# 4.23.0-ec.1
Created: 2026-09-28 10:52:55 +0000 UTC
Image Digest: `sha256:04c9fd20fe9f5a4978d759448524cafe77096e1c50fe66f79f0eeeb084ecb7cd`
## Changes from 4.23.0-ec.0
### Components
* Kubectl 1.36.2
* Kubernetes 1.36.3
* Kubernetes Tests 1.36.2
* Red Hat Enterprise Linux CoreOS 10.2 upgraded from 10.2.20260825-0 to 10.2.20260918-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| GomaxprocsInjection
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| EtcdBackendQuota
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| GCPSovereignCloudInstall
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| OpenShiftPodSecurityAdmission
(0 tests)| Disabled
(Changed)| Disabled
(Changed)| Enabled| Enabled| Disabled
(Changed)| Disabled
(Changed)| Enabled| Enabled |
| OSStreams
(0 tests)| Enabled
(Changed)| Enabled| Enabled| Enabled| Enabled
(Changed)| Enabled| Enabled| Enabled |
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [d6ec9243](https://github.com/openshift/apiserver-network-proxy/commit/d6ec9243d24050d7d7ad7f939e45f821171f000e) `sha256:11c7d7cf4e747167d9ea2e5dd4e36cdabc4c78ea2ecfea0f7354effef4be89fe`
* [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws) git [278e8c07](https://github.com/openshift/cloud-provider-aws/commit/278e8c07a72a50e7d3f28fc743c38c64f008f5aa) `sha256:4de13124fb761e7b756844002454cc7191103458252d2779d8abc42b145d0e78`
* [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver) git [8b8c4cef](https://github.com/openshift/aws-ebs-csi-driver/commit/8b8c4cef02ec9b670e2709f2aacc0ed72420be90) `sha256:4a6caac761f81b10db90e53cf3ef21e7176afdffdd2d869a0c487726640b355a`
* [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider) git [9b18930d](https://github.com/openshift/aws-encryption-provider/commit/9b18930d2db9521a08faa7165488bdcf6482b9cf) `sha256:9a2e666ab6e50440b34e8407074fa9029eff0151ba9eaf983478c6c179b12df8`
* [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws) git [9f2e9b3c](https://github.com/openshift/machine-api-provider-aws/commit/9f2e9b3c46b391c7219257a426ad80ca8a296af0) `sha256:1664c0af00bbfa8e48af0091e508973c0ef5bf972e1f08fedb08b731d81b44ce`
* [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [0d33a459](https://github.com/openshift/aws-pod-identity-webhook/commit/0d33a4596e2a22d188fe74c4a6497c37c2528c1f) `sha256:4dab78190030d10867c4f4b43f0e7e4dcdfd27c3cf19b4c04a9156f3222166c7`
* [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure) git [63731729](https://github.com/openshift/cluster-api-provider-azure/commit/63731729974bff3be90ae2206c53d760572499d1) `sha256:c7b9bd2121dcae95b09db49da7f1277c9101412455c2ef53a0999d2167fadc1e`
* [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver) git [9689f030](https://github.com/openshift/azure-file-csi-driver/commit/9689f03011ce700b3bffc32791af839e80d0e0ab) `sha256:dfb331142714b86638097c6bbbe45ca3a2d084098483f73633f98b7855f9ca23`
* [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure) git [4ff6c6b8](https://github.com/openshift/machine-api-provider-azure/commit/4ff6c6b8730c1253918f1f5261b9c12cab2e5903) `sha256:c91278d229998d23294efe7158fb9685272ef54ed9ac7a6f680e5bf5e9caf190`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:3ff150cc417b80b595fc2d391dd1f5f1a3ad7efd12bb8550a36d735a35b37741`
* [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity) git [2b4705c5](https://github.com/openshift/azure-workload-identity/commit/2b4705c5d999339ce17d47a9b2a637d238891dae) `sha256:00e1c70e7b9f19bd11bb338e93353ddcbda203c323a60a5c14685c3303130d36`
* [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3) git [ad4f1c2b](https://github.com/openshift/cluster-api-provider-metal3/commit/ad4f1c2bd7b527437496b71b5b93ee1439243d65) `sha256:d7a3c170d2dc90b3064bb9b87fe4e2975ebf27fa72b3d97fc5dcad723bda79d1`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [f2b0db19](https://github.com/openshift/cluster-api-provider-baremetal/commit/f2b0db1919fff1344bc68948894c6775c0bf24a3) `sha256:7961dcaa5909eed507c221087b6dea3637c825a90372e83c40a7089a761d64af`
* [baremetal-operator](https://github.com/openshift/baremetal-operator) git [34bbeb37](https://github.com/openshift/baremetal-operator/commit/34bbeb376836bf01793d4e70d29065d619ebcaa1) `sha256:0f50a4a2d760f5963c599db33c218eb2cdc92f895b0c807c25a8fe7b450dd62d`
* [cli](https://github.com/openshift/oc) git [4b0a124d](https://github.com/openshift/oc/commit/4b0a124d300cef187037bda6f1b04caa69ab8b62) `sha256:e0817f459fb4de691a15231cb9597fae0406544211b42905ec738d6a9f6a2236`
* [cli-artifacts](https://github.com/openshift/oc) git [4b0a124d](https://github.com/openshift/oc/commit/4b0a124d300cef187037bda6f1b04caa69ab8b62) `sha256:a475c0e807a29b2bd13403a82188cb7bcca7d03def92d5299fc1f9534cfd7e75`
* [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator) git [b187feee](https://github.com/openshift/cloud-credential-operator/commit/b187feee66f4ce0f992059b21a97a2ae88e4cdd9) `sha256:7876aff14dac3df2a2c0b7767ba6f48fb674f3c227dbcfc9d72459921d4ac3cd`
* [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller) git [7afccf2d](https://github.com/openshift/cloud-network-config-controller/commit/7afccf2d78f6cb5dd3181de1588c5063bd995d7d) `sha256:4e0890fea1c7ba87f916b9bbb62dd035ac65d0d1f5363ba745582b088732df7a`
* [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler) git [f393f542](https://github.com/openshift/kubernetes-autoscaler/commit/f393f54229e6c3ae74c35ae72012af92d31c03d3) `sha256:b5f530096d35aa0996c6bf6f6f68517738198c73e074fc3010576fe66f9cf4a1`
* [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator) git [e48fe117](https://github.com/openshift/cluster-autoscaler-operator/commit/e48fe1179ad671757b5a40688e2d125c1f326e8b) `sha256:d2d848fb9c59258e785792107979d90b0e5126ca316f333213f8985fd592e919`
* [cluster-capi-controllers](https://github.com/openshift/cluster-api) git [303d9786](https://github.com/openshift/cluster-api/commit/303d9786a5017d299b6e7fc702bb92f5cb4550cf) `sha256:e8c1c407d9bfb52b3567fb391392dc4c1f49340fb92c1456e4565db3ee0efda0`
* [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator) git [0da197f8](https://github.com/openshift/cluster-cloud-controller-manager-operator/commit/0da197f80d941f537331f173bc7613d6729a2767) `sha256:ed0b69b9453a98f55bfb652e3e953b6f8d6de11cfee9f92bdac7f62e7a17daea`
* [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator) git [35ec0224](https://github.com/openshift/cluster-csi-snapshot-controller-operator/commit/35ec0224eb0e5219d5eae012fb703223a6f3e1f7) `sha256:f27f10450f96343364167aba19d0553ca9115bdf8da1571ec5a654ac0d43c855`
* [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator) git [c0ed09e3](https://github.com/openshift/cluster-dns-operator/commit/c0ed09e329e9001629518604a58205e3fbe8284a) `sha256:3f25404404a58830082d3666e097682f0645ac99820c5b81531d69a43b973eae`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [8da2f1fc](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/8da2f1fcb1e76e8b1b97b16ca7bbfa7116287eb8) `sha256:2484d8bf16e8ff889ffaaf081f5ca50bb89123c238c429dbefebc756889caf14`
* [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller) git [469bbf21](https://github.com/openshift/cluster-policy-controller/commit/469bbf211d35eee0df4422bda7e9e600b080f0f2) `sha256:9447e70347b7c3534975bf018e7ff6cf20e548bb0911d95ad0f90f6c03941ce5`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:2a0e38939304a52641a7423b54650b48370c5888fe8e8733822534bd91b513f1`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [ce80869a](https://github.com/openshift/configmap-reload/commit/ce80869a83b55ebbdc21a5550ec5747645203bd2) `sha256:4e9028a2586478b166235d1ccd8a739ef973ae7b15841b9ad0e9eb3ef0654ae4`
* [console-operator](https://github.com/openshift/console-operator) git [63049512](https://github.com/openshift/console-operator/commit/630495120bc5ddc9e05cd6defc2102690ced6301) `sha256:d2e46c4fed862eadc205de5cf9c2f3c68af79c1b68d93645908fa21be594679f`
* [coredns](https://github.com/openshift/coredns) git [37aaba89](https://github.com/openshift/coredns/commit/37aaba896e97f4b9a091aab6d36f2213b8854474) `sha256:a57efbbf6fea57c2ba411b614dab7f4da733773721a7931d4125732f14885360`
* [csi-driver-manila](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:c1306d712f31a300e5433b62fd7a40aefa298e89c53f043227ccf9a76b3e000d`
* [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs) git [beb9567b](https://github.com/openshift/csi-driver-nfs/commit/beb9567b4ef15656a88c1c71e0b08e7bf2e96aaa) `sha256:379b82c2f9f0cb848853e7922e2da888da17ad892c8fae9139b806e36a1a70b2`
* [csi-external-attacher](https://github.com/openshift/csi-external-attacher) git [3fd668b3](https://github.com/openshift/csi-external-attacher/commit/3fd668b3f07dd382e5c7b6239d50f7988f652e64) `sha256:06791b1bd2f3d7be79e3e3ba479c965da0ec42e5e8360f3b87d44312ad4c0e32`
* [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner) git [7ff338c9](https://github.com/openshift/csi-external-provisioner/commit/7ff338c9d1296f0e5d4d8080a76bb191c8f3be30) `sha256:be143d5506a95c45eb1c99be1b72497fe88ec7a31acd1d228217bea46426f2b7`
* [csi-external-resizer](https://github.com/openshift/csi-external-resizer) git [14aa7028](https://github.com/openshift/csi-external-resizer/commit/14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf) `sha256:a388f1f57f3a0ebaeec7d41e317afa45f9531c86b97408cbfc9f69a5708e6a7e`
* [csi-external-snapshotter](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:c46e68d9cbaf25c5348829abd9e0dbe6c50f99c95f53957016b07228e41991b8`
* [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar) git [5766960d](https://github.com/openshift/csi-node-driver-registrar/commit/5766960d82ffb9ef84d15e903ae57d0a6781ef11) `sha256:348b93ba89902cca16f8a4cd59fa9ef2fd5789235208c933f27799b38636e775`
* [csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter) git [a019d1a9](https://github.com/openshift/csi-external-snapshotter/commit/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2) `sha256:d6c10f3866314eb02e5fd07d7bf942c3714a33d3611b2ae7f6ad11f5deccaa65`
* [deployer](https://github.com/openshift/oc) git [4b0a124d](https://github.com/openshift/oc/commit/4b0a124d300cef187037bda6f1b04caa69ab8b62) `sha256:6ed37f53a598f07084611eb2ebe49167dca84eac7e01e4b97aacd0dc75a554c1`
* [driver-toolkit](https://github.com/openshift/driver-toolkit) git [b63b175a](https://github.com/openshift/driver-toolkit/commit/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a) `sha256:cebb28f3a4de45017d566c6637176d21a19a33ded21ee8deca196b956086d4b8`
* [etcd](https://github.com/openshift/etcd) git [609b11ed](https://github.com/openshift/etcd/commit/609b11ed8fc404fb95572d7c87e3243a1206cdb7) `sha256:d119023149ee77d6b7289f28d6800b0611e6a5273746aa76c6db5a1b1eaea182`
