# 5.0.0-ec.6
Created: 2026-08-14 09:16:44 +0000 UTC
Image Digest: `sha256:224ce6435e8e5b46cdf3b94f89fbf0ecab8d570155b368ce1187ac9f09577a2e`
## Changes from 5.0.0-ec.5
### Components
* Kubectl 1.36.2
* Kubernetes 1.36.2
* Kubernetes Tests upgraded from 1.35.1 to 1.36.2
* Red Hat Enterprise Linux CoreOS 10.2 upgraded from 10.2.20260724-0 to 10.2.20260808-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| NewOLMPreflightPermissionChecks
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| RouteExternalCertificate
(0 tests)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed)| Unconditionally Enabled
(Changed) |
| AWSDualStackInstall
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| IngressControllerMultipleHAProxyVersions
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| IrreconcilableMachineConfig
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| CRIOCredentialProviderConfig
(0 tests)| Disabled| Enabled
(Changed)| Disabled
(Changed)| Enabled| Disabled| Enabled
(Changed)| Disabled
(Changed)| Enabled |
| NoRegistryClusterInstall
(0 tests)| Disabled| Enabled
(Changed)| Disabled| Enabled| Disabled| Enabled
(Changed)| Disabled| Enabled |
| GatewayAPIManagementMode
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
### New images
* [agentic-skills](https://github.com/openshift/agentic-skills) git [39429747](https://github.com/openshift/agentic-skills/commit/39429747952afd5e3c56fd86299f8a7614d27a79) `sha256:a48d73f252982b1cb3269052d51137dc38a7a7a7e05d3b40ac2116f663f399a1`
* [oc-mirror](https://github.com/openshift/oc-mirror) git [9054b9a9](https://github.com/openshift/oc-mirror/commit/9054b9a94cf71f27d141c72807928ded09dadb8e) `sha256:b1fac691e89d8854b14b866c1cc75867f3ea8f13cf52faa31fb59b390a619be1`
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [8264c02d](https://github.com/openshift/apiserver-network-proxy/commit/8264c02deda9abb6cd9a6a5c23305428431473c2) `sha256:52a24d0e448c7ba9e769b0b55d97672df449f3137da32be0eab4127656e377eb`
* [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler) git [e4ff2aae](https://github.com/openshift/aws-node-termination-handler/commit/e4ff2aaec292db42de9f3eef4908ba1c421a2a6c) `sha256:b036a926094231bd549f51f618af51cd3df4d8c7ade30c22d8e43b3630c7c6db`
* [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms) git [ca3d747d](https://github.com/openshift/azure-kubernetes-kms/commit/ca3d747de321b88a2c606e546851d1841d2fab9f) `sha256:87bb0c85b299f3ccecea2c4c8b1716f5661030f555f8332030d92314b9586ca3`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [0611cd27](https://github.com/openshift/azure-service-operator/commit/0611cd27b9eaa4a1fa8e0ab8ddc85352a61903e0) `sha256:17764a1d445464a8c1c0a71cc4b0c7d9d435c3e501ee97c1cf6fc7099b6dc962`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [f2b0db19](https://github.com/openshift/cluster-api-provider-baremetal/commit/f2b0db1919fff1344bc68948894c6775c0bf24a3) `sha256:44333b86e1b802f4a1f014d96e05f454e713967bdbd33dec69a4f996758af637`
* [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg) git [66007361](https://github.com/openshift/baremetal-runtimecfg/commit/660073616802e3d1258a036f2e57ca18a7baafa0) `sha256:fa8d7e32495f96c1cb4a6840cfc7596cdc0bfc431dbe74d428e108fdbbbc5d86`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [7b1593a4](https://github.com/openshift/cluster-bootstrap/commit/7b1593a47898b6a97dc457efaca464624e9f2afa) `sha256:37339e97f0ad1f227c1fbb69446ce006dd33480cd7c3a0f36a4aac9428e4eb94`
* [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator) git [4e72164b](https://github.com/openshift/cluster-kube-controller-manager-operator/commit/4e72164b8bc505033ad565ab01d57963e7c9688e) `sha256:f50263472e9da2475c450b1d4687408d0e132ca09fd251f9f7542e8ff1c6afb6`
* [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator) git [56fa3254](https://github.com/openshift/cluster-kube-scheduler-operator/commit/56fa325466a1f2a2d41435ba3a58b2bf8fdab2f3) `sha256:379483f75d8b8e2cfd20046fb56f45a13ab6073e9317f808be5eeb7f4bbcce2c`
* [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator) git [f5d3bfe6](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/commit/f5d3bfe64bda67ffb8299af01ebf2722287edf04) `sha256:d46f17475a02e2241628d66717a730a80fd82ddfb2a36d0cffe31f717f685784`
* [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator) git [34f95b07](https://github.com/openshift/cluster-openshift-controller-manager-operator/commit/34f95b07f4afbc47558e54e4fa2710fd692e615e) `sha256:cbe2eed8db0431015758fa6ba3819301743c8cb540a3079482686818c688e424`
* [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller) git [01afc4aa](https://github.com/openshift/cluster-policy-controller/commit/01afc4aac71a8e8be26383a0421bed7673391750) `sha256:9cb7ead318e92b63e4f9f6bf76b10cab05175dae358c1952fd11097584d1a702`
* [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator) git [eee95bab](https://github.com/openshift/cluster-samples-operator/commit/eee95babd52053191e29355108f7daf149dfbf8f) `sha256:cf39c48a9ddcc90a5e807a72a0754c46720756ffd66d07c5d1c2e2363064dc10`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [9607604d](https://github.com/openshift/cluster-update-keys/commit/9607604d35acee234051bd0da8a14321b4edd38e) `sha256:837e15f1e983a3fbe5ad26ab5f8a0cbb81fb58954e8a0ba474bb8b7b72a14773`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [ce80869a](https://github.com/openshift/configmap-reload/commit/ce80869a83b55ebbdc21a5550ec5747645203bd2) `sha256:a0a363a55e8838ae31818787772f7f624987f518fe6058f18da2255bde99379f`
* [container-networking-plugins](https://github.com/openshift/containernetworking-plugins) git [d6f73950](https://github.com/openshift/containernetworking-plugins/commit/d6f73950658d258e0ddbf2a4ac92e13ac840158b) `sha256:2546f2a340bad19727ecb4f8d604ba926ea3e92b2ca59546a524388b7b57f8b5`
* [containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins) git [d6f73950](https://github.com/openshift/containernetworking-plugins/commit/d6f73950658d258e0ddbf2a4ac92e13ac840158b) `sha256:2fb12d8ff70b5ce4e8ad4b6594ef4143a5bb78373e12ac9fe3c8415bc0e34d5d`
* [coredns](https://github.com/openshift/coredns) git [37aaba89](https://github.com/openshift/coredns/commit/37aaba896e97f4b9a091aab6d36f2213b8854474) `sha256:a8f28dc3ce1e5cf58fbe49a1a15417674c3b5749254a672d79a4e46f6c889e09`
* [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata) git [239703c6](https://github.com/openshift/csi-external-snapshot-metadata/commit/239703c637e005cf785892d214d219add70e3533) `sha256:3c2f0b968b8af0f7c1a2e69927622f7a90bfc6763a10c2757c5a9e0acfe87e7d`
* [docker-builder](https://github.com/openshift/builder) git [2cda03a9](https://github.com/openshift/builder/commit/2cda03a93696d4620703848471b3b873b0b2fa1e) `sha256:d1f0d1a8c3e80c447b74d85d526364f88b543290a8ec239b392c6543033896a1`
* [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator) git [be4fd017](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/commit/be4fd01725ce5ab0b47f846c905a349aeee8ab53) `sha256:31d359744f38667cb3f8bdc8cd3b723f3681921871aaf48fb6442c0017fee953`
* [keepalived-ipfailover](https://github.com/openshift/images) git [13118bff](https://github.com/openshift/images/commit/13118bff15103b31a6528bf8de2d0d6de05f4742) `sha256:e8944ed7540b927ef2bb10d9d64683f486428038b182f7840ee4ad32db35edb8`
* [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [43c114bc](https://github.com/openshift/kube-rbac-proxy/commit/43c114bc124f59e2fc3223dea8e0a8f4cdeed18d) `sha256:ec8e0c1495375f2786b536aa59a431417ced6c055b5d920bd81c9e0e59b268c0`
* [kube-state-metrics](https://github.com/openshift/kube-state-metrics) git [019ecc7d](https://github.com/openshift/kube-state-metrics/commit/019ecc7d533333dfd3bf8893e78cd7ec6e282f01) `sha256:22f64667e0c1152fa0913cb8bbc249b16e2c2cf71bbe3d74f05049bf5b8443e9`
* [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [72835e43](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/72835e43c7754356645e41031f3a99926b4d42e6) `sha256:4bc20086cfb932870f0f7cda0cb04a5ef72b3ca559fc67c8211b47c264be18d7`
* [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt) git [5eb884ab](https://github.com/openshift/cloud-provider-kubevirt/commit/5eb884abcd2ff17ae8d7b2691ca12494597c08a6) `sha256:05975183eec3d0668964c229cfe5af28c936872dde09e34c7ed8e65976a6498a`
* [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver) git [7ff99994](https://github.com/openshift/kubevirt-csi-driver/commit/7ff99994ecc3a675fac6f9aa7fa418cdb0dca32b) `sha256:b6faa66030114ecdbb2463c98f0632360491fa38e55a269ca9ca09cb93463ad0`
* [multus-admission-controller](https://github.com/openshift/multus-admission-controller) git [4bb2e206](https://github.com/openshift/multus-admission-controller/commit/4bb2e2069c3e4f11fbc4c1befd6dc1c41fa802b7) `sha256:13bb073fc2f2def81c573d64b49a4a88f698eb3deff16ea97ff17f74ef5ab1e2`
* [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [932bdaa4](https://github.com/openshift/multus-networkpolicy/commit/932bdaa4250d0a1db41a1a1fcac8192f2757211c) `sha256:2beeef27a13f5e988d89d8933a6b95269e0232d3e2b864f1e5c01eb169ba7881`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [08af4127](https://github.com/openshift/route-override-cni/commit/08af4127c77976510cad1c096d9aca977d8ae5af) `sha256:0ab001d5b19395e34c828f3142396ddcab46094f162efdb664f56c2fda98b314`
* [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni) git [d918bda2](https://github.com/openshift/whereabouts-cni/commit/d918bda28ad3d0200b6e4f2ef2801556764762e5) `sha256:245ef8b52a29fe6d350037b9a448be75b165ce17f0e922c60b988346b3dc0f6f`
* [network-interface-bond-cni](https://github.com/openshift/bond-cni) git [19d390fd](https://github.com/openshift/bond-cni/commit/19d390fd4d353619fdfb5e0070962d2ddf54b5bb) `sha256:659ccdb2076786967ca16d64750d4cdd515a8791cf63cab4483020675975840b`
* [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon) git [e0fc86da](https://github.com/openshift/network-metrics-daemon/commit/e0fc86dadfa62716b69d2ed9e084f9dcd0fc8844) `sha256:000d2baa799cac61fd78f8f476c3ad1b876eded584db591b6299c49715e3596b`
* [network-tools](https://github.com/openshift/network-tools) git [0b53ac3d](https://github.com/openshift/network-tools/commit/0b53ac3dccf59cd169555bf18c207122374bf003) `sha256:ddd98803f304743e966bf42f98d65ee4dd6773a3f3f0777a602e242ae1bee7fb`
* [oauth-apiserver](https://github.com/openshift/oauth-apiserver) git [688f57b5](https://github.com/openshift/oauth-apiserver/commit/688f57b5af12182644b33b770151352b1d54df3a) `sha256:c950e27479f71e47ff155e4e213e6bef8a4204ee9b7e4bb7996a36ec25ff8787`
* [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager) git [5631cf49](https://github.com/openshift/openshift-controller-manager/commit/5631cf493b006cbc72a8600a7435813272d71940) `sha256:7db8f714bd437a0b108428452207cc986cd8c80fc53bd62b053b0ab2815c4b52`
* [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [0e12f5d6](https://github.com/openshift/openshift-state-metrics/commit/0e12f5d6df02b37b0353a747d144e8069c3d0c2a) `sha256:fb5130c57ff54f4ae5df19e2a018f41e148539a4c0bb4fca56616e094a027057`
* [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack) git [6b30092b](https://github.com/openshift/machine-api-provider-openstack/commit/6b30092b0a1196b016f4300b79c895f0e7f2e9a8) `sha256:c5b02d812b8f533bb2dc8bd1bac35d02bc8b94c7799faf8d912be37c3da5b65f`
