Back to index
Download the installer for your operating system or run
oc adm release extract --tools quay.io/openshift-release-dev/ocp-release:4.12.96-x86_64 Qualifiers (status api ): None
Tests:
Blocking jobs Informing jobs Upgrades from:
Untested upgrades:
4.11.14 ,
4.11.15 ,
4.11.16 ,
4.11.17 ,
4.11.18 ,
4.11.19 ,
4.11.20 ,
4.11.21 ,
4.11.22 ,
4.11.24 ,
4.11.25 ,
4.11.26 ,
4.11.27 ,
4.11.28 ,
4.11.29 ,
4.11.30 ,
4.11.31 ,
4.11.33 ,
4.11.34 ,
4.11.35 ,
4.11.36 ,
4.11.37 ,
4.11.38 ,
4.11.39 ,
4.11.40 ,
4.11.42 ,
4.11.43 ,
4.11.44 ,
4.11.45 ,
4.11.46 ,
4.11.47 ,
4.11.48 ,
4.11.49 ,
4.11.50 ,
4.11.51 ,
4.11.52 ,
4.11.53 ,
4.11.54 ,
4.11.55 ,
4.11.56 ,
4.12.10 ,
4.12.11 ,
4.12.12 ,
4.12.13 ,
4.12.14 ,
4.12.15 ,
4.12.16 ,
4.12.17 ,
4.12.18 ,
4.12.20 ,
4.12.21 ,
4.12.22 ,
4.12.23 ,
4.12.24 ,
4.12.25 ,
4.12.26 ,
4.12.27 ,
4.12.28 ,
4.12.29 ,
4.12.3 ,
4.12.30 ,
4.12.31 ,
4.12.32 ,
4.12.33 ,
4.12.34 ,
4.12.35 ,
4.12.36 ,
4.12.37 ,
4.12.38 ,
4.12.39 ,
4.12.4 ,
4.12.40 ,
4.12.41 ,
4.12.42 ,
4.12.43 ,
4.12.44 ,
4.12.45 ,
4.12.46 ,
4.12.47 ,
4.12.48 ,
4.12.49 ,
4.12.5 ,
4.12.50 ,
4.12.51 ,
4.12.52 ,
4.12.53 ,
4.12.54 ,
4.12.55 ,
4.12.56 ,
4.12.57 ,
4.12.58 ,
4.12.59 ,
4.12.6 ,
4.12.60 ,
4.12.61 ,
4.12.62 ,
4.12.63 ,
4.12.64 ,
4.12.65 ,
4.12.66 ,
4.12.67 ,
4.12.69 ,
4.12.7 ,
4.12.70 ,
4.12.71 ,
4.12.72 ,
4.12.73 ,
4.12.74 ,
4.12.75 ,
4.12.76 ,
4.12.77 ,
4.12.78 ,
4.12.79 ,
4.12.8 ,
4.12.80 ,
4.12.81 ,
4.12.82 ,
4.12.83 ,
4.12.84 ,
4.12.85 ,
4.12.86 ,
4.12.87 ,
4.12.89 ,
4.12.9 ,
4.12.90 ,
4.12.91 ,
4.12.92 Upgrades to:
Loading changelog, this may take a while ...
