GCP Releases
Google Cloud releases and Terraform Google provider. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.
Tracking 829 GCP releases · Updated
- Google Cloud release notes securitygcpsecurity-advisoryengineer ·
Container Optimized OS Updates Address Security and Memory Errors
This update to Container Optimized OS includes several security fixes for CVEs in systemd and the Linux kernel, alongside a feature that enhances memory error handling for CUDA workloads on ARM64. It also contains patches for Docker and GPU drivers. Users running CUDA on ARM64 may see improved stability, and all users benefit from the security remediations.
security feature patch - Google Cloud release notes securitygcpsecurity-advisoryengineer ·
Apigee X 1-18-0-apigee-1 Release
This release of Apigee X includes several security fixes and bug resolutions, enhancing reliability and patching vulnerabilities. It affects users of Apigee X, particularly those using cache policies, API proxy deployments, and SAML assertions. The rollout began today and may take several business days to complete across all Google Cloud zones.
security patch announcement - Google Cloud Blog blogsecuritygcpengineerfinanceretailmediagovernmentgcp-cloud-rungcp-cloud-storagegcp-compute-enginegcp-cloud-functions ·
Securing Serverless Applications Against Common Attacks on GCP
Mandiant highlights risks of publicly exposed serverless applications on Google Cloud, such as Cloud Run, lacking authentication. Exploiting vulnerabilities like LFI and command injection can lead to full cloud environment compromise, a growing concern with increased AI usage. This post details attack scenarios and provides hardening guidance, applicable to any public serverless deployment, emphasizing secure secrets management and least privilege principles for service accounts.
announcement security - Google Cloud release notes securitygcpengineer ·
Apigee Hybrid v1.15.6 Release Includes Security Fixes
Apigee hybrid has been updated to version v1.15.6, released on July 15, 2026. This release incorporates various security and CVE fixes, enhancing the overall security posture of the hybrid runtime. The update is delivered via Helm charts, automatically updating container images, and is recommended for all users.
security announcement - Terraform Google Provider Releases terraforminfragcpgapreviewdeprecationengineergcp-bigquerygcp-cloud-rungcp-cloud-sqlgcp-cloud-storagegcp-dataflowgcp-dataprocgcp-spannergcp-firestore ·
Terraform Google Provider v7.40.0: New Data Sources and Resources
This release of the Terraform Google Provider introduces several new data sources and resources, enhancing infrastructure management capabilities for Google Cloud services. Notably, it adds new integrations for Data Catalog, Oracle Database Exascale, and Chronicle, alongside improvements to existing Compute Engine and Container resources. These updates benefit engineers and architects managing GCP infrastructure via Terraform, with many new resources becoming generally available.
deprecation feature patch announcement - Google Cloud Blog blogsecuritygcpengineer ·
ADFS signing key recovery via Machine DPAPI, bypassing MFA
Mandiant discovered a vulnerability where manually rotated Active Directory Federation Services (ADFS) signing keys can be exposed in Machine DPAPI, allowing attackers to forge SAML tokens. This 'ghost certificate' issue arises when AutoCertificateRollover is disabled and the WID database isn't updated after manual certificate rotation. The technique bypasses traditional defenses like LSASS monitoring and MFA, granting unauthorized access to federated applications.
security announcement - Google Cloud release notes securitygcpgaengineergcp-bigquery ·
BigQuery Security Advisory and New Features Announced
A critical security vulnerability allowing unauthorized permission escalation in BigQuery, Dataform, and Colab Enterprise has been addressed. Additionally, the BigQuery Overview page is now generally available, offering guided paths for all skill levels, and incremental data transfers for Salesforce are also GA. These updates impact users of BigQuery and related services, with the security fix being paramount.
security feature - Google Cloud release notes securitygcpengineergcp-bigquery ·
Colab Enterprise Security Vulnerability in BigQuery, Dataform
A critical security vulnerability, GCP-2026-047, has been identified in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could escalate permissions to achieve cross-tenant repository takeover. Users of these services should consult the security bulletin for details on the vulnerability and its potential impact.
security - Google Cloud release notes securitygcpengineer ·
Developer Connect enhances security for GitLab/Bitbucket connections
Developer Connect now enforces granular permissions for GitLab Enterprise and Bitbucket Data Center connections by checking both the calling principal and the service agent against Secret Manager secrets. This change adheres to the principle of least privilege, enhancing security by ensuring only authorized entities can access sensitive Git provider credentials. The update affects users managing these specific types of repository connections and is detailed in the Developer Connect security bulletin.
security - Google Cloud release notes datasecuritygcpengineergcp-bigquery ·
Dataform Security Vulnerability in BigQuery and Colab Enterprise
A security vulnerability was found in Dataform repositories within BigQuery and Colab Enterprise, allowing authenticated attackers to escalate privileges and take over cross-tenant repositories. This impacts users of Dataform, BigQuery, and Colab Enterprise. Further details are available in the GCP-2026-047 security bulletin.
