1356](https://github.com/openshift/cluster-image-registry-operator/pull/1356)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/02bb5c2cd4d5f4d277cf987d6f65e58a732aefee...94cd22d000c8b8eef24dd43cd05d06544df24930)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/acca9642a81370bc1a587155f7e1e7998b7c5489)
* [OCPBUGS-99921](https://issues.redhat.com/browse/OCPBUGS-99921): Annotate GatewayClass when istiod is available to fix startup race [#1540](https://github.com/openshift/cluster-ingress-operator/pull/1540)
* [OCPBUGS-100424](https://issues.redhat.com/browse/OCPBUGS-100424), [OCPBUGS-104205](https://issues.redhat.com/browse/OCPBUGS-104205): Harden DNS duplicate-domain ownership checks [#1543](https://github.com/openshift/cluster-ingress-operator/pull/1543)
* [OCPBUGS-99920](https://issues.redhat.com/browse/OCPBUGS-99920): Vendor sail-operator from OSSM release-3.4.1 [#1527](https://github.com/openshift/cluster-ingress-operator/pull/1527)
* [OCPBUGS-100435](https://issues.redhat.com/browse/OCPBUGS-100435): Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways [#1539](https://github.com/openshift/cluster-ingress-operator/pull/1539)
* [TRT-2874](https://issues.redhat.com/browse/TRT-2874): Revert #1513 "NE-2836: Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways" [#1537](https://github.com/openshift/cluster-ingress-operator/pull/1537)
* [NE-2833](https://issues.redhat.com/browse/NE-2833): Replace deprecated io/ioutil usage [#1531](https://github.com/openshift/cluster-ingress-operator/pull/1531)
* [NE-2823](https://issues.redhat.com/browse/NE-2823): Bump API to promote Multi HAProxy Versions feature [#1535](https://github.com/openshift/cluster-ingress-operator/pull/1535)
* [OCPBUGS-85680](https://issues.redhat.com/browse/OCPBUGS-85680): Re-fetch infraConfig on every periodic loop iteration [#1458](https://github.com/openshift/cluster-ingress-operator/pull/1458)
* [OCPBUGS-31521](https://issues.redhat.com/browse/OCPBUGS-31521): Don't publish duplicate DNS records [#1229](https://github.com/openshift/cluster-ingress-operator/pull/1229)
* [NE-2836](https://issues.redhat.com/browse/NE-2836): Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways [#1513](https://github.com/openshift/cluster-ingress-operator/pull/1513)
* [OCPBUGS-63219](https://issues.redhat.com/browse/OCPBUGS-63219): Support NLB protocol to configure proxy protocol and client IP preservation [#1426](https://github.com/openshift/cluster-ingress-operator/pull/1426)
* [OCPBUGS-100186](https://issues.redhat.com/browse/OCPBUGS-100186): Rename network policy in TestContainerLoggingMinLength [#1532](https://github.com/openshift/cluster-ingress-operator/pull/1532)
* [NE-2585](https://issues.redhat.com/browse/NE-2585): Bump GWAPI to v1.5.1 and Istio v1.30.1 [#1530](https://github.com/openshift/cluster-ingress-operator/pull/1530)
* [NE-2796](https://issues.redhat.com/browse/NE-2796): Respect OpenShift TLS Profiles during Istio/GatewayAPI installation [#1480](https://github.com/openshift/cluster-ingress-operator/pull/1480)
* [NE-2742](https://issues.redhat.com/browse/NE-2742): Apply cluster TLS security profile to operator metrics and canary endpoints [#1501](https://github.com/openshift/cluster-ingress-operator/pull/1501)
* [OCPBUGS-86841](https://issues.redhat.com/browse/OCPBUGS-86841): Add BackendTLSPolicy to Gateway API e2e CRD test coverage [#1523](https://github.com/openshift/cluster-ingress-operator/pull/1523)
* [CORS-4451](https://issues.redhat.com/browse/CORS-4451): GCP: Set Universe Domain [#1515](https://github.com/openshift/cluster-ingress-operator/pull/1515)
* [NE-2809](https://issues.redhat.com/browse/NE-2809): Add upgradeable logic for HAProxy version [#1517](https://github.com/openshift/cluster-ingress-operator/pull/1517)
* [OCPBUGS-99775](https://issues.redhat.com/browse/OCPBUGS-99775): Update TestHTTPHeaderBufferSize for HAProxy 3.2 response code change [#1524](https://github.com/openshift/cluster-ingress-operator/pull/1524)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/d7aafd957d1c126f5241ab716ad55ad0d160c042...acca9642a81370bc1a587155f7e1e7998b7c5489)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/238179f3e2a5a2daa639fa0260972e787dca7661)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms key controller preflight support [#2252](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2252)
* NO-JIRA: bump library-go api and client-go [#2257](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2257)
* NO-JIRA: Add parallelism KMS OnOff Scenarios [#2251](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2251)
* NO-JIRA: Bump library-go [#2255](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2255)
* NO-JIRA: Update openshift/* [#2249](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2249)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client [#2248](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2248)
* [MON-4502](https://issues.redhat.com/browse/MON-4502): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#2036](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2036)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#2246](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2246)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/dab04ebace1a4b36bb40e8f4f87804754b69760b...238179f3e2a5a2daa639fa0260972e787dca7661)
### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/cdf27353008200166f1ad754c4ade033370077ae)
* [OCPBUGS-100160](https://issues.redhat.com/browse/OCPBUGS-100160): Fix status controller unit-test teardown race [#312](https://github.com/openshift/cluster-machine-approver/pull/312)
* NO-JIRA: Bump envtest to 1.36.2 [#314](https://github.com/openshift/cluster-machine-approver/pull/314)
* [OCPCLOUD-3612](https://issues.redhat.com/browse/OCPCLOUD-3612): Bump k8s v1.36, go 1.26 [#311](https://github.com/openshift/cluster-machine-approver/pull/311)
* [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/1ae3f157b88c167a7dbe06c36d6e55a82f7fd4f0...cdf27353008200166f1ad754c4ade033370077ae)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/c68fc0aba966f39fcd91e725017811b7fee08f5b)
* [MON-4637](https://issues.redhat.com/browse/MON-4637): implement merge logic to support the new MessageVersion field in the config CRD [#3036](https://github.com/openshift/cluster-monitoring-operator/pull/3036)
* NO-JIRA: Add test descriptions [#3037](https://github.com/openshift/cluster-monitoring-operator/pull/3037)
* [MON-4577](https://issues.redhat.com/browse/MON-4577): restrict alertmanager gossip mesh ports to same-instance pods [#3032](https://github.com/openshift/cluster-monitoring-operator/pull/3032)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3035](https://github.com/openshift/cluster-monitoring-operator/pull/3035)
* NO-JIRA: Allow to pass custom arguments to e2e test command [#3033](https://github.com/openshift/cluster-monitoring-operator/pull/3033)
* NO-JIRA: tasks: pass context to MetricsServerTask methods instead of storing it [#3025](https://github.com/openshift/cluster-monitoring-operator/pull/3025)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3017](https://github.com/openshift/cluster-monitoring-operator/pull/3017)
* NO-JIRA: chore: update Prometheus-operator to v0.93.0 [#3010](https://github.com/openshift/cluster-monitoring-operator/pull/3010)
* [MON-4630](https://issues.redhat.com/browse/MON-4630): support the dmmultipath collector in the config CRD [#3015](https://github.com/openshift/cluster-monitoring-operator/pull/3015)
* : OCPBUGS-91735: fix: watch cluster wide proxy changes and apply changes accordingly [#3004](https://github.com/openshift/cluster-monitoring-operator/pull/3004)
* NO-JIRA: test: make TestDocExamples and TestNetworkPolicy more stable [#3013](https://github.com/openshift/cluster-monitoring-operator/pull/3013)
* NO-JIRA: add metrics for the validating webhook [#2838](https://github.com/openshift/cluster-monitoring-operator/pull/2838)
* NO-JIRA: e2e: defer subtest resource cleanup in TestPrometheusRemoteWrite [#3016](https://github.com/openshift/cluster-monitoring-operator/pull/3016)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3014](https://github.com/openshift/cluster-monitoring-operator/pull/3014)
* NO-JIRA: chore: pin GOTOOLCHAIN in update-go-deps + update Go dependencies [#3006](https://github.com/openshift/cluster-monitoring-operator/pull/3006)
* NO-JIRA: increase golangci-lint timeout [#3011](https://github.com/openshift/cluster-monitoring-operator/pull/3011)
* [MON-4624](https://issues.redhat.com/browse/MON-4624): enable the nvmesubsystem collector by default [#3005](https://github.com/openshift/cluster-monitoring-operator/pull/3005)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#2994](https://github.com/openshift/cluster-monitoring-operator/pull/2994)
* [MON-4413](https://issues.redhat.com/browse/MON-4413): support MessageVersion v2.0 for remote-write [#2977](https://github.com/openshift/cluster-monitoring-operator/pull/2977)
* [OCPBUGS-85522](https://issues.redhat.com/browse/OCPBUGS-85522): disable kubelet Endpoints in prometheus-operator [#2931](https://github.com/openshift/cluster-monitoring-operator/pull/2931)
* NO-JIRA: test: adjust e2e tests on retention settings [#2999](https://github.com/openshift/cluster-monitoring-operator/pull/2999)
* [MON-4615](https://issues.redhat.com/browse/MON-4615): add option to disable the dmmultipath collector [#2996](https://github.com/openshift/cluster-monitoring-operator/pull/2996)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/5042b52541130c3856028e29c7142d477c3f7d7d...c68fc0aba966f39fcd91e725017811b7fee08f5b)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/a0ebeb0c4d6d5baa353f1e123553dfecf7092eda)
* [OCPBUGS-98918](https://issues.redhat.com/browse/OCPBUGS-98918): Use service-ca certificates for network-check-source metrics [#3097](https://github.com/openshift/cluster-network-operator/pull/3097)
* [OCPBUGS-99460](https://issues.redhat.com/browse/OCPBUGS-99460): Fix connectivity check for nodes named with IP address [#3083](https://github.com/openshift/cluster-network-operator/pull/3083)
* [CORENET-5658](https://issues.redhat.com/browse/CORENET-5658): Bump ovn-controller CPU request to 50m to prevent CPU starvation [#3051](https://github.com/openshift/cluster-network-operator/pull/3051)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Enable Network Observability on Day 0 [#3087](https://github.com/openshift/cluster-network-operator/pull/3087)