Changes from 4.12.1
Created: 2026-08-12 19:36:09 +0000 UTC
Image Digest: sha256:fc0a3dd609a60dd4ad10fe4badef3058d61a1a33436d33ec4b563d5aaf9f26cc
Components
Rebuilt images without code change
cluster-update-keys git 2796e173 sha256:933a010babaf058b66ad4ea3fe030d6b4765c3f8fe5f0250a7933906bbe9dca0
configmap-reloader git e4d9170e sha256:1d613ed9540ab2f487ba1a40440bfea4b2fb762ed255e7c27d28691d7938f266
egress-router-cni git a92e4157 sha256:fa9f1d2d69bd8800d431a7ff20605fd240a3c729850f83110d705a49fda87124
keepalived-ipfailover git 7e8a0105 sha256:bee4a7aba8a860d1960e8f473663e05f8b64f2ab2088329e63aea0f711664caa
kubevirt-csi-driver git f407c8a7 sha256:1d0e7a5aa3d4ed2e64615a8c5cd4ad3cbe7bead9d8fd4cfd1a11ba72b0f1cf55
libvirt-machine-controllers git a2882f7a sha256:d8a8278f0bd690be98b074f738ad3282afeb650c8845a0143e30fd32d1ede183
machine-os-content sha256:92618a5d179c9e61418680d6e6f1d5a7e8bd3b0b1dca9d941ced0368e0315859
network-tools git c76613c7 sha256:8a996b69c0e5b0d854ca9199572d56859573bfafbfea6dce64f631e900c5b019
prom-label-proxy git b1907888 sha256:ec20f9310843c0afb330e77fccb142a8bea768713e9e67415ac530dd222614b3
rhel-coreos-8 sha256:626471555006f3d9e003b792b8dd9477a3e473d56b66a53e175cae536caddba1
rhel-coreos-8-extensions sha256:3dee2ced6b21c4339b2ede3416a203391a54a50afdd6182a0f26c0f7b5c5fb02
Updating ose-alibaba-machine-controllers images to be consistent with ART #35
Full changelog
NO-JIRA: refactor: Updating go builder in the CI, Dockerfile and go.mod to be consistent with ART 4.12 #2175
OCPBUGS-67424 : CVE-2025-65637 openshift4/ose-cluster-kube-apiserver-operator: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [openshift-4.12.z] #2048
OCPBUGS-50880 : Increase waitForFallbackDegradedConditionTimeout #1811
OCPBUGS-22736 : pkg/operator/configobserver: check that the serving certificate refer… #1571
: OCPBUGS-20855: bump library-go to include switch to HTTP/1.1 #1574
OCPBUGS-19837 : Update staticpod file permissions to conform with CIS benchmarks #1559
OCPBUGS-17139 : make webhook connection failure a warning in log #1533
OCPBUGS-13346 : dont log jwt tokens #1524
OCPBUGS-6789 : enable pod security admission for techpreview #1440
OCPBUGS-6789 : make the bootstrap kube-apiserver honor cluster-wide featuregates #1439
OCPBUGS-7369 : Guard pod set readiness probe endpoint explicitly #1445
Full changelog
NO-JIRA: Reconciling the ART and CI go tool chain versions #173
OCPBUGS-67429 : Bump github.com/sirupsen/logrus to v1.8.3 #143
: OCPBUGS-21336: bump library-go to include switch to HTTP/1.1 #98
Full changelog
irqbalance: set banned cpus list to 0 (#1006) #1006
Refactor IRQ load balancing enable/disable test (#1038) #1038
Scheduler plugin: ignore IRQs (#1034) #1034
Disable HTTP/2 for webhook and metrics servers (#849) #849
Remove obsolete protocols and weak ciphers (#847) #847
OCPBUGS-21837 : nto: pao avoid timeout when there are too many CSV (#838) #838
Tighten the rules for modifying Tuned Profiles (#790) #790
OCPBUGS-19459 : check for object being nil (#821) #821
OCPBUGS-18868 : [release-4.14] e2e: add expected max latancy to hwlatdetec test & rename constant (#788) (#808) (#809) #788
Release leader election on manager exit (#789) #789
Fix a race in e2e test rollback.go code (#742) #742
pao: e2e: Make script executable (#734) #734
pao e2e: Split gcp-pao lane (#728) #728
Do not rollback settings on TuneD exit (#711) #711
OCPBUGS-15800 : e2e: latency testing: increase the expected threshold and fix gomega truncating output (#710) #710
Revert “Remove optimization to allow full resync (#569)” (#688) #569
update owners 20230109 (#549) #549
Add PerformanceProfiles to ‘oc adm must-gather’ (#667) #667
