<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:gcp-release-notes</id>
  <title>Google Cloud Platform (GCP) - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/gcp-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-06-17T00:00:00-07:00</updated>

  <entry>
    <title>June 17, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_17_2026</id>
    <updated>2026-06-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_17_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Memorystore for Redis</h2>
<h3>Feature</h3>
<p>Memorystore for Redis supports the <a href="https://docs.cloud.google.com/products#product-launch-stages">General Availability</a>
of the following health issues:</p>
<ul>
<li><a href="https://docs.cloud.google.com/memorystore/docs/redis/expensive-commands"><strong>Expensive commands</strong></a>:
resolve performance issues that are associated with using Redis commands that
are resource-intensive (expensive).</li>
<li><a href="https://docs.cloud.google.com/memorystore/docs/redis/high-resource-utilization"><strong>High resource utilization</strong></a>:
resolve issues that are associated with instances not performing optimally.</li>
<li><a href="https://docs.cloud.google.com/memorystore/docs/redis/maintenance-policy-not-set"><strong>Maintenance policy not set</strong></a>:
check whether users set maintenance windows for instances. If there's an optimal
time slot for the maintenance windows when there's low traffic, then the health
issue provides this slot.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 16, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_16_2026</id>
    <updated>2026-06-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_16_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>AlloyDB integration with Knowledge Catalog is now generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<p>This integration provides a unified metadata view to simplify data governance and analysis. It includes near real-time synchronization and expanded metadata details, like primary and foreign keys.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/knowledge-catalog-integration">Integrate AlloyDB with Knowledge Catalog</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Announcement</h3>
<p>Table Explorer behavior is moving to the <strong>Reference</strong> panel. This transition
will occur in July 2026 or later. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/table-explorer">Table Explorer</a>.</p>
<h2 class="release-note-product-title">Cloud SDK</h2>
<h3>Breaking</h3>
<h2 id="57300_2026-06-16">573.0.0 (2026-06-16)</h2>
<h3 id="breaking_changes">Breaking Changes</h3>
<ul>
<li><strong>(Anthos Multi-Cloud)</strong> Deprecated <code>gcloud container attached clusters get-credentials</code>.
Use <code>gcloud container fleet memberships get-credentials</code> to get credentials
for a running Attached cluster.</li>
</ul>
<h3 id="google_cloud_cli">Google Cloud CLI</h3>
<ul>
<li>Updated Windows bundled Python for the <code>gcloud</code> CLI to 3.14.5.</li>
</ul>
<h3 id="ai">AI</h3>
<ul>
<li>Added <code>gcloud ai tuning-jobs</code> command group to manage Vertex AI supervised fine-tuning jobs.</li>
</ul>
<h3 id="app_engine">App Engine</h3>
<ul>
<li>Updated the Java SDK to version 5.0.4 build from the open source project
<a href="https://github.com/GoogleCloudPlatform/appengine-java-standard/releases/tag/v5.0.4">https://github.com/GoogleCloudPlatform/appengine-java-standard/releases/tag/v5.0.4</a>.</li>
<li>fixed <a href="https://github.com/GoogleCloudPlatform/appengine-java-standard/issues/506">https://github.com/GoogleCloudPlatform/appengine-java-standard/issues/506</a>.</li>
</ul>
<h3 id="artifact_registry">Artifact Registry</h3>
<ul>
<li>Added <code>gcloud artifacts image-streaming-cache</code> command group to manage
image streaming caches per region. This group includes <code>create</code>,
<code>describe</code>, <code>delete</code>, and <code>list</code> commands.</li>
</ul>
<h3 id="biglake">BigLake</h3>
<ul>
<li>Promoted <code>--unity-service-principal-application-id</code> flag for <code>gcloud biglake iceberg catalogs create</code> and <code>update</code> to BETA, making it publicly visible.</li>
<li>Promoted BigLake catalogs and arguments for <code>gcloud biglake iceberg catalogs</code> to GA.</li>
</ul>
<h3 id="cloud_data_lineage">Cloud Data Lineage</h3>
<ul>
<li>Added <code>gcloud datalineage</code> command group to manage Cloud Data Lineage resources.</li>
<li>Added <code>gcloud datalineage config describe</code> and <code>gcloud datalineage config update</code> commands to manage Data Lineage configurations.</li>
</ul>
<h3 id="cloud_datastream">Cloud Datastream</h3>
<ul>
<li>Added support for Dataverse, Salesforce Marketing Cloud, and ServiceNow connection profiles to <code>gcloud datastream connection-profiles create</code> and <code>update</code> commands.</li>
<li>Added support for Dataverse, Salesforce Marketing Cloud, and ServiceNow streams to <code>gcloud datastream streams create</code> and <code>update</code> commands.</li>
</ul>
<h3 id="cloud_run">Cloud Run</h3>
<ul>
<li>Promoted <code>--readiness_probe</code> in <code>gcloud run deploy</code> and <code>gcloud run services update</code> to GA.</li>
</ul>
<h3 id="cloud_services">Cloud Services</h3>
<ul>
<li><strong>API Keys</strong>: Updated <code>gcloud services api-keys</code> <code>create</code> and <code>update</code>
commands' <code>--api-target</code> flag to accept a colon-separated list of <code>methods</code>
inline (e.g. <code>--api-target="service=foo,methods=m1:m2"</code>).</li>
</ul>
<h3 id="cloud_storage">Cloud Storage</h3>
<ul>
<li>Promoted <code>gcloud storage batch-operations bucket-operations</code> commands to GA.</li>
</ul>
<h3 id="cluster_director">Cluster Director</h3>
<ul>
<li>Added support for creating clusters using blueprints in <code>gcloud beta cluster-director clusters create</code>.</li>
</ul>
<h3 id="compute_engine">Compute Engine</h3>
<ul>
<li>Promoted <code>--action-on-vm-failed-health-check</code> flag to GA for <code>gcloud compute instance-groups managed create</code> and <code>gcloud compute instance-groups managed update</code>.</li>
<li>Fixed an issue where waiting for asynchronous operations would fail for certain global nested resources (like <code>cross-site-networks wire-groups</code>).</li>
<li>Added <code>any-reservation-then-fail</code> choice to <code>--reservation-affinity</code> flag in
beta for <code>gcloud compute instances create</code>,
<code>gcloud compute instances bulk create</code>,
<code>gcloud compute instance-templates create</code>,
<code>gcloud compute instances create-with-container</code>, and
<code>gcloud compute instance-templates create-with-container</code> commands.</li>
<li>Promoted <code>--include-disks</code> and <code>--exclude-disks</code> flags for <code>gcloud compute machine-images create</code> to the BETA release track.</li>
</ul>
<h3 id="kubernetes_engine">Kubernetes Engine</h3>
<ul>
<li>Added <code>--dataplane-optimization-mode</code> flag to <code>gcloud container clusters create</code> to select scalability mode for Dataplane V2.</li>
<li>Deprecated None value of --release-channel flag from gcloud container clusters create and update command. Use RAPID, REGULAR, STABLE or EXTENDED instead.</li>
</ul>
<h3 id="network_connectivity">Network Connectivity</h3>
<ul>
<li>Updated help text for <code>--region</code> flag in <code>gcloud network-connectivity transports create</code> to include supported regions list.</li>
</ul>
<h3 id="network_security">Network Security</h3>
<ul>
<li>Added <code>gcloud network-security operations</code> command group (<code>describe</code>, <code>wait</code>, <code>list</code>, <code>cancel</code>).</li>
<li>Promoted project scoping for
<code>gcloud network-security firewall-endpoints</code> commands
(<code>create</code>, <code>delete</code>, <code>describe</code>, <code>list</code>, <code>update</code>) to GA.</li>
<li>Promoted <code>gcloud network-security security-profiles wildfire-analysis</code>
commands to BETA.</li>
<li>Promoted
<code>gcloud network-security firewall-endpoints wildfire-verdict-change-requests</code>
commands to beta.</li>
<li>Promoted WildFire-related flags in
<code>gcloud network-security firewall-endpoints create</code> command to
BETA.</li>
<li>Promoted WildFire-related flags in
<code>gcloud network-security firewall-endpoints update</code> command to
BETA.</li>
</ul>
<h3 id="recaptcha">Recaptcha</h3>
<ul>
<li>Fixed an issue where <code>gcloud recaptcha keys create</code> ignored <code>--testing-score</code> when creating Android or iOS keys.</li>
</ul>
<p>Subscribe to these release notes at <a href="https://groups.google.com/forum/#!forum/google-cloud-sdk-announce">https://groups.google.com/forum/#!forum/google-cloud-sdk-announce</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>QueryData adds support for parameterized secure views (PSVs) to help secure
applications that use natural language queries. For more information, see <a href="https://docs.cloud.google.com/sql/docs/postgres/secure-app-data-parameterized-secure-views-qd">Secure
and control access to application data</a>.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Confidential VM</h2>
<h3>Feature</h3>
<p>Support for the accelerator-optimized
<a href="https://docs.cloud.google.com/compute/docs/accelerator-optimized-machines#g4-vms">g4-standard-48 machine type</a>
for securely running AI and ML workloads is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>, with the
following specifications:</p>
<ul>
<li>5th Generation AMD EPYC Turin processor</li>
<li>AMD SEV</li>
<li>1 NVIDIA RTX PRO 6000 GPU</li>
</ul>
<h2 class="release-note-product-title">Dataflow</h2>
<h3>Feature</h3>
<p>Dataflow now supports NVIDIA RTX Pro 6000 GPUs. You can use this
GPU model to run your Apache Beam pipelines on Dataflow. RTX
Pro 6000 GPUs are recommended for large, medium, and small model inference
workloads. To configure your workers with this GPU model, set the accelerator
type to <code>nvidia-rtx-pro-6000</code>. For more information, see <a href="https://docs.cloud.google.com/dataflow/docs/gpu/gpu-support">Dataflow
support for GPUs</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: ServiceNow data store actions and federation</strong></p>
<p>The ServiceNow data store supports federation and assistant actions in
Gemini Enterprise.</p>
<p>You can connect a ServiceNow site to search and read incidents, change
requests, tasks, and knowledge base articles using natural language. You
can also perform actions, such as creating and updating incidents,
directly from the Gemini Enterprise app.</p>
<p>This feature is generally available (GA). For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/servicenow">Connect ServiceNow</a>.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.35.200-gke.66 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.35.200-gke.66 runs on Kubernetes v1.35.3-gke.400.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.35.200-gke.66:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where a transient or partial failure during node pool updates
could cause node taints or labels to become permanently stuck (stranded) on
worker nodes, even after you removed them from the NodePool custom resource
specification.

<ul>
<li>Fixed an issue where, during the machine initialization phase, the
<code>etcd-events</code> pod read the stale data directory when it started
and attempted to reuse the old member ID to rejoin the cluster instead of the
new one. Trying to use the old member ID to rejoin the cluster resulted in an
infinite retry loop and caused the cluster to reject the connection. The fix
ensures the <code>/var/lib/etcd-events</code> directory is
cleared upon failure, and adds retry logic to <code>kubeadm-reset</code> to improve resiliency against transient API errors.
</li>
</ul></li>
<li>Fixed an issue where, when enabling or updating etcd encryption, the API
server was terminated abruptly, causing transient connection timeouts or
failures for in-cluster workloads for up to five minutes.
</li>
<li>Fixed an issue where, during control plane certificate rotation or etcd
encryption updates, the installer stalled for three minutes per control plane node
while waiting for the local API server to restart, causing nodes to temporarily
report an Unknown status and triggering transient routing disruptions (such as
503 Service Unavailable or ImagePullBackOff errors) for workloads scheduled on
those nodes.</li></ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Announcement</h3>
<p><strong>New Documentation changelogs</strong></p>
<p>Google SecOps is now releasing a monthly changelog to capture major documentation updates.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs">Documentation changelog</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Ask Gemini Cloud Assist in Feed Management</strong></p>
<p>Google SecOps now provides Gemini Cloud Assist (GCA) directly within the Feed Management interface to help you with feed creation, setup, and general troubleshooting questions.</p>
<p>A new <strong>Ask Gemini Cloud Assist</strong> button is now available in the Feed Management interface. You can click this button to open the Gemini Cloud Assist panel and ask questions to get guidance on:
*   Configuring and managing data feeds.
*   Understanding ingestion pre-requisites and setup steps for different log sources.
*   Resolving common setup issues.</p>
<p><em>Note: Gemini Cloud Assist provides recommendations and answers to your questions, but does not perform configuration changes on your behalf. You must apply any recommended changes manually to your feeds.</em></p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/administration/feed-management-overview">Feed management overview</a>.</p>
<h3>Announcement</h3>
<p><strong>New Documentation changelogs</strong></p>
<p>Google SecOps is now releasing a monthly changelog to capture major documentation updates.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs">Documentation changelog</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><strong>New Documentation changelogs</strong></p>
<p>Google SecOps is now releasing a monthly changelog to capture major documentation updates.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/changelogs/changelogs">Documentation changelog</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Announcement</h3>
<p><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine): Rollout of the <a href="https://docs.cloud.google.com/dataproc/docs/concepts/versioning/dataproc-version-clusters#supported-dataproc-image-versions">new sub-minor versions without pre-configured channels</a> will begin on June 22, 2026, delayed from the previously planned date of June 15, 2026 ETA.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 15, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_15_2026</id>
    <updated>2026-06-15T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_15_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AI Hypercomputer</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: Before you create Spot VMs, you can view the real-time
availability, estimated uptime, historical preemption rate, and pricing for a
specific machine type and location. This information helps you maximize the
chances of successfully creating Spot VMs and choose the
configuration that best fits your workload needs and budget. For more
information, see <a href="https://docs.cloud.google.com/ai-hypercomputer/docs/consumption-models#spot">Use Spot</a>.</p>
<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>The Database Insights remote Model Context Protocol (MCP) server now supports
the following advanced query insights tools for AlloyDB for PostgreSQL:</p>
<ul>
<li><code>get_advanced_aggregated_query_stats</code></li>
<li><code>get_advanced_aggregated_wait_event_stats</code></li>
<li><code>get_advanced_time_series_query_stats</code></li>
<li><code>get_advanced_time_series_wait_event_stats</code></li>
<li><code>get_index_recommendations</code></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/alloydb/docs/reference/mcp/databaseinsights/mcp/index">Database Insights remote MCP server</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>Use Gemini Cloud Assist to analyze your SQL queries and receive
recommendations to <a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#optimize-query">optimize query performance in BigQuery</a>.
This feature is available to customers who use BigQuery editions.
This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Issue</h3>
<p>Support for configuring daily token quotas for BigQuery generative AI
functions has been temporarily disabled. We are working to restore this
feature as soon as possible.</p>
<h3>Feature</h3>
<p>You can resize the width of table columns in BigQuery Studio for
BigQuery listings such as datasets, repositories, job history,
and connections. To resize a column, hover over the column divider and drag it
to your preferred width.</p>
<h3>Feature</h3>
<p>You can use Gemini Code Assist directly within the BigQuery <strong>Jobs explorer</strong>,
<strong>Job details</strong>, <strong>Job history</strong>, and <strong>Capacity management</strong> pages to help you
troubleshoot and analyze performance issues. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/admin-jobs-explorer#get-job-details">Troubleshoot job
performance</a>. This feature
is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Blockchain Node Engine</h2>
<h3>Announcement</h3>
<p><strong>Limited support for Blockchain Node Engine</strong></p>
<p>Starting June 15, 2026, Blockchain Node Engine will enter a period of limited support.</p>
<ul>
<li><p>New node creation in Blockchain Node Engine and provisioning of new Blockchain RPC endpoints will be disabled.</p></li>
<li><p>Existing nodes and endpoints will continue to function and receive critical updates until the final shutdown date.</p></li>
<li><p>We recommend migrating your workloads to our partner, <a href="https://www.quicknode.com/gcp-node-migration"><strong>Quicknode</strong></a>, to avoid service disruption.</p></li>
</ul>
<p>For more information, see the <a href="https://docs.cloud.google.com/blockchain-node-engine/docs/migrate-to-quicknode.md">migration guide</a>.</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>New filters and group-by options available in Cloud Billing Reports</strong></p>
<p>Cloud Billing has added two <strong>filters</strong> to the <strong>Billing Reports</strong>
page to help you analyze and understand your costs:</p>
<ul>
<li><p><strong>Products</strong>: Google Cloud
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-products">Products</a>
consist of a group of SKUs (potentially from more than one
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-services">Google Cloud <em>Service</em></a>)
that work together and are sold as a single service, sometimes referred to as
a <em>logical</em> product family or a subscription service. Examples include
Gemini Enterprise and Firebase App Hosting.</p></li>
<li><p><strong>Originating services</strong>: An
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#filter-by-orig-services">Originating service</a>
is a Google Cloud service that causes usage in another service. For
example, Google Kubernetes Engine (GKE) can cause usage in Compute Engine. In
this use case, when you are viewing the Compute Engine usage and
costs, GKE is an originating service when it causes usage
in Compute Engine.</p></li>
</ul>
<p>You can also
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by"><strong>Group by</strong></a> the new filters, to
summarize your costs by the dimension you select.</p>
<ul>
<li><strong>Product</strong>: When you
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by-product">group by <em>Product</em></a>,
the Report shows your costs and savings summarized by Product.</li>
<li><strong>Originating service &gt; Service</strong>: When you
<a href="https://docs.cloud.google.com/billing/docs/how-to/reports#group-by-orig-service">group by <em>Originating service &gt; Service</em></a>,
the Report shows your costs and savings summarized by Originating service.
In the <strong>report table</strong>, you can expand each row for an <em>Originating service</em>
to see your costs summarized by each <em>Service</em> that is associated with the
<em>Originating service</em>.</li>
</ul>
<p>Learn more about <a href="https://docs.cloud.google.com/billing/docs/how-to/reports">analyzing billing data and cost trends with Reports</a>.</p>
<p>Learn how to <a href="https://docs.cloud.google.com/billing/docs/how-to/reports/gemini-enterprise-costs">view Gemini Enterprise costs in Cloud Billing reports</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility#typegoogleapiscomenvoyextensionsfiltershttpcompressorv3compressor">Envoy Compressor Filter</a>
is now GA in the rapid release channel.</p>
<p>To ensure your <code>EnvoyFilter</code> compressor configuration is fully supported, see
<a href="https://docs.cloud.google.com/service-mesh/docs/migrate/modernize-envoyfilter-compressor">Modernize EnvoyFilter compressor configurations</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Preview</strong>: Before you create Spot VMs, you can view the following
  information for a specific machine type and location:</p>
<ul>
<li><p><strong>You can view the real-time obtainability and estimated uptime</strong>. This
information helps you maximize your chances of successfully creating
Spot VMs, as well as help ensure that your workload starts
and runs efficiently.</p></li>
<li><p><strong>You can view historical and current preemption rate and pricing</strong>. This
information helps you compare and choose the configuration that best fits
your workload needs and budget.</p></li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instances/view-vm-availability">View the availability of Spot VMs</a>
and
<a href="https://docs.cloud.google.com/compute/docs/instances/view-spot-preemption-price">View the preemption rate and pricing for Spot VMs</a>.</p>
<h2 class="release-note-product-title">Dataflow</h2>
<h3>Feature</h3>
<p>Dataflow has updated and expanded its pipeline update features for
streaming jobs:</p>
<ul>
<li><strong>Automated stop-and-replace updates</strong>: You can perform automated,
declarative stop-and-replace updates to streaming jobs.</li>
<li><strong>Parallel updates with the same job name</strong>: When you perform automated
parallel updates, you can use the same job name for the new replacement job.</li>
<li><strong>Auto-cancel draining jobs</strong>: When performing parallel or stop-and-replace
updates, you can configure Dataflow to automatically cancel
the old job if it does not finish draining after a timeout you specify.</li>
<li><strong>Update strategy configuration</strong>: You can explicitly choose between a
parallel update (<code>update_strategy_parallel_job_update</code>) and a standard
in-place update (<code>update_strategy_in_place_update</code>) while keeping all other
configuration the same.</li>
<li><strong>Template upsert functionality</strong>: When launching pipelines from classic
templates, flex templates, Terraform, or Config Connector, you can use the
<code>create_or_update_job</code> experiment to enable automatic create-or-update
(upsert) behavior. If an active job with the specified name already exists,
it is updated. Otherwise, a new job is created.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#automated-stop-replace">Automated stop and
replace</a>, <a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#automated-parallel-updates">Automated
parallel pipeline
updates</a>, and
<a href="https://docs.cloud.google.com/dataflow/docs/guides/upgrade-guide#templates-create-or-update">Automatic create or update (upsert) for
templates</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: New data stores and support for new actions (Public Preview)</strong></p>
<p>The following data stores are available in Public Preview:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/airops">AirOps</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/airtable">Airtable</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/calendly">Calendly</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/dynamics365">Dynamics 365</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/freshservice">Freshservice</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/googlestitch">Google Stitch</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/intercom">Intercom</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/mailerlite">MailerLite</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zohocrm">Zoho CRM</a></li>
</ul>
<p>Additionally, support for new actions is available for the following data
stores:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/smartsheet">Smartsheet</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/wrike">Wrike</a></li>
<li><a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/zohoprojects">Zoho Projects</a></li>
</ul>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/connect-third-party-data-source">Connect a third-party data source</a>.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Observability settings for individual agents (Preview)</strong></p>
<p>You can now configure observability settings for individual agents in
Agent Designer employee-made agents. This allows you to monitor metrics in
Metrics Explorer and view trace results in Trace Explorer for specific
agents.</p>
<p>Observability settings for individual agents are configured inside the
agent-level settings. Previously, observability was only available at the
application level, which applies to the Core Assistant agent.</p>
<p>This feature is in Public Preview. For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-observability-settings">Manage observability settings</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Advanced reporting dashboards 4.36</strong></p>
<p>We've released version 4.36 of the advanced reporting dashboards.</p>
<h3>Feature</h3>
<p><strong>New child queues filter option</strong></p>
<p>Dashboards that have the <strong>Queue Name</strong> filter now also have a <strong>Child Queues</strong>
checkbox. Select <strong>Yes</strong> if you want to include all child queues of the
specified queue. There's also a new <strong>Child Queues (Yes / No)</strong> filter available
in Explores that have the <strong>Queue Name</strong> filter.</p>
<h3>Feature</h3>
<p><strong>The Agent &amp; Queue Status (Live) Explore contains new real-time agent and queue metrics</strong></p>
<p>The <strong>Agent &amp; Queue Status (Live)</strong> Explore contains the following new metrics:</p>
<ul>
<li><p><strong>In Call</strong>: the number of agents currently on a call</p></li>
<li><p><strong>Available / Waiting</strong>: the number of agents available and waiting for the
next contact</p></li>
<li><p><strong>Contacts in Queue</strong>: the number of calls currently waiting in the queue</p></li>
</ul>
<h3>Feature</h3>
<p><strong>Link directly to CSAT scores in your CRM from the CSAT dashboards</strong></p>
<p>In the <strong>CSAT Interactions</strong> table of the <strong>CSAT - Calls</strong> and <strong>CSAT - Chats</strong>
dashboards, next to the <strong>Session ID</strong> numbers, links to the associated CSAT
scores in your CRM are now available. You can go directly to the CSAT scores
without needing to search for them in your CRM.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-csat">CSAT dashboards</a>.</p>
<h3>Feature</h3>
<p><strong>Updates to the Real-time Queue Monitoring - Calls dashboard</strong></p>
<p>The <strong>Real-time Queue Monitoring - Calls</strong> dashboard now includes the following
metrics tiles:</p>
<ul>
<li><p><strong>Total Rolled Over Pending Callbacks</strong></p></li>
<li><p><strong>Total Rolled Over Completed Callbacks</strong></p></li>
<li><p><strong>Avg CSAT Calls</strong></p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-real-time-queue-monitor">Queue monitoring dashboards</a>.</p>
<h3>Feature</h3>
<p><strong>Updates to the Queue Performance dashboards</strong></p>
<ul>
<li><p>The <strong>Queue Performance - Calls</strong> and <strong>Queue Performance - Chats</strong>
dashboards now include the following:</p>
<ul>
<li><p>A new <strong>Interaction Type</strong> filter</p></li>
<li><p>A new <strong>Interaction Type</strong> column in the <strong>Queue Detailed Table</strong></p></li>
</ul></li>
<li><p>The <strong>Queue Performance - Calls</strong> dashboard now includes the following
metrics tiles:</p>
<ul>
<li><p><strong>Total Rolled Over Completed Callbacks</strong></p></li>
<li><p><strong>Total Rolled Over Pending Callbacks</strong></p></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p><strong>Repeat contact data in the Queue Performance dashboards</strong></p>
<p>The <strong>Queue Summary Table</strong> of the <strong>Queue Performance - Calls</strong> and <strong>Queue
Performance - Chats</strong> dashboards now includes the following columns:</p>
<ul>
<li><p><strong>Total Repeat Contacts</strong></p></li>
<li><p><strong>Repeat Contact %</strong></p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-performance">Queue Performance dashboards</a>.</p>
<h3>Fixed</h3>
<p>The following issues were addressed in this release:</p>
<ul>
<li><p>Fixed an issue where <strong>Repeat Contact %</strong> values in the <strong>Queue Summary
Table</strong> of the <strong>Queue Performance - Calls</strong> dashboard exceeded 100%.</p></li>
<li><p>Fixed an issue where the <strong>Date</strong> filter in Explores returned no results
when <strong>is on or after</strong> was set for an absolute date.</p></li>
<li><p>Removed the <strong>Total Logged in Time</strong> metrics tile from the <strong>Agent
Availability</strong> dashboard.</p></li>
<li><p>Fixed an issue where language labels were missing from the advanced
reporting dashboards.</p></li>
<li><p>Fixed an issue that occurred when filtering by chat ID in the <strong>All
Interactions - Chats</strong> dashboard. The wrong chat ID appeared in the
<strong>Virtual Agent Chats</strong> table.</p></li>
<li><p>Fixed an issue where disposition codes were missing or blank for outbound
calls in the <strong>Call Agent Metrics (Historical)</strong> dashboard.</p></li>
</ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Starting with Distributed Cloud software only for VMware version
1.33.0-gke.799, you must add <code>us.gcr.io</code> to your firewall allowlist to
create or upgrade advanced clusters.</p>
<h2 class="release-note-product-title">Identity and Access Management</h2>
<h3>Feature</h3>
<p>You can use the error ID provided in permission error messages to help
troubleshoot access. Error IDs provide context for the error, including the
principal, resource, permission, and supported IAM conditions.
This feature is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/iam/docs/permission-error-messages">Permission error messages</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 14, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_14_2026</id>
    <updated>2026-06-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_14_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.89 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 13, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_13_2026</id>
    <updated>2026-06-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_13_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>Non-prioritized IoC Matching rules Category</strong></p>
<p>Google SecOps has introduced a new detection category, <em>Non-prioritized IoC Matching rules</em>, as part of the <a href="https://docs.cloud.google.com/chronicle/docs/detection/curated-detections">Curated Detections</a> feature. These rule sets integrate with Google's Indicators of Compromise (IoC) feeds and build on curated threat intelligence to identify malicious activities within Google SecOps environments, specifically focusing on threats identifiable through high-fidelity indicators like IPs, domains, and file hashes.</p>
<p>This rules category provides comprehensive coverage for threats often missed by standard managed content, including cryptomining, Command and Control (C2) communications, and the use of malicious anonymization services.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/detection/non-prioritized-ioc-matching-threats-category">Non-prioritized IoC Matching rules category overview</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>Non-prioritized IoC Matching rules Category</strong></p>
<p>Google SecOps has introduced a new detection category, <em>Non-prioritized IoC Matching rules</em>, as part of the <a href="https://docs.cloud.google.com/chronicle/docs/detection/curated-detections">Curated Detections</a> feature. These rule sets integrate with Google's Indicators of Compromise (IoC) feeds and build on curated threat intelligence to identify malicious activities within Google SecOps environments, specifically focusing on threats identifiable through high-fidelity indicators like IPs, domains, and file hashes.</p>
<p>This rules category provides comprehensive coverage for threats often missed by standard managed content, including cryptomining, Command and Control (C2) communications, and the use of malicious anonymization services.</p>
<p>For more information, refer to <a href="https://docs.cloud.google.com/chronicle/docs/detection/non-prioritized-ioc-matching-threats-category">Non-prioritized IoC Matching rules category overview</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#June_07_2026">Release 6.3.88</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 12, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_12_2026</id>
    <updated>2026-06-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_12_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/generative-ai-overview">BigQuery AI functions</a> can use
<a href="https://docs.cloud.google.com/bigquery/docs/work-with-objectref"><code>ObjectRef</code> values</a> directly as input,
without calling the <code>OBJ.GET_ACCESS_URL</code> function.
This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Change</h3>
<p>All <code>agent.googleapis.com/processes</code> metrics are retained for 24 months. For
more information, see <a href="https://docs.cloud.google.com/monitoring/quotas#data_retention_policy">Data retention</a>.</p>
<h2 class="release-note-product-title">Cloud SQL for PostgreSQL</h2>
<h3>Feature</h3>
<p>You can now create and query <a href="https://docs.cloud.google.com/sql/docs/postgres/parameterized-secure-views">parameterized secure views</a>
in Cloud SQL for PostgreSQL.</p>
<p>Parameterized secure views let you use PostgreSQL views with more granular
access control over your data. While you can issue a <code>GRANT</code> statement to control
whether a user can query a PostgreSQL view, a <code>GRANT</code> statement doesn't let you
control the data that the view returns based on the user who is making the
query.</p>
<p>To gain this level of control, use parameterized secure views. You can
define parameters such as a user ID or region within the view. When your
application queries the view, a user can provide values for these parameters,
which customizes the query results. Using parameterized secure views lets you
enforce "least privilege" access to help ensure that your users interact only
with the data that is relevant and authorized to them.</p>
<p>This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Security</h3>
<p>The following images are now rolling out for managed Cloud Service Mesh:</p>
<ul>
<li>Sidecar version 1.21.6-asm.36, is rolling out to the rapid release channel.</li>
<li>Sidecar version 1.20.8-asm.86 is rolling out to the regular release channel.</li>
<li>Sidecar version 1.19.10-asm.76 is rolling out to the stable release channel.</li>
</ul>
<p>These rollouts will preempt those <a href="#June_03_2026">previously announced on June 3, 2026</a>.</p>
<p>These patch releases contain the fix for the vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a></p>
<h3>Security</h3>
<p>Proxy version csm_mesh_proxy.20260423_RC03 for Gateway API on GKE clusters is
rolling out to all Managed Cloud Service Mesh release channels over the next
week.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise mobile app: General availability (GA) for Google Identity users</strong></p>
<p>The Gemini Enterprise mobile app is generally available (GA) for organizations using Google Identity as their identity provider. Users can access their agents, search enterprise data, utilize voice features, and perform interactive actions from iOS and Android devices.</p>
<p>With this release, administrators can display a configuration QR code on the web app homepage to enable user access by scanning the QR code. For organizations using Microsoft Entra ID, access to the mobile app is in GA with allowlist.</p>
<p>To learn more, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/configure-mobile-app">Configure the mobile app</a> and <a href="https://docs.cloud.google.com/gemini/enterprise/docs/use-the-mobile-app">Use the mobile app</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.40</strong></p>
<p>We've released version 4.40 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue with Salesforce where virtual agent responses appeared out of
order in transcripts.</p></li>
<li><p>Fixed an issue where the advanced reporting dashboards didn't load.</p></li>
<li><p>Fixed an issue where PDF and audio attachments weren't visible to agents
after a chat transfer.</p></li>
<li><p>Fixed an issue where end-users were incorrectly placed on hold following a
cold transfer to a queue.</p></li>
<li><p>Fixed an issue where MP3 audio files for agent call deflections couldn't be
uploaded.</p></li>
<li><p>Fixed an issue where agents were automatically logged out due to inactivity
while still engaged in active calls or chats.</p></li>
<li><p>Fixed an issue where a bulk user upload with blank phone number columns
caused existing direct inbound phone numbers to become unassigned from agent
profiles.</p></li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1059000</li>
<li>1.34.8-gke.1126000</li>
<li>1.35.5-gke.1057000</li>
<li>1.36.0-gke.2459000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.2190000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2458000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2608000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1868000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1986000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1492000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1657000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.2190000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r23-security-updates">(2026-R23) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.30.14-gke.2681000</td>
<td>cos-117-18613-613-40</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-40_">cos-117-18613-613-40 release notes</a></td>
</tr>
<tr>
<td>1.31.14-gke.2074000</td>
<td>cos-117-18613-613-40</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-40_">cos-117-18613-613-40 release notes</a></td>
</tr>
<tr>
<td>1.33.12-gke.1166000</td>
<td>cos-121-18867-381-161</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-161_">cos-121-18867-381-161 release notes</a></td>
</tr>
<tr>
<td>1.35.5-gke.1241000</td>
<td>cos-125-19216-395-55</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-55_">cos-125-19216-395-55 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.2459000</td>
<td>cos-129-19506-120-64</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-120-64_">cos-129-19506-120-64 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.2190000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1059000</li>
<li>1.34.8-gke.1126000</li>
<li>1.35.5-gke.1057000</li>
<li>1.36.0-gke.2459000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1166000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1278000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1241000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3009002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.3070003</a></li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r23-version-updates">(2026-R23) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2681000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.2074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1729000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2458000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2608000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1868000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1986000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1492000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1657000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.2190000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Search for cases using SIEM Search</strong></p>
<p>Google SecOps SIEM Search now provides robust capabilities for analyzing cases and case history alongside existing Unified Data Model (UDM) events and entities. This update allows security analysts to seamlessly correlate case details with other security telemetry within a single interface, streamlining workflows and accelerating incident response.</p>
<p>Key Highlights:</p>
<ul>
<li><p><strong>Unified Search Experience</strong>: Conduct searches across UDM events, entities, cases, and case history from a single SIEM Search interface.</p></li>
<li><p><strong>Correlate SIEM and SOAR Data</strong>: Effortlessly link case details and historical activities with security data, reducing context switching and improving investigation efficiency.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-and-search-case-history">Search cases and case history</a>.</p>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Investigate detections in Google SecOps Search</strong></p>
<p>Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or entities, matching detections will now appear in the <strong>Alerts and Detections</strong> tab, providing a more holistic workflow for threat investigation.</p>
<p>For more details, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/investigate-detections-in-search">Investigate detections in Search</a>.</p>
<h3>Announcement</h3>
<p><strong>Asynchronous Search APIs for large datasets</strong></p>
<p>Google SecOps now supports asynchronous Search APIs that let you perform
long-running queries without blocking your applications. This is ideal for 
searches that return a large volume of results.</p>
<ul>
<li><strong>Non-blocking queries</strong>: Initiate searches and receive an operation ID to
track progress, so your application remains responsive.</li>
<li><strong>Handle large result sets</strong>: Retrieve up to 1 million results from data
sources including Unified Data Model (UDM) events, data tables, and Entity
Context Graph (ECG).</li>
<li><strong>Paginated results</strong>: View results efficiently in manageable pages.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-lro-api">Asynchronous Search APIs</a>
and <a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#resultLimitsDataSources">Result limits for data sources</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Investigate detections in Google SecOps Search</strong></p>
<p>Google SecOps Search now supports querying, filtering, and analyzing system-generated detections. When searching on events or entities, matching detections will now appear in the <strong>Alerts and Detections</strong> tab, providing a more holistic workflow for threat investigation.</p>
<p>For more details, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/investigate-detections-in-search">Investigate detections in Search</a>.</p>
<h3>Announcement</h3>
<p><strong>Asynchronous Search APIs for large datasets</strong></p>
<p>Google SecOps now supports asynchronous Search APIs that let you perform
long-running queries without blocking your applications. This is ideal for 
searches that return a large volume of results.</p>
<ul>
<li><strong>Non-blocking queries</strong>: Initiate searches and receive an operation ID to
track progress, so your application remains responsive.</li>
<li><strong>Handle large result sets</strong>: Retrieve up to 1 million results from data
sources including Unified Data Model (UDM) events, data tables, and Entity
Context Graph (ECG).</li>
<li><strong>Paginated results</strong>: View results efficiently in manageable pages.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/search-lro-api">Asynchronous Search APIs</a>
and <a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#resultLimitsDataSources">Result limits for data sources</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Feature</h3>
<p>New Managed Airflow (Gen 2) environments created while the Restrict Endpoint
Usage organization policy is active now use regional endpoints for services
like Cloud Storage, Cloud Logging, Pub/Sub, and Data Lineage. For more
information, see
<a href="https://docs.cloud.google.com/composer/docs/composer-2/configure-restrict-endpoint-usage-environments">Configure environments with Restrict Endpoint Usage policy</a>.</p>
<h2 class="release-note-product-title">Media CDN</h2>
<h3>Feature</h3>
<p>The maximum cacheable object size for Media CDN can be increased up to 1 TiB. To
request a limit increase for your project, contact your Google support
representative. This feature is <strong>Generally Available</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/media-cdn/quotas">Quotas and limits</a>.</p>
<h3>Feature</h3>
<p>Media CDN lets you identify the country codes of the edge caches serving client
requests. This feature is <strong>Generally Available</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/media-cdn/docs/custom-headers#header-variables">Custom headers</a>.</p>
<h2 class="release-note-product-title">Policy Intelligence</h2>
<h3>Feature</h3>
<p>The ability to <a href="https://docs.cloud.google.com/policy-intelligence/docs/remediate-requests">remediate access
issues</a> with Policy Troubleshooter
is <a href="https://cloud.google.com/products#product-launch-stages">generally
available</a>.</p>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p>Added support for inspecting and de-identifying batched content. You can now include a <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem#BatchContentItem">BatchContentItem</a></code> in your <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem">ContentItem</a></code> requests.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 11, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_11_2026</id>
    <updated>2026-06-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_11_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can <a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#administer_bigquery">monitor performance, analyze capacity, and optimize costs with Gemini Cloud Assist in BigQuery</a>.
