Back to index
Download the installer for your operating system or run
oc adm release extract --tools quay.io/openshift-release-dev/ocp-release:4.13.70-x86_64 Qualifiers (status api ): None
Tests:
Blocking jobs Informing jobsaws-sdn-serial Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-sdn-serialaws-sdn-upgrade-4.13-micro Succeeded (1 retry) periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-sdn-upgradeazure-ovn-upgrade-4.13-micro Failed (1 retry) periodic-ci-openshift-release-main-ci-4.13-e2e-azure-ovn-upgradedriver-toolkit Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-aws-driver-toolkitfips-scan Succeeded periodic-ci-openshift-release-main-nightly-4.13-fips-payload-scanmetal-ipi-ovn-ipv6 Succeeded periodic-ci-openshift-release-main-nightly-4.13-e2e-metal-ipi-ovn-ipv6metal-ipi-sdn-ipv4 Succeeded (1 retry) periodic-ci-openshift-release-main-nightly-4.13-e2e-metal-ipi-sdn-ipv4 Upgrades from:
Untested upgrades:
4.12.19 ,
4.12.20 ,
4.12.21 ,
4.12.22 ,
4.12.23 ,
4.12.24 ,
4.12.25 ,
4.12.26 ,
4.12.27 ,
4.12.28 ,
4.12.30 ,
4.12.31 ,
4.12.32 ,
4.12.33 ,
4.12.34 ,
4.12.35 ,
4.12.36 ,
4.12.37 ,
4.12.38 ,
4.12.39 ,
4.12.40 ,
4.12.41 ,
4.12.42 ,
4.12.43 ,
4.12.44 ,
4.12.45 ,
4.12.46 ,
4.12.47 ,
4.12.48 ,
4.12.49 ,
4.12.50 ,
4.12.51 ,
4.12.52 ,
4.12.53 ,
4.12.54 ,
4.12.55 ,
4.12.57 ,
4.12.58 ,
4.12.59 ,
4.12.60 ,
4.12.61 ,
4.12.62 ,
4.12.63 ,
4.12.64 ,
4.12.65 ,
4.12.66 ,
4.12.67 ,
4.12.68 ,
4.12.69 ,
4.12.70 ,
4.12.71 ,
4.12.72 ,
4.12.73 ,
4.12.74 ,
4.12.75 ,
4.12.76 ,
4.12.78 ,
4.12.79 ,
4.12.80 ,
4.12.81 ,
4.12.82 ,
4.12.83 ,
4.12.84 ,
4.12.85 ,
4.12.86 ,
4.12.87 ,
4.12.88 ,
4.12.89 ,
4.12.90 ,
4.12.91 ,
4.12.92 ,
4.12.93 ,
4.13.10 ,
4.13.11 ,
4.13.12 ,
4.13.13 ,
4.13.14 ,
4.13.15 ,
4.13.16 ,
4.13.18 ,
4.13.19 ,
4.13.21 ,
4.13.22 ,
4.13.23 ,
4.13.24 ,
4.13.25 ,
4.13.26 ,
4.13.27 ,
4.13.28 ,
4.13.3 ,
4.13.30 ,
4.13.31 ,
4.13.32 ,
4.13.33 ,
4.13.34 ,
4.13.35 ,
4.13.36 ,
4.13.37 ,
4.13.38 ,
4.13.39 ,
4.13.4 ,
4.13.40 ,
4.13.41 ,
4.13.42 ,
4.13.43 ,
4.13.44 ,
4.13.45 ,
4.13.47 ,
4.13.48 ,
4.13.49 ,
4.13.5 ,
4.13.50 ,
4.13.51 ,
4.13.52 ,
4.13.53 ,
4.13.54 ,
4.13.55 ,
4.13.56 ,
4.13.57 ,
4.13.58 ,
4.13.59 ,
4.13.6 ,
4.13.60 ,
4.13.61 ,
4.13.62 ,
4.13.63 ,
4.13.64 ,
4.13.65 ,
4.13.66 ,
4.13.7 ,
4.13.8 ,
4.13.9 Upgrades to:
Loading changelog, this may take a while ...