OCPBUGS-14472 : Fix updating numa core siblings map in GetCpuSiblings function (#675) #675
Remove trailing spaces from test names (#572) #572
Remove optimization to allow full resync (#569) #569
e2e:latency: count LATENCY_TEST_DELAY in timeout (#539) #539
e2e: add missing test id (#630) #630
Remove subPaths, they are broken (#627) #627
Remove the preStop hook for openshift-tuned (#621) #621
E2E: Per Core Runtime Tuning Test automation (#509) (#568) #509
E2E: Network stack Pinning tests (#533) #533
Run node selector tests only if we 2 non Performanceworker nodes (#554) #554
skip multiple ranges test if cores < 20 and use core as key to delete cpu siblings (#543) #543
pao: latency-tests: read test log directly from pod (#547) #547
Add authentication to the /metrics endpoint (#553) #553
Update NTO images to be consistent with ART (#557) #557
OCPBUGS-5021 : [release-4.12] Fix two irqbalance tests - smp affinity vs online (#530) #530
Full changelog
OCPBUGS-87112 : Fix authenticated SSRF in Dev Console webhooks and Helm chartproxy #14
OCPBUGS-88398 , OCPBUGS-88416 : Bump Axios to fix CVE-2026-44486. Requires a Patch of axios 0.33.0 types to be compatible with old version of TS #16793
OCPBUGS-79430 : CVE-2026-29063 Bump immutable #16331
ART-18753 : pin fsevents to latest #16482
NO-JIRA: enable multi-architecture yarn builds #16422
NO-JIRA: Updating openshift-enterprise-console-container image to be consistent with ART for 4.12 #12539
CONSOLE-5011 : migrate to yarn berry #16084
NO-JIRA: Bump builder image to v29 #15988
OCPBUGS-74435 : Bump lodash to latest #15973
OCPBUGS-44155 : bump dompurify to latest #15595
OCPBUGS-57101 : Add all files to vendor regardless of gitignore #15137
OCPBUGS-55210 : Show Observe section without PROMETHEUS and MONITORING flags #14986
Dockerfile yarn line update #14838
OCPBUGS-45291 : Application creation fail when manually entering input scaling value in local setup #14572
OCPBUGS-45235 : Edit the secret and add the Chinese in the web-console, garbled characters will be displayed #14561
OCPBUGS-36561 : Increase login flow state paramater length/entropy #14539
OCPBUGS-43639 : Copy response code from proxied plugin requests #14423
OCPBUGS-33519 : Observe > Metrics targets, Alert user if they do not have access to information on this page (e.g. 403). #14334
OCPBUGS-41600 : Fix plugin proxy handler #14266
OCPBUGS-41854 : Redirects to new PipelineRun logs URL from old PipelineRun logs URL #14283
OCPBUGS-34564 : Routes created by devfiles do not always use HTTPS #13907
OCPBUGS-34933 : Helm Plugin’s Catalog incorrectly renders a single index entry into multiple tiles #13930
OCPBUGS-32146 : Bump graphql-go to v1.3.0 #13923
OCPBUGS-34845 : Fix PipelineRun Logs tab navigation #13920
OCPBUGS-33778 : fix issues with Edit Route form #13859
OCPBUGS-27479 : Bump helm pkg #13528
OCPBUGS-29746 : Add Pipeline metrics tab using plugin #13621
OCPBUGS-29348 : Added Proxy to non k8s endpoints #13600
OCPBUGS-22431 : Check if filtered object contains name property #13285
OCPBUGS-25213 : add access review for impersonate #13440
OCPBUGS-18116 : Bump helm version #13104
OCPBUGS-24236 : Remove tech preview badge from Pipeline repository pages #13384
OCPBUGS-23413 : Correct logout process #13342
OCPBUGS-24364 : Subsequent PipelineRuns take initial PipelineRun name into account #13401
OCPBUGS-13357 : add multipath device type to LocalVolumeSet #12805
OCPBUGS-23346 : update the KnativeServing API version to v1beta1 for global-config extension #13334
OCPBUGS-23154 : remove expandable toggle for conditional update risk d… #13322
OCPBUGS-22964 : add support for new features annotations while preservi… #13305