* [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp) git [51c32646](https://github.com/openshift/cloud-provider-gcp/commit/51c326465b3160124b8097953b42e44f1056da5a) `sha256:ca0d62fb0ff4f2e47e913948e7ced5c473e136a9eee583da2e346d6c94467786`
* [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp) git [dbcbfe70](https://github.com/openshift/cluster-api-provider-gcp/commit/dbcbfe70efa75f192309f2d0f8daae2c6a441e90) `sha256:3440ff8ec38f6fb9f5ca36abe29b8f29509bbe6784bfa878ff2d30ad2fb13338`
* [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp) git [91033fc5](https://github.com/openshift/machine-api-provider-gcp/commit/91033fc5b42f58acdad7be8c89a0012f5f2c9b5b) `sha256:12f767664eadbdf0947c04ece92947f809c934dc26d7cccca034bcfbe22d0fa4`
* [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver) git [049c0b96](https://github.com/openshift/gcp-pd-csi-driver/commit/049c0b96742c40fdd4384920afe17cefa5fa3d27) `sha256:a732c43448a5df4867f26115188f2931b36cabd2fd87264f0d6725bbb4d854ce`
* [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook) git [4501ff2f](https://github.com/openshift/gcp-workload-identity-federation-webhook/commit/4501ff2f53576c31df0511b69444e65e1eeba745) `sha256:e2a8a766e161bca3001f0b9b71b17ea6fa09bc9d141f7d8dfb0f335ff00fdee7`
* [haproxy-router](https://github.com/openshift/router) git [33812291](https://github.com/openshift/router/commit/3381229146657d2e6bd94115dda0885f25cb3bed) `sha256:34f4f907abf8ea783e51921381a84a387766581108a45cbdb21c08e81c4a4e20`
* [haproxy-router-haproxy28](https://github.com/openshift/router) git [33812291](https://github.com/openshift/router/commit/3381229146657d2e6bd94115dda0885f25cb3bed) `sha256:4e9d6a61ebf2e3625f61fb1243e9463cfe2a2ccfe2add061305e768799717e2c`
* [haproxy-router-haproxy32](https://github.com/openshift/router) git [33812291](https://github.com/openshift/router/commit/3381229146657d2e6bd94115dda0885f25cb3bed) `sha256:68554eba5e9d9108a9ff6cd8b2db9e74ad8f56f6b6d85a2d01fa3b75c4bf3683`
* [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm) git [11bc35dd](https://github.com/openshift/cloud-provider-ibm/commit/11bc35dd6fd5163259023a6f1dfcc59ce813ab5f) `sha256:8e725a4a85a06ba66113339b822814196fe9b807cc00355bd51c80a08c4c195e`
* [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver) git [3a89d7d1](https://github.com/openshift/ibm-vpc-block-csi-driver/commit/3a89d7d17d25727270414b07d3daaa3bc329d743) `sha256:9a16d5c177b5318d9837a1117356afb60314a8da9e41a72cdb03e3b593920871`
* [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator) git [be4fd017](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/commit/be4fd01725ce5ab0b47f846c905a349aeee8ab53) `sha256:d036435801870b4c29d755b44f4981fc40658314281faeb7e03eca2a277bbab4`
* [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud) git [2615d13b](https://github.com/openshift/machine-api-provider-ibmcloud/commit/2615d13b730255b21ccb401d3dc039006c54a4fe) `sha256:a01098f46ebc3ff6a633a5e161455e8e5d859836043135d288115cef43f9d3da`
* [insights-runtime-exporter](https://github.com/openshift/insights-runtime-extractor) git [7c9aa149](https://github.com/openshift/insights-runtime-extractor/commit/7c9aa14915e639edd20bc0869747487e2e73fe51) `sha256:0d17bfbf28b1ba7021e11d9a5563cdb40634a6a6667c35d502ce5e25550c7926`
* [insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor) git [7c9aa149](https://github.com/openshift/insights-runtime-extractor/commit/7c9aa14915e639edd20bc0869747487e2e73fe51) `sha256:0cf5a289ef6a5654a3b3dbfaf9bc8b76e2384ecf554ea5c46d374049fc834fa6`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [f8e41b2e](https://github.com/openshift/ironic-rhcos-downloader/commit/f8e41b2ed8915474a99e3eb34b54692afb0611da) `sha256:a6c9dcd228b987547edffabff08edb62225afc6ec153e0e76d3008c7642447ca`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [486a0418](https://github.com/openshift/ironic-static-ip-manager/commit/486a041897d703d55ef59c98e2b20a01588a0b4c) `sha256:54fe1adce59464e06f378dcdb5585a8c2f0cd7dbc65672f9770f3b43f33547f0`
* [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server) git [3d2e9cd0](https://github.com/openshift/kubernetes-metrics-server/commit/3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71) `sha256:d5b36a18f900569574967517a2a5d9e5f2a553cc69988f969ac03755e3d5809a`
* [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [43c114bc](https://github.com/openshift/kube-rbac-proxy/commit/43c114bc124f59e2fc3223dea8e0a8f4cdeed18d) `sha256:24a53ad4ed6a3847ddb0f81eed7ca3ac3df8913d42982ea0e9ea80ddd1f55064`
* [kube-state-metrics](https://github.com/openshift/kube-state-metrics) git [019ecc7d](https://github.com/openshift/kube-state-metrics/commit/019ecc7d533333dfd3bf8893e78cd7ec6e282f01) `sha256:64185e343c1ebea12fe97e34f8676ba69db1ddeb9a59f6a8bf3ab07e9a7f8dba`
* [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt) git [5eb884ab](https://github.com/openshift/cloud-provider-kubevirt/commit/5eb884abcd2ff17ae8d7b2691ca12494597c08a6) `sha256:eefacdcc6eba018a1a56d39e10dc407adc5f974fbd84f5d17ee47bc9b72b380e`
* [machine-image-customization-controller](https://github.com/openshift/image-customization-controller) git [e49b0968](https://github.com/openshift/image-customization-controller/commit/e49b096880f17296d42a77443dc14d732683333d) `sha256:8e0d0408e24a14f56c34da6d5b7d4c5384da9961d65b99df50292d0d71fc47fe`
* [machine-os-images](https://github.com/openshift/machine-os-images) git [bf618aac](https://github.com/openshift/machine-os-images/commit/bf618aac93c71a56e8249669c579f0a782742e2e) `sha256:01a68044ae00fd83e9928802887ff2dc99d27b4ccc89a324fa4e897a088da30b`
* [metallb-frr](https://github.com/openshift/frr) git [54a6ea48](https://github.com/openshift/frr/commit/54a6ea48902d81460536b81ea6bdceb89c12e622) `sha256:c636f9212022818dbdc1518ab862d6de7cc5ec68bc738e53722b67d59e5b97c4`
* [network-tools](https://github.com/openshift/network-tools) git [0b53ac3d](https://github.com/openshift/network-tools/commit/0b53ac3dccf59cd169555bf18c207122374bf003) `sha256:0e0c59397232056f49efb5b2a85cc11ff2454a674df112518aebb3b42a057a7e`
* [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [dc584c6b](https://github.com/openshift/cloud-provider-nutanix/commit/dc584c6b2e895a6217f9e2dbed765209af1898a1) `sha256:6badfa4b905c5f7d034d8e55570acd1c0665194688ad7b66afb4badfbe7e9b37`
* [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix) git [249b7c8e](https://github.com/openshift/machine-api-provider-nutanix/commit/249b7c8edfca8f25413dc76bc5a216fbe12a9ab1) `sha256:a80b72345da938c71d245641cbecfaabc09df48d231d38e098d2a10f8b7e1e8d`
* [openshift-apiserver](https://github.com/openshift/openshift-apiserver) git [ab031522](https://github.com/openshift/openshift-apiserver/commit/ab0315228cde432c8cd62df012b791a66a72c7b3) `sha256:68158934419e66ac85f86de08abcb92fda93fcd5eac5cd34c5055be879e82b27`
* [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [3b4ea3e7](https://github.com/openshift/openshift-state-metrics/commit/3b4ea3e753d97fea66e0f52c8282a711358b4ff7) `sha256:7b6e7617470b2d48ed69dc275e418172aab8b554377356537d91ae6a4a0b0e8b`
* [openstack-cinder-csi-driver](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:4cc7583dd2a12dad8815b69b8c67b307ed62a7e9c23728d48f141dc41a1f0217`
* [openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack) git [aa9a8100](https://github.com/openshift/cloud-provider-openstack/commit/aa9a8100e87ff13abf4dd6343c84c9f4948debef) `sha256:4559c5562c2e5d34d59fe4bcbf8dacd5477082267ff1560db43c0feb269d8640`
* [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:86806215f0df9b5aedf0ad2d741bda6eac9c398438ab3ec967a4827ecff4873d`
* [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller) git [58dbc048](https://github.com/openshift/openstack-resource-controller/commit/58dbc0482c144c21effee2476947889122a518eb) `sha256:c824d0ddcae3bd7038af129445a9e4be4b7b494ab66ef830f80f4a61945de658`
* [operator-marketplace](https://github.com/operator-framework/operator-marketplace) git [fa9e19b2](https://github.com/operator-framework/operator-marketplace/commit/fa9e19b2ae7ad8de20b345e3bd736923f5c516cc) `sha256:04cce16da3f4a5871330653ba36739dde69ec6adc389628106a5a78730051c60`
* [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator) git [f90431bf](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/commit/f90431bfe8ca93850450b2b24fae152d2385ca08) `sha256:572a913b6eaa43d0ed39c7f7f9f961284d9f8832ed20e6dd9eb9433298defe3c`
* [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs) git [18eb5238](https://github.com/openshift/cloud-provider-powervs/commit/18eb5238fb2c86632edb24175f536d815f28ddf6) `sha256:883cd06573d41b63feaee747beceb7a217c1ae130fa5d0c50e01b0f4fd402a48`
* [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs) git [28c928ff](https://github.com/openshift/machine-api-provider-powervs/commit/28c928ff78def160837170991f084b0fe71ca9be) `sha256:069614501eebfe194dfe7e488035403624fe73186c8e02b00cd5767511fb1473`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [4ab9ff73](https://github.com/openshift/prom-label-proxy/commit/4ab9ff73c665319352288fe0b9b9e1df71832525) `sha256:ce957a428481ab6d65e6cfed811e29bea2c5220d7a116eea973a43a4de656437`
* [prometheus](https://github.com/openshift/prometheus) git [01d83356](https://github.com/openshift/prometheus/commit/01d8335673aa6f88f5742ef510e133efee88a7bf) `sha256:f173e6de8cc8838d1e594526ffc68553ce507c794c476a6c0dd484478755ac9d`
* [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager) git [89bdff8b](https://github.com/openshift/prometheus-alertmanager/commit/89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce) `sha256:21d57157ccba14c8b80c13c2a12bedacd6305066212eb36f39de86181c4d1b6f`
* [prometheus-config-reloader](https://github.com/openshift/prometheus-operator) git [67895c7c](https://github.com/openshift/prometheus-operator/commit/67895c7c968f42e97efec58f4140fffae4832028) `sha256:0c1b0e8490c0e5f6a413fc30151fbd74e3a49a32ce5533fef0df1daa153d409e`
* [prometheus-operator](https://github.com/openshift/prometheus-operator) git [67895c7c](https://github.com/openshift/prometheus-operator/commit/67895c7c968f42e97efec58f4140fffae4832028) `sha256:58605134c290444b3e595579be822c78380e1311e631b0e428c8dffe7ca44275`
* [prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator) git [67895c7c](https://github.com/openshift/prometheus-operator/commit/67895c7c968f42e97efec58f4140fffae4832028) `sha256:12513b023cc0bdf9dd148d988f466b46e47d7921a3197ca59300d4a71efede61`
* [route-controller-manager](https://github.com/openshift/route-controller-manager) git [59697cf7](https://github.com/openshift/route-controller-manager/commit/59697cf7af4517dd44e28179a57f7f35b6ea0e22) `sha256:2117d1b5b3d23a9daeaf7acd1c5d03f306c32a5e68d021619536803a5341df16`