* [CORENET-7054](https://issues.redhat.com/browse/CORENET-7054): Use TLS profile to render CLI args for deployed components [#3043](https://github.com/openshift/cluster-network-operator/pull/3043)
* [CORENET-5972](https://issues.redhat.com/browse/CORENET-5972): Consume openvswitch-ipsec systemd service for OVN IPsec deployment [#2662](https://github.com/openshift/cluster-network-operator/pull/2662)
* NO-JIRA: vendor: bump github.com/openshift/api to latest master [#3089](https://github.com/openshift/cluster-network-operator/pull/3089)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/00e6cc59b92af5c8f73f9c3908ed3b0ef591bf63...a0ebeb0c4d6d5baa353f1e123553dfecf7092eda)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/837ae9f6da1c7a5ff24718c8210047571a3909a3)
* [OCPBUGS-99461](https://issues.redhat.com/browse/OCPBUGS-99461): Add missing annotations to NetworkPolicy manifests [#1569](https://github.com/openshift/cluster-node-tuning-operator/pull/1569)
* [MON-4506](https://issues.redhat.com/browse/MON-4506): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#1468](https://github.com/openshift/cluster-node-tuning-operator/pull/1468)
* [OCPBUGS-100115](https://issues.redhat.com/browse/OCPBUGS-100115): E2E: LLC: Restore uncore cache annotation to true [#1570](https://github.com/openshift/cluster-node-tuning-operator/pull/1570)
* NO-JIRA: owners: update [#1563](https://github.com/openshift/cluster-node-tuning-operator/pull/1563)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/a9d25d502ca894272f88753f1bd7ecef82fb188e...837ae9f6da1c7a5ff24718c8210047571a3909a3)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/228ec940921e4443b2724ef512c0d211d4a38ba7)
* NO-ISSUE: Add dependabot configuration [#225](https://github.com/openshift/cluster-olm-operator/pull/225)
* [OPRUN-4665](https://issues.redhat.com/browse/OPRUN-4665): Update k8s dependencies from v0.35.1 to v0.36.2 and OpenShift dependencies to latest [#217](https://github.com/openshift/cluster-olm-operator/pull/217)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/9983877dbed43c0ae050ad4646e31b9cfbd41329...228ec940921e4443b2724ef512c0d211d4a38ba7)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/f730b48c7dbd76b3125fa7508c80c6a083d364f8)
* [OCPBUGS-98618](https://issues.redhat.com/browse/OCPBUGS-98618): Add HostToContainer mountPropagation to node-pullsecrets volume mount [#744](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/744)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms key controller preflight support [#747](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/747)
* NO-JIRA: bump library-go api and client-go [#746](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/746)
* Revert "NO-JIRA: Disable WatchList feature gate due to the missing support of Project watch" [#681](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/681)
* NO-JIRA: Bump library-go [#745](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/745)
* NO-JIRA: Update openshift/* [#742](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/742)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client [#741](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/741)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#739](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/739)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/7bac3548875ec36a6c4967df818ccae533dcce7c...f730b48c7dbd76b3125fa7508c80c6a083d364f8)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/bb8d2fd11a18ce59cf84a2982189d9ca2c23599e)
* [OCPBUGS-101758](https://issues.redhat.com/browse/OCPBUGS-101758): Fix SELinuxMountGAReadiness on HyperShift [#721](https://github.com/openshift/cluster-storage-operator/pull/721)
* [STOR-2918](https://issues.redhat.com/browse/STOR-2918): update AWS EBS CSI credentials request policy to mirror upstream [#717](https://github.com/openshift/cluster-storage-operator/pull/717)
* [STOR-3056](https://issues.redhat.com/browse/STOR-3056): inject TLS adherence from API to vsphere problem detector configmap [#718](https://github.com/openshift/cluster-storage-operator/pull/718)
* [OCPBUGS-99492](https://issues.redhat.com/browse/OCPBUGS-99492): NetworkPolicies should use numeric ports instead of named ports [#720](https://github.com/openshift/cluster-storage-operator/pull/720)
* [STOR-3013](https://issues.redhat.com/browse/STOR-3013): Add e2e test for SELinuxMount upgrade readiness [#715](https://github.com/openshift/cluster-storage-operator/pull/715)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#719](https://github.com/openshift/cluster-storage-operator/pull/719)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/8ac48254009fb4987bee1f3e00cbb8e4d730f545...bb8d2fd11a18ce59cf84a2982189d9ca2c23599e)
### [cluster-update-console-plugin](https://github.com/openshift/cluster-update-console-plugin/tree/02b220dd2aef5c1788768178e3ffd8592ccb89b9)
* [OCPBUGS-104520](https://issues.redhat.com/browse/OCPBUGS-104520): Use latest analysis result instead of first [#22](https://github.com/openshift/cluster-update-console-plugin/pull/22)
* [Full changelog](https://github.com/openshift/cluster-update-console-plugin/compare/e222a514a3f1977cdc99bbf41d405729aba2d910...02b220dd2aef5c1788768178e3ffd8592ccb89b9)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/97ee3b743cc3eadf2e53252910a5d54c207c6d49)
* [OCPBUGS-79358](https://issues.redhat.com/browse/OCPBUGS-79358): pkg/cvo/egress: Disable Proxy respect on HyperShift [#1357](https://github.com/openshift/cluster-version-operator/pull/1357)
* NO-JIRA: fix(pkg/cincinnati): log the correct root CA pool size [#1413](https://github.com/openshift/cluster-version-operator/pull/1413)
* [OTA-1997](https://issues.redhat.com/browse/OTA-1997): Allow the CVO to use the agentic-skills payload image when creating proposals [#1433](https://github.com/openshift/cluster-version-operator/pull/1433)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084): Register agenticrunv1alpha1 in the Runtime client scheme [#1434](https://github.com/openshift/cluster-version-operator/pull/1434)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084): pkg/agenticrun/controller: Inline AgenticRun prompt, dropping the ConfigMap [#1432](https://github.com/openshift/cluster-version-operator/pull/1432)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/70bafacd988182acbc5160d61088a6d1ddad785a...97ee3b743cc3eadf2e53252910a5d54c207c6d49)
### [console](https://github.com/openshift/console/tree/1fbc1a87fdfe55253664dce9a37021dbb8c18284)
* [OTA-2035](https://issues.redhat.com/browse/OTA-2035): Address ProdSec findings for OLS Helper Buttons [#16910](https://github.com/openshift/console/pull/16910)
* [CONSOLE-5414](https://issues.redhat.com/browse/CONSOLE-5414): Migrate dev-console Cypress tests to Playwright (batch 2) [#16741](https://github.com/openshift/console/pull/16741)
* [OCPBUGS-105314](https://issues.redhat.com/browse/OCPBUGS-105314): Fix xterm ResizeObserver crash on uninitialized dimensions [#16918](https://github.com/openshift/console/pull/16918)
* [OCPBUGS-105273](https://issues.redhat.com/browse/OCPBUGS-105273): Fix nested interactive controls on Search page [#16914](https://github.com/openshift/console/pull/16914)
* [CONSOLE-5228](https://issues.redhat.com/browse/CONSOLE-5228): re-enable eslint rules and autofix + bump prettier [#16915](https://github.com/openshift/console/pull/16915)
* [OCPBUGS-105318](https://issues.redhat.com/browse/OCPBUGS-105318): Fix node-groups-filter test to use correct page-heading test ID [#16912](https://github.com/openshift/console/pull/16912)
* [OCPBUGS-102342](https://issues.redhat.com/browse/OCPBUGS-102342): Dismiss Quick Start drawer in Playwright e2e tests [#16903](https://github.com/openshift/console/pull/16903)
* [OCPBUGS-90514](https://issues.redhat.com/browse/OCPBUGS-90514): Fix CVE-2026-12143 form-data CRLF injection [#16865](https://github.com/openshift/console/pull/16865)
* NO-JIRA: Prepare for publishing new 4.23 prerelease plugin SDK packages [#16905](https://github.com/openshift/console/pull/16905)
* [CONSOLE-5424](https://issues.redhat.com/browse/CONSOLE-5424): Add minimize action for toast notifications [#16762](https://github.com/openshift/console/pull/16762)
* [CONSOLE-5118](https://issues.redhat.com/browse/CONSOLE-5118): Improve AI assessment prompts [#16880](https://github.com/openshift/console/pull/16880)
* [CONSOLE-5241](https://issues.redhat.com/browse/CONSOLE-5241): Migrate knative-ci.feature Cypress tests to Playwright [#16658](https://github.com/openshift/console/pull/16658)
* [CONSOLE-5065](https://issues.redhat.com/browse/CONSOLE-5065): Bump @openshift/dynamic-plugin-sdk to 9.1.0 [#16897](https://github.com/openshift/console/pull/16897)
* [CONSOLE-5425](https://issues.redhat.com/browse/CONSOLE-5425): Add rspack native bindings for linux/s390x and linux/ppc64le [#16890](https://github.com/openshift/console/pull/16890)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Fix Playwright e2e flakes across multiple test suites [#16881](https://github.com/openshift/console/pull/16881)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Increase Playwright CI retries and abort after 10 failures [#16887](https://github.com/openshift/console/pull/16887)
* [OCPBUGS-99434](https://issues.redhat.com/browse/OCPBUGS-99434): Show toast notification for invalid Helm Chart repositories [#16792](https://github.com/openshift/console/pull/16792)
* [CONSOLE-5417](https://issues.redhat.com/browse/CONSOLE-5417): Migrate dev-console Cypress tests to Playwright (batch 4) [#16767](https://github.com/openshift/console/pull/16767)
* [CONSOLE-5065](https://issues.redhat.com/browse/CONSOLE-5065): Align Console useResolvedExtensions hook with upstream plugin SDK [#16815](https://github.com/openshift/console/pull/16815)
* [OCPBUGS-99491](https://issues.redhat.com/browse/OCPBUGS-99491): Fix Installed Operators table row cells ignoring column management [#16817](https://github.com/openshift/console/pull/16817)
* [CONSOLE-5439](https://issues.redhat.com/browse/CONSOLE-5439): Migrate to eslint 9 [#16878](https://github.com/openshift/console/pull/16878)
* [CONSOLE-5409](https://issues.redhat.com/browse/CONSOLE-5409): Add Playwright e2e test for operator lifecycle metadata UI [#16701](https://github.com/openshift/console/pull/16701)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Replace page.locator with getByTestId in Playwright tests [#16873](https://github.com/openshift/console/pull/16873)