OCPBUGS-19382 : Could not import multiple resources via JSON (while YAML supports this) #13168
OCPBUGS-20071 : Fix that “Delete application” doesn’t work in topology when Pipelines operator is not installed #13212
OCPBUGS-21727 : fetch TaskRuns without selector and reduces the get TaskRuns requests #13251
OCPBUGS-21731 : show all the legends for Pipeline metrics in PipelineRun TaskRun Duration chart #13252
OCPBUGS-13580 : Regression: OpenShift Console no-longer filters SecretList when displaying ServiceAccount #12747
OCPBUGS-19907 : Fixed Edit Application form for Knative Services #13205
OCPBUGS-19045 : Web console slowness on Project>Project access page #13155
OCPBUGS-18273 : Fix topology crash when a console.topology/data/factory extension tries to resolve a resource with version from the CRDs which doesn’t exists #13113
OCPBUGS-18563 : OLM Pages work when copied CSVs are disabled #13055
OCPBUGS-17530 : fix bug where binary secret values are corrupted on edit and add test coverage #13087
OCPBUGS-18366 : Fix DeploymentConfig list performance issues by lazy loading their ReplicationControllers #13122
OCPBUGS-16660 : Manual cherry-pick of #12978 #13039
OCPBUGS-17192 : “Duplicate RoleBinding” leads to “Unsupported value” error #13063
OCPBUGS-16846 : Fix stop PLR option #13051
OCPBUGS-2182 : re-enable operator-install-single-namespace.spec.ts test #13013
OCPBUGS-16732 : When removing the project owner from the project in GUI, instead of that user, the group (the default group added as project admin through the project template) will be removed. #13047
OCPBUGS-16046 , OCPBUGS-16047 , OCPBUGS-16048 : Helm Chart installation form hangs on create if JSON-schema is using 2019-09 or 2020-20 standard revisions #12997
OCPBUGS-15898 : account for single object in status.conditions instead… #12982
OCPBUGS-16139 : The upgrade Helm Release tab in OpenShift GUI Developer console is not refreshing with updated values. #13004
OCPBUGS-15710 : Create helm release page doesn’t show a YAML editor when schema isn’t available (httpd-imagestreams chart) #12962
OCPBUGS-15849 : Add Pipeline metrics unsupported empty page #12977
OCPBUGS-9405 : [OSD] There is no error message shown on node label edi… #12965
OCPBUGS-15798 : Remove access review check for PipelineResource from Pipeline section #12969
OCPBUGS-13643 : Fix OLM k8sResourcePrefix descriptor dropdown behavior #12813
OCPBUGS-15569 : use service port name instead targetPort in the Pipeline Event listener route #12958
OCPBUGS-15535 : Delete annotation ‘tekton.dev/v1beta1TaskRuns’ when rerun the PLR #12955
OCPBUGS-15404 : Importing a kn Service shows a non-working Open URL decorator also when the Add Route checkbox was unselected #12935
OCPBUGS-15057 : only copy workload annotations to debug pod #12903
OCPBUGS-15099 : visiting Configurations page returns error Cannot read… #12906
OCPBUGS-15482 : Remove PipelineResource CRD check because it’s not installed with PO 1.11 anymore #12948
OCPBUGS-14190 : When Creating Sample Devfile from the Samples Page, Topology Icon is not set #12859
OCPBUGS-11989 : Modified git import flow module to handle create button enable-disable issue #12775
OCPBUGS-6848 : Service name search ability while creating the Route from console #12505
OCPBUGS-7619 : Search page: LazyActionMenus are shown below Add/Remove from navigation button #12575
OCPBUGS-7924 : Developer - Topology : ‘Filter by resource’ drop-down i18n misses #12598
OCPBUGS-13803 : add support for minimal status of tekton #12831
OCPBUGS-13750 : use PipelineRun template from ‘pipelines-as-code-pipelinerun-go’ configMap for Go runtime #12829
OCPBUGS-12839 : Show type of sample on the samples view #12783