* [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller) git [58dbc048](https://github.com/openshift/openstack-resource-controller/commit/58dbc0482c144c21effee2476947889122a518eb) `sha256:5d8677f7acb484459d27416cf172e6e51315cb187821ed82b8a5641ca4540a0e`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [4ab9ff73](https://github.com/openshift/prom-label-proxy/commit/4ab9ff73c665319352288fe0b9b9e1df71832525) `sha256:6a01bfd588723c920088e343a4f261546a9d9ae24d68aba621d8dcf29828a8ef`
* [route-controller-manager](https://github.com/openshift/route-controller-manager) git [59697cf7](https://github.com/openshift/route-controller-manager/commit/59697cf7af4517dd44e28179a57f7f35b6ea0e22) `sha256:e70f354cf477a6eaa47d39acfef5cdcbe1ae206df421be4ee9dc95e66643281b`
* [telemeter](https://github.com/openshift/telemeter) git [22ba1701](https://github.com/openshift/telemeter/commit/22ba1701333f3fd26490cc15b89ddf21df3f67f6) `sha256:ea57c6f918eba529aa645f4d82ef686e295b75cd80f7d327cec68dbe1a6ec76e`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/90c28e0308dcbc321654cdbcb4cb958550037240)
* [OCPBUGS-93750](https://issues.redhat.com/browse/OCPBUGS-93750): Bump github.com/moby/moby to v28.5.2 [#10680](https://github.com/openshift/assisted-service/pull/10680)
* [MGMT-24827](https://issues.redhat.com/browse/MGMT-24827): Resource-scoped auth for urlAuth endpoints [#10667](https://github.com/openshift/assisted-service/pull/10667)
* [MGMT-24831](https://issues.redhat.com/browse/MGMT-24831): Add ntpSources field to InfraEnv and AgentClusterInstall CRDs [#10756](https://github.com/openshift/assisted-service/pull/10756)
* [ACM-30180](https://issues.redhat.com/browse/ACM-30180): Honor cluster TLS security profile in Infrastructure Operator [#10734](https://github.com/openshift/assisted-service/pull/10734)
* NO-ISSUE: [master] Bump OCP versions: 4.22 [#10735](https://github.com/openshift/assisted-service/pull/10735)
* [MGMT-24939](https://issues.redhat.com/browse/MGMT-24939): (assisted-service) Upgrade operator-sdk from v1.10.1 to v1.42.3 (kubebuilder v3→v4 migration) [#10716](https://github.com/openshift/assisted-service/pull/10716)
* NO-ISSUE: [master] Bump OCP versions: 4.16, 4.14, 5.0 [#10733](https://github.com/openshift/assisted-service/pull/10733)
* [MGMT-24903](https://issues.redhat.com/browse/MGMT-24903): Fall back to CoreOS image from worker ignition for day-2 persistent-boot [#10717](https://github.com/openshift/assisted-service/pull/10717)
* [MULTIARCH-6274](https://issues.redhat.com/browse/MULTIARCH-6274): agent: Enable platform external s390x [#10424](https://github.com/openshift/assisted-service/pull/10424)
* [MGMT-24352](https://issues.redhat.com/browse/MGMT-24352): Reset finalizing timeout on transition from installing-pending-user-action [#10293](https://github.com/openshift/assisted-service/pull/10293)
* [OCPBUGS-97919](https://issues.redhat.com/browse/OCPBUGS-97919): fix: use typed credentials key to support MAC-based fencing in ABI flow [#10477](https://github.com/openshift/assisted-service/pull/10477)
* [ACM-38238](https://issues.redhat.com/browse/ACM-38238): Assisted-installer repos: Set Up Set up Renovate configuration to automatically create Hive API Synchronization PRs [#10711](https://github.com/openshift/assisted-service/pull/10711)
* [OCPBUGS-91733](https://issues.redhat.com/browse/OCPBUGS-91733): manifest_generator add a label to LUKS root [#10676](https://github.com/openshift/assisted-service/pull/10676)
* NO-ISSUE: [master] Bump OCP versions: 4.18, 4.19 [#10724](https://github.com/openshift/assisted-service/pull/10724)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [SECURITY] [#10718](https://github.com/openshift/assisted-service/pull/10718)
* NO-ISSUE: [master] Bump OCP versions: 4.20, 4.21, 4.22 [#10715](https://github.com/openshift/assisted-service/pull/10715)
* And 4 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/assisted-service/compare/f46558c1df1388bc21448ae7fd3b249febb29798...90c28e0308dcbc321654cdbcb4cb958550037240)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/02d30997f8496c348ea45c4f950f360574178e45)
* [MGMT-24598](https://issues.redhat.com/browse/MGMT-24598): CVE-2026-42306 Bump assisted-service dep to pick up docker v28.5.2 [#2219](https://github.com/openshift/assisted-installer/pull/2219)
* [OCPBUGS-96799](https://issues.redhat.com/browse/OCPBUGS-96799): Bump golang.org/x/net from v0.48.0 to v0.55.0 [#2244](https://github.com/openshift/assisted-installer/pull/2244)
* [OCPBUGS-96696](https://issues.redhat.com/browse/OCPBUGS-96696): Wait for all nodes to join before exiting for ABI [#2230](https://github.com/openshift/assisted-installer/pull/2230)
* [ACM-38238](https://issues.redhat.com/browse/ACM-38238): Assisted-installer repos: Set Up Set up Renovate configuration to automatically create Hive API Synchronization PRs [#2224](https://github.com/openshift/assisted-installer/pull/2224)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/e4afa401ce7d4f8a24a857fd2edf3338fef1556e...02d30997f8496c348ea45c4f950f360574178e45)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/aeec165131a4c528174a58a011d1c3c31cfd7cc1)
* [MGMT-24597](https://issues.redhat.com/browse/MGMT-24597): CVE-2026-42306 Bump assisted-service dep to pick up docker v28.5.2 [#1560](https://github.com/openshift/assisted-installer-agent/pull/1560)
* NO-ISSUE: Refresh RPM lockfiles RPM lockfile refresh [#1578](https://github.com/openshift/assisted-installer-agent/pull/1578)
* [MGMT-24903](https://issues.redhat.com/browse/MGMT-24903): Preserve encapsulated MachineConfig in filtered ignition [#1568](https://github.com/openshift/assisted-installer-agent/pull/1568)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/bfa655c8a4905031aab68000b84535674413f3b4...aeec165131a4c528174a58a011d1c3c31cfd7cc1)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/c031572a47209d362aec8f775cdbef7d0ae4a172)
* [OCPBUGS-101759](https://issues.redhat.com/browse/OCPBUGS-101759): Update Konflux references [#331](https://github.com/openshift/agent-installer-utils/pull/331)
* [OCPBUGS-99905](https://issues.redhat.com/browse/OCPBUGS-99905): Update Konflux references [#303](https://github.com/openshift/agent-installer-utils/pull/303)
* [OCPBUGS-99745](https://issues.redhat.com/browse/OCPBUGS-99745): Use Operator catalog in 4.22 for OVE [#323](https://github.com/openshift/agent-installer-utils/pull/323)
* [OCPBUGS-87367](https://issues.redhat.com/browse/OCPBUGS-87367): Updating ose-agent-installer-utils-container image to be consistent with ART for 5.0 [#308](https://github.com/openshift/agent-installer-utils/pull/308)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/4c1ca15266d79b638bb0bc376b9536522f302025...c031572a47209d362aec8f775cdbef7d0ae4a172)
### [aws-cloud-controller-manager, aws-cluster-api-controllers, aws-ebs-csi-driver, aws-ebs-csi-driver-operator, aws-machine-controllers, aws-pod-identity-webhook, azure-cloud-controller-manager, azure-cloud-node-manager, azure-cluster-api-controllers, azure-disk-csi-driver, azure-disk-csi-driver-operator, azure-file-csi-driver, azure-file-csi-driver-operator, azure-machine-controllers, azure-workload-identity-webhook, csi-driver-manila, csi-driver-manila-operator, csi-driver-nfs, gcp-cloud-controller-manager, gcp-cluster-api-controllers, gcp-machine-controllers, gcp-pd-csi-driver, gcp-pd-csi-driver-operator, hyperkube, ironic, ironic-agent, ironic-machine-os-downloader, ironic-static-ip-manager, kube-proxy, machine-image-customization-controller, nutanix-cloud-controller-manager, nutanix-machine-controllers, pod, powervs-block-csi-driver, powervs-block-csi-driver-operator, powervs-cloud-controller-manager, powervs-machine-controllers, vsphere-cloud-controller-manager, vsphere-cluster-api-controllers, vsphere-csi-driver, vsphere-csi-driver-operator, vsphere-csi-driver-syncer, vsphere-problem-detector](https://github.com/openshift/kubernetes/tree/e63ab41237b34f2a457e76900f6162184420cf96)
* [OCPBUGS-85262](https://issues.redhat.com/browse/OCPBUGS-85262): Re-enable kubectl kuberc commands e2e tests [#2731](https://github.com/openshift/kubernetes/pull/2731)
* [OCPBUGS-92798](https://issues.redhat.com/browse/OCPBUGS-92798): Add NodeSelectorAdjuster admission plugin for standalone clusters (part 2) [#2717](https://github.com/openshift/kubernetes/pull/2717)
* [STOR-2961](https://issues.redhat.com/browse/STOR-2961): UPSTREAM: 138768: move VolumeGroupSnapshot to V1 [#2723](https://github.com/openshift/kubernetes/pull/2723)
* [CNTRLPLANE-3323](https://issues.redhat.com/browse/CNTRLPLANE-3323): Update openshift-hack/rebase.sh [#2701](https://github.com/openshift/kubernetes/pull/2701)
* [OCPBUGS-98100](https://issues.redhat.com/browse/OCPBUGS-98100): e2e: storage snapshot tests should read custom timeouts from manifest [#2719](https://github.com/openshift/kubernetes/pull/2719)
* [Full changelog](https://github.com/openshift/kubernetes/compare/63ee93dac28329fd9d81e91b21ea8d8c43105d01...e63ab41237b34f2a457e76900f6162184420cf96)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/dc822233cc526b6cc55f20009a4c1b034f245133)
* [OCPBUGS-100043](https://issues.redhat.com/browse/OCPBUGS-100043): Updating aws-karpenter-provider-aws-container image to be consistent with ART for 5.0 [#34](https://github.com/openshift/aws-karpenter-provider-aws/pull/34)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/abcf7d1e34173037a13fc47317f313cb6ac2f667...dc822233cc526b6cc55f20009a4c1b034f245133)
### [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider/tree/9b18930d2db9521a08faa7165488bdcf6482b9cf)
* [CNTRLPLANE-4011](https://issues.redhat.com/browse/CNTRLPLANE-4011): Rebase aws-encryption-provider repo to upstream/master (8c16f8c) for OCP 5.0 [#52](https://github.com/openshift/aws-encryption-provider/pull/52)
* [Full changelog](https://github.com/openshift/aws-encryption-provider/compare/6ca6eea2f3a9d0b090ff63ba5b8e342d5686c9a8...9b18930d2db9521a08faa7165488bdcf6482b9cf)
### [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3/tree/ad4f1c2bd7b527437496b71b5b93ee1439243d65)
* [OCPBUGS-98546](https://issues.redhat.com/browse/OCPBUGS-98546): Remove dangling symlink [#87](https://github.com/openshift/cluster-api-provider-metal3/pull/87)
* [Full changelog](https://github.com/openshift/cluster-api-provider-metal3/compare/0afcbf370086fe550560784f9cbf7182a9e8b72e...ad4f1c2bd7b527437496b71b5b93ee1439243d65)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/1b579f10fb2c89d061112a15c178a1f9e7cfad63)
* no-jira: vendor: update o/api to the latest after several Feature promotions to default [#10746](https://github.com/openshift/installer/pull/10746)
* [OCPBUGS-101695](https://issues.redhat.com/browse/OCPBUGS-101695): bump golang.org/x/net to v0.56.0 [#10749](https://github.com/openshift/installer/pull/10749)
* [OCPBUGS-85296](https://issues.redhat.com/browse/OCPBUGS-85296): export Azure Metadata.Region for state file serialization [#10736](https://github.com/openshift/installer/pull/10736)
* [CORS-4406](https://issues.redhat.com/browse/CORS-4406): CORS-4407: CORS-4408: CORS-4410: CORS-4411: CORS-4413: Installer use customer managed kms keys to encrypt S3 for Ignition and Internal Registry [#10553](https://github.com/openshift/installer/pull/10553)