This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>Support for the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-key-drivers"><code>AI.KEY_DRIVERS</code> function</a>
is restored. You can use the
<code>AI.KEY_DRIVERS</code> function to identify segments of data that cause statistically significant changes to a summable metric.</p>
<p>This feature is in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p>In an autoscaled managed instance group (MIG), you can configure the
stabilization period to manage how quickly the autoscaler deletes instances
after a decrease in the load. This configuration can help optimize costs or
maintain extra capacity based on your workload requirements. For more
information, see
<a href="https://docs.cloud.google.com/compute/docs/autoscaler/managing-autoscalers#configure_stabilization_period">Configure stabilization period</a>.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Announcement</h3>
<p>The VMware Engine <a href="https://docs.cloud.google.com/vmware-engine/docs/concepts/node-types"><code>ve2</code> node type</a> is now available in the following
additional region:</p>
<ul>
<li>Mexico City (<code>northamerica-south1</code>)</li></ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 109.0</p>
<ul>
<li><p>Refactored the code in the following action:</p>
<ul>
<li><strong>Attach Playbook to Alert</strong></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Knowledge Catalog now supports data profile scans for unstructured data
(such as PDFs in Cloud Storage) on existing BigQuery object tables.
This feature uses Vertex AI Gemini models to extract semantic insights,
including entities and relationships, from unstructured content.</p>
<aside class="note"><strong>Note:</strong><span> Data profile scans for unstructured data are currently available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a> using the
Dataplex REST API only. The cloud console and gcloud
workflows are not supported for this feature.</span></aside>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/data-insights-unstructured-data">About unstructured data insights</a>
and <a href="https://docs.cloud.google.com/dataplex/docs/use-data-profile-unstructured-data">Use data profile for unstructured data</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 10, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_10_2026</id>
    <updated>2026-06-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_10_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Agent Assist</h2>
<h3>Change</h3>
<p>Agent Assist offers <a href="https://docs.cloud.google.com/agent-assist/docs/pgka">Proactive generative knowledge assist</a> V2 in GA. This version supports rich search context, multiple suggested queries, and granular control over triggering events.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>BigQuery continuous queries now support the following aggregation functions:</p>
<ul>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/aggregate_functions#array_agg"><code>ARRAY_AGG</code></a></li>
<li><a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/aggregate_functions#string_agg"><code>STRING_AGG</code></a></li>
</ul>
<p>Support for these functions is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>Multi-project access to Cloud Billing cost views available in
Preview</strong></p>
<p>In Cloud Billing accounts, multi-project access to usage costs lets
project owners, solution owners, developers, and other non-billing admins
see cost data for all of their authorized projects in a single view in the
Cloud Billing console.</p>
<p>The multi-project view uses a combination of Cloud Billing account
permissions and Google Cloud project permissions that let Cloud Billing
administrators and organization administrators jointly control access to
project-level cost data.</p>
<p>Using project-scoped Cloud Billing account permissions,
Cloud Billing administrators can control which solution owners can
view aggregated cost data in the Cloud Billing console.</p>
<ul>
<li>Learn more about <a href="https://docs.cloud.google.com/billing/docs/how-to/project-owners/overview">cost management for project owners</a>.</li>
<li>Learn how to <a href="https://docs.cloud.google.com/billing/docs/how-to/project-owners/setup-multi-project-access">set up multi-project access to costs views</a>.</li></ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Deprecated</h3>
<p>The configuration option to not enroll your cluster in a release channel (known
as <em>No channel</em>, formerly as <em>Static</em>) is now deprecated, and will be removed
on June 14, 2027. For any clusters not enrolled in a release channel, we
recommend that you <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/release-channels#existing-cluster">enroll the cluster</a>
before this date. After the removal date, GKE will enroll all remaining clusters
in the Stable channel. For more information about this deprecation and how you
can achieve the same functionality with release channels, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/release-channels#no_channel">Clusters not
enrolled in a release channel</a>.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>Azure Security Center</strong>: Version 17.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connector:</p>
<ul>
<li><strong>Azure Security Center - Security Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 85.0</p>
<ul>
<li><p>Updated partial batch handling and added dynamic batch sizing to prevent 
timeout loops, refactored logging and added monitoring signals for process 
health, and pipeline states, and improved detections batch parsing and 
processing efficiency in the following connector:</p>
<ul>
<li><strong>Chronicle Alerts Connector</strong></li>
</ul></li>
<li><p><strong>Integration</strong>: Updated authentication flow mechanism.</p></li>
</ul>
<h3>Change</h3>
<p><strong>Google Cloud IAM</strong>: Version 20.0</p>
<ul>
<li><p>Updated Predefined Widgets in the following widgets:</p>
<ul>
<li><p><strong>List Roles</strong></p></li>
<li><p><strong>List Service Accounts</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Azure Sentinel</strong>: Version 64.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Azure Sentinel Incident Connector v2</strong></p></li>
<li><p><strong>Microsoft Sentinel Incident Tracking Connector</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Defender ATP</strong>: Version 32.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Defender ATP Connector</strong></p></li>
<li><p><strong>Microsoft Defender ATP Connector V2</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail</strong>: Version 42.0</p>
<ul>
<li><p>Updated the logic for robust handling of transient upstream API errors and 
connection issues in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Mail Delegated</strong>: Version 19.0</p>
<ul>
<li><p>Updated the logic for robust handling of transient upstream API errors and 
connection issues in the following connector:</p>
<ul>
<li><strong>Microsoft Graph Mail Delegated Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Microsoft Graph Security</strong>: Version 27.0</p>
<ul>
<li><p>Announced deprecation notice. Connector will be deprecated on 30th March 2027. 
Only critical bug fixes will be considered. For more information refer to the 
documentation of individual connectors in the following connectors:</p>
<ul>
<li><p><strong>Microsoft Graph Office 365 Security and Compliance Connector</strong></p></li>
<li><p><strong>Microsoft Graph Security Connector</strong></p></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Protectwise</strong>: Version 7.0</p>
<ul>
<li><p>Refactored the code in the following action:</p>
<ul>
<li><strong>Get Pcap</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Qualys VM</strong>: Version 28.0</p>
<ul>
<li><p>Fixed AttributeError during parsing of multiple host lists and added fallback 
hostname matching in the following actions:</p>
<ul>
<li><p><strong>List Endpoint Detections</strong></p></li>
<li><p><strong>Enrich Host</strong></p></li>
</ul></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 09, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_09_2026</id>
    <updated>2026-06-09T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_09_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud Domains</h2>
<h3>Feature</h3>
<p>Organization Policy Service custom constraints are
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
for Cloud Domains. For more information, see
<a href="https://docs.cloud.google.com/domains/docs/custom-constraints">Use custom organization policies</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Announcement</h3>
<p><strong>1.29.4-asm.0 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>You can now download 1.29.4-asm.0 for in-cluster Cloud Service Mesh. It includes
the features of <a href="https://istio.io/latest/news/releases/1.29.x/announcing-1.29/">Istio 1.29.4</a> subject to the list of
<a href="https://docs.cloud.google.com/service-mesh/docs/supported-features-in-cluster">supported features</a>.</p>
<p>The following environment variables, labels, and annotations are not supported:</p>
<ul>
<li><code>PILOT_IGNORE_RESOURCES</code> and <code>PILOT_INCLUDE_RESOURCES</code></li>
<li><code>RetryIgnorePreviousHosts</code></li>
<li><code>omit_empty_values</code></li>
<li><code>PILOT_SPAWN_UPSTREAM_SPAN_FOR_GATEWAY</code></li>
<li><code>MAX_CONNECTIONS_PER_SOCKET_EVENT_LOOP</code> with the value 1</li>
<li><code>PILOT_DNS_JITTER_DURATION</code></li>
<li><code>PILOT_DNS_JITTER_DURATION</code></li>
<li><code>ENABLE_NATIVE_SIDECARS</code> with the value true</li>
<li><code>PILOT_IP_AUTOALLOCATE_IPV4_PREFIX</code> and <code>PILOT_IP_AUTOALLOCATE_IPV6_PREFIX</code></li>
<li><code>PILOT_DNS_CARES_UDP_MAX_QUERIES</code></li>
<li><code>ENABLE_WILDCARD_HOST_SERVICE_ENTRIES_FOR_TLS</code></li>
<li>'BLOCKED_CIDRS_IN_JWKS_URIS`</li>
<li><code>ENABLE_DEBUG_ENDPOINT_AUTH</code></li>
<li><code>DISABLE_TRACK_REMAINING_CB_METRICS</code></li>
<li><code>gateway.istio.io/tls-cipher-suites</code></li>
<li><code>fileFlushMinSizeKB</code> and <code>fileFlushInterval</code> settings in ProxyConfig</li>
<li><code>topology.istio.io/locality</code></li>
<li><code>statsCompression</code> ProxyConfig option</li>
<li><code>proxy.istio.io/config</code> annotation for metric compression overrides</li>
</ul>
<p>Istio's experimental feature to enable lazy subset creation of envoy statistics
is not supported.</p>
<p>The formatter option within the <code>spec.tracing[].customTags</code> field of the
Telemetry custom resource (telemetry.istio.io) is unsupported.</p>
<p>The <code>istiod_remote_cluster_sync_status</code> Prometheus gauge metric, exposed on the
<strong>Istiod control plane metrics endpoint</strong> (port 15014 <code>/metrics</code>), is not
supported.</p>
<p>The following are unsupported for proxyless gRPC clients:</p>
<ul>
<li><p>Configuring the <code>LEAST_REQUEST</code> load balancing policy within the
<code>spec.trafficPolicy.loadBalancer.simple</code> field of a <strong>DestinationRule</strong> custom
resource (<code>networking.istio.io</code>)</p></li>
<li><p>Configuring the <code>http2MaxRequests</code> circuit breaker within the
<code>spec.trafficPolicy.connectionPool.http.http2MaxRequests</code> field of a
<strong>DestinationRule</strong> custom resource (<code>networking.istio.io</code>)</p></li>
</ul>
<p>The <code>ENABLE_AUTO_SNI</code> flag is still supported to keep aligned with the legacy
behavior.</p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh version 1.29.4-asm.0 uses Envoy v1.37.4-dev.</p>
<h3>Announcement</h3>
<p>In-cluster Cloud Service Mesh 1.26 is no longer supported. For more information and to view the earliest end-of-life dates for other versions, see <a href="https://docs.cloud.google.com/service-mesh/docs/supported-features-in-cluster#supported_versions">Supported versions</a>.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Security</h3>
<p>A vulnerability (CVE-2025-10263) about bypass of translation stages or GPT protections in some Arm core families
was discovered and has been addressed.
For more information, see the
<a href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-036">GCP-2026-036 security bulletin</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code_2">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Share agents with Google Groups</strong></p>
<p>End users can share agents created using Agent Designer with Google Identity
groups, provided an administrator has enabled this feature for the
Gemini Enterprise app.</p>
<p>This feature is generally available (GA). For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer/share-agent">Share an agent</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Anthropic's Claude Fable 5</strong></p>
<p><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude/fable-5">Claude Fable 5</a>
is available in Model Garden.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Mobile SDK for Android version 2.15.3 patch</strong></p>
<p>We've released version 2.15.3 of the Mobile SDK for Android.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where <code>UjetWebFormCallback</code> in the Android SDK lacked the
necessary methods to pass form data.</p></li>
<li><p>Fixed an issue where chat messages and content cards in the Mobile SDK
displayed out of order.</p></li>
<li><p>Fixed an issue where the Android SDK didn't start a new chat session after
the previous session ended.</p></li>
<li><p>Fixed an issue where customers couldn't customize the Android SDK to
display the timeout message to end-users.</p></li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>UDM fields now show the sources of enrichment</strong></p>
<p>The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its data source: U for unenriched fields and E for enriched fields. Enriched fields contain additional metadata values that indicate the source of the enriched data.</p>
<p>For more information, see: <a href="https://docs.cloud.google.com/chronicle/docs/event-processing/data-enrichment#viewing_events">Viewing events</a>.</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>UDM fields now show the sources of enrichment</strong></p>
<p>The new Enrichment feature introduces improvements for managing and understanding your data. Each UDM field is now labeled with an icon to indicate its data source: U for unenriched fields and E for enriched fields. Enriched fields contain additional metadata values that indicate the source of the enriched data.</p>
<p>For more information, see: <a href="https://docs.cloud.google.com/chronicle/docs/event-processing/data-enrichment#viewing_events">Viewing events</a>.</p>
<h2 class="release-note-product-title">NetApp Volumes</h2>
<h3>Feature</h3>
<p>The backup capabilities for <a href="https://docs.cloud.google.com/netapp/volumes/docs/ontap/overview#about_ontap-mode">ONTAP-mode</a>
are generally available (GA). For more information, see <a href="https://docs.cloud.google.com/netapp/volumes/docs/protect-data/about-backups">About backups</a>.</p>
<h3>Feature</h3>
<p>Google Cloud NetApp Volumes remote Model Context Protocol (MCP) server is
generally available. NetApp Volumes remote MCP server lets you manage storage
pools, volumes, backup vaults, backup policies, backups, and snapshots from
LLMs, AI applications, and AI-enabled development platforms. For more
information, see <a href="https://docs.cloud.google.com/netapp/volumes/docs/deploy-use-cases/mcp/use-netapp-mcp">Use the NetApp Volumes remote MCP server</a>
and <a href="https://docs.cloud.google.com/netapp/volumes/docs/reference/mcp">NetApp Volumes MCP Reference</a>.</p>
<h2 class="release-note-product-title">Network Connectivity Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/network-connectivity/docs/network-connectivity-center/concepts/ncc-gateway-overview">NCC Gateway</a>
is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<p>NCC Gateway lets you enable security functions, such
as third-party Security Service Edge (SSE), for cross-cloud network traffic.
You can use <a href="https://docs.cloud.google.com/secure-access-connect/docs/overview">Secure Access Connect</a> with
NCC Gateway to securely connect remote workforces to private
applications in Google Cloud, on-premises, or other cloud providers and to
public applications, like Palo Alto Networks Prisma Access.</p>
<p>For information about pricing, see
<a href="https://cloud.google.com/network-connectivity/pricing#ncc-gateway-pricing">NCC Gateway pricing</a>.</p>
<h2 class="release-note-product-title">Policy Intelligence</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/policy-intelligence/docs/deny-simulator-overview">Policy Simulator for deny policies</a>
is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<h2 class="release-note-product-title">Pub/Sub Lite</h2>
<h3>Announcement</h3>
<p>The <a href="https://docs.cloud.google.com/pubsub/lite/docs/migrate-pubsub-lite-to-managed-service-for-apache-kafka">Pub/Sub Lite to Managed Service for Apache Kafka migration guide</a>
has been updated to use the latest client libraries and to use
<a href="https://docs.cloud.google.com/managed-service-for-apache-kafka/docs/kafka-connect-overview">Kafka Connect</a>
in Managed Service for Apache Kafka.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 08, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_08_2026</id>
    <updated>2026-06-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_08_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On June 8th, 2026, we released an updated version of Apigee (1-17-0-apigee-9).</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>514384893</strong></td>
<td><strong>Security fix for Apigee.</strong> Hardened the Script policy to block server-side request forgery (SSRF) to link-local addresses.</td>
</tr>
<tr>
<td><strong>N/A</strong></td>
<td><strong>Security fix for Apigee infrastructure.</strong></td>
</tr>
</tbody>
</table>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>512850756</strong></td>
<td>Added observability metrics for the OpenTelemetry trace export pipeline, reporting spans exported, export latency, batch size, and dropped spans.</td>
</tr>
<tr>
<td><strong>515039499</strong></td>
<td>Fixed an issue where OpenTelemetry trace export over HTTP could fail to authenticate when sent through a forward proxy that requires basic authentication.</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1165">v1.16.5</h3>
<p>On June 8, 2026 we released an updated version of the Apigee hybrid software, v1.16.5.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.5</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">App Hub</h2>
<h3>Feature</h3>
<p>App Hub support for resources from <a href="https://docs.cloud.google.com/app-hub/docs/supported-resources">Memorystore</a> is now generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>You can <a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#analyze-lineage">analyze data lineage with Gemini Cloud Assist in
BigQuery</a>. This feature is in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can now use Gemini Cloud Assist to
<a href="https://docs.cloud.google.com/bigquery/docs/use-cloud-assist#schedule_a_query">schedule queries</a>. This
feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h3>Feature</h3>
<p>You can use the Google-developed, open source
<a href="https://docs.cloud.google.com/bigquery/docs/jdbc-for-bigquery">Java Database Connectivity (JDBC) driver for BigQuery</a>
to connect your Java applications to BigQuery. This feature is
<a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can use custom constraints with Organization Policy to provide more
granular control over specific fields for some BigQuery sharing
resources. For more information, see
<a href="https://docs.cloud.google.com/bigquery/docs/analytics-hub-custom-constraints">Manage Sharing data exchanges and listings using custom constraints</a>.
This feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/control-access-to-resources-iam#deny_access_to_a_resource">IAM deny policies</a>
for BigQuery are now <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h3>Feature</h3>
<p>You can manage and limit the costs associated with BigQuery generative AI
functions by configuring <a href="https://docs.cloud.google.com/bigquery/docs/control-genai-costs">daily token quotas</a>.
Token-based cost management for BigQuery generative AI functions is
<a href="https://cloud.google.com/products/#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>FOCUS billing data export to BigQuery available in Preview</strong></p>
<p><a href="https://docs.cloud.google.com/billing/docs/how-to/export-data-bigquery">Cloud Billing data export to BigQuery</a>
now offers a FOCUS billing data export available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.
The <a href="https://focus.finops.org/what-is-focus/" track-metadata-position="body" track-name="externalLink" track-type="tasks"><em>FinOps Open Cost and Usage Specification</em> (FOCUS)</a> 
is an open specification that defines clear requirements for technology billing
data generators to produce consistent cost and usage datasets. The Google Cloud
billing data export using the
<a href="https://focus.finops.org/focus-specification/">FOCUS specifications</a>
includes FOCUS columns up to
<a href="https://focus.finops.org/focus-specification/v1-2/">FOCUS version 1.2</a>.</p>
<p>For more information about the FOCUS billing data export to BigQuery, refer
to the following documentation:</p>
<ul>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/export-data-bigquery-focus-setup">Set up FOCUS Cloud Billing data export to BigQuery</a></li>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/export-data-bigquery-tables/focus-export">Structure of the FOCUS data export</a></li>
<li><a href="https://docs.cloud.google.com/billing/docs/how-to/export-data-bigquery-tables/focus-export#conformance-report">FOCUS conformance report</a></li>
<li><a href="https://focus.finops.org/use-cases/?version=v1-2">Query examples for FOCUS use cases</a></li></ul>
<h2 class="release-note-product-title">Cloud SQL for MySQL</h2>
<h3>Feature</h3>
<p>Cloud SQL for MySQL <a href="https://docs.cloud.google.com/sql/docs/mysql/optimize-high-memory-usage#enable-managed-buffer-pool">managed buffer pool</a>
is now generally available (<a href="https://cloud.google.com/products/#product-launch-stages">GA</a>).
Managed buffer pool helps you avoid out-of-memory events (OOMs) on your
Cloud SQL instance by reducing <code>innodb_buffer_pool_size</code> when memory usage is high.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Security</h3>
<p><strong>1.28.7-asm.4 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>This patch release contains the fix for the security vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a>.</p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.28.7-asm.4 uses Envoy v1.36.8-dev.</p>
<h3>Security</h3>
<p><strong>1.27.9-asm.5 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>This patch release contains the fix for the security vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a>.</p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/v1.27/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.27.9-asm.5 uses Envoy v1.35.12-dev.</p>
<h3>Security</h3>
<p><strong>1.26.8-asm.11 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>This patch release contains the fix for the security vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a>.</p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/v1.26/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.26.8-asm.11 uses Envoy v1.34.14.</p>
<h3>Announcement</h3>
<p>The rollouts <a href="#June_03_2026">previously announced on June 3, 2026</a> have been
stopped. The following release will supersede them and include those patches
and the fix for the vulnerability listed in
<a href="https://docs.cloud.google.com/service-mesh/docs/security-bulletins#gcp-2026-035">GCP-2026-035</a>.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>The Trace API supports regional endpoints. For a list of supported endpoints,
see the REST API reference pages:</p>
<ul>
<li><a href="https://docs.cloud.google.com/trace/docs/reference/v1/rest?rep_location=global">v1 REST reference</a></li>
<li><a href="https://docs.cloud.google.com/trace/docs/reference/v2/rest?rep_location=global">v2 REST reference</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Feature</h3>
<p>The workstation configuration creation page in the Google Cloud console has been optimized to make configuration creation faster and easier. Common machine settings are grouped into selectable machine presets, frequently used settings are consolidated on the <strong>Configuration essentials</strong> landing page, and a pending cluster with default settings is automatically provisioned when no cluster exists in your selected region.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>:
The <a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#supported_disk_types_for_c4d">C4D</a>
machine series supports Hyperdisk Balanced High Availability disks.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/disks/hd-types/hyperdisk-balanced-ha">About Hyperdisk Balanced High Availability</a>
and <a href="https://docs.cloud.google.com/compute/docs/disks/hyperdisk-perf-limits#hdbha-perf">Performance limits for machine series</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-125-19216-395-73_">cos-125-19216-395-73 <a id='"cos-arm64-125-19216-395-73"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/9b2019e2a0a65bafcc7fb941120bfa3088ef8a59
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.73/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43492 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43503 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45837 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46061 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46062 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46072 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46076 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46108 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46128 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46129 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46139 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46159 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46177 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46193 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-129-19506-224-16_">cos-129-19506-224-16 <a id='"cos-arm64-129-19506-224-16"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e06aec09f8bd1eace9b1d1adb0ec84899e9a05f5
">COS-6.12.90</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.224.16/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-162_">cos-121-18867-381-162 <a id='"cos-arm64-121-18867-381-162"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3d2eca1b468c707fe3702ad6e28719c31d6176b1
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.162/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Announcement</h3>
<h3 id="gemini_35_flash_is_generally_available">Gemini 3.5 Flash is generally available</h3>
<p><a href="https://docs.cloud.google.com/gemini/docs/codeassist/gemini-3">Gemini 3.5 Flash</a>
is now generally available to Gemini Code Assist users in VS Code and IntelliJ.
You can use this model for <a href="https://docs.cloud.google.com/gemini/docs/codeassist/agent-mode">agent mode</a>,
<a href="https://docs.cloud.google.com/gemini/docs/codeassist/chat-gemini">chat</a>, and
<a href="https://docs.cloud.google.com/gemini/docs/codeassist/write-code-gemini#generate_code_with_prompts">code generation</a>.</p>
<h3>Announcement</h3>
<h3 id="gemini_35_flash_is_generally_available">Gemini 3.5 Flash is generally available</h3>
<p><a href="https://docs.cloud.google.com/gemini/docs/codeassist/gemini-3">Gemini 3.5 Flash</a>
is now generally available to Gemini Code Assist users in VS Code and IntelliJ.
You can use this model for <a href="https://docs.cloud.google.com/gemini/docs/codeassist/agent-mode">agent mode</a>,
<a href="https://docs.cloud.google.com/gemini/docs/codeassist/chat-gemini">chat</a>, and
<a href="https://docs.cloud.google.com/gemini/docs/codeassist/write-code-gemini#generate_code_with_prompts">code generation</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Gemini 3.5 Flash feature management toggle is no longer available after June 16, 2026</strong></p>
<p>Starting June 16, 2026, the Gemini 3.5 Flash feature management toggle is no longer available. This
change applies to the Global, US, and EU multi-regions.</p>
<aside class="note"><strong>Note:</strong><span> This is a correction to the date mentioned previously in the <a href="https://docs.cloud.google.com/gemini/enterprise/docs/release-notes#June_05_2026">June 05,
2026 release note</a>.</span></aside>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.39</strong></p>
<p>We've released version 4.39 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue with Salesforce where cases weren't created when a virtual
agent connected to a call.</p></li>
<li><p>Fixed an issue where agents on teams with transfer restrictions couldn't
transfer chats to agents not assigned to a team.</p></li>
<li><p>Fixed an issue where agents who weren't available for chat transfers still
appeared in the transfer list, causing transfer attempts to fail.</p></li>
<li><p>Fixed an issue where the <strong>Submit</strong> wrap-up button didn't appear in the
call adapter after agents completed outbound calls.</p></li>
<li><p>Fixed an issue where an agent and caller could still hear each other after
the agent placed the caller on hold.</p></li>
<li><p>Fixed an issue in the agent desktop that occurred after an agent transferred
a call to a different queue. The agent desktop layout of the source queue
displayed to the receiving agent instead of the layout of the destination
queue.</p></li>
<li><p>Fixed an issue where the reporting for After Call Work (ACW) time was
artificially high for calls transferred to a third party.</p></li>
<li><p>Fixed an issue where overcapacity deflection settings interfered with
after-hours deflections, causing calls to be incorrectly queued.</p></li>
<li><p>Fixed an issue where the inactivity timeout didn't function as configured.</p></li>
</ul>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Change</h3>
<p>Several API dependencies that aren't required by Managed Airflow (Gen 3) are
now phased out and must be enabled separately if you want to create
Managed Airflow (Gen 2) environments in a new project. This change was
<a href="https://docs.cloud.google.com/composer/docs/release-notes#June_16_2025">announced previously</a>.</p>
<p>The following API dependencies were phased out:</p>
<ul>
<li>artifactregistry.googleapis.com</li>
<li>cloudbuild.googleapis.com</li>
<li>container.googleapis.com</li>
<li>pubsub.googleapis.com</li>
</ul>
<p>The following API dependencies aren't phased out yet and are scheduled to be
detached from the Cloud Composer API in the future:</p>
<ul>
<li>sqladmin.googleapis.com</li>
</ul>
<p>Existing Managed Airflow (Gen 3) and Managed Airflow (Gen 2) environments in
projects where the Cloud Composer API is already enabled aren't impacted.</p>
<p>You can do the following:</p>
<ul>
<li>If your project has only Managed Airflow (Gen 3) environments, then you can
manually disable the listed APIs that were phased out.</li>
<li>If your project has Managed Airflow (Gen 2) environments, then we recommend
to keep these APIs enabled because disabling them might lead to environment's malfunction.</li>
<li>If you want to create Managed Airflow (Gen 2) environments in a new project,
you can enable the listed APIs manually or using a Google Cloud CLI
command. For more information, see
<a href="https://docs.cloud.google.com/composer/docs/composer-2/enable-composer-service#enable-gen-2-dependencies">Enable Managed Airflow (Gen 2) dependencies</a>.</li>
<li>If you use automation scripts to provision Managed Airflow (Gen 2)
environments, then make sure that the listed APIs are enabled in addition
to the Cloud Composer API.</li>
</ul>
<h2 class="release-note-product-title">Network Intelligence Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/">Cloud Network Insights</a> is in <strong>General Availability</strong>.</p>
<p>Cloud Network Insights monitors your network and web application performance
across multicloud and hybrid networks and provides visualization tools to help
identify and diagnose network issues.</p>
<p>The following additional features are included in this release:</p>
<ul>
<li><p><strong>Compute Engine VM Monitoring Points</strong>: <a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/add-monitoring-points#gce_vm">deploy a Monitoring Point</a> optimized for Google Cloud directly to your Google
Cloud infrastructure using Terraform.</p></li>
<li><p><strong>Connectivity Tests support</strong>: <a href="https://docs.cloud.google.com/network-intelligence-center/docs/cloud-network-insights/run-connectivity-tests">run Connectivity Tests</a>
from Cloud Network Insights to validate connectivity
between endpoints of some dual-ended network paths.</p></li>
</ul>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p>The <code>OBJECT_TYPE/PERSON/SIGNATURE</code> infoType detector is available in <code>global</code> and the <code>asia</code>, <code>europe</code>, and <code>us</code> multi-regions. For more information about all infoTypes, see <a href="https://cloud.google.com/sensitive-data-protection/docs/infotypes-reference">InfoType detector reference</a>.</p>
<h2 class="release-note-product-title">Vertex AI Search</h2>
<h3>Feature</h3>
<p><strong>Agent Search: Prefix and partial matching for filtering search queries (Preview)</strong></p>
<p>You can configure schema fields to support prefix matching and partial matching
in filter expressions:</p>
<ul>
<li><p>Prefix matching lets you filter search results based on whether a field value
starts with a specific string.</p></li>
<li><p>Partial matching lets you filter results based on whether the query contains
some of the words in the field value. Partial matching doesn't require a
perfect match like the <code>ANY</code> operator does.</p></li>
</ul>
<p>This feature is in Public Preview. For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/configure-field-settings">Configure field
settings</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Search: <code>EXISTS</code> filter for filtering search queries (Preview)</strong></p>
<p>You can use the <code>EXISTS</code> filter to filter search results for documents.
Specifying <code>EXISTS</code> for a field means that a document can only be returned in a
search request if the field has a value and that value is not the default.