OCPBUGS-12992 : Pipeline doesn’t render correctly when displayed but looks fine in edit mode #12791
OCPBUGS-9336 : use buildconfig form also for create #12770
OCPBUGS-11601 : Move operator install status to it’s own … #12715
OCPBUGS-12232 : Fix for broken Create key/value secrets e2e tests #12750
OCPBUGS-11844 : delete associated pipeline, triggertemplate and eventlistener when deleting app #12727
OCPBUGS-11972 : update the default pipelineRun template name #12687
OCPBUGS-6888 : Show Git icon and repo link as per the Git provider #12511
OCPBUGS-12476 : Pipelines repository list and creation form doesn’t show Tech Preview status #12763
OCPBUGS-1753 : Fix OLM descriptor components deletes operand e2e test failing #12573
OCPBUGS-12477 : Users don’t know what type of resource is being created by Import from Git or Deploy Image flows #12765
OCPBUGS-11998 : Do not show builder ImageStreams without sampleRepo as samples #12740
OCPBUGS-5009 : Helm Charts and Samples are not disabled in topology actions if actions are disabled in customization #12382
OCPBUGS-7953 : fix devfile error #12605
OCPBUGS-6672 : In DeploymentConfig both the Form view and Yaml view are not in sync #12475
OCPBUGS-8016 : PipelineRun templates must be fetched from OpenShift namespace #12614
OCPBUGS-10225 : Get the Event type value from the latest PLR of the Repository #12643
OCPBUGS-7333 : Add missing SDK extensions descriptions #12556
OCPBUGS-7951 : delete application should delete all part-of resources #12604
OCPBUGS-6036 : Project dropdown order is not as smart as project list page order #12447
OCPBUGS-7800 : add subject kind dropdown in the project access form #12586
OCPBUGS-8339 : disable operator-install-single-namespace.spec.ts until… #12624
OCPBUGS-3892 : Add cluster to query params of websocket requests #12282
OCPBUGS-5092 : Fix to use and set correct secretReference for build-config triggers #12388
OCPBUGS-7895 : Bump helm version to 3.10.1 #12579
OCPBUGS-6873 : The dropdown list component will be covered by deployment details page on Topology page #12507
OCPBUGS-6831 : Fix crash when pinnedResources is null #12503
OCPBUGS-7471 : Right border radius is 0 for the pipeline visualization wrapper in dark mode #12565
OCPBUGS-7506 : Fix different CI issues #12555
OCPBUGS-6966 : Remove description field from the PLR parameters page #12519
OCPBUGS-7437 : Webhook Secret (1 of 2) is not removed when Knative Service is deleted #12560
OCPBUGS-6887 : Show Tag label and tag name if tag is detected in repository PipelineRun list and details page #12510
OCPBUGS-6816 : Repositories list does not show the running pipelinerun as last pipelinerun #12500
OCPBUGS-4072 : Fix rerender loop/crash when bindable-kinds is found but has no status #12304
OCPBUGS-6671 : fix broken pipeline secret #12474
OCPBUGS-6913 : PipelineRun task status overlaps status text #12516
OCPBUGS-6766 : Fix to provide an option to delete all app resources on delete-resource modal for D/DC/KSVC #12491
OCPBUGS-6969 : Added translation to Last used in resource type dropdown #12521
OCPBUGS-6764 : Add Git Repository (PAC) showed empty permission content and non-working help link until a git url is entered #12490
OCPBUGS-4281 : Do not disable metrics when auth is disabled #12323
OCPBUGS-6669 : Do not show UpdateInProgress when status is Failing #12473
OCPBUGS-5093 : Fix to show correct help texts for each git repo status error code #12389
OCPBUGS-6085 : Editing Pipeline in the ocp console should show correct information #12452
OCPBUGS-6758 : Add RBAC check on Create a Project link in all-namespaces pages #12489
OCPBUGS-6755 : Remove refs-heads from the branch name for Repository pipelineRun row #12487