* [OCPBUGS-100189](https://issues.redhat.com/browse/OCPBUGS-100189): Patch GCP Load Balancer Health Checks [#10731](https://github.com/openshift/installer/pull/10731)
* [OCPBUGS-98700](https://issues.redhat.com/browse/OCPBUGS-98700): Azure: delete bootstrap ignition storage during bootstrap destroy [#10701](https://github.com/openshift/installer/pull/10701)
* [OCPBUGS-78995](https://issues.redhat.com/browse/OCPBUGS-78995): Azure Machines: Accept explicit image ID [#10712](https://github.com/openshift/installer/pull/10712)
* [OCPBUGS-104455](https://issues.redhat.com/browse/OCPBUGS-104455): Add a 10sec restart interval for ICC service, so that there is enough time for CRDs to become available [#10739](https://github.com/openshift/installer/pull/10739)
* no-jira: Update hack scripts to set min go version to 1.26 [#10738](https://github.com/openshift/installer/pull/10738)
* [CORS-4516](https://issues.redhat.com/browse/CORS-4516): GCP: Configure cloud provider to use mounted creds [#10733](https://github.com/openshift/installer/pull/10733)
* [OCPBUGS-98102](https://issues.redhat.com/browse/OCPBUGS-98102): Add validations Azure Dualstack [#10677](https://github.com/openshift/installer/pull/10677)
* [CORS-4537](https://issues.redhat.com/browse/CORS-4537): GCP: gracefully handle 503 in disk type check [#10732](https://github.com/openshift/installer/pull/10732)
* [CORS-3898](https://issues.redhat.com/browse/CORS-3898): azure: Fix the dualstack errors [#10656](https://github.com/openshift/installer/pull/10656)
* [OCPEDGE-2788](https://issues.redhat.com/browse/OCPEDGE-2788): agent: split fencing credentials placement by identification key [#10684](https://github.com/openshift/installer/pull/10684)
* [OCPBUGS-99164](https://issues.redhat.com/browse/OCPBUGS-99164): bootstrap: replace envsubst with sed in konnectivity.sh [#10728](https://github.com/openshift/installer/pull/10728)
* [CORS-4542](https://issues.redhat.com/browse/CORS-4542): restrict ClusterAPI machine management to only supported platforms [#10717](https://github.com/openshift/installer/pull/10717)
* [CORS-4425](https://issues.redhat.com/browse/CORS-4425): gcp: add OS image validation for sovereign clouds [#10709](https://github.com/openshift/installer/pull/10709)
* [CNTRLPLANE-2012](https://issues.redhat.com/browse/CNTRLPLANE-2012): Wire signer certs to read PKI config via SignerKeyParams [#10595](https://github.com/openshift/installer/pull/10595)
* [OCPBUGS-63133](https://issues.redhat.com/browse/OCPBUGS-63133): PowerVS: Error out if VPC does not exist [#10137](https://github.com/openshift/installer/pull/10137)
* [OCPBUGS-98696](https://issues.redhat.com/browse/OCPBUGS-98696): baremetal: fix provisioning ISO kernel arguments [#10702](https://github.com/openshift/installer/pull/10702)
* no-jira: bump k8s packages to v0.36 [#10713](https://github.com/openshift/installer/pull/10713)
* [CORS-4428](https://issues.redhat.com/browse/CORS-4428): gcp: reject PSC endpoint overrides for sovereign clouds [#10708](https://github.com/openshift/installer/pull/10708)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/installer/compare/d8f6a96a1c18ee540099ff73789fde54cc9b12cd...1b579f10fb2c89d061112a15c178a1f9e7cfad63)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/34bbeb376836bf01793d4e70d29065d619ebcaa1)
* NO-ISSUE: Merge upstream 2026-07-30 [#516](https://github.com/openshift/baremetal-operator/pull/516)
* NO-ISSUE: Merge upstream 2026-07-25 [#513](https://github.com/openshift/baremetal-operator/pull/513)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/775d84f5afecf432c7a0330bfaadd669b4a68ab0...34bbeb376836bf01793d4e70d29065d619ebcaa1)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/d436a450e4b65cfba1547d1dddb376bbceca82f3)
* NO-JIRA: Fix issues collection when CVO handles the risks [#2352](https://github.com/openshift/oc/pull/2352)
* [OCPBUGS-99013](https://issues.redhat.com/browse/OCPBUGS-99013): inspect: Redact OAuthClient secrets [#2354](https://github.com/openshift/oc/pull/2354)
* [OTA-1959](https://issues.redhat.com/browse/OTA-1959): Case 1 - `oc adm upgrade recommend` shows both Cincinnati-sourced and alert-sourced risks in output [#2349](https://github.com/openshift/oc/pull/2349)
* NO-JIRA: Update docs.openshift.com base URL to point to OCP docs [#2353](https://github.com/openshift/oc/pull/2353)
* [OCPBUGS-101781](https://issues.redhat.com/browse/OCPBUGS-101781): Isolate OCP-42982 kubeconfig writes [#2337](https://github.com/openshift/oc/pull/2337)
* [OTA-1814](https://issues.redhat.com/browse/OTA-1814): Handle accept risks with different commands [#2336](https://github.com/openshift/oc/pull/2336)
* [OCPBUGS-100310](https://issues.redhat.com/browse/OCPBUGS-100310): oc login --exec-plugin oc-oidc fails to refresh expired token against Microsoft Entra ID [#2332](https://github.com/openshift/oc/pull/2332)
* Revert "TRT-2817: Revert "Merge pull request #2279 from nbottari9/1814-duplicate-warning"" [#2322](https://github.com/openshift/oc/pull/2322)
* [OCPBUGS-99757](https://issues.redhat.com/browse/OCPBUGS-99757): Include extra scopes in OIDC token cache key [#2323](https://github.com/openshift/oc/pull/2323)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/oc/compare/a88e785e90aa96ac96da93359bacf3ea5c174733...d436a450e4b65cfba1547d1dddb376bbceca82f3)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/f323f9eb76e4031934c47f2623781f1f15cd5c9e)
* [CCO-837](https://issues.redhat.com/browse/CCO-837): Replace deprecated golang/mock with go.uber.org/mock [#1069](https://github.com/openshift/cloud-credential-operator/pull/1069)
* NO-ISSUE: Add patrickdillon to OWNERS [#1071](https://github.com/openshift/cloud-credential-operator/pull/1071)
* [CCO-834](https://issues.redhat.com/browse/CCO-834), [CCO-835](https://issues.redhat.com/browse/CCO-835), [CCO-836](https://issues.redhat.com/browse/CCO-836): Upgrade to Kubernetes 1.36 with CI and e2e tests [#1066](https://github.com/openshift/cloud-credential-operator/pull/1066)
* [CORS-4524](https://issues.redhat.com/browse/CORS-4524): Enable GCP custom universe domain support for CCO [#1068](https://github.com/openshift/cloud-credential-operator/pull/1068)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/672b790022dbea667460b1a0467b6a0bc39c544b...f323f9eb76e4031934c47f2623781f1f15cd5c9e)
### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/dada7547e3d89f301be73b27063ac91f2acb9088)
* [CORS-4523](https://issues.redhat.com/browse/CORS-4523): support GCP custom universe domain [#249](https://github.com/openshift/cloud-network-config-controller/pull/249)
* NO-JIRA: Update OWNERS file [#229](https://github.com/openshift/cloud-network-config-controller/pull/229)
* [CORENET-7047](https://issues.redhat.com/browse/CORENET-7047): CNCC K8s rebase to 1.36.2 [#223](https://github.com/openshift/cloud-network-config-controller/pull/223)
* [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/0b49df2bc4b10110463f1aa2a5fc475ebaeef9ab...dada7547e3d89f301be73b27063ac91f2acb9088)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/f3df4f5b26043e7c0f2bc724cd3cbc0a2a6d14f7)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Watch openshift-config ConfigMaps in OAuth route health check controller [#964](https://github.com/openshift/cluster-authentication-operator/pull/964)
* NO-JIRA: bump library-go api and client-go [#963](https://github.com/openshift/cluster-authentication-operator/pull/963)
* NO-JIRA: Bump library-go [#962](https://github.com/openshift/cluster-authentication-operator/pull/962)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Include system cert pool in proxy resolver transport [#961](https://github.com/openshift/cluster-authentication-operator/pull/961)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Clear IdP validation hash when all identity providers are removed [#960](https://github.com/openshift/cluster-authentication-operator/pull/960)
* NO-JIRA: Update openshift/* [#959](https://github.com/openshift/cluster-authentication-operator/pull/959)
* [CNTRLPLANE-3762](https://issues.redhat.com/browse/CNTRLPLANE-3762): Add support for component-scoped proxy [#946](https://github.com/openshift/cluster-authentication-operator/pull/946)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client- #741 [#958](https://github.com/openshift/cluster-authentication-operator/pull/958)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#956](https://github.com/openshift/cluster-authentication-operator/pull/956)
* [CNTRLPLANE-3375](https://issues.redhat.com/browse/CNTRLPLANE-3375): bugfix: make switched controller clear status conditions on delegate controller shutdown [#955](https://github.com/openshift/cluster-authentication-operator/pull/955)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/482d82f81fc7b460eb3f4024c7fcb4c4a841aecd...f3df4f5b26043e7c0f2bc724cd3cbc0a2a6d14f7)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/f393f54229e6c3ae74c35ae72012af92d31c03d3)
* [OCPBUGS-99660](https://issues.redhat.com/browse/OCPBUGS-99660): Fix VPA checkpoint overwrite bug [#433](https://github.com/openshift/kubernetes-autoscaler/pull/433)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/70920d3c6f5ff55d0eb72368767a81aea1a62abb...f393f54229e6c3ae74c35ae72012af92d31c03d3)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/e48fe1179ad671757b5a40688e2d125c1f326e8b)
* NO-JIRA: Add /release-chores chore cycle skill [#382](https://github.com/openshift/cluster-autoscaler-operator/pull/382)
* [OCPBUGS-100034](https://issues.redhat.com/browse/OCPBUGS-100034): Dump kube RBAC proxy and do metrics endpoint authn & authz in process [#381](https://github.com/openshift/cluster-autoscaler-operator/pull/381)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/4eba1788615dcaf77498d063f51812d5d4b2281a...e48fe1179ad671757b5a40688e2d125c1f326e8b)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/4ecb36c02378147632acde2fa91aea1d9efc229b)
* [OCPBUGS-86888](https://issues.redhat.com/browse/OCPBUGS-86888): Mount IDMS mirror config into machine-os-images init container [#636](https://github.com/openshift/cluster-baremetal-operator/pull/636)
* [OCPBUGS-100033](https://issues.redhat.com/browse/OCPBUGS-100033): Migrate metrics from kube-rbac-proxy sidecar to controller-runtime's SecureServing [#638](https://github.com/openshift/cluster-baremetal-operator/pull/638)
* [OCPBUGS-66101](https://issues.redhat.com/browse/OCPBUGS-66101): set Progressing=True during cluster update [#599](https://github.com/openshift/cluster-baremetal-operator/pull/599)
* [OCPQE-32094](https://issues.redhat.com/browse/OCPQE-32094): Address review feedback from PR #622 [#637](https://github.com/openshift/cluster-baremetal-operator/pull/637)
* [METAL-1922](https://issues.redhat.com/browse/METAL-1922): Bump BMO to latest downstream main branch, update the supported TLS groups for BMO [#639](https://github.com/openshift/cluster-baremetal-operator/pull/639)
* [METAL-1833](https://issues.redhat.com/browse/METAL-1833): Add host_fw_components tests to CBO test extension [#622](https://github.com/openshift/cluster-baremetal-operator/pull/622)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/fd483524f88dd685d663aa46b21803b7a24c5c69...4ecb36c02378147632acde2fa91aea1d9efc229b)
