GCP Releases

Google Cloud releases and Terraform Google provider. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.

Tracking 829 GCP releases · Updated

  • Google Cloud release notes securitygcpengineer ·

    Developer Connect enhances security for GitLab/Bitbucket connections

    Developer Connect now enforces granular permissions for GitLab Enterprise and Bitbucket Data Center connections by checking both the calling principal and the service agent against Secret Manager secrets. This change adheres to the principle of least privilege, enhancing security by ensuring only authorized entities can access sensitive Git provider credentials. The update affects users managing these specific types of repository connections and is detailed in the Developer Connect security bulletin.

    security
  • Google Cloud release notes datasecuritygcpengineergcp-bigquery ·

    Dataform Security Vulnerability in BigQuery and Colab Enterprise

    A security vulnerability was found in Dataform repositories within BigQuery and Colab Enterprise, allowing authenticated attackers to escalate privileges and take over cross-tenant repositories. This impacts users of Dataform, BigQuery, and Colab Enterprise. Further details are available in the GCP-2026-047 security bulletin.

    security
  • Google Cloud release notes infradeprecationgcp-gke ·

    GKE Updates Include New Versions and Security Patches

    Google Kubernetes Engine (GKE) has released new cluster versions across its Rapid, Regular, Stable, and Extended channels, enabling upgrades and new cluster creation. This update also incorporates security fixes through updated Container-Optimized OS images, enhancing system security for all users. Specific versions are being deprecated in the Extended channel, with removal scheduled within 90 days, requiring users to plan their upgrades accordingly.

    security patch
  • Google Cloud release notes infragcpengineer ·

    Apigee hybrid v1.16.7 includes security fixes

    Google Cloud has released Apigee hybrid v1.16.7, incorporating various security and CVE fixes. This patch release also includes updates to container images integrated with Apigee hybrid Helm charts. Users can upgrade via the Helm chart, which automatically updates the necessary images. The release is available now for users of Apigee hybrid.

    security announcement
  • Google Cloud release notes securityinfragcpsecurity-advisoryengineerenergy ·

    Container Optimized OS Updates: Kernel, Docker, Security Fixes, NVIDIA Drivers

    This release of Container Optimized OS (COS) includes multiple updates across kernel versions, Docker, and Containerd. Notably, it addresses several security vulnerabilities, including CVE-2026-53359 and KCTF-d82ba05 in the Linux kernel, and adds support for specific NVIDIA GRID driver versions. These updates are primarily targeted at users of COS who rely on containerization and GPU acceleration.

    security patch
  • Google Cloud release notes securitygcpsecurity-advisorygcp-bigquery ·

    Apigee X Security Vulnerability Affecting BigQuery DAO

    A vulnerability in Apigee X's BigQuery Data Access Object allowed authenticated attackers to exfiltrate cross-tenant data. This issue has been patched and affects specific versions on Google Cloud Platform, with Apigee hybrid remaining unaffected. No customer action is required for this security fix.

    security
  • Google Cloud release notes securityinfragcpsecurity-advisoryengineer ·

    Container Optimized OS Updates: Kernel, Docker, and Security Fixes

    This release of Container Optimized OS includes updates to the Linux kernel, Docker, and Containerd, alongside numerous package upgrades and critical security vulnerability fixes. These updates are crucial for maintaining system security and stability, affecting all users of the OS. Notably, multiple CVEs are addressed, enhancing the overall security posture of the system.

    security patch
  • Google Cloud release notes infragcpengineer ·

    Apigee Hybrid v1.15.5: Security Fixes and Patch Update

    Apigee Hybrid has released version v1.15.5, a patch update that includes various security and CVE fixes. This release integrates container images with Apigee Hybrid Helm charts, simplifying upgrades for users. The update is available now and is relevant for all users of Apigee Hybrid.

    security announcement
  • Google Cloud release notes securityinfragcpsecurity-advisoryengineer ·

    Container Optimized OS Updates Address Security and Features

    This release of Container Optimized OS includes numerous package updates and security patches for the Linux kernel and various libraries. It introduces new features for GPU support and enhances existing components. The updates are relevant for users running workloads on Google Cloud Platform, particularly those utilizing containers and GPU instances.

    security feature patch
  • Google Cloud release notes infradeprecationgcp-gke ·

    GKE Version Updates and Deprecations

    Google Kubernetes Engine (GKE) has released new cluster versions and updated default versions across its Rapid, Regular, Stable, and Extended channels. These updates provide users with newer Kubernetes features and bug fixes, while also deprecating older versions that will be removed within 90 days. The changes affect users managing GKE clusters, particularly those creating new clusters or performing manual upgrades, and are subject to rollout progress.

    security patch
  • Google Cloud release notes securityinfragcpengineergcp-gke ·

    Cloud Service Mesh Security Patch Releases and Gateway API Update

    Multiple patch releases for Cloud Service Mesh (versions 1.29.5-asm.5, 1.28.9-asm.4, and 1.27.9-asm.9) address security vulnerabilities including GCP-2026-045. Additionally, a new Security Proxy version (csm_mesh_proxy.csm_mesh_proxy.20260624e_RC01) for Gateway API on GKE clusters fixes vulnerabilities listed in GCP-2026-040. These updates are critical for maintaining the security posture of in-cluster Cloud Service Mesh deployments and GKE Gateway API users.