This
filter is available for custom search and for media search. Use <code>EXISTS</code> with
other filters such as <code>ANY</code> and <code>IN</code> to create expressions to scope the
documents that can be returned in a search query.</p>
<p>This feature is in Public Preview. For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/filter-search-metadata">Filter custom
search for structured or unstructured
data</a>, <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/filter-website-search">Filter website
search</a>, and <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/filter-media-search">Filter
media search</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 07, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_07_2026</id>
    <updated>2026-06-07T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_07_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.88 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 06, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_06_2026</id>
    <updated>2026-06-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_06_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud Location Finder</h2>
<h3>Announcement</h3>
<p>Cloud Location Finder is generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_31_2026">Release 6.3.87</a> is now available for all regions.</p>
<h2 class="release-note-product-title">VPC Service Controls</h2>
<h3>Feature</h3>
<p><a href="https://cloud.google.com/products#product-launch-stages">General availability</a>
support for the following integration:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_firebase_phone_number_verification">Firebase Phone Number Verification</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 05, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_05_2026</id>
    <updated>2026-06-05T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_05_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Cloud Data Fusion</h2>
<h3>Feature</h3>
<p>Cloud Data Fusion version 6.11.1.3 is
generally available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).</p>
<h3>Fixed</h3>
<p>Fixed in Cloud Data Fusion 6.11.1.3:</p>
<ul>
<li><p>Fixed an issue that caused pipeline preview runs to fail with an
<code>InaccessibleObjectException</code> when using certain plugins, such as
Cloud SQL for PostgreSQL
(<a href="https://cdap.atlassian.net/browse/CDAP-21212">CDAP-21212</a>).</p></li>
<li><p>Fixed an issue causing custom plugins to lose their logging context when
running in parallel pipeline branches, ensuring consistent log propagation
across both linear and parallel branched pipeline executions
(<a href="https://cdap.atlassian.net/browse/CDAP-21245">CDAP-21245</a>).</p></li>
<li><p>Fixed critical security vulnerabilities in CDAP
(<a href="https://cdap.atlassian.net/browse/CDAP-21250">CDAP-21250</a>).</p></li>
<li><p>Improved the latency of the <strong>List pipelines</strong> page
(<a href="https://cdap.atlassian.net/browse/CDAP-21244">CDAP-21244</a>).</p></li>
<li><p>Fixed an issue causing intermittent service unavailability after instance
upgrades (<a href="https://cdap.atlassian.net/browse/CDAP-21254">CDAP-21254</a>).</p></li>
</ul>
<h3>Change</h3>
<p>Changes in Cloud Data Fusion 6.11.1.3:</p>
<ul>
<li>Introduced a <code>deployStrategy</code> query parameter in the
<a href="https://cdap.atlassian.net/wiki/spaces/DOCS/pages/477560983/Lifecycle+Microservices#Create-an-Application">Deploy Application API</a>
to skip the re-deployment of an existing pipeline if its configuration hasn't
changed
(<a href="https://cdap.atlassian.net/browse/CDAP-21246">CDAP-21246</a>).</li>
</ul>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>Custom dashboards can display trace data. You can view individual spans or
aggregated data. This feature is
<a href="https://docs.cloud.google.com/products#product-launch-stages">public preview</a>.
For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/monitoring/dashboards/display-traces-on-dashboards">Display trace data (Google Cloud console)</a></li>
<li><a href="https://docs.cloud.google.com/monitoring/dashboards/api-examples#dashboard-with-trace-data">Dashboard with trace data (API)</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>Custom dashboards can display trace data. You can view individual spans or
aggregated data. This feature is
<a href="https://docs.cloud.google.com/products#product-launch-stages">public preview</a>.
For more information, see
<a href="https://docs.cloud.google.com/trace/docs/display-traces-on-dashboards">Display traces on a custom dashboard</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Asana data store (Preview)</strong></p>
<p>The Asana data store is available in Public Preview in Gemini Enterprise.</p>
<p>You can connect an Asana account to search and read projects, workspaces,
teams, and tasks using natural language. You can also perform actions,
such as creating projects and tasks, directly from the Gemini Enterprise app.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/asana">Connect Asana</a>.</p>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Administrator control for Gemini 3.5 Flash</strong></p>
<p>As a reminder, effective June 9, 2026, the feature management toggle for
Gemini 3.5 Flash is no longer available. Gemini 3.5 Flash
is enabled by default for all users in the Gemini Enterprise app and cannot
be disabled.</p>
<p>This change applies to the Global, US, and EU multi-regions.</p>
<aside class="note"><strong>Note:</strong><span> The effective date has been extended by one day from the <a href="https://docs.cloud.google.com/gemini/enterprise/docs/release-notes#May_26_2026">originally
announced schedule</a>.</span></aside>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.33.900-gke.90 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.33.900-gke.90 runs on Kubernetes v1.33.11-gke.100.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.33.900-gke.90:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where a transient or partial failure during node pool updates
could cause node taints or labels to become permanently stuck (stranded) on
worker nodes, even after you removed them from the NodePool custom resource
specification.
</li>
<li>Fixed an issue where, if a new control plane node failed to join a cluster
during bootstrapping or scaling (associated with installer Ansible runner job
failures), orphaned etcd memberships were not cleaned up, causing the existing
control plane's API server to restart repeatedly (flap) and blocking subsequent
retry attempts. </li>
<li>Fixed an issue where, during control plane certificate rotation or etcd
encryption updates, the installer stalled for three minutes per control plane
node while waiting for the local API server to restart, causing nodes to
temporarily report an Unknown status and triggering transient routing
disruptions (such as 503 Service Unavailable or ImagePullBackOff errors) for
workloads scheduled on those nodes.
</li>
<li>Fixed an issue where, when enabling or updating etcd encryption, the API
server was terminated abruptly, causing transient connection timeouts or
failures for in-cluster workloads for up to five minutes.
</li>
<li>Fixed an issue where, when recreating a user cluster with a previously used
name (which commonly occurs during Terraform deployments or manual
reinstalls), cluster provisioning stalled indefinitely in the provisioning
state due to a missing k8s-health-check service account. The installer
ensures that the service account is created, eliminating the need to manually
create the service account as a workaround.</li></ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Deprecated</h3>
<p>Starting June 1, 2026, the Data Catalog service begins a phased shutdown. From this date onward, you might experience disruptions or a complete lack of access to Data Catalog APIs. Knowledge Catalog (formerly known as Dataplex Catalog) operates without impact.</p>
<p>For more information about migrating from Data Catalog to Knowledge Catalog, see <a href="https://docs.cloud.google.com/dataplex/docs/transition-to-dataplex-catalog">Transition from Data Catalog to Knowledge Catalog</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview">AI Protection</a> supports
data residency in the European Union (EU) for the Security Command Center Premium tier.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/security-command-center/docs/data-residency-support">Planning for data
residency</a>.</p>
<h3>Change</h3>
<p>The following Security Command Center finding category names from AI Protection have
new names that clarify that AI Protection detects Gemini foundation models:</p>
<ul>
<li><code>VERTEX_AI_MODEL_DETECTED</code> changes to <code>GEMINI_MODEL_DETECTED</code>.</li>
<li><code>VERTEX_AI_MODEL_NOT_PROTECTED_BY_MODEL_ARMOR</code> changes to
<code>GEMINI_MODEL_NOT_PROTECTED_BY_MODEL_ARMOR</code>.</li>
</ul>
<p>For more information about AI Protection findings, see
<a href="https://docs.cloud.google.com/security-command-center/docs/ai-protection-overview">AI Protection overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 04, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_04_2026</id>
    <updated>2026-06-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_04_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Anthos Config Management</h2>
<h3>Change</h3>
<p>Addressed multiple Common Vulnerabilities and Exposures (CVEs) by updating dependencies.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>To view the instrumentation scope or the schema associated with a span, open the
<strong>Details</strong> view for the span and select the <strong>Metadata &amp; Links</strong> tab.
For more information, see
<a href="https://docs.cloud.google.com/trace/docs/finding-traces#attributes-events">View attributes, log entries, and events</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-121-18867-381-161_">cos-121-18867-381-161 <a id='"cos-arm64-121-18867-381-161"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3d2eca1b468c707fe3702ad6e28719c31d6176b1
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.161/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43503 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-40_">cos-117-18613-613-40 <a id='"cos-arm64-117-18613-613-40"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8b4d5a73b054b07c3abedde85bd34343fffb9566
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.40/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<h2 class="release-note-product-title">Document AI</h2>
<h3>Feature</h3>
<p>Custom extractor offers document validation and correction in <a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.</p>
<p>This feature allows you to enhance extraction accuracy with validation rules
and document data using Common Expression Language (CEL) dialect.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/document-ai/docs/ce-common-expression-validation.md">CEL dialect for document
validation</a>.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1000000</li>
<li>1.34.8-gke.1000000</li>
<li>1.35.5-gke.1000000</li>
<li>1.36.0-gke.2253000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1074000</li>
<li>1.34.7-gke.1055000</li>
<li>1.35.3-gke.1389002</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.11-gke.1013000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1307000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2608000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1986000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1657000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2441000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2558000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1850000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1967000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1449000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1592000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1074000</li>
<li>1.34.7-gke.1055000</li>
<li>1.35.3-gke.1389002</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1868000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1492000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2608000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1986000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1657000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.11-gke.1013000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1154000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1389000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1993000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r22-security-updates">(2026-R22) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.34.8-gke.1218000</td>
<td>cos-125-19216-395-7</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-7_">cos-125-19216-395-7 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.2684000</td>
<td>cos-129-19506-120-64</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-120-64_">cos-129-19506-120-64 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.11-gke.1013000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1307000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1074000</li>
<li>1.34.7-gke.1055000</li>
<li>1.35.3-gke.1389002</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2684000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.12-gke.1000000</li>
<li>1.34.8-gke.1000000</li>
<li>1.35.5-gke.1000000</li>
<li>1.36.0-gke.2253000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2608000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1986000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1657000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1116000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1218000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1163000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.11-gke.1013000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1154000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1389000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1993000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Feature</h3>
<p>GKE Gateway now supports frontend mTLS (client certificate validation). Frontend mTLS allows the Gateway to authenticate client-presented certificates. This feature is available for the following GatewayClasses:</p>
<ul>
<li><code>gke-l7-global-external-managed</code></li>
<li><code>gke-l7-regional-external-managed</code></li>
<li><code>gke-l7-rilb</code></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/secure-gateway#configure-frontend-mtls">Configure frontend mTLS for a Gateway</a>.</p>
<h3>Change</h3>
<h4 id="2026-r22-version-updates">(2026-R22) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2608000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1986000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1657000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2441000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2558000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1850000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1967000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1449000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1592000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1074000</li>
<li>1.34.7-gke.1055000</li>
<li>1.35.3-gke.1389002</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2458000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1868000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1492000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>You can use the <a href="https://docs.cloud.google.com/dataplex/docs/reference/rest/v1/projects.locations/lookupContext"><code>lookupContext</code></a> method to retrieve a pre-formatted bundle of data asset context optimized for interactive agentic workflows. This LLM-ready context helps to ground your agents in assessing and using data assets.</p>
<p>This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/retrieve-data-context">Retrieve context for data assets</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p><strong>Looker 26.10</strong> is expected to include the following changes, features, and fixes:</p>
<ul>
<li>Expected Looker (original) deployment start: <strong>Sunday, June 7, 2026</strong></li>
<li>Expected Looker (original) final deployment and download available: <strong>Sunday, June 21, 2026</strong></li>
<li>Expected Looker (Google Cloud core) deployment start: <strong>Sunday, June 7, 2026</strong></li>
<li>Expected Looker (Google Cloud core) final deployment: <strong>Sunday, June 21, 2026</strong></li>
</ul>
<h3>Fixed</h3>
<p>An issue has been fixed where clicking <strong>Save and Schedule</strong> on an Explore could fail to load the <strong>Schedule</strong> dialog in a Looker (Google Cloud core) instance. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where cross filters didn't properly appear in the right-aligned filter bar. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where attempting to download or schedule the <strong>Recent Login Failures</strong> tile on the <strong>User Activity</strong> System Activity dashboard could fail. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where users were unable to scroll dashboards when the filter bar was open. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where dragging a dashboard tile horizontally could cause the tile to expand beyond the browser window. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed for filters on <a href="https://docs.cloud.google.com/looker/docs/custom-calendars">custom calendar</a> fields that was causing a SQL error when the custom calendar <code>dimension_group</code> or the custom calendar <code>reference_date</code> had a non-timestamp <code>datatype</code> specified. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where configuring remote dependencies with custom SSH ports for on-premise Git repositories could fail. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where applying string matching filters (such as <code>Contains</code> or <code>Starts With</code>) with an empty value could generate incorrect filter SQL. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the labels that were specified in the <strong>PDT Override Additional JDBC Parameters</strong> field weren't being applied to BigQuery table creation jobs. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where changes to Markdown files weren't saved when you switched between <strong>Edit</strong> and <strong>Preview</strong> mode. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where running queries against derived tables in SQL Runner could cause Looker to return a 500 error. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the right-aligned filter bar could become wide enough to require a scroll bar if a range slider filter was added. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where right-clicking in a drill-down menu during a cookieless embed session could incorrectly close the menu. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where retrieving all schemas for a Denodo connection could overload the database CPU. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the <strong>Unsubscribe</strong> link could fail to appear in a scheduled report email. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the Advanced Vis Config editor would not recognize the <code>plotOptions.column.borderRadius</code> option. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where dashboard filters could fail to be updated from inactive to active color highlighting when certain types of date inputs were present. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where visualizations could overflow instead of shrinking when a tile or browser was resized. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>When you edit a visualization, the Advanced Vis Config editor can now override default theme border and padding styles. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where a join wouldn't be added to a query if the join was required by a measure that was excluded from an Explore. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where period-over-period (POP) measures of types <code>previous</code> and <code>difference</code> that were based on <code>count</code> and <code>sum</code> measures would incorrectly return null instead of zero when no data was available for the comparison period. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where filter suggestions on dashboard filters could incorrectly retain previous filter values. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where setting a field name or an Explore name in a LookML dashboard as a non-string datatype could cause the LookML validator to return a 500 error. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where the <code>button group</code> dashboard filter type could display more than 30 options, cluttering the UI. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where moving a filter by dragging it could also inadvertently highlight text. This feature now performs as expected.</p>
<h3>Fixed</h3>
<p>An issue has been fixed where some PDT settings were unavailable when you created a BigQuery connection by using the Quickstart flow in a Looker (Google Cloud core) instance. This feature now performs as expected.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/looker/docs/period-over-period">Period-over-period (PoP) measures</a> are now supported on connections to Trino databases.</p>
<h2 class="release-note-product-title">Memorystore for Valkey</h2>
<h3>Feature</h3>
<p>Memorystore for Valkey has additional <a href="https://docs.cloud.google.com/memorystore/docs/valkey/supported-monitoring-metrics#cloud-monitoring-node-metrics">node-level metrics</a> for Cloud
Monitoring. These metrics offer detailed insights into the health and
performance of individual nodes within an instance. You can use the metrics to
troubleshoot issues with the nodes to optimize their performance. The metrics
are available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud's Agent for SAP version 3.15</strong></p>
<p>Version 3.15 of Google Cloud's Agent for SAP is generally available (GA). This
version updates the libraries in the agent's
<a href="https://github.com/GoogleCloudPlatform/sapagent">GitHub repository</a> to address
vulnerabilities when you're building the agent from its GitHub source.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/sap/docs/agent-for-sap/whats-new">What's new with Google Cloud's Agent for SAP</a>.</p>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Change</h3>
<p>reCAPTCHA Mobile SDK v18.9.1 is available for iOS. This version
fixes symbol collisions with libraries using Objective-C protos.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 03, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_03_2026</id>
    <updated>2026-06-03T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_03_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">App Engine standard environment Go</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Java</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Node.js</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment PHP</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Python</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">App Engine standard environment Ruby</h2>
<h3>Feature</h3>
<p>App Engine supports <a href="https://docs.cloud.google.com/appengine/docs/standard/vpc-direct-vpc">Direct VPC egress</a> in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Direct VPC egress lets your workloads access VPC network resources as a simpler, more cost-effective <a href="https://docs.cloud.google.com/appengine/docs/standard/compare-direct-vpc-egress-connectors">alternative to Serverless VPC Access connectors</a>.</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/slots#slot-autoscaling">BigQuery fluid scaling</a>, which provides
per-second billing with no minimum duration for autoscaling reservations,
is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>
(GA).</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Announcement</h3>
<p><strong>1.28.7-asm.3 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.28.7-asm.3 uses Envoy v1.36.7-dev.</p>
<h3>Fixed</h3>
<p>Patch 1.28.7-asm.3 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27143">CVE-2026-27143</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31789">CVE-2026-31789</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27140">CVE-2026-27140</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (8.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28387">CVE-2026-28387</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41413">CVE-2026-41413</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (7.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-2219">CVE-2026-2219</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27135">CVE-2026-27135</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28388">CVE-2026-28388</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28389">CVE-2026-28389</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28390">CVE-2026-28390</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-29181">CVE-2026-29181</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31790">CVE-2026-31790</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32280">CVE-2026-32280</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32281">CVE-2026-32281</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32283">CVE-2026-32283</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33811">CVE-2026-33811</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33814">CVE-2026-33814</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-34986">CVE-2026-34986</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39820">CVE-2026-39820</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39836">CVE-2026-39836</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4046">CVE-2026-4046</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42499">CVE-2026-42499</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42501">CVE-2026-42501</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4437">CVE-2026-4437</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5773">CVE-2026-5773</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6276">CVE-2026-6276</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27144">CVE-2026-27144</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39883">CVE-2026-39883</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4878">CVE-2026-4878</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5545">CVE-2026-5545</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32282">CVE-2026-32282</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32289">CVE-2026-32289</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39823">CVE-2026-39823</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39826">CVE-2026-39826</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39817">CVE-2026-39817</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4873">CVE-2026-4873</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6253">CVE-2026-6253</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32288">CVE-2026-32288</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39350">CVE-2026-39350</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4438">CVE-2026-4438</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39819">CVE-2026-39819</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39825">CVE-2026-39825</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6429">CVE-2026-6429</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-7168">CVE-2026-7168</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-35469">CVE-2026-35469</a></td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>High (0.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5958">CVE-2026-5958</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h3>Announcement</h3>
<p><strong>1.27.9-asm.4 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.27.9-asm.4 uses Envoy v1.35.10-dev.</p>
<h3>Fixed</h3>
<p>Patch 1.27.9-asm.4 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2022-31045">CVE-2022-31045</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27143">CVE-2026-27143</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31789">CVE-2026-31789</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27140">CVE-2026-27140</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (8.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28387">CVE-2026-28387</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41413">CVE-2026-41413</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (7.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2019-14993">CVE-2019-14993</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2021-39155">CVE-2021-39155</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2021-39156">CVE-2021-39156</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2022-23635">CVE-2022-23635</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-2219">CVE-2026-2219</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27135">CVE-2026-27135</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28388">CVE-2026-28388</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28389">CVE-2026-28389</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28390">CVE-2026-28390</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-29181">CVE-2026-29181</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31790">CVE-2026-31790</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32280">CVE-2026-32280</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32281">CVE-2026-32281</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32283">CVE-2026-32283</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33811">CVE-2026-33811</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33814">CVE-2026-33814</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-34986">CVE-2026-34986</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39820">CVE-2026-39820</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39836">CVE-2026-39836</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4046">CVE-2026-4046</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42499">CVE-2026-42499</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42501">CVE-2026-42501</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4437">CVE-2026-4437</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5773">CVE-2026-5773</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6276">CVE-2026-6276</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27144">CVE-2026-27144</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39883">CVE-2026-39883</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4878">CVE-2026-4878</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5545">CVE-2026-5545</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32282">CVE-2026-32282</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32289">CVE-2026-32289</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39823">CVE-2026-39823</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39826">CVE-2026-39826</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39817">CVE-2026-39817</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4873">CVE-2026-4873</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6253">CVE-2026-6253</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32288">CVE-2026-32288</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39350">CVE-2026-39350</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4438">CVE-2026-4438</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39819">CVE-2026-39819</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39825">CVE-2026-39825</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6429">CVE-2026-6429</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-7168">CVE-2026-7168</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-35469">CVE-2026-35469</a></td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>High (0.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5958">CVE-2026-5958</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h3>Announcement</h3>
<p>The following images are now rolling out for managed Cloud Service Mesh:</p>
<ul>
<li>1.21.6-asm.32 is rolling out to the rapid release channel.</li>
<li>The regular release channel is being upgraded from 1.20 to 1.21.6-asm.32.</li>
<li>The stable release channel is being upgraded from 1.19 to 1.20.8-asm.80.</li>
</ul>
<h3>Fixed</h3>
<p>These patch releases contain the fixes for the following CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27143">CVE-2026-27143</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31789">CVE-2026-31789</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27140">CVE-2026-27140</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (8.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28387">CVE-2026-28387</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41413">CVE-2026-41413</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (7.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-2219">CVE-2026-2219</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27135">CVE-2026-27135</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28388">CVE-2026-28388</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28389">CVE-2026-28389</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28390">CVE-2026-28390</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-29181">CVE-2026-29181</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31790">CVE-2026-31790</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32280">CVE-2026-32280</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32281">CVE-2026-32281</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32283">CVE-2026-32283</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33811">CVE-2026-33811</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33814">CVE-2026-33814</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-34986">CVE-2026-34986</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39820">CVE-2026-39820</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39836">CVE-2026-39836</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4046">CVE-2026-4046</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42499">CVE-2026-42499</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42501">CVE-2026-42501</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4437">CVE-2026-4437</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5773">CVE-2026-5773</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6276">CVE-2026-6276</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27144">CVE-2026-27144</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39883">CVE-2026-39883</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4878">CVE-2026-4878</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5545">CVE-2026-5545</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32282">CVE-2026-32282</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32289">CVE-2026-32289</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39823">CVE-2026-39823</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39826">CVE-2026-39826</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39817">CVE-2026-39817</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4873">CVE-2026-4873</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6253">CVE-2026-6253</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32288">CVE-2026-32288</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39350">CVE-2026-39350</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4438">CVE-2026-4438</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39819">CVE-2026-39819</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39825">CVE-2026-39825</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6429">CVE-2026-6429</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-7168">CVE-2026-7168</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-35469">CVE-2026-35469</a></td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>High (0.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5958">CVE-2026-5958</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h3>Announcement</h3>
<p><strong>1.26.8-asm.10 is now available for in-cluster Cloud Service Mesh.</strong></p>
<p>For details on upgrading Cloud Service Mesh, see
<a href="https://docs.cloud.google.com/service-mesh/docs/upgrade/upgrade">Upgrade Cloud Service Mesh</a>. Cloud Service
Mesh 1.26.8-asm.10 uses Envoy v1.34.14.</p>
<h3>Fixed</h3>
<p>Patch 1.26.8-asm.10 contains fixes for the following platform CVEs:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Proxy</th>
<th>Control Plane</th>
<th>Distroless</th>
<th>CNI</th>
<th>Severity</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2022-31045">CVE-2022-31045</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27143">CVE-2026-27143</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Critical (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31789">CVE-2026-31789</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (9.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27140">CVE-2026-27140</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (8.8)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28387">CVE-2026-28387</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (8.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-41413">CVE-2026-41413</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (7.7)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2019-14993">CVE-2019-14993</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2021-39155">CVE-2021-39155</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2021-39156">CVE-2021-39156</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2022-23635">CVE-2022-23635</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-2219">CVE-2026-2219</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27135">CVE-2026-27135</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28388">CVE-2026-28388</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28389">CVE-2026-28389</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-28390">CVE-2026-28390</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-29181">CVE-2026-29181</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-31790">CVE-2026-31790</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32280">CVE-2026-32280</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32281">CVE-2026-32281</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32283">CVE-2026-32283</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33811">CVE-2026-33811</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-33814">CVE-2026-33814</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-34986">CVE-2026-34986</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39820">CVE-2026-39820</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39836">CVE-2026-39836</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4046">CVE-2026-4046</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42499">CVE-2026-42499</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-42501">CVE-2026-42501</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4437">CVE-2026-4437</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>High (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5773">CVE-2026-5773</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6276">CVE-2026-6276</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (7.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-27144">CVE-2026-27144</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39883">CVE-2026-39883</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>High (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4878">CVE-2026-4878</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (7.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5545">CVE-2026-5545</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (6.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32282">CVE-2026-32282</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32289">CVE-2026-32289</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39823">CVE-2026-39823</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39826">CVE-2026-39826</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (6.1)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39817">CVE-2026-39817</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4873">CVE-2026-4873</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Low (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6253">CVE-2026-6253</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.9)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-32288">CVE-2026-32288</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.5)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39350">CVE-2026-39350</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-4438">CVE-2026-4438</a></td>
<td>No</td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Medium (5.4)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39819">CVE-2026-39819</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-39825">CVE-2026-39825</a></td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-6429">CVE-2026-6429</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-7168">CVE-2026-7168</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (5.3)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-35469">CVE-2026-35469</a></td>
<td>No</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>High (0.0)</td>
</tr>
<tr>
<td><a href="https://ubuntu.com/security/CVE-2026-5958">CVE-2026-5958</a></td>
<td>Yes</td>
<td>Yes</td>
<td>No</td>
<td>Yes</td>
<td>Medium (0.0)</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: You can gradually create Flex-start VMs in a
managed instance group (MIG) as capacity becomes available. Unlike resize
requests for MIGs that wait for full capacity before creating VMs, this method
might create only a portion of your requested Flex-start VMs if
capacity is unavailable. The MIG creates the remaining VMs later as capacity
permits. Flex-start VMs run for up to seven days and help you
obtain high-demand resources, such as GPUs, at a discounted price.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instance-groups/create-mig-with-flex-start-vms">Create a MIG that uses Flex-start VMs</a>.</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_intellij">Bug fixes in IntelliJ</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: DRZ and MLP compliance in the EU for NotebookLM Enterprise</strong></p>
<p>Gemini Enterprise is compliant with data residency (DRZ) and machine learning
processing (MLP) requirements in the EU for NotebookLM Enterprise
for adding sources and interacting with the sources (chat). However, the
Discover Sources feature and Studio features, such as audio overview, slide
deck, infographic, video overview, mind map, and reports, are not MLP
compliant.</p>
<p>For more information on location limitations, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/locations#notebooklm-limitations">NotebookLM
limitations</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.38</strong></p>
<p>We've released version 4.38 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Feature</h3>
<p><strong>Sort and filter emails</strong></p>
<p>Agents can now sort and filter emails by date in the email adapter.</p>
<p>User experience changes: The email adapter has the following new UI elements:</p>
<ul>
<li><p>A button to toggle between <strong>Oldest to newest</strong> and <strong>Newest to oldest</strong> in
the email list.</p></li>
<li><p>A <strong>Filter by Date</strong> list to filter by preset filters or by a configurable
date range.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/email-adapter#email-lists">Email
lists</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where Canadian French translations for notifications and
error messages were appearing in English.</p></li>
<li><p>Fixed an issue where the Alvaria WFM <strong>Agent Performance</strong> report was
exporting every minute instead of once daily.</p></li>
<li><p>Fixed an issue where the <strong>Agent Preferences</strong> table on the <strong>Agent
Availability</strong> dashboard didn't update when an agent modified their
availability preferences.</p></li>
<li><p>Fixed an agent desktop issue where clicking the <strong>Transfer</strong> button in an
SMS chat displayed an error instead of starting a transfer.</p></li>
<li><p>Fixed an issue where a delay in Salesforce task creation caused a lag in
updating the ticket ID on calls.</p></li>
<li><p>Fixed an issue where agents were unable to transfer SMS chats.</p></li>
<li><p>Fixed an issue where incoming chats were routed to newly signed-in agents
instead of to those who had been available the longest.</p></li>
<li><p>Fixed an issue where messages in the chat adapter's chat history weren't
labeled or aligned to distinguish agent messages from end-user messages.</p></li>
<li><p>Fixed an issue in the IVR <strong>Queue Menu Settings</strong> pane where the text input
field didn't appear when users selected <strong>Text-to-speech</strong>.</p></li>
<li><p>Fixed an issue in the SMS <strong>Queue Menu Settings</strong> pane where phone numbers
weren't appearing in the incoming and outbound <strong>Assigned Numbers</strong> fields.</p></li>
<li><p>Fixed an issue where the web SDK didn't load.</p></li>
<li><p>Fixed an issue where live transcripts and conversation summarization didn't
display in the agent desktop following an instance update.</p></li>
</ul>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>AlienVault USM Appliance</strong>: Version 28.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get PCAP Files For Events</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ConnectWise</strong>: Version 23.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alerts Ticket</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 84.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get Detection Details</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Jira</strong>: Version 58.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Issue</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceDesk Plus</strong>: Version 10.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceDesk PlusV3</strong>: Version 10.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 67.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Incident</strong></li></ul></li></ul>
<h3>Change</h3>
<p><strong>Siemplify</strong>: Version 245.0</p>
<ul>
<li>Refactored internal code execution logic for the platform integration.</li></ul>
<h3>Change</h3>
<p><strong>MISP</strong>: Version 275.6</p>
<ul>
<li>Refactored internal code execution logic and optimized core integration components.</li></ul>
<h3>Change</h3>
<p><strong>Microsoft Sentinel Incident Tracking Connector</strong>: Version 29.0</p>
<ul>
<li>Added the <code>Incident Creation Time Filter (days)</code> advanced parameter and optimized error handling logic.</li></ul>
<h2 class="release-note-product-title">Policy Intelligence</h2>
<h3>Feature</h3>
<p>You can use Policy Analyzer to visualize allow policy queries. This
can help you understand the relationship between identities, roles, permissions,
and resources within your resource hierarchy.</p>
<p>Policy Analyzer supports queries about agent identities. You can see
who can access an agent or what resources and agents a specific agent can reach.</p>
<p>These features are available in in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/policy-intelligence/docs/analyze-iam-policies">Analyze allow policies</a>.</p>
<h2 class="release-note-product-title">Sensitive Data Protection</h2>
<h3>Feature</h3>
<p>Added support for inspecting and de-identifying conversational content. You can now include a <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem#Conversation">Conversation</a></code> in your <code><a href="https://cloud.google.com/sensitive-data-protection/docs/reference/rest/v2/ContentItem">ContentItem</a></code> requests.</p>
<h2 class="release-note-product-title">VPC Service Controls</h2>
<h3>Feature</h3>
<p><a href="https://cloud.google.com/products#product-launch-stages">Preview stage</a> support
for the following integration:</p>
<ul>
<li><a href="https://docs.cloud.google.com/vpc-service-controls/docs/supported-products#table_workloadidentity">Workload Identity API</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>June 02, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_02_2026</id>
    <updated>2026-06-02T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_02_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Feature</h3>
<p>You can now configure a cooldown period to determine when autoscaling occurs
for your read pool instances. For more information, see
<a href="https://docs.cloud.google.com/alloydb/docs/instance-read-pool-scale#autoscale-read-pool">Scale an instance</a>.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On June 2nd, 2026, we released an updated version of Apigee Cassandra.</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Security</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>Apigee Cassandra security update</strong></td>
<td><strong>Security fix for Apigee Cassandra infrastructure.</strong> <p>This addresses the following vulnerabilities:<ul><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39820">CVE-2026-39820</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42499">CVE-2026-42499</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39836">CVE-2026-39836</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33814">CVE-2026-33814</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42501">CVE-2026-42501</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33811">CVE-2026-33811</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39825">CVE-2026-39825</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39817">CVE-2026-39817</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39823">CVE-2026-39823</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39819">CVE-2026-39819</a></li><li><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39826">CVE-2026-39826</a></li></ul></p></td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/remote-functions#create_a_remote_function">Remote functions</a> now
support a custom path in the endpoint URL. You can reuse a single Cloud Run
service for multiple BigQuery remote functions by specifying different path
suffixes on the same endpoint. This feature is <a href="https://cloud.google.com/products/#product-launch-stages">generally
available</a> (GA).</p>
<h2 class="release-note-product-title">Cloud Interconnect</h2>
<h3>Feature</h3>
<p>A single-region Critical production SLA for Cloud Interconnect is
<a href="https://cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<p>For workloads that require 99.99% availability within a single region, you can
now configure a single-region topology that achieves the Critical production SLA.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/tutorials/dedicated-creating-9999-availability">Establish 99.99% availability for Dedicated Interconnect</a>
or the
<a href="https://docs.cloud.google.com/network-connectivity/docs/interconnect/concepts/cci-overview">Cross-Cloud Interconnect overview</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>TLS post-quantum key exchange support is now available for
Application Load Balancers and external proxy Network Load Balancers.
Post-quantum key exchange is
essential for protecting today's traffic from future quantum computing
decryption risks (<em>harvest now, decrypt later</em> attacks).