### [cluster-capi-controllers](https://github.com/openshift/cluster-api/tree/8e2d2bddb8f3f17b80d0461cf8eeebc8d833c38b)
* [OCPCLOUD-3434](https://issues.redhat.com/browse/OCPCLOUD-3434), [OCPCLOUD-3556](https://issues.redhat.com/browse/OCPCLOUD-3556): Exclude unsupported CAPI CRDs and scope ClusterRole [#304](https://github.com/openshift/cluster-api/pull/304)
* [Full changelog](https://github.com/openshift/cluster-api/compare/16b6909b3c73d84fe1fbda0d12f9be80aaae00db...8e2d2bddb8f3f17b80d0461cf8eeebc8d833c38b)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/9e2ecb9f5e026953d98980aabd3b0926ac50b261)
* [OCPCLOUD-3647](https://issues.redhat.com/browse/OCPCLOUD-3647): Consolidate install-time object processing in toBoxcutterRevision [#633](https://github.com/openshift/cluster-capi-operator/pull/633)
* NO-JIRA: resolve placeholder version for k8s.io/autoscaler APIs [#642](https://github.com/openshift/cluster-capi-operator/pull/642)
* [OCPBUGS-100143](https://issues.redhat.com/browse/OCPBUGS-100143): e2e: skip CRD Compatibility Checker tests on External topology clusters [#638](https://github.com/openshift/cluster-capi-operator/pull/638)
* NO-JIRA: go.mod: pin k8s.io/cri-streaming to v0.36.2 [#639](https://github.com/openshift/cluster-capi-operator/pull/639)
* [OCPBUGS-100246](https://issues.redhat.com/browse/OCPBUGS-100246): Fix e2es on CAPI-native clusters [#641](https://github.com/openshift/cluster-capi-operator/pull/641)
* [OCPCLOUD-3571](https://issues.redhat.com/browse/OCPCLOUD-3571): Add OTE e2e tests for ClusterAPIMachineManagementAWS feature gate [#613](https://github.com/openshift/cluster-capi-operator/pull/613)
* [OCPCLOUD-3538](https://issues.redhat.com/browse/OCPCLOUD-3538), [OCPCLOUD-3556](https://issues.redhat.com/browse/OCPCLOUD-3556): manifests-gen: enable KRM plugins and add exclude/rename-resources transformers [#621](https://github.com/openshift/cluster-capi-operator/pull/621)
* [OCPBUGS-84321](https://issues.redhat.com/browse/OCPBUGS-84321): ClusterAPIMachineManagement: capi-controllers: excessive restarts of during cluster installation [#614](https://github.com/openshift/cluster-capi-operator/pull/614)
* [OCPCLOUD-3507](https://issues.redhat.com/browse/OCPCLOUD-3507): Add OTE e2e tests for ClusterAPIMachineManagement feature gate [#606](https://github.com/openshift/cluster-capi-operator/pull/606)
* NO-JIRA: Fix buildComponentList godoc [#632](https://github.com/openshift/cluster-capi-operator/pull/632)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/5767be9caecedf9dbbd2bdfd04633514b34b408f...9e2ecb9f5e026953d98980aabd3b0926ac50b261)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/bc52198c1c3c61099ba3cd20bf5fca80ed7754e7)
* [CORS-4516](https://issues.redhat.com/browse/CORS-4516): GCP: Update Required Permissions [#493](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/493)
* [OCPCLOUD-3610](https://issues.redhat.com/browse/OCPCLOUD-3610): Update to K8s 1.36.3 dependencies [#496](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/496)
* [OCPBUGS-99755](https://issues.redhat.com/browse/OCPBUGS-99755): OTE: fix AWS endpoint resolution for non-standard partitions [#494](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/494)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/38f5e00cbd0085f6b62b98cd9ed044f54c89ad07...bc52198c1c3c61099ba3cd20bf5fca80ed7754e7)
### [cluster-config-api](https://github.com/openshift/api/tree/72ae4424ef350e688068890e69da9ced377ea495)
* [MON-4625](https://issues.redhat.com/browse/MON-4625): add support for the nvmesubsystem collector [#2960](https://github.com/openshift/api/pull/2960)
* Promote IrreconcilableMachineConfig to GA [#2929](https://github.com/openshift/api/pull/2929)
* [NE-2777](https://issues.redhat.com/browse/NE-2777), [NE-2778](https://issues.redhat.com/browse/NE-2778): Implement Gateway API management knob [#2890](https://github.com/openshift/api/pull/2890)
* Use regex instead of format help for KMS secret name validation [#2966](https://github.com/openshift/api/pull/2966)
* [OCPBUGS-74511](https://issues.redhat.com/browse/OCPBUGS-74511): Remove RouteExternalCertificate feature gate [#2962](https://github.com/openshift/api/pull/2962)
* [MON-4607](https://issues.redhat.com/browse/MON-4607): add zoneinfo to NodeExporterCollectorConfig CRD types [#2948](https://github.com/openshift/api/pull/2948)
* [AGENT-1493](https://issues.redhat.com/browse/AGENT-1493): Promote NoRegistryClusterInstall Feature to Default [#2859](https://github.com/openshift/api/pull/2859)
* [MON-4620](https://issues.redhat.com/browse/MON-4620): expose remote-write protocol version [#2958](https://github.com/openshift/api/pull/2958)
* [CORS-4417](https://issues.redhat.com/browse/CORS-4417): Add UniverseDomain field to GCPPlatformStatus [#2963](https://github.com/openshift/api/pull/2963)
* [OCPNODE-4622](https://issues.redhat.com/browse/OCPNODE-4622): Promote CRIOCredentialProviderConfig feature gate Default [#2844](https://github.com/openshift/api/pull/2844)
* [NE-2823](https://issues.redhat.com/browse/NE-2823): Promote Multi HAProxy Versions feature to default [#2947](https://github.com/openshift/api/pull/2947)
* [MON-4616](https://issues.redhat.com/browse/MON-4616): add support for dmmultipath collector [#2956](https://github.com/openshift/api/pull/2956)
* [CORS-4387](https://issues.redhat.com/browse/CORS-4387): Promote AWS DualStack to Default [#2797](https://github.com/openshift/api/pull/2797)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): Kms plugin health report clean up [#2931](https://github.com/openshift/api/pull/2931)
* [OPRUN-4705](https://issues.redhat.com/browse/OPRUN-4705): Remove NewOLMPreflightPermissionChecks FeatureGate [#2957](https://github.com/openshift/api/pull/2957)
* [SPLAT-2827](https://issues.redhat.com/browse/SPLAT-2827): Added vSphere failure domain to vcenter check [#2932](https://github.com/openshift/api/pull/2932)
* [Full changelog](https://github.com/openshift/api/compare/9bcaa16cb258e544dd76b78ff2dc3f89af840f76...72ae4424ef350e688068890e69da9ced377ea495)
### [cluster-config-operator](https://github.com/openshift/cluster-config-operator/tree/9f787f73f5fffca5cd511ef2c2e704afc14f68ce)
* [OCPBUGS-104562](https://issues.redhat.com/browse/OCPBUGS-104562): Mark kube-cloud-config recreation test disruptive [#497](https://github.com/openshift/cluster-config-operator/pull/497)
* [MON-4499](https://issues.redhat.com/browse/MON-4499): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#468](https://github.com/openshift/cluster-config-operator/pull/468)
* [Full changelog](https://github.com/openshift/cluster-config-operator/compare/a02c879931c6108326c0a514df0ce2e390f3536c...9f787f73f5fffca5cd511ef2c2e704afc14f68ce)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/0a98fb46580fa472b86e1aeaa96821e0db51b741)
* NO-JIRA: Fix flaky unit-test harness races and tight timeouts [#416](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/416)
* [OCPCLOUD-3611](https://issues.redhat.com/browse/OCPCLOUD-3611): Bump Kubernetes dependencies to 1.36 [#414](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/414)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/452cee8c1f4efb683fb6bcb15b61366695d98e1e...0a98fb46580fa472b86e1aeaa96821e0db51b741)
### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/35ec0224eb0e5219d5eae012fb703223a6f3e1f7)
* [STOR-3005](https://issues.redhat.com/browse/STOR-3005): Remove v1beta2 group snapshot API [#283](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/283)
* [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/67648d56d6b312e661714f8e7bf0e9be1d532c1c...35ec0224eb0e5219d5eae012fb703223a6f3e1f7)
### [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator/tree/c0ed09e329e9001629518604a58205e3fbe8284a)
* [OCPBUGS-86009](https://issues.redhat.com/browse/OCPBUGS-86009): Fix dns operator reporting Progressing=True on scale up [#477](https://github.com/openshift/cluster-dns-operator/pull/477)
* [NE-2817](https://issues.redhat.com/browse/NE-2817): Gate operator metrics TLS on tlsAdherence via ShouldHonorClusterTLSProfile [#484](https://github.com/openshift/cluster-dns-operator/pull/484)
* [Full changelog](https://github.com/openshift/cluster-dns-operator/compare/4b8ae49940eefc50fa48da5179e735dd6ccd42d9...c0ed09e329e9001629518604a58205e3fbe8284a)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/2f256f2638e892af38c274c62131565ec8df6dff)
* [CNTRLPLANE-3403](https://issues.redhat.com/browse/CNTRLPLANE-3403): reduce default snapshot-count to 5000 [#1666](https://github.com/openshift/cluster-etcd-operator/pull/1666)
* [OCPBUGS-84695](https://issues.redhat.com/browse/OCPBUGS-84695): feat(tnf): TNF job controller framework and lifecycle management [#1655](https://github.com/openshift/cluster-etcd-operator/pull/1655)
* NO-JIRA: add ceo disruptive suite to sippy's disruptive [#1667](https://github.com/openshift/cluster-etcd-operator/pull/1667)
* [OCPBUGS-100294](https://issues.redhat.com/browse/OCPBUGS-100294): fix TNFNodeInMaintenance PromQL label mismatch [#1664](https://github.com/openshift/cluster-etcd-operator/pull/1664)
* [OCPBUGS-94106](https://issues.redhat.com/browse/OCPBUGS-94106): Add APIServer informer to EnvVarController cache sync [#1659](https://github.com/openshift/cluster-etcd-operator/pull/1659)
* [OCPBUGS-100072](https://issues.redhat.com/browse/OCPBUGS-100072): Revert 'OCPBUGS-88490: fix etcd operator deadlock when etcd-endpoints configmap is stale' [#1660](https://github.com/openshift/cluster-etcd-operator/pull/1660)
* [OCPEDGE-2094](https://issues.redhat.com/browse/OCPEDGE-2094): Add console notifications for pacemaker health events [#1654](https://github.com/openshift/cluster-etcd-operator/pull/1654)
* [CNTRLPLANE-3609](https://issues.redhat.com/browse/CNTRLPLANE-3609): update TestEtcdDBScaling to also include the validation check for BackendQuotaGiB [#1656](https://github.com/openshift/cluster-etcd-operator/pull/1656)
* [OCPEDGE-2118](https://issues.redhat.com/browse/OCPEDGE-2118): Record Kubernetes events for etcd transition lifecycle [#1653](https://github.com/openshift/cluster-etcd-operator/pull/1653)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/ebea15aeb57ecaca4ff8e8fdf5aa28d5a4469d12...2f256f2638e892af38c274c62131565ec8df6dff)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/94cd22d000c8b8eef24dd43cd05d06544df24930)
* [CORS-4520](https://issues.redhat.com/browse/CORS-4520): GCP Universe Domain Support [#1356](https://github.com/openshift/cluster-image-registry-operator/pull/1356)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/02bb5c2cd4d5f4d277cf987d6f65e58a732aefee...94cd22d000c8b8eef24dd43cd05d06544df24930)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/acca9642a81370bc1a587155f7e1e7998b7c5489)
* [OCPBUGS-99921](https://issues.redhat.com/browse/OCPBUGS-99921): Annotate GatewayClass when istiod is available to fix startup race [#1540](https://github.com/openshift/cluster-ingress-operator/pull/1540)
* [OCPBUGS-100424](https://issues.redhat.com/browse/OCPBUGS-100424), [OCPBUGS-104205](https://issues.redhat.com/browse/OCPBUGS-104205): Harden DNS duplicate-domain ownership checks [#1543](https://github.com/openshift/cluster-ingress-operator/pull/1543)