    security
  • Google Cloud release notes infradeprecationgcp-gke ·

    Google Kubernetes Engine version updates and deprecations

    Google Kubernetes Engine (GKE) has released new versions across its Rapid, Regular, Stable, and Extended channels, with updated defaults and availability for cluster creation and upgrades. Several older GKE versions are now deprecated and will be removed within 90 days, impacting users running these specific minor versions. Users are advised to review the updated version lists and plan their upgrades accordingly.

    security patch
  • Google Cloud release notes securitygcpengineer ·

    Application Integration Security Bulletins Page Launched

    Google Cloud has introduced a dedicated Security Bulletins page for Application Integration. This new resource aims to keep users informed about security updates, vulnerabilities, and remediation steps relevant to the service. All users of Application Integration should familiarize themselves with this page for timely security information.

    security
  • Google Cloud release notes securitygcpsecurity-advisoryengineer ·

    Apigee Emulator v2.0.1: Security Hotfix for Netty and Go Libraries

    Apigee Emulator v2.0.1, released June 24, 2026, is a security-only hotfix addressing 10 vulnerabilities in the Netty networking library and the embedded Cassandra Go standard library. This update provides a drop-in replacement for v2.0.0 with no functional, API, or configuration changes, affecting users of the Apigee Emulator. The updated image is available via Google Artifact Registry, and users can upgrade by updating their VS Code Cloud Code settings.

    security feature announcement
  • Google Cloud release notes securitygcpengineer ·

    Cloud Build security update for GitLab/Bitbucket connections

    Cloud Build now enforces stricter permissions checks for GitLab Enterprise and Bitbucket Data Center connections to enhance security. Previously, only the service agent's permissions were checked; now, both the calling principal and the service agent must have access to the necessary Secret Manager secrets. This change, which adheres to the principle of least privilege, affects users managing these specific Git repository connections.

    security
  • Google Cloud release notes infragcpengineergcp-dataprocgcp-compute-engine ·

    Managed Service for Apache Spark: New image versions, Iceberg, and Spark optimizations

    New subminor image versions for Managed Service for Apache Spark have been released, impacting Conda channel configurations until August 2026. These new versions introduce Iceberg 1.10 support for Dataproc 2.3 clusters and enable Spark skewed-join and self-join optimizations by default. Users creating clusters with the new subminor versions must specify exact subminor versions and can opt-in to Iceberg 1.10 via a cluster property.

    breaking announcement
  • Google Cloud release notes securitygcpsecurity-advisoryengineer ·

    Container Optimized OS Releases Include Security Fixes and Minor Updates

    Several recent Container Optimized OS releases have been published, bringing minor updates and significant security patches. These updates include upgraded packages like logrotate, oslogin, and GPU installers, alongside critical fixes for CVEs affecting containerd and glibc. The changes primarily impact users running workloads on Google Cloud's Container Optimized OS.

    security patch announcement
  • Google Cloud release notes securitygcpsecurity-advisoryengineer ·

    Container Optimized OS Updates Address Multiple Security Vulnerabilities

    This release of Container Optimized OS (COS) incorporates numerous security fixes for Docker, containerd, and the Linux kernel, including multiple CVEs. These updates are critical for maintaining system integrity and protecting against known vulnerabilities. All users of COS are advised to update to benefit from these security enhancements.

    security patch
  • Google Cloud release notes securitygcpsecurity-advisoryengineer ·

    Cloud Service Mesh Security Patch Releases

    Multiple versions of Cloud Service Mesh (1.29.5-asm.3, 1.28.9-asm.2, 1.27.9-asm.8, and managed sidecar versions 1.21.6-asm.38, 1.20.8-asm.88, 1.19.10-asm.78) have been released with fixes for security vulnerabilities, including CVE-2026-34182 and CVE-2026-45447. These updates address critical security issues and are available for in-cluster and managed deployments. Users are advised to upgrade to the latest versions to incorporate these security patches.

    security patch
  • Google Cloud release notes securitygcpdeprecationengineer ·

    Google SecOps SOAR: siemAlertId Field Reservation

    Effective July 5, 2026, Google SecOps SOAR will reserve the `siemAlertId` field exclusively for internal Chronicle SIEM alert IDs, overwriting any custom data. This change impacts all ingestion methods and requires users to migrate custom `siemAlertId` fields immediately to prevent data loss. Engineers and architects using SOAR for alert ingestion should update their configurations before the deadline.

    breaking

About GCP release tracking on ReleaseBytes

Google Cloud publishes release notes per product — BigQuery, GKE, Cloud Run, Cloud SQL, Vertex AI and dozens more — which makes platform-wide awareness hard. ReleaseBytes aggregates the official GCP release notes and the Terraform Google provider changelog into a single feed, with a plain-English summary of each update and tags for breaking changes, deprecations and security fixes.

Frequently asked questions

How often are GCP release notes updated on ReleaseBytes?

Continuously. ReleaseBytes monitors the official GCP release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.

What kinds of GCP changes does ReleaseBytes track?

New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.

How can I get alerts for new GCP releases?

Set up a free email or Slack alert filtered to GCP, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.

Where does the GCP release data come from?

From the official sources: Google Cloud releases and Terraform Google provider. Every item links back to the original vendor announcement.