* [OCPBUGS-90080](https://issues.redhat.com/browse/OCPBUGS-90080): Validate chart URL in /api/helm/verify to prevent SSRF [#16786](https://github.com/openshift/console/pull/16786)
* [CONSOLE-5400](https://issues.redhat.com/browse/CONSOLE-5400): Make Node management enhancements flagged by OpenShift 5 [#16797](https://github.com/openshift/console/pull/16797)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Fix Playwright e2e flakes and CI reliability [#16863](https://github.com/openshift/console/pull/16863)
* NO-JIRA: Remove generated plugin manifest JSON schema files [#16875](https://github.com/openshift/console/pull/16875)
* [CONSOLE-5428](https://issues.redhat.com/browse/CONSOLE-5428): i18next-cli migration follow up [#16864](https://github.com/openshift/console/pull/16864)
* [RFE-4925](https://issues.redhat.com/browse/RFE-4925): Fix inconsistent Search page filter default (use Name) [#16601](https://github.com/openshift/console/pull/16601)
* [HELM-763](https://issues.redhat.com/browse/HELM-763): Add secrets for Helm release upgrade [#16787](https://github.com/openshift/console/pull/16787)
* [CONSOLE-5397](https://issues.redhat.com/browse/CONSOLE-5397): Log perspective overrides when starting Bridge [#16838](https://github.com/openshift/console/pull/16838)
* NO-JIRA: Remove plugin sdk build from `yarn dev` [#16850](https://github.com/openshift/console/pull/16850)
* [OCPBUGS-33836](https://issues.redhat.com/browse/OCPBUGS-33836): quickstart page i18n misses (Fix Quick Starts i18n bundle lookup for zh-CN) [#16819](https://github.com/openshift/console/pull/16819)
* [OCPBUGS-99418](https://issues.redhat.com/browse/OCPBUGS-99418): Bump protobufjs to 7.6.5 to fix CVE-2026-59877, CVE-2026-48712, CVE-2026-41242 [#16813](https://github.com/openshift/console/pull/16813)
* [OCPBUGS-84564](https://issues.redhat.com/browse/OCPBUGS-84564): remove block volume mode in case of ocs-storagecluster-ceph-nfs [#16397](https://github.com/openshift/console/pull/16397)
* [OCPBUGS-86280](https://issues.redhat.com/browse/OCPBUGS-86280): Guard against null plugin route components [#16587](https://github.com/openshift/console/pull/16587)
* [CONSOLE-5434](https://issues.redhat.com/browse/CONSOLE-5434): Replace Popper with PF components [#16831](https://github.com/openshift/console/pull/16831)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: inject centralized TLS into console operand [#16804](https://github.com/openshift/console/pull/16804)
* NO-JIRA: Make regular notification icon outlined by default [#16811](https://github.com/openshift/console/pull/16811)
* [OCPBUGS-94168](https://issues.redhat.com/browse/OCPBUGS-94168): Fix CVE-2026-13149 brace-expansion DoS vulnerability [#16812](https://github.com/openshift/console/pull/16812)
* [OCPBUGS-72369](https://issues.redhat.com/browse/OCPBUGS-72369): i18n format missing for Request/limit unit labels on deploy image page [#16805](https://github.com/openshift/console/pull/16805)
* [OCPBUGS-57309](https://issues.redhat.com/browse/OCPBUGS-57309): '0 B' is shown on details page when create pvc with 'EiB' unit [#16800](https://github.com/openshift/console/pull/16800)
* [OCPBUGS-77379](https://issues.redhat.com/browse/OCPBUGS-77379): Incorrect translations for 'CatalogSources' and 'OperatorGroups' in l… [#16801](https://github.com/openshift/console/pull/16801)
* [OCPBUGS-99475](https://issues.redhat.com/browse/OCPBUGS-99475): Fix virtualized table row overlap after react-virtualized 9.22.6 upgrade [#16798](https://github.com/openshift/console/pull/16798)
* [CONSOLE-5428](https://issues.redhat.com/browse/CONSOLE-5428): migrate to `i18next-cli` [#16796](https://github.com/openshift/console/pull/16796)
* NO-JIRA: Move jest config out of package.json [#16799](https://github.com/openshift/console/pull/16799)
* [CONSOLE-5425](https://issues.redhat.com/browse/CONSOLE-5425): Migrate to rspack [#16761](https://github.com/openshift/console/pull/16761)
* And 7 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/6d0dcf1d76337e46d95ea1b546d5ffe692d7918d...1fbc1a87fdfe55253664dce9a37021dbb8c18284)
### [console-operator](https://github.com/openshift/console-operator/tree/684157180b1dfeb4a5106c669da1ac42258372ec)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): Revert "TRT-2858: Revert "Merge pull request #1196 from ingvagabund/tls-injection-to-console"" [#1205](https://github.com/openshift/console-operator/pull/1205)
* [OSDOCS-20110](https://issues.redhat.com/browse/OSDOCS-20110): Add Helm 3 CLI download links alongside Helm 4 [#1197](https://github.com/openshift/console-operator/pull/1197)
* [OCPBUGS-99943](https://issues.redhat.com/browse/OCPBUGS-99943): set API-server-defaulted fields on deployment specs to prevent excessive update events [#1201](https://github.com/openshift/console-operator/pull/1201)
* [CONSOLE-5431](https://issues.redhat.com/browse/CONSOLE-5431): Add allow-all NetworkPolicy to openshift-console namespace [#1199](https://github.com/openshift/console-operator/pull/1199)
* [TRT-2858](https://issues.redhat.com/browse/TRT-2858): Revert "Merge pull request #1196 from ingvagabund/tls-injection-to-console" [#1200](https://github.com/openshift/console-operator/pull/1200)
* [CONSOLE-5432](https://issues.redhat.com/browse/CONSOLE-5432): Add NetworkPolicy manifests for openshift-console-operator namespace [#1198](https://github.com/openshift/console-operator/pull/1198)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: inject centralized TLS into console operand [#1196](https://github.com/openshift/console-operator/pull/1196)
* [Full changelog](https://github.com/openshift/console-operator/compare/694a2de9e7d36a7453de16c5a7f29ce39e0d5ce3...684157180b1dfeb4a5106c669da1ac42258372ec)
### [csi-driver-manila, csi-driver-manila-operator, csi-driver-nfs, hyperkube, ibm-cloud-controller-manager, ibm-vpc-block-csi-driver, ibm-vpc-block-csi-driver-operator, ibmcloud-cluster-api-controllers, ibmcloud-machine-controllers, kube-proxy, nutanix-cloud-controller-manager, nutanix-machine-controllers, pod, powervs-block-csi-driver, powervs-block-csi-driver-operator, powervs-cloud-controller-manager, powervs-machine-controllers, vsphere-cloud-controller-manager, vsphere-cluster-api-controllers, vsphere-csi-driver, vsphere-csi-driver-operator, vsphere-csi-driver-syncer, vsphere-problem-detector](https://github.com/openshift/kubernetes/tree/e63ab41237b34f2a457e76900f6162184420cf96)
* [OCPBUGS-85262](https://issues.redhat.com/browse/OCPBUGS-85262): Re-enable kubectl kuberc commands e2e tests [#2731](https://github.com/openshift/kubernetes/pull/2731)
* [OCPBUGS-92798](https://issues.redhat.com/browse/OCPBUGS-92798): Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) [#2717](https://github.com/openshift/kubernetes/pull/2717)
* [STOR-2961](https://issues.redhat.com/browse/STOR-2961): UPSTREAM: 138768: move VolumeGroupSnapshot to V1 [#2723](https://github.com/openshift/kubernetes/pull/2723)
* [CNTRLPLANE-3323](https://issues.redhat.com/browse/CNTRLPLANE-3323): Update openshift-hack/rebase.sh [#2701](https://github.com/openshift/kubernetes/pull/2701)
* [OCPBUGS-98100](https://issues.redhat.com/browse/OCPBUGS-98100): e2e: storage snapshot tests should read custom timeouts from manifest [#2719](https://github.com/openshift/kubernetes/pull/2719)
* [Full changelog](https://github.com/openshift/kubernetes/compare/63ee93dac28329fd9d81e91b21ea8d8c43105d01...e63ab41237b34f2a457e76900f6162184420cf96)
### [csi-external-attacher](https://github.com/openshift/csi-external-attacher/tree/3fd668b3f07dd382e5c7b6239d50f7988f652e64)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v4.12.0 for OCP 5.0 [#110](https://github.com/openshift/csi-external-attacher/pull/110)
* [Full changelog](https://github.com/openshift/csi-external-attacher/compare/96ebfa733c06c3398555d164c788e310908fecf6...3fd668b3f07dd382e5c7b6239d50f7988f652e64)
### [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner/tree/7ff338c9d1296f0e5d4d8080a76bb191c8f3be30)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v6.3.0 for OCP 5.0 [#146](https://github.com/openshift/csi-external-provisioner/pull/146)
* [Full changelog](https://github.com/openshift/csi-external-provisioner/compare/bdf440fab8a48e4b76cf0902ad5ba17a20881a8b...7ff338c9d1296f0e5d4d8080a76bb191c8f3be30)
### [csi-external-resizer](https://github.com/openshift/csi-external-resizer/tree/14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.2.1 for OCP 5.0 [#198](https://github.com/openshift/csi-external-resizer/pull/198)
* [Full changelog](https://github.com/openshift/csi-external-resizer/compare/c608adfc7e82c7c59221bb9d22642a1902cace43...14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf)
### [csi-external-snapshotter, csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter/tree/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2)
* [OCPBUGS-99009](https://issues.redhat.com/browse/OCPBUGS-99009): [external-snapshotter] SnapshotContentObjectDeleteError event fired when VolumeSnapshotContent is already deleted [#226](https://github.com/openshift/csi-external-snapshotter/pull/226)
* [Full changelog](https://github.com/openshift/csi-external-snapshotter/compare/b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8...a019d1a9d9e1d26ffd0b2e0d911733180fa608b2)
### [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe/tree/463dc553ebb04df192d573c5a1612dcb50cb1f52)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.19.0 for OCP 5.0 [#94](https://github.com/openshift/csi-livenessprobe/pull/94)
* [Full changelog](https://github.com/openshift/csi-livenessprobe/compare/f649d2c76f2484b73c70007801eb81ab4be63635...463dc553ebb04df192d573c5a1612dcb50cb1f52)
### [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar/tree/5766960d82ffb9ef84d15e903ae57d0a6781ef11)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.17.0 for OCP 5.0 [#108](https://github.com/openshift/csi-node-driver-registrar/pull/108)
* [Full changelog](https://github.com/openshift/csi-node-driver-registrar/compare/02d5345005aeb6aac2277818937501cdd1a3a88e...5766960d82ffb9ef84d15e903ae57d0a6781ef11)
### [docker-registry](https://github.com/openshift/image-registry/tree/a91ce6edf2c5cc08aa184c47dff79e842079c533)
* [CORS-4520](https://issues.redhat.com/browse/CORS-4520): GCP: Support Alternate Universe Domain [#474](https://github.com/openshift/image-registry/pull/474)
* [Full changelog](https://github.com/openshift/image-registry/compare/eb1b09dc465a8d53c5683da40f5d5fd306fd945a...a91ce6edf2c5cc08aa184c47dff79e842079c533)