* [OCPBUGS-99920](https://issues.redhat.com/browse/OCPBUGS-99920): Vendor sail-operator from OSSM release-3.4.1 [#1527](https://github.com/openshift/cluster-ingress-operator/pull/1527)
* [OCPBUGS-100435](https://issues.redhat.com/browse/OCPBUGS-100435): Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways [#1539](https://github.com/openshift/cluster-ingress-operator/pull/1539)
* [TRT-2874](https://issues.redhat.com/browse/TRT-2874): Revert #1513 "NE-2836: Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways" [#1537](https://github.com/openshift/cluster-ingress-operator/pull/1537)
* [NE-2833](https://issues.redhat.com/browse/NE-2833): Replace deprecated io/ioutil usage [#1531](https://github.com/openshift/cluster-ingress-operator/pull/1531)
* [NE-2823](https://issues.redhat.com/browse/NE-2823): Bump API to promote Multi HAProxy Versions feature [#1535](https://github.com/openshift/cluster-ingress-operator/pull/1535)
* [OCPBUGS-85680](https://issues.redhat.com/browse/OCPBUGS-85680): Re-fetch infraConfig on every periodic loop iteration [#1458](https://github.com/openshift/cluster-ingress-operator/pull/1458)
* [OCPBUGS-31521](https://issues.redhat.com/browse/OCPBUGS-31521): Don't publish duplicate DNS records [#1229](https://github.com/openshift/cluster-ingress-operator/pull/1229)
* [NE-2836](https://issues.redhat.com/browse/NE-2836): Set Accepted=False and Prometheus alert for ListenerSets on managed Gateways [#1513](https://github.com/openshift/cluster-ingress-operator/pull/1513)
* [OCPBUGS-63219](https://issues.redhat.com/browse/OCPBUGS-63219): Support NLB protocol to configure proxy protocol and client IP preservation [#1426](https://github.com/openshift/cluster-ingress-operator/pull/1426)
* [OCPBUGS-100186](https://issues.redhat.com/browse/OCPBUGS-100186): Rename network policy in TestContainerLoggingMinLength [#1532](https://github.com/openshift/cluster-ingress-operator/pull/1532)
* [NE-2585](https://issues.redhat.com/browse/NE-2585): Bump GWAPI to v1.5.1 and Istio v1.30.1 [#1530](https://github.com/openshift/cluster-ingress-operator/pull/1530)
* [NE-2796](https://issues.redhat.com/browse/NE-2796): Respect OpenShift TLS Profiles during Istio/GatewayAPI installation [#1480](https://github.com/openshift/cluster-ingress-operator/pull/1480)
* [NE-2742](https://issues.redhat.com/browse/NE-2742): Apply cluster TLS security profile to operator metrics and canary endpoints [#1501](https://github.com/openshift/cluster-ingress-operator/pull/1501)
* [OCPBUGS-86841](https://issues.redhat.com/browse/OCPBUGS-86841): Add BackendTLSPolicy to Gateway API e2e CRD test coverage [#1523](https://github.com/openshift/cluster-ingress-operator/pull/1523)
* [CORS-4451](https://issues.redhat.com/browse/CORS-4451): GCP: Set Universe Domain [#1515](https://github.com/openshift/cluster-ingress-operator/pull/1515)
* [NE-2809](https://issues.redhat.com/browse/NE-2809): Add upgradeable logic for HAProxy version [#1517](https://github.com/openshift/cluster-ingress-operator/pull/1517)
* [OCPBUGS-99775](https://issues.redhat.com/browse/OCPBUGS-99775): Update TestHTTPHeaderBufferSize for HAProxy 3.2 response code change [#1524](https://github.com/openshift/cluster-ingress-operator/pull/1524)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/d7aafd957d1c126f5241ab716ad55ad0d160c042...acca9642a81370bc1a587155f7e1e7998b7c5489)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/238179f3e2a5a2daa639fa0260972e787dca7661)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms key controller preflight support [#2252](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2252)
* NO-JIRA: bump library-go api and client-go [#2257](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2257)
* NO-JIRA: Add parallelism KMS OnOff Scenarios [#2251](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2251)
* NO-JIRA: Bump library-go [#2255](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2255)
* NO-JIRA: Update openshift/* [#2249](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2249)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client [#2248](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2248)
* [MON-4502](https://issues.redhat.com/browse/MON-4502): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#2036](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2036)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#2246](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2246)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/dab04ebace1a4b36bb40e8f4f87804754b69760b...238179f3e2a5a2daa639fa0260972e787dca7661)
### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/cdf27353008200166f1ad754c4ade033370077ae)
* [OCPBUGS-100160](https://issues.redhat.com/browse/OCPBUGS-100160): Fix status controller unit-test teardown race [#312](https://github.com/openshift/cluster-machine-approver/pull/312)
* NO-JIRA: Bump envtest to 1.36.2 [#314](https://github.com/openshift/cluster-machine-approver/pull/314)
* [OCPCLOUD-3612](https://issues.redhat.com/browse/OCPCLOUD-3612): Bump k8s v1.36, go 1.26 [#311](https://github.com/openshift/cluster-machine-approver/pull/311)
* [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/1ae3f157b88c167a7dbe06c36d6e55a82f7fd4f0...cdf27353008200166f1ad754c4ade033370077ae)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/c68fc0aba966f39fcd91e725017811b7fee08f5b)
* [MON-4637](https://issues.redhat.com/browse/MON-4637): implement merge logic to support the new MessageVersion field in the config CRD [#3036](https://github.com/openshift/cluster-monitoring-operator/pull/3036)
* NO-JIRA: Add test descriptions [#3037](https://github.com/openshift/cluster-monitoring-operator/pull/3037)
* [MON-4577](https://issues.redhat.com/browse/MON-4577): restrict alertmanager gossip mesh ports to same-instance pods [#3032](https://github.com/openshift/cluster-monitoring-operator/pull/3032)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3035](https://github.com/openshift/cluster-monitoring-operator/pull/3035)
* NO-JIRA: Allow to pass custom arguments to e2e test command [#3033](https://github.com/openshift/cluster-monitoring-operator/pull/3033)
* NO-JIRA: tasks: pass context to MetricsServerTask methods instead of storing it [#3025](https://github.com/openshift/cluster-monitoring-operator/pull/3025)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3017](https://github.com/openshift/cluster-monitoring-operator/pull/3017)
* NO-JIRA: chore: update Prometheus-operator to v0.93.0 [#3010](https://github.com/openshift/cluster-monitoring-operator/pull/3010)
* [MON-4630](https://issues.redhat.com/browse/MON-4630): support the dmmultipath collector in the config CRD [#3015](https://github.com/openshift/cluster-monitoring-operator/pull/3015)
* : OCPBUGS-91735: fix: watch cluster wide proxy changes and apply changes accordingly [#3004](https://github.com/openshift/cluster-monitoring-operator/pull/3004)
* NO-JIRA: test: make TestDocExamples and TestNetworkPolicy more stable [#3013](https://github.com/openshift/cluster-monitoring-operator/pull/3013)
* NO-JIRA: add metrics for the validating webhook [#2838](https://github.com/openshift/cluster-monitoring-operator/pull/2838)
* NO-JIRA: e2e: defer subtest resource cleanup in TestPrometheusRemoteWrite [#3016](https://github.com/openshift/cluster-monitoring-operator/pull/3016)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#3014](https://github.com/openshift/cluster-monitoring-operator/pull/3014)
* NO-JIRA: chore: pin GOTOOLCHAIN in update-go-deps + update Go dependencies [#3006](https://github.com/openshift/cluster-monitoring-operator/pull/3006)
* NO-JIRA: increase golangci-lint timeout [#3011](https://github.com/openshift/cluster-monitoring-operator/pull/3011)
* [MON-4624](https://issues.redhat.com/browse/MON-4624): enable the nvmesubsystem collector by default [#3005](https://github.com/openshift/cluster-monitoring-operator/pull/3005)
* NO-JIRA: [bot] Synchronize versions of the downstream components [#2994](https://github.com/openshift/cluster-monitoring-operator/pull/2994)
* [MON-4413](https://issues.redhat.com/browse/MON-4413): support MessageVersion v2.0 for remote-write [#2977](https://github.com/openshift/cluster-monitoring-operator/pull/2977)
* [OCPBUGS-85522](https://issues.redhat.com/browse/OCPBUGS-85522): disable kubelet Endpoints in prometheus-operator [#2931](https://github.com/openshift/cluster-monitoring-operator/pull/2931)
* NO-JIRA: test: adjust e2e tests on retention settings [#2999](https://github.com/openshift/cluster-monitoring-operator/pull/2999)
* [MON-4615](https://issues.redhat.com/browse/MON-4615): add option to disable the dmmultipath collector [#2996](https://github.com/openshift/cluster-monitoring-operator/pull/2996)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/5042b52541130c3856028e29c7142d477c3f7d7d...c68fc0aba966f39fcd91e725017811b7fee08f5b)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/a0ebeb0c4d6d5baa353f1e123553dfecf7092eda)
* [OCPBUGS-98918](https://issues.redhat.com/browse/OCPBUGS-98918): Use service-ca certificates for network-check-source metrics [#3097](https://github.com/openshift/cluster-network-operator/pull/3097)
* [OCPBUGS-99460](https://issues.redhat.com/browse/OCPBUGS-99460): Fix connectivity check for nodes named with IP address [#3083](https://github.com/openshift/cluster-network-operator/pull/3083)
* [CORENET-5658](https://issues.redhat.com/browse/CORENET-5658): Bump ovn-controller CPU request to 50m to prevent CPU starvation [#3051](https://github.com/openshift/cluster-network-operator/pull/3051)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Enable Network Observability on Day 0 [#3087](https://github.com/openshift/cluster-network-operator/pull/3087)
* [CORENET-7054](https://issues.redhat.com/browse/CORENET-7054): Use TLS profile to render CLI args for deployed components [#3043](https://github.com/openshift/cluster-network-operator/pull/3043)
* [CORENET-5972](https://issues.redhat.com/browse/CORENET-5972): Consume openvswitch-ipsec systemd service for OVN IPsec deployment [#2662](https://github.com/openshift/cluster-network-operator/pull/2662)
* NO-JIRA: vendor: bump github.com/openshift/api to latest master [#3089](https://github.com/openshift/cluster-network-operator/pull/3089)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/00e6cc59b92af5c8f73f9c3908ed3b0ef591bf63...a0ebeb0c4d6d5baa353f1e123553dfecf7092eda)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/837ae9f6da1c7a5ff24718c8210047571a3909a3)
* [OCPBUGS-99461](https://issues.redhat.com/browse/OCPBUGS-99461): Add missing annotations to NetworkPolicy manifests [#1569](https://github.com/openshift/cluster-node-tuning-operator/pull/1569)
* [MON-4506](https://issues.redhat.com/browse/MON-4506): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#1468](https://github.com/openshift/cluster-node-tuning-operator/pull/1468)
* [OCPBUGS-100115](https://issues.redhat.com/browse/OCPBUGS-100115): E2E: LLC: Restore uncore cache annotation to true [#1570](https://github.com/openshift/cluster-node-tuning-operator/pull/1570)