With post-quantum key exchange enabled, the
load balancer uses post-quantum key exchange with clients that support TLS
1.3 and <code>X25519MLKEM768</code> key exchange.</p>
<p>This feature is rolling out in three phases:</p>
<ul>
<li><p>Phase 1 (Until October 2026): Post-quantum key exchange is not enabled by
default. Customers can elect to opt in and enable it using their SSL policy.</p></li>
<li><p>Phase 2 (October 2026 through October 2027): The feature is enabled by
default. Customers can elect to defer (opt out) if required.</p></li>
<li><p>Phase 3 (After October 2027): The feature is enabled by default,
and options to defer are no longer effective.</p></li>
</ul>
<p>We strongly encourage you to enable post-quantum key exchange now, even before
it is turned on by default. The opportunity to test this today will help you
verify that clients and any intermediate network devices can properly negotiate
post-quantum key exchange.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/load-balancing/docs/post-quantum-tls#post-quantum-key-exchange">Post-quantum key exchange</a>.</p>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>Support for <strong>Histogram</strong> widgets on custom dashboards is
<a href="https://docs.cloud.google.com/products#product-launch-stages">generally available</a>. These widgets extract
the most recent value from each time series, group those values into ranges,
and then provide a graphical representation of the result. Unlike tables or
other widgets that display the most recent values, <strong>Histograms</strong> display
information about the relative frequency of ranges of values.</p>
<p>This widget is one of several visualizations that you can use to display the
most recent values. For more information, see the following documents:</p>
<ul>
<li><a href="https://docs.cloud.google.com/monitoring/charts#add_histogram">Configure a histogram (Google Cloud console)</a></li>
<li><a href="https://docs.cloud.google.com/monitoring/dashboards/api-examples#dashboard_with_a_histogram_widget">Dashboard with an XyChart configured as a histogram (API)</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>The create-observability bucket flow enforces organization policies with
constraints on resource locations. This flow also enforces policies that require
customer-managed encryption keys (CMEKs) and that restrict the projects that
store those keys. Your trace data is stored in an observability bucket.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/set-defaults-for-observability-buckets">Set defaults for observability buckets</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/cmek">Support for CMEKs</a></li>
</ul>
<h2 class="release-note-product-title">Datastream</h2>
<h3>Feature</h3>
<p>Datastream now offers a free tier for change data capture
(CDC) data processed from Google Cloud sources, such as
AlloyDB for PostgreSQL and Spanner. You get the first 100 GiB of
CDC data for free per billing account, per month.</p>
<p>For more information, see the <a href="https://cloud.google.com/datastream/pricing">Pricing</a> page.</p>
<h2 class="release-note-product-title">Filestore</h2>
<h3>Feature</h3>
<p>You can configure your Filestore instances to use Private Service Connect with NFSv3 or NFSv4.1 file system protocols and IPv4 or IPv6 address families to allow consumers access managed services privately from inside their VPC network. This feature is <a href="https://cloud.google.com/products#product-launch-stages">generally available</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/filestore/docs/configure-psc">Create a Filestore instance with Private Service Connect</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Gemini 3 pro image (Nano Banana Pro) and Gemini 3.1 flash image (Nano Banana 2) for image generation</strong></p>
<p>Gemini 3.1 flash image (Nano Banana 2) and Gemini 3 pro image
(gemini-3.0-pro-image) are generally available (GA) in Gemini Enterprise app.</p>
<p>To make these models available to users in your Gemini Enterprise app, a
Gemini Enterprise administrator can manage them in the feature controls:</p>
<ul>
<li><p><strong>Gemini 3 pro image (Nano Banana Pro)</strong>: Turned off by default and is only available in the
Global region.</p></li>
<li><p><strong>Gemini 3.1 flash image (Nano Banana 2)</strong>: Turned off by default and is only available in the
Global region. If an administrator turned on this model during
its Public Preview, it remains turned on in GA in the
Gemini Enterprise app.</p></li>
</ul>
<p>For more information about feature controls, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web app</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Announcement</h3>
<p><strong>Updates to abuse monitoring and zero data retention documentation</strong></p>
<p>Documentation for abuse monitoring, zero data retention, and responsible AI has
been updated to align with the Advanced AI Safety Addendum. These updates
include new details regarding Advanced AI safety, partner-specific terms, and
request-response logging for models like Claude Mythos and Opus.</p>
<p>For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/abuse-monitoring">Abuse monitoring</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention">Zero data retention</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/responsible-ai">Responsible AI</a></li></ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>GKE is introducing the following changes to expand the capabilities of maintenance exclusions:</p>
<ul>
<li><strong>Per-node pool maintenance exclusions</strong>: Available in release channels, these replicate the functionality of disabling node pool auto-upgrades when your cluster isn't enrolled in a release channel.</li>
<li><strong>Extended "No upgrades" exclusion</strong>: The "No upgrades" default maintenance exclusion can now be up to 90 days long.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">Maintenance exclusions</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Feature</h3>
<p><em>(Managed Airflow Gen 3)</em> You can now
<a href="https://docs.cloud.google.com/composer/docs/composer-3/connect-vpc-network#cloud-run-traffic">access Cloud Run endpoints restricted to internal ingress traffic</a>
through your environment's network attachment. This feature is available
through gcloud CLI beta commands and beta Cloud Composer API in all Managed
Airflow (Gen 3) versions.</p>
<h2 class="release-note-product-title">NetApp Volumes</h2>
<h3>Announcement</h3>
<p>Google Cloud NetApp Volumes Flex Unified service level is available with
limited performance in the following region:</p>
<ul>
<li>us-east5 (Columbus)</li>
</ul>
<p>For more information about limited performance regions, see <a href="https://docs.cloud.google.com/netapp/volumes/docs/discover/service-levels#supported_regions_for_flex_unified_limited_performance">Supported regions for Flex Unified limited performance</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 01, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#June_01_2026</id>
    <updated>2026-06-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#June_01_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Agent Assist</h2>
<h3>Feature</h3>
<p>Agent Assist offers <a href="https://docs.cloud.google.com/agent-assist/docs/summarization-with-custom-sections">summarization with custom sections 6.0</a> in GA. The 6.0 version is powered by <code>gemini-3.5-flash</code> and available in all Agent Assist <a href="https://docs.cloud.google.com/agent-assist/docs/regionalization">regions</a>.</p>
<h3>Change</h3>
<p>Agent Assist offers summarization autoevaluation with more rubrics for evaluating completeness. This update also explains the use of N/A in the overall performance view.</p>
<p><a href="https://docs.cloud.google.com/agent-assist/docs/summarization-autoeval-metrics">Summarization autoevaluation</a> is available in the following additional regions:</p>
<ul>
<li>us-east1</li>
<li>northamerica-northeast1</li>
<li>eu-west1</li>
<li>eu-west2</li>
<li>eu-west3</li>
<li>eu-west4</li>
<li>asia-southeast1</li>
<li>asia-northeast1</li>
<li>asia-south1</li>
<li>australia-southeast1</li>
</ul>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>The Facebook Ads connector for the BigQuery Data Transfer Service now supports
data transfers from the following Facebook Ads reports:</p>
<ul>
<li><code>AdInsightsMMM</code></li>
<li><code>Ads</code></li>
<li><code>AdCreatives</code></li>
<li><code>AdSets</code></li>
<li><code>Campaigns</code></li>
<li><code>AdImages</code></li>
<li><code>AdLabels</code></li>
<li><code>Businesses</code></li>
<li><code>CustomAudiences</code></li>
</ul>
<h2 class="release-note-product-title">Cloud Billing</h2>
<h3>Feature</h3>
<p><strong>CUD Analysis is Generally Available</strong></p>
<p>CUD Analysis has reached general availability (GA). This tool supports the new
spend-based CUD model and provides a unified interface for customers to examine
both spend-based and resource-based CUDs. It offers a consolidated view of
Compute resources including the benefits of both resource-based and spend-based
CUDs.</p>
<p>You can use this tool to do the following:</p>
<ul>
<li><strong>Understand savings</strong>: Understand the financial impact of your commitments.</li>
<li><strong>Track key metrics</strong>: Track how effectively your commitments are being
used.</li>
<li><strong>Download data</strong>: Download a CSV file of your daily usage for offline
analysis and reporting.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/billing/docs/how-to/analyze-cuds">Analyze the effectiveness of your CUDs</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>A modernized, component-centric interface for Cloud Load Balancing is available
in <strong>Preview</strong>. This inaugural release provides an expanded perspective of load
balancing infrastructure, offering enhanced transparency into individual
component configurations.</p>
<p><a class="button button-primary" href="https://console.cloud.google.com/net-services/loadbalancing/advanced" target="console">Go to Cloud Console</a> </p>
<p>The key features of this release include the following:</p>
<ul>
<li><p><strong>Comprehensive resource inventory</strong>: A centralized, searchable, and sortable
management layer for granular resources—including forwarding rules,
target proxies, and TLSRoutes—facilitating detailed monitoring of
resource status and interdependencies.</p></li>
<li><p><strong>Interactive resource topology</strong>: A contextual visualization tool that maps
traffic flow from forwarding rules through proxies to backends, enabling
technical teams to efficiently analyze dependencies and accelerate issue
resolution.</p></li>
<li><p><strong>Integrated audit logging</strong>: Embedded audit logs within the console that
offer a unified module for monitoring and tracking
historical configuration changes.</p></li></ul>
<h2 class="release-note-product-title">Cloud Monitoring</h2>
<h3>Feature</h3>
<p>The details page for a span can display the call hierarchy of a trace by using a
directed acyclic graph (DAG). If you view an Application Monitoring dashboard
and explore the trace data that it displays, the flyout supports the DAG option.
If you open the <strong>Trace Explorer</strong> page and explore a span, the DAG option is
also available.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/monitoring/docs/application-monitoring#explore-trace">Application Monitoring: Explore a trace</a></li>
<li><a href="https://docs.cloud.google.com/trace/docs/finding-traces#explore">Trace Explorer: Explore a trace</a></li>
</ul>
<h2 class="release-note-product-title">Cloud TPU</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Compute Engine supports Google's custom-developed
accelerator Tensor Processing Unit (TPU), providing a converged experience
across AI accelerators on Google Cloud. You can use the Compute Engine
instance API and managed instance group (MIG) API to create and manage TPU VMs.
You can perform standard VM configurations such as using a custom OS or
configure boot disk size. Compute Engine APIs support the creation and
management of TPU slices across all consumption options, enabling small-scale
experimentation and large-scale training and inference workloads.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/tpu/docs/tpus-in-compute-engine">TPU resources in Compute
Engine</a>.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Feature</h3>
<p>The details page for a span can display the call hierarchy of a trace using a
directed acyclic graph (DAG). One way to view a span's details is to open the
<strong>Trace Explorer</strong> page and select the span. The DAG view is also available for
some integrations. For example, if you view an Application Monitoring dashboard
and explore the trace data it displays, the flyout supports the DAG option.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/trace/docs/finding-traces#explore">Trace Explorer: Explore a trace</a></li>
<li><a href="https://docs.cloud.google.com/monitoring/docs/application-monitoring#explore-trace">Application Monitoring: Explore a trace</a></li>
</ul>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Compute Engine supports the Google's
custom-developed accelerator Tensor Processing Unit (TPU), providing a converged
experience across AI accelerators on Google Cloud. You can use the
Compute Engine instance API and managed instance group (MIG) API to
create and manage TPU VMs. You can perform standard VM configurations such as
using a custom OS or configure boot disk size. Compute Engine APIs
support the creation and management of TPU slices across all consumption
options, enabling small-scale experimentation and large-scale training and
inference workloads.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/compute/docs/tpus/tpu-resources-in-compute-engine">TPU resources in Compute Engine</a>.</p>
<h3>Feature</h3>
<p><strong>Generally available</strong>: In a managed instance group (MIG), obtain the requested
number of virtual machine (VM) instances all at once by using bulk mode of the
target size policy. Using bulk mode helps you avoid partial VM provisioning in a
MIG. Bulk mode is particularly beneficial for batch workloads, such as high
performance computing (HPC) or distributed training, that require full capacity
before they can start. For more information, see
<a href="https://docs.cloud.google.com/compute/docs/instance-groups/about-bulk-mode">About bulk mode</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-121-18867-381-148_">cos-121-18867-381-148 <a id='"cos-arm64-121-18867-381-148"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6c119c63599291cd468409254669be8082f330b9
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.148/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added dev-libs/mpdecimal and dev-python/gentoo-common.</p>
<h3>Change</h3>
<p>Updated app-containers/runc from v1.2.8 to v1.2.9</p>
<h3>Change</h3>
<p>Updated dev-lang/python to v3.11.15.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-395-55_">cos-125-19216-395-55 <a id='"cos-arm64-125-19216-395-55"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/d2ec5b118f6f5f38bb03d3079965327c76256ba1
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.55/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Allow overriding IMA policy from oem partition.</p>
<h3>Change</h3>
<p>On cchost boards, autoload IMA policy on boot.</p>
<h3>Change</h3>
<p>Set static UUID for the stateful partition.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-29_">cos-117-18613-613-29 <a id='"cos-arm64-117-18613-613-29"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/4c8dd0401cd7357d11e75a8467d834167db03513
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.29/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated Python to v3.8.20.</p>
<h3>Change</h3>
<p>Updated app-containers/runc from v1.2.8 to v1.2.9</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Change</h3>
<h3 id="cos-129-19506-224-7_">cos-129-19506-224-7 <a id='"cos-arm64-129-19506-224-7"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ee5c0e72ce4f921969d64843af4f37b1e22a9738
">COS-6.12.90</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.224.7/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h2 class="release-note-product-title">Filestore</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/filestore/docs/use-filestore-mcp">Filestore remote Model Context Protocol (MCP) server</a> is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
The Filestore remote MCP server lets you create and manage Filestore instances from LLMs, AI applications, and AI-enabled development platforms.</p>
<h2 class="release-note-product-title">Firestore</h2>
<h3>Feature</h3>
<p>Support for searching for and managing your Firestore resources
using Knowledge Catalog, which is a platform for
storing, managing, and accessing your metadata. To learn more, see
<a href="https://cloud.google.com/firestore/native/docs/knowledge-catalog">View Knowledge Catalog insights</a>.</p>
<h2 class="release-note-product-title">Firestore with MongoDB compatibility</h2>
<h3>Feature</h3>
<p>Support for searching for and managing your Firestore resources
using Knowledge Catalog, which is a platform for
storing, managing, and accessing your metadata. To learn more, see
<a href="https://docs.cloud.google.com/firestore/mongodb-compatibility/docs/knowledge-catalog">View Knowledge Catalog insights</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Agent Designer migration to Gemini 3.5 Flash</strong></p>
<p>Agent Designer agents in the US and Global regions that previously migrated
from Gemini 2.5 Flash and Gemini 2.5 Pro to
Gemini 3.1 Pro have been migrated to Gemini 3.5 Flash. This
migration is automatic and requires no action.</p>
<p>To use a different model, edit your agent's settings using either
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer/edit-agent#edit-using-chat">conversational chat</a>
or the <a href="https://docs.cloud.google.com/gemini/enterprise/docs/agent-designer/edit-agent#edit-using-flow">flow builder</a>.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Create and edit documents and slides in Canvas</strong></p>
<p>Canvas is a dedicated, interactive tool within the Gemini Enterprise
web app. It allows you to create and edit AI-generated documents and
presentations directly from your chats. You can then export these to Google
Workspace, Microsoft Office formats, and PDF.</p>
<p>A Gemini Enterprise administrator must turn on the feature so that users can
use it in the Gemini Enterprise app. For more information about feature
controls, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web
app</a>.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/assistant-canvas">Create and edit documents and slides in Canvas</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Breaking</h3>
<p><strong>Gemini 2.0 Flash and Gemini 2.0 Flash-Lite are discontinued</strong></p>
<p>Gemini 2.0 Flash and 2.0 Flash-Lite are discontinued and are no longer
available. This includes both model serving and Provisioned Throughput. Use
Gemini 3.1 Flash-Lite, Gemma 4, or more recent Gemini releases.</p>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Announcement</h3>
<p>All 3-year (36-month) post-paid <code>ve2</code> <a href="https://docs.cloud.google.com/vmware-engine/docs/cud">committed use discounts (CUDs)</a> for Google Cloud VMware Engine purchased after May 31, 2026, will terminate on October 15, 2028. 3-year CUD pricing will apply, regardless of the actual term of the CUD. Additionally, 3-year pre-paid CUDs are no longer available; only 1-year pre-paid CUDs are available.</p>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Announcement</h3>
<p>The <a href="https://docs.cloud.google.com/chronicle/docs/secops/release-notes#May_28_2026">Manage access to preview features feature</a> has been rolled back.</p>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>New SAP certification for operating system: RHEL 10.0 for SAP</strong></p>
<p>For use with SAP HANA and SAP NetWeaver on Google Cloud, SAP has certified the
operating system Red Hat Enterprise Linux (RHEL) 10.0 for SAP.</p>
<p>For more information about SAP-certified operating systems, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/sap/docs/sap-hana-os-support#quick_reference_table">Certified operating systems for SAP HANA</a></li>
<li><a href="https://docs.cloud.google.com/sap/docs/netweaver-os-support#quick_reference_table">Certified operating systems for SAP NetWeaver</a></li>
</ul>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p><strong>General Availability</strong>: <a href="https://docs.cloud.google.com/vpc/docs/about-composite-health">Composite Health for Private Service
Connect</a>, formerly known as Private Service
Connect health, lets service producers define health criteria for published
services, enabling automatic cross-region failover for consumers that access the
service by using Private Service Connect backends.</p>
<h2 class="release-note-product-title">reCAPTCHA</h2>
<h3>Change</h3>
<p>reCAPTCHA Mobile SDK v18.9.1 is available for Android. This version
fixes an issue that caused package name collisions when
building projects using Android Gradle Plugin version 9.0 or higher.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 31, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_31_2026</id>
    <updated>2026-05-31T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_31_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Change</h3>
<p>Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.</p>
<p>The following supported default parsers have been updated. Each parser is listed by product name and <code>log_type</code> value, where applicable. This list includes both released default parsers and pending parser updates.</p>
<ul>
<li>1Password Audit Events (<code>ONEPASSWORD_AUDIT_EVENTS</code>)</li>
<li>AIX system (<code>AIX_SYSTEM</code>)</li>
<li>Apache (<code>APACHE</code>)</li>
<li>Aruba EdgeConnect SD-WAN (<code>ARUBA_EDGECONNECT_SDWAN</code>)</li>
<li>Avaya Aura Experience Portal (<code>AVAYA_AURA</code>)</li>
<li>AWS CloudFront (<code>AWS_CLOUDFRONT</code>)</li>
<li>AWS Cloudtrail (<code>AWS_CLOUDTRAIL</code>)</li>
<li>AWS GuardDuty (<code>GUARDDUTY</code>)</li>
<li>AWS Security Hub (<code>AWS_SECURITY_HUB</code>)</li>
<li>Azure AD (<code>AZURE_AD</code>)</li>
<li>Azure AD Organizational Context (<code>AZURE_AD_CONTEXT</code>)</li>
<li>Azure AD Sign-In (<code>AZURE_AD_SIGNIN</code>)</li>
<li>Azure SQL (<code>AZURE_SQL</code>)</li>
<li>Azure Storage Audit (<code>AZURE_STORAGE_AUDIT</code>)</li>
<li>Barracuda WAF (<code>BARRACUDA_WAF</code>)</li>
<li>Blue Coat Proxy (<code>BLUECOAT_WEBPROXY</code>)</li>
<li>Chrome Management (<code>CHROME_MANAGEMENT</code>)</li>
<li>Cisco ACS (<code>CISCO_ACS</code>)</li>
<li>Cisco ISE (<code>CISCO_ISE</code>)</li>
<li>Cisco Secure Access (<code>CISCO_SECURE_ACCESS</code>)</li>
<li>Cisco Secure Workload (<code>CISCO_SECURE_WORKLOAD</code>)</li>
<li>Cisco Switch (<code>CISCO_SWITCH</code>)</li>
<li>Cisco Umbrella Audit (<code>CISCO_UMBRELLA_AUDIT</code>)</li>
<li>Citrix Netscaler (<code>CITRIX_NETSCALER</code>)</li>
<li>Claroty Xdome (<code>CLAROTY_XDOME</code>)</li>
<li>Claude Compliance Logs (<code>CLAUDE_COMPLIANCE_LOGS</code>)</li>
<li>Cloudflare (<code>CLOUDFLARE</code>)</li>
<li>Cloudflare Warp (<code>CLOUDFLARE_WARP</code>)</li>
<li>Corelight (<code>CORELIGHT</code>)</li>
<li>CrowdStrike Alerts API (<code>CS_ALERTS</code>)</li>
<li>CrowdStrike Falcon (<code>CS_EDR</code>)</li>
<li>CyberArk (<code>CYBERARK</code>)</li>
<li>CyberArk Privileged Access Manager (PAM) (<code>CYBERARK_PAM</code>)</li>
<li>Duo Administrator Logs (<code>DUO_ADMIN</code>)</li>
<li>EfficientIP DDI (<code>EFFICIENTIP_DDI</code>)</li>
<li>Elastic Audit Beats (<code>ELASTIC_AUDITBEAT</code>)</li>
<li>Elastic Windows Event Log Beats (<code>ELASTIC_WINLOGBEAT</code>)</li>
<li>F5 ASM (<code>F5_ASM</code>)</li>
<li>Forcepoint Proxy (<code>FORCEPOINT_WEBPROXY</code>)</li>
<li>FortiGate (<code>FORTINET_FIREWALL</code>)</li>
<li>GitHub (<code>GITHUB</code>)</li>
<li>Google Cloud Asset Inventory (<code>GCP_CLOUD_ASSET_INVENTORY</code>)</li>
<li>Google Cloud Audit (<code>GCP_CLOUDAUDIT</code>)</li>
<li>Google Compute Context (<code>GCP_COMPUTE_CONTEXT</code>)</li>
<li>Google Threat Intelligence IOC (<code>GTI_IOC</code>)</li>
<li>GTB Technologies DLP (<code>GTB_DLP</code>)</li>
<li>HP Aruba (ClearPass) (<code>CLEARPASS</code>)</li>
<li>IBM Websphere Application Server (<code>IBM_WEBSPHERE_APP_SERVER</code>)</li>
<li>IBM z/OS (<code>IBM_ZOS</code>)</li>
<li>Imperva (<code>IMPERVA_WAF</code>)</li>
<li>Imperva CEF (<code>IMPERVA_CEF</code>)</li>
<li>Imperva DRA (<code>IMPERVA_DRA</code>)</li>
<li>Imperva SecureSphere Management (<code>IMPERVA_SECURESPHERE</code>)</li>
<li>Island Browser logs (<code>ISLAND_BROWSER</code>)</li>
<li>Juniper (<code>JUNIPER_FIREWALL</code>)</li>
<li>Juniper Mist (<code>JUNIPER_MIST</code>)</li>
<li>Kubernetes Node (<code>KUBERNETES_NODE</code>)</li>
<li>LastPass Password Management (<code>LASTPASS</code>)</li>
<li>Linux Auditing System (AuditD) (<code>AUDITD</code>)</li>
<li>Microsoft Azure Activity (<code>AZURE_ACTIVITY</code>)</li>
<li>Microsoft Defender for Office 365 (<code>MICROSOFT_DEFENDER_MAIL</code>)</li>
<li>Microsoft IIS (<code>IIS</code>)</li>
<li>Mobileiron (<code>MOBILEIRON</code>)</li>
<li>Mongo Database (<code>MONGO_DB</code>)</li>
<li>MySQL (<code>MYSQL</code>)</li>
<li>Netapp Storagegrid (<code>NETAPP_STORAGEGRID</code>)</li>
<li>Netskope V2 (<code>NETSKOPE_ALERT_V2</code>)</li>
<li>Netskope Web Proxy (<code>NETSKOPE_WEBPROXY</code>)</li>
<li>NGFW Enterprise (<code>GCP_NGFW_ENTERPRISE</code>)</li>
<li>Office 365 (<code>OFFICE_365</code>)</li>
<li>Office 365 Message Trace (<code>OFFICE_365_MESSAGETRACE</code>)</li>
<li>Okta Scaleft (<code>OKTA_SCALEFT</code>)</li>
<li>Oracle (<code>ORACLE_DB</code>)</li>
<li>Oracle Cloud Infrastructure Audit Logs (<code>OCI_AUDIT</code>)</li>
<li>Orca Cloud Security Platform (<code>ORCA</code>)</li>
<li>Proofpoint On Demand (<code>PROOFPOINT_ON_DEMAND</code>)</li>
<li>Radware Web Application Firewall (<code>RADWARE_FIREWALL</code>)</li>
<li>Red Hat Directory Server LDAP (<code>REDHAT_DIRECTORY_SERVER</code>)</li>
<li>Red Hat OpenShift (<code>REDHAT_OPENSHIFT</code>)</li>
<li>Salesforce (<code>SALESFORCE</code>)</li>
<li>Sangfor Next Generation Firewall (<code>SANGFOR_NGAF</code>)</li>
<li>Security Command Center Error (<code>GCP_SECURITYCENTER_ERROR</code>)</li>
<li>Security Command Center Misconfiguration (<code>GCP_SECURITYCENTER_MISCONFIGURATION</code>)</li>
<li>Security Command Center Observation (<code>GCP_SECURITYCENTER_OBSERVATION</code>)</li>
<li>Security Command Center Posture Violation (<code>GCP_SECURITYCENTER_POSTURE_VIOLATION</code>)</li>
<li>Security Command Center Threat (<code>GCP_SECURITYCENTER_THREAT</code>)</li>
<li>Security Command Center Toxic Combination (<code>GCP_SECURITYCENTER_TOXIC_COMBINATION</code>)</li>
<li>Security Command Center Unspecified (<code>GCP_SECURITYCENTER_UNSPECIFIED</code>)</li>
<li>Security Command Center Vulnerability (<code>GCP_SECURITYCENTER_VULNERABILITY</code>)</li>
<li>SentinelOne Singularity Cloud Funnel (<code>SENTINELONE_CF</code>)</li>
<li>ServiceNow Security (<code>SERVICENOW_SECURITY</code>)</li>
<li>Sourcefire (<code>SOURCEFIRE_IDS</code>)</li>
<li>Suricata EVE (<code>SURICATA_EVE</code>)</li>
<li>Symantec Endpoint Protection (<code>SEP</code>)</li>
<li>Sysdig (<code>SYSDIG</code>)</li>
<li>Trend Micro Deep Security (<code>TRENDMICRO_DEEP_SECURITY</code>)</li>
<li>Trend Micro Vision One Observerd Attack Techniques (<code>TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES</code>)</li>
<li>Ubiquiti UniFi Switch (<code>UBIQUITI_SWITCH</code>)</li>
<li>Unix system (<code>NIX_SYSTEM</code>)</li>
<li>Upwind (<code>UPWIND</code>)</li>
<li>VMware ESXi (<code>VMWARE_ESX</code>)</li>
<li>VMWare VSphere (<code>VMWARE_VSPHERE</code>)</li>
<li>Windows DNS (<code>WINDOWS_DNS</code>)</li>
<li>Windows Event (<code>WINEVTLOG</code>)</li>
<li>Wiz.io (<code>WIZ_IO</code>)</li>
<li>Workday User Activity (<code>WORKDAY_USER_ACTIVITY</code>)</li>
<li>Workspace Activities (<code>WORKSPACE_ACTIVITY</code>)</li>
<li>Zscaler (<code>ZSCALER_WEBPROXY</code>)</li>
<li>Zscaler CASB (<code>ZSCALER_CASB</code>)</li>
<li>Zscaler DLP (<code>ZSCALER_DLP</code>)</li>
<li>Zscaler Private Access (<code>ZSCALER_ZPA</code>)</li>
</ul>
<p>The following log types were added without a default parser. Each parser is listed by product name and <code>log_type</code> value, where applicable.</p>
<ul>
<li>Azure Software Vulnerabilities (<code>AZURE_SOFTWARE_VULNERABILITIES</code>)</li>
<li>Caller Verify (<code>CALLER_VERIFY</code>)</li>
<li>CertSecure Log (<code>CERTSECURE_LOG</code>)</li>
<li>Cisco MultiCloud Defense Firewall (<code>CISCO_MULTICLOUD_DEFENSE_FIREWALL</code>)</li>
<li>Cursor (<code>CURSOR</code>)</li>
<li>Cyfirma (<code>CYFIRMA_DECYFIR_LOG</code>)</li>
<li>Databahn (<code>DATABAHN</code>)</li>
<li>Flare Darkweb Alerts (<code>FLARE_DARKWEB_ALERTS</code>)</li>
<li>Fortinet FortiAppSec Cloud (<code>FORTINET_FORTIAPPSEC</code>)</li>
<li>Hikvision Network Video Recorders (<code>HIKVISION_NVR</code>)</li>
<li>IBM B2B Integrator (<code>IBM_B2B_INTEGRATOR</code>)</li>
<li>IBM InfoSphere Virtual Data Pipeline (<code>IBM_VDP</code>)</li>
<li>Imperva Account TakeOver (<code>IMPERVA_ATO</code>)</li>
<li>Imperva Client Side Protection (<code>IMPERVA_CSP</code>)</li>
<li>Imperva DNS (<code>IMPERVA_DNS</code>)</li>
<li>Imperva Network Security (<code>IMPERVA_NETWORK_SECURITY</code>)</li>
<li>Microsoft Defender XDR (<code>MICROSOFT_DEFENDER_XDR</code>)</li>
<li>Nakivo Backup and Recovery (<code>NAKIVO_BACKUP</code>)</li>
<li>Netcraft Takedown (<code>NETCRAFT_TAKEDOWN</code>)</li>
<li>Next Level Performance Amplify (<code>NXL_AMPLIFY</code>)</li>
<li>Siemens Desigo (<code>SIEMENS_DESIGO</code>)</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Change</h3>
<p>Google SecOps has updated the list of supported default parsers. Parsers are updated gradually, so it might take one to four days before you see the changes reflected in your region.</p>
<p>The following supported default parsers have been updated. Each parser is listed by product name and <code>log_type</code> value, where applicable. This list includes both released default parsers and pending parser updates.</p>
<ul>
<li>1Password Audit Events (<code>ONEPASSWORD_AUDIT_EVENTS</code>)</li>
<li>AIX system (<code>AIX_SYSTEM</code>)</li>
<li>Apache (<code>APACHE</code>)</li>
<li>Aruba EdgeConnect SD-WAN (<code>ARUBA_EDGECONNECT_SDWAN</code>)</li>
<li>Avaya Aura Experience Portal (<code>AVAYA_AURA</code>)</li>
<li>AWS CloudFront (<code>AWS_CLOUDFRONT</code>)</li>
<li>AWS Cloudtrail (<code>AWS_CLOUDTRAIL</code>)</li>
<li>AWS GuardDuty (<code>GUARDDUTY</code>)</li>
<li>AWS Security Hub (<code>AWS_SECURITY_HUB</code>)</li>
<li>Azure AD (<code>AZURE_AD</code>)</li>
<li>Azure AD Organizational Context (<code>AZURE_AD_CONTEXT</code>)</li>
<li>Azure AD Sign-In (<code>AZURE_AD_SIGNIN</code>)</li>
<li>Azure SQL (<code>AZURE_SQL</code>)</li>
<li>Azure Storage Audit (<code>AZURE_STORAGE_AUDIT</code>)</li>
<li>Barracuda WAF (<code>BARRACUDA_WAF</code>)</li>
<li>Blue Coat Proxy (<code>BLUECOAT_WEBPROXY</code>)</li>
<li>Chrome Management (<code>CHROME_MANAGEMENT</code>)</li>
<li>Cisco ACS (<code>CISCO_ACS</code>)</li>
<li>Cisco ISE (<code>CISCO_ISE</code>)</li>
<li>Cisco Secure Access (<code>CISCO_SECURE_ACCESS</code>)</li>
<li>Cisco Secure Workload (<code>CISCO_SECURE_WORKLOAD</code>)</li>
<li>Cisco Switch (<code>CISCO_SWITCH</code>)</li>
<li>Cisco Umbrella Audit (<code>CISCO_UMBRELLA_AUDIT</code>)</li>
<li>Citrix Netscaler (<code>CITRIX_NETSCALER</code>)</li>
<li>Claroty Xdome (<code>CLAROTY_XDOME</code>)</li>
<li>Claude Compliance Logs (<code>CLAUDE_COMPLIANCE_LOGS</code>)</li>
<li>Cloudflare (<code>CLOUDFLARE</code>)</li>
<li>Cloudflare Warp (<code>CLOUDFLARE_WARP</code>)</li>
<li>Corelight (<code>CORELIGHT</code>)</li>
<li>CrowdStrike Alerts API (<code>CS_ALERTS</code>)</li>
<li>CrowdStrike Falcon (<code>CS_EDR</code>)</li>
<li>CyberArk (<code>CYBERARK</code>)</li>
<li>CyberArk Privileged Access Manager (PAM) (<code>CYBERARK_PAM</code>)</li>
<li>Duo Administrator Logs (<code>DUO_ADMIN</code>)</li>
<li>EfficientIP DDI (<code>EFFICIENTIP_DDI</code>)</li>
<li>Elastic Audit Beats (<code>ELASTIC_AUDITBEAT</code>)</li>
<li>Elastic Windows Event Log Beats (<code>ELASTIC_WINLOGBEAT</code>)</li>
<li>F5 ASM (<code>F5_ASM</code>)</li>
<li>Forcepoint Proxy (<code>FORCEPOINT_WEBPROXY</code>)</li>
<li>FortiGate (<code>FORTINET_FIREWALL</code>)</li>
<li>GitHub (<code>GITHUB</code>)</li>
<li>Google Cloud Asset Inventory (<code>GCP_CLOUD_ASSET_INVENTORY</code>)</li>
<li>Google Cloud Audit (<code>GCP_CLOUDAUDIT</code>)</li>
<li>Google Compute Context (<code>GCP_COMPUTE_CONTEXT</code>)</li>
<li>Google Threat Intelligence IOC (<code>GTI_IOC</code>)</li>
<li>GTB Technologies DLP (<code>GTB_DLP</code>)</li>
<li>HP Aruba (ClearPass) (<code>CLEARPASS</code>)</li>
<li>IBM Websphere Application Server (<code>IBM_WEBSPHERE_APP_SERVER</code>)</li>
<li>IBM z/OS (<code>IBM_ZOS</code>)</li>
<li>Imperva (<code>IMPERVA_WAF</code>)</li>
<li>Imperva CEF (<code>IMPERVA_CEF</code>)</li>
<li>Imperva DRA (<code>IMPERVA_DRA</code>)</li>
<li>Imperva SecureSphere Management (<code>IMPERVA_SECURESPHERE</code>)</li>
<li>Island Browser logs (<code>ISLAND_BROWSER</code>)</li>
<li>Juniper (<code>JUNIPER_FIREWALL</code>)</li>
<li>Juniper Mist (<code>JUNIPER_MIST</code>)</li>
<li>Kubernetes Node (<code>KUBERNETES_NODE</code>)</li>
<li>LastPass Password Management (<code>LASTPASS</code>)</li>
<li>Linux Auditing System (AuditD) (<code>AUDITD</code>)</li>
<li>Microsoft Azure Activity (<code>AZURE_ACTIVITY</code>)</li>
<li>Microsoft Defender for Office 365 (<code>MICROSOFT_DEFENDER_MAIL</code>)</li>
<li>Microsoft IIS (<code>IIS</code>)</li>
<li>Mobileiron (<code>MOBILEIRON</code>)</li>
<li>Mongo Database (<code>MONGO_DB</code>)</li>
<li>MySQL (<code>MYSQL</code>)</li>
<li>Netapp Storagegrid (<code>NETAPP_STORAGEGRID</code>)</li>
<li>Netskope V2 (<code>NETSKOPE_ALERT_V2</code>)</li>
<li>Netskope Web Proxy (<code>NETSKOPE_WEBPROXY</code>)</li>
<li>NGFW Enterprise (<code>GCP_NGFW_ENTERPRISE</code>)</li>
<li>Office 365 (<code>OFFICE_365</code>)</li>
<li>Office 365 Message Trace (<code>OFFICE_365_MESSAGETRACE</code>)</li>
<li>Okta Scaleft (<code>OKTA_SCALEFT</code>)</li>
<li>Oracle (<code>ORACLE_DB</code>)</li>
<li>Oracle Cloud Infrastructure Audit Logs (<code>OCI_AUDIT</code>)</li>
<li>Orca Cloud Security Platform (<code>ORCA</code>)</li>
<li>Proofpoint On Demand (<code>PROOFPOINT_ON_DEMAND</code>)</li>
<li>Radware Web Application Firewall (<code>RADWARE_FIREWALL</code>)</li>
<li>Red Hat Directory Server LDAP (<code>REDHAT_DIRECTORY_SERVER</code>)</li>
<li>Red Hat OpenShift (<code>REDHAT_OPENSHIFT</code>)</li>
<li>Salesforce (<code>SALESFORCE</code>)</li>
<li>Sangfor Next Generation Firewall (<code>SANGFOR_NGAF</code>)</li>
<li>Security Command Center Error (<code>GCP_SECURITYCENTER_ERROR</code>)</li>
<li>Security Command Center Misconfiguration (<code>GCP_SECURITYCENTER_MISCONFIGURATION</code>)</li>
<li>Security Command Center Observation (<code>GCP_SECURITYCENTER_OBSERVATION</code>)</li>
<li>Security Command Center Posture Violation (<code>GCP_SECURITYCENTER_POSTURE_VIOLATION</code>)</li>
<li>Security Command Center Threat (<code>GCP_SECURITYCENTER_THREAT</code>)</li>
<li>Security Command Center Toxic Combination (<code>GCP_SECURITYCENTER_TOXIC_COMBINATION</code>)</li>
<li>Security Command Center Unspecified (<code>GCP_SECURITYCENTER_UNSPECIFIED</code>)</li>
<li>Security Command Center Vulnerability (<code>GCP_SECURITYCENTER_VULNERABILITY</code>)</li>
<li>SentinelOne Singularity Cloud Funnel (<code>SENTINELONE_CF</code>)</li>
<li>ServiceNow Security (<code>SERVICENOW_SECURITY</code>)</li>
<li>Sourcefire (<code>SOURCEFIRE_IDS</code>)</li>
<li>Suricata EVE (<code>SURICATA_EVE</code>)</li>
<li>Symantec Endpoint Protection (<code>SEP</code>)</li>
<li>Sysdig (<code>SYSDIG</code>)</li>
<li>Trend Micro Deep Security (<code>TRENDMICRO_DEEP_SECURITY</code>)</li>
<li>Trend Micro Vision One Observerd Attack Techniques (<code>TRENDMICRO_VISION_ONE_OBSERVERD_ATTACK_TECHNIQUES</code>)</li>
<li>Ubiquiti UniFi Switch (<code>UBIQUITI_SWITCH</code>)</li>
<li>Unix system (<code>NIX_SYSTEM</code>)</li>
<li>Upwind (<code>UPWIND</code>)</li>
<li>VMware ESXi (<code>VMWARE_ESX</code>)</li>
<li>VMWare VSphere (<code>VMWARE_VSPHERE</code>)</li>
<li>Windows DNS (<code>WINDOWS_DNS</code>)</li>
<li>Windows Event (<code>WINEVTLOG</code>)</li>
<li>Wiz.io (<code>WIZ_IO</code>)</li>
<li>Workday User Activity (<code>WORKDAY_USER_ACTIVITY</code>)</li>
<li>Workspace Activities (<code>WORKSPACE_ACTIVITY</code>)</li>
<li>Zscaler (<code>ZSCALER_WEBPROXY</code>)</li>
<li>Zscaler CASB (<code>ZSCALER_CASB</code>)</li>
<li>Zscaler DLP (<code>ZSCALER_DLP</code>)</li>
<li>Zscaler Private Access (<code>ZSCALER_ZPA</code>)</li>
</ul>
<p>The following log types were added without a default parser. Each parser is listed by product name and <code>log_type</code> value, where applicable.</p>
<ul>
<li>Azure Software Vulnerabilities (<code>AZURE_SOFTWARE_VULNERABILITIES</code>)</li>
<li>Caller Verify (<code>CALLER_VERIFY</code>)</li>
<li>CertSecure Log (<code>CERTSECURE_LOG</code>)</li>
<li>Cisco MultiCloud Defense Firewall (<code>CISCO_MULTICLOUD_DEFENSE_FIREWALL</code>)</li>
<li>Cursor (<code>CURSOR</code>)</li>
<li>Cyfirma (<code>CYFIRMA_DECYFIR_LOG</code>)</li>
<li>Databahn (<code>DATABAHN</code>)</li>
<li>Flare Darkweb Alerts (<code>FLARE_DARKWEB_ALERTS</code>)</li>
<li>Fortinet FortiAppSec Cloud (<code>FORTINET_FORTIAPPSEC</code>)</li>
<li>Hikvision Network Video Recorders (<code>HIKVISION_NVR</code>)</li>
<li>IBM B2B Integrator (<code>IBM_B2B_INTEGRATOR</code>)</li>
<li>IBM InfoSphere Virtual Data Pipeline (<code>IBM_VDP</code>)</li>
<li>Imperva Account TakeOver (<code>IMPERVA_ATO</code>)</li>
<li>Imperva Client Side Protection (<code>IMPERVA_CSP</code>)</li>
<li>Imperva DNS (<code>IMPERVA_DNS</code>)</li>
<li>Imperva Network Security (<code>IMPERVA_NETWORK_SECURITY</code>)</li>
<li>Microsoft Defender XDR (<code>MICROSOFT_DEFENDER_XDR</code>)</li>
<li>Nakivo Backup and Recovery (<code>NAKIVO_BACKUP</code>)</li>
<li>Netcraft Takedown (<code>NETCRAFT_TAKEDOWN</code>)</li>
<li>Next Level Performance Amplify (<code>NXL_AMPLIFY</code>)</li>
<li>Siemens Desigo (<code>SIEMENS_DESIGO</code>)</li>
</ul>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p>Release 6.3.87 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 30, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_30_2026</id>
    <updated>2026-05-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_30_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1154">v1.15.4</h3>
<p>On May 30, 2026 we released an updated version of the Apigee hybrid software, v1.15.4.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/upgrade">Upgrading Apigee hybrid to version v1.15.4</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.15/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_24_2026">Release 6.3.86</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 29, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_29_2026</id>
    <updated>2026-05-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_29_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On May 29, 2026, we released an updated version of the Apigee UI.</p>
<h3>Feature</h3>
<p><b>Apigee EventFlow now supports the DataCapture policy</b></p>
<p>You can now use the DataCapture policy within an EventFlow to extract and
persist data from server-sent events (SSE) streams, such as token counts and
other fields from streaming LLM responses.