### [driver-toolkit, driver-toolkit-10](https://github.com/openshift/driver-toolkit/tree/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a)
* [OCPBUGS-82502](https://issues.redhat.com/browse/OCPBUGS-82502): Fix e2e test duplicate output from oc run -i --rm [#198](https://github.com/openshift/driver-toolkit/pull/198)
* [Full changelog](https://github.com/openshift/driver-toolkit/compare/7ec03cbba69b4dc86ee33e313bad32ae2ea2924e...b63b175a79b9fe0c29f6ed63df3c2d7862ba408a)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/7b9f54aff1a90ba59242b305fb628db9f20d1d2c)
* NO-JIRA: Remove dead code, drastically shrink vendored deps [#110](https://github.com/openshift/egress-router-cni/pull/110)
* NO-JIRA: Update OWNERS file [#104](https://github.com/openshift/egress-router-cni/pull/104)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/a923d37cfe033853603240f862cb907ba997cb68...7b9f54aff1a90ba59242b305fb628db9f20d1d2c)
### [etcd](https://github.com/openshift/etcd/tree/3688f53af36d9412ab3d99c86d66aafbfb711e7f)
* [CNTRLPLANE-3461](https://issues.redhat.com/browse/CNTRLPLANE-3461): refactor defrag to minimize database lock time [#378](https://github.com/openshift/etcd/pull/378)
* [Full changelog](https://github.com/openshift/etcd/compare/64f8851a001f7e102d47bfe51ca0dac23951879a...3688f53af36d9412ab3d99c86d66aafbfb711e7f)
### [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp/tree/51c326465b3160124b8097953b42e44f1056da5a)
* [CORS-4516](https://issues.redhat.com/browse/CORS-4516): Support setting universe domain in client options [#131](https://github.com/openshift/cloud-provider-gcp/pull/131)
* [OCPCLOUD-3592](https://issues.redhat.com/browse/OCPCLOUD-3592): Merge https://github.com/kubernetes/cloud-provider-gcp:master (b01dfd6) into main [#104](https://github.com/openshift/cloud-provider-gcp/pull/104)
* [Full changelog](https://github.com/openshift/cloud-provider-gcp/compare/30cc04797f50e78e91f8e47cc6c36c0da84eee2c...51c326465b3160124b8097953b42e44f1056da5a)
### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/dbcbfe70efa75f192309f2d0f8daae2c6a441e90)
* [OCPCLOUD-3601](https://issues.redhat.com/browse/OCPCLOUD-3601): Merge https://github.com/kubernetes-sigs/cluster-api-provider-gcp:v1.13.0 (be0534e) into main [#300](https://github.com/openshift/cluster-api-provider-gcp/pull/300)
* [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/194befaa927c8e6ca56526218f2d4f5e2d4bd431...dbcbfe70efa75f192309f2d0f8daae2c6a441e90)
### [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp/tree/91033fc5b42f58acdad7be8c89a0012f5f2c9b5b)
* [OCPCLOUD-3617](https://issues.redhat.com/browse/OCPCLOUD-3617): Update to Kubernetes 1.36 dependencies [#182](https://github.com/openshift/machine-api-provider-gcp/pull/182)
* [CORS-4521](https://issues.redhat.com/browse/CORS-4521): Support Alternate Universe Domain [#180](https://github.com/openshift/machine-api-provider-gcp/pull/180)
* [Full changelog](https://github.com/openshift/machine-api-provider-gcp/compare/1d098131fa7123b9793e01dcdac4d0b18b9ef1ae...91033fc5b42f58acdad7be8c89a0012f5f2c9b5b)
### [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook/tree/4501ff2f53576c31df0511b69444e65e1eeba745)
* [OCPCLOUD-3585](https://issues.redhat.com/browse/OCPCLOUD-3585): Update gcp-workload-identity-federation-webhook to k8s 1.36 [#21](https://github.com/openshift/gcp-workload-identity-federation-webhook/pull/21)
* [Full changelog](https://github.com/openshift/gcp-workload-identity-federation-webhook/compare/a8f16141e4234fa2c9f6aeb8498622af6e4a080d...4501ff2f53576c31df0511b69444e65e1eeba745)
### [haproxy-router, haproxy-router-haproxy28, haproxy-router-haproxy32](https://github.com/openshift/router/tree/4b401a86dccc657a8a5254c2794a312241f40e87)
* [NE-2826](https://issues.redhat.com/browse/NE-2826): Fix staticcheck warnings across multiple packages [#815](https://github.com/openshift/router/pull/815)
* "NO-JIRA: Add AGENTS.md" [#710](https://github.com/openshift/router/pull/710)
* [NE-2829](https://issues.redhat.com/browse/NE-2829): images/router/f5: Delete F5 router Dockerfile [#826](https://github.com/openshift/router/pull/826)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Revert #825 "Make external cert validation asynchronous (v2 — race condition fixes)" [#829](https://github.com/openshift/router/pull/829)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Make external cert validation asynchronous (v2 — race condition fixes) [#825](https://github.com/openshift/router/pull/825)
* [Full changelog](https://github.com/openshift/router/compare/682319a1bb432f0203951c33336d0f55947e1099...4b401a86dccc657a8a5254c2794a312241f40e87)
### [hypershift](https://github.com/openshift/hypershift/tree/a26a7a40e5993ceaee71154720f5bf53fe677169)
* NO-JIRA: isolate NewSession tests from ambient AWS env vars [#8911](https://github.com/openshift/hypershift/pull/8911)
* [CNTRLPLANE-3984](https://issues.redhat.com/browse/CNTRLPLANE-3984): document all skills and commands in SKILLS.md [#9210](https://github.com/openshift/hypershift/pull/9210)
* [OCPBUGS-105193](https://issues.redhat.com/browse/OCPBUGS-105193): extract HCCO webhook validation into a dedicated controller [#9239](https://github.com/openshift/hypershift/pull/9239)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): add manual trigger and fix path filter for docs publish [#9261](https://github.com/openshift/hypershift/pull/9261)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): correct wrangler pages deploy flags for docs publish [#9252](https://github.com/openshift/hypershift/pull/9252)
* [OCPBUGS-60093](https://issues.redhat.com/browse/OCPBUGS-60093): fix(upsert): add desired-state hash to detect spec field removals [#7713](https://github.com/openshift/hypershift/pull/7713)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): add workflow to publish docs to Cloudflare Pages on merge [#9221](https://github.com/openshift/hypershift/pull/9221)
* [CNTRLPLANE-3291](https://issues.redhat.com/browse/CNTRLPLANE-3291): docs: add upstream documentation for configurable log levels [#9193](https://github.com/openshift/hypershift/pull/9193)
* [CNTRLPLANE-3978](https://issues.redhat.com/browse/CNTRLPLANE-3978): Fix CPO finalizer race leaving orphaned Azure Private Endpoint resources [#9194](https://github.com/openshift/hypershift/pull/9194)
* [CNTRLPLANE-3873](https://issues.redhat.com/browse/CNTRLPLANE-3873), [CNTRLPLANE-3874](https://issues.redhat.com/browse/CNTRLPLANE-3874), [OCPBUGS-94518](https://issues.redhat.com/browse/OCPBUGS-94518): update azure CPO overrides for 4.20, 4.21, 4.22 [#9211](https://github.com/openshift/hypershift/pull/9211)
* [CNTRLPLANE-3375](https://issues.redhat.com/browse/CNTRLPLANE-3375): test(e2e): remove oc dependency in external oidc e2e tests [#9208](https://github.com/openshift/hypershift/pull/9208)
* [OCPBUGS-104543](https://issues.redhat.com/browse/OCPBUGS-104543): fix test isolation bug in EnsureDefaultSecurityGroupTagsTest [#9228](https://github.com/openshift/hypershift/pull/9228)
* NO-JIRA: build(deps): bump the github-dependencies group with 23 updates [#9190](https://github.com/openshift/hypershift/pull/9190)
* [OCPBUGS-104505](https://issues.redhat.com/browse/OCPBUGS-104505): fix(ci): trigger envtest workflows on dependency changes [#9215](https://github.com/openshift/hypershift/pull/9215)
* [CNTRLPLANE-3673](https://issues.redhat.com/browse/CNTRLPLANE-3673): add HO Konflux release gating documentation [#8947](https://github.com/openshift/hypershift/pull/8947)
* [OCPBUGS-100279](https://issues.redhat.com/browse/OCPBUGS-100279): load plugin explicitly in bare mode for skill resolution [#9220](https://github.com/openshift/hypershift/pull/9220)
* [OCPBUGS-104528](https://issues.redhat.com/browse/OCPBUGS-104528): Update openshift API to resolve broken hypershift integration tests on K8s 1.30 [#9231](https://github.com/openshift/hypershift/pull/9231)
* [OCPBUGS-105207](https://issues.redhat.com/browse/OCPBUGS-105207): Revert "OCPBUGS-89689: (karpenter) use completed release image for unpinned NodeClaims during CP upgrade" [#9233](https://github.com/openshift/hypershift/pull/9233)
* NO-JIRA: fix(build): bump hack/tools Go version to 1.26.0 to match main module [#9223](https://github.com/openshift/hypershift/pull/9223)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): e2e: Remove osImageStream cleanup that violates immutability [#9206](https://github.com/openshift/hypershift/pull/9206)
* [OCPBUGS-100054](https://issues.redhat.com/browse/OCPBUGS-100054): Fix Azure Private clusters without external DNS [#9171](https://github.com/openshift/hypershift/pull/9171)
* [GCP-896](https://issues.redhat.com/browse/GCP-896): chore: add gbarabasz to gcp-reviewers alias [#9000](https://github.com/openshift/hypershift/pull/9000)
* [CNTRLPLANE-3979](https://issues.redhat.com/browse/CNTRLPLANE-3979): Add missing ProjectDevelopmentStream 4.14 [#9225](https://github.com/openshift/hypershift/pull/9225)
* [CNTRLPLANE-3863](https://issues.redhat.com/browse/CNTRLPLANE-3863): emit lifecycle-aware JUnit for informing e2e tests [#9168](https://github.com/openshift/hypershift/pull/9168)
* NO-JIRA: add e2e-approvers owner alias, grant Dan Mace e2e role [#9216](https://github.com/openshift/hypershift/pull/9216)
* NO-JIRA: build(deps): bump the k8s-dependencies group across 1 directory with 12 updates [#9189](https://github.com/openshift/hypershift/pull/9189)
* [OCPBUGS-100184](https://issues.redhat.com/browse/OCPBUGS-100184): Wait for Azure ignition DNS before creating workers [#9172](https://github.com/openshift/hypershift/pull/9172)
* [OCPBUGS-100279](https://issues.redhat.com/browse/OCPBUGS-100279): isolate Claude from push credentials in PR workflows [#9214](https://github.com/openshift/hypershift/pull/9214)
* [OCPBUGS-98983](https://issues.redhat.com/browse/OCPBUGS-98983): improve guest cluster state management reliability [#9198](https://github.com/openshift/hypershift/pull/9198)
* [STOR-2918](https://issues.redhat.com/browse/STOR-2918): update AWS EBS CSI credentials request policy to mirror upstream [#8954](https://github.com/openshift/hypershift/pull/8954)
* [OCPBUGS-100301](https://issues.redhat.com/browse/OCPBUGS-100301): fix(hostedcluster): handle Unknown status in ClusterVersionFailing inversion [#9186](https://github.com/openshift/hypershift/pull/9186)