* NO-JIRA: owners: update [#1563](https://github.com/openshift/cluster-node-tuning-operator/pull/1563)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/a9d25d502ca894272f88753f1bd7ecef82fb188e...837ae9f6da1c7a5ff24718c8210047571a3909a3)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/228ec940921e4443b2724ef512c0d211d4a38ba7)
* NO-ISSUE: Add dependabot configuration [#225](https://github.com/openshift/cluster-olm-operator/pull/225)
* [OPRUN-4665](https://issues.redhat.com/browse/OPRUN-4665): Update k8s dependencies from v0.35.1 to v0.36.2 and OpenShift dependencies to latest [#217](https://github.com/openshift/cluster-olm-operator/pull/217)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/9983877dbed43c0ae050ad4646e31b9cfbd41329...228ec940921e4443b2724ef512c0d211d4a38ba7)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/f730b48c7dbd76b3125fa7508c80c6a083d364f8)
* [OCPBUGS-98618](https://issues.redhat.com/browse/OCPBUGS-98618): Add HostToContainer mountPropagation to node-pullsecrets volume mount [#744](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/744)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): kms key controller preflight support [#747](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/747)
* NO-JIRA: bump library-go api and client-go [#746](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/746)
* Revert "NO-JIRA: Disable WatchList feature gate due to the missing support of Project watch" [#681](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/681)
* NO-JIRA: Bump library-go [#745](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/745)
* NO-JIRA: Update openshift/* [#742](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/742)
* [CNTRLPLANE-3237](https://issues.redhat.com/browse/CNTRLPLANE-3237): creates the kms status provider from the operator client [#741](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/741)
* NO-JIRA: add KMS preflight deploy e2e to encryption-kms-2 [#739](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/739)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/7bac3548875ec36a6c4967df818ccae533dcce7c...f730b48c7dbd76b3125fa7508c80c6a083d364f8)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/bb8d2fd11a18ce59cf84a2982189d9ca2c23599e)
* [OCPBUGS-101758](https://issues.redhat.com/browse/OCPBUGS-101758): Fix SELinuxMountGAReadiness on HyperShift [#721](https://github.com/openshift/cluster-storage-operator/pull/721)
* [STOR-2918](https://issues.redhat.com/browse/STOR-2918): update AWS EBS CSI credentials request policy to mirror upstream [#717](https://github.com/openshift/cluster-storage-operator/pull/717)
* [STOR-3056](https://issues.redhat.com/browse/STOR-3056): inject TLS adherence from API to vsphere problem detector configmap [#718](https://github.com/openshift/cluster-storage-operator/pull/718)
* [OCPBUGS-99492](https://issues.redhat.com/browse/OCPBUGS-99492): NetworkPolicies should use numeric ports instead of named ports [#720](https://github.com/openshift/cluster-storage-operator/pull/720)
* [STOR-3013](https://issues.redhat.com/browse/STOR-3013): Add e2e test for SELinuxMount upgrade readiness [#715](https://github.com/openshift/cluster-storage-operator/pull/715)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#719](https://github.com/openshift/cluster-storage-operator/pull/719)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/8ac48254009fb4987bee1f3e00cbb8e4d730f545...bb8d2fd11a18ce59cf84a2982189d9ca2c23599e)
### [cluster-update-console-plugin](https://github.com/openshift/cluster-update-console-plugin/tree/02b220dd2aef5c1788768178e3ffd8592ccb89b9)
* [OCPBUGS-104520](https://issues.redhat.com/browse/OCPBUGS-104520): Use latest analysis result instead of first [#22](https://github.com/openshift/cluster-update-console-plugin/pull/22)
* [Full changelog](https://github.com/openshift/cluster-update-console-plugin/compare/e222a514a3f1977cdc99bbf41d405729aba2d910...02b220dd2aef5c1788768178e3ffd8592ccb89b9)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/97ee3b743cc3eadf2e53252910a5d54c207c6d49)
* [OCPBUGS-79358](https://issues.redhat.com/browse/OCPBUGS-79358): pkg/cvo/egress: Disable Proxy respect on HyperShift [#1357](https://github.com/openshift/cluster-version-operator/pull/1357)
* NO-JIRA: fix(pkg/cincinnati): log the correct root CA pool size [#1413](https://github.com/openshift/cluster-version-operator/pull/1413)
* [OTA-1997](https://issues.redhat.com/browse/OTA-1997): Allow the CVO to use the agentic-skills payload image when creating proposals [#1433](https://github.com/openshift/cluster-version-operator/pull/1433)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084): Register agenticrunv1alpha1 in the Runtime client scheme [#1434](https://github.com/openshift/cluster-version-operator/pull/1434)
* [OTA-2084](https://issues.redhat.com/browse/OTA-2084): pkg/agenticrun/controller: Inline AgenticRun prompt, dropping the ConfigMap [#1432](https://github.com/openshift/cluster-version-operator/pull/1432)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/70bafacd988182acbc5160d61088a6d1ddad785a...97ee3b743cc3eadf2e53252910a5d54c207c6d49)
### [console](https://github.com/openshift/console/tree/1fbc1a87fdfe55253664dce9a37021dbb8c18284)
* [OTA-2035](https://issues.redhat.com/browse/OTA-2035): Address ProdSec findings for OLS Helper Buttons [#16910](https://github.com/openshift/console/pull/16910)
* [CONSOLE-5414](https://issues.redhat.com/browse/CONSOLE-5414): Migrate dev-console Cypress tests to Playwright (batch 2) [#16741](https://github.com/openshift/console/pull/16741)
* [OCPBUGS-105314](https://issues.redhat.com/browse/OCPBUGS-105314): Fix xterm ResizeObserver crash on uninitialized dimensions [#16918](https://github.com/openshift/console/pull/16918)
* [OCPBUGS-105273](https://issues.redhat.com/browse/OCPBUGS-105273): Fix nested interactive controls on Search page [#16914](https://github.com/openshift/console/pull/16914)
* [CONSOLE-5228](https://issues.redhat.com/browse/CONSOLE-5228): re-enable eslint rules and autofix + bump prettier [#16915](https://github.com/openshift/console/pull/16915)
* [OCPBUGS-105318](https://issues.redhat.com/browse/OCPBUGS-105318): Fix node-groups-filter test to use correct page-heading test ID [#16912](https://github.com/openshift/console/pull/16912)
* [OCPBUGS-102342](https://issues.redhat.com/browse/OCPBUGS-102342): Dismiss Quick Start drawer in Playwright e2e tests [#16903](https://github.com/openshift/console/pull/16903)
* [OCPBUGS-90514](https://issues.redhat.com/browse/OCPBUGS-90514): Fix CVE-2026-12143 form-data CRLF injection [#16865](https://github.com/openshift/console/pull/16865)
* NO-JIRA: Prepare for publishing new 4.23 prerelease plugin SDK packages [#16905](https://github.com/openshift/console/pull/16905)
* [CONSOLE-5424](https://issues.redhat.com/browse/CONSOLE-5424): Add minimize action for toast notifications [#16762](https://github.com/openshift/console/pull/16762)
* [CONSOLE-5118](https://issues.redhat.com/browse/CONSOLE-5118): Improve AI assessment prompts [#16880](https://github.com/openshift/console/pull/16880)
* [CONSOLE-5241](https://issues.redhat.com/browse/CONSOLE-5241): Migrate knative-ci.feature Cypress tests to Playwright [#16658](https://github.com/openshift/console/pull/16658)
* [CONSOLE-5065](https://issues.redhat.com/browse/CONSOLE-5065): Bump @openshift/dynamic-plugin-sdk to 9.1.0 [#16897](https://github.com/openshift/console/pull/16897)
* [CONSOLE-5425](https://issues.redhat.com/browse/CONSOLE-5425): Add rspack native bindings for linux/s390x and linux/ppc64le [#16890](https://github.com/openshift/console/pull/16890)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Fix Playwright e2e flakes across multiple test suites [#16881](https://github.com/openshift/console/pull/16881)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Increase Playwright CI retries and abort after 10 failures [#16887](https://github.com/openshift/console/pull/16887)
* [OCPBUGS-99434](https://issues.redhat.com/browse/OCPBUGS-99434): Show toast notification for invalid Helm Chart repositories [#16792](https://github.com/openshift/console/pull/16792)
* [CONSOLE-5417](https://issues.redhat.com/browse/CONSOLE-5417): Migrate dev-console Cypress tests to Playwright (batch 4) [#16767](https://github.com/openshift/console/pull/16767)
* [CONSOLE-5065](https://issues.redhat.com/browse/CONSOLE-5065): Align Console useResolvedExtensions hook with upstream plugin SDK [#16815](https://github.com/openshift/console/pull/16815)
* [OCPBUGS-99491](https://issues.redhat.com/browse/OCPBUGS-99491): Fix Installed Operators table row cells ignoring column management [#16817](https://github.com/openshift/console/pull/16817)
* [CONSOLE-5439](https://issues.redhat.com/browse/CONSOLE-5439): Migrate to eslint 9 [#16878](https://github.com/openshift/console/pull/16878)
* [CONSOLE-5409](https://issues.redhat.com/browse/CONSOLE-5409): Add Playwright e2e test for operator lifecycle metadata UI [#16701](https://github.com/openshift/console/pull/16701)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Replace page.locator with getByTestId in Playwright tests [#16873](https://github.com/openshift/console/pull/16873)
* [OCPBUGS-90080](https://issues.redhat.com/browse/OCPBUGS-90080): Validate chart URL in /api/helm/verify to prevent SSRF [#16786](https://github.com/openshift/console/pull/16786)
* [CONSOLE-5400](https://issues.redhat.com/browse/CONSOLE-5400): Make Node management enhancements flagged by OpenShift 5 [#16797](https://github.com/openshift/console/pull/16797)
* [CONSOLE-5196](https://issues.redhat.com/browse/CONSOLE-5196): Fix Playwright e2e flakes and CI reliability [#16863](https://github.com/openshift/console/pull/16863)
* NO-JIRA: Remove generated plugin manifest JSON schema files [#16875](https://github.com/openshift/console/pull/16875)
* [CONSOLE-5428](https://issues.redhat.com/browse/CONSOLE-5428): i18next-cli migration follow up [#16864](https://github.com/openshift/console/pull/16864)
* [RFE-4925](https://issues.redhat.com/browse/RFE-4925): Fix inconsistent Search page filter default (use Name) [#16601](https://github.com/openshift/console/pull/16601)
* [HELM-763](https://issues.redhat.com/browse/HELM-763): Add secrets for Helm release upgrade [#16787](https://github.com/openshift/console/pull/16787)
* [CONSOLE-5397](https://issues.redhat.com/browse/CONSOLE-5397): Log perspective overrides when starting Bridge [#16838](https://github.com/openshift/console/pull/16838)
* NO-JIRA: Remove plugin sdk build from `yarn dev` [#16850](https://github.com/openshift/console/pull/16850)
* [OCPBUGS-33836](https://issues.redhat.com/browse/OCPBUGS-33836): quickstart page i18n misses (Fix Quick Starts i18n bundle lookup for zh-CN) [#16819](https://github.com/openshift/console/pull/16819)
* [OCPBUGS-99418](https://issues.redhat.com/browse/OCPBUGS-99418): Bump protobufjs to 7.6.5 to fix CVE-2026-59877, CVE-2026-48712, CVE-2026-41242 [#16813](https://github.com/openshift/console/pull/16813)
* [OCPBUGS-84564](https://issues.redhat.com/browse/OCPBUGS-84564): remove block volume mode in case of ocs-storagecluster-ceph-nfs [#16397](https://github.com/openshift/console/pull/16397)
* [OCPBUGS-86280](https://issues.redhat.com/browse/OCPBUGS-86280): Guard against null plugin route components [#16587](https://github.com/openshift/console/pull/16587)