OCPBUGS-6743 : Fix react warning when open console, add missing keys in navigation #12484
OCPBUGS-5875 : Don’t proxy CORS response headers #12276
OCPBUGS-6678 : fix run-time error on Cluster Settings when availableUp… #12476
OCPBUGS-4633 : Monitoring: Fix alert descriptions with duplicate resources #12352
And 3 elided commits (e.g. from squash or rebase merges)
Full changelog
OCPBUGS-77768 : fix vendor for hermetic 4.12 #7823
Updating ose-hypershift-container image to be consistent with ART for 4.12 #6976
OCPBUGS-41516 : set Konnectivity cipher suites #4283
MULTIARCH-3709 : PowerVS - Add reuse resource flags to e2e test #2994
MULTIARCH-3732 : PowerVS - Fix cluster deletion when existing resources passed #2993
MULTIARCH-3733 : Add dev flags in destroy cluster powervs command #2998
Updated secret permissions for openshift-route-controller-manager #2924
fix(hcco): Add HCP label to HCCO by default #2972
fix(ignition): Add HCP label to ignition-server by default #2949
OCPBUGS-16847 : use ignition-proxy Service to populate ignitionEndpoint with strategy NodePort #2855
[release 4.12] OCPBUGS-11555: OAuth OpenShift deployment requires ConfigMap mount patch2 #2803
OCPBUGS-16411 : fix deletion bug when hostedzone is already deleted #2835
Kas policy 4.12 #2826
Leader election config update. #2800
OCPBUGS-15614 : Check OwningIngressController also in Labels #2759
OCPBUGS-16086 : autoscaling balance similar groups #2806
HOSTEDCP-1060 : refactor ignition-server reconcilation and add ignition-server proxy #2749
OCPBUGS-14873 : Update vendored openshift API for 4.12 #2734
HOSTEDCP-1073 : enforce blocked rollout of HCP #2745
properly handle user CA bundle not existing #2711
OCPBUGS-15304 : [release-4.12] fix(oauth): Do not proxy IBM Cloud IAM endpoints #2695
OCPBUGS-14873 : Honor global ingress configuration LoadBalancer type on AWS #2678
OCPBUGS-14803 : Set DisableStrictZoneCheck = true in the AWS Cloud Provider config #2667
[release 4.12] OCPBUGS-11555: OAuth OpenShift deployment requires ConfigMap mount #2512
OCPBUGS-14156 : Reconcile oauthDeployment annotations even if kubeadmin secret is not found #2614
OCPBUGS-14031 : Include default ingress CA in root CA bundle #2600
OCPBUGS-13626 : Sync proxy TrustedCA to guest cluster #2557
OCPBUGS-13639 : Cherry pick aws endpoint sg #2579
OCPBUGS-12787 : fix(hcco): Get OLM CatalogSource images from defined map #2485
ACM-5173 [backport 4.12] get pull secret instead of dockerconfigjson from mce credentials #2486
Configurable SRE MetricsSet #2545
OCPBUGS-13077 : Ensure ingress controllers are removed before load balancers #2515
OCPBUGS-11544 : Pass runAsUser to CNO so it can run its managed services with proper security context #2391
OCPBUGS-12845 : Delete kubeadmin secret when an idp is defined #2492
OCPBUGS-12738 : Pass OPENSHIFT_RELEASE_IMAGE env variable to CNO #2473
OCPBUGS-12199 : remove ACL for aws bucket #2458
OCPBUGS-11607 : properly reconcile with user specified changes for in proxy configuration #2395
OCPBUGS-11726 : Update HostedCluster oauthCallbackURLTemplate #2410
e2e: Cleanup shared OIDC provider on SIGTERM #2449
HOSTEDCP-568 : Update Konnectiviy socks5 proxy for IBM exception #2406
OCPBUGS-10584 : Switch NTO metrics auth to certs generated by HCP controller #2293
OCPBUGS-11014 : Do not proxy when guest cluster resolution fails #2340
OCPBUGS-11654 : [release-4.12] Create new EC2 client for AWS identity provider health check #2403
OCPBUGS-10646 : Add storage operators perms. to watch HostedControlPlane #2306
HOSTEDCP-939 : [release-4.12] Setup shared OIDC provider for e2e clusters #2365
HOSTEDCP-806 : Fix ValidAWSKMSConfig condition #2362