* [OCPBUGS-89689](https://issues.redhat.com/browse/OCPBUGS-89689): (karpenter) use completed release image for unpinned NodeClaims during CP upgrade [#8957](https://github.com/openshift/hypershift/pull/8957)
* NO-JIRA: build(deps): bump the misc-dependencies group across 1 directory with 6 updates [#9164](https://github.com/openshift/hypershift/pull/9164)
* [CNTRLPLANE-3863](https://issues.redhat.com/browse/CNTRLPLANE-3863): add e2e v2 test flow document [#9151](https://github.com/openshift/hypershift/pull/9151)
* docs: add July 2026 progress report blog post [#9057](https://github.com/openshift/hypershift/pull/9057)
* [OCPBUGS-100302](https://issues.redhat.com/browse/OCPBUGS-100302): fix(metrics): only report limited support when label … [#9185](https://github.com/openshift/hypershift/pull/9185)
* NO-JIRA: build(deps): bump github.com/google/cel-go from 0.28.1 to 0.29.0 [#9125](https://github.com/openshift/hypershift/pull/9125)
* [CNTRLPLANE-3943](https://issues.redhat.com/browse/CNTRLPLANE-3943): feat(destroy): add --force flag to strip finalizers on grace period expiry [#9134](https://github.com/openshift/hypershift/pull/9134)
* [STOR-2954](https://issues.redhat.com/browse/STOR-2954): inject centralized TLS configuration for storage operators [#8887](https://github.com/openshift/hypershift/pull/8887)
* Revert "CNTRLPLANE-3890: Add product-cli unit tests for HCP create cluster" [#9201](https://github.com/openshift/hypershift/pull/9201)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): resolve RHEL stream dynamically for boot images [#9099](https://github.com/openshift/hypershift/pull/9099)
* NO-JIRA: build(deps): bump the sigs-k8s-dependencies group across 1 directory with 8 updates [#9177](https://github.com/openshift/hypershift/pull/9177)
* [CNTRLPLANE-3890](https://issues.redhat.com/browse/CNTRLPLANE-3890): Add product-cli unit tests for HCP create cluster [#9107](https://github.com/openshift/hypershift/pull/9107)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): wire up AWS v2 e2e lifecycle test coverage [#9174](https://github.com/openshift/hypershift/pull/9174)
* [OCPBUGS-100140](https://issues.redhat.com/browse/OCPBUGS-100140): bracket IPv6 in OAuth issuer and callback URLs [#9120](https://github.com/openshift/hypershift/pull/9120)
* [AUTOSCALE-644](https://issues.redhat.com/browse/AUTOSCALE-644): bump karpenter deps to 1.13.0 [#9170](https://github.com/openshift/hypershift/pull/9170)
* [CNTRLPLANE-3976](https://issues.redhat.com/browse/CNTRLPLANE-3976): Document management cluster vs hosted cluster feature gates [#9182](https://github.com/openshift/hypershift/pull/9182)
* [OCPBUGS-97804](https://issues.redhat.com/browse/OCPBUGS-97804): Avoid printing errors twice [#8931](https://github.com/openshift/hypershift/pull/8931)
* [CNTRLPLANE-3887](https://issues.redhat.com/browse/CNTRLPLANE-3887): test(e2e): add metricsSet filtering coverage to metrics forwarder test [#9078](https://github.com/openshift/hypershift/pull/9078)
* [OCPBUGS-86843](https://issues.redhat.com/browse/OCPBUGS-86843): fix(konnectivity): conditionally prefer IPv4 based on HCP network config [#9140](https://github.com/openshift/hypershift/pull/9140)
* [OCPBUGS-91511](https://issues.redhat.com/browse/OCPBUGS-91511): Fix CPO infinite requeue during deletion when OIDC provider is gone [#8894](https://github.com/openshift/hypershift/pull/8894)
* [OCPBUGS-98654](https://issues.redhat.com/browse/OCPBUGS-98654): delete_hosted_cluster.sh fails to run with no --dns-zone-rg-name flag [#8945](https://github.com/openshift/hypershift/pull/8945)
* NO-JIRA: docs: fix ARCHITECTURE.md to reflect current CPO image resolution [#9179](https://github.com/openshift/hypershift/pull/9179)
* [OCPBUGS-100087](https://issues.redhat.com/browse/OCPBUGS-100087): Replace exponential backoff with fixed-interval requeue in CRR controller [#9148](https://github.com/openshift/hypershift/pull/9148)
* [OCPBUGS-99783](https://issues.redhat.com/browse/OCPBUGS-99783): fix(e2e): check pre-upgrade HO version for shared role support [#8891](https://github.com/openshift/hypershift/pull/8891)
* [CNTRLPLANE-3709](https://issues.redhat.com/browse/CNTRLPLANE-3709): test(azure): enable Global Pull Secret test in Azure CI [#9073](https://github.com/openshift/hypershift/pull/9073)
* [CNTRLPLANE-3956](https://issues.redhat.com/browse/CNTRLPLANE-3956): Make EnsureGlobalPullSecret e2e test informing [#9167](https://github.com/openshift/hypershift/pull/9167)
* [CNTRLPLANE-2539](https://issues.redhat.com/browse/CNTRLPLANE-2539): Move generation of the CAPI Provider Role [#8305](https://github.com/openshift/hypershift/pull/8305)
* NO-JIRA: docs: add hash migration impact guidance and CPO data-plane component docs [#9161](https://github.com/openshift/hypershift/pull/9161)
* [CNTRLPLANE-3897](https://issues.redhat.com/browse/CNTRLPLANE-3897): Add product-cli unit tests for create nodepool [#9121](https://github.com/openshift/hypershift/pull/9121)
* [CNTRLPLANE-3600](https://issues.redhat.com/browse/CNTRLPLANE-3600): Bump k8s to v0.36.2, controller-runtime to v0.24.1, CAPI to v1.12.8 [#8695](https://github.com/openshift/hypershift/pull/8695)
* [CNTRLPLANE-3944](https://issues.redhat.com/browse/CNTRLPLANE-3944): Regenerate requirements.txt files with pinned --hash entries [#9135](https://github.com/openshift/hypershift/pull/9135)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): fix yq dependency for running upstream karpenter tests [#9060](https://github.com/openshift/hypershift/pull/9060)
* [OCPBUGS-99288](https://issues.redhat.com/browse/OCPBUGS-99288): Add proxy env vars to AWS cloud-controller-manager deployment [#9053](https://github.com/openshift/hypershift/pull/9053)
* [CNTRLPLANE-3604](https://issues.redhat.com/browse/CNTRLPLANE-3604): Add CAPI migration flag placeholder [#9145](https://github.com/openshift/hypershift/pull/9145)
* [CNTRLPLANE-3564](https://issues.redhat.com/browse/CNTRLPLANE-3564): test(awsprivatelink): add unit test for NoSuchHostedZone handling dur… [#9141](https://github.com/openshift/hypershift/pull/9141)
* NO-JIRA: build(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 [#9113](https://github.com/openshift/hypershift/pull/9113)
* NO-JIRA: build(deps): bump google.golang.org/grpc from 1.79.3 to 1.82.1 in /hack/tools [#9111](https://github.com/openshift/hypershift/pull/9111)
* [CNTRLPLANE-3888](https://issues.redhat.com/browse/CNTRLPLANE-3888): docs: add on-demand jira-agent triggering and plugin install instructions [#9079](https://github.com/openshift/hypershift/pull/9079)
* [OCPBUGS-54776](https://issues.redhat.com/browse/OCPBUGS-54776): fix(ignition-server): log MCS output on HTTP request failures [#8936](https://github.com/openshift/hypershift/pull/8936)
* [CNTRLPLANE-400](https://issues.redhat.com/browse/CNTRLPLANE-400): feat(remediationAllowed in NP): propagate MHC RemediationAllowed to NodePool Ready condition [#9019](https://github.com/openshift/hypershift/pull/9019)
* NO-JIRA: align control-plane Dockerfile builder image with main Dockerfile [#9138](https://github.com/openshift/hypershift/pull/9138)
* [OCPBUGS-99768](https://issues.redhat.com/browse/OCPBUGS-99768): fix OSImageStream e2e test and Makefile test-changed for OCP 5.0 [#9115](https://github.com/openshift/hypershift/pull/9115)
* [CNTRLPLANE-3893](https://issues.redhat.com/browse/CNTRLPLANE-3893): Add product-cli unit tests for destroy cluster [#9116](https://github.com/openshift/hypershift/pull/9116)
* NO-JIRA: ci(deps): bump actions/checkout from 6.0.2 to 7.0.1 [#9090](https://github.com/openshift/hypershift/pull/9090)
* NO-JIRA: ci(deps): bump actions/setup-python from 6.2.0 to 7.0.0 [#9089](https://github.com/openshift/hypershift/pull/9089)
* NO-JIRA: ci(deps): bump actions/setup-go from 6.4.0 to 7.0.0 [#9029](https://github.com/openshift/hypershift/pull/9029)
* [OCPBUGS-86494](https://issues.redhat.com/browse/OCPBUGS-86494): fix(nodepool): preserve KubeVirt userdata Secrets during NodePool rollout [#8581](https://github.com/openshift/hypershift/pull/8581)
* [Full changelog](https://github.com/openshift/hypershift/compare/872a7e821c3fe01b2f866ceada3749a899e3d64f...a26a7a40e5993ceaee71154720f5bf53fe677169)
### [insights-operator](https://github.com/openshift/insights-operator/tree/8494b69b8075fd1e8eac49db77bcda7588078155)
* [CCXDEV-16647](https://issues.redhat.com/browse/CCXDEV-16647): add create gatherer skill [#1335](https://github.com/openshift/insights-operator/pull/1335)
* NO-JIRA: remove katarina [#1336](https://github.com/openshift/insights-operator/pull/1336)
* [CCXDEV-16629](https://issues.redhat.com/browse/CCXDEV-16629): Add network policy [#1331](https://github.com/openshift/insights-operator/pull/1331)
* [CCXDEV-15210](https://issues.redhat.com/browse/CCXDEV-15210): secrets and configmap revisions count gathering [#1316](https://github.com/openshift/insights-operator/pull/1316)
* [OCPBUGS-98690](https://issues.redhat.com/browse/OCPBUGS-98690): Fix indentation bug on livenessProbe [#1320](https://github.com/openshift/insights-operator/pull/1320)
* [OCPBUGS-96894](https://issues.redhat.com/browse/OCPBUGS-96894): Update net and crypto libraries [#1321](https://github.com/openshift/insights-operator/pull/1321)
* [Full changelog](https://github.com/openshift/insights-operator/compare/46db2e2ca9b0b7576e0b66f4521a2cf83aad8893...8494b69b8075fd1e8eac49db77bcda7588078155)
### [insights-runtime-exporter, insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor/tree/d70c566bcd4a2af3825fe5cfa6383d73530d6a0f)
* NO-JIRA: Add new owners required for managing OCP CI config [#86](https://github.com/openshift/insights-runtime-extractor/pull/86)
* [Full changelog](https://github.com/openshift/insights-runtime-extractor/compare/ce30b4f9bc3ec867b976886a5207d36c50a396d9...d70c566bcd4a2af3825fe5cfa6383d73530d6a0f)
### [ironic](https://github.com/openshift/ironic-image/tree/e66245ac7cb2569be6e5fa67b27fad8e8c8a1ae9)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#873](https://github.com/openshift/ironic-image/pull/873)
* NO-ISSUE: Merge upstream 2026 07 24 [#872](https://github.com/openshift/ironic-image/pull/872)
* NO-ISSUE: Filter blank lines from build-packages-list.ocp in Dockerfile [#869](https://github.com/openshift/ironic-image/pull/869)
* [METAL-1912](https://issues.redhat.com/browse/METAL-1912): Add PQC support until we have pqc minimal images available [#871](https://github.com/openshift/ironic-image/pull/871)