Changes from 4.13.2
Created: 2026-08-12 09:19:49 +0000 UTC
Image Digest: sha256:033e3d7ba0937c0b3d2f88993bbe2e97c8b396f1782a7353c68ebe1282b2586c
Components
Rebuilt images without code change
alibaba-machine-controllers git 4c0f96a6 sha256:73d111697ae8f3616fad6c6f509d097d2f69a86d1071fa5f6928aba61c5f0773
cluster-bootstrap git ee908b6b sha256:486ce6cc9321c92f18b10a3f2aa38a82935b706013b09b5f1246118e2d2a6740
configmap-reloader git 9adad592 sha256:d19f918c64906e8844e24e7a1b220234503dedea7f253da58d35d548662f9b8b
driver-toolkit git d719bdcf sha256:36424623a6c359b5dca9e637ee0046ba9bed11fefdef338cdccf871001c6188f
machine-os-content sha256:3b96a99636f9283f19e2a63e4a4cdc2e012e9268a9d7588084dc2e60ca7bb4fb
ovirt-machine-controllers git 22d89b3f sha256:d09dbb0746059d65553ecb138bf7c4de018d4cee77696362b6673c0825aa18ad
prom-label-proxy git b501d5e2 sha256:b1546d98eef7a4c96dd3667c9074cab35c650dfb71793aaa555d3b9211f8db29
rhel-coreos sha256:ee30344527602744bfa9996f0ed2a4fe7ee9f310ba8df1c45298153cc93c9dce
rhel-coreos-extensions sha256:88e09c2dd91304a5d611495448ee01642596336808c569bc103c90a2bfd23453
OCPBUGS-67602 : CVE-2025-65637 openshift4/ose-cluster-kube-apiserver-operator: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [openshift-4.13.z] #2047
OCPBUGS-50850 : Increase waitForFallbackDegradedConditionTimeout #1809
OCPBUGS-34062 : [4.13] add a controller that reconciles SCCs’ volumes #1677
OCPBUGS-25922 : [release-4.13] dashboard: use recording rules for most metrics #1611
: OCPBUGS-24023: Add workload partitioning annotation #1591
: OCPBUGS-20880: bump library-go to include switch to HTTP/1.1 #1573
OCPBUGS-19825 : Update staticpod file permissions to conform with CIS benchmarks #1558
OCPBUGS-15853 : pkg/operator/configobserver: check that the serving certificate refer… #1522
OCPBUGS-17081 : make webhook connection failure a warning in log #1532
OCPBUGS-13763 : dont log jwt tokens #1499
Full changelog
E2E: workload hints: compare existing profile with changes being made to avoid mcp getting stuck (#1069) #1069
OCPBUGS-33030 : [release-4.13][manual]Reduce number of reboots in offline tests (#1048) #1048
Scheduler plugin: ignore IRQs (#1027) #1027
irqbalance: set banned cpus list to 0 (#1003) #1003
OCPBUGS-24353 : rps: cherry-picks of rps fixes (#865) #865
Disable HTTP/2 for webhook and metrics servers (#846) #846
Remove obsolete protocols and weak ciphers (#843) #843
OCPBUGS-18493 : e2e: deflake IRQ load-balancing (#782) #782
Use RHEL9 as a base (#829) #829
OCPBUGS-17943 : Add rtentsk plugin to pp tuned profile Signed-off-by: Brent Rowsell <browsell@redhat.com> (#796) #796
nto: avoid timeout when there are too many CSV (#818) #818
OCPBUGS-19459 : check for object being nil (#820) #820
Add kubeconfig path for IBM Managed OpenShift (#814) #814
OCPBUGS-14137 : e2e: perfprof: add SNO device recovery test (#653) (#806) #653
OCPBUGS-18868 : [release-4.14] e2e: add expected max latancy to hwlatdetec test & rename constant (#788) (#808) #788
Sync DaemonSet if operand image changes (#786) #786
Revert “Revert “Release leader election on manager exit (#773)” (#797)” (#802) #773
OCPBUGS-19351 : Keep Profile status.bootcmdline around (#803) #803
Revert “Release leader election on manager exit (#773)” (#797) #773
Release leader election on manager exit (#773) #773
Tighten the rules for modifying Tuned Profiles (#766) #766
OCPBUGS-18063 : cgroup: Match the name of the cgroup to what is expected by kubelet (#774) #774
update tsc karg to tsc=reliable (#757) #757
OCPBUGS-17845 : deflake ht aware test (#763) #763
OCPBUGS-17794 : rps: use default rps mask kernel API (#760) #760
Improve render error handling (#755) #755
nto:tuned: remove sched_min_granularity_ns settings (#726) #726
Fix a race in e2e test rollback.go code (#740) #740
E2E: Add memory manager sanity test case (#573) (#695) #573
e2e: latency testing: increase the expected threshold (#709) #709