For more information, see
<a href="https://docs.cloud.google.com/apigee/docs/api-platform/develop/server-sent-events#datacapture-token-counts">Use the DataCapture policy to capture token counts</a>.</p>
<h3>Feature</h3>
<p><b>Manage Spaces in the Apigee UI</b></p>
<p>You can now create, view, update, and delete spaces, and manage their Identity and Access Management (IAM) policies directly in the Apigee UI.
Previously, these actions could only be performed using the Apigee API.
For more information, see
<a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/spaces/apigee-spaces-overview">Apigee Spaces overview</a>.</p>
<h2 class="release-note-product-title">Cloud Workstations</h2>
<h3>Announcement</h3>
<p>The <a href="https://docs.cloud.google.com/workstations/docs/preconfigured-base-images">preconfigured base images</a>
include <a href="https://antigravity.google/product/antigravity-cli">Antigravity CLI</a>.</p>
<h3>Announcement</h3>
<p>The base VM was upgraded to use <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/features-and-benefits">Container-Optimized OS</a>
<a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129">129 LTS</a>.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/workstations/docs/preconfigured-base-images#list_of_preconfigured_base_images">JetBrains RubyMine preconfigured base image</a>
uses a custom gem directory (<code>/usr/local/share/gems/ruby/3.1.0</code>).</p>
<h2 class="release-note-product-title">Gemini</h2>
<h3>Other</h3>
<h3 id="bug_fixes_in_vs_code_3">Bug fixes in VS Code</h3>
<p>Various bug fixes and minor product enhancements.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Issue</h3>
<p>In GKE version 1.35 and later, workloads that use Workload Identity to
<a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/workload-identity">authenticate to Google Cloud
APIs</a> might experience
transient connectivity timeouts or refused connections to the GKE metadata
server immediately following node startup. For recommendations and workarounds,
see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/troubleshooting/authentication#troubleshoot-timeout">Timeout errors at Pod
startup</a>.</p>
<h3>Feature</h3>
<p>GKE Gateway now supports backend authenticated TLS for Gateway-originated
connections to Pods or InferencePools for the following GatewayClasses:</p>
<ul>
<li><code>gke-l7-global-external-managed</code></li>
<li><code>gke-l7-regional-external-managed</code></li>
<li><code>gke-l7-rilb</code></li>
</ul>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>The Data Lineage API includes the <a href="dataplex/docs/reference/data-lineage/rest/v1/projects.locations/searchLineageStreaming?rep_location=global"><code>searchLineageStreaming</code></a> method that performs a breadth-first search (upstream or downstream) to retrieve lineage links for an asset identified by its Fully Qualified Name (FQN).</p>
<p>For more information, see the Data Lineage API reference for
<a href="https://docs.cloud.google.com/dataplex/docs/reference/data-lineage/rest">REST</a>.</p>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Announcement</h3>
<p><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine):
Added support for selecting specific <a href="https://docs.cloud.google.com/managed-spark/docs/concepts/configuring-clusters/confidential-compute">Confidential Computing</a> technologies (AMD SEV, AMD SEV-SNP, Intel TDX) when creating clusters using the new <code>--confidential-compute-type</code> flag in <code>gcloud</code> and the <code>confidentialInstanceType</code> field in the API. The boolean <code>--enable-confidential-compute</code> flag is now deprecated but will continue to function, defaulting to AMD SEV for backward compatibility.</p>
<ul>
<li>Introduced <code>confidentialInstanceType</code> enum in the <a href="https://docs.cloud.google.com/managed-spark/docs/reference/rest/v1/ClusterConfig#confidentialinstanceconfig">API</a>.</li>
<li>The <code>--enable-confidential-compute</code> flag and <code>enableConfidentialCompute</code> field are deprecated in favor of the new type-specific flag/field.</li>
<li>Clusters created with the deprecated boolean flag will default to <code>SEV</code>.</li>
<li>Added validation for machine type compatibility for <code>SEV</code>, <code>SEV-SNP</code>, and <code>TDX</code>.</li>
<li>Updated live migration logic to support compatible machine types and CPU platforms for each technology, including N2D and C3D for SEV.</li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 28, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_28_2026</id>
    <updated>2026-05-28T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_28_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Backup and DR</h2>
<h3>Feature</h3>
<p>You can now view the Google Cloud Backup and DR Service protection summary at
the organization and folder levels. To learn more about protection summary, see
<a href="https://docs.cloud.google.com/backup-disaster-recovery/docs/backup-admin/protection-summary">Find unprotected resources using protection summary</a>.</p>
<h2 class="release-note-product-title">Bigtable</h2>
<h3>Feature</h3>
<p>As part of Bigtable Enterprise Plus <a href="https://docs.cloud.google.com/bigtable/docs/editions-overview">edition</a>,
you can configure a retention period of up to 365 days for backups. This feature
is <a href="https://cloud.google.com/products#product-launch-stages">generally available (GA)</a>.
For more information, see <a href="https://docs.cloud.google.com/bigtable/docs/backups">Bigtable backups overview</a>.</p>
<h2 class="release-note-product-title">Cloud Logging</h2>
<h3>Announcement</h3>
<p>You can view the available regional endpoints for the
Cloud Logging API on the REST reference pages. For an example, see
<a href="https://docs.cloud.google.com/logging/docs/reference/v2/rest/v2/projects.locations.buckets/list?rep_location=global">Method: projects.locations.buckets.list</a>.</p>
<h2 class="release-note-product-title">Cloud Storage</h2>
<h3>Breaking</h3>
<p>As of August 26, 2026, in buckets with hierarchical namespace enabled,
the <a href="https://docs.cloud.google.com/storage/docs/lifecycle">Object Lifecycle Management</a> <code>Delete</code> action will
delete empty folders when the empty folder meets all of the conditions in the
lifecycle rule.</p>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Announcement</h3>
<p>You can view the available regional endpoints for the
Observability API and for the Telemetry API on their REST reference pages.
For more information, see
<a href="https://docs.cloud.google.com/stackdriver/docs/reference/api-overview">API overview</a>.</p>
<h2 class="release-note-product-title">Error Reporting</h2>
<h3>Announcement</h3>
<p>You can view the available regional endpoints for the
Error Reporting API on the REST reference pages. For an example, see
<a href="https://docs.cloud.google.com/error-reporting/reference/rest/v1beta1/projects.events/list?rep_location=global">Method: projects.events.list</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Release of Core Assistant (General Availability) and new Trace and Metrics information for Core Assistant (Preview)</strong></p>
<p>This release includes Core Assistant, a Google-provided ("Made by Google") root
agent that handles interactions when users talk to the Gemini Enterprise app
without specifying any other agent.</p>
<p>Core Assistant is
<a href="https://cloud.google.com/products#product-launch-stages">Generally Available</a>.</p>
<p>Core Assistant includes new observability and monitoring functionality:</p>
<ul>
<li><strong>Traces</strong>: A chronological summary and visualization of trace spans showing execution flow, duration, inputs, outputs, and precise details if OpenTelemetry trace and logging instrumentation is enabled.</li>
<li><strong>Metrics</strong>: A default-on dashboard displaying session counts, latency, agent invocations, tool call counts, and error rates without any extra billing costs.</li>
</ul>
<p>The Trace and Metrics tabs are in
<a href="https://cloud.google.com/products#product-launch-stages">Public Preview</a>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/core-assistant">Observe and trace agent behavior with Core Assistant</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Agent Platform Gemini 3.1 Flash Image and Gemini 3 Pro Image</strong></p>
<p>Gemini Enterprise Agent Platform Gemini 3.1 Flash Image and Gemini 3 Pro Image
are <a href="https://cloud.google.com/products#product-launch-stages">Generally
Available</a>.</p>
<p>With this release, Gemini 3.1 Flash Image and Gemini 3 Pro Image support 4K
image outputs in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<p>Also supported in this release, Gemini 3.1 Flash Image supports video inputs in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. You can use
video inputs to generate thumbnails or representative images of videos.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-1-flash-image">Gemini 3.1 Flash Image (Nano Banana
2)</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-pro-image">Gemini 3 Pro Image (Nano Banana
Pro)</a></li>
</ul>
<h3>Deprecated</h3>
<p><strong>Agent Platform Gemini 3.1 Flash Image Preview and Gemini 3 Pro Image Preview deprecation</strong></p>
<p>Gemini Enterprise Agent Platform Gemini 3.1 Flash Image Preview and Gemini 3 Pro
Image Preview are deprecated. We recommend that you update your model endpoints
before July 17, 2026, to avoid service disruption.</p>
<p>The following are the discontinued endpoints and recommended endpoint migration:</p>
<table>
<thead>
<tr>
<th>Discontinued endpoints</th>
<th>Recommended endpoint migration</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>gemini-3.1-flash-image-preview</code></td>
<td><code>gemini-3.1-flash-image</code></td>
</tr>
<tr>
<td><code>gemini-3-pro-image-preview</code></td>
<td><code>gemini-3-pro-image</code></td>
</tr>
</tbody>
</table>
<h3>Feature</h3>
<p><strong>Anthropic's Claude Opus 4.8</strong></p>
<p><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/partner-models/claude/opus-4-8">Claude Opus 4.8</a>
is available in Model Garden.</p>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>C4A bare metal instances are generally available with GKE clusters. For more
information, see the <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/arm-on-gke">Arm workloads on
GKE</a>
document, including the "Requirements and limitations" section for specific
version requirements.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/confidential-gke-nodes#confidential-gke-nodes">Confidential GKE
Nodes</a>
now support cluster level enablement of <a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/confidential-vm-overview#amd_sev-snp">AMD
SEV-SNP</a>
and <a href="https://docs.cloud.google.com/confidential-computing/confidential-vm/docs/confidential-vm-overview#intel_tdx">Intel
TDX</a>
on GKE Autopilot.</p>
<h3>Feature</h3>
<p>In GKE versions 1.36.0-gke.2459000 and later, you can directly configure Cloud
Logging for L4 load balancer backend services by using the L4LBConfig
CustomResourceDefinition (CRD).</p>
<p>This feature is available for the following load balancer types:</p>
<ul>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/internal-load-balancing#enable-logging">Internal L4 load
balancers</a>
with subsetting enabled.</li>
<li><a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/backend-service-based-external-load-balancer#enable-logging">External L4 load
balancers</a>
with regional backend services (RBS) enabled.</li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Unified and Upgraded Chronicle API</strong></p>
<p><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> has been unified with API resources from <a href="https://docs.cloud.google.com/chronicle/docs/soar/reference/working-with-chronicle-soar-apis">legacy SOAR API</a>. Further, we've upgraded the following Chronicle API resources from v1 beta to v1. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for a more robust, secure, and extensible experience. Learn more about <a href="https://google.aip.dev/181">API Stability</a>.</p>
<p>The following features and resources are included in this update:</p>
<table>
<tr>
<td style="background-color: null"><strong>Feature</strong>
</td>
<td style="background-color: null"><strong>Chronicle API Resources upgraded to v1</strong>
</td>
</tr>
<tr>
<td style="background-color: null">Alerts and ATIs, UEBA
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.threatCollections">Threat Collection</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.iocs">IoC</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.coverageDetails">CoverageDetail</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/getRiskConfig">EntityRisk</a>
</td>
</tr>
<tr>
<td style="background-color: null">Dashboards
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.nativeDashboards">NativeDashboard</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dashboardCharts">DashboardChart</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dashboardQueries">DashboardQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.featuredContentNativeDashboards">FeaturedContentNativeDashboard</a>
</td>
</tr>
<tr>
<td style="background-color: null">Data Tables
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTables">DataTable</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTables.dataTableRows">DataTableRow</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTableOperationErrors">DataTableOperationError</a>
</td>
</tr>
<tr>
<td style="background-color: null">Ingestion
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes.logs">Logs</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feeds">Feed</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedSourceTypeSchemas.logTypeSchemas">LogTypeSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedSourceTypeSchemas">FeedSourceSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedPacks">FeedPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.forwarders">Forwarder</a>
</td>
</tr>
<tr>
<td style="background-color: null">Normalization
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes">Logtype</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes.parsers">Parser</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ingestionLogLabels">IngestionLogLabel</a>
</td>
</tr>
<tr>
<td style="background-color: null">Detections
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.findingsRefinements">FindingsRefinement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/verifyRuleText">VerifyRuleText</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.featuredContentRules">FeaturedContentRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ruleExecutionErrors">RuleExecutionError</a>
</td>
</tr>
<tr>
<td style="background-color: null">Search &amp; Investigation
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.events">Event</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.entities">Entity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.users.searchQueries">SearchQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.savedColumnSets">SavedColumnSet</a>
</td>
</tr>
<tr>
<td style="background-color: null">Exports
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.bigQueryExport">BigQueryExportService</a>
</td>
</tr>
<tr>
<td style="background-color: null">Enrichment Controls
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.enrichmentControls">EnrichmentControl</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/getEnrichmentCombination">EnrichmentCombination</a>
</td>
</tr>
<tr>
<td style="background-color: null">SOAR
   </td>
<td style="background-color: null"><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases">Case</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts">CaseAlert</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseStageDefinitions">CaseStageDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseTagDefinitions">CaseTagDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseQueueFilters">CaseQueueFilter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseCloseDefinitions">CaseCloseDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts.contextProperties">ContextProperty</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts.involvedEntities">InvolvedEntity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.tasks">Task</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseComments">CaseComment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseWallRecords">CaseWallRecord</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.chatMessages">ChatMessage</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.views">View</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ontologyRecords.visualFamilies">VisualFamily</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.chatMessages.attachments">ChatMessages.attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.contentPacks">ContentPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.socRoles">SocRole</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.emailTemplates">EmailTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dynamicParameters">DynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.entitiesBlocklists">EntitiesBlocklist</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.environments">Environment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.environmentGroups">EnvironmentGroup</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations">Integration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.actions">Integrationaction</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.userNotifications">UserNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.actions.revisions">Integrationactionrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors">Connector</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.connectorInstances">ConnectorInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.remoteAgents">RemoteAgent</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.connectorInstances.logs">Connectorlog</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.revisions">Connectorrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.integrationInstances">IntegrationInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.uniqueEntities">UniqueEntity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs">Integrationsjob</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.jobInstances">JobInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.jobInstances.logs">JobInstances.log</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.revisions">Jobs.revision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.managers">Integrationmanager</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.managers.revisions">Integrationmanagerrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.alertGroupingRules">AlertGroupingRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.announcements">Announcement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.attachments">Attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.customLists">CustomList</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.formDynamicParameters">FormDynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.marketplaceIntegrations">MarketplaceIntegration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.moduleSettings">ModuleSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.slaDefinitions">SlaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers/getNotificationSettings">NotificationSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.propertySchemaDefinitions">PropertySchemaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.requestTemplates">RequestTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.soarDomains">SoarDomain</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.soarNetworks">SoarNetwork</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskLinks">WorkdeskLink</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.systemNotifications">SystemNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskContacts">WorkdeskContact</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskNotes">WorkdeskNote</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers/getLocalization">LegacySoarUsers.localization</a>.
   </td>
</tr>
</table>
<p>For a full list of updated resources and links to the documentation, please see the <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API documentation</a>.</p>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Manage access to preview features</strong></p>
<p>Google Sec0ps tenant administrators can enable or disable access to public preview features. Previously, all public preview features needed to be enabled through official Support channels.</p>
<p>The new <strong>Public Preview Features</strong> page lists all the public preview features, the status of each feature (on or off)—along with (when available) the expected GA date and a link to a relevant user guide.</p>
<aside class="note"><strong>Note:</strong><span> In <a href="https://docs.cloud.google.com/chronicle/docs/onboard#set-up-assured-workloads-folder">compliance-controlled tenants</a> (for example, FedRAMP or HIPAA), using the <strong>Public Preview Features</strong> page to turn features on and off isn't available. In these tenants, you must contact Google Sec0ps support to get public preview features enabled.</span></aside>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/secops/preview-features-manage">Manage access to preview features</a>.</p>
<aside class="note"><strong>Note:</strong><span> It might take one to six days before you see the changes reflected in your region.</span></aside>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>Upgraded Chronicle API</strong></p>
<p>We've upgraded the following <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> resources from v1 beta to v1. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for all new integrations, for a more robust, secure, and extensible experience. Learn more about <a href="https://google.aip.dev/181">API Stability</a>.</p>
<p>The following features and resources are included in this update:</p>
<ul>
<li><strong>Alerts and ATIs, UEBA:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.threatCollections">Threat Collection</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.iocs">IoC</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.coverageDetails">CoverageDetail</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/getRiskConfig">EntityRisk</a></li>
<li><strong>Dashboards:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.nativeDashboards">NativeDashboard</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dashboardCharts">DashboardChart</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dashboardQueries">DashboardQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.featuredContentNativeDashboards">FeaturedContentNativeDashboard</a></li>
<li><strong>Data Tables:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTables">DataTable</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTables.dataTableRows">DataTableRow</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dataTableOperationErrors">DataTableOperationError</a></li>
<li><strong>Ingestion:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes.logs">Logs</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feeds">Feed</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedSourceTypeSchemas.logTypeSchemas">LogTypeSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedSourceTypeSchemas">FeedSourceSchema</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.feedPacks">FeedPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.forwarders">Forwarder</a></li>
<li><strong>Normalization:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes">Logtype</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.logTypes.parsers">Parser</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ingestionLogLabels">IngestionLogLabel</a></li>
<li><strong>Detections:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.findingsRefinements">FindingsRefinement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/verifyRuleText">VerifyRuleText</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.featuredContentRules">FeaturedContentRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ruleExecutionErrors">RuleExecutionError</a></li>
<li><strong>Search &amp; Investigation:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.events">Event</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.entities">Entity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.users.searchQueries">SearchQuery</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.savedColumnSets">SavedColumnSet</a></li>
<li><strong>Exports:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.bigQueryExport">BigQueryExportService</a></li>
<li><strong>Enrichment Controls:</strong> <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.enrichmentControls">EnrichmentControl</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances/getEnrichmentCombination">EnrichmentCombination</a></li>
</ul>
<p>For a full list of updated resources and links to the documentation, please see the <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API documentation</a>.</p>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Feature</h3>
<p><strong>Unified and Upgraded Chronicle API</strong></p>
<p><a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API</a> has been unified with API resources from <a href="https://docs.cloud.google.com/chronicle/docs/soar/reference/working-with-chronicle-soar-apis">legacy SOAR API</a>. This unification provides a more robust, secure, and extensible experience. This upgrade signals API stability and functional completeness, enabling customer and partner adoption for production usage. We recommend that customers and partners use Chronicle API for a more robust, secure, and extensible experience. Learn more about <a href="https://google.aip.dev/181">API Stability</a>.</p>
<p>This update includes the following resources: <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases">Case</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts">CaseAlert</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseStageDefinitions">CaseStageDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseTagDefinitions">CaseTagDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseQueueFilters">CaseQueueFilter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.caseCloseDefinitions">CaseCloseDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts.contextProperties">ContextProperty</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseAlerts.involvedEntities">InvolvedEntity</a>,  <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.tasks">Task</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseComments">CaseComment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.caseWallRecords">CaseWallRecord</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.chatMessages">ChatMessage</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.views">View</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.ontologyRecords.visualFamilies">VisualFamily</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.cases.chatMessages.attachments">ChatMessages.attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.contentHub.contentPacks">ContentPack</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.socRoles">SocRole</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.emailTemplates">EmailTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.dynamicParameters">DynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.entitiesBlocklists">EntitiesBlocklist</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.environments">Environment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.environmentGroups">EnvironmentGroup</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations">Integration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.actions">Integrationaction</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.userNotifications">UserNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.actions.revisions">Integrationactionrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors">Connector</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.connectorInstances">ConnectorInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.remoteAgents">RemoteAgent</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.connectorInstances.logs">Connectorlog</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.connectors.revisions">Connectorrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.integrationInstances">IntegrationInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.uniqueEntities">UniqueEntity</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs">Integrationsjob</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.jobInstances">JobInstance</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.jobInstances.logs">JobInstances.log</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.jobs.revisions">Jobs.revision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.managers">Integrationmanager</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.integrations.managers.revisions">Integrationmanagerrevision</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.alertGroupingRules">AlertGroupingRule</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.announcements">Announcement</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.attachments">Attachment</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.customLists">CustomList</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.formDynamicParameters">FormDynamicParameter</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.marketplaceIntegrations">MarketplaceIntegration</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.moduleSettings">ModuleSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.slaDefinitions">SlaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers/getNotificationSettings">NotificationSetting</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.propertySchemaDefinitions">PropertySchemaDefinition</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.requestTemplates">RequestTemplate</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.soarDomains">SoarDomain</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.soarNetworks">SoarNetwork</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskLinks">WorkdeskLink</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.systemNotifications">SystemNotification</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskContacts">WorkdeskContact</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers.workdeskNotes">WorkdeskNote</a>, <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest/v1/projects.locations.instances.legacySoarUsers/getLocalization">LegacySoarUsers.localization</a>.</p>
<p>For a full list of updated resources and links to the documentation, please see the <a href="https://docs.cloud.google.com/chronicle/docs/reference/rest">Chronicle API documentation</a>.</p>
<h2 class="release-note-product-title">Secure Source Manager</h2>
<h3>Breaking</h3>
<p>To enhance security and address potential vulnerabilities (such as GHSA-3m6q-h5gj-7mrw), the Secure Source Manager Git-over-SSH server configuration has removed support for several legacy and insecure SSH algorithms.</p>
<p>SSH clients must support one or more of the following modern algorithms to connect:</p>
<ul>
<li><strong>Key Exchange Algorithms:</strong> <code>curve25519-sha256</code>, <code>diffie-hellman-group14-sha256</code></li>
<li><strong>Ciphers:</strong> <code>chacha20-poly1305@openssh.com</code>, <code>aes128-ctr</code>, <code>aes192-ctr,aes256-ctr</code>, <code>aes128-gcm@openssh.com</code>, <code>aes256-gcm@openssh.com</code></li>
<li><strong>MACs:</strong> <code>hmac-sha2-256-etm@openssh.com</code>, <code>hmac-sha2-256</code></li>
</ul>
<p>Users with old or non-standard SSH clients lacking support for these algorithms will be unable to connect using SSH for Git operations. Ensure your SSH client is up-to-date.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/attack-exposure-supported-features">Risk Engine</a> detects
toxic combinations that are related to Managed Service for Apache Spark (formerly known as Dataproc), including Lightning Engine.</p>
<h3>Feature</h3>
<p>Risk reports are updated to include more content in the <strong>Risk Engine introduction</strong>
and the <strong>System attack exposure</strong> pages. For more information about what's
included in risk reports, see <a href="https://docs.cloud.google.com/security-command-center/docs/risk-reports-overview">Risk reports overview</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 27, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_27_2026</id>
    <updated>2026-05-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_27_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">App Engine standard environment Go</h2>
<h3>Feature</h3>
<p>Enable only needed legacy bundled services using the <a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=go#app_engine_bundled_services"><code>app_engine_bundled_services</code></a> field for improved security and maintainability of your applications (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment Java</h2>
<h3>Feature</h3>
<p>Enable only needed legacy bundled services using the <a href="https://docs.cloud.google.com/appengine/docs/standard/java-gen2/config/appref-xml#app_engine_apis"><code>app_engine_bundled_services</code></a> field for improved security and maintainability of your applications (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment PHP</h2>
<h3>Feature</h3>
<p>Enable only needed legacy bundled services using the <a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=php#app_engine_bundled_services"><code>app_engine_bundled_services</code></a> field for improved security and maintainability of your applications (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment Python</h2>
<h3>Feature</h3>
<p>Enable only needed legacy bundled services using the <a href="https://docs.cloud.google.com/appengine/docs/standard/reference/app-yaml?tab=python#app_engine_bundled_services"><code>app_engine_bundled_services</code></a> field for improved security and maintainability of your applications (<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Change</h3>
<p>An updated version of the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/odbc-jdbc-drivers#current_odbc_driver">Simba ODBC driver for BigQuery</a>
is now available.</p>
<h2 class="release-note-product-title">Compute Engine</h2>
<h3>Feature</h3>
<p><strong>Generally available</strong>: Two C4A bare metal machine types are generally
available:</p>
<ul>
<li><code>c4a-standard-96-metal</code> with 96 vCPUs and 384 GB of DDR5
memory</li>
<li><code>c4a-highmem-96-metal</code> with 96 vCPUs and 768 GB DDR5
memory</li>
</ul>
<p>These two machine types support Hyperdisk Balanced, Hyperdisk Extreme, Hyperdisk Throughput, and Hyperdisk ML
volume storage and up to 100 Gbps of network bandwidth.</p>
<p>To learn more about the C4A machine family, read
<a href="https://docs.cloud.google.com/compute/docs/general-purpose-machines#n4a_series">General-purpose machines</a>.
To see where you can create C4A bare metal instances, read
<a href="https://docs.cloud.google.com/compute/docs/instances/bare-metal-instances">Bare metal instances</a>.</p>
<h2 class="release-note-product-title">Document AI</h2>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/document-ai/docs/layout-parse-chunk">Layout parser</a> image and
table annotations is in <a href="https://cloud.google.com/products/#product-launch-stages">General Availability (GA)</a>.</p>
<p>Layout parser can identify if there are images or tables in parsed documents.