* [Full changelog](https://github.com/openshift/ironic-image/compare/e9478ec49dd508f74234582a8247f9186f584500...e66245ac7cb2569be6e5fa67b27fad8e8c8a1ae9)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/6bc9a57af3931a6d5ef5e96b766c9fabcf2829b4)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#297](https://github.com/openshift/ironic-agent-image/pull/297)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#295](https://github.com/openshift/ironic-agent-image/pull/295)
* NO-ISSUE: Filter blank lines from build-packages-list.ocp in Dockerfile [#292](https://github.com/openshift/ironic-agent-image/pull/292)
* NO-ISSUE: Update requirements.cachito with latest ironic-python-agent [#293](https://github.com/openshift/ironic-agent-image/pull/293)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/f0ff570e26f0312dbb02058a092887c276bf0706...6bc9a57af3931a6d5ef5e96b766c9fabcf2829b4)
### [karpenter-operator](https://github.com/openshift/karpenter-operator/tree/560232d2b6962e041dc332f08026adda14552d41)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): Add make target and scripts for karpenter core regression e2e tests [#20](https://github.com/openshift/karpenter-operator/pull/20)
* [AUTOSCALE-871](https://issues.redhat.com/browse/AUTOSCALE-871): allow Karpenter Operator to run in ManagementCluster mode [#19](https://github.com/openshift/karpenter-operator/pull/19)
* no-jira: change karpenter CR singleton name to default [#17](https://github.com/openshift/karpenter-operator/pull/17)
* [Full changelog](https://github.com/openshift/karpenter-operator/compare/79a93d5b4221424832a247a618e20b8177ec71ed...560232d2b6962e041dc332f08026adda14552d41)
### [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server/tree/3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71)
* [OCPBUGS-93753](https://issues.redhat.com/browse/OCPBUGS-93753): Bump openshift/kubernetes-metrics-server to v0.9.0 [#71](https://github.com/openshift/kubernetes-metrics-server/pull/71)
* [Full changelog](https://github.com/openshift/kubernetes-metrics-server/compare/e24eb97b02b3d39095c70675f5594ae5bc98d238...3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/0db39ee372bf7b75f56898fd2df555e063d32952)
* [OCPBUGS-85110](https://issues.redhat.com/browse/OCPBUGS-85110): Move required-scc annotation to pod template for machine-api-controllers [#1511](https://github.com/openshift/machine-api-operator/pull/1511)
* [OCPBUGS-100056](https://issues.redhat.com/browse/OCPBUGS-100056): fix: skip Multisubnet test for single network infra [#1527](https://github.com/openshift/machine-api-operator/pull/1527)
* [OCPBUGS-99903](https://issues.redhat.com/browse/OCPBUGS-99903): Fixing test issue where error result was for other resource type [#1524](https://github.com/openshift/machine-api-operator/pull/1524)
* [OCPBUGS-100067](https://issues.redhat.com/browse/OCPBUGS-100067): Deduplicate unchanged status upgrade events [#1526](https://github.com/openshift/machine-api-operator/pull/1526)
* [CORS-4521](https://issues.redhat.com/browse/CORS-4521): GCP: Add regional permission [#1523](https://github.com/openshift/machine-api-operator/pull/1523)
* [OCPCLOUD-3614](https://issues.redhat.com/browse/OCPCLOUD-3614): bump k8s and openshift deps [#1520](https://github.com/openshift/machine-api-operator/pull/1520)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/3be0a58b3e9d168eb2dd746c58d79e9081f10c73...0db39ee372bf7b75f56898fd2df555e063d32952)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/84999756cf4ca5b20cc0b1f3b20cfda9bd22fdd6)
* [OCPBUGS-105432](https://issues.redhat.com/browse/OCPBUGS-105432): fix nil pointer panic in IRI controller informer race [#6385](https://github.com/openshift/machine-config-operator/pull/6385)
* NO-ISSUE: Adapt vsphere bootimage tests for mult-vcenter scenarios [#6317](https://github.com/openshift/machine-config-operator/pull/6317)
* [OCPBUGS-92062](https://issues.redhat.com/browse/OCPBUGS-92062): reduce memory usage in MCC and MCD [#6259](https://github.com/openshift/machine-config-operator/pull/6259)
* [OCPBUGS-100433](https://issues.redhat.com/browse/OCPBUGS-100433): Update AMI Whitelist [#6358](https://github.com/openshift/machine-config-operator/pull/6358)
* [MCO-2275](https://issues.redhat.com/browse/MCO-2275): Part2 Migrate MCO OCB [#6340](https://github.com/openshift/machine-config-operator/pull/6340)
* [MCO-1814](https://issues.redhat.com/browse/MCO-1814), [MCO-2377](https://issues.redhat.com/browse/MCO-2377): Setup metrics for builds, Add metric to gather how many people are using OCL [#6316](https://github.com/openshift/machine-config-operator/pull/6316)
* [OCPNODE-4040](https://issues.redhat.com/browse/OCPNODE-4040): Use single KubeletConfigAccepted condition type with True/False status [#5854](https://github.com/openshift/machine-config-operator/pull/5854)
* [OCPBUGS-92182](https://issues.redhat.com/browse/OCPBUGS-92182): OCPBUGS-99219: Use providerSpec.Template in vSphere machineset reconciliation [#6234](https://github.com/openshift/machine-config-operator/pull/6234)
* [OCPBUGS-99696](https://issues.redhat.com/browse/OCPBUGS-99696): Add extension verification failure test cases OCP-89090 and OCP-89095 [#6333](https://github.com/openshift/machine-config-operator/pull/6333)
* [MCO-2485](https://issues.redhat.com/browse/MCO-2485): Mark scale-up test as 'informing' [#6364](https://github.com/openshift/machine-config-operator/pull/6364)
* [OCPBUGS-100458](https://issues.redhat.com/browse/OCPBUGS-100458): Adapt bootimage tests for CAPI migration [#6363](https://github.com/openshift/machine-config-operator/pull/6363)
* [MCO-1540](https://issues.redhat.com/browse/MCO-1540): Set up events for builds [#6252](https://github.com/openshift/machine-config-operator/pull/6252)
* [MCO-2482](https://issues.redhat.com/browse/MCO-2482): Revert "MCO-2470: Disable scale-up test support for AWS and vSphere" [#6356](https://github.com/openshift/machine-config-operator/pull/6356)
* [TRT-2875](https://issues.redhat.com/browse/TRT-2875): Revert #6303 "MCO-2205: Make ImageModeStatusReporting MCP count test more resilient on SNO" [#6359](https://github.com/openshift/machine-config-operator/pull/6359)
* [MCO-2205](https://issues.redhat.com/browse/MCO-2205): Make ImageModeStatusReporting MCP count test more resilient on SNO [#6303](https://github.com/openshift/machine-config-operator/pull/6303)
* [OCPBUGS-98316](https://issues.redhat.com/browse/OCPBUGS-98316): Fix SHA idempotency test in nmstate-configuration.sh [#6291](https://github.com/openshift/machine-config-operator/pull/6291)
* [OCPBUGS-100389](https://issues.redhat.com/browse/OCPBUGS-100389): machine-config-daemon-firstboot: disable ostree fsync during bootstrap [#6122](https://github.com/openshift/machine-config-operator/pull/6122)
* [MCO-2275](https://issues.redhat.com/browse/MCO-2275): Part 1 Migrate OCB test cases from openshift-tests-private [#6080](https://github.com/openshift/machine-config-operator/pull/6080)
* NO-ISSUE: test MCC proxy. Refactor TC 52373 proxy test. [#6355](https://github.com/openshift/machine-config-operator/pull/6355)
* [MCO-2468](https://issues.redhat.com/browse/MCO-2468): Cache backed OSImageStreams for PIS [#6329](https://github.com/openshift/machine-config-operator/pull/6329)
* NO-ISSUE: Fix setArchitectureAndCheckStatus corrupting multi-label annotations [#6347](https://github.com/openshift/machine-config-operator/pull/6347)
* [OCPBUGS-100277](https://issues.redhat.com/browse/OCPBUGS-100277): Fix TC 43278 failing when release payload has no MCO commit info [#6349](https://github.com/openshift/machine-config-operator/pull/6349)
* NO-ISSUE: Fix incorrect OSImageStreams log [#6338](https://github.com/openshift/machine-config-operator/pull/6338)
* [MCO-2244](https://issues.redhat.com/browse/MCO-2244): Update MCO dependencies to Kubernetes 1.36 [#6321](https://github.com/openshift/machine-config-operator/pull/6321)
* [MCO-2470](https://issues.redhat.com/browse/MCO-2470): Disable scale-up test support for AWS and vSphere [#6344](https://github.com/openshift/machine-config-operator/pull/6344)
* NO-ISSUE: fix fencing_validator ocdebug fence dispatch race condition [#6341](https://github.com/openshift/machine-config-operator/pull/6341)
* [OCPBUGS-82139](https://issues.redhat.com/browse/OCPBUGS-82139): Add control-plane NoSchedule taint support alongside master taint [#6313](https://github.com/openshift/machine-config-operator/pull/6313)
* NO-JIRA: vendor: bump github.com/openshift/api to latest master [#6334](https://github.com/openshift/machine-config-operator/pull/6334)
* NO-ISSUE: Use context instead of discrete signal [#6337](https://github.com/openshift/machine-config-operator/pull/6337)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/3b4a5c7d9fa127981c57efac6fa29bc76eac019d...84999756cf4ca5b20cc0b1f3b20cfda9bd22fdd6)
### [machine-image-customization-controller](https://github.com/openshift/image-customization-controller/tree/e49b096880f17296d42a77443dc14d732683333d)
* NO-ISSUE: update BMO [#183](https://github.com/openshift/image-customization-controller/pull/183)
* [Full changelog](https://github.com/openshift/image-customization-controller/compare/7a348422137de33a9bfa6368b3797686ff4e8f98...e49b096880f17296d42a77443dc14d732683333d)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/bf618aac93c71a56e8249669c579f0a782742e2e)
* [OCPBUGS-86888](https://issues.redhat.com/browse/OCPBUGS-86888): Add IDMS mirror support for disconnected aarch64 ISO extraction [#108](https://github.com/openshift/machine-os-images/pull/108)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/7e514b05e0825994d858d0a142e255abdd0e8f2d...bf618aac93c71a56e8249669c579f0a782742e2e)
### [metallb-frr](https://github.com/openshift/frr/tree/54a6ea48902d81460536b81ea6bdceb89c12e622)
* [OCPBUGS-104452](https://issues.redhat.com/browse/OCPBUGS-104452): Fix TLS ciphers for MinVersion=1.3 [#135](https://github.com/openshift/frr/pull/135)
* [Full changelog](https://github.com/openshift/frr/compare/5d3b12b6ce0a7def4a7a4d1df7ff9e88deb430f5...54a6ea48902d81460536b81ea6bdceb89c12e622)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/2abd16ff885db25f1211cc9daf591c8c35e399b7)
* [OCPBUGS-98488](https://issues.redhat.com/browse/OCPBUGS-98488): security: fix js-yaml vulnerable version [#1115](https://github.com/openshift/monitoring-plugin/pull/1115)
* NO-JIRA: feat: add renovate configuration [#1113](https://github.com/openshift/monitoring-plugin/pull/1113)