Do not rollback settings on TuneD exit (#704) #704
Switch to rslave/HostToContainer volume mount propagation (#705) #705
e2e: perf-prof: disable truncating gomega output (#707) #707
OCPBUGS-14895 : Do not fail creating cgroups if they exist already (#684) #684
OCPBUGS-14331 : Fix updating numa core siblings map in GetCpuSiblings function (#669) #669
render: remove uid from render-sync target (#594) (#609) #594
Remove cpu-quota.crio.io: disable annotation (#670) #670
Add PerformanceProfiles to ‘oc adm must-gather’ (#657) #657
Full changelog
NO-ISSUE: Updating ose-cluster-update-keys-container image to be consistent with ART for 4.13 #78
OCPBUGS-43886 : keys: Update Red Hat keys to use SHA256 signatures #67
Adding the new CI Signer public key #50
Full changelog
Fix for OCPBUGS-81594: CVE-2026-4800 #16569
OCPBUGS-88410 , OCPBUGS-88442 : CVE-2026-44486 openshift4/ose-console: Axios: Information disclosure of proxy credentials via HTTP redirects #16779
OCPBUGS-88375 , OCPBUGS-88384 , OCPBUGS-88391 , OCPBUGS-88404 , OCPBUGS-88410 , OCPBUGS-88414 , OCPBUGS-88442 : CVE-2026-44495 #16622
OCPBUGS-79432 : CVE-2026-29063 Bump immutable #16330
ART-18919 : pin fsevents to latest #16481
NO-JIRA: enable multi-architecture yarn builds #16423
CONSOLE-5011 : migrate to yarn berry #16083
NO-JIRA: Bump builder image to v29 #15989
OCPBUGS-74437 : Bump lodash to latest #15972
OCPBUGS-44160 : bump dompurify to latest #15594
OCPBUGS-57100 : Add all files to vendor regardless of gitignore #15136
OCPBUGS-54892 : Show Observe section without PROMETHEUS and MONITORING flags #14960
OCPBUGS-45292 : A value submitted in From view is wrapped with single quotation after switching to Yaml view. #14573
OCPBUGS-44356 : Application creation fail when manually entering input scaling value in local setup #14509
OCPBUGS-45197 : Edit the secret and add the Chinese in the web-console, garbled characters will be displayed #14552
OCPBUGS-44585 : Need to allow blank for Project/namespace when setting SA Subject in ‘Project access tab’ #14497
OCPBUGS-36557 : Increase login flow state paramater length/entropy #14483
OCPBUGS-42951 : The filepath including leading slash makes error during parsing devfile using Gitlab #14383
OCPBUGS-41594 : Redirects to new PipelineRun logs URL from old PipelineRun logs URL #14263
OCPBUGS-35259 : fix vCenter cluster being empty #13952
OCPBUGS-32147 : Bump graphql-go to v1.3.0 #13922
OCPBUGS-33978 : Helm Plugin’s Catalog incorrectly renders a single index entry into multiple tiles #13872
OCPBUGS-34342 : Fix PipelineRun Logs tab navigation #13890
OCPBUGS-24395 : Extra space is in the translation text(Chinese) of ‘Create rolebinding’ and ‘replicate rolebinding’ #13405
OCPBUGS-33777 : restrict Masthead logo to max-height to 60px #13860
OCPBUGS-33749 : Add visual connector between VMs and non VMs workloads #13857
OCPBUGS-33382 : Routes created by devfiles do not always use HTTPS #13827
OCPBUGS-33650 : fix issues with Edit Route form #13851
OCPBUGS-32500 : PipelineRuns in Console show wrong status or load indefinitely #13780
OCPBUGS-31077 : Pipeline Name gets changed to “new-pipeline” on the Edit Pipeline YAML/Builder #13683
OCPBUGS-31595 : Fix operands list endpoint. #13714
OCPBUGS-29063 : add additional check to determine if file is binary #13579
OCPBUGS-28788 : Copy response code from proxied plugin requests #13561
OCPBUGS-29243 : Add a new allowInsecure option to the internet proxy #13593
OCPBUGS-27406 : Add Pipeline metrics tab using plugin #13525
OCPBUGS-23483 : add access to create, edit and delete silences for developer user from developer perspective #13349
OCPBUGS-25427 : Fix plugin proxy handler #13449
OCPBUGS-25465 : fix runtime error on Node details Overview when Machin… #13452
OCPBUGS-25146 : add access review for impersonate #13437
OCPBUGS-24591 : ConsolePlugin metrics must no longer be grouped by the vendor #13424