security - Google Cloud release notes infragcpdeprecationengineer ·
Managed Service for Apache Airflow: New Builds and Deprecations
Managed Airflow has released new builds for both Generation 3 and Generation 2, offering updated Apache Airflow versions. Concurrently, several older versions and builds across both generations have reached their end of support and are now deprecated. This impacts users on older Managed Airflow deployments who need to plan for upgrades.
deprecation patch - endoflife.date eolgcp-cloud-run-go ·
Cloud Run functions Go runtime 1.24 reaches end of life in 52 days
Cloud Run functions Go runtime 1.24 reaches end of life on 2026-09-02 (52 days from now). Extended support runs until 2027-03-02.
deprecation - endoflife.date eolgcp-cloud-run-python ·
Cloud Run functions Python runtime 3.10 reaches end of life in 84 days
Cloud Run functions Python runtime 3.10 reaches end of life on 2026-10-04 (84 days from now). Extended support runs until 2027-04-04.
deprecation - endoflife.date eolgoogle-kubernetes-engine ·
Google Kubernetes Engine 1.33 reaches end of life in 22 days
Google Kubernetes Engine 1.33 reaches end of life on 2026-08-03 (22 days from now). Latest release in this cycle: 1.33.13-gke.1101000.
deprecation - endoflife.date eolgoogle-kubernetes-engine ·
Google Kubernetes Engine 1.34 reaches end of life in 81 days
Google Kubernetes Engine 1.34 reaches end of life on 2026-10-01 (81 days from now). Latest release in this cycle: 1.34.9-gke.1287000.
deprecation - Google Cloud release notes infradeprecationgcp-gke ·
GKE Updates Include New Versions and Security Patches
Google Kubernetes Engine (GKE) has released new cluster versions across its Rapid, Regular, Stable, and Extended channels, enabling upgrades and new cluster creation. This update also incorporates security fixes through updated Container-Optimized OS images, enhancing system security for all users. Specific versions are being deprecated in the Extended channel, with removal scheduled within 90 days, requiring users to plan their upgrades accordingly.
security patch - Google Cloud release notes infragcpengineer ·
Apigee hybrid v1.16.7 includes security fixes
Google Cloud has released Apigee hybrid v1.16.7, incorporating various security and CVE fixes. This patch release also includes updates to container images integrated with Apigee hybrid Helm charts. Users can upgrade via the Helm chart, which automatically updates the necessary images. The release is available now for users of Apigee hybrid.
security announcement - Google Cloud release notes aipreviewdeprecationengineer ·
Apigee Advanced API Security GenAI Feature Deprecated
The GenAI Incident Summary feature within Apigee Advanced API Security's Abuse Detection is deprecated and will be shut down on July 9, 2026. This AI-powered tool provided automated summaries and mitigation advice for security incidents. Users relying on this feature should explore alternative solutions before the shutdown date.
deprecation - Google Cloud release notes securityinfragcpsecurity-advisoryengineerenergy ·
Container Optimized OS Updates: Kernel, Docker, Security Fixes, NVIDIA Drivers
This release of Container Optimized OS (COS) includes multiple updates across kernel versions, Docker, and Containerd. Notably, it addresses several security vulnerabilities, including CVE-2026-53359 and KCTF-d82ba05 in the Linux kernel, and adds support for specific NVIDIA GRID driver versions. These updates are primarily targeted at users of COS who rely on containerization and GPU acceleration.
security patch - Google Cloud release notes securitygcpsecurity-advisorygcp-bigquery ·
Apigee X Security Vulnerability Affecting BigQuery DAO
A vulnerability in Apigee X's BigQuery Data Access Object allowed authenticated attackers to exfiltrate cross-tenant data. This issue has been patched and affects specific versions on Google Cloud Platform, with Apigee hybrid remaining unaffected. No customer action is required for this security fix.
security
About GCP release tracking on ReleaseBytes
Google Cloud publishes release notes per product — BigQuery, GKE, Cloud Run, Cloud SQL, Vertex AI and dozens more — which makes platform-wide awareness hard. ReleaseBytes aggregates the official GCP release notes and the Terraform Google provider changelog into a single feed, with a plain-English summary of each update and tags for breaking changes, deprecations and security fixes.
Frequently asked questions
How often are GCP release notes updated on ReleaseBytes? ›
Continuously. ReleaseBytes monitors the official GCP release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.
What kinds of GCP changes does ReleaseBytes track? ›
New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.
How can I get alerts for new GCP releases? ›
Set up a free email or Slack alert filtered to GCP, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.
Where does the GCP release data come from? ›
From the official sources: Google Cloud releases and Terraform Google provider. Every item links back to the original vendor announcement.