* [CONSOLE-5434](https://issues.redhat.com/browse/CONSOLE-5434): Replace Popper with PF components [#16831](https://github.com/openshift/console/pull/16831)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: inject centralized TLS into console operand [#16804](https://github.com/openshift/console/pull/16804)
* NO-JIRA: Make regular notification icon outlined by default [#16811](https://github.com/openshift/console/pull/16811)
* [OCPBUGS-94168](https://issues.redhat.com/browse/OCPBUGS-94168): Fix CVE-2026-13149 brace-expansion DoS vulnerability [#16812](https://github.com/openshift/console/pull/16812)
* [OCPBUGS-72369](https://issues.redhat.com/browse/OCPBUGS-72369): i18n format missing for Request/limit unit labels on deploy image page [#16805](https://github.com/openshift/console/pull/16805)
* [OCPBUGS-57309](https://issues.redhat.com/browse/OCPBUGS-57309): '0 B' is shown on details page when create pvc with 'EiB' unit [#16800](https://github.com/openshift/console/pull/16800)
* [OCPBUGS-77379](https://issues.redhat.com/browse/OCPBUGS-77379): Incorrect translations for 'CatalogSources' and 'OperatorGroups' in l… [#16801](https://github.com/openshift/console/pull/16801)
* [OCPBUGS-99475](https://issues.redhat.com/browse/OCPBUGS-99475): Fix virtualized table row overlap after react-virtualized 9.22.6 upgrade [#16798](https://github.com/openshift/console/pull/16798)
* [CONSOLE-5428](https://issues.redhat.com/browse/CONSOLE-5428): migrate to `i18next-cli` [#16796](https://github.com/openshift/console/pull/16796)
* NO-JIRA: Move jest config out of package.json [#16799](https://github.com/openshift/console/pull/16799)
* [CONSOLE-5425](https://issues.redhat.com/browse/CONSOLE-5425): Migrate to rspack [#16761](https://github.com/openshift/console/pull/16761)
* And 7 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/6d0dcf1d76337e46d95ea1b546d5ffe692d7918d...1fbc1a87fdfe55253664dce9a37021dbb8c18284)
### [console-operator](https://github.com/openshift/console-operator/tree/684157180b1dfeb4a5106c669da1ac42258372ec)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): Revert "TRT-2858: Revert "Merge pull request #1196 from ingvagabund/tls-injection-to-console"" [#1205](https://github.com/openshift/console-operator/pull/1205)
* [OSDOCS-20110](https://issues.redhat.com/browse/OSDOCS-20110): Add Helm 3 CLI download links alongside Helm 4 [#1197](https://github.com/openshift/console-operator/pull/1197)
* [OCPBUGS-99943](https://issues.redhat.com/browse/OCPBUGS-99943): set API-server-defaulted fields on deployment specs to prevent excessive update events [#1201](https://github.com/openshift/console-operator/pull/1201)
* [CONSOLE-5431](https://issues.redhat.com/browse/CONSOLE-5431): Add allow-all NetworkPolicy to openshift-console namespace [#1199](https://github.com/openshift/console-operator/pull/1199)
* [TRT-2858](https://issues.redhat.com/browse/TRT-2858): Revert "Merge pull request #1196 from ingvagabund/tls-injection-to-console" [#1200](https://github.com/openshift/console-operator/pull/1200)
* [CONSOLE-5432](https://issues.redhat.com/browse/CONSOLE-5432): Add NetworkPolicy manifests for openshift-console-operator namespace [#1198](https://github.com/openshift/console-operator/pull/1198)
* [CNTRLPLANE-3423](https://issues.redhat.com/browse/CNTRLPLANE-3423): feat: inject centralized TLS into console operand [#1196](https://github.com/openshift/console-operator/pull/1196)
* [Full changelog](https://github.com/openshift/console-operator/compare/694a2de9e7d36a7453de16c5a7f29ce39e0d5ce3...684157180b1dfeb4a5106c669da1ac42258372ec)
### [csi-external-attacher](https://github.com/openshift/csi-external-attacher/tree/3fd668b3f07dd382e5c7b6239d50f7988f652e64)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v4.12.0 for OCP 5.0 [#110](https://github.com/openshift/csi-external-attacher/pull/110)
* [Full changelog](https://github.com/openshift/csi-external-attacher/compare/96ebfa733c06c3398555d164c788e310908fecf6...3fd668b3f07dd382e5c7b6239d50f7988f652e64)
### [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner/tree/7ff338c9d1296f0e5d4d8080a76bb191c8f3be30)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v6.3.0 for OCP 5.0 [#146](https://github.com/openshift/csi-external-provisioner/pull/146)
* [Full changelog](https://github.com/openshift/csi-external-provisioner/compare/bdf440fab8a48e4b76cf0902ad5ba17a20881a8b...7ff338c9d1296f0e5d4d8080a76bb191c8f3be30)
### [csi-external-resizer](https://github.com/openshift/csi-external-resizer/tree/14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.2.1 for OCP 5.0 [#198](https://github.com/openshift/csi-external-resizer/pull/198)
* [Full changelog](https://github.com/openshift/csi-external-resizer/compare/c608adfc7e82c7c59221bb9d22642a1902cace43...14aa7028f485e95c800bb7ffbf9b66a2bf75ceaf)
### [csi-external-snapshotter, csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter/tree/a019d1a9d9e1d26ffd0b2e0d911733180fa608b2)
* [OCPBUGS-99009](https://issues.redhat.com/browse/OCPBUGS-99009): [external-snapshotter] SnapshotContentObjectDeleteError event fired when VolumeSnapshotContent is already deleted [#226](https://github.com/openshift/csi-external-snapshotter/pull/226)
* [Full changelog](https://github.com/openshift/csi-external-snapshotter/compare/b5e4b73f9a761ff8a59f31b982a63e1cdbb76ed8...a019d1a9d9e1d26ffd0b2e0d911733180fa608b2)
### [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe/tree/463dc553ebb04df192d573c5a1612dcb50cb1f52)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.19.0 for OCP 5.0 [#94](https://github.com/openshift/csi-livenessprobe/pull/94)
* [Full changelog](https://github.com/openshift/csi-livenessprobe/compare/f649d2c76f2484b73c70007801eb81ab4be63635...463dc553ebb04df192d573c5a1612dcb50cb1f52)
### [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar/tree/5766960d82ffb9ef84d15e903ae57d0a6781ef11)
* [STOR-2931](https://issues.redhat.com/browse/STOR-2931): Rebase to upstream v2.17.0 for OCP 5.0 [#108](https://github.com/openshift/csi-node-driver-registrar/pull/108)
* [Full changelog](https://github.com/openshift/csi-node-driver-registrar/compare/02d5345005aeb6aac2277818937501cdd1a3a88e...5766960d82ffb9ef84d15e903ae57d0a6781ef11)
### [docker-registry](https://github.com/openshift/image-registry/tree/a91ce6edf2c5cc08aa184c47dff79e842079c533)
* [CORS-4520](https://issues.redhat.com/browse/CORS-4520): GCP: Support Alternate Universe Domain [#474](https://github.com/openshift/image-registry/pull/474)
* [Full changelog](https://github.com/openshift/image-registry/compare/eb1b09dc465a8d53c5683da40f5d5fd306fd945a...a91ce6edf2c5cc08aa184c47dff79e842079c533)
### [driver-toolkit, driver-toolkit-10](https://github.com/openshift/driver-toolkit/tree/b63b175a79b9fe0c29f6ed63df3c2d7862ba408a)
* [OCPBUGS-82502](https://issues.redhat.com/browse/OCPBUGS-82502): Fix e2e test duplicate output from oc run -i --rm [#198](https://github.com/openshift/driver-toolkit/pull/198)
* [Full changelog](https://github.com/openshift/driver-toolkit/compare/7ec03cbba69b4dc86ee33e313bad32ae2ea2924e...b63b175a79b9fe0c29f6ed63df3c2d7862ba408a)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/7b9f54aff1a90ba59242b305fb628db9f20d1d2c)
* NO-JIRA: Remove dead code, drastically shrink vendored deps [#110](https://github.com/openshift/egress-router-cni/pull/110)
* NO-JIRA: Update OWNERS file [#104](https://github.com/openshift/egress-router-cni/pull/104)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/a923d37cfe033853603240f862cb907ba997cb68...7b9f54aff1a90ba59242b305fb628db9f20d1d2c)
### [etcd](https://github.com/openshift/etcd/tree/3688f53af36d9412ab3d99c86d66aafbfb711e7f)
* [CNTRLPLANE-3461](https://issues.redhat.com/browse/CNTRLPLANE-3461): refactor defrag to minimize database lock time [#378](https://github.com/openshift/etcd/pull/378)
* [Full changelog](https://github.com/openshift/etcd/compare/64f8851a001f7e102d47bfe51ca0dac23951879a...3688f53af36d9412ab3d99c86d66aafbfb711e7f)
### [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook/tree/4501ff2f53576c31df0511b69444e65e1eeba745)
* [OCPCLOUD-3585](https://issues.redhat.com/browse/OCPCLOUD-3585): Update gcp-workload-identity-federation-webhook to k8s 1.36 [#21](https://github.com/openshift/gcp-workload-identity-federation-webhook/pull/21)
* [Full changelog](https://github.com/openshift/gcp-workload-identity-federation-webhook/compare/a8f16141e4234fa2c9f6aeb8498622af6e4a080d...4501ff2f53576c31df0511b69444e65e1eeba745)
### [haproxy-router, haproxy-router-haproxy28, haproxy-router-haproxy32](https://github.com/openshift/router/tree/4b401a86dccc657a8a5254c2794a312241f40e87)
* [NE-2826](https://issues.redhat.com/browse/NE-2826): Fix staticcheck warnings across multiple packages [#815](https://github.com/openshift/router/pull/815)
* "NO-JIRA: Add AGENTS.md" [#710](https://github.com/openshift/router/pull/710)
* [NE-2829](https://issues.redhat.com/browse/NE-2829): images/router/f5: Delete F5 router Dockerfile [#826](https://github.com/openshift/router/pull/826)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Revert #825 "Make external cert validation asynchronous (v2 — race condition fixes)" [#829](https://github.com/openshift/router/pull/829)
* [OCPBUGS-77056](https://issues.redhat.com/browse/OCPBUGS-77056): Make external cert validation asynchronous (v2 — race condition fixes) [#825](https://github.com/openshift/router/pull/825)
* [Full changelog](https://github.com/openshift/router/compare/682319a1bb432f0203951c33336d0f55947e1099...4b401a86dccc657a8a5254c2794a312241f40e87)
### [hypershift](https://github.com/openshift/hypershift/tree/a26a7a40e5993ceaee71154720f5bf53fe677169)
* NO-JIRA: isolate NewSession tests from ambient AWS env vars [#8911](https://github.com/openshift/hypershift/pull/8911)
* [CNTRLPLANE-3984](https://issues.redhat.com/browse/CNTRLPLANE-3984): document all skills and commands in SKILLS.md [#9210](https://github.com/openshift/hypershift/pull/9210)
* [OCPBUGS-105193](https://issues.redhat.com/browse/OCPBUGS-105193): extract HCCO webhook validation into a dedicated controller [#9239](https://github.com/openshift/hypershift/pull/9239)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): add manual trigger and fix path filter for docs publish [#9261](https://github.com/openshift/hypershift/pull/9261)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): correct wrangler pages deploy flags for docs publish [#9252](https://github.com/openshift/hypershift/pull/9252)
* [OCPBUGS-60093](https://issues.redhat.com/browse/OCPBUGS-60093): fix(upsert): add desired-state hash to detect spec field removals [#7713](https://github.com/openshift/hypershift/pull/7713)
* [CNTRLPLANE-3997](https://issues.redhat.com/browse/CNTRLPLANE-3997): add workflow to publish docs to Cloudflare Pages on merge [#9221](https://github.com/openshift/hypershift/pull/9221)
* [CNTRLPLANE-3291](https://issues.redhat.com/browse/CNTRLPLANE-3291): docs: add upstream documentation for configurable log levels [#9193](https://github.com/openshift/hypershift/pull/9193)
* [CNTRLPLANE-3978](https://issues.redhat.com/browse/CNTRLPLANE-3978): Fix CPO finalizer race leaving orphaned Azure Private Endpoint resources [#9194](https://github.com/openshift/hypershift/pull/9194)
