github.com/fluxcd/source-controller/api
The GitOps Toolkit source management component
Activity
- Latest release
- 1w ago
- Total releases
- 65
- Cadence
- ~19 days
- Last 12 months
- 16
Reach
- Stars
- 282
Details
- First release
- Aug 17, 2020
| Version | Released | |
|---|---|---|
v1.9.5
patch
|
v1.9.5
patch
Dependencies (4)
|
|
v1.9.4
patch
|
v1.9.4
patch
Dependencies (4)
|
|
v1.9.3
patch
|
v1.9.3
patch
Dependencies (4)
|
|
v1.9.2
minor
|
v1.9.2
minor
Dependencies (4)
|
|
v1.9.1
patch
|
v1.9.1
patch
Dependencies (4)
|
|
v1.9.0
minor
|
v1.9.0
minor
Dependencies (4)
|
|
v1.8.5
patch
|
v1.8.5
patch
Dependencies (4)
|
|
v1.8.4
patch
|
v1.8.4
patch
Dependencies (4)
|
|
v1.8.3
patch
|
v1.8.3
patch
Dependencies (4)
|
|
v1.8.2
patch
|
v1.8.2
patch
Dependencies (4)
|
|
v1.8.1
minor
|
v1.8.1
minor
Dependencies (4)
|
|
v1.8.0
minor
|
v1.8.0
minor
Dependencies (4)
|
|
v1.7.4
minor
|
v1.7.4
minor
Dependencies (4)
|
|
v1.7.3
patch
|
v1.7.3
patch
Dependencies (4)
|
|
v1.7.2
patch
|
v1.7.2
patch
Dependencies (4)
|
|
v1.7.1
patch
|
v1.7.1
patch
Dependencies (4)
|
|
v1.7.0
minor
|
v1.7.0
minor
Dependencies (4)
|
|
v1.7.0-rc.3
pre
|
v1.7.0-rc.3
pre
Dependencies (4)
|
|
v1.7.0-rc.2
pre
|
v1.7.0-rc.2
pre
Dependencies (4)
|
|
v1.7.0-rc.1
pre
|
v1.7.0-rc.1
pre
Dependencies (4)
|
|
v1.6.2
patch
|
v1.6.2
patch
Dependencies (4)
|
|
v1.6.1
minor
|
v1.6.1
minor
Dependencies (4)
|
|
v1.2.2
patch
|
v1.2.2
patch
Dependencies (4)
|
|
v1.2.0
minor
|
v1.2.0
minor
Dependencies (4)
|
|
v1.1.0
minor
|
v1.1.0
minor
Dependencies (4)
|
|
v1.0.1
major
|
v1.0.1
major
Dependencies (4)
|
|
v1.0.0-rc.4
pre
|
v1.0.0-rc.4
pre
Dependencies (4)
|
|
v0.36.1
minor
|
v0.36.1
minor
Dependencies (4)
|
|
v0.35.0
minor
|
v0.35.0
minor
Dependencies (4)
|
|
v0.32.0
minor
|
v0.32.0
minor
Dependencies (4)
|
|
v0.31.0
minor
|
v0.31.0
minor
Dependencies (4)
|
|
v0.30.1
patch
|
v0.30.1
patch
Dependencies (4)
|
|
v0.30.0
minor
|
v0.30.0
minor
Dependencies (4)
|
|
v0.29.0
minor
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.29.0
minor
Dependencies (4)
|
|
v0.28.0
minor
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.28.0
minor
Dependencies (4)
|
|
v0.25.7
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.25.7
patch
Dependencies (4)
|
|
v0.25.6
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.25.6
patch
Dependencies (4)
|
|
v0.25.5
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.25.5
patch
Dependencies (4)
|
|
v0.25.4
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.25.4
patch
Dependencies (4)
|
|
v0.25.2
minor
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.25.2
minor
Dependencies (4)
|
|
v0.24.4
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.24.4
patch
Dependencies (4)
|
|
v0.24.2
minor
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.24.2
minor
Dependencies (4)
|
|
v0.22.5
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.22.5
patch
Dependencies (4)
|
|
v0.22.3
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.22.3
patch
Dependencies (4)
|
|
v0.22.2
minor
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.22.2
minor
Dependencies (4)
|
|
v0.19.2
minor
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.19.2
minor
Dependencies (4)
|
|
v0.17.2
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.17.2
patch
Dependencies (3)
|
|
v0.17.0
minor
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (3)
|
|
v0.16.1
patch
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.16.1
patch
Dependencies (3)
|
|
v0.16.0
minor
1 CVE
CVE-2022-39272
GO-2022-1071
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GHSA-f4p5-x4vc-mh4v
Oct 28, 2022
Denial of service in flux controllers in github.com/fluxcd modules Flux controllers are vulnerable to a denial of service attack. Users that have permissions to change Flux's objects, either through a Flux source or directly within a cluster, can provide invalid data to fields .spec.interval or .spec.timeout (and structured variations of these fields), causing the entire object type to stop being processed. The issue has two root causes: a) the Kubernetes type metav1.Duration is not fully compatible with the Go type time.Duration as explained in https://github.com/kubernetes/apimachinery/issues/131, and b) a lack of validation within Flux to restrict allowed values. Fixed in
0.30.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (3)
|