When found, images and tables are annotated as a descriptive block of text with
the information depicted in the image and table.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Slack data store</strong></p>
<p>The Slack data store is generally available (GA) in Gemini Enterprise.</p>
<p>You can connect a Slack Workspace to search and read conversations,
files, and messages using natural language. You can also perform actions,
such as sending and scheduling messages, directly from the
Gemini Enterprise app chat box.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/slack">Connect Slack</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>User ID logging now included with agent logs when you opt in to "Enable logging of prompt inputs and response outputs"</strong></p>
<p>Prompt input and response output logging now includes the
<code>user.id</code> field. This addition allows better tracking of
anomalous tool interactions.</p>
<aside class="special"><strong>Important:</strong><span> Logging of <code>user.id</code> is included when opting in to "Enable logging of
prompt inputs and response outputs" effective May 22, 2026 and later and with
the Agent Development Kit (ADK) version 2.1 and later. If you opted in prior to
this change, your logs do not include <code>user.id</code>. You will need to redeploy your
agents and opt-in again for this setting to take effect.</span></aside>
<p>For details on configuration, see
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/runtime/tracing#write-traces">Write traces for an agent</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Advanced reporting dashboards 4.22</strong></p>
<p>We've released version 4.22 of the advanced reporting dashboards.</p>
<h3>Feature</h3>
<p><strong>Added a Location filter to dashboards</strong></p>
<p>The following dashboards now include a <strong>Location</strong> filter:</p>
<ul>
<li><p><a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-real-time-channel-perf">Real-time Channel
Performance</a></p></li>
<li><p><a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-transfers">Transfers</a></p></li>
<li><p><a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-interval">Queue
Interval</a></p></li>
</ul>
<h3>Feature</h3>
<p><strong>Queue Performance dashboard improvements</strong></p>
<p>We've made the following improvements to the <strong>Queue Performance - Calls</strong> and
<strong>Queue Performance - Chats</strong> dashboards:</p>
<ul>
<li><p>Added the dashboards to the Advanced Reporting Landing Page.</p></li>
<li><p>Added a <strong>Support Phone Number</strong> filter.</p></li>
<li><p>Renamed the <strong>Total Inbound Handled</strong> tile (calls only) to <strong>Total Queue
Answered</strong>.</p></li>
<li><p>Added a <strong>Total Failed</strong> tile.</p></li>
<li><p>In the <strong>Queue Summary</strong> table, removed the <strong>Total Inbound Calls Handled</strong>
column and added the following columns: <strong>Total Queue Interactions</strong>,
<strong>Total Queue Entries</strong>, <strong>Total Queue Answered</strong>, <strong>Total Failed</strong>, and
<strong>Total Transfers</strong>.</p></li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-performance">Queue Performance
dashboards</a>.</p>
<h3>Feature</h3>
<p><strong>General dashboard updates</strong></p>
<ul>
<li><p>In the <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-perf-overview">Performance
Overview</a>
dashboard, we renamed the following tiles:</p>
<ul>
<li><p><strong>Queued Now</strong> to <strong>Current Queued Now</strong></p></li>
<li><p><strong>Max Queue Time</strong> to <strong>Current Max Queue Time</strong></p></li>
</ul></li>
<li><p>The <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-calls-connected">Real-time Connected -
Calls</a> and
<a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-chats-connected">Real-time Connected -
Chats</a>
dashboards now include the following tiles:</p>
<ul>
<li><p><strong>Total Connected Calls</strong> (calls only)</p></li>
<li><p><strong>Total Connected Chats</strong> (chats only)</p></li>
<li><p><strong>Avg Current Sentiment Score</strong></p></li>
</ul></li>
<li><p>In the <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/dashboards-queue-group-perf">Queue Group Performance -
All</a>
dashboard, we renamed the <strong>Lang</strong> filter to <strong>Language</strong>.</p></li>
</ul>
<h3>Fixed</h3>
<p>The following issues were addressed in this release:</p>
<ul>
<li><p>Fixed an issue where the CSAT scores in the <strong>Performance Overview</strong> and
<strong>CSAT</strong> dashboards didn't match.</p></li>
<li><p>Fixed an issue where the <strong>Queue Performance</strong> dashboard incorrectly totaled
queue interactions, resulting in lower counts than expected.</p></li>
<li><p>Fixed an issue in the <strong>All Interactions - Chat</strong> dashboard where the
<strong>Virtual Agents Chats</strong> table displayed the wrong chat.</p></li>
<li><p>Fixed an issue in the <strong>All Interactions - Chat</strong> dashboard where the
<strong>Failed Interaction</strong> column of the <strong>Chat Metric Detail</strong> table displayed
<code>False</code> for a failed interaction.</p></li>
<li><p>Fixed an issue in the <strong>All Interactions - Chat</strong> dashboard where the
<strong>Failed Interaction</strong> column of the <strong>Chat Metric Detail</strong> table displayed
<code>False</code> for a failed interaction.</p></li>
<li><p>Fixed an issue where the <strong>Chat ID</strong> filter on the <strong>Queue Performance -
Chats</strong> dashboard incorrectly displayed placeholder values.</p></li>
<li><p>Fixed an issue where scheduled exports of large queries were limited to 500
rows, causing reporting delays.</p></li>
<li><p>Fixed an issue in the <strong>Historical Data</strong> table of the <strong>Agent Activity</strong>
dashboard where the <strong>Start Time</strong> and <strong>End Time</strong> columns indicated
incorrect durations for agents belonging to multiple teams.</p></li>
<li><p>Fixed an issue where short abandoned calls and chats were incorrectly
included in the <strong>Abandons</strong> dashboard, causing inaccurate reporting of
queue abandon times.</p></li>
<li><p>Fixed an issue where dashboard windows didn't fully display their contents.</p></li>
</ul>
<h2 class="release-note-product-title">Google Cloud Marketplace Partners</h2>
<h3>Change</h3>
<p>We've reduced the processing and delivery delay for Google Cloud Marketplace
partner reports from 2 days (D+2) to 1 day (D+1), accelerating by one day the
delivery of the
<a href="https://docs.cloud.google.com/marketplace/docs/partners/reports/report-customer-insight">Customer Insights reports</a>
to Cloud Marketplace partners.</p>
<p>For information about processing times, see
<a href="https://docs.cloud.google.com/marketplace/docs/partners/reports/report-customer-insight#report_frequency">Customer Insights report frequency</a></p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for VMware 1.34.500-gke.108 is now available
for download. To upgrade, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading.md">Upgrade clusters</a>.
Google Distributed Cloud 1.34.500-gke.108 runs on Kubernetes v1.34.7-gke.200.</p>
<p>If you are using a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for use with GKE On-Prem API clients: the Google Cloud console, the
gcloud CLI, and Terraform.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.500-gke.108:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where, when setting <code>stackdriver.disableVsphereResourceMetrics</code> to true in the cluster configuration file, user cluster installations or upgrades stalled indefinitely because the installer erroneously deleted the vsphere-ca-certificate ConfigMap, causing vsphere-csi-controller pods to fail with mount errors. You no longer need to manually recreate the ConfigMap or scale down the vsphere-metrics-exporter deployment as a workaround. </li>
<li>Fixed an issue where, when recreating a user cluster with a previously used name (which commonly occurs during Terraform deployments or manual reinstalls), cluster provisioning stalled indefinitely in the provisioning state due to a missing k8s-health-check service account. The installer ensures that the service account is created, eliminating the need to manually create the service account as a workaround. </li>
<li>Fixed an issue where the <code>gkectl diagnose</code> command failed to run on standard user clusters managed by an advanced admin cluster.</li></ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.34.500-gke.108 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.34.500-gke.108 runs on Kubernetes v1.34.7-gke.200.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.34.500-gke.108:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li>
<li>Fixed an issue where, if a new control plane node failed to join a cluster
during bootstrapping or scaling (associated with installer Ansible runner job
failures), orphaned etcd memberships were not cleaned up, causing the existing
control plane's API server to restart repeatedly (flap) and blocking subsequent
retry attempts.
</li>
<li>Fixed an issue where, during control plane certificate rotation or etcd
encryption updates, the installer stalled for three minutes per control plane node
while waiting for the local API server to restart, causing nodes to temporarily
report an Unknown status and triggering transient routing disruptions (such as
503 Service Unavailable or ImagePullBackOff errors) for workloads scheduled on
those nodes.
</li>
<li>Fixed an issue where, when enabling or updating etcd encryption, the API
server was terminated abruptly, causing transient connection timeouts or
failures for in-cluster workloads for up to five minutes.
</li>
<li>Fixed an issue where, when recreating a user cluster with a previously used
name (which commonly occurs during Terraform deployments or manual
reinstalls), cluster provisioning stalled indefinitely in the provisioning
state due to a missing k8s-health-check service account. The installer
ensures that the service account is created, eliminating the need to manually
create the service account as a workaround.</li></ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.11-gke.1074000</li>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1055000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.1993000</li>
<li>1.35.3-gke.2190000</li>
<li>1.36.0-gke.1575000</li>
<li>1.36.0-gke.1759000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2253000</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.10-gke.1115000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1154000</li>
<li>1.34.6-gke.1237000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2415000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2530000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1816000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1823000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1942000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1258000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1318000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1551000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.10-gke.1115000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1237000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1737000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r21-security-updates">(2026-R21) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.30.14-gke.2558000</td>
<td>cos-117-18613-613-5</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-5_">cos-117-18613-613-5 release notes</a></td>
</tr>
<tr>
<td>1.31.14-gke.1967000</td>
<td>cos-117-18613-613-7</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m117#cos-117-18613-613-7_">cos-117-18613-613-7 release notes</a></td>
</tr>
<tr>
<td>1.33.12-gke.1059000</td>
<td>cos-121-18867-381-125</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m121#cos-121-18867-381-125_">cos-121-18867-381-125 release notes</a></td>
</tr>
<tr>
<td>1.35.5-gke.1057000</td>
<td>cos-125-19216-395-7</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m125#cos-125-19216-395-7_">cos-125-19216-395-7 release notes</a></td>
</tr>
<tr>
<td>1.36.0-gke.2459000</td>
<td>cos-129-19506-120-64</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-129-19506-120-64_">cos-129-19506-120-64 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a> is now the default version for cluster creation in the Stable channel.</li>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
</ul></li>
<li>The following versions are no longer available in the Stable channel:
<ul>
<li>1.33.10-gke.1115000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1154000</li>
<li>1.34.6-gke.1237000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Stable channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation in the Regular channel.</li>
<li>The following versions are now available in the Regular channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available in the Regular channel:
<ul>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a> is now the default version for cluster creation in the Rapid channel.</li>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2459000</a></li>
</ul></li>
<li>The following versions are no longer available in the Rapid channel:
<ul>
<li>1.33.11-gke.1074000</li>
<li>1.33.11-gke.1197000</li>
<li>1.34.7-gke.1055000</li>
<li>1.34.7-gke.1499000</li>
<li>1.35.3-gke.1993000</li>
<li>1.35.3-gke.2190000</li>
<li>1.36.0-gke.1575000</li>
<li>1.36.0-gke.1759000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li>1.36 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2253000</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation.</li>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1059000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1126000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1057000</a></li>
</ul></li>
<li>The following versions are no longer available:
<ul>
<li>1.33.10-gke.1115000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.10-gke.1176000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1068000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.34.6-gke.1237000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1234002 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.35.3-gke.1737000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a>. This version will be removed in 90 days, or at the end of support, if sooner.</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r21-version-updates">(2026-R21) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now the default version for cluster creation in the Extended channel.</li>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2558000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1967000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1592000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1197000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1499000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.2190000</a></li>
</ul></li>
<li>The following versions are no longer available in the Extended channel:
<ul>
<li>1.30.14-gke.2407000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2415000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.30.14-gke.2530000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1816000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1823000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.31.14-gke.1942000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1258000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1318000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.32.13-gke.1551000 is <a href="https://docs.cloud.google.com/kubernetes-engine/versioning#patch-version-support">deprecated</a> in the Extended channel. This version will be removed in 90 days, or at the end of support, if sooner.</li>
<li>1.33.11-gke.1013000</li>
<li>1.34.6-gke.1307000</li>
<li>1.35.3-gke.1389000</li>
</ul></li>
<li>Clusters in this channel running the listed minor version have new general auto-upgrade targets. GKE can upgrade control planes and nodes to the following new versions with this release:
<ul>
<li>GKE upgrades clusters to the following new minor versions if there are no factors, such as <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or deprecated APIs, preventing upgrades:
<ul>
<li>1.29 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
</ul></li>
<li>GKE upgrades clusters to the following new patch versions if no minor version upgrade is available, or if the cluster has <a href="https://cloud.google.com/kubernetes-engine/docs/concepts/maintenance-windows-and-exclusions#exclusions">maintenance exclusions</a> or other factors preventing minor version upgrades:
<ul>
<li>1.30 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2441000</a></li>
<li>1.31 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1850000</a></li>
<li>1.32 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1449000</a></li>
<li>1.33 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1074000</a></li>
<li>1.34 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1347">1.34.7-gke.1055000</a></li>
<li>1.35 to <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>Standard parser support policy</strong></p>
<p>Google SecOps introduced a focused support policy for Standard parsers to scale platform stability, predictable performance, and high-quality data normalization. The new policy structures service level objectives (SLOs) and request triaging by customer support tiers (Standard versus Expert/Expert+), and prioritizes core security data through <a href="https://docs.cloud.google.com/chronicle/docs/reference/important-udm-fields">Important UDM Fields</a>. Additionally, the policy outlines a community-driven model where low-usage, longtail prebuilt parsers migrate to a dedicated GitHub repository maintained by partners and the Google SecOps community. </p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/standard-parser-support-policy">Standard parser support policy</a>.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Feature</h3>
<p>New <strong>Cloud Identity</strong> integration</p>
<h2 class="release-note-product-title">Google SecOps SIEM</h2>
<h3>Feature</h3>
<p><strong>Standard parser support policy</strong></p>
<p>Google SecOps introduced a focused support policy for Standard parsers to scale platform stability, predictable performance, and high-quality data normalization. The new policy structures service level objectives (SLOs) and request triaging by customer support tiers (Standard versus Expert/Expert+), and prioritizes core security data through <a href="https://docs.cloud.google.com/chronicle/docs/reference/important-udm-fields">Important UDM Fields</a>. Additionally, the policy outlines a community-driven model where low-usage, longtail prebuilt parsers migrate to a dedicated GitHub repository maintained by partners and the Google SecOps community. </p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/ingestion/standard-parser-support-policy">Standard parser support policy</a>.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>You can use the data lineage remote MCP server to interact with Knowledge Catalog (formerly Dataplex Universal Catalog) to query data lineage graphs, discover upstream data provenance, and analyze downstream impact.</p>
<p>This feature is available in <a href="https://cloud.google.com/products#product-launch-stages">preview</a>.
For more information, see <a href="https://docs.cloud.google.com/dataplex/docs/use-lineage-mcp">Use the data lineage remote MCP server</a>.</p>
<h2 class="release-note-product-title">Looker</h2>
<h3>Announcement</h3>
<p>The following features will begin rolling out as part of Looker 26.8.</p>
<h3>Feature</h3>
<p>The Looker <a href="https://docs.cloud.google.com/looker/docs/continuous-integration">Continuous Integration (CI)</a> feature is now generally available.</p>
<h3>Feature</h3>
<p>Conversational Analytics now supports the ability to run queries when users are in <a href="https://docs.cloud.google.com/looker/docs/dev-mode-prod-mode#development_mode">Development Mode</a>.</p>
<h3>Feature</h3>
<p>Now available in preview for BigQuery and Snowflake connections, Looker integrates with in-database analytic models (<a href="https://docs.cloud.google.com/bigquery/docs/graph-overview">BigQuery Graph</a> and <a href="https://docs.snowflake.com/en/user-guide/views-semantic/overview">Snowflake semantic views</a>), so that you can keep your semantic definitions consistent across Looker and other BI tools, applications, or workloads that interface with your data warehouse.</p>
<p>See the <a href="https://docs.cloud.google.com/looker/docs/analytic-models">In-database analytic models</a> documentation page for more information.</p>
<p><strong>Note:</strong> This item was added on May 28, 2026.</p>
<h3>Feature</h3>
<p>Now available in preview, dashboard editors can change the size and layout of dashboard tiles with more granularity. To enable this feature, a Looker admin must turn on the <a href="https://docs.cloud.google.com/looker/docs/admin-panel-general-labs#granular-dashboard-sizing"><strong>Granular Dashboard Sizing</strong></a> setting on the <strong>Preview</strong> page in the <strong>Admin</strong> panel.</p>
<h3>Feature</h3>
<p>Now available in preview, enhanced observability metrics, including engagement and token usage data, are available for Conversational Analytics on the <a href="https://docs.cloud.google.com/looker/docs/system-activity-dashboards#conversational-analytics">Conversational Analytics System Activity dashboard</a>. To use this feature, a Looker admin must turn on the <strong>Conversational Analytics Observability</strong> setting on the <strong>Preview</strong> admin page. <strong>Note:</strong> Token usage monitoring for Conversational Analytics is not available at this time. This item was updated on June 1, 2026.</p>
<h3>Feature</h3>
<p>Now available in preview, you can use natural language to instruct a Conversational Analytics data agent to create a <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-agentic-workflows">workflow</a> that notifies you when your data has met certain conditions. To use this feature, a Looker admin must turn on the <strong>Agentic Workflows</strong> setting on the <strong>Gemini in Looker</strong> admin page.</p>
<h3>Feature</h3>
<p>Now available in preview, the <a href="https://docs.cloud.google.com/looker/docs/mcp">Looker-managed Model Context Protocol (MCP) server</a> allows AI agents to securely connect to your Looker instance without requiring separate middleware. Looker admins can enable this feature and <a href="https://docs.cloud.google.com/looker/docs/admin-panel-platform-mcp#model_context_protocol_mcp_settings">manage which AI tools</a> are available to developers from the new <strong>Model Context Protocol (MCP)</strong> page in the <strong>Admin</strong> panel. Usage of the managed MCP server is also tracked within <a href="https://docs.cloud.google.com/looker/docs/mcp#system_activity">System Activity Explores</a> and <a href="https://docs.cloud.google.com/looker/docs/looker-core-audit-logging#sample_queries">Cloud Audit Logs</a>.</p>
<h3>Feature</h3>
<p>Model localization for imported projects will be supported in a future release.</p>
<p><strong>Note:</strong> This item was updated on May 28, 2026.</p>
<h3>Feature</h3>
<p>Now available in preview, you can <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents">publish the Conversational Analytics data agents</a> that you create in Looker to Gemini Enterprise. All users who have the <code>save_agents</code> permission will be granted the <code>publish_agent_externally</code> permission. To use this feature, a Looker admin must turn on the <strong>Publish to Gemini Enterprise</strong> setting on the <strong>Gemini in Looker</strong> admin page.</p>
<h3>Feature</h3>
<p>Now available in preview, you can create and use Conversational Analytics <a href="https://docs.cloud.google.com/looker/docs/conversational-analytics-looker-data-agents-dashboards">data agents on Looker user-defined dashboards</a>. Conversational Analytics uses the <a href="https://docs.cloud.google.com/looker/docs/dev-mode-prod-mode#production_mode">Production Mode</a> of content when it queries Looker dashboards. To use this feature, a Looker admin must turn on the <strong>Enable Dashboard Agents</strong> setting on the <strong>Gemini in Looker</strong> admin page.</p>
<h3>Feature</h3>
<p>Looker has introduced the following new feature updates for tabbed dashboards:</p>
<ul>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#add-buttons-with-navigation-to-tabs">add buttons with navigation to tabs</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#duplicate-tabs">duplicate tabs</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#apply-filters">select all or deselect all tiles on a dashboard tab for filters</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#monitor-dashboard-tab-usage-with-system-activity">monitor dashboard tab usage with the <strong>Dashboard</strong> System Activity Explore</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#schedule-pdf">schedule or send a single dashboard tab or a specific set of tabs</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#download-pdf">download a single dashboard tab or a specific set of tabs</a></li>
<li>The ability to <a href="https://docs.cloud.google.com/looker/docs/tabbed-dashboards#add-to-board">add a dashboard tab view to a board</a></li>
</ul>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/exploring-self-service"><strong>Self-service Explores</strong></a> feature is now supported on Snowflake connections. Your Looker admin can select a Snowflake connection in the <a href="https://docs.cloud.google.com/looker/docs/admin-panel-self-service-explore#enable"><strong>Default Connection</strong> field</a> of the <strong>Self-service Explores</strong> admin page. On Snowflake connections, you can <a href="https://docs.cloud.google.com/looker/docs/exploring-self-service#files-from-computer">upload comma-separated files (CSV) and Excel files (XLS and XLSX)</a> to create a self-service Explore.</p>
<h3>Feature</h3>
<p>Looker has introduced a security sandboxing enhancement for Git command-line interface (CLI) operations. For Looker projects that are configured with SSH connections, this enhancement restricts which directories and executables can be accessed on the instance when Git worktree commands are executed. Looker projects that use HTTPS connections are not affected.</p>
<p>This sandboxing feature is enabled automatically for Cloud-hosted Looker (original) and Looker (Google Cloud core) instances starting in Looker 26.8.</p>
<p>For <a href="https://docs.cloud.google.com/looker/docs/glossary#customer-hosted">customer-hosted</a> Looker instances, this security enhancement is available starting in Looker 26.10. To opt in to security sandboxing, you must install the <a href="https://proot-me.github.io/"><code>proot</code> package</a> on your Looker host machine. If <code>proot</code> isn't installed, SSH-connected Git operations will still be executed successfully but won't have the sandboxing protection.</p>
<p><strong>Note:</strong> This item was updated on May 29, 2026.</p>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-roles">Admin &gt; Roles panel</a> user interface has been updated.</p>
<h3>Feature</h3>
<p>Looker admins can no longer create or manage API credentials for individual standard users in Looker (original) instances. Users must now <a href="https://docs.cloud.google.com/looker/docs/user-account#api-keys">manage their own keys</a> from their <strong>Account</strong> page. Admins can <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-users#api_keys">enable or disable self-service API key management</a> for users and continue to manage credentials for API-only service accounts. To improve security, API keys are no longer visible to admins while they are <a href="https://docs.cloud.google.com/looker/docs/admin-panel-users-users#impersonating_users">sudoing</a> as another user.</p>
<h2 class="release-note-product-title">Managed Service for Apache Airflow</h2>
<h3>Feature</h3>
<p>Managed Service for Apache Airflow now
<a href="https://docs.cloud.google.com/composer/docs/composer-3/create-and-manage-tags">supports Google Cloud tags</a>
for environments.</p>
<p><a href="https://docs.cloud.google.com/resource-manager/docs/tags/tags-overview">Tags</a>
provide a way to create annotations for resources, and conditionally allow or
deny policies based on whether a resource has a specific tag.</p>
<h3>Feature</h3>
<p>In Managed Airflow (Gen 3), it is now possible to
create Kubernetes Secrets with the <code>kubernetes.io/dockerconfigjson</code>
<a href="https://kubernetes.io/docs/concepts/configuration/secret/#secret-types">secret type</a>
through the beta Cloud Composer API, in addition to the default
<code>Opaque</code> secret type. For more information, see <a href="https://docs.cloud.google.com/composer/docs/composer-3/use-kubernetes-pod-operator#api">Manage Kubernetes Secrets</a>.</p>
<h3>Fixed</h3>
<p>(Airflow 3) The INFO log level filter in Airflow UI now correctly displays log
messages with this logging level.</p>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-3">Airflow builds</a>
are available in Managed Airflow (Gen 3):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-3-1-7-build-10">composer-3-airflow-3.1.7-build.10</a></li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-11-1-build-6">composer-3-airflow-2.11.1-build.6</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-3-airflow-2-10-5-build-39">composer-3-airflow-2.10.5-build.39</a></li>
</ul>
<h3>Change</h3>
<p>New <a href="https://docs.cloud.google.com/composer/docs/composer-versions#images-composer-2">images</a>
are available in Managed Airflow (Gen 2):</p>
<ul>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-3-airflow-2-11-1">composer-2.17.3-airflow-2.11.1</a> (default)</li>
<li><a href="https://docs.cloud.google.com/composer/docs/versions-packages#composer-2-17-3-airflow-2-10-5">composer-2.17.3-airflow-2.10.5</a></li>
</ul>
<h3>Deprecated</h3>
<p>The following Managed Airflow versions and builds have reached their
<a href="https://docs.cloud.google.com/composer/docs/composer-versioning-overview#version-deprecation-and-support">end of support period</a>:
composer-3-airflow-2.9.3-build.24, composer-2.13.2-airflow-2.9.3,
composer-2.13.2-airflow-2.10.5.</p>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>For Exadata Database Service on Exascale infrastructure, Base Database Service, and Goldengate, Oracle Database@Google Cloud adds
the following regions and zones:</p>
<ul>
<li><code>australia-southeast2-a-r2</code> (Melbourne, Australia)</li>
<li><code>europe-west8-b-r1</code> and <code>europe-west8-a-r1</code> (Milan, Italy)</li>
</ul>
<p>For a list of supported locations, see <a href="https://docs.cloud.google.com/oracle/database/docs/regions-and-zones">Supported regions and zones</a>.</p>
<h2 class="release-note-product-title">Secure Source Manager</h2>
<h3>Feature</h3>
<p>Secure Source Manager enforces a daily rate quota on the size of code
scanned for credentials per instance. The default quota limit is 1 GB per day
per instance. For more information, see <a href="https://docs.cloud.google.com/secure-source-manager/docs/quotas">Quotas and
limits</a>.</p>
<h2 class="release-note-product-title">Spanner</h2>
<h3>Feature</h3>
<p>Spanner Graph supports a suite of
<a href="https://docs.cloud.google.com/spanner/docs/graph/graph-algorithms-overview">graph algorithms</a> covering
use cases such as fraud detection, entity resolution, and recommendations.
You can invoke graph algorithms as built-in function calls in Spanner Graph
queries. You can save your output to Cloud Storage or Spanner.
This feature is available in <a href="https://docs.cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Vertex AI Search</h2>
<h3>Feature</h3>
<p><strong>Agent Search: Table and image annotation in layout parser</strong></p>
<p>The table annotation and image annotation features of the layout parser are
generally available (GA).</p>
<p>You can ask the layout parser to annotate images or tables with
a descriptive block of text describing the information in the image or table.
The annotation can then be used as a source in a generated answer.
For more information, see <a href="https://docs.cloud.google.com/generative-ai-app-builder/docs/parse-chunk-documents#layout-parsing">Layout
parser</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 26, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_26_2026</id>
    <updated>2026-05-26T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_26_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">BigQuery</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/bigquery/docs/colab-data-science-agent">Data Science Agent</a> (DSA) for
Colab Enterprise and BigQuery is now <a href="https://cloud.google.com/products/#product-launch-stages">generally
available</a> (GA).</p>
<h2 class="release-note-product-title">Cloud CDN</h2>
<h3>Feature</h3>
<p>For <a href="https://docs.cloud.google.com/load-balancing/docs/https/setting-up-global-traffic-mgmt#cdn-cache-policy">global external Application Load Balancers</a>, you can configure Cloud CDN
cache policies at various levels of a URL map, providing more granular control
over caching. You can now apply specific caching logic based on hostnames,
URL paths, HTTP headers, and query parameters. This feature is
<strong>Generally Available</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/cdn/docs/caching#cache-policies-url-maps">Cache policies in URL maps</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>For global external Application Load Balancers, you can configure Cloud CDN cache policies at
various levels of a URL map. This provides granular control over caching
policies based on criteria like hostname, URL path, HTTP headers, and query
parameters. This feature is in <strong>General availability</strong>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/load-balancing/docs/https/setting-up-global-traffic-mgmt#cdn-cache-policy">Configure a Cloud CDN cache policy</a>.</p>
<h3>Feature</h3>
<p>Frontend configuration for load balancing incoming IPv6 traffic is now supported
for the following load balancers:</p>
<ul>
<li>Regional external Application Load Balancer</li>
<li>Regional external proxy Network Load Balancer</li>
<li>Regional internal Application Load Balancer</li>
<li>Regional internal proxy Network Load Balancer</li>
<li>Cross-region internal Application Load Balancer</li>
<li>Cross-region internal proxy Network Load Balancer</li>
</ul>
<p>This feature is in <strong>Preview</strong>.</p>
<p>For more information, see the following documentation:</p>
<ul>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/forwarding-rule-concepts">Forwarding rules overview</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/ipv6">IPv6 for Application Load Balancers and proxy Network Load Balancers</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/https/convert-applb-dualstack">Convert Application Load Balancer to IPv6</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/tcp/convert-proxynetlb-dualstack">Convert Proxy Network Load Balancer to IPv6</a></li>
<li><a href="https://docs.cloud.google.com/load-balancing/docs/proxy-only-subnets#proxy_only_subnet_create">Proxy-only subnets for Envoy-based load balancers</a></li>
</ul>
<h2 class="release-note-product-title">Cloud Trace</h2>
<h3>Announcement</h3>
<p>Cloud Trace in Observability Analytics is generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
Observability Analytics lets you query and analyze your trace data by using SQL.
You can chart your query results, save your queries, and join your trace and
log data.</p>
<p>For more information, see the following documents:</p>
<ul>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/analytics">Query and analyze telemetry with Observability Analytics</a>.</li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/analytics-chart">Chart SQL query results</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/analytics-samples">Sample SQL queries</a></li>
<li><a href="https://docs.cloud.google.com/trace/docs/analytics-query-linked-dataset">Analyze trace data with BigQuery</a>.</li>
</ul>
<h3>Announcement</h3>
<p>The Observability API is generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
This API lets you configure the following:</p>
<ul>
<li>The default storage location and the default encryption key for your
trace data.</li>
<li>The observability scope.</li>
<li>A linked BigQuery dataset, which lets your use BigQuery
services to analyze your trace data.</li>
</ul>
<p>For more information, see the following documents:</p>
<ul>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/set-defaults-for-observability-buckets">Set defaults for observability buckets</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/scopes">Configure observability scopes for multi-project queries</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/observability/storage-manage">Manage observability buckets</a></li>
<li><a href="https://docs.cloud.google.com/stackdriver/docs/reference/api-overview">API overview</a></li>
</ul>
<h3>Announcement</h3>
<p>Trace scopes are generally available
(<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
For more information, see
<a href="https://docs.cloud.google.com/trace/docs/trace-scope/create-and-manage">Create and manage trace scopes</a>.</p>
<h3>Feature</h3>
<p>The following remote MCP servers automatically generate a trace span for
<code>tools/call</code> operations. These spans can help you understand the behavior of
your agentic applications. For more information, see
<a href="https://docs.cloud.google.com/stackdriver/docs/instrumentation/trace-remote-mcp-server-calls">Investigate MCP calls using Trace</a>.</p>
<ul>
<li>BigQuery</li>
<li>Cloud SQL</li>
</ul>
<h2 class="release-note-product-title">Colab Enterprise</h2>
<h3>Feature</h3>
<p><strong>Data Science Agent</strong></p>
<p><a href="https://cloud.google.com/products#product-launch-stages">Generally available</a>:
Use the Data Science Agent to automate exploratory data analysis,
perform machine learning tasks, and deliver insights from within
a Colab Enterprise notebook. To get started, see
<a href="https://docs.cloud.google.com/colab/docs/use-data-science-agent">Use the Data Science Agent</a>.</p>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-129-19506-120-115_">cos-129-19506-120-115 <a id='"cos-arm64-129-19506-120-115"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/4b67db877bccca1607f98ab4fd34f80e6245828f
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.115/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Added support for the <code>swiotlb=any</code> kernel command line parameter.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded net-misc/openssh to v10.0_p2.</p>
<h3>Fixed</h3>
<p>Fixed a crash that occurs when using the <code>configfile</code> or
<code>source</code> GRUB2 commands when Secure Boot is enabled.</p>
<h3>Fixed</h3>
<p>Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31419 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31430 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43074 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43088 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-32289,CVE-2026-32282,CVE-2026-32288,CVE-2026-27142,CVE-2025-61728,CVE-2026-27139,CVE-2026-39817,CVE-2026-39819,CVE-2025-68119,CVE-2025-61732,CVE-2026-32280,CVE-2026-25679,CVE-2026-27144,CVE-2026-32283,CVE-2026-27140,CVE-2025-61731,CVE-2026-32281,CVE-2025-61726,CVE-2025-68121,CVE-2026-27143,CVE-2026-39826,CVE-2026-39823,CVE-2026-39825,CVE-2026-33814,CVE-2026-39820,CVE-2026-42499,CVE-2026-39836.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h3>Change</h3>
<h3 id="cos-125-19216-395-47_">cos-125-19216-395-47 <a id='"cos-arm64-125-19216-395-47"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/b82d4fb79da9ccb0fb216da3a51f977397f3193d
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.47/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Added support for the <code>swiotlb=any</code> kernel command line parameter.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Upgrade app-admin/fluent-bit to v3.2.10</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded net-misc/openssh to v10.0_p2.</p>
<h3>Fixed</h3>
<p>Fixed a crash that occurs when using the <code>configfile</code> or
<code>source</code> GRUB2 commands when Secure Boot is enabled.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31419 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43088 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-42499,CVE-2026-39820,CVE-2026-39826,CVE-2026-33814,CVE-2026-39836,CVE-2026-39823,CVE-2026-39825,CVE-2026-39817,CVE-2026-39819.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-144_">cos-121-18867-381-144 <a id='"cos-arm64-121-18867-381-144"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/49ca470354b8180a68a948c2512fb9b5f4ef8b5f
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.144/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Upgrade app-admin/fluent-bit to v3.2.10</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43109 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-33814,CVE-2026-39823,CVE-2026-39826,CVE-2026-39817,CVE-2026-39819,CVE-2026-39820,CVE-2026-39836,CVE-2026-42499,CVE-2026-39825.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-25_">cos-117-18613-613-25 <a id='"cos-arm64-117-18613-613-25"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6cd389d7730d16d15e008a822b46e2f5d450d562
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.25/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded app-containers/containerd from v1.7.29 to
v1.7.31.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43109 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-39817,CVE-2026-39825,CVE-2026-33814,CVE-2026-39819,CVE-2026-39826,CVE-2026-39823,CVE-2026-39820,CVE-2026-42499,CVE-2026-39836.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Filter support for Google Sites data stores (Preview)</strong></p>
<p>You can add Site URL prefix filters to Google Sites data stores in
Gemini Enterprise to include or exclude specific sites from search results.</p>
<p>This feature is in Public Preview. For more information, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/gsites/add-filters-to-gsites-data-store">Add filters to a Google Sites data store</a>.</p>
<h3>Deprecated</h3>
<p><strong>Gemini Enterprise: Gemini Enterprise assist is deprecated</strong></p>
<p>The Gemini Enterprise assist feature is deprecated and shut down.
Users can now find comprehensive and relevant answers directly in the
Gemini Enterprise documentation.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Data store for PagerDuty (Preview)</strong></p>
<p>You can connect PagerDuty data stores to Gemini Enterprise.</p>
<p>Support for PagerDuty data stores is in Public Preview. For more information,
see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/pagerduty">Connect PagerDuty</a>.</p>
<h3>Announcement</h3>
<p><strong>Gemini Enterprise: Administrator control for Gemini 3.5 Flash</strong></p>
<p>Gemini Enterprise administrators can use the feature management toggle to turn on
or turn off Gemini 3.5 Flash, controlling its visibility in the
Gemini Enterprise app chat box.</p>
<p>The feature management toggle for Gemini 3.5 Flash will not be
available after June 8, 2026. Starting June 8, 2026, Gemini 3.5 Flash
is enabled by default and cannot be turned off for users in the Gemini Enterprise
app.</p>
<p>For more information about feature controls, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web app</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>The Gemini Deep Research Agent released in Preview</strong></p>
<p>The Gemini Deep Research Agent has been released in Preview. The Gemini Deep
Research Agent is a managed AI agent that plans, executes, and synthesizes
complex, multi-step research workflows across the public web and private
enterprise data to generate comprehensive, cited reports.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/agents/use-deep-research">Use the Gemini Deep Research
Agent</a>.</p>
<h3>Feature</h3>
<p><strong>Agent Platform Sandboxes</strong></p>
<p>Additional Agent Platform <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox">sandbox</a>
features are now available:</p>
<ul>
<li><strong><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/computer-use">Computer use</a> (Preview)</strong>:
Enables agents to automate browser-based tasks within an isolated web
browser environment. You can control the browser using the API or connect
directly using the Chrome DevTools Protocol (CDP).</li>
<li><strong><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/custom-containers">Custom container sandboxes</a> (Preview)</strong>:
Bring your own container (BYOC) to run custom workloads with specialized
dependencies hosted in Artifact Registry.</li>
<li><strong><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/manage-templates">Sandbox templates</a> (Preview)</strong>:
Define sandbox specifications as reusable templates relying on pre-warmed
pools to facilitate rapid, reliable startups.</li>
<li><strong><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/sandbox/manage-snapshots">Sandbox snapshots</a> (Preview)</strong>:
Save the exact state of your sandbox environment (including dependencies and
file systems) and restore it to a new sandbox.</li>
</ul>
<h3>Feature</h3>
<p><strong>Identify the agents with the most content security violations</strong></p>
<p>The <strong>Security</strong> dashboard displays the top 10 agents with the most content
violations detected by Model Armor. The list shows the agent ID of each
agent and the number of violations detected for that agent. For more
information, see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/govern/monitor-content-security">Monitor content
security</a>.</p>
<h2 class="release-note-product-title">Generative AI on Vertex AI</h2>
<h3>Deprecated</h3>
<p><strong>Vertex AI Extensions deprecation</strong></p>
<p>Vertex AI Extensions is deprecated and will be shut down after November 26, 2026.
We recommend
<a href="https://docs.cloud.google.com/vertex-ai/generative-ai/docs/extensions/migrate">migrating to Agent Platform</a>
to avoid service disruption.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.35</strong></p>
<p>We've released version 4.35 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where URLs copied from Microsoft Word into SMS chat sessions
were incorrectly formatted, causing links to merge with adjacent text.</p></li>
<li><p>Fixed an issue with Alvaria campaigns where the dialer didn't correctly use
the country code from the <strong>@COUNTRYCODE</strong> field when selecting the contact
number to dial.</p></li>
<li><p>Fixed an issue where live transcription didn't resume after an agent enabled
and then disabled redaction during IVR payment card collection.</p></li>
<li><p>Fixed an issue where agents couldn't upload PDF files in chat sessions.</p></li>
<li><p>Fixed an issue where end-users encountered errors or empty details when
accessing call history immediately after a call ended.</p></li>
<li><p>Fixed an issue where agents became stuck in the <code>In-call</code> status and
couldn't end calls or change their status, preventing them from handling new
interactions.</p></li>
<li><p>Fixed an issue where the deletion of the default greeting message for a
language didn't persist.</p></li>
<li><p>Fixed a web SDK issue where scheduling a call in one queue incorrectly
showed the <strong>Reschedule Call</strong> screen from a different queue.</p></li>
<li><p>Fixed an issue that occurred when a human agent invoked the payment virtual
task assistant to collect card details. When the call was transferred back
to the human agent, live transcription and sentiment analysis didn't resume.</p></li>
<li><p>Fixed an issue where HubSpot ticket creation failed when <strong>Skip CRM Account
Creation</strong> and <strong>Skip Account Lookup</strong> were enabled. This resulted in
tickets being created without an associated phone number.</p></li>
<li><p>Fixed an issue where, after transferring a call from one queue to another,
the receiving agent's desktop temporarily showed the source queue's agent
desktop layout instead of the destination queue's layout.</p></li>
<li><p>Fixed an issue where outbound Telnyx calls got stuck on the agent adapter
<strong>Connecting</strong> screen when <strong>Agent Voice Detection</strong> was enabled globally.</p></li>
<li><p>Fixed an issue where Alvaria Advanced Outreach outbound campaign batch files
weren't ingested by Contact Center AI Platform, preventing campaigns from loading
contacts.</p></li>
<li><p>Fixed an issue where a single inbound call in Salesforce created two cases.</p></li>
<li><p>Fixed an issue where the <strong>Agents</strong> dashboard showed an invalid <code>-10</code> agent
status during wrap-up and after calls.</p></li>
<li><p>Fixed an issue where Alvaria WFM Agent Performance reports displayed no
agent activity.</p></li>
<li><p>Fixed an issue where the NICE WFM exporter reported higher abandoned call
counts than Contact Center AI Platform reporting.</p></li>
<li><p>Fixed an issue where chats escalated from a virtual agent to a human agent
were dismissed shortly after assignment.</p></li>
<li><p>Fixed an issue where the <strong>Ticket URL</strong> column in the <strong>Individual Call
History CSV report</strong> was blank for newly recorded calls, preventing
customers from accessing and downloading call recordings from the report.</p></li>
<li><p>Fixed an issue where newly created teams couldn't be reordered in the
CCAI Platform portal.</p></li>
<li><p>Fixed an issue where the agent desktop <strong>Previous Interactions</strong> panel
didn't show Agent Assist summaries from past calls.</p></li>
<li><p>Fixed an issue where conversation history didn't display correctly in the
agent adapter when a chat was escalated from a virtual agent to a human
agent and then a large number of messages were sent by the end-user.</p></li>
</ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>Cloud Storage FUSE CSI driver is now supported for Google Cloud Dedicated
clusters and node pools running GKE version 1.36.0-gke.1266000 and higher. To
use the driver, you must specify the <code>custom-endpoint</code> mount option by using
either the <a href="https://docs.cloud.google.com/storage/docs/cloud-storage-fuse/cli-options#options">gcsfuse CLI</a>
or the <a href="https://docs.cloud.google.com/storage/docs/cloud-storage-fuse/config-file#format-and-fields">configuration
file</a> format.
For more information, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/cloud-storage-fuse-csi-driver">About Cloud Storage FUSE CSI driver for
GKE</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 25, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_25_2026</id>
    <updated>2026-05-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_25_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Feature</h3>
<p>To monitor the efficiency of the GKE training JobSet, the following two GKE
system metrics are available in Preview:</p>
<ul>
<li><code>kubernetes.io/jobset/scheduling_goodput</code>: the fraction of time that all the
resources required to run the training JobSet are available.</li>
<li><code>kubernetes.io/jobset/proxy_runtime_goodput</code>: the fraction of time that all
required accelerators are productive. This metric provides an estimate of the
real runtime goodput.</li>
</ul>
<p>For details about GKE metrics, see <a href="https://docs.cloud.google.com/monitoring/api/metrics_kubernetes#kubernetes-kubernetes">Kubernetes
metrics</a>.
For details about goodput metrics that are used to measure efficiency, see
<a href="https://docs.cloud.google.com/tpu/docs/goodput#jobset-dashboard">Monitor goodput with the ML Goodput Measurement
library</a>.</p>
<p>You can also view these new GKE metrics in the <a href="https://docs.cloud.google.com/kubernetes-engine/docs/tutorials/tpu-multislice-kueue#monitor_the_workloads">JobSet monitoring dashboard</a>.</p>
<h2 class="release-note-product-title">Knowledge Catalog</h2>
<h3>Feature</h3>
<p>Data products in Knowledge Catalog is
Generally Available (<a href="https://cloud.google.com/products#product-launch-stages">GA</a>).
A data product serves as a logical, curated package of data assets and context
designed to solve a specific business problem.</p>
<p>This release includes the following new features:</p>
<ul>
<li><p><strong>Approval workflows for data product consumption:</strong> Data product consumers
can browse published data products, submit access requests, and track their
status. Data product owners can track, approve, or reject access requests
using the Google Cloud Console or the API. For more information, see
<a href="https://cloud.google.com/dataplex/docs/use-data-products">Use data products</a>
and
<a href="https://cloud.google.com/dataplex/docs/manage-data-products">Manage data products</a>.</p></li>
<li><p><strong>Automated documentation and insights:</strong> Data product owners can leverage
Knowledge Catalog data insights and Gemini to automatically generate sample
queries, business insights, and documentation templates for data products.
For more information, see
<a href="https://cloud.google.com/dataplex/docs/create-data-products">Create data products</a>.</p></li>
<li><p><strong>Service account support:</strong> Data product owners can configure service
accounts in access groups, and data product consumers can request access for
their service accounts. For more information, see
<a href="https://cloud.google.com/dataplex/docs/create-data-products">Create data products</a>.</p></li>
<li><p><strong>Remote Model Context Protocol (MCP) server support (Preview)</strong> Data
applications and AI agents can programmatically interact with data products.
By deploying the Knowledge Catalog remote MCP server, developers can create
data products, discover data products, and inspect data product metadata from
external IDEs and LLM clients. For more information, see
<a href="https://cloud.google.com/dataplex/docs/use-data-products#mcp-server">Access data products using Model Context Protocol</a>.</p></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 24, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_24_2026</id>
    <updated>2026-05-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_24_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps</h2>
<h3>Feature</h3>
<p><strong>[Spotlight Feature] Create and manage calculated fields</strong></p>
<p>The Calculated Fields feature is now available in Preview. With Calculated Fields, you can dynamically derive new data points within Google Security Operations cases and alerts. By defining logical formulas, you can compute values based on existing system or custom fields. The calculated value is automatically evaluated and stored in a user-selected, pre-existing custom field (labeled <strong>Target Field</strong>) in real time.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/calculated-fields">Create and manage calculated fields</a>.</p>
<h3>Change</h3>
<p><strong>Time range selection for searches</strong></p>
<p>Google SecOps has now added relative and absolute time range options to define
the required time period for retrieving search results.</p>
<ul>
<li><strong>Relative time range</strong>: Set a search window looking backward from the current time
using custom intervals.</li>
<li><strong>Absolute time range</strong>: Define fixed start and end times using calendar presets,
exact date and time selections, or event-based timeframes.</li>
</ul>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/investigation/udm-search#setDateTime">Set the date and time range</a>.</p>
<aside class="note"><strong>Note:</strong><span> This change follows a phased rollout from from <strong>May 12, 2026</strong>, to <strong>May 18, 2026</strong>.
Reach out to support if you do not see the new limits applied to your environment
after <strong>May 18, 2026</strong>.</span></aside>
<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Feature</h3>
<p><strong>Create and manage calculated fields</strong></p>
<p>The Calculated Fields feature is now available in Preview. With Calculated Fields, you can dynamically derive new data points within Google Security Operations cases and alerts. By defining logical formulas, you can compute values based on existing system or custom fields. The calculated value is automatically evaluated and stored in a user-selected, pre-existing custom field (labeled <strong>Target Field</strong>) in real time.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/chronicle/docs/soar/investigate/working-with-cases/calculated-fields">Create and manage calculated fields</a>.</p>
<h3>Announcement</h3>
<p>Release 6.3.86 is being rolled out to the first phase of regions as listed <a href="https://docs.cloud.google.com/chronicle/docs/soar/overview-and-introduction/soar-gradual-release">here</a>.</p>
<p>This release contains internal and customer bug fixes.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 23, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_23_2026</id>
    <updated>2026-05-23T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_23_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Google SecOps SOAR</h2>
<h3>Announcement</h3>
<p><a href="https://docs.cloud.google.com/chronicle/docs/soar/release-notes#May_17_2026">Release 6.3.85</a> is now available for all regions.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 22, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_22_2026</id>
    <updated>2026-05-22T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_22_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Access Approval</h2>
<h3>Feature</h3>
<p>DNS Armor is generally available <a href="https://cloud.google.com/products#product-launch-stages">(GA)</a>.</p>
<h2 class="release-note-product-title">Access Transparency</h2>
<h3>Feature</h3>
<p>DNS Armor is generally available <a href="https://cloud.google.com/products#product-launch-stages">(GA)</a>.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p><strong>Apigee Emulator</strong></p>
<h3 id="apigee_emulator_v200">Apigee Emulator v2.0.0</h3>
<p>On May 22, 2026, we released Apigee Emulator version 2.0.0.</p>
<p>Starting with this release, the Apigee Emulator is versioned and released
independently from Apigee hybrid. This enables faster delivery of security
patches and updates without waiting for hybrid release cycles. The emulator
image continues to be available at
<a href="https://console.cloud.google.com/artifacts/docker/apigee-release/us/gcr.io/hybrid%2Fapigee-emulator">Google Artifact Registry</a>.</p>
<p>To use the new version, update the emulator version in your VS Code Cloud Code
settings to <code>2.0.0</code>. See
<a href="https://docs.cloud.google.com/apigee/docs/api-platform/local-development/vscode/manage-apigee-emulator#choose_the_emulator_version">Manage the Apigee Emulator</a>
for details.</p>
<h3>Feature</h3>
<p><strong>Apigee Emulator</strong></p>
<h4 id="changed_in_this_release">Changed in this release</h4>
<ul>
<li>The Apigee Emulator now follows independent semantic versioning
(MAJOR.MINOR.PATCH), decoupled from Apigee hybrid versioning.</li>
<li>Updated base Cassandra image to version 4.0.19.</li>
<li>Updated Java runtime to Eclipse Temurin JRE 11.0.31.</li>
</ul>
<h3>Security</h3>
<p><strong>Apigee Emulator</strong></p>
<h4 id="security">Security</h4>
<p>This release addresses 78 security vulnerabilities across Cassandra base image,
Go standard library, Java dependencies, and Python packages. Key fixes include:</p>
<table>
<thead>
<tr>
<th>CVE</th>
<th>Component</th>
</tr>
</thead>
<tbody>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42003">CVE-2022-42003</a></td>
<td>Jackson Databind</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-42004">CVE-2022-42004</a></td>
<td>Jackson Databind</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38749">CVE-2022-38749</a></td>
<td>SnakeYAML</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38750">CVE-2022-38750</a></td>
<td>SnakeYAML</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2976">CVE-2023-2976</a></td>
<td>Google Guava</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-8908">CVE-2020-8908</a></td>
<td>Google Guava</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12798">CVE-2024-12798</a></td>
<td>Logback</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22866">CVE-2025-22866</a></td>
<td>Go stdlib</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22870">CVE-2025-22870</a></td>
<td>Go stdlib</td>
</tr>
<tr>
<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-40897">CVE-2022-40897</a></td>
<td>Python setuptools</td>
</tr>
</tbody>
</table>
<p>And 68 additional CVEs fixed through updated upstream dependencies.</p>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1145">v1.14.5</h3>
<p>On May 22, 2026 we released an updated version of the Apigee hybrid software, v1.14.5.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/upgrade">Upgrading Apigee hybrid to version v1.14.5</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.14/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Security</h3>
<p>Various security and CVE fixes are included in this release.</p>
<h3>Announcement</h3>
<p>On May 22, 2026 we released an updated version of the Apigee UI.</p>
<p>The <b>Management <span aria-label="and then">&gt;</span> Instances</b> page now displays Apigee hybrid instances. The display includes the instance name, location, and runtime version.</p>
<p>See <a href="https://docs.cloud.google.com/apigee/docs/api-platform/system-administration/instances">Managing instances</a>.</p>
<h3>Announcement</h3>
<h3 id="apigee_emulator_is_now_released_independently">Apigee Emulator is now released independently</h3>
<p>Starting May 22, 2026, the Apigee Emulator is versioned and released
independently from Apigee hybrid. Emulator updates, including security patches,
are no longer tied to hybrid release cycles.</p>
<p>The emulator image continues to be available at
<code>gcr.io/apigee-release/hybrid/apigee-emulator</code>. The first independent release
is <strong>v2.0.0</strong>.</p>
<p>For emulator release notes going forward, see
<a href="https://docs.cloud.google.com/apigee/docs/release/release-notes">Apigee release notes</a>.</p>
<h2 class="release-note-product-title">Cloud Database Migration Service</h2>
<h3>Feature</h3>
<p>Database Migration Service for homogeneous SQL Server migrations now provides
dedicated support for Cloud SQL for SQL Server sources. This feature is generally
available
(<a href="https://cloud.google.com/products#product-launch-stages" track-metadata-position="releaseNotes" track-metadata-srcpg="docs/release-notes" track-name="launch-stages-GA" track-type="releaseNoteLink">GA</a>).</p>
<p>For Cloud SQL for SQL Server sources, Database Migration Service automatically exports all
required backup files and uploads them to a dedicated Cloud Storage bucket.
For more information, see the
<a href="https://docs.cloud.google.com/database-migration/docs/sqlserver/csql-sql-server-src-guide" track-metadata-position="releaseNotes" track-metadata-srcpg="docs/release-notes" track-name="csql_src_full_migration_guide" track-type="releaseNoteLink">
Migration guide for Cloud SQL for SQL Server sources</a> in the Database Migration Service
homogeneous SQL Server documentation.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>Application Load Balancers now support the configuration of a
<a href="https://docs.cloud.google.com/load-balancing/docs/backend-service#applb-csm-traffic-duration">traffic duration</a>
setting when you add backends to backend services. You can configure this
setting as <code>SHORT</code> or <code>LONG</code> based on the response time needed by backends to
complete HTTP requests.</p>
<p>Application Load Balancers also support the use of the
<a href="https://docs.cloud.google.com/load-balancing/docs/backend-service#bmtc-inflight"><em>in-flight</em> balancing mode</a>
that lets you configure the load balancer's traffic distribution to supported
backends when requests take more than a second to complete.</p>
<p>This feature is in <strong>General availability</strong>.</p>
<h2 class="release-note-product-title">Database Center</h2>
<h3>Feature</h3>
<p>Database Center generative views are available in
<a href="https://cloud.google.com/products/#product-launch-stages">Preview</a>.
Generative views use Gemini and natural language prompts to
let you generate and save customized dashboard views of your database fleet
inventory and metrics.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/database-center/docs/generative-views">Generate dashboard views using Gemini</a>.</p>
<h2 class="release-note-product-title">Key Access Justifications</h2>
<h3>Feature</h3>
<p>Default Key Access Justifications policies are generally available. When you use
Key Access Justifications with Cloud Key Management Service or Cloud HSM for the
Assured Workloads <a href="https://docs.cloud.google.com/assured-workloads/docs/control-packages/japan-data-boundary">Japan Data
Boundary</a>, you can
create default Key Access Justifications policies at the organization, folder,
or project level. For more information about default Key Access Justifications
policies, see <a href="https://docs.cloud.google.com/assured-workloads/key-access-justifications/docs/set-default-policy">Set default Key Access Justifications
policy</a>.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 21, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_21_2026</id>
    <updated>2026-05-21T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_21_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">AlloyDB for PostgreSQL</h2>
<h3>Fixed</h3>
<p>ChatGPT users are now able to list and use the AlloyDB toolset provided by the
AlloyDB remote MCP server.</p>
<h2 class="release-note-product-title">Apigee X</h2>
<h3>Announcement</h3>
<p>On May 21st, 2026, we released an updated version of Apigee (1-17-0-apigee-8).</p>
<aside class="note"><strong>Note:</strong><span> Rollouts of this release began today and may take four or more business days to be completed across all Google Cloud zones. Your instances may not have the features and fixes available until the rollout is complete.</span></aside>
<h3>Fixed</h3>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>514973778</strong></td>
<td>Fixed Model Armor response parsing to gracefully handle unknown fields, so future Model Armor field additions no longer cause policy failures.</td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1164">v1.16.4</h3>
<p>On May 21, 2026 we released an updated version of the Apigee hybrid software, v1.16.4.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.4</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>515424331</strong></td>
<td><strong>Fixed an issue with missing container images in the <code>gcr.io/apigee-release/hybrid/</code> repository.</strong></td>
</tr>
</tbody>
</table>
<h2 class="release-note-product-title">App Engine standard environment Go</h2>
<h3>Feature</h3>
<p>The App Engine Migration hub lets you migrate services in the App Engine standard environment to Cloud Run, and also provides cost-saving recommendations. For more information, see <a href="https://docs.cloud.google.com/appengine/migration-center/run/migrate-app-engine-standard-to-run">Deploy an App Engine app in the standard environment to Cloud Run</a> (<a href="https://cloud.google.com/products?e=48754805#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment Java</h2>
<h3>Feature</h3>
<p>The App Engine Migration hub lets you migrate services in the App Engine standard environment to Cloud Run, and also provides cost-saving recommendations. For more information, see <a href="https://docs.cloud.google.com/appengine/migration-center/run/migrate-app-engine-standard-to-run">Deploy an App Engine app in the standard environment to Cloud Run</a> (<a href="https://cloud.google.com/products?e=48754805#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment Node.js</h2>
<h3>Feature</h3>
<p>The App Engine Migration hub lets you migrate services in the App Engine standard environment to Cloud Run, and also provides cost-saving recommendations. For more information, see <a href="https://docs.cloud.google.com/appengine/migration-center/run/migrate-app-engine-standard-to-run">Deploy an App Engine app in the standard environment to Cloud Run</a> (<a href="https://cloud.google.com/products?e=48754805#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment PHP</h2>
<h3>Feature</h3>
<p>The App Engine Migration hub lets you migrate services in the App Engine standard environment to Cloud Run, and also provides cost-saving recommendations. For more information, see <a href="https://docs.cloud.google.com/appengine/migration-center/run/migrate-app-engine-standard-to-run">Deploy an App Engine app in the standard environment to Cloud Run</a> (<a href="https://cloud.google.com/products?e=48754805#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment Python</h2>
<h3>Feature</h3>
<p>The App Engine Migration hub lets you migrate services in the App Engine standard environment to Cloud Run, and also provides cost-saving recommendations. For more information, see <a href="https://docs.cloud.google.com/appengine/migration-center/run/migrate-app-engine-standard-to-run">Deploy an App Engine app in the standard environment to Cloud Run</a> (<a href="https://cloud.google.com/products?e=48754805#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">App Engine standard environment Ruby</h2>
<h3>Feature</h3>
<p>The App Engine Migration hub lets you migrate services in the App Engine standard environment to Cloud Run, and also provides cost-saving recommendations. For more information, see <a href="https://docs.cloud.google.com/appengine/migration-center/run/migrate-app-engine-standard-to-run">Deploy an App Engine app in the standard environment to Cloud Run</a> (<a href="https://cloud.google.com/products?e=48754805#product-launch-stages">Preview</a>).</p>
<h2 class="release-note-product-title">Cloud Asset Inventory</h2>
<h3>Feature</h3>
<p>The following resource types are publicly available through the
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/exportAssets">ExportAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/listing-assets">ListAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/batchGetAssetsHistory">BatchGetAssetsHistory</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/queryAssets">QueryAssets</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/feeds">Feed</a>,
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/searchAllResources">SearchAllResources</a>,
and
<a href="https://docs.cloud.google.com/asset-inventory/docs/reference/rest/v1/TopLevel/searchAllIamPolicies">SearchAllIamPolicies</a>
APIs.</p>
<ul>
<li>Apigee
<ul>
<li><code>apigee.googleapis.com/SecurityAction</code></li>
<li><code>apigee.googleapis.com/SecurityMonitoringCondition</code></li>
<li><code>apigee.googleapis.com/SecurityProfileV2</code></li>
</ul></li>
<li>Cloud Key Management Service
<ul>
<li><code>cloudkms.googleapis.com/RetiredResource</code></li>
</ul></li>
<li>Hypercompute Cluster
<ul>
<li><code>hypercomputecluster.googleapis.com/Cluster</code></li></ul></li></ul>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>Zonal affinity, which was previously available in Preview,
is generally available (GA).</p>
<p>For more information, see <a href="https://docs.cloud.google.com/load-balancing/docs/internal/zonal-affinity">Zonal affinity for internal passthrough Network Load Balancers</a>.</p>
<h2 class="release-note-product-title">Config Controller</h2>
<h3>Change</h3>
<p>Config Controller now uses the following versions of its included products:</p>
<ul>
<li>Config Connector v1.148.0-cc.3, <a href="https://docs.cloud.google.com/config-connector/docs/release-notes#April_22_2026">release notes</a></li>
<li>Config Sync v1.23.3, <a href="https://docs.cloud.google.com/kubernetes-engine/config-sync/docs/release-notes#March_26_2026">release notes</a></li>
</ul>
<h2 class="release-note-product-title">Container Optimized OS</h2>
<h3>Change</h3>
<h3 id="cos-129-19506-120-97_">cos-129-19506-120-97 <a id='"cos-arm64-129-19506-120-97"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/dfd76308ba62f00253b0f99cf10089931d12241d
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.97/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19804-0-0_">cos-dev-133-19804-0-0 <a id='"cos-arm64-dev-133-19804-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/39aff0f4a2a2fe29718f45dcab025a25fc7c46d6
">COS-6.18.32</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19804.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Switch cchost-* boards to legacy iptables.</p>
<h3>Change</h3>
<p>Added support for the R595 Nvidia driver production branch.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.309.01.</p>
<h3>Change</h3>
<p>Apply hardening sysctls on cchost boards.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Change</h3>
<p>Dropped support for the NVIDIA 535 drivers.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v595.71.05.</p>
<h3>Change</h3>
<p>Enabled mm hardening kernel cmdlines on cchost.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Change</h3>
<p>Increased the size of the EFI partition from 32 MiB to 64 MiB and increased the sizes of both kernel partitions from 16 MiB to 32 MiB on x86.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Change</h3>
<p>Made it so that /etc/machine-id is mounted with noexec, nosuid, and nodev.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.2.</p>
<h3>Change</h3>
<p>Switch cchost-* boards to legacy iptables.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38584 in the Linux kernel.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.18.32.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Change</h3>
<p>Updated uhaul to v6.18-0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43060 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgrade the Linux kernel to version 6.18.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43063 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded sys-apps/xemu to v0.0.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43065 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded sys-fs/cryptsetup to v2.8.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43066 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded sysram to v6.18-0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43067 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Added the cos_kernel_args tool that allows manipulating kernel command line arguments of a COS image.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43068 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Added nvidia-fs support to the COS GPU installer.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43071 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43073 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43079 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43085 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v595.71.05.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43086 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43089 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Dropped support for NVIDIA MFT Tools v4.32.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43090 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded CASFS to v0.1.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43091 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260227.00.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43093 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260430.00.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43094 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43099 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43107 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43112 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43114 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r672.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43117 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2738.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43329 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2026.04.24.230834-r272.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43332 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2026.05.06.161957-r274.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43333 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2973.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43336 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2834.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43338 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43339 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.53.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43341 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.8.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43350 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.8.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43359 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_queue to v1.0.5-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43360 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43361 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43362 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libcap to v2.78.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43363 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43365 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded the dump capture kernel to Linux v6.18.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43366 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43383 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 and CVE-2026-35386 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43393 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43394 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43409 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43438 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated go to v1.25.9. This resolves CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVE-2026-27140, CVE-2026-27144.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated the Linux kernel to v6.18.31.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43441 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded containerd to v2.2.3. This fixes CVE-2026-35469.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43448 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/openssl to v3.5.6 to fix CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31790.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43450 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: dev.raid.sync_io_depth: 32</li>
<li>Added: fs.dentry-negative: 0</li>
<li>Added: fs.fanotify.watchdog_timeout: 0</li>
<li>Added: fs.fuse.default_request_timeout: 0</li>
<li>Added: fs.fuse.max_request_timeout: 0</li>
<li>Added: kernel.core_modes: socket</li>
<li>Added: kernel.hung_task_detect_count: 0</li>
<li>Added: kernel.panic_sys_info: </li>
<li>Added: net.ipv4.tcp_ecn_option: 2</li>
<li>Added: net.ipv4.tcp_ecn_option_beacon: 3</li>
<li>Added: net.ipv4.tcp_rto_max_ms: 120000</li>
<li>Added: net.ipv4.tcp_tw_reuse_delay: 1000</li>
<li>Added: net.ipv6.conf.all.force_forwarding: 0</li>
<li>Added: net.ipv6.conf.default.force_forwarding: 0</li>
<li>Added: net.ipv6.conf.docker0.force_forwarding: 0</li>
<li>Added: net.ipv6.conf.eth0.force_forwarding: 0</li>
<li>Added: net.ipv6.conf.lo.force_forwarding: 0</li>
<li>Added: vm.defrag_mode: 0</li>
<li>Added: vm.vfs_cache_pressure_denom: 100</li>
<li>Changed: fs.epoll.max_user_watches: 1808517 -&gt; 1808094</li>
<li>Changed: fs.fanotify.max_user_marks: 68412 -&gt; 68395</li>
<li>Changed: fs.inotify.max_user_watches: 64189 -&gt; 64173</li>
<li>Changed: kernel.threads-max: 63178 -&gt; 63459</li>
<li>Changed: net.core.rmem_max: 212992 -&gt; 4194304</li>
<li>Changed: net.core.wmem_max: 212992 -&gt; 4194304</li>
<li>Changed: net.ipv4.tcp_mem: 94017    125357  188034 -&gt; 93993 125327  187986</li>
<li>Changed: net.ipv4.tcp_rmem: 4096    131072  6291456 -&gt; 4096 131072  33554432</li>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 187989    250654  375978</li>
<li>Changed: net.ipv6.icmp.ratelimit: 1000 -&gt; 100</li>
<li>Changed: user.max_cgroup_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_fanotify_marks: 68412 -&gt; 68395</li>
<li>Changed: user.max_inotify_watches: 64189 -&gt; 64173</li>
<li>Changed: user.max_ipc_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_mnt_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_net_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_pid_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_time_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_user_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_uts_namespaces: 31589 -&gt; 31729</li>
<li>Deleted: fs.xfs.irix_sgid_inherit: 0</li>
<li>Deleted: fs.xfs.irix_symlink_mode: 0</li>
<li>Deleted: fs.xfs.speculative_cow_prealloc_lifetime: 300</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_loose: 1</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_closereq: 64</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_closing: 64</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_open: 43200</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_partopen: 480</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_request: 240</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_respond: 480</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_timewait: 240</li>
</ul></p>
<h3>Security</h3>
<p>Fixed CVE-2026-43451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43470 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43472 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43475 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43482 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43486 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43487 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46333 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<h3>Change</h3>
<h3 id="cos-121-18867-381-132_">cos-121-18867-381-132 <a id='"cos-arm64-121-18867-381-132"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/068bbd7c450db6c0538186d272865f74efd74316
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.132/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This is an <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/versioning#lts_refresh_releases">LTS Refresh release.</a></p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.309.01.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20251014.00.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.4.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_conntrack to v1.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libtirpc to v1.3.7.</p>
<h3>Fixed</h3>
<p>Upgraded net-nds/rpcbind to v1.2.8.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.3.2-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/gentoo-functions to v1.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-auth/pambase to v20251104.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libcap to v2.77.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43187 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46333 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: net.ipv4.tcp_pingpong_thresh: 1</li>
</ul></p>
<h3>Change</h3>
<h3 id="cos-125-19216-395-31_">cos-125-19216-395-31 <a id='"cos-arm64-125-19216-395-31"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/5241cda1d789949bbcddde5d9320a36c610237d4
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.31/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Switch cchost-* boards to legacy iptables.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.309.01.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v595.71.05.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38584 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46333 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<h3>Change</h3>
<h3 id="cos-117-18613-613-15_">cos-117-18613-613-15 <a id='"cos-arm64-117-18613-613-15"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3b26f2eb5b1d5bcf6947c6656262e5b073999775
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.15/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.309.01.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46333 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for VMware</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for VMware 1.35.100-gke.72 is now available
for download. To upgrade, see <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/vmware/docs/how-to/upgrading.md">Upgrade clusters</a>.
Google Distributed Cloud 1.35.100-gke.72 runs on Kubernetes v1.35.3-gke.400.</p>
<p>If you are using a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for use with GKE On-Prem API clients: the Google Cloud console, the
gcloud CLI, and Terraform.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.35.100-gke.72:</p>
<ul>
<li>Fixed an issue that prevented administrators from running cluster health checks and gathering diagnostics on non-advanced user clusters managed by an advanced admin cluster. You can successfully use <code>gkectl diagnose</code> on user clusters that are awaiting migration to advanced mode.</li></ul>
<h2 class="release-note-product-title">Google Distributed Cloud (software only) for bare metal</h2>
<h3>Announcement</h3>
<p>Google Distributed Cloud (software only) for bare metal 1.35.100-gke.72 is now available for
download. To upgrade, see <a href="how-to/upgrade">Upgrade clusters</a>.
Google Distributed Cloud for bare metal
1.35.100-gke.72 runs on Kubernetes v1.35.3-gke.400.</p>
<p>After a release, it takes approximately 7 to 14 days for the version to become
available for installations or upgrades with the GKE On-Prem API clients: the
Google Cloud console, the gcloud CLI, and Terraform.</p>
<p>If you use a third-party storage vendor, check the Google Distributed Cloud-ready
storage partners document to make sure the storage vendor has already passed the
qualification for this release of Google Distributed Cloud for bare metal.</p>
<h3>Fixed</h3>
<p>The following issues were fixed in 1.35.100-gke.72:</p>
<ul>
<li>Fixed vulnerabilities listed in <a href="https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/vulnerabilities">Vulnerability fixes</a>.</li></ul>
<h2 class="release-note-product-title">Google Kubernetes Engine</h2>
<h3>Change</h3>
<h4 id="2026-r20-version-updates">(2026-R20) Version updates</h4>
<p>GKE cluster versions have been updated.</p>
<p><strong>New versions available for upgrades and new clusters.</strong></p>
<p>The following versions are now available for new GKE clusters, and for
manual control plane upgrades and node upgrades for existing clusters. For more
information about versioning and upgrades, see <a href="https://cloud.google.com/kubernetes-engine/versioning">GKE versioning and
support</a> and <a href="https://cloud.google.com/kubernetes-engine/upgrades">About GKE
cluster upgrades</a>.</p>
<div>
<devsite-selector>
<section>
<h3>Rapid channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2253000</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Regular channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now available in the Regular channel.</li>
</ul>
</section>
<section>
<h3>Stable channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>Extended channel</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul>
</section>
<section>
<h3>No channel (deprecated)</h3>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
</ul>
</section>
</devsite-selector>
</div>
<h3>Security</h3>
<h4 id="2026-r20-security-updates">(2026-R20) Security updates</h4>
<p>This release includes new GKE versions that use updated
Container-Optimized OS images. These updated images are cumulative,
incorporating security fixes from all Container-Optimized OS
versions released since the previous GKE release.</p>
<p>To identify the specific vulnerabilities that were resolved in each updated
Container-Optimized OS image, see the <strong>Security</strong> release notes
for that image. The following table includes links to the release notes for
each updated Container-Optimized OS image:</p>
<p>
<table>
<tbody>
<tr>
<th>GKE version</th>
<th>Container-Optimized OS version</th>
<th>Details</th>
</tr>
<tr>
<td>1.36.0-gke.2253000</td>
<td>cos-beta-129-19506-120-52</td>
<td><a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes/m129#cos-beta-129-19506-120-52_">cos-beta-129-19506-120-52 release notes</a></td>
</tr>
</tbody>
</table>
</p>
<h3>Change</h3>
<h4 id="2026-r20-version-updates">(2026-R20) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Stable channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13311">1.33.11-gke.1013000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1346">1.34.6-gke.1307000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r20-version-updates">(2026-R20) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>Version <a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a> is now available in the Regular channel.</li>
</ul>
<h3>Change</h3>
<h4 id="2026-r20-version-updates">(2026-R20) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Rapid channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.36.md#v1360">1.36.0-gke.2253000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r20-version-updates">(2026-R20) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
<li>The following node versions are now available:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.33.md#v13312">1.33.12-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.34.md#v1348">1.34.8-gke.1000000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1355">1.35.5-gke.1000000</a></li>
</ul></li>
</ul>
<h3>Change</h3>
<h4 id="2026-r20-version-updates">(2026-R20) Version updates</h4>
<aside class="note"><strong>Note</strong>: Your clusters might not have these versions available.
Rollouts are already in progress when we publish the release notes, and can take
multiple days to complete across all Google Cloud zones.</aside>
<ul>
<li>The following versions are now available in the Extended channel:
<ul>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.30.md#v13014">1.30.14-gke.2530000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.31.md#v13114">1.31.14-gke.1942000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.32.md#v13213">1.32.13-gke.1551000</a></li>
<li><a href="https://github.com/kubernetes/kubernetes/blob/master/CHANGELOG/CHANGELOG-1.35.md#v1353">1.35.3-gke.1389002</a></li>
</ul></li>
</ul>
<h2 class="release-note-product-title">SAP on Google Cloud</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud's Agent for SAP version 3.14</strong></p>
<p>Version 3.14 of Google Cloud's Agent for SAP is generally available (GA). This
version introduces support for using a customer-managed encryption key (CMEK) to
encrypt disks during disk snapshot based SAP HANA recovery, some logging and
stability enhancements, and minor bug fixes.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/sap/docs/agent-for-sap/whats-new">What's new with Google Cloud's Agent for SAP</a>.</p>
<h2 class="release-note-product-title">Secure Web Proxy</h2>
<h3>Feature</h3>
<p>When deploying your Secure Web Proxy instance as <a href="https://docs.cloud.google.com/secure-web-proxy/docs/deploy-next-hop">next
hop</a>, you can now configure the gateway
to listen on all ports (from <code>1</code> to <code>65535</code>). By using this feature, your proxy
can automatically intercept and enforce security policies and rules to all
outbound traffic, removing the need to manage specific port lists.</p>
<p>This feature is supported in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Change</h3>
<p>The following <a href="https://docs.cloud.google.com/security-command-center/docs/compliance-manager-frameworks">Compliance Manager frameworks</a> were updated:</p>
<ul>
<li>CIS Critical Security Controls v8 (version 8.0)</li>
<li>CIS GCP Foundations Benchmark v3.0 (version 7.0)</li>
<li>CSA Cloud Controls Matrix v4.0.11 (version 7.0)</li>
<li>ISO 27001:2022 (version 9.0)</li>
<li>NIST 800-53 Revision 5 (version 9.0)</li>
<li>NIST Cybersecurity Framework 1.1 (version 8.0)</li>
<li>PCI DSS v4.0.1 (version 6.0)</li>
<li>Qatar National Information Assurance Standard v2.1 (version 6.0)</li>
<li>SOC 2017 (version 7.0)</li>
</ul>
<h3>Deprecated</h3>
<p>The Security Command Center Enterprise service tier is deprecated. It will be shut down
on May 21, 2027. By default, your organization will automatically move to the
Premium service tier on that date.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/artifact-guard-overview">Artifact guard</a> is available in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>
to the Security Command Center Enterprise and Premium tiers. Artifact guard is a
service that helps you prevent the deployment of vulnerable packages throughout the
software development lifecycle.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/attack-exposure-supported-features">Risk Engine</a> detects
toxic combinations that are related to Cloud Build resources.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 20, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_20_2026</id>
    <updated>2026-05-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_20_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Apigee X</h2>
<h3>Security</h3>
<p><strong>On May 20, 2026, we published a security bulletin for Apigee.</strong></p>
<p>A vulnerability was found in Apigee
(<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-2264">CVE-2026-2264</a>)
where the <code>IntegrationRegion</code>
parameter in the <code>SetIntegrationRequest</code> policy lacks validation,
allowing for Server-Side Request Forgery (SSRF) and service account token
exfiltration. The issue arises when an attacker can control a flow variable used
for <code>IntegrationRegion</code>, leading to requests being sent to an
attacker-controlled host with the service account token.</p>
<p><strong>Security bulletin published: <a href="https://docs.cloud.google.com/apigee/docs/security-bulletins/security-bulletins#gcp-2026-034">GCP-2026-034</a></strong></p>
<h2 class="release-note-product-title">BigQuery</h2>
<h3>Announcement</h3>
<p>BigQuery can re-execute instructions (queries) to try to proactively detect performance, correctness, or functional regressions.
These re-executions will have no side effects and will happen with no additional cost or resource consumption.
Data access logs may show <code>bigquery-adminbot@system.gserviceaccount.com</code> when BigQuery re-executes an instruction.</p>
<h3>Feature</h3>
<p><a href="https://docs.cloud.google.com/bigquery/docs/user-defined-functions-python">Python UDFs</a> are now
<a href="https://cloud.google.com/products/#product-launch-stages">Generally Available</a>
(GA).</p>
<p>You can use Python UDFs to implement a scalar function in Python and use it in a
SQL query. Python UDFs let you install third-party libraries from the
<a href="https://pypi.org/">Python Package Index (PyPI)</a> and let you access external
services using a <a href="https://docs.cloud.google.com/bigquery/docs/create-cloud-resource-connection">Cloud resource connection</a>.</p>
<h3>Feature</h3>
<p>You can now use the
<a href="https://docs.cloud.google.com/bigquery/docs/reference/standard-sql/bigqueryml-syntax-ai-agg"><code>AI.AGG</code> function</a>
to semantically aggregate unstructured input data based on natural language
instructions. This feature is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>.</p>
<h2 class="release-note-product-title">Cloud Service Mesh</h2>
<h3>Announcement</h3>
<p>Managed Cloud Service Mesh using the <code>TRAFFIC_DIRECTOR</code> implementation in the
stable channel now supports a limited implementation of the <code>EnvoyFilter</code> API.
To learn about the supported fields, extensions, and how to use <code>EnvoyFilter</code>
for features like local rate limiting see
<a href="https://docs.cloud.google.com/service-mesh/docs/data-plane-extensibility">Data plane extensibility with <code>EnvoyFilter</code></a>.</p>
<p>To troubleshoot any issue while configuring, see
<a href="https://docs.cloud.google.com/service-mesh/docs/troubleshooting/troubleshoot-data-plane-extensibility">Resolving data plane extensibility issues</a>.</p>
<h3>Announcement</h3>
<p>Cloud Service Mesh can now report a status code to indicate whether an Istio API
is accepted or rejected. You can view the status code on the resource and mesh
state. For more information see
<a href="https://docs.cloud.google.com/service-mesh/docs/troubleshooting/troubleshoot-configuration#membershipstate_error_codes">MembershipState Error Codes</a>.</p>
<h2 class="release-note-product-title">Confidential Space</h2>
<h3>Announcement</h3>
<p>Confidential Space image 260500 is available. This image introduces support
for <a href="https://docs.trustauthority.intel.com/main/articles/articles/ita/introduction.html">Intel Trust Authority (ITA)</a>
as an independent attestation verifier service for your workloads. This lets
you verify the identity, the hardware state, and the software state of the
Confidential Space environment directly using Intel's attestation service.</p>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Deprecated</h3>
<p><strong>NotebookLM Enterprise: The Podcast API is deprecated</strong></p>
<p>The <a href="https://docs.cloud.google.com/gemini/enterprise/notebooklm-enterprise/docs/podcast-api">Podcast API</a> is
deprecated. Google isn't allowlisting new customers.</p>
<p>This feature was available as GA with allowlist.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Change</h3>
<p><strong>Supervised fine-tuning available for Gemini 3.1 Flash Lite (Preview)</strong></p>
<p>Supervised fine-tuning is now available for limited support for the
<code>gemini-3.1-flash-lite</code> model. During this period, model tuning for Gemini
3.1 Flash Lite is restricted to <code>us-central1</code> and <code>europe-west4</code> and tuned model
serving is restricted to the <code>us</code> and <code>eu</code> multi-region endpoints.</p>
<p>See <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini-supervised-tuning">About supervised
fine-tuning</a>
for more information.</p>
<h3>Change</h3>
<p><strong>Set media resolution at a Part-level for data when using supervised fine-tuning</strong></p>
<p>Supervised fine-tuning now supports <code>Part</code>-level <code>mediaResolution</code> declarations
for images, videos, and PDFs. <code>Part</code>-level media resolution declarations also
support the <code>MEDIA_RESOLUTION_ULTRA_HIGH</code> level.</p>
<p>See the following media type–specific pages for more information:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/tune_gemini/doc_tune">Document tuning</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/tune_gemini/image_tune">Image tuning</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/tune_gemini/video_tune">Video tuning</a></li>
</ul>
<h2 class="release-note-product-title">Google Cloud VMware Engine</h2>
<h3>Announcement</h3>
<p>All 1-year <a href="https://docs.cloud.google.com/vmware-engine/docs/cud">committed use discounts (CUDs)</a> for Google Cloud VMware Engine <code>ve1</code> SKUs are now End-of-Sale across the europe-west2 (London, UK) region. You can continue to use <code>ve1</code> nodes with on-demand pricing. This change doesn't affect existing CUDs. You can also use <code>ve2</code> nodes, including <code>ve2</code> CUDs.</p>
<h2 class="release-note-product-title">Google SecOps Marketplace</h2>
<h3>Change</h3>
<p><strong>AlienVault USM Appliance</strong>: Version 27.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get PCAP Files For Events</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Protectwise</strong>: Version 6.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Get Pcap</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Service Desk Plus</strong>: Version 9.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Service Desk Plus V3</strong>: Version 9.0</p>
<ul>
<li>Refactored the code for the following action:
<ul>
<li><strong>Create Alert Request</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>ServiceNow</strong>: Version 66.0</p>
<ul>
<li>Updated the code for the following action:
<ul>
<li><strong>Update Incident</strong>: Added support for updating reference fields.</li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Google Chronicle</strong>: Version 83.0</p>
<ul>
<li>Added support for filtering alerts by rule type to the following connector:
<ul>
<li><strong>Google Chronicle - Chronicle Alerts Connector</strong></li>
</ul></li>
</ul>
<h3>Change</h3>
<p><strong>Tanium</strong>: Version 20.0</p>
<ul>
<li><strong>Integration</strong>: Added a partner header to all API requests.</li>
</ul>
<h2 class="release-note-product-title">Guest Environment</h2>
<h3>Fixed</h3>
<p>Version <code>20260511.00</code> of the <a href="https://docs.cloud.google.com/compute/docs/images/guest-agent">guest agent</a>
is now available for all supported operating systems. This is a rebuild of
version <code>20260423.01</code> announced in the
<a href="https://docs.cloud.google.com/compute/docs/images/guest-environment/release-notes#April_27_2026">April 27, 2026 release notes</a>.
It includes no additional changes and is released specifically to trigger a guest agent restart.</p>
<p>Between May 4, 2026, and May 11, 2026, the control plane accidentally sent an
erroneous request to remove the core plugin. This caused the agent to stop
functioning, which disrupted features that rely on it, such as SSH and Windows
password resets. This package update automatically restarts the agent on
instances where auto-update is enabled to resolve the issue.</p>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>Oracle Database@Google Cloud supports Oracle Cloud Infrastructure Goldengate. You can <a href="https://docs.cloud.google.com/oracle/database/docs/deploy-and-connect">create Goldengate deployments and connections</a> to replicate and transform data between systems.</p>
<p>This feature is <a href="https://cloud.google.com/products#product-launch-stages">Generally Available (GA)</a>.</p>
<h2 class="release-note-product-title">Secret Manager</h2>
<h3>Feature</h3>
<p>Secret Manager and Parameter Manager integrate with the Agent
Development Kit (ADK) to retrieve secrets and parameters securely at runtime.
This integration prevents the exposure of sensitive credentials to the LLM
context window or conversation history.</p>
<p>For more information, see the following resources:</p>
<ul>
<li><a href="https://docs.cloud.google.com/secret-manager/docs/integrate-secret-manager-with-adk">Manage secrets for external services in Agent Development Kit</a></li>
<li><a href="https://docs.cloud.google.com/secret-manager/parameter-manager/docs/parameter-manager-adk-integration">Parameter Manager integration with Agent Development Kit</a></li>
</ul>
]]>
    </content>
  </entry>

  <entry>
    <title>May 19, 2026</title>
    <id>tag:google.com,2016:gcp-release-notes#May_19_2026</id>
    <updated>2026-05-19T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/release-notes#May_19_2026"/>
    <content type="html"><![CDATA[<h2 class="release-note-product-title">Anti Money Laundering AI</h2>
<h3>Announcement</h3>
<p>Improvements to backtest API and recall metrics are now available with engine version <strong>v004.011</strong>. This includes support for Performance Targeting by number of parties required above threshold and a simplified recall metric calculation.</p>
<h2 class="release-note-product-title">Apigee hybrid</h2>
<h3>Announcement</h3>
<h3 id="v1163">v1.16.3</h3>
<p>On May 19, 2026 we released an updated version of the Apigee hybrid software, v1.16.3.</p>
<ul>
<li>For information on upgrading, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/upgrade">Upgrading Apigee hybrid to version v1.16.3</a>.</li>
<li>For information on new installations, see <a href="https://docs.cloud.google.com/apigee/docs/hybrid/v1.16/big-picture">The big picture</a>.</li>
</ul>
<aside class="note"><strong>Note:</strong><span> This is a patch release: The container images used in patch releases are integrated with the Apigee hybrid Helm charts. Upgrading to a patch via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see <a href="https://docs.cloud.google.com/apigee/docs/release/apigee-release-process#apigee-hybrid-container-images">Apigee release process</a>.</span></aside>
<h3>Fixed</h3>
<h4 id="fixed_in_this_release_2">Fixed in this release</h4>
<table>
<thead>
<tr>
<th>Bug ID</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>512866352</strong></td>
<td><strong>Fixed an issue where the <code>apigee-redis</code> pod entered a <code>CrashLoopBackOff</code> state when deployed with Vault-based secret injection due to a GLIBC version mismatch in the bundled <code>/bin/sh</code> and <code>/bin/cat</code> binaries.</strong></td>
</tr>
</tbody>
</table>
<h3>Feature</h3>
<p><strong>Custom environment variables for Guardrail pods (<code>guardrails.envVars</code>)</strong></p>
<p>Starting in version v1.16.3, you can inject custom environment variables into Apigee hybrid Guardrail pods using the new <code>guardrails.envVars</code> property in <code>overrides.yaml</code>. This is most commonly used to set <code>NO_PROXY</code> (or <code>no_proxy</code>) so that Guardrail pods bypass a configured forward HTTP proxy when calling internal in-cluster endpoints such as the Kubernetes API server, which previously failed in restricted-network environments with a global <code>httpProxy</code> configured. The property is supported on Guardrail pods for the following components: <code>apigee-datastore</code>, <code>apigee-env</code>, <code>apigee-ingress-manager</code>, <code>apigee-operator</code>, <code>apigee-org</code>, <code>apigee-redis</code>, <code>apigee-telemetry</code>, and <code>apigee-virtualhost</code>.</p>
<p>Example:</p>
<pre class="prettyprint lang-yaml"><code>guardrails:
  envVars:
    NO_PROXY: 'kubernetes.default.svc,172.20.0.1'
</code></pre>
<h2 class="release-note-product-title">Certificate Manager</h2>
<h3>Feature</h3>
<p>Certificate Manager (2nd gen) is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. Certificate Manager (2nd gen) offers a unified control plane to observe, manage, and automate certificates across your organization.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/certificate-manager/docs/v2/overview">Certificate Manager (2nd gen) overview</a>.</p>
<h2 class="release-note-product-title">Cloud Load Balancing</h2>
<h3>Feature</h3>
<p>Google tag gateway for advertisers lets website owners host and deploy Google
tags through Google Cloud. You can use a
global external Application Load Balancer to route measurement traffic on your website through your
domain for improved measurement data accuracy. This provides more reliable data
for advertising campaign optimization.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/load-balancing/docs/https#tag-gateway">Google tag gateway for advertisers</a>.</p>
<h2 class="release-note-product-title">Config Connector</h2>
<h3>Announcement</h3>
<p>Config Connector version 1.151.0 is now available.</p>
<h3>Change</h3>
<p>New Alpha Resources (Direct Reconciler):</p>
<ul>
<li>CloudDeployAutomation</li>
<li>ComputeFutureReservation</li>
<li>GKEHubMembershipBinding</li>
<li>GKEHubNamespace</li>
<li>GKEHubScopeRBACRoleBinding</li>
<li>NetworkServicesWasmPlugin</li>
<li>VertexAIDataLabelingJob</li>
</ul>
<h3>Feature</h3>
<p>New Fields:</p>
<ul>
<li><a href="https://cloud.google.com/config-connector/docs/reference/resource-docs/memorystore/memorystoreinstance"><code>MemorystoreInstance</code></a>
<ul>
<li>Added <code>spec.automatedBackupConfig</code> field.</li>
<li>Added <code>spec.crossInstanceReplicationConfig</code> field.</li>
<li>Added <code>spec.maintenanceVersion</code> field.</li>
<li>Added <code>status.observedState.availableMaintenanceVersions</code> field.</li>
<li>Added <code>status.observedState.crossInstanceReplicationConfig</code> field.</li>
<li>Added <code>status.observedState.effectiveMaintenanceVersion</code> field.</li>
<li>Added <code>status.observedState.pscAttachmentDetails</code> field.</li></ul></li></ul>
<h3>Fixed</h3>
<ul>
<li><a href="https://docs.cloud.google.com/config-connector/docs/reference/resource-docs/bigquerydatatransfer/bigquerydatatransferconfig"><code>BigQueryDataTransferConfig</code></a>
<ul>
<li>Fix resource duplication loop.</li>
</ul></li>
<li><a href="https://docs.cloud.google.com/config-connector/docs/reference/resource-docs/container/containercluster"><code>ContainerCluster</code></a>
<ul>
<li>Enable projectID to projectNumber transform in fields in Container LROs.</li></ul></li></ul>
<h2 class="release-note-product-title">Gemini Enterprise</h2>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Data store for Crossbeam (Preview)</strong></p>
<p>You can now connect Crossbeam data stores to Gemini Enterprise.</p>
<p>Support for Crossbeam data stores is in Public Preview. For more information, see <a href="https://docs.cloud.google.com/gemini/enterprise/docs/connectors/crossbeam">Connect Crossbeam</a>.</p>
<h3>Feature</h3>
<p><strong>Gemini Enterprise: Use Gemini 3.5 Flash (GA)</strong></p>
<p>Gemini 3.5 Flash is generally available (GA) in the Global, US, and
EU regions with Gemini Enterprise. Users can select it in the model selector
dropdown within the Gemini Enterprise app assistant and in Agent Designer.</p>
<p>As Gemini 3.5 Flash is the current GA Flash model, Gemini 2.5
Flash is removed from the model selector. Administrators can't toggle
Gemini 3.5 Flash off.</p>
<p>For more information about feature controls, see
<a href="https://docs.cloud.google.com/gemini/enterprise/docs/manage-web-app-features">Manage features on the web app</a>.</p>
<h3>Feature</h3>
<p><strong>NotebookLM Enterprise: Create slide decks and infographics</strong></p>
<p>You can create slide decks and infographics using
NotebookLM Enterprise. This feature is generally available (GA).
For more information on the usage limits, see <a href="https://docs.cloud.google.com/gemini/enterprise/notebooklm-enterprise/docs/overview#usage-limits">Usage limits</a>.</p>
<h2 class="release-note-product-title">Gemini Enterprise Agent Platform</h2>
<h3>Feature</h3>
<p><strong>Gemini 3.5 Flash is generally available (GA)</strong></p>
<p>For details, see the <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/gemini/3-5-flash">model specifications page</a>.</p>
<h3>Feature</h3>
<p><strong>Manage agent revisions and traffic splitting</strong></p>
<p>Agent revisions and traffic splitting are now available in public preview. You
can create immutable revisions of deployed agents, and split traffic between the
different active revisions. This enables canary deployments and safe testing of
new agent versions. For more information, see
<a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/scale/runtime/manage-revisions-and-traffic">Manage revisions and traffic</a>.</p>
<h3>Feature</h3>
<p><strong>Manage and discover agent skills with Skill Registry</strong></p>
<p>Manage and discover agent skills with the Skill Registry, in public preview.
This secure, private, and low-latency repository stores skills as
self-contained packages, including instructions, code, and documentation, to
enhance agent abilities.</p>
<p>For more information, see:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/skill-registry">Skill Registry overview</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/skill-registry/create-manage">Create and manage skills</a></li>
</ul>
<h3>Feature</h3>
<p><strong>Managed Agents API on Agent Platform released in Preview</strong></p>
<p>The Managed Agents API on Agent Platform has been released in Preview.</p>
<p>This feature allows you to build and scale autonomous agents, including those
built from configuration using the Antigravity harness. These agents run in a
fully managed and isolated sandbox environment, equipped with tools and skills,
and can be interacted with via a dedicated API.</p>
<p>For more information, see the following:</p>
<ul>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents">Managed Agents API on Agent Platform overview</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/create-manage">Create and manage agents</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/interact-with-agents">Interact with agents</a></li>
<li><a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/sandbox-environment">Managed Agents API on Agent Platform sandbox environment</a></li>
</ul>
<h3>Feature</h3>
<p><strong>AI Content Detection API available</strong></p>
<p>AI Content Detection API is available in <a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. For details see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/models/ai-content-detection">AI Content Detection</a>.</p>
<h3>Feature</h3>
<p><strong>Provisioned Throughput for Gemini now supports latency SLA</strong></p>
<p>Provisioned Throughput now provides a tokens per second latency SLA,
covering generation speed from the first returned token to the last.</p>
<p>For more information, see the
<a href="https://cloud.google.com/vertex-ai/generative-ai/sla?e=48754805">Gemini Enterprise Agent Platform Online Inference Service Level Agreement
(SLA)</a>.</p>
<h3>Change</h3>
<p>Memory Bank and Sessions support for multi-regional and global endpoints is in
<a href="https://cloud.google.com/products#product-launch-stages">Preview</a>. For more,
see <a href="https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/agent-locations#multi-regional_and_global_endpoints">Supported locations for agents in Agent Platform</a>.</p>
<h2 class="release-note-product-title">Google Cloud Contact Center as a Service</h2>
<h3>Announcement</h3>
<p><strong>Google Cloud CCaaS 4.30</strong></p>
<p>We've released version 4.30 of Google Cloud CCaaS.</p>
<p>The timing of the update to your instance depends on the deployment schedule
that you have chosen. For more information, see <a href="https://cloud.google.com/contact-center/ccai-platform/docs/deployment-schedules">Deployment
schedules</a>.</p>
<h3>Feature</h3>
<p><strong>Skip the IVR greeting message</strong></p>
<p>You can now configure your instance to skip the IVR greeting message.</p>
<p>Administrators: A new <strong>Skip IVR Greeting</strong> option is available in the
<strong>Settings <span aria-label="and then">&gt;</span> Languages &amp; Messages <span aria-label="and then">&gt;</span> IVR-specific
Messages</strong> section.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/customizing_languages_recordings_messages#configure-ivr-specific-messages">Customize IVR-specific
messages</a>.</p>
<h3>Feature</h3>
<p><strong>Headless web SDK: advanced call scheduling is turned on by default</strong></p>
<p>The <code>useAdvancedCallScheduling</code> parameter in the headless SDK is now set to
<code>true</code> by default.</p>
<h3>Feature</h3>
<p><strong>Queue status endpoint</strong></p>
<p>The new queue status endpoint provides real-time data for leaf queues, including
estimated wait times, agent availability, callback slot capacity, hours of
operation, and holidays. This capability lets voice AI systems dynamically
decide whether to escalate a call to a live agent or offer scheduled callback
windows to the caller. You can access the queue status endpoint in the apps API:
<code>GET /apps/api/v1/queues/status</code>.</p>
<p>For more information, see <a href="https://docs.cloud.google.com/contact-center/ccai-platform/docs/apps-api-queue-status-endpoint">The queue status
endpoint</a>.</p>
<h3>Feature</h3>
<p><strong>For call transfers in HubSpot, the ticket owner is automatically updated</strong></p>
<p>When a call is transferred from one agent to another with a HubSpot integration,
HubSpot tickets now automatically update to reflect the new ticket owner. This
provides an accurate record of ownership throughout the interaction lifecycle.
No configuration is required.</p>
<h3>Fixed</h3>
<p>This release addresses the following issues:</p>
<ul>
<li><p>Fixed an issue where email messages in some queues displayed a blank white
panel when opened.</p></li>
<li><p>Fixed an issue that occurred when a closed ticket ID was passed to HubSpot
using the SDK. The ticket wasn't reopened, resulting in new tickets being
created.</p></li>
<li><p>Fixed an issue where agents could paste images into the chat adapter even
when the <strong>Allow agents to attach files</strong> setting was turned off.</p></li>
<li><p>Fixed an issue where the agent adapter displayed generic error messages
instead of call failure reasons such as <code>Busy</code> or <code>No answer</code>.</p></li>
<li><p>Fixed an issue where chat history wasn't deleted after a session ended,
causing the agent desktop to become unstable for high-volume agents.</p></li>
<li><p>Fixed an issue where the NICE WFM ASCWS heartbeat timed out, causing agents
to appear inactive and disrupting adherence reporting.</p></li>
<li><p>Fixed an issue where virtual agents unexpectedly disconnected during inbound
IVR calls, causing the calls to escalate to a human agent.</p></li>
<li><p>Fixed an issue where customer utterances were missing from the Live
Transcript when conversations were transferred from a Dialogflow CX agent to
a human agent.</p></li>
<li><p>Fixed an issue where, when an agent searched for a queue during a chat
transfer, the queue appeared with <code>No logged in agents</code> when agents were
available.</p></li>
<li><p>Fixed an issue where launching a task virtual assistant during a chat caused
the agent's screen to freeze.</p></li>
<li><p>Fixed an issue where call transcripts from CX Agent Studio agent
conversations were added to CRM records as garbled and unreadable text, with
repeated words and incorrect turn order.</p></li>
<li><p>Fixed an issue where the <strong>Wait Time</strong> custom field on Zendesk tickets
displayed an incorrect value when using custom fields for <strong>Account</strong> and
<strong>Record</strong>.</p></li>
<li><p>Fixed an issue where agents assigned a direct SMS-capable line didn't
receive visual notifications for incoming SMS chats in the agent adapter
while their status was set to <code>Unavailable</code>.</p></li>
<li><p>Fixed an issue where some chat transcripts couldn't be downloaded from the
<strong>Completed Chats</strong> page.</p></li>
<li><p>Fixed an issue where customer calls were unexpectedly abandoned during
payment transactions when DTMF inputs were provided.</p></li>
<li><p>Fixed an issue where agents heard repeated call notification sounds during
active calls, even when no new call was assigned.</p></li>
<li><p>Fixed an issue where only English IVR queues appeared when configuring
agent-specific deflection settings, even when other language queues were
available.</p></li>
</ul>
<!--
-   Fixed an issue where sentiment analysis didn't display to agents when calls
    were escalated from a virtual agent, even though the data was generated.
-->
<ul>
<li><p>Fixed an issue where email messages in queues displayed a blank white panel
when opened.</p></li>
<li><p>Fixed an issue where chat transcript and metadata files were generated as
empty files, causing API timeouts and blocking reporting pipelines.</p></li>
<li><p>Fixed an issue where chat sessions that ended due to end-user inactivity
were marked as <strong>Disconnected by end user</strong> instead of <strong>Timeout: end user
stopped responding</strong>.</p></li>
<li><p>Fixed an issue where agents couldn't receive more than 12 concurrent chats
despite being configured for up to 30.</p></li>
<li><p>Fixed an issue where virtual agent calls were routed back to the original
queue instead of being handled as expected.</p></li>
<li><p>Fixed an issue that occurred when a third party was added to a call. After
all participants left the call, the call still appeared to be connected.</p></li>
<li><p>Fixed an issue where cascade conditions for agent queues didn't correctly
enforce the minimum number of available UK agents before allowing calls to
cascade from the US queue, resulting in calls being routed incorrectly.</p></li>
<li><p>Fixed an issue where bulk user import incorrectly limited the chat
concurrency value to the global default, preventing valid per-agent settings
from being uploaded.</p></li>
</ul>
<h2 class="release-note-product-title">Managed Service for Apache Spark</h2>
<h3>Announcement</h3>
<p>New <a href="https://docs.cloud.google.com/managed-spark/docs/concepts/versioning/image-version-lists#supported-dataproc-image-versions"><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine) subminor cluster image versions</a>:</p>
<ul>
<li>2.1.114-debian11, 2.1.114-rocky8, 2.1.114-ubuntu20, 2.1.114-ubuntu20-arm</li>
<li>2.2.82-debian12, 2.2.82-rocky9, 2.2.82-ubuntu22, 2.2.82-ubuntu22-arm</li>
<li>2.3.30-debian12, 2.3.30-ml-ubuntu22, 2.3.30-rocky9, 2.3.30-ubuntu22, 2.3.30-ubuntu22-arm</li>
</ul>
<h3>Breaking</h3>
<p><strong>Managed Service for Apache Spark</strong> (formerly Dataproc on Compute Engine):
The configuration for Spark shuffle partitions (<code>spark.sql.shuffle.partitions</code>) has changed from an integer to a string type.</p>
<p>This change impacts image versions <code>2.3.30</code> and later in version <code>2.3</code>, and <code>2.2.82</code> and later in version <code>2.2</code>.</p>
<ul>
<li><strong>Impact:</strong> This change only affects users who are programmatically setting the configuration in code using <code>spark.conf.set()</code> with an integer literal.
<ul>
<li><strong>Impacted example:</strong> <code>spark.conf.set("spark.sql.shuffle.partitions", 100)</code></li>
</ul></li>
<li><strong>User action:</strong> Update your code to pass a string literal instead of an integer.
<ul>
<li><strong>Example fix:</strong> <code>spark.conf.set("spark.sql.shuffle.partitions", "100")</code></li>
</ul></li>
<li><strong>Not impacted:</strong> Setting the configuration via command-line arguments (e.g., <code>spark-submit --conf spark.sql.shuffle.partitions=100</code>), properties files, or Spark SQL commands (<code>spark.sql("SET spark.sql.shuffle.partitions=100")</code>) remains unaffected, as these methods naturally parse the input as strings.</li>
</ul>
<h2 class="release-note-product-title">Oracle Database@Google Cloud</h2>
<h3>Feature</h3>
<p>Oracle Database@Google Cloud lets you <a href="https://docs.cloud.google.com/oracle/database/docs/manage-dr-type">enable Autonomous Data Guard for local peer databases</a>.</p>
<p>This feature is <a href="https://cloud.google.com/products#product-launch-stages">Generally Available (GA)</a>.</p>
<h2 class="release-note-product-title">Security Command Center</h2>
<h3>Change</h3>
<p><a href="https://docs.cloud.google.com/security-command-center/docs/vulnerability-assessment-google-cloud">Vulnerability Assessment for Google Cloud</a>
supports scanning XFS and NTFS disk partition types.</p>
<h2 class="release-note-product-title">Virtual Private Cloud</h2>
<h3>Feature</h3>
<p>The <a href="https://docs.cloud.google.com/vpc/docs/release-notes#December_19_2023">December 2023 release notes</a>
include a release note for the <strong>General Availability</strong> of
Organization Policy Service custom constraints that provide more granular
control over specific fields for some VPC resources.</p>
<p>This feature has been available in <strong>General Availability</strong> since December
19, 2023, but the release note was previously omitted.</p>
<p>For more information, see
<a href="https://docs.cloud.google.com/vpc/docs/custom-constraints">Manage VPC resources by using custom organization policies</a>.</p>
<h3>Feature</h3>
<p>You can cancel pending deletion requests for VPC Network Peering connections
that are in consensus mode. This feature is available in <strong>Preview</strong>.
For more information, see
<a href="https://docs.cloud.google.com/vpc/docs/using-vpc-peering#cancel-delete">Cancel a deletion request</a>.</p>
]]>
    </content>
  </entry>

</feed>
