GCP Releases
Google Cloud releases and Terraform Google provider. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.
Tracking 829 GCP releases · Updated
- Google Cloud release notes securityinfragcpsecurity-advisoryengineer ·
Container Optimized OS Security and Bug Fixes
This release of Container Optimized OS addresses numerous security vulnerabilities across the Linux kernel, systemd, Python, and OpenSSH. It also includes fixes for an xfs file system bug and an update to fluent-bit. These updates are crucial for maintaining system integrity and security for all users running Container Optimized OS.
security patch - Google Cloud release notes infragcpgapreviewengineergcp-bigquerygcp-cloud-rungcp-gkegcp-cloud-sqlgcp-compute-enginegcp-composer ·
Cloud SDK 578.0.0: Database Migration default change, AlloyDB backup DR GA, BigQuery improvements
The Cloud SDK 578.0.0 release introduces breaking changes, notably making the `--auto-commit` flag the default for database migration operations and promoting AlloyDB Backup DR restore flags to GA. Key enhancements include BigQuery improvements like force deletion for connections and fixed configuration reading, along with updates to Cloud Run, Compute Engine, and Secret Manager commands. This release affects users of various Google Cloud services, with some changes requiring explicit action to maintain previous behavior.
breaking - Google Cloud release notes securitygcpengineer ·
Apigee X: Security Fixes and Infrastructure Updates
Google Cloud has released an updated version of Apigee X, incorporating security fixes for the Java Callout policy and infrastructure updates. This release aims to address vulnerabilities and improve the overall stability of the Apigee platform. The rollout began today and may take several business days to complete across all Google Cloud zones.
security patch announcement - Google Cloud release notes networkinggcpgaengineergcp-gke ·
GKE Mixed-Protocol Load Balancers Reach General Availability
Google Kubernetes Engine has reached general availability for mixed-protocol Services of type LoadBalancer. This feature allows a single IP address to handle simultaneous TCP and UDP traffic for both external and internal Network Load Balancers across IPv4, IPv6, and dual-stack environments. This resolves prior traffic routing errors and is available in GKE version 1.36.2-gke.1498000 and later, benefiting users managing diverse network traffic patterns.
security feature - Google Cloud release notes securitygcpengineer ·
Cloud NGFW: WildFire feature temporarily removed due to outage risk
Cloud NGFW is temporarily removing the WildFire feature. Enabling WildFire in an existing firewall endpoint risks a temporary data plane outage, affecting existing traffic. This removal impacts users attempting to enable WildFire on established firewall endpoints.
breaking - Google Cloud release notes infragcpgadeprecationengineergcp-gke ·
Google Kubernetes Engine: Version Updates and Security Patches
Google Kubernetes Engine has released new cluster versions across its Rapid, Regular, Stable, Extended, and default channels, offering new default versions and updated patch/minor version availability for upgrades. Several older versions are now deprecated and scheduled for removal within 90 days, requiring users to plan their upgrades. The release also includes security updates via updated Container-Optimized OS images for enhanced vulnerability management.
security patch - Google Cloud release notes infragcpengineer ·
Apigee Hybrid v1.16.8 Release Notes
Apigee Hybrid has released version 1.16.8, including a fix for ignored nodeSelector configurations and a new runtime rollout strategy configuration. This update also contains various security and CVE fixes. It is recommended for all users managing Apigee Hybrid deployments, with container images automatically updated via Helm charts for patch releases.
security feature patch announcement - Google Cloud release notes aigcppreviewengineer ·
Gemini Enterprise Agent Platform: Image Models Retired
The Gemini Enterprise Agent Platform has retired the gemini-3.1-flash-image-preview and gemini-3-pro-image-preview models. Users must update their code to reference alternative image models to avoid disruption. This change affects users of these specific preview models.
breaking - Google Cloud release notes securityinfragcpsecurity-advisoryengineer ·
Container Optimized OS Updates Address Security Vulnerabilities and Bugs
Several updates have been released for Container Optimized OS (COS) addressing multiple security vulnerabilities across glib, Python, wget, and the Linux kernel. These updates also include fixes for a bug in the XFS file system and upgraded versions of Docker and containerd. The changes are available for various COS versions and are relevant to users running containerized workloads on Google Cloud.
security patch - Google Cloud release notes securitygcpsecurity-advisoryengineergcp-looker ·
Looker Security Advisory: Cross-Site Scripting Vulnerability
A critical Cross-Site Scripting (XSS) vulnerability in Looker could allow an attacker to execute arbitrary scripts by tricking an administrator into opening a malicious URL. This affects both Looker-hosted and self-hosted instances. Looker-hosted instances are already mitigated, while self-hosted instances require an urgent update to patched versions.
security - Google Cloud release notes aigcpsecurity-advisoryengineer ·
Gemini Enterprise Agent Platform Security Update
A Server-Side Request Forgery (SSRF) vulnerability in Agent Studio's auto-generated API proxy backend has been fixed. This addresses a potential security risk for web applications generated before July 1, 2026. Users who created applications before this date should regenerate and redeploy their apps from Agent Studio to incorporate the security patch, which includes strict domain allowlist validation.