* [service-ca-operator](https://github.com/openshift/service-ca-operator) git [ed872ba1](https://github.com/openshift/service-ca-operator/commit/ed872ba14b615ca5726ae90e987268877a0b0b20) `sha256:e7a5bac908f8580c4a4bb9f3d13774d7ccbc799de841dbcc195d57e7d453fef7`
* [telemeter](https://github.com/openshift/telemeter) git [22ba1701](https://github.com/openshift/telemeter/commit/22ba1701333f3fd26490cc15b89ddf21df3f67f6) `sha256:7bd72d4c5719d0eff7adbc04b24223668a40f1a4b70de6d85dccd26e3a9c94c8`
* [tools](https://github.com/openshift/oc) git [4b0a124d](https://github.com/openshift/oc/commit/4b0a124d300cef187037bda6f1b04caa69ab8b62) `sha256:55103ee6ef5655b2d8f39fb86b04ed552d12dc44926f8756dead6885dead3924`
* [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator) git [ee9cd7ab](https://github.com/openshift/volume-data-source-validator/commit/ee9cd7aba4e096a9a957386ef20777e8950df352) `sha256:0ccb562c6afc8cbf36d0edfdc94e59ae0f3318a5c5892803c0a46c2ed7c2d128`
* [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere) git [eb29de19](https://github.com/openshift/cloud-provider-vsphere/commit/eb29de194594bad8e5bc572102f1008cb26655a7) `sha256:636366c251309348c5894547a07f8266deb43d98b1777eaa81d54b1ec41db4d6`
* [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere) git [557fdf1a](https://github.com/openshift/cluster-api-provider-vsphere/commit/557fdf1a9a3540d9aa8f3a81e4a950673a416a80) `sha256:a9de73f936fdc30adae517655c7dc363156e6f82997d5471512ff308f7116524`
* [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator) git [aa279467](https://github.com/openshift/vmware-vsphere-csi-driver-operator/commit/aa27946700642a9c8e518e130673097b38a2f8bb) `sha256:a2fd64d96942f254ae82923414adc1a59a3e3108d3af255807f7f4061540b28b`
* [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector) git [14a2d338](https://github.com/openshift/vsphere-problem-detector/commit/14a2d33817c1ddd1d753cc76decea059376e30c9) `sha256:5a6d4f4a37e626827da3442823a4ad515ce50649c6fac463bfae852adf42ce50`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/8177722b388c34c334961352e9ab471ed4f8e95c)
* [OCPBUGS-87328](https://issues.redhat.com/browse/OCPBUGS-87328): Updating ose-agent-installer-api-server-container image to be consistent with ART for 5.0 [#10434](https://github.com/openshift/assisted-service/pull/10434)
* [OCPBUGS-120841](https://issues.redhat.com/browse/OCPBUGS-120841): Fix NUMAResourcesOperator CR name so it can be applied [#10923](https://github.com/openshift/assisted-service/pull/10923)
* [OCPBUGS-107941](https://issues.redhat.com/browse/OCPBUGS-107941): Bump go.opentelemetry.io/otel to v1.44.0 for CVE-2026-41178 [#10855](https://github.com/openshift/assisted-service/pull/10855)
* [OCPBUGS-120739](https://issues.redhat.com/browse/OCPBUGS-120739): added missing subscription name for lvms-operator [#10916](https://github.com/openshift/assisted-service/pull/10916)
* [Full changelog](https://github.com/openshift/assisted-service/compare/a6888f164db6d9eb0eda1a18269ad1b6b97a6261...8177722b388c34c334961352e9ab471ed4f8e95c)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/fa7eb52b083a161b122e1c543d487edb3de0955c)
* [OCPBUGS-87444](https://issues.redhat.com/browse/OCPBUGS-87444): Updating ose-agent-installer-csr-approver-container image to be consistent with ART for 5.0 [#2173](https://github.com/openshift/assisted-installer/pull/2173)
* [OCPBUGS-87377](https://issues.redhat.com/browse/OCPBUGS-87377): Updating ose-agent-installer-orchestrator-container image to be consistent with ART for 5.0 [#2172](https://github.com/openshift/assisted-installer/pull/2172)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/880389d450131a12a888202877b28dbae61ac0da...fa7eb52b083a161b122e1c543d487edb3de0955c)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/b1d92ca20c3a276744861d8fb77745bb8f42ea9a)
* [OCPBUGS-87404](https://issues.redhat.com/browse/OCPBUGS-87404): Updating ose-agent-installer-node-agent-container image to be consistent with ART for 5.0 [#1491](https://github.com/openshift/assisted-installer-agent/pull/1491)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/aeec165131a4c528174a58a011d1c3c31cfd7cc1...b1d92ca20c3a276744861d8fb77745bb8f42ea9a)
### [agent-installer-ui](https://github.com/openshift-assisted/assisted-installer-ui/tree/d085665f508757802bb8686c3dd39a8f1088fc06)
* [OCPBUGS-121378](https://issues.redhat.com/browse/OCPBUGS-121378): Do not show IRI custom manifests in the disconnected UI (#4048) (#4053) [#4048](https://github.com/openshift-assisted/assisted-installer-ui/pull/4048)
* Remove stale OCM_REFRESH_TOKEN code (#4024) [#4024](https://github.com/openshift-assisted/assisted-installer-ui/pull/4024)
* [OCPBUGS-115122](https://issues.redhat.com/browse/OCPBUGS-115122): Show IPv6 Technology Preview badge in Subnets dropdown for single-cluster only (#4039) [#4039](https://github.com/openshift-assisted/assisted-installer-ui/pull/4039)
* [OCPBUGS-120719](https://issues.redhat.com/browse/OCPBUGS-120719): Change reuse SSH key label in OVE (#4037) [#4037](https://github.com/openshift-assisted/assisted-installer-ui/pull/4037)
* Add LVM as an operator for OVE (#4004) [#4004](https://github.com/openshift-assisted/assisted-installer-ui/pull/4004)
* Allow LSO to be selected as a standalone operator (#4002) [#4002](https://github.com/openshift-assisted/assisted-installer-ui/pull/4002)
* Update OWNERS file (#3995) [#3995](https://github.com/openshift-assisted/assisted-installer-ui/pull/3995)
* [Full changelog](https://github.com/openshift-assisted/assisted-installer-ui/compare/93a1cdfd9a5f0a4b6be2f1fac45e151b7658d2d4...d085665f508757802bb8686c3dd39a8f1088fc06)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/6fe56d037dc82c8babc6d70228dc89d3606385cd)
* 🌱 OCPBUGS-119953: UPSTREAM: <carry>: Remove upstream .github files unused in OpenShift CI [#634](https://github.com/openshift/cluster-api-provider-aws/pull/634)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/e345a83efda50037cd59ae0741a62cf7169f5def...6fe56d037dc82c8babc6d70228dc89d3606385cd)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, csi-driver-manila-operator, gcp-pd-csi-driver-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/57a5d72c6758cccafb9f14b1c28d1b2ea4510364)
* [OCPBUGS-120666](https://issues.redhat.com/browse/OCPBUGS-120666): fix(gcp-pd): do not apply guest-cluster resources against the management cluster on HyperShift [#623](https://github.com/openshift/csi-operator/pull/623)
* [OCPBUGS-114002](https://issues.redhat.com/browse/OCPBUGS-114002): GCP-1074: feat(gcp-pd): enable HyperShift support for GCP PD CSI driver operator [#607](https://github.com/openshift/csi-operator/pull/607)
* [OCPBUGS-111893](https://issues.redhat.com/browse/OCPBUGS-111893): Add proxy hook for HyperShift CSI driver controller deployments [#599](https://github.com/openshift/csi-operator/pull/599)
* [Full changelog](https://github.com/openshift/csi-operator/compare/9ce1841451cafd77907d38c9bf6062aeccf24eaf...57a5d72c6758cccafb9f14b1c28d1b2ea4510364)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/d04b52621a47868d907e986b37a01fcddeb8a23f)
* [OCPBUGS-115308](https://issues.redhat.com/browse/OCPBUGS-115308): default max-pods to 250 for Custom AMI family [#42](https://github.com/openshift/aws-karpenter-provider-aws/pull/42)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/dc822233cc526b6cc55f20009a4c1b034f245133...d04b52621a47868d907e986b37a01fcddeb8a23f)
### [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler/tree/9b33cce5107d71df5c65dbca6c08f1f71d9e6e8a)
* [OCPBUGS-87280](https://issues.redhat.com/browse/OCPBUGS-87280): Updating aws-node-termination-handler-container image to be consistent with ART for 5.0 [#11](https://github.com/openshift/aws-node-termination-handler/pull/11)
* [Full changelog](https://github.com/openshift/aws-node-termination-handler/compare/e4ff2aaec292db42de9f3eef4908ba1c421a2a6c...9b33cce5107d71df5c65dbca6c08f1f71d9e6e8a)
### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/95f0a12ce3f7f3770d099d3610a376f06cc713df)
* [OCPBUGS-122326](https://issues.redhat.com/browse/OCPBUGS-122326): skip public ip check for azure stack [#216](https://github.com/openshift/cloud-provider-azure/pull/216)
* [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/b99e4ce4ff5c2665b273384b0673824833c40ce5...95f0a12ce3f7f3770d099d3610a376f06cc713df)
### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/64091ea10ac93fd62b83c63b4b7379063aca9058)
* [OCPBUGS-121351](https://issues.redhat.com/browse/OCPBUGS-121351): UPSTREAM: 3754: chore: upgrade Azure cloud provider lib- [#181](https://github.com/openshift/azure-disk-csi-driver/pull/181)
* [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/c5e303bb0c6a55332637d7a583cfceec1a3a900b...64091ea10ac93fd62b83c63b4b7379063aca9058)
### [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms/tree/6409e379fa979104a9515108608c22492bb803a7)
* [CNTRLPLANE-4025](https://issues.redhat.com/browse/CNTRLPLANE-4025): support sovereign Managed HSM endpoints [#55](https://github.com/openshift/azure-kubernetes-kms/pull/55)
* [Full changelog](https://github.com/openshift/azure-kubernetes-kms/compare/f7f447daa864d71c16d8ccb312b2fce91ebc0c2f...6409e379fa979104a9515108608c22492bb803a7)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/2060c6b26391f7dacd6fe19920b8b267f5f8f8b9)
* [OCPBUGS-126682](https://issues.redhat.com/browse/OCPBUGS-126682): Inject the pull-secret as podman secret in the agent-installer-ui container [#10887](https://github.com/openshift/installer/pull/10887)
* [OCPBUGS-120677](https://issues.redhat.com/browse/OCPBUGS-120677): vsphere: retry and throttle vCenter lookups during UPI VM creation [#10849](https://github.com/openshift/installer/pull/10849)
* [OCPBUGS-115147](https://issues.redhat.com/browse/OCPBUGS-115147): Missing ability to not install Network Observability during installation [#10822](https://github.com/openshift/installer/pull/10822)
* [OCPBUGS-114620](https://issues.redhat.com/browse/OCPBUGS-114620): bump openshift api for gcd feature gate [#10845](https://github.com/openshift/installer/pull/10845)
* [OCPBUGS-119104](https://issues.redhat.com/browse/OCPBUGS-119104): gcp: allow GCD load balancer health-check firewall ranges [#10852](https://github.com/openshift/installer/pull/10852)
* Revert "TRT-2925: Revert "CORS-4441: Bump Azure Marketplace Images" (#10802)" [#10819](https://github.com/openshift/installer/pull/10819)
* [TRT-2925](https://issues.redhat.com/browse/TRT-2925): Revert "CORS-4441: Bump Azure Marketplace Images" (#10802) [#10814](https://github.com/openshift/installer/pull/10814)
* [OCPBUGS-113634](https://issues.redhat.com/browse/OCPBUGS-113634): images: add BUILD_VERSION arg [#10801](https://github.com/openshift/installer/pull/10801)
