verdict: Act · 8 items
- Platform/SRE — Act: The Minimus registry goes offline October 22, 2026; audit all Dockerfiles, Helm charts, and Kubernetes manifests for Minimus base image references and complete migration to Docker Hardened Images before that date to prevent broken image pulls in production.
- CI/CD — Act: Any pipeline pulling from the Minimus registry will break after October 22, 2026; inventory all build Dockerfiles and CI base-image references now and migrate to Docker Hardened Images using the provided migration path and Docker’s free migration assistance before the deadline.
- Leader — Skip
- Platform/SRE — Act: OpenTofu 1.11 hit EOL on 2026-08-19 and this is its final patch; the credential-leak via OCI HTTP redirect and the DoS via crafted remote-state URLs are both active security risks in IaC runs. Upgrade to a supported OpenTofu release series (1.12+) now that EOL has passed.
- CI/CD — Act: The credential-leak bug affects
tofu initwhen pulling modules or providers from OCI registries — a standard pipeline step — and could expose registry credentials to a redirect target. Upgrade the OpenTofu version pinned in CI pipelines from 1.11.x to a supported series immediately; 1.11 is already EOL. - Leader — Skip
- Signals: OpenTofu 1.11 is past EOL (2026-08-19, 5d ago)
- Platform/SRE — Plan: If running a self-managed GitLab instance, upgrade to the patched version in your release line; no public PoC or KEV listing is confirmed from the title alone, so this is urgent-but-scheduled rather than emergency.
- CI/CD — Act: GitLab CI users on self-managed instances should upgrade to 19.2.4, 19.1.6, 19.0.8, or 18.11.11 promptly — a critical patch to the CI/CD platform itself can directly break or compromise pipelines and should be treated as an outage-level priority.
- Leader — Skip
- Signals: major release (19.0)
- Platform/SRE — Skip
- CI/CD — Act: Published GHSA-pp25-4cg4-qcr9 details a critical server-side template injection in serena-agent ≤1.6.1 that executes arbitrary code via a malicious .serena/project.yml smuggled in any cloned repo — a direct supply-chain threat to developer and CI environments; upgrade to serena-agent 1.7.0 now.
- Leader — Plan: This is an early, documented example of a new risk class: MCP servers embedded in the SDL grant LLMs broad filesystem and shell access, making any compromise severe; evaluate whether your AI coding-agent adoption policies explicitly address this attack surface before broader org rollout.
- Platform/SRE — Act: If you run the containerized SAP data connector agent for Microsoft Sentinel, migrate to the replacement agent before September 14, 2026, when the agent will be permanently disabled and SAP log ingestion will stop.
- CI/CD — Skip
- Leader — Skip
- Signals: deprecation/EOL deadline mentioned: September 14, 2026
- Platform/SRE — Act: If you operate GitHub Enterprise Server, review the new security requirements for support bundle uploads and ensure your GHES instance is compliant before August 18, 2026, or uploads will be rejected, hampering incident troubleshooting.
- CI/CD — Skip
- Leader — Skip
- Platform/SRE — Act: GCP Batch will reject jobs whose
allowedLocations[]field lists regions or zones outside the job’s own location; the deadline is July 31, 2026 for most projects (June 30, 2027 for projects that already submitted a cross-region job before that date). Audit all Batch workloads for cross-regionallowedLocations[]entries and restrict them to the job’s location before July 31, 2026. - CI/CD — Skip
- Leader — Skip
- Platform/SRE — Act: ingress-nginx reached end-of-life in March 2026 (now four months past); remaining on it means exposure to unpatched CVEs in a critical ingress path with no upstream fixes coming. Audit clusters for ingress-nginx usage and complete migration to a maintained alternative (Envoy Gateway, Ingress-NGINX from F5, Traefik) immediately.
- CI/CD — Skip
- Leader — Act: The SIG Network ingress-nginx controller is retired, making any org standardized on it subject to growing unpatched CVE exposure with no remediation path; this warrants a brief to leadership and a decision on a replacement ingress standard before the vulnerability surface widens further.
- Signals: deprecation mentioned (no explicit date found)