OCPBUGS-22241 : Save also the location.search and .hash values in localStorage to restore them after login #13271
OCPBUGS-24240 : Subsequent PipelineRuns take initial PipelineRun name into account #13385
OCPBUGS-23497 : Cannot Edit Shipwright Build #13352
OCPBUGS-11316 : Fix description for BuildAdapter SDK extension #12703
OCPBUGS-22986 : Correct logout process #13310
OCPBUGS-23065 : remove expandable toggle for conditional update risk d… #13316
OCPBUGS-22784 : add support for new features annotations while preservi… #13299
OCPBUGS-19532 : use active namespace in Create cta href of create action for operator backed #13179
OCPBUGS-18271 : update the KnativeServing API version to v1beta1 for global-config extension #13112
OCPBUGS-20232 : show all the legends for Pipeline metrics in PipelineRun TaskRun Duration chart #13224
OCPBUGS-20231 : fetch TaskRuns without selector and reduces the get TaskRuns requests #13223
OCPBUGS-20330 : Check if filtered object contains name property #13227
OCPBUGS-13285 : add multipath device type to LocalVolumeSet #12804
OCPBUGS-17481 : Fix that “Delete application” doesn’t work in topology when Pipelines operator is not installed #13083
OCPBUGS-18764 : Fixed Edit Application form for Knative Services #13147
OCPBUGS-18538 : OCP console mandate secret for repository creation #13135
OCPBUGS-18679 : [knative] Don’t rely on openshift/hello-openshift as a sample image #13140
OCPBUGS-18289 : Not able to import the repository with .tekton directory and func.yaml file present #13116
OCPBUGS-18443 : Fix crash when filtering the quick start catalog #13127
OCPBUGS-18312 : Web console slowness on Project>Project access page #13119
OCPBUGS-18335 : Fix DeploymentConfig list performance issues by lazy loading their ReplicationControllers #13120
OCPBUGS-17876 : Fix topology crash when a console.topology/data/factory extension tries to resolve a resource with version from the CRDs which doesn’t exists #13095
OCPBUGS-16668 : Dynamic plugin translation support for plurals broken #13041
OCPBUGS-17181 : Creation of GH webhook and attaching it to repo while importing from git using PAC #13060
OCPBUGS-16040 : fix bug where binary secret values are corrupted on edit and add test coverage #13048
OCPBUGS-16659 : Fix RTE in bridge. #13038
OCPBUGS-16158 : “Duplicate RoleBinding” leads to “Unsupported value” error #13008
OCPBUGS-16434 : Fix stop PLR option #13031
OCPBUGS-14265 : Regression: OpenShift Console no-longer filters SecretList when displaying ServiceAccount #12865
OCPBUGS-13641 : Do not fetch catalog sources on CSV or Subscription details pages. #12811
OCPBUGS-16421 : When removing the project owner from the project in GUI, instead of that user, the group (the default group added as project admin through the project template) will be removed. #13030
OCPBUGS-15998 : Upload JAR file does not work if the Cluster Samples Operator is disabled #12992
OCPBUGS-15810 : only show pipelines doc link for downstream #12981
OCPBUGS-15982 : get Kamelets from the camel-k-operator namespace as well #12988
OCPBUGS-16244 : Fix operator backed catalog page when copied CSVs disabled #13019
OCPBUGS-15194 : Remove tech preview badge from Pipeline repository pages #12916
OCPBUGS-10326 : re-enable operator-install-single-namespace.spec.ts test #12653
OCPBUGS-15848 : The upgrade Helm Release tab in OpenShift GUI Developer console is not refreshing with updated values. #12976
OCPBUGS-15890 : Use proxy with web socket connection and monitoring dashboard #12978
OCPBUGS-15720 , OCPBUGS-15721 , OCPBUGS-15722 : Helm Chart installation form hangs on create if JSON-schema is using 2019-09 or 2020-20 standard revisions #12963
OCPBUGS-14426 : account for single object in status.conditions instead… #12875
OCPBUGS-14267 : Add Pipeline metrics unsupported empty page #12864