* [CORS-4441](https://issues.redhat.com/browse/CORS-4441): Bump Azure Marketplace Images [#10802](https://github.com/openshift/installer/pull/10802)
* [OCPBUGS-113641](https://issues.redhat.com/browse/OCPBUGS-113641): Update timeout in GetMarketplaceImage to 5 minutes [#10803](https://github.com/openshift/installer/pull/10803)
* [Full changelog](https://github.com/openshift/installer/compare/4f7b5547859546c12e3250b56728a78d923d8c3b...2060c6b26391f7dacd6fe19920b8b267f5f8f8b9)
### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/3a261a6f4a6211e8f4031611104ced4def436dde)
* [OCPBUGS-112466](https://issues.redhat.com/browse/OCPBUGS-112466): Cloud Platforms: Filter out node's own IP from Upstreams [#400](https://github.com/openshift/baremetal-runtimecfg/pull/400)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/75dd020cfa556db528be28e0fd456aaa023a973e...3a261a6f4a6211e8f4031611104ced4def436dde)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/848c4c96d8e322b7987e44eecc4ad30e64ce5ed4)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#998](https://github.com/openshift/cluster-authentication-operator/pull/998)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/954abf76eb0000ff218257489783c8e61dc115b8...848c4c96d8e322b7987e44eecc4ad30e64ce5ed4)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/d7957265fdafbbb93bb2a0d4723fc9719da1378d)
* [OCPBUGS-123600](https://issues.redhat.com/browse/OCPBUGS-123600): Add bmo_validations and ncsi_reject_poweroff OTE test [#657](https://github.com/openshift/cluster-baremetal-operator/pull/657)
* [OCPBUGS-115281](https://issues.redhat.com/browse/OCPBUGS-115281): Increase firmware e2e timeouts and add HPE Mellanox NIC bastion mapping [#651](https://github.com/openshift/cluster-baremetal-operator/pull/651)
* [OCPBUGS-114007](https://issues.redhat.com/browse/OCPBUGS-114007): Add batched firmware update tests (bmc+bios+nic) [#648](https://github.com/openshift/cluster-baremetal-operator/pull/648)
* [OCPBUGS-111889](https://issues.redhat.com/browse/OCPBUGS-111889): drop IRONIC_INSECURE from BMO [#644](https://github.com/openshift/cluster-baremetal-operator/pull/644)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/ce1bd1f1ff5eb9335f13fa3839add119bb51f946...d7957265fdafbbb93bb2a0d4723fc9719da1378d)
### [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap/tree/9573b4d6ef1638c013cde95ec29ddcc80e10cf87)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#147](https://github.com/openshift/cluster-bootstrap/pull/147)
* [OCPBUGS-87218](https://issues.redhat.com/browse/OCPBUGS-87218): Updating ose-cluster-bootstrap-container image to be consistent with ART for 5.0 [#132](https://github.com/openshift/cluster-bootstrap/pull/132)
* [Full changelog](https://github.com/openshift/cluster-bootstrap/compare/7b1593a47898b6a97dc457efaca464624e9f2afa...9573b4d6ef1638c013cde95ec29ddcc80e10cf87)
### [cluster-config-api](https://github.com/openshift/api/tree/31af9f93e31ecd483504b3302d78f67c5a077a9e)
* [OCPBUGS-114877](https://issues.redhat.com/browse/OCPBUGS-114877): move empty CRIOCredentialProviderConfig CR to run-level 0000_10 [#3019](https://github.com/openshift/api/pull/3019)
* [OCPBUGS-114620](https://issues.redhat.com/browse/OCPBUGS-114620): Promote GCD to Default [#3017](https://github.com/openshift/api/pull/3017)
* [OCPBUGS-83412](https://issues.redhat.com/browse/OCPBUGS-83412): Disable PSA for placeholder for 5.0 [#3002](https://github.com/openshift/api/pull/3002)
* [OCPBUGS-112657](https://issues.redhat.com/browse/OCPBUGS-112657): Handle Sippy date-only format in featuregate-test-analyzer [#3007](https://github.com/openshift/api/pull/3007)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default for Hypershift [#2997](https://github.com/openshift/api/pull/2997)
* [TRT-2908](https://issues.redhat.com/browse/TRT-2908): Revert openshift/api#2986 [#2992](https://github.com/openshift/api/pull/2992)
* [CNTRLPLANE-3609](https://issues.redhat.com/browse/CNTRLPLANE-3609): graduate etcdBackendQuota to GA [#2987](https://github.com/openshift/api/pull/2987)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default for Hypershift [#2986](https://github.com/openshift/api/pull/2986)
* [Full changelog](https://github.com/openshift/api/compare/dffcf504e2ea64d417e0778229b7be6df398a9be...31af9f93e31ecd483504b3302d78f67c5a077a9e)
### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/324996d8fff21db132e0c4764600d4720adab4be)
* [OCPBUGS-87358](https://issues.redhat.com/browse/OCPBUGS-87358): Updating ose-cluster-config-operator-container image to be consistent with ART for 5.0 [#493](https://github.com/openshift/cluster-config-operator/pull/493)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#502](https://github.com/openshift/cluster-config-operator/pull/502)
* [Full changelog](https://github.com/openshift/cluster-config-operator/compare/9f787f73f5fffca5cd511ef2c2e704afc14f68ce...324996d8fff21db132e0c4764600d4720adab4be)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/c00cf58dd81954ca100757f6a2d2af8d84770fd5)
* [OCPBUGS-115467](https://issues.redhat.com/browse/OCPBUGS-115467): Guard against empty workspace field on vsphere [#419](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/419)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/14e9821d573de4c9771d87c0772b81b82565efb8...c00cf58dd81954ca100757f6a2d2af8d84770fd5)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/73835ffac883949ae5fcea3fd9eb0f4076ae711a)
* [OCPBUGS-123640](https://issues.redhat.com/browse/OCPBUGS-123640): fix: add missing workload paritioning annotation on cert-watcher daemonset [#1709](https://github.com/openshift/cluster-etcd-operator/pull/1709)
* [OCPBUGS-121354](https://issues.redhat.com/browse/OCPBUGS-121354): feat: add cert-watcher DaemonSet to restart etcd on CA bundle rotation [#1702](https://github.com/openshift/cluster-etcd-operator/pull/1702)
* [OCPBUGS-111703](https://issues.redhat.com/browse/OCPBUGS-111703): Fix tnf_cluster_in_service during per-node maintenance [#1681](https://github.com/openshift/cluster-etcd-operator/pull/1681)
* [OCPBUGS-114671](https://issues.redhat.com/browse/OCPBUGS-114671): fall back to intermediate ciphers during etcd bootstrap [#1690](https://github.com/openshift/cluster-etcd-operator/pull/1690)
* [OCPBUGS-111300](https://issues.redhat.com/browse/OCPBUGS-111300): Derive console notification docs URL from cluster version [#1679](https://github.com/openshift/cluster-etcd-operator/pull/1679)
* [CNTRLPLANE-4136](https://issues.redhat.com/browse/CNTRLPLANE-4136): update api to pull in etcd db ga [#1682](https://github.com/openshift/cluster-etcd-operator/pull/1682)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/6b88b761570ac42e18919ff9ee92f9c726799697...73835ffac883949ae5fcea3fd9eb0f4076ae711a)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/b6d3329d7059adba44dd0c3e9c0e9da264f9a551)
* [OCPBUGS-121350](https://issues.redhat.com/browse/OCPBUGS-121350): imageconfig: Preserve ImageStreamImportMode during upgrade race [#1367](https://github.com/openshift/cluster-image-registry-operator/pull/1367)
* [OCPBUGS-100042](https://issues.redhat.com/browse/OCPBUGS-100042): Updating ose-cluster-image-registry-operator-container image to be consistent with ART for 5.0 [#1359](https://github.com/openshift/cluster-image-registry-operator/pull/1359)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/94cd22d000c8b8eef24dd43cd05d06544df24930...b6d3329d7059adba44dd0c3e9c0e9da264f9a551)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/fe8a2bcf6342fab7aa19c47b4397a7d226962136)
* [OCPBUGS-114134](https://issues.redhat.com/browse/OCPBUGS-114134): Preserve server-defaulted fields on init containers and volumes [#1563](https://github.com/openshift/cluster-ingress-operator/pull/1563)
* [OCPBUGS-109738](https://issues.redhat.com/browse/OCPBUGS-109738): Add BackendTLSPolicy and ReferenceGrant e2e test coverage helpers [#1550](https://github.com/openshift/cluster-ingress-operator/pull/1550)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/5b9c7adbbda37bd3f5eb3b049993a0ab320958c5...fe8a2bcf6342fab7aa19c47b4397a7d226962136)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/b8c26db7c7c7e49476235ec83b2e81ef0996e242)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#2311](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2311)
* [OCPBUGS-83400](https://issues.redhat.com/browse/OCPBUGS-83400): revert dev cert rotation [#2272](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2272)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/57553b18b7cdc53a203ee5e4b25968a3b0ac42ef...b8c26db7c7c7e49476235ec83b2e81ef0996e242)
### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/1ee372e7019b41fbcb4c64323142c4a06bf266d0)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#968](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/968)
* [OCPBUGS-111832](https://issues.redhat.com/browse/OCPBUGS-111832): Updating ose-cluster-kube-controller-manager-operator-container image to be consistent with ART for 5.0 [#954](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/954)
* [OCPBUGS-112788](https://issues.redhat.com/browse/OCPBUGS-112788): fix CVE-2026-41178 [#957](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/957)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/8db74e3fe8793043d942ef1f59cce3b0a0bcc548...1ee372e7019b41fbcb4c64323142c4a06bf266d0)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/e0d271fceb3727138177e017f860a8ff79738bb3)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#677](https://github.com/openshift/cluster-kube-scheduler-operator/pull/677)
* [OCPBUGS-113761](https://issues.redhat.com/browse/OCPBUGS-113761): bump otel to v1.44.0 to fix CVE-2026-41178 [#663](https://github.com/openshift/cluster-kube-scheduler-operator/pull/663)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3...e0d271fceb3727138177e017f860a8ff79738bb3)
### [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/tree/ec1db56482efc9dced72b44a1c2b6817dbfffe91)
* [OCPBUGS-87479](https://issues.redhat.com/browse/OCPBUGS-87479): Updating ose-cluster-kube-storage-version-migrator-operator-container image to be consistent with ART for 5.0 [#178](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/178)
* [Full changelog](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/compare/f5d3bfe64bda67ffb8299af01ebf2722287edf04...ec1db56482efc9dced72b44a1c2b6817dbfffe91)
### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/11c03d0952f281ca9cfb62e528e5a0e24ae644ab)
* [OCPBUGS-113529](https://issues.redhat.com/browse/OCPBUGS-113529): Always validate EgressIPs [#315](https://github.com/openshift/cluster-machine-approver/pull/315)