* [OCPBUGS-104374](https://issues.redhat.com/browse/OCPBUGS-104374): upgrade go stdlib and patch vulnerabilities [#1111](https://github.com/openshift/monitoring-plugin/pull/1111)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): fix: remove deprecation in favor of k8sListItems to fetch agentic runs [#1110](https://github.com/openshift/monitoring-plugin/pull/1110)
* [OU-1466](https://issues.redhat.com/browse/OU-1466): swap dashboard-list-page to use shared table setup [#1109](https://github.com/openshift/monitoring-plugin/pull/1109)
* NO-JIRA: don't filter silences based on namespace in acm [#1108](https://github.com/openshift/monitoring-plugin/pull/1108)
* [OCPBUGS-98877](https://issues.redhat.com/browse/OCPBUGS-98877): fix: upgrade linkify-it [#1104](https://github.com/openshift/monitoring-plugin/pull/1104)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): remove default features from plugin-backend [#1078](https://github.com/openshift/monitoring-plugin/pull/1078)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/9fbf9a64cdd3659c677452193e9afbc3d87ad702...2abd16ff885db25f1211cc9daf591c8c35e399b7)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/f099946680e376f722674e684aec96a73c58e919)
* [OCPBUGS-86046](https://issues.redhat.com/browse/OCPBUGS-86046), [OCPBUGS-94044](https://issues.redhat.com/browse/OCPBUGS-94044): DS Merge 07/24/2026 [#335](https://github.com/openshift/multus-cni/pull/335)
* [CORENET-7233](https://issues.redhat.com/browse/CORENET-7233): Update OWNERS file [#304](https://github.com/openshift/multus-cni/pull/304)
* [Full changelog](https://github.com/openshift/multus-cni/compare/15a47271dcfda5c0e57a0a79720bab4e0baabdd8...f099946680e376f722674e684aec96a73c58e919)
### [must-gather](https://github.com/openshift/must-gather/tree/fd47ab2c1d183a1e66a1a74fe30cf6a26f433409)
* [MG-233](https://issues.redhat.com/browse/MG-233): compress service and window node logs (#554) [#554](https://github.com/openshift/must-gather/pull/554)
* [Full changelog](https://github.com/openshift/must-gather/compare/9bb48fe05db060476f9a380b9d6ea16f1e94a98b...fd47ab2c1d183a1e66a1a74fe30cf6a26f433409)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/33788405f30ef023250fd8fab71caeab57ec6b90)
* IP address & Adapter model columns [#465](https://github.com/openshift/networking-console-plugin/pull/465)
* [OCPNETUI-58](https://issues.redhat.com/browse/OCPNETUI-58): Add Health and Backend health columns to Services and Routes list pages [#457](https://github.com/openshift/networking-console-plugin/pull/457)
* [OCPNETUI-38](https://issues.redhat.com/browse/OCPNETUI-38): Virtual Machines tab on NAD/UDN/CUDN detail pages [#442](https://github.com/openshift/networking-console-plugin/pull/442)
* [OCPNETUI-21](https://issues.redhat.com/browse/OCPNETUI-21), [OCPNETUI-25](https://issues.redhat.com/browse/OCPNETUI-25): made form for creating services [#453](https://github.com/openshift/networking-console-plugin/pull/453)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/2d8f85d257952c1a90467b6ee397334d49b7820e...33788405f30ef023250fd8fab71caeab57ec6b90)
### [oauth-server](https://github.com/openshift/oauth-server/tree/ffad196a95584670d3a2e20e270cb23a64e6a327)
* [RFE-9629](https://issues.redhat.com/browse/RFE-9629): Add copy to clipboard buttons to display token page [#200](https://github.com/openshift/oauth-server/pull/200)
* [Full changelog](https://github.com/openshift/oauth-server/compare/af32a04e7a91c538afe3808d51a5d28cf3480b22...ffad196a95584670d3a2e20e270cb23a64e6a327)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/cf65286ba31b6e4eda0ecb03ae10581a7e1ac688)
* [OCPBUGS-89330](https://issues.redhat.com/browse/OCPBUGS-89330): Synchronize From Upstream Repositories [#779](https://github.com/openshift/operator-framework-operator-controller/pull/779)
* NO-ISSUE: Synchronize From Upstream Repositories [#776](https://github.com/openshift/operator-framework-operator-controller/pull/776)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/be80e0c78d4e2ff3d29fd89df29dff79b00b15f6...cf65286ba31b6e4eda0ecb03ae10581a7e1ac688)
### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/58298ec3f0772b16598ca8df5ce29c0a3e5f022c)
* [OCPBUGS-85429](https://issues.redhat.com/browse/OCPBUGS-85429): hack/update-openapi-spec: prefer REGISTRY_AUTH_FILE over cluster profile pull secret [#669](https://github.com/openshift/openshift-apiserver/pull/669)
* [OCPBUGS-78480](https://issues.redhat.com/browse/OCPBUGS-78480): address review feedback on project watcher [#664](https://github.com/openshift/openshift-apiserver/pull/664)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/3725a4aafba556cc24626541f5121ccbab54916a...58298ec3f0772b16598ca8df5ce29c0a3e5f022c)
### [openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/aa9a8100e87ff13abf4dd6343c84c9f4948debef)
* [OCPBUGS-96822](https://issues.redhat.com/browse/OCPBUGS-96822): Bump golang.org/x/net to v0.55.0 [#405](https://github.com/openshift/cloud-provider-openstack/pull/405)
* [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/f8bb5994f3cee8ee2bb5cca25e3e9783ad7dd57c...aa9a8100e87ff13abf4dd6343c84c9f4948debef)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/4f65df9309c97435fc53c05f6ea4b6135b243166)
* [OSPRH-33339](https://issues.redhat.com/browse/OSPRH-33339): Add rebasebot post-rebase hook script [#428](https://github.com/openshift/cluster-api-provider-openstack/pull/428)
* [OCPBUGS-94057](https://issues.redhat.com/browse/OCPBUGS-94057): UPSTREAM: 3265: :bug: allow unconditional providerID updates in OpenStackMachine [#425](https://github.com/openshift/cluster-api-provider-openstack/pull/425)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/51bafa8bfb18064eae0ca9502fb4bb6c6963ff61...4f65df9309c97435fc53c05f6ea4b6135b243166)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/ebb46755980dd2c08d186e79cd7e98029a5adc2a)
* NO-ISSUE: Synchronize From Upstream Repositories [#1343](https://github.com/openshift/operator-framework-olm/pull/1343)
* NO-ISSUE: Synchronize From Upstream Repositories [#1340](https://github.com/openshift/operator-framework-olm/pull/1340)
* [OCPBUGS-96749](https://issues.redhat.com/browse/OCPBUGS-96749), [OCPBUGS-96752](https://issues.redhat.com/browse/OCPBUGS-96752): Synchronize From Upstream Repositories [#1338](https://github.com/openshift/operator-framework-olm/pull/1338)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/56b3931de4636f7e0d212001f2074b9dddb45a8f...ebb46755980dd2c08d186e79cd7e98029a5adc2a)
### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/089b758a29524877a831d3b91a0655bfa5b72424)
* NO-ISSUE: Bump github.com/prometheus/client_golang from 1.24.0 to 1.24.1 [#772](https://github.com/operator-framework/operator-marketplace/pull/772)
* NO-ISSUE: Bump github.com/operator-framework/operator-lifecycle-manager from 0.45.0 to 0.46.0 [#771](https://github.com/operator-framework/operator-marketplace/pull/771)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/1b7ac84cc2c8bdef32807efa5650752a46bca96c...089b758a29524877a831d3b91a0655bfa5b72424)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/7ef6640e2f19f9fa01aa4e24b3c831a08004ea28)
* NO-JIRA: openshift: fix lint issues [#3301](https://github.com/openshift/ovn-kubernetes/pull/3301)
* [CORENET-7229](https://issues.redhat.com/browse/CORENET-7229): OTE: Add test list validation tooling [#3221](https://github.com/openshift/ovn-kubernetes/pull/3221)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove RHEL 8 binary build [#3149](https://github.com/openshift/ovn-kubernetes/pull/3149)
* [OCPBUGS-87283](https://issues.redhat.com/browse/OCPBUGS-87283), [OCPBUGS-87530](https://issues.redhat.com/browse/OCPBUGS-87530), [OCPBUGS-87532](https://issues.redhat.com/browse/OCPBUGS-87532), [OCPBUGS-93623](https://issues.redhat.com/browse/OCPBUGS-93623), [OCPBUGS-95512](https://issues.redhat.com/browse/OCPBUGS-95512), [OCPBUGS-98138](https://issues.redhat.com/browse/OCPBUGS-98138): DownStream Merge [07-31-2026] [#3332](https://github.com/openshift/ovn-kubernetes/pull/3332)
* [OCPBUGS-65865](https://issues.redhat.com/browse/OCPBUGS-65865), [OCPBUGS-86223](https://issues.redhat.com/browse/OCPBUGS-86223), [OCPBUGS-89327](https://issues.redhat.com/browse/OCPBUGS-89327): DownStream Merge [07-17-2026] [#3298](https://github.com/openshift/ovn-kubernetes/pull/3298)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/88e9f0f146784e8525f6304a1f6f7c986eba2319...7ef6640e2f19f9fa01aa4e24b3c831a08004ea28)
### [prometheus](https://github.com/openshift/prometheus/tree/01d8335673aa6f88f5742ef510e133efee88a7bf)
* NO-JIRA: [bot] Bump openshift/prometheus to v3.13.2 [#351](https://github.com/openshift/prometheus/pull/351)
* [OCPBUGS-100192](https://issues.redhat.com/browse/OCPBUGS-100192): [bot] Bump openshift/prometheus to v3.13.2 [#350](https://github.com/openshift/prometheus/pull/350)
* [Full changelog](https://github.com/openshift/prometheus/compare/52ee2d3abf00f3c31611cd9fff36e97cdfd28dcc...01d8335673aa6f88f5742ef510e133efee88a7bf)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce)
* [OCPBUGS-104610](https://issues.redhat.com/browse/OCPBUGS-104610): bump dependencies from the golang-org-x group [#156](https://github.com/openshift/prometheus-alertmanager/pull/156)
* [OCPBUGS-98190](https://issues.redhat.com/browse/OCPBUGS-98190): bump github.com/hashicorp/memberlist from 0.5.4 to 0.6.0 [#155](https://github.com/openshift/prometheus-alertmanager/pull/155)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/5434dc397b4590f2906a9cd774d711113fc9f25b...89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce)
### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/49894fa3421065dfd2378f664240d07f5bd208cd)
* NO-ISSUE: [bot] Bump openshift/prometheus-operator to v0.93.0 [#388](https://github.com/openshift/prometheus-operator/pull/388)
* [OCPBUGS-96853](https://issues.redhat.com/browse/OCPBUGS-96853): [bot] Bump openshift/prometheus-operator to v0.92.1 [#385](https://github.com/openshift/prometheus-operator/pull/385)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/6a36acbd5ecd5a308bc81267f3b0567f93377247...49894fa3421065dfd2378f664240d07f5bd208cd)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07)
* [OCPBUGS-100376](https://issues.redhat.com/browse/OCPBUGS-100376): fibre_channel: fix crash when attempting to dereference invalid count… [#183](https://github.com/openshift/node_exporter/pull/183)
* [Full changelog](https://github.com/openshift/node_exporter/compare/6241c74e49baed25b1479c1786a6fc69b57b5a5b...4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07)