OCPBUGS-11056 : fix external APIServer address selection based on endpointAccess #2350
OCPBUGS-10823 ensure well known public domains do not get proxied on image imports #2351
SDA-8707 : No more specifying the scrape interval at servicemonitors & podmonitors level #2356
HOSTEDCP-900 : Modified AWSPrivateLinkController and AWSEndpointServiceController to respect PausedUntil spec field #2285
OCPBUGS-10504 : Deletion of the VPCEnpoint on conflicting service names #2310
HOSTEDCP-806 : [release-4.12] Validate etcd KMS config #2273
HOSTEDCP-801 : [release-4.12] Expose external DNS for private cluster endpoints #2314
HOSTEDCP-839 : Audit log sidecars for openshift-apiserver and openshift-oauth-apiserver #2297
OCPBUGS-10587 : Use appropriate serving certificate for OAuth #2295
OSD-15099 : Delaying the creation of servicemonitor and podmonitor resources till the hostedcluster is Completed #2274
Add PodMonitor for ingress-operator pods in HCP namespaces #2275
OCPBUGS-8334 : [release-4.12] Update the pull secret source for ignition payload #2268
Force controleplane upgrade always #2289
OCPBUGS-8370 : Fix cleanup of volumes on cluster deletion #2253
OCPBUGS-8241 : Add external DNS health condition / release-4.12 #2206
HOSTEDCP-809 : Clone CA key/cert to TLS key/cert #2263
Add configuration for automatic labeling and label commands #2255
fix(cpo): Delete multus validatingwebhookconfiguration on CNO init #2251
feat(HCCO): Block DNS operator delete until Cluster Version updated #2242
kms addition for pod identity workflow #2247
Add e2e test for hosted cluster behind a proxy #2199
Add e2e test for cluster creation with AWS KMS #2201
HOSTEDCP-826 : Customize DNS base domain prefix #2235
feat: Add pod gone check to prober + DNS operator leader elect #2209
fix(ibmcloud): Explicitly set HCCO controllers #2208
ensure reconcilation of apiserver port is in 4.12 #2195
Cleanup default security group only if authorized #2212
fix(cpo): Set restart annotation on multus-admission-controller #2190
fix(cpo): Remove OLM collect for IBM Cloud to reduce artifacts and rbac #2189
fix(cpo): Reduce CNO access if Calico used as network provider #2184
Skip destroyAWSDefaultSecurityGroup if not AWS #2168
Create default security group for AWS clusters #2162
AUTH-323 : pki: split out konnectivity certs from the rootCA #2156
fix(ibmcloud): Initialize image registry config on creates and bad config #2104
fix(cpo): Allow KAS profiling disablement #2122
reduce ignition server scope #2140
OpenID add support for groups claim in the config #2129
fix(cpo): Restart registry operator on annotation #2121
Fix CAPA crd generation #2120
Set k8s.io/kubernetes dependency to v0.23.3 #2118
fix(cpo): Separate RBAC for NTO + CNO #2112
Merge main up to db7c22ae into ‘release-4.12’ #2101
Full changelog
-sOCPBUGS-59700:Bump github.com/golang/glog to v1.2.4 (#125) #125
Replace e2e test image (#134) #134
swtich golint install method (#133) #133
Correct 4.16 owners file (#131) #131
Added METRIC_TEST_IMAGE var (#92) #92
Update the k8s dependencies to 1.25.15 (#84) #84
Revert “Remove e2e tests that consistently fail in 4.12 (#74)” (#77) #74
Remove e2e tests that consistently fail in 4.12 (#74) #74
Updating ose-network-metrics-daemon images to be consistent with ART (#60) #60
Fix gofmt check issue (#68) #68
Update golang.org/x/text to 0.7.0 (#66) #66
Full changelog
: OCPBUGS-27593,OCPBUGS-27678: Update go-git to v5.11.0 #76
OCPBUGS-23449 : [release-4.12] Address http2 Vulnerability #64
OCPBUGS-21343 : [release-4.12] Bump golang.org/x/net to v0.17.0 #41
UPSTREAM: <carry>: add downstream owners #43
And 1 elided commits (e.g. from squash or rebase merges)
Full changelog
Source code for this page located on github