* [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/cdf27353008200166f1ad754c4ade033370077ae...11c03d0952f281ca9cfb62e528e5a0e24ae644ab)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/efeeabf10a9c46f7a82086d2c04c9fc6d93a2b22)
* [OCPBUGS-112571](https://issues.redhat.com/browse/OCPBUGS-112571): Makefile: version-stamp golangci-lint binary to prevent stale linter [#3061](https://github.com/openshift/cluster-monitoring-operator/pull/3061)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/942c2dad78d6c22c4e19a375515b17a68b3f6007...efeeabf10a9c46f7a82086d2c04c9fc6d93a2b22)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/3b484353063fe95156373f7cf51c5ba13f501256)
* [OCPBUGS-115428](https://issues.redhat.com/browse/OCPBUGS-115428): Adds rendering of enable-multi-network-policy in ovnkube-node [#3149](https://github.com/openshift/cluster-network-operator/pull/3149)
* [OCPBUGS-107980](https://issues.redhat.com/browse/OCPBUGS-107980): CVE-2026-41178 - bump go.opentelemetry.io/otel to v1.44.0 [#3133](https://github.com/openshift/cluster-network-operator/pull/3133)
* [OCPBUGS-115064](https://issues.redhat.com/browse/OCPBUGS-115064): Install NOO using OLMv0 instead of OLMv1 [#3143](https://github.com/openshift/cluster-network-operator/pull/3143)
* [OCPBUGS-115900](https://issues.redhat.com/browse/OCPBUGS-115900): CNF-26697: [release-5.0] CORENET-7330: Allow per-node OVN encap IP override via env-overrides [#3124](https://github.com/openshift/cluster-network-operator/pull/3124)
* [OCPBUGS-105887](https://issues.redhat.com/browse/OCPBUGS-105887): [cherry-pick 5.0] Filter unsupported cipher suites to prevent ovnkube-identity crash [#3128](https://github.com/openshift/cluster-network-operator/pull/3128)
* [OCPBUGS-111097](https://issues.redhat.com/browse/OCPBUGS-111097): Drop strategy.rollingUpdate and switch strategy.type to Recreate via pre-patch in frr-k8s-statuscleaner deployments on SNO [#3129](https://github.com/openshift/cluster-network-operator/pull/3129)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/c27dc71a8630e864970fd315f3e749a30950fb42...3b484353063fe95156373f7cf51c5ba13f501256)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/ea084dcf2a92e08a6686e89da49738383bbefd39)
* [OCPBUGS-123511](https://issues.redhat.com/browse/OCPBUGS-123511): e2e: make OVS dynamic pinning tests compatible with ovsDpdk CPUs [#1631](https://github.com/openshift/cluster-node-tuning-operator/pull/1631)
* [OCPBUGS-119931](https://issues.redhat.com/browse/OCPBUGS-119931): add optional --ovs-dpdk-cpu-count flag (default 0) [#1630](https://github.com/openshift/cluster-node-tuning-operator/pull/1630)
* [OCPBUGS-114934](https://issues.redhat.com/browse/OCPBUGS-114934): Disable timer.migration on RHCOS 10 [#1625](https://github.com/openshift/cluster-node-tuning-operator/pull/1625)
* [OCPBUGS-114144](https://issues.redhat.com/browse/OCPBUGS-114144): Update PPC help description [#1617](https://github.com/openshift/cluster-node-tuning-operator/pull/1617)
* [OCPBUGS-104311](https://issues.redhat.com/browse/OCPBUGS-104311): Bump golang.org/x/net [#1600](https://github.com/openshift/cluster-node-tuning-operator/pull/1600)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/258062a23f0cba08eaf4d7f39b1594fadae8ecd1...ea084dcf2a92e08a6686e89da49738383bbefd39)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/d56fffed57ce229b53b4cb1eba63311360051806)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#771](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/771)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/28420873a3c92985df8ec089e6513b16c4f2f3a0...d56fffed57ce229b53b4cb1eba63311360051806)
### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/ba80c7efd89885b08dc890eb5aefb994ee1e7ab9)
* [OKD-425](https://issues.redhat.com/browse/OKD-425): Revert openliberty back to 26.0.0.6 [#711](https://github.com/openshift/cluster-samples-operator/pull/711)
* [OCPBUGS-111886](https://issues.redhat.com/browse/OCPBUGS-111886): Fix python:latest and nodejs template references after UBI 8 tag removal - #707 [#707](https://github.com/openshift/cluster-samples-operator/pull/707)
* [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/88b9454ff474a85de5ddddf803eeb0183f05b566...ba80c7efd89885b08dc890eb5aefb994ee1e7ab9)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/b2ee363241ad0425efd56badb6046884cadda97d)
* [OCPBUGS-111892](https://issues.redhat.com/browse/OCPBUGS-111892): Pass management cluster proxy env vars to CSI driver operator deployments [#725](https://github.com/openshift/cluster-storage-operator/pull/725)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/b75f14a9bdea51838b1e7fd03f86cfb46580a103...b2ee363241ad0425efd56badb6046884cadda97d)
### [cluster-update-console-plugin](https://github.com/openshift/cluster-update-console-plugin/tree/8e684dc03729798295e1b2b059826a5a5abe76c8)
* [OCPBUGS-100041](https://issues.redhat.com/browse/OCPBUGS-100041): Updating cluster-update-console-plugin-container image to be consistent with ART for 5.0 [#21](https://github.com/openshift/cluster-update-console-plugin/pull/21)
* [Full changelog](https://github.com/openshift/cluster-update-console-plugin/compare/02b220dd2aef5c1788768178e3ffd8592ccb89b9...8e684dc03729798295e1b2b059826a5a5abe76c8)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/219aba7debd16c83bb6ccdccf156af921ce54dfe)
* [OCPBUGS-122172](https://issues.redhat.com/browse/OCPBUGS-122172): pkg/readiness/cluster_conditions: Conditionally include Upgradeable [#1468](https://github.com/openshift/cluster-version-operator/pull/1468)
* [OCPBUGS-112659](https://issues.redhat.com/browse/OCPBUGS-112659): Remove the CRB for the default openshift-cluster-version SA [#1454](https://github.com/openshift/cluster-version-operator/pull/1454)
* [OCPBUGS-111971](https://issues.redhat.com/browse/OCPBUGS-111971): pkg/agenticrun/controller: Pivot to cluster-update-advisor directory [#1448](https://github.com/openshift/cluster-version-operator/pull/1448)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/f94dc81765de89b6610894a3994a8aa4724e9787...219aba7debd16c83bb6ccdccf156af921ce54dfe)
### [console](https://github.com/openshift/console/tree/0216b2de8b57c3375fcc161d2c75a031bef72c1b)
* [OCPBUGS-114008](https://issues.redhat.com/browse/OCPBUGS-114008): Strip version tag from OCI chart URL to prevent doubl… [#17097](https://github.com/openshift/console/pull/17097)
* [OCPBUGS-122258](https://issues.redhat.com/browse/OCPBUGS-122258): Handle Prometheus percentage strings [#17161](https://github.com/openshift/console/pull/17161)
* [OCPBUGS-123616](https://issues.redhat.com/browse/OCPBUGS-123616): increase httpRetry and update yarn [#17181](https://github.com/openshift/console/pull/17181)
* [OCPBUGS-123202](https://issues.redhat.com/browse/OCPBUGS-123202): Fix Namespace column hidden on Node Pods tab with active namespace [#17175](https://github.com/openshift/console/pull/17175)
* [OCPBUGS-123647](https://issues.redhat.com/browse/OCPBUGS-123647): i18n upload/download routine task - version 4.23/5.0 [#17183](https://github.com/openshift/console/pull/17183)
* [OCPBUGS-120694](https://issues.redhat.com/browse/OCPBUGS-120694): Installed Operators page fails with catalogsources "forbidden ... at the cluster scope" error [#17142](https://github.com/openshift/console/pull/17142)
* [OCPBUGS-121974](https://issues.redhat.com/browse/OCPBUGS-121974): Migrate OLM Cypress tests to Playwright [#17149](https://github.com/openshift/console/pull/17149)
* [OCPBUGS-120712](https://issues.redhat.com/browse/OCPBUGS-120712): Update stale comment [#17143](https://github.com/openshift/console/pull/17143)
* [OCPBUGS-115209](https://issues.redhat.com/browse/OCPBUGS-115209): Fix webhook creation in Git for PAC [#17123](https://github.com/openshift/console/pull/17123)
* [OCPBUGS-120668](https://issues.redhat.com/browse/OCPBUGS-120668): improve playwright reliability [#17138](https://github.com/openshift/console/pull/17138)
* [OCPBUGS-115402](https://issues.redhat.com/browse/OCPBUGS-115402): Rename e2e scripts so playwright is the main one [#17129](https://github.com/openshift/console/pull/17129)
* [OCPBUGS-115155](https://issues.redhat.com/browse/OCPBUGS-115155): move yarn install to prow scripts [#17122](https://github.com/openshift/console/pull/17122)
* [OCPBUGS-112307](https://issues.redhat.com/browse/OCPBUGS-112307): Show CPU/Memory metrics for non-admin users on Projects page [#17053](https://github.com/openshift/console/pull/17053)
* [OCPBUGS-114388](https://issues.redhat.com/browse/OCPBUGS-114388): display operators in catalog when Tech Preview enabled [#17100](https://github.com/openshift/console/pull/17100)
* [OCPBUGS-113650](https://issues.redhat.com/browse/OCPBUGS-113650): Helm chart is created in incorrect namespace [#17085](https://github.com/openshift/console/pull/17085)
* [OCPBUGS-113704](https://issues.redhat.com/browse/OCPBUGS-113704): Helm test setup: revert silent skip and restore panic on infrastructure failure [#17087](https://github.com/openshift/console/pull/17087)
* [OCPBUGS-112325](https://issues.redhat.com/browse/OCPBUGS-112325): 'Edit Machine count' from action list doesn't work [#17061](https://github.com/openshift/console/pull/17061)
* [OCPBUGS-112467](https://issues.redhat.com/browse/OCPBUGS-112467): Remove empty integration-tests package from CI [#17068](https://github.com/openshift/console/pull/17068)
* [OCPBUGS-111972](https://issues.redhat.com/browse/OCPBUGS-111972): Fix plugin entrypoint failing to load [#17033](https://github.com/openshift/console/pull/17033)
* [OCPBUGS-112288](https://issues.redhat.com/browse/OCPBUGS-112288): Migrate app/ Cypress e2e tests to Playwright [#17049](https://github.com/openshift/console/pull/17049)
* [OCPBUGS-112327](https://issues.redhat.com/browse/OCPBUGS-112327): Helm backend tests flake due to chartmuseum/zot failing to bind ports in CI [#17062](https://github.com/openshift/console/pull/17062)
* [OCPBUGS-112268](https://issues.redhat.com/browse/OCPBUGS-112268): Keep OLS cluster-update prompts within OpenAI 32k limit [#17044](https://github.com/openshift/console/pull/17044)
* [OCPBUGS-112088](https://issues.redhat.com/browse/OCPBUGS-112088): Migrate secrets e2e tests from Cypress to Playwright [#17043](https://github.com/openshift/console/pull/17043)
* [OCPBUGS-111928](https://issues.redhat.com/browse/OCPBUGS-111928): Shared Playwright e2e context and test generation skill [#17023](https://github.com/openshift/console/pull/17023)
* [OCPBUGS-111921](https://issues.redhat.com/browse/OCPBUGS-111921): make cloud provider fields optional during operator install [#17022](https://github.com/openshift/console/pull/17022)
* [OCPBUGS-112009](https://issues.redhat.com/browse/OCPBUGS-112009): Fix flaky TestAsyncCache backend test due to timing-dependent assertions [#17037](https://github.com/openshift/console/pull/17037)
* And 4 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/68185f46a763099efa0c89e06074e79a53193854...0216b2de8b57c3375fcc161d2c75a031bef72c1b)
### [container-networking-plugins, containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins/tree/d253ee09d629b8172ffc9c3e4b571320fc63ee34)
* [OCPBUGS-114407](https://issues.redhat.com/browse/OCPBUGS-114407): Remove rhel8 build stage [#247](https://github.com/openshift/containernetworking-plugins/pull/247)
* [Full changelog](https://github.com/openshift/containernetworking-plugins/compare/d6f73950658d258e0ddbf2a4ac92e13ac840158b...d253ee09d629b8172ffc9c3e4b571320fc63ee34)
### [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata/tree/b929f29695d4a1ab21a70868f681d463a673380f)
* [OCPBUGS-104319](https://issues.redhat.com/browse/OCPBUGS-104319): Bump golang.org/x/net to v0.53.0 and Go to 1.25.10 [#23](https://github.com/openshift/csi-external-snapshot-metadata/pull/23)
* [Full changelog](https://github.com/openshift/csi-external-snapshot-metadata/compare/239703c637e005cf785892d214d219add70e3533...b929f29695d4a1ab21a70868f681d463a673380f)
### [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe/tree/cab57d511106916bba6953977106f06b2fec01fd)
* [OCPBUGS-107993](https://issues.redhat.com/browse/OCPBUGS-107993): Bump go.opentelemetry.io/otel to v1.44.0 to address CVE-2026-41178 [#95](https://github.com/openshift/csi-livenessprobe/pull/95)
* [Full changelog](https://github.com/openshift/csi-livenessprobe/compare/463dc553ebb04df192d573c5a1612dcb50cb1f52...cab57d511106916bba6953977106f06b2fec01fd)
### [docker-builder](https://github.com/openshift/builder/tree/1e53243554dead3d84297e341651c5eb83eb37a4)
* [OCPBUGS-95492](https://issues.redhat.com/browse/OCPBUGS-95492), [OCPBUGS-98108](https://issues.redhat.com/browse/OCPBUGS-98108): Bump golang.org/x/crypto to fix CVE-2025-22869,CVE-2025-47913,CVE-2026-46597,CVE-2026-39829,CVE-2026-39832 [#550](https://github.com/openshift/builder/pull/550)
* [OCPBUGS-87365](https://issues.redhat.com/browse/OCPBUGS-87365): Updating openshift-enterprise-builder-container image to be consistent with ART for 5.0 [#539](https://github.com/openshift/builder/pull/539)
* [Full changelog](https://github.com/openshift/builder/compare/2cda03a93696d4620703848471b3b873b0b2fa1e...1e53243554dead3d84297e341651c5eb83eb37a4)
### [docker-registry](https://github.com/openshift/image-registry/tree/9436b2271fc9b687bda31e335bacc4031dcba80a)
* [OCPBUGS-87287](https://issues.redhat.com/browse/OCPBUGS-87287): Updating openshift-enterprise-registry-container image to be consistent with ART for 5.0 [#472](https://github.com/openshift/image-registry/pull/472)
* [Full changelog](https://github.com/openshift/image-registry/compare/a91ce6edf2c5cc08aa184c47dff79e842079c533...9436b2271fc9b687bda31e335bacc4031dcba80a)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/bc639044a3aee89f1f9547ad0539481b8d808516)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Update Dockerfiles [#113](https://github.com/openshift/egress-router-cni/pull/113)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/7b9f54aff1a90ba59242b305fb628db9f20d1d2c...bc639044a3aee89f1f9547ad0539481b8d808516)
### [hyperkube, kube-proxy, pod](https://github.com/openshift/kubernetes/tree/b376ee7b841bed5a51cb9520b37d87931c48a821)
* [OCPBUGS-108014](https://issues.redhat.com/browse/OCPBUGS-108014): UPSTREAM: <carry>: bump otel to v1.44.0 to fix CVE-2026-41178 [#2762](https://github.com/openshift/kubernetes/pull/2762)
* NO-JIRA: Make graceful-termination-duration flag required for the watch-termination command [#2763](https://github.com/openshift/kubernetes/pull/2763)
* [Full changelog](https://github.com/openshift/kubernetes/compare/7b29fb077260554429dcef8234272e9fd25fcfbd...b376ee7b841bed5a51cb9520b37d87931c48a821)
### [hypershift](https://github.com/openshift/hypershift/tree/f17305a432f02f3352c052c717e98db730a6edb4)
* [ACM-41684](https://issues.redhat.com/browse/ACM-41684): Switch hypershift-operator runtime to PQC base image [#9590](https://github.com/openshift/hypershift/pull/9590)
* [OCPBUGS-112730](https://issues.redhat.com/browse/OCPBUGS-112730): fix(certs): normalize IP SANs to stop dual-stack KAS cert churn [#9495](https://github.com/openshift/hypershift/pull/9495)
* [OCPBUGS-122229](https://issues.redhat.com/browse/OCPBUGS-122229): filter AWS-reserved tag keys before calling DeleteTags [#9576](https://github.com/openshift/hypershift/pull/9576)
* [OCPBUGS-123150](https://issues.redhat.com/browse/OCPBUGS-123150): [release-5.0] [CNTRLPLANE-3626](https://redhat.atlassian.net/browse/CNTRLPLANE-3626): feat(ignition-server, ignition-server-proxy): inject centralized TLS configuration [#9408](https://github.com/openshift/hypershift/pull/9408)
* [OCPBUGS-123793](https://issues.redhat.com/browse/OCPBUGS-123793): Use multiarch CI build root on release-5.0 [#9633](https://github.com/openshift/hypershift/pull/9633)
* [OCPBUGS-123146](https://issues.redhat.com/browse/OCPBUGS-123146): Updating ose-hypershift-container image to be consistent with ART for 5.0 [#9597](https://github.com/openshift/hypershift/pull/9597)
* [OCPBUGS-117010](https://issues.redhat.com/browse/OCPBUGS-117010): preserve immutable AWS load balancer annotations [#9489](https://github.com/openshift/hypershift/pull/9489)
* [OCPBUGS-114435](https://issues.redhat.com/browse/OCPBUGS-114435): fix(konnectivity): enable --sync-forever to restore lost agent-server tunnels [#9430](https://github.com/openshift/hypershift/pull/9430)
* [OCPBUGS-113998](https://issues.redhat.com/browse/OCPBUGS-113998): fix(azure): skip KMS validation for private Key Vaults on ARO HCP [#9405](https://github.com/openshift/hypershift/pull/9405)
* [OCPBUGS-115188](https://issues.redhat.com/browse/OCPBUGS-115188), [OCPBUGS-121650](https://issues.redhat.com/browse/OCPBUGS-121650): backport safe-to-evict annotation and operator health probes fixes [#9534](https://github.com/openshift/hypershift/pull/9534)
* [OCPBUGS-98883](https://issues.redhat.com/browse/OCPBUGS-98883), [OCPBUGS-98887](https://issues.redhat.com/browse/OCPBUGS-98887): bump haproxy to 3.0.5-6.el10_2.2 for CVE fix [#9336](https://github.com/openshift/hypershift/pull/9336)
* [OCPBUGS-111891](https://issues.redhat.com/browse/OCPBUGS-111891): Add proxy env vars to cluster-storage-operator deployment [#9332](https://github.com/openshift/hypershift/pull/9332)
* [ACM-41685](https://issues.redhat.com/browse/ACM-41685): Enable PQC crypto policy in hypershift-cli image [#9462](https://github.com/openshift/hypershift/pull/9462)
* [CNTRLPLANE-4025](https://issues.redhat.com/browse/CNTRLPLANE-4025): feat(azure): support managed HSM for KMS encryption [#9376](https://github.com/openshift/hypershift/pull/9376)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): promote OSStreams feature gate to Default [#9372](https://github.com/openshift/hypershift/pull/9372)
* [Full changelog](https://github.com/openshift/hypershift/compare/a7fbf215c7593a7f374b0cae9deaa7bc6a176874...f17305a432f02f3352c052c717e98db730a6edb4)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/3604a6c42f3002800e5cad2a012aacaf9b5f7405)
* [OCPBUGS-108009](https://issues.redhat.com/browse/OCPBUGS-108009): UPSTREAM: 2933: Bump all go.opentelemetry.io/otel modules to v1.44.0 [#186](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/186)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/286dd2de7957e9c2897e152417f16907d324d819...3604a6c42f3002800e5cad2a012aacaf9b5f7405)
### [insights-operator](https://github.com/openshift/insights-operator/tree/2f616dc436db2e35d70c9a049be98c185f684243)
* [OCPBUGS-111992](https://issues.redhat.com/browse/OCPBUGS-111992): add custom proxy field to insights config [#1346](https://github.com/openshift/insights-operator/pull/1346)
* [OCPBUGS-112481](https://issues.redhat.com/browse/OCPBUGS-112481): Add multicluster gatherer [#1349](https://github.com/openshift/insights-operator/pull/1349)
* [Full changelog](https://github.com/openshift/insights-operator/compare/8494b69b8075fd1e8eac49db77bcda7588078155...2f616dc436db2e35d70c9a049be98c185f684243)
### [ironic](https://github.com/openshift/ironic-image/tree/b5082f7909065eb50306af483309e756557f7a60)
* Bug OCPBUGS-123709: Bumping sushy hash to include jobstate fixes [#914](https://github.com/openshift/ironic-image/pull/914)
* NO-ISSUE: Update requirements.cachito with latest openshift forks commits [#897](https://github.com/openshift/ironic-image/pull/897)
* [Full changelog](https://github.com/openshift/ironic-image/compare/001adec7884e75a5078e4e72c8bc8d2a51376b43...b5082f7909065eb50306af483309e756557f7a60)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/601c9bf36bbc4a0796c4c55e59bfe3cc46252ed3)
* [METAL-1931](https://issues.redhat.com/browse/METAL-1931): [5.0] Add cargo for bcrypt rust extensions [#305](https://github.com/openshift/ironic-agent-image/pull/305)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/8eb658a0ad45b0d826e36dbeb6d5b2b731762975...601c9bf36bbc4a0796c4c55e59bfe3cc46252ed3)
### [keepalived-ipfailover](https://github.com/openshift/images/tree/3f1cf0830f196a6755b8baf179fc0401188251c4)
* [OCPBUGS-87506](https://issues.redhat.com/browse/OCPBUGS-87506): Updating openshift-enterprise-keepalived-ipfailover-container image to be consistent with ART for 5.0 [#238](https://github.com/openshift/images/pull/238)
* [Full changelog](https://github.com/openshift/images/compare/32930575a2bb3571601a7444becc06d06e901657...3f1cf0830f196a6755b8baf179fc0401188251c4)
### [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator/tree/05d6b0c4537954b2b115c793646fb598756bb303)
* [OCPBUGS-87255](https://issues.redhat.com/browse/OCPBUGS-87255): Updating ose-kube-storage-version-migrator-container image to be consistent with ART for 5.0 [#243](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/243)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#260](https://github.com/openshift/kubernetes-kube-storage-version-migrator/pull/260)
* [Full changelog](https://github.com/openshift/kubernetes-kube-storage-version-migrator/compare/72835e43c7754356645e41031f3a99926b4d42e6...05d6b0c4537954b2b115c793646fb598756bb303)
### [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver/tree/00dd0030fdfcdb6937ebefd8fb92363a8f78ef73)
* [OCPBUGS-87572](https://issues.redhat.com/browse/OCPBUGS-87572): Updating ose-kubevirt-csi-driver-container image to be consistent with ART for 5.0 [#106](https://github.com/openshift/kubevirt-csi-driver/pull/106)