security - Google Cloud release notes infragcp-compute-engine ·
Batch: Jobs restricted to job's location
Google Cloud Batch will enforce stricter location policies for Compute Engine resources used by jobs. Starting July 31, 2026 (or June 30, 2027 for some existing projects), new jobs cannot specify Compute Engine resources outside the job's location. This change requires users to update any jobs using the `allowedLocations[]` field to align with the job's region, otherwise, existing jobs might fail after the respective dates. No action is needed if `allowedLocations[]` is not specified.
breaking - Google Cloud release notes securitygcpsecurity-advisoryengineer ·
Container Optimized OS Updates Address Security and Memory Errors
This update to Container Optimized OS includes several security fixes for CVEs in systemd and the Linux kernel, alongside a feature that enhances memory error handling for CUDA workloads on ARM64. It also contains patches for Docker and GPU drivers. Users running CUDA on ARM64 may see improved stability, and all users benefit from the security remediations.
security feature patch - Google Cloud release notes securitygcpsecurity-advisoryengineer ·
Apigee X 1-18-0-apigee-1 Release
This release of Apigee X includes several security fixes and bug resolutions, enhancing reliability and patching vulnerabilities. It affects users of Apigee X, particularly those using cache policies, API proxy deployments, and SAML assertions. The rollout began today and may take several business days to complete across all Google Cloud zones.
security patch announcement - Google Cloud Blog blogsecuritygcpengineerfinanceretailmediagovernmentgcp-cloud-rungcp-cloud-storagegcp-compute-enginegcp-cloud-functions ·
Securing Serverless Applications Against Common Attacks on GCP
Mandiant highlights risks of publicly exposed serverless applications on Google Cloud, such as Cloud Run, lacking authentication. Exploiting vulnerabilities like LFI and command injection can lead to full cloud environment compromise, a growing concern with increased AI usage. This post details attack scenarios and provides hardening guidance, applicable to any public serverless deployment, emphasizing secure secrets management and least privilege principles for service accounts.
announcement security - Google Cloud release notes securitygcpengineer ·
Apigee Hybrid v1.15.6 Release Includes Security Fixes
Apigee hybrid has been updated to version v1.15.6, released on July 15, 2026. This release incorporates various security and CVE fixes, enhancing the overall security posture of the hybrid runtime. The update is delivered via Helm charts, automatically updating container images, and is recommended for all users.
security announcement - Google Cloud release notes securityinfragcpgapreviewdeprecationsecurity-advisoryengineergcp-bigquerygcp-cloud-rungcp-gkegcp-cloud-sqlgcp-cloud-storagegcp-dataprocgcp-compute-enginegcp-looker ·
Cloud SDK 576.0.0: BigLake, GKE, Compute Engine updates
Cloud SDK version 576.0.0 introduces several feature promotions to GA, including BigLake Delta sharing commands and GKE rollbackable upgrades, alongside numerous enhancements across Compute Engine, Cloud SQL, and other services. A breaking change updates gcloud storage rsync to decompress gzip files by default, impacting users who previously relied on the default behavior. Linux bundled Python was updated to address a security vulnerability, and a performance regression in Artifact Registry was fixed. Most changes are applicable to engineers and architects managing Google Cloud resources.
breaking - Google Cloud Blog blogsecuritygcpengineer ·
ADFS signing key recovery via Machine DPAPI, bypassing MFA
Mandiant discovered a vulnerability where manually rotated Active Directory Federation Services (ADFS) signing keys can be exposed in Machine DPAPI, allowing attackers to forge SAML tokens. This 'ghost certificate' issue arises when AutoCertificateRollover is disabled and the WID database isn't updated after manual certificate rotation. The technique bypasses traditional defenses like LSASS monitoring and MFA, granting unauthorized access to federated applications.
security announcement - Google Cloud release notes securitygcpgaengineergcp-bigquery ·
BigQuery Security Advisory and New Features Announced
A critical security vulnerability allowing unauthorized permission escalation in BigQuery, Dataform, and Colab Enterprise has been addressed. Additionally, the BigQuery Overview page is now generally available, offering guided paths for all skill levels, and incremental data transfers for Salesforce are also GA. These updates impact users of BigQuery and related services, with the security fix being paramount.
security feature - Google Cloud release notes securitygcpengineergcp-bigquery ·
Colab Enterprise Security Vulnerability in BigQuery, Dataform
A critical security vulnerability, GCP-2026-047, has been identified in BigQuery, Dataform, and Colab Enterprise. An authenticated attacker could escalate permissions to achieve cross-tenant repository takeover. Users of these services should consult the security bulletin for details on the vulnerability and its potential impact.
security
About GCP release tracking on ReleaseBytes
Google Cloud publishes release notes per product — BigQuery, GKE, Cloud Run, Cloud SQL, Vertex AI and dozens more — which makes platform-wide awareness hard. ReleaseBytes aggregates the official GCP release notes and the Terraform Google provider changelog into a single feed, with a plain-English summary of each update and tags for breaking changes, deprecations and security fixes.
Frequently asked questions
How often are GCP release notes updated on ReleaseBytes? ›
Continuously. ReleaseBytes monitors the official GCP release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.
What kinds of GCP changes does ReleaseBytes track? ›
New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.
How can I get alerts for new GCP releases? ›
Set up a free email or Slack alert filtered to GCP, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.
Where does the GCP release data come from? ›
From the official sources: Google Cloud releases and Terraform Google provider. Every item links back to the original vendor announcement.