OCPBUGS-15410 : Add Git Repository (PAC) doesn’t setup GitLab and Bitbucket configuration correct #12936
OCPBUGS-15787 : Remove access review check for PipelineResource from Pipeline section #12967
OCPBUGS-15228 : Create helm release page doesn’t show a YAML editor when schema isn’t available (httpd-imagestreams chart) #12937
[release 4.13] OCPBUGS-15360: Serverless functions UI warning is misleading #12931
OCPBUGS-14166 : Fixed Make Serverless Form Error #12857
OCPBUGS-14336 : use service port name instead targetPort in the Pipeline Event listener route #12870
OCPBUGS-14310 : Could not import multiple resources via JSON (while YAML supports this) #12868
OCPBUGS-15335 : Delete annotation ‘tekton.dev/v1beta1TaskRuns’ when rerun the PLR #12927
OCPBUGS-15130 : Helm Repository “Edit” button results in 404 #12909
OCPBUGS-14189 : Corrected Labels for resolving the bug related to the Create Route Checkbox #12858
OCPBUGS-13642 : Fix OLM k8sResourcePrefix descriptor dropdown behavior #12812
OCPBUGS-11974 : Add page title to Devconsole pages #12844
OCPBUGS-15465 , OCPBUGS-15481 : Remove PipelineResource CRD check because it’s not installed with PO 1.11 anymore and disable operator-uninstall test #12949
OCPBUGS-14943 : visiting Configurations page returns error Cannot read… #12897
OCPBUGS-12785 : Project admin can update and view subscription from operator details page #12780
OCPBUGS-14574 : only copy workload annotations to debug pod #12879
OCPBUGS-14258 : Add vSphere cluster field. #12862
OCPBUGS-14195 : Topology UI doesn’t recognize Serverless Rust function for proper UI icon #12860
OCPBUGS-10527 : When there are 2 pipelines displayed in the dropdown menu, selecting one, unchecks the Add Pipeline checkbox #12658
OCPBUGS-14165 : propagate labels to pipeline resources #12856
Full changelog
OCPBUGS-84928 : Replace google.golang.org/grpc with github.com/openshift-sustaining/grpc-go v1.64.1-sec.1 to avoid go version bump and fix CVE-2026-33186 #185
Full changelog
“OCPBUGS-29791: [release-4.13] Address CVE-2024-1725: Restrict access to infrastructure PVCs by requiring matching infraClusterLabels on tenant PVCs” #35
Full changelog
OCPBUGS-59699 : Bump github.com/golang/glog to v1.2.4 (#117) #117
[release 4.13] OCPBUGS-60541: Replace e2e test image (#132) #132
swtich golint install method (#129) #129
Correct 4.16 owners file (#130) #130
Added METRIC_TEST_IMAGE var (#90) #90
Update the k8s dependencies to 1.26.10 (#83) #83
Full changelog
changes the owners file (#1012) #1012
OCPBUGS-48513 : e2e: use same version of crane as in go.mod (#1025) #1025
Bump version to include v5.11.0 of go-git (#823) #823
OCPBUGS-385 : Capability to override default channel (#749) (#791) #749
OCPBUGS-19429 : Fix cross EUS channel upgrade path calculation (#775) #775
OCPBUGS-21460 : Fix CVE-2023-44487 and CVE-2023-39325 (#714) #714
Fix OCPBUGS-17546: pod catalogsource generated by oc-mirror will crashloopBackOff randomly (#700) #700
Fix OCPBUGS-14402 (#675) #675
OCPBUGS-18556 : operator catalogs from oc-mirror fail to deploy because of invalid caches (#691) #691
OCPBUGS-18106 : manual cherrypick (#684) #684
OCPBUGS-17998 : fix: ICSP with incorrect mirror path (#685) #685
OCPBUGS-17453 : Fix “ OCI index found, but accept header does not support OCI indexes (#677) #677
OCPBUGS-16372 : A variety of changes needed for correct operation with multi… (#661) #661
OCPBUGS-13871 : fix: changes on help info content (#654) #654
Fix OCPBUGS-11840: ParseImageReference supports cases where both tag and digest are present in a ref (#637) #637
Full changelog
: OCPBUGS-27594,OCPBUGS-27679: Update go-git to v5.11.0 #75
OCPBUGS-23403 : [release-4.13] Address http2 vulnerability #58
OCPBUGS-21363 : [release-4.13] Bump golang.org/x/net to v0.17.0 #40
UPSTREAM: <carry>: add downstream owners #42
And 1 elided commits (e.g. from squash or rebase merges)
Full changelog
Source code for this page located on github