* [Full changelog](https://github.com/openshift/kubevirt-csi-driver/compare/7ff99994ecc3a675fac6f9aa7fa418cdb0dca32b...00dd0030fdfcdb6937ebefd8fb92363a8f78ef73)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/b3cabb0301b12a2b256bf8aed85c3f4c7b0dab3c)
* [OCPBUGS-120320](https://issues.redhat.com/browse/OCPBUGS-120320): Compare against oldObject in vSphere failure-domain VAPs [#1540](https://github.com/openshift/machine-api-operator/pull/1540)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/0db39ee372bf7b75f56898fd2df555e063d32952...b3cabb0301b12a2b256bf8aed85c3f4c7b0dab3c)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/ea7d971717f7c6fac339f5cf4ffbbccb23234edc)
* [OCPBUGS-126703](https://issues.redhat.com/browse/OCPBUGS-126703): Add '..' block, max-length, and cross-store uniqueness [#6483](https://github.com/openshift/machine-config-operator/pull/6483)
* [OCPBUGS-122238](https://issues.redhat.com/browse/OCPBUGS-122238): [TNF] Add infinite retry on untaint systemd unit [#6553](https://github.com/openshift/machine-config-operator/pull/6553)
* [OCPBUGS-122915](https://issues.redhat.com/browse/OCPBUGS-122915): Mount /etc/container in mosb [#6537](https://github.com/openshift/machine-config-operator/pull/6537)
* [OCPBUGS-122217](https://issues.redhat.com/browse/OCPBUGS-122217): Dump compact cache to CM for persistence [#6525](https://github.com/openshift/machine-config-operator/pull/6525)
* [OCPBUGS-121942](https://issues.redhat.com/browse/OCPBUGS-121942): Replace wildcard permissions with explicit verbs in MachineConfigServer ClusterRole [#6514](https://github.com/openshift/machine-config-operator/pull/6514)
* [OCPBUGS-123672](https://issues.redhat.com/browse/OCPBUGS-123672): Pass missing proxy vars to bootstrap MCC [#6548](https://github.com/openshift/machine-config-operator/pull/6548)
* [OCPBUGS-114854](https://issues.redhat.com/browse/OCPBUGS-114854): CVE-2026-15792 openshift4/ose-machine-config-rhel9-operator: BuildKit: Denial of Service via malicious client request [openshift-5.0] [#6519](https://github.com/openshift/machine-config-operator/pull/6519)
* [OCPBUGS-122284](https://issues.redhat.com/browse/OCPBUGS-122284): updateLayeredOS deploy-from-self when skopeo < 1.22.2 [#6534](https://github.com/openshift/machine-config-operator/pull/6534)
* [OCPBUGS-114722](https://issues.redhat.com/browse/OCPBUGS-114722): crio: drop restore support [#6465](https://github.com/openshift/machine-config-operator/pull/6465)
* [OCPBUGS-121651](https://issues.redhat.com/browse/OCPBUGS-121651): remove nft chains before checking the ignition config [#6511](https://github.com/openshift/machine-config-operator/pull/6511)
* [OCPBUGS-121379](https://issues.redhat.com/browse/OCPBUGS-121379): Retry on conflict in syncMachineConfigNodes [#6510](https://github.com/openshift/machine-config-operator/pull/6510)
* [OCPBUGS-121850](https://issues.redhat.com/browse/OCPBUGS-121850): Fix vsphere network absolute paths [#6513](https://github.com/openshift/machine-config-operator/pull/6513)
* [OCPBUGS-115056](https://issues.redhat.com/browse/OCPBUGS-115056): limit ContainerRuntimeConfig status condition to 3 [#6468](https://github.com/openshift/machine-config-operator/pull/6468)
* [OCPBUGS-116711](https://issues.redhat.com/browse/OCPBUGS-116711): Skip vsphere fd-unmatched machinesets for bootimage updates [#6484](https://github.com/openshift/machine-config-operator/pull/6484)
* [OCPBUGS-117427](https://issues.redhat.com/browse/OCPBUGS-117427): Increase TC-74751 Eventually timeout for vSphere OVA upload [#6491](https://github.com/openshift/machine-config-operator/pull/6491)
* [OCPBUGS-116944](https://issues.redhat.com/browse/OCPBUGS-116944): Update AMI Whitelist [#6490](https://github.com/openshift/machine-config-operator/pull/6490)
* [OCPBUGS-114709](https://issues.redhat.com/browse/OCPBUGS-114709): Preserve proxy environment vars [#6464](https://github.com/openshift/machine-config-operator/pull/6464)
* [OCPBUGS-115195](https://issues.redhat.com/browse/OCPBUGS-115195): fix: adjust fencing validator to match MAC-address based credential secrets [#6467](https://github.com/openshift/machine-config-operator/pull/6467)
* [OCPBUGS-114485](https://issues.redhat.com/browse/OCPBUGS-114485): Update the MachineOSBuild event and condition functionality to more clearly handle pod failures with retries [#6463](https://github.com/openshift/machine-config-operator/pull/6463)
* [OCPBUGS-112790](https://issues.redhat.com/browse/OCPBUGS-112790): Revert TNF Graceful node shutdown [#6460](https://github.com/openshift/machine-config-operator/pull/6460)
* [OCPBUGS-114389](https://issues.redhat.com/browse/OCPBUGS-114389): Use kubernetes scheme in drain controller event recorder [#6455](https://github.com/openshift/machine-config-operator/pull/6455)
* [CORS-4441](https://issues.redhat.com/browse/CORS-4441): Bootimage controller should gracefully handle Azure gen1 image removal [#6453](https://github.com/openshift/machine-config-operator/pull/6453)
* [OCPBUGS-113615](https://issues.redhat.com/browse/OCPBUGS-113615): Azure confidential clusters should be flagged by skew enforcement [#6448](https://github.com/openshift/machine-config-operator/pull/6448)
* [OCPBUGS-112447](https://issues.redhat.com/browse/OCPBUGS-112447): Increase rpm-ostree rebase retry backoff and preserve error [#6425](https://github.com/openshift/machine-config-operator/pull/6425)
* [OCPBUGS-112466](https://issues.redhat.com/browse/OCPBUGS-112466): Fix upstreams for CoreDNS pods on Cloud platforms [#6429](https://github.com/openshift/machine-config-operator/pull/6429)
* [OCPBUGS-112082](https://issues.redhat.com/browse/OCPBUGS-112082): skip proxy for OSImageStream discovery in HyperShift [#6423](https://github.com/openshift/machine-config-operator/pull/6423)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/c7aecba7975d129529d1ec6a67ac6e5b9991aefb...ea7d971717f7c6fac339f5cf4ffbbccb23234edc)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/e8610c3c8b35ec0758523c21a2e60aa8c7e59914)
* NO-JIRA: [release-5.0] Sanitize alert runbook URLs [#1290](https://github.com/openshift/monitoring-plugin/pull/1290)
* [OCPBUGS-114748](https://issues.redhat.com/browse/OCPBUGS-114748): [release-5.0] DOMPurify: Cross-Site Scripting via IN_PLACE sanitization [#1265](https://github.com/openshift/monitoring-plugin/pull/1265)
* NO-JIRA: Add dchromik to observability-ui aliases [#1232](https://github.com/openshift/monitoring-plugin/pull/1232)
* [OU-1423](https://issues.redhat.com/browse/OU-1423): fix: adjust perses mui theme to patternfly glass mode [#1198](https://github.com/openshift/monitoring-plugin/pull/1198)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): [release-5.0] : include the legal disclaimer in the alert actions to agentic runs [#1193](https://github.com/openshift/monitoring-plugin/pull/1193)
* [OLS-3921](https://issues.redhat.com/browse/OLS-3921): disable button shrink [#1191](https://github.com/openshift/monitoring-plugin/pull/1191)
* NO-JIRA: remove `cypress/` imports [#1146](https://github.com/openshift/monitoring-plugin/pull/1146)
* [OU-1107](https://issues.redhat.com/browse/OU-1107), [OU-1108](https://issues.redhat.com/browse/OU-1108): ACM alerting UI with alerts and perses [#1143](https://github.com/openshift/monitoring-plugin/pull/1143)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/df674f002d52c80e82532b9c0d668291be6ed431...e8610c3c8b35ec0758523c21a2e60aa8c7e59914)
### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/c0bdec9ce6a1a69985fdba5481c47fb34461eb6c)
* [OCPBUGS-104355](https://issues.redhat.com/browse/OCPBUGS-104355): [release-5.0] Bump golang.org/x/net to 0.58.0 to fix CVE-2026-33814 [#126](https://github.com/openshift/multus-admission-controller/pull/126)
* [Full changelog](https://github.com/openshift/multus-admission-controller/compare/6d9df61378321846c00a32f0c42b6688daacd649...c0bdec9ce6a1a69985fdba5481c47fb34461eb6c)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/8f597f4b90dffe1d1cb9aee558fe53a0046c9e35)
* [OCPBUGS-120678](https://issues.redhat.com/browse/OCPBUGS-120678): [Release 5.0] Cherry-pick fix for restoring conflist CNINetworkConfigList fast path and fix cached DEL without load cost [#349](https://github.com/openshift/multus-cni/pull/349)
* [OCPBUGS-114733](https://issues.redhat.com/browse/OCPBUGS-114733): [release-5.0] Revert "Sort DeviceIDs in GetPodResourceMap for deterministic ordering" [#348](https://github.com/openshift/multus-cni/pull/348)
* [Full changelog](https://github.com/openshift/multus-cni/compare/f099946680e376f722674e684aec96a73c58e919...8f597f4b90dffe1d1cb9aee558fe53a0046c9e35)
### [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy/tree/bfbac5025c056c4bf53aeeef50c4bcf466f5eb11)
* [OCPBUGS-104353](https://issues.redhat.com/browse/OCPBUGS-104353): [release-5.0] Bump golang.org/x/net to 0.57.0 to fix CVE-2026-33814 [#121](https://github.com/openshift/multus-networkpolicy/pull/121)
* [Full changelog](https://github.com/openshift/multus-networkpolicy/compare/7a26023b1ebb3d2c6120973a97a9bed9adfae334...bfbac5025c056c4bf53aeeef50c4bcf466f5eb11)
### [multus-route-override-cni](https://github.com/openshift/route-override-cni/tree/375ac966115fd03febd218a8331e8794560bd28e)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#78](https://github.com/openshift/route-override-cni/pull/78)
* [Full changelog](https://github.com/openshift/route-override-cni/compare/08af4127c77976510cad1c096d9aca977d8ae5af...375ac966115fd03febd218a8331e8794560bd28e)
### [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni/tree/4b0c2166726247e36a0125432609844045e48dc3)
* [OCPBUGS-104367](https://issues.redhat.com/browse/OCPBUGS-104367): [release-5.0] Bump go to 1.25.11 and golang.org/x/net to 0.58.0 to fix CVE-2026-33814 [#421](https://github.com/openshift/whereabouts-cni/pull/421)
* [Full changelog](https://github.com/openshift/whereabouts-cni/compare/d918bda28ad3d0200b6e4f2ef2801556764762e5...4b0c2166726247e36a0125432609844045e48dc3)
### [must-gather](https://github.com/openshift/must-gather/tree/f4c72a69ebedddead25591da3a115bc4b0bc49ca)
* [OCPBUGS-123521](https://issues.redhat.com/browse/OCPBUGS-123521): Add windows_exporter log collection [#566](https://github.com/openshift/must-gather/pull/566)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#564](https://github.com/openshift/must-gather/pull/564)
* [OCPBUGS-113491](https://issues.redhat.com/browse/OCPBUGS-113491): REDUCE_LOGS=compress_logs compresses large must-gather logs before rsync [#561](https://github.com/openshift/must-gather/pull/561)
* [Full changelog](https://github.com/openshift/must-gather/compare/fd47ab2c1d183a1e66a1a74fe30cf6a26f433409...f4c72a69ebedddead25591da3a115bc4b0bc49ca)