### [rhel-coreos, rhel-coreos-10, rhel-coreos-10-extensions, rhel-coreos-extensions](https://github.com/openshift/os/tree/bf90b219ae4ba42e07bf8c010b725401b5402cc8)
* Revert "Revert "OCPBUGS-104572: NetworkManager-ovs has moved up to RHCOS"" [#1955](https://github.com/openshift/os/pull/1955)
* Revert "OCPBUGS-104572: NetworkManager-ovs has moved up to RHCOS" [#1954](https://github.com/openshift/os/pull/1954)
* [OCPBUGS-104572](https://issues.redhat.com/browse/OCPBUGS-104572): NetworkManager-ovs has moved up to RHCOS [#1952](https://github.com/openshift/os/pull/1952)
* [Full changelog](https://github.com/openshift/os/compare/5ffc1da076e834332482544182c22d984dbf76d2...bf90b219ae4ba42e07bf8c010b725401b5402cc8)
### [service-ca-operator](https://github.com/openshift/service-ca-operator/tree/ed872ba14b615ca5726ae90e987268877a0b0b20)
* [CNTRLPLANE-3898](https://issues.redhat.com/browse/CNTRLPLANE-3898): Bump kubernetes dependencies to v1.36.2 [#366](https://github.com/openshift/service-ca-operator/pull/366)
* [MON-4515](https://issues.redhat.com/browse/MON-4515): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#319](https://github.com/openshift/service-ca-operator/pull/319)
* [Full changelog](https://github.com/openshift/service-ca-operator/compare/e260be2b3710137012814ce9ca48f155f24f0b02...ed872ba14b615ca5726ae90e987268877a0b0b20)
### [tests](https://github.com/openshift/origin/tree/a302321dc817cc65ea1806e167da941ba17d8908)
* [OCPBUGS-84491](https://issues.redhat.com/browse/OCPBUGS-84491): Remove openshift-ingress terminationMessagePolicy exemption [#31435](https://github.com/openshift/origin/pull/31435)
* [OCPBUGS-99492](https://issues.redhat.com/browse/OCPBUGS-99492): remove storage NetworkPolicies from validation skip list [#31429](https://github.com/openshift/origin/pull/31429)
* NO-ISSUE: Skip Additional Storage tests on HyperShift - MachineConfig API not available [#31489](https://github.com/openshift/origin/pull/31489)
* [NE-2788](https://issues.redhat.com/browse/NE-2788): exempt ingress Upgradeable=False for deprecated HAProxy versions [#31494](https://github.com/openshift/origin/pull/31494)
* NO-JIRA: Remove Istio configmap workaround from ClusterResourceQuota test [#31444](https://github.com/openshift/origin/pull/31444)
* [OCPEDGE-2787](https://issues.redhat.com/browse/OCPEDGE-2787): fix: skip MCPs with non-ready nodes during MCN property validation [#31380](https://github.com/openshift/origin/pull/31380)
* [OCPEDGE-2785](https://issues.redhat.com/browse/OCPEDGE-2785): fix: adjusting DaemonSet test to dynamically compute expected pod count [#31378](https://github.com/openshift/origin/pull/31378)
* [OCPCLOUD-3074](https://issues.redhat.com/browse/OCPCLOUD-3074): Validate Azure dual-stack load balancers [#31452](https://github.com/openshift/origin/pull/31452)
* [CNTRLPLANE-2157](https://issues.redhat.com/browse/CNTRLPLANE-2157): Migrate tests of Prometheus, Audit and TLS to OTE [#31360](https://github.com/openshift/origin/pull/31360)
* [TRT-2618](https://issues.redhat.com/browse/TRT-2618): Add env var support to selectively enable resource monitor tests and event collection [#31420](https://github.com/openshift/origin/pull/31420)
* Bug OCPBUGS-104497: Fix [sig-ci] prow job name OS version test for 4.23 rhcos9 [#31481](https://github.com/openshift/origin/pull/31481)
* [OCPBUGS-100392](https://issues.redhat.com/browse/OCPBUGS-100392): Exclude openshift-debug-* namespaces from CPU Partitioning annotation check [#31465](https://github.com/openshift/origin/pull/31465)
* NO-ISSUE: Automated - Update synthetic test data [#31459](https://github.com/openshift/origin/pull/31459)
* Revert "TRT-2869: Revert "NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO"" [#31462](https://github.com/openshift/origin/pull/31462)
* [OCPBUGS-101912](https://issues.redhat.com/browse/OCPBUGS-101912): derive cluster quota from namespace configmaps [#31476](https://github.com/openshift/origin/pull/31476)
* [STOR-3065](https://issues.redhat.com/browse/STOR-3065): Add storage CSI tests for cloning PVC to a larger volume [#31443](https://github.com/openshift/origin/pull/31443)
* [OCPBUGS-100386](https://issues.redhat.com/browse/OCPBUGS-100386): test: scope hosted etcd leader metrics by namespace [#31456](https://github.com/openshift/origin/pull/31456)
* [OCPBUGS-63219](https://issues.redhat.com/browse/OCPBUGS-63219): Remove NLB hairpin workaround from dual-stack test [#31453](https://github.com/openshift/origin/pull/31453)
* [OCPBUGS-99899](https://issues.redhat.com/browse/OCPBUGS-99899): add os name exception for runc jobs [#31479](https://github.com/openshift/origin/pull/31479)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Adding netobserv namespace exception for prometheus endpoint auth [#31447](https://github.com/openshift/origin/pull/31447)
* [OCPBUGS-100388](https://issues.redhat.com/browse/OCPBUGS-100388): Fix project name collision in test framework [#31464](https://github.com/openshift/origin/pull/31464)
* [OCPBUGS-100385](https://issues.redhat.com/browse/OCPBUGS-100385): MonitorTest: measure the union of ClusterOperator wait intervals [#31457](https://github.com/openshift/origin/pull/31457)
* [OCPBUGS-99397](https://issues.redhat.com/browse/OCPBUGS-99397): remove custom MCP and pause master pool in mirror-set tests to prevent PDB drain deadlock and suite timeout [#31408](https://github.com/openshift/origin/pull/31408)
* Revert: Fix APIs for openshift.io must have stable versions check [#31468](https://github.com/openshift/origin/pull/31468)
* [OCPBUGS-99916](https://issues.redhat.com/browse/OCPBUGS-99916): exclude openshift-debug-* namespaces from best-effort QoS invariant [#31437](https://github.com/openshift/origin/pull/31437)
* [TRT-2869](https://issues.redhat.com/browse/TRT-2869): Revert #31440 "NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO" [#31460](https://github.com/openshift/origin/pull/31460)
* [OCPBUGS-100308](https://issues.redhat.com/browse/OCPBUGS-100308): Fix test `APIs for openshift.io must have stable versions` [#31458](https://github.com/openshift/origin/pull/31458)
* [OCPBUGS-99047](https://issues.redhat.com/browse/OCPBUGS-99047): Fix flaky oc adm storage-admin test [#31400](https://github.com/openshift/origin/pull/31400)
* [OCPBUGS-84695](https://issues.redhat.com/browse/OCPBUGS-84695): [TNF] Fix update-setup job discovery to limit check to active job [#31451](https://github.com/openshift/origin/pull/31451)
* [OCPBUGS-99921](https://issues.redhat.com/browse/OCPBUGS-99921): Dump istiod logs and gateway state on GatewayAPI test failure [#31454](https://github.com/openshift/origin/pull/31454)
* NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO [#31440](https://github.com/openshift/origin/pull/31440)
* [OCPBUGS-100183](https://issues.redhat.com/browse/OCPBUGS-100183): Always tear down upgrade tests after setup failures [#31450](https://github.com/openshift/origin/pull/31450)
* [OCPBUGS-98576](https://issues.redhat.com/browse/OCPBUGS-98576): Improve test output for nodes should be ready test [#31419](https://github.com/openshift/origin/pull/31419)
* [OCPBUGS-78480](https://issues.redhat.com/browse/OCPBUGS-78480): handle bookmark events in project watch tests [#31313](https://github.com/openshift/origin/pull/31313)
* NO-JIRA: Update minio image to use source with all supported architectures [#31441](https://github.com/openshift/origin/pull/31441)
* [OCPBUGS-85529](https://issues.redhat.com/browse/OCPBUGS-85529): Fix IPv6 prefix in MultiNetworkPolicy test (/32 → /64) [#31407](https://github.com/openshift/origin/pull/31407)
* [OCPBUGS-99535](https://issues.redhat.com/browse/OCPBUGS-99535): Skip Squid proxy configuration [#31423](https://github.com/openshift/origin/pull/31423)
* NO-ISSUE: Skip additional storage support E2E test for on single-node - MCP rollouts timeout [#31439](https://github.com/openshift/origin/pull/31439)
* [CNTRLPLANE-3789](https://issues.redhat.com/browse/CNTRLPLANE-3789): images: Add squid image used in CAO e2e tests [#31434](https://github.com/openshift/origin/pull/31434)
* [OTA-1814](https://issues.redhat.com/browse/OTA-1814): Skip tests temporarily for the new output of the recommend cmd [#31417](https://github.com/openshift/origin/pull/31417)
* [STOR-3063](https://issues.redhat.com/browse/STOR-3063): Add GCP regional PD e2e test for cross-zone data sync [#31416](https://github.com/openshift/origin/pull/31416)
* [CNTRLPLANE-3741](https://issues.redhat.com/browse/CNTRLPLANE-3741): PKI config tests for service-ca and kube-apiserver-operator [#31341](https://github.com/openshift/origin/pull/31341)
* NO-JIRA: Replace a bug id: 25739 -> 92835 [#31345](https://github.com/openshift/origin/pull/31345)
* [OCPNODE-4055](https://issues.redhat.com/browse/OCPNODE-4055): Add e2e testcase for additional storage support feature [#31399](https://github.com/openshift/origin/pull/31399)
* NO-ISSUE: Automated - Update synthetic test data [#31260](https://github.com/openshift/origin/pull/31260)
* [OCPNODE-4494](https://issues.redhat.com/browse/OCPNODE-4494): e2e test case for RHCOS upgrade from 9 → 10 [#31393](https://github.com/openshift/origin/pull/31393)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#31237](https://github.com/openshift/origin/pull/31237)
* [Full changelog](https://github.com/openshift/origin/compare/a7b3bba9780389699e8426c6d3f1afee8464a5ad...a302321dc817cc65ea1806e167da941ba17d8908)
### [thanos](https://github.com/openshift/thanos/tree/75fa632b483716e53aec19f6adf7d4c4652a4453)
* [OCPBUGS-104611](https://issues.redhat.com/browse/OCPBUGS-104611): vendor: bump vulnerable Go dependencies for CVE remediation [#198](https://github.com/openshift/thanos/pull/198)
* NO-JIRA: [bot] Bump openshift/thanos to v0.42.4 [#196](https://github.com/openshift/thanos/pull/196)
* NO-ISSUE: [bot] Bump openshift/thanos to v0.42.3 [#195](https://github.com/openshift/thanos/pull/195)
* [Full changelog](https://github.com/openshift/thanos/compare/7923992496585d7471b26abbd15bfa7aaa745755...75fa632b483716e53aec19f6adf7d4c4652a4453)
### [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator/tree/ee9cd7aba4e096a9a957386ef20777e8950df352)
* [STOR-2917](https://issues.redhat.com/browse/STOR-2917): Rebase to v1.7.0 for OCP 5.0 [#16](https://github.com/openshift/volume-data-source-validator/pull/16)
* [Full changelog](https://github.com/openshift/volume-data-source-validator/compare/a6c21eee63d1fae58b63d8493aeb0fd662d1c91e...ee9cd7aba4e096a9a957386ef20777e8950df352)