* [CNTRLPLANE-3873](https://issues.redhat.com/browse/CNTRLPLANE-3873), [CNTRLPLANE-3874](https://issues.redhat.com/browse/CNTRLPLANE-3874), [OCPBUGS-94518](https://issues.redhat.com/browse/OCPBUGS-94518): update azure CPO overrides for 4.20, 4.21, 4.22 [#9211](https://github.com/openshift/hypershift/pull/9211)
* [CNTRLPLANE-3375](https://issues.redhat.com/browse/CNTRLPLANE-3375): test(e2e): remove oc dependency in external oidc e2e tests [#9208](https://github.com/openshift/hypershift/pull/9208)
* [OCPBUGS-104543](https://issues.redhat.com/browse/OCPBUGS-104543): fix test isolation bug in EnsureDefaultSecurityGroupTagsTest [#9228](https://github.com/openshift/hypershift/pull/9228)
* NO-JIRA: build(deps): bump the github-dependencies group with 23 updates [#9190](https://github.com/openshift/hypershift/pull/9190)
* [OCPBUGS-104505](https://issues.redhat.com/browse/OCPBUGS-104505): fix(ci): trigger envtest workflows on dependency changes [#9215](https://github.com/openshift/hypershift/pull/9215)
* [CNTRLPLANE-3673](https://issues.redhat.com/browse/CNTRLPLANE-3673): add HO Konflux release gating documentation [#8947](https://github.com/openshift/hypershift/pull/8947)
* [OCPBUGS-100279](https://issues.redhat.com/browse/OCPBUGS-100279): load plugin explicitly in bare mode for skill resolution [#9220](https://github.com/openshift/hypershift/pull/9220)
* [OCPBUGS-104528](https://issues.redhat.com/browse/OCPBUGS-104528): Update openshift API to resolve broken hypershift integration tests on K8s 1.30 [#9231](https://github.com/openshift/hypershift/pull/9231)
* [OCPBUGS-105207](https://issues.redhat.com/browse/OCPBUGS-105207): Revert "OCPBUGS-89689: (karpenter) use completed release image for unpinned NodeClaims during CP upgrade" [#9233](https://github.com/openshift/hypershift/pull/9233)
* NO-JIRA: fix(build): bump hack/tools Go version to 1.26.0 to match main module [#9223](https://github.com/openshift/hypershift/pull/9223)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): e2e: Remove osImageStream cleanup that violates immutability [#9206](https://github.com/openshift/hypershift/pull/9206)
* [OCPBUGS-100054](https://issues.redhat.com/browse/OCPBUGS-100054): Fix Azure Private clusters without external DNS [#9171](https://github.com/openshift/hypershift/pull/9171)
* [GCP-896](https://issues.redhat.com/browse/GCP-896): chore: add gbarabasz to gcp-reviewers alias [#9000](https://github.com/openshift/hypershift/pull/9000)
* [CNTRLPLANE-3979](https://issues.redhat.com/browse/CNTRLPLANE-3979): Add missing ProjectDevelopmentStream 4.14 [#9225](https://github.com/openshift/hypershift/pull/9225)
* [CNTRLPLANE-3863](https://issues.redhat.com/browse/CNTRLPLANE-3863): emit lifecycle-aware JUnit for informing e2e tests [#9168](https://github.com/openshift/hypershift/pull/9168)
* NO-JIRA: add e2e-approvers owner alias, grant Dan Mace e2e role [#9216](https://github.com/openshift/hypershift/pull/9216)
* NO-JIRA: build(deps): bump the k8s-dependencies group across 1 directory with 12 updates [#9189](https://github.com/openshift/hypershift/pull/9189)
* [OCPBUGS-100184](https://issues.redhat.com/browse/OCPBUGS-100184): Wait for Azure ignition DNS before creating workers [#9172](https://github.com/openshift/hypershift/pull/9172)
* [OCPBUGS-100279](https://issues.redhat.com/browse/OCPBUGS-100279): isolate Claude from push credentials in PR workflows [#9214](https://github.com/openshift/hypershift/pull/9214)
* [OCPBUGS-98983](https://issues.redhat.com/browse/OCPBUGS-98983): improve guest cluster state management reliability [#9198](https://github.com/openshift/hypershift/pull/9198)
* [STOR-2918](https://issues.redhat.com/browse/STOR-2918): update AWS EBS CSI credentials request policy to mirror upstream [#8954](https://github.com/openshift/hypershift/pull/8954)
* [OCPBUGS-100301](https://issues.redhat.com/browse/OCPBUGS-100301): fix(hostedcluster): handle Unknown status in ClusterVersionFailing inversion [#9186](https://github.com/openshift/hypershift/pull/9186)
* [OCPBUGS-89689](https://issues.redhat.com/browse/OCPBUGS-89689): (karpenter) use completed release image for unpinned NodeClaims during CP upgrade [#8957](https://github.com/openshift/hypershift/pull/8957)
* NO-JIRA: build(deps): bump the misc-dependencies group across 1 directory with 6 updates [#9164](https://github.com/openshift/hypershift/pull/9164)
* [CNTRLPLANE-3863](https://issues.redhat.com/browse/CNTRLPLANE-3863): add e2e v2 test flow document [#9151](https://github.com/openshift/hypershift/pull/9151)
* docs: add July 2026 progress report blog post [#9057](https://github.com/openshift/hypershift/pull/9057)
* [OCPBUGS-100302](https://issues.redhat.com/browse/OCPBUGS-100302): fix(metrics): only report limited support when label … [#9185](https://github.com/openshift/hypershift/pull/9185)
* NO-JIRA: build(deps): bump github.com/google/cel-go from 0.28.1 to 0.29.0 [#9125](https://github.com/openshift/hypershift/pull/9125)
* [CNTRLPLANE-3943](https://issues.redhat.com/browse/CNTRLPLANE-3943): feat(destroy): add --force flag to strip finalizers on grace period expiry [#9134](https://github.com/openshift/hypershift/pull/9134)
* [STOR-2954](https://issues.redhat.com/browse/STOR-2954): inject centralized TLS configuration for storage operators [#8887](https://github.com/openshift/hypershift/pull/8887)
* Revert "CNTRLPLANE-3890: Add product-cli unit tests for HCP create cluster" [#9201](https://github.com/openshift/hypershift/pull/9201)
* [CNTRLPLANE-3871](https://issues.redhat.com/browse/CNTRLPLANE-3871): resolve RHEL stream dynamically for boot images [#9099](https://github.com/openshift/hypershift/pull/9099)
* NO-JIRA: build(deps): bump the sigs-k8s-dependencies group across 1 directory with 8 updates [#9177](https://github.com/openshift/hypershift/pull/9177)
* [CNTRLPLANE-3890](https://issues.redhat.com/browse/CNTRLPLANE-3890): Add product-cli unit tests for HCP create cluster [#9107](https://github.com/openshift/hypershift/pull/9107)
* [CNTRLPLANE-3646](https://issues.redhat.com/browse/CNTRLPLANE-3646): wire up AWS v2 e2e lifecycle test coverage [#9174](https://github.com/openshift/hypershift/pull/9174)
* [OCPBUGS-100140](https://issues.redhat.com/browse/OCPBUGS-100140): bracket IPv6 in OAuth issuer and callback URLs [#9120](https://github.com/openshift/hypershift/pull/9120)
* [AUTOSCALE-644](https://issues.redhat.com/browse/AUTOSCALE-644): bump karpenter deps to 1.13.0 [#9170](https://github.com/openshift/hypershift/pull/9170)
* [CNTRLPLANE-3976](https://issues.redhat.com/browse/CNTRLPLANE-3976): Document management cluster vs hosted cluster feature gates [#9182](https://github.com/openshift/hypershift/pull/9182)
* [OCPBUGS-97804](https://issues.redhat.com/browse/OCPBUGS-97804): Avoid printing errors twice [#8931](https://github.com/openshift/hypershift/pull/8931)
* [CNTRLPLANE-3887](https://issues.redhat.com/browse/CNTRLPLANE-3887): test(e2e): add metricsSet filtering coverage to metrics forwarder test [#9078](https://github.com/openshift/hypershift/pull/9078)
* [OCPBUGS-86843](https://issues.redhat.com/browse/OCPBUGS-86843): fix(konnectivity): conditionally prefer IPv4 based on HCP network config [#9140](https://github.com/openshift/hypershift/pull/9140)
* [OCPBUGS-91511](https://issues.redhat.com/browse/OCPBUGS-91511): Fix CPO infinite requeue during deletion when OIDC provider is gone [#8894](https://github.com/openshift/hypershift/pull/8894)
* [OCPBUGS-98654](https://issues.redhat.com/browse/OCPBUGS-98654): delete_hosted_cluster.sh fails to run with no --dns-zone-rg-name flag [#8945](https://github.com/openshift/hypershift/pull/8945)
* NO-JIRA: docs: fix ARCHITECTURE.md to reflect current CPO image resolution [#9179](https://github.com/openshift/hypershift/pull/9179)
* [OCPBUGS-100087](https://issues.redhat.com/browse/OCPBUGS-100087): Replace exponential backoff with fixed-interval requeue in CRR controller [#9148](https://github.com/openshift/hypershift/pull/9148)
* [OCPBUGS-99783](https://issues.redhat.com/browse/OCPBUGS-99783): fix(e2e): check pre-upgrade HO version for shared role support [#8891](https://github.com/openshift/hypershift/pull/8891)
* [CNTRLPLANE-3709](https://issues.redhat.com/browse/CNTRLPLANE-3709): test(azure): enable Global Pull Secret test in Azure CI [#9073](https://github.com/openshift/hypershift/pull/9073)
* [CNTRLPLANE-3956](https://issues.redhat.com/browse/CNTRLPLANE-3956): Make EnsureGlobalPullSecret e2e test informing [#9167](https://github.com/openshift/hypershift/pull/9167)
* [CNTRLPLANE-2539](https://issues.redhat.com/browse/CNTRLPLANE-2539): Move generation of the CAPI Provider Role [#8305](https://github.com/openshift/hypershift/pull/8305)
* NO-JIRA: docs: add hash migration impact guidance and CPO data-plane component docs [#9161](https://github.com/openshift/hypershift/pull/9161)
* [CNTRLPLANE-3897](https://issues.redhat.com/browse/CNTRLPLANE-3897): Add product-cli unit tests for create nodepool [#9121](https://github.com/openshift/hypershift/pull/9121)
* [CNTRLPLANE-3600](https://issues.redhat.com/browse/CNTRLPLANE-3600): Bump k8s to v0.36.2, controller-runtime to v0.24.1, CAPI to v1.12.8 [#8695](https://github.com/openshift/hypershift/pull/8695)
* [CNTRLPLANE-3944](https://issues.redhat.com/browse/CNTRLPLANE-3944): Regenerate requirements.txt files with pinned --hash entries [#9135](https://github.com/openshift/hypershift/pull/9135)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): fix yq dependency for running upstream karpenter tests [#9060](https://github.com/openshift/hypershift/pull/9060)
* [OCPBUGS-99288](https://issues.redhat.com/browse/OCPBUGS-99288): Add proxy env vars to AWS cloud-controller-manager deployment [#9053](https://github.com/openshift/hypershift/pull/9053)
* [CNTRLPLANE-3604](https://issues.redhat.com/browse/CNTRLPLANE-3604): Add CAPI migration flag placeholder [#9145](https://github.com/openshift/hypershift/pull/9145)
* [CNTRLPLANE-3564](https://issues.redhat.com/browse/CNTRLPLANE-3564): test(awsprivatelink): add unit test for NoSuchHostedZone handling dur… [#9141](https://github.com/openshift/hypershift/pull/9141)
* NO-JIRA: build(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 [#9113](https://github.com/openshift/hypershift/pull/9113)
* NO-JIRA: build(deps): bump google.golang.org/grpc from 1.79.3 to 1.82.1 in /hack/tools [#9111](https://github.com/openshift/hypershift/pull/9111)
* [CNTRLPLANE-3888](https://issues.redhat.com/browse/CNTRLPLANE-3888): docs: add on-demand jira-agent triggering and plugin install instructions [#9079](https://github.com/openshift/hypershift/pull/9079)
* [OCPBUGS-54776](https://issues.redhat.com/browse/OCPBUGS-54776): fix(ignition-server): log MCS output on HTTP request failures [#8936](https://github.com/openshift/hypershift/pull/8936)
* [CNTRLPLANE-400](https://issues.redhat.com/browse/CNTRLPLANE-400): feat(remediationAllowed in NP): propagate MHC RemediationAllowed to NodePool Ready condition [#9019](https://github.com/openshift/hypershift/pull/9019)
* NO-JIRA: align control-plane Dockerfile builder image with main Dockerfile [#9138](https://github.com/openshift/hypershift/pull/9138)
* [OCPBUGS-99768](https://issues.redhat.com/browse/OCPBUGS-99768): fix OSImageStream e2e test and