### [network-interface-bond-cni](https://github.com/openshift/bond-cni/tree/2c395f566f259f1a1726409e2472029fa52918c9)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove rhel8 build stage [#122](https://github.com/openshift/bond-cni/pull/122)
* [Full changelog](https://github.com/openshift/bond-cni/compare/19d390fd4d353619fdfb5e0070962d2ddf54b5bb...2c395f566f259f1a1726409e2472029fa52918c9)
### [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon/tree/20e6b987ea44e7cf0805662e8fec44d625b6f278)
* [OCPBUGS-101707](https://issues.redhat.com/browse/OCPBUGS-101707), [OCPBUGS-104373](https://issues.redhat.com/browse/OCPBUGS-104373): Fix CVE for ose-network-metrics-daemon [#148](https://github.com/openshift/network-metrics-daemon/pull/148)
* [Full changelog](https://github.com/openshift/network-metrics-daemon/compare/e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844...20e6b987ea44e7cf0805662e8fec44d625b6f278)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/4509d691e67664e9b3a911278fcbf38d54bb9cfc)
* [OCPNETUI-78](https://issues.redhat.com/browse/OCPNETUI-78): Remove unused Dockerfile.art [#517](https://github.com/openshift/networking-console-plugin/pull/517)
* [OCPNETUI-78](https://issues.redhat.com/browse/OCPNETUI-78): Sync Dockerfile and Dockerfile.art [#495](https://github.com/openshift/networking-console-plugin/pull/495)
* [OCPBUGS-112661](https://issues.redhat.com/browse/OCPBUGS-112661): Marked strings for i18n in NetworkPolicies list page [#479](https://github.com/openshift/networking-console-plugin/pull/479)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/7d9d46ba0976840e7559b5b13f14624fd807472c...4509d691e67664e9b3a911278fcbf38d54bb9cfc)
### [oauth-apiserver](https://github.com/openshift/oauth-apiserver/tree/a59e07d789b5a2531e94053cfe7c53edde90e931)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#229](https://github.com/openshift/oauth-apiserver/pull/229)
* [Full changelog](https://github.com/openshift/oauth-apiserver/compare/51b07b6d36fd59d809d280630d542c6f702a528a...a59e07d789b5a2531e94053cfe7c53edde90e931)
### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/310d2f7b90762b407d6100eb3940bd5b2f348108)
* [OCPBUGS-115304](https://issues.redhat.com/browse/OCPBUGS-115304): [release-5.0] bugfix: rewrite open redirect strings to '/' [#376](https://github.com/openshift/oauth-proxy/pull/376)
* [OCPBUGS-87343](https://issues.redhat.com/browse/OCPBUGS-87343): Updating golang-github-openshift-oauth-proxy-container image to be consistent with ART for 5.0 [#367](https://github.com/openshift/oauth-proxy/pull/367)
* [Full changelog](https://github.com/openshift/oauth-proxy/compare/e9046946c11e46d310c83830687eb3284cb53525...310d2f7b90762b407d6100eb3940bd5b2f348108)
### [oauth-server](https://github.com/openshift/oauth-server/tree/6c2c889640ec53563021d0c0f09c4388cdcdb806)
* [OCPBUGS-122387](https://issues.redhat.com/browse/OCPBUGS-122387): Update build-machinery-go vendor dependency [#261](https://github.com/openshift/oauth-server/pull/261)
* [OCPBUGS-115306](https://issues.redhat.com/browse/OCPBUGS-115306): [release-5.0] bugfix: default to english when Accept-Language header contains more than 1000 underscores [#259](https://github.com/openshift/oauth-server/pull/259)
* [Full changelog](https://github.com/openshift/oauth-server/compare/1600eafd18f46d54ad0a9ff70fa03a085f6f6218...6c2c889640ec53563021d0c0f09c4388cdcdb806)
### [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager/tree/726a0562818b68faccfa130ae7ea17ff42915418)
* [OCPBUGS-112448](https://issues.redhat.com/browse/OCPBUGS-112448): bump(k8s.io): 1.36.3 [#452](https://github.com/openshift/openshift-controller-manager/pull/452)
* [Full changelog](https://github.com/openshift/openshift-controller-manager/compare/5631cf493b006cbc72a8600a7435813272d71940...726a0562818b68faccfa130ae7ea17ff42915418)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/c3d56d2021bbb8d57bc359fabded3b35b253f55e)
* [OCPBUGS-83412](https://issues.redhat.com/browse/OCPBUGS-83412): set catalogsource spec.grpcpodconfig.scc: restricted for all non-legacy cases [#1360](https://github.com/openshift/operator-framework-olm/pull/1360)
* [OCPBUGS-113283](https://issues.redhat.com/browse/OCPBUGS-113283): force node arch for opm and catalogsource pod for multiarch tests; fix test failure [#1358](https://github.com/openshift/operator-framework-olm/pull/1358)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/c64b9ca2026d13e8907d547b1cbe5226b0a25219...c3d56d2021bbb8d57bc359fabded3b35b253f55e)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/3ce12184bf66e8be8abe365f81ffdfa7dbb4dd76)
* [OCPBUGS-122287](https://issues.redhat.com/browse/OCPBUGS-122287): Fix wrong infrastructure-locked role when namespace is missing [#3438](https://github.com/openshift/ovn-kubernetes/pull/3438)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/7b4de5ed3bd4381e3a17cdfddbe14be1432b9860...3ce12184bf66e8be8abe365f81ffdfa7dbb4dd76)
### [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver/tree/5911994c5d70906e0f0972411176392ada9942d1)
* [OCPBUGS-108052](https://issues.redhat.com/browse/OCPBUGS-108052): Mitigate CVE-2026-41178 by bumping go.opentelemetry.io/otel to v1.44.0 [#143](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/143)
* OCPBUGS-93616,OCPBUGS-95518,OCPBUGS-98129, OCPBUGS-101725 and OCPBUGS-96872: Mitigate CVE-2026-39828, CVE-2026-46597 and CVE-2026-39835 [#141](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/141)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver/compare/e7c2c09bd0507f8bd5a6dc3921024a379f4a8af0...5911994c5d70906e0f0972411176392ada9942d1)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/b8af472104ce559c8fb9bf31fd4fc38bdbdc34e7)
* [OCPBUGS-112719](https://issues.redhat.com/browse/OCPBUGS-112719): cherry-pick 24c6dce279c418bcb911824e8c8be1c81a1e832b - Fix fibrechannel_linux for ppc64le (#3769) [#185](https://github.com/openshift/node_exporter/pull/185)
* [Full changelog](https://github.com/openshift/node_exporter/compare/4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07...b8af472104ce559c8fb9bf31fd4fc38bdbdc34e7)
### [rhel-coreos, rhel-coreos-10, rhel-coreos-10-extensions, rhel-coreos-extensions](https://github.com/openshift/os/tree/7324ccd30e5b2b3146639cb610bfe92c743c91a1)
* [OCPBUGS-115309](https://issues.redhat.com/browse/OCPBUGS-115309): Re-enable sandboxed-containers extension for 5.0 [#1965](https://github.com/openshift/os/pull/1965)
* [Full changelog](https://github.com/openshift/os/compare/d2f3751e77c4b79b1553d18758c2ea91f06f51fc...7324ccd30e5b2b3146639cb610bfe92c743c91a1)
### [tests](https://github.com/openshift/origin/tree/5469b61543bdbba51f6701bbc8882ccbd1fc3098)
* [OCPBUGS-123600](https://issues.redhat.com/browse/OCPBUGS-123600): Register cluster-baremetal-tests-ext in extension registry [#31641](https://github.com/openshift/origin/pull/31641)
* [[release-5.0] OCPBUGS-121193: Fixed Flakiness of Webhook test - ClusterResourceQuota validation](https://github.com/openshift/origin/pull/31642#top) [#31642](https://github.com/openshift/origin/pull/31642)
* Revert "OCPBUGS-83412: monitortests: skip PodSecurityViolation invariant when OpenShiftPodSecurityAdmission is disabled" [#31604](https://github.com/openshift/origin/pull/31604)
* [OKD-454](https://issues.redhat.com/browse/OKD-454): [release-5.0] Skip OKD job name check for cluster-bot launch jobs [#31629](https://github.com/openshift/origin/pull/31629)
* [CORENET-7243](https://issues.redhat.com/browse/CORENET-7243): Add TLS Profile Compliance tests for networking components [release-5.0] [#31613](https://github.com/openshift/origin/pull/31613)
* [OCPBUGS-120743](https://issues.redhat.com/browse/OCPBUGS-120743): Fix the number of requests in repeated exec [#31610](https://github.com/openshift/origin/pull/31610)
* [OCPBUGS-120715](https://issues.redhat.com/browse/OCPBUGS-120715): Add Degraded=True exception for authentication operator during upgrade [#31608](https://github.com/openshift/origin/pull/31608)
* [OKD-443](https://issues.redhat.com/browse/OKD-443): Handle missing OSImageStream CR on OKD SCOS during upgrades [#31592](https://github.com/openshift/origin/pull/31592)
* [OCPBUGS-114674](https://issues.redhat.com/browse/OCPBUGS-114674): Allow KubeDaemonSetRolloutStuck alert on external platform clusters [#31573](https://github.com/openshift/origin/pull/31573)
* [OCPBUGS-112042](https://issues.redhat.com/browse/OCPBUGS-112042): allow baremetal to progress while MCO does [#31537](https://github.com/openshift/origin/pull/31537)
* [OCPBUGS-113994](https://issues.redhat.com/browse/OCPBUGS-113994): Raise status polling timeout and write bound [#31559](https://github.com/openshift/origin/pull/31559)
* [OCPBUGS-114437](https://issues.redhat.com/browse/OCPBUGS-114437): Fix probe termination test to use pod status instead of kubelet event text [#31567](https://github.com/openshift/origin/pull/31567)
* [OCPBUGS-113706](https://issues.redhat.com/browse/OCPBUGS-113706): Fix pathological events [#31557](https://github.com/openshift/origin/pull/31557)
* [OCPBUGS-83412](https://issues.redhat.com/browse/OCPBUGS-83412): monitortests: skip PodSecurityViolation invariant when OpenShiftPodSecurityAdmission is disabled [#31561](https://github.com/openshift/origin/pull/31561)
* [OCPBUGS-113760](https://issues.redhat.com/browse/OCPBUGS-113760): Allow KubeDaemonSetMisScheduled alert on external platform clusters [#31558](https://github.com/openshift/origin/pull/31558)
* [OCPBUGS-111877](https://issues.redhat.com/browse/OCPBUGS-111877): tolerate brief olm Available=False during upgrades [#31529](https://github.com/openshift/origin/pull/31529)
* [Full changelog](https://github.com/openshift/origin/compare/fb432ca0c1efb729d8f221c7e8231bbe88edda43...5469b61543bdbba51f6701bbc8882ccbd1fc3098)
### [thanos](https://github.com/openshift/thanos/tree/2a09eb84b92ccd71d5f1f11e0dda6d5aa9624e19)
* [OCPBUGS-121890](https://issues.redhat.com/browse/OCPBUGS-121890): bump go.opentelemetry.io/otel to fix CVE-2026-41178 [#205](https://github.com/openshift/thanos/pull/205)
* [Full changelog](https://github.com/openshift/thanos/compare/75fa632b483716e53aec19f6adf7d4c4652a4453...2a09eb84b92ccd71d5f1f11e0dda6d5aa9624e19)
### [vsphere-csi-driver, vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver/tree/5351c207d5668dd59a445ee57591ba13657fad89)
* [OCPBUGS-126711](https://issues.redhat.com/browse/OCPBUGS-126711): UPSTREAM: 4272: Fix crash in syncer when node can't be found [#202](https://github.com/openshift/vmware-vsphere-csi-driver/pull/202)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver/compare/6b18bb29fc45383c21aa6c7513d151e443aa305e...5351c207d5668dd59a445ee57591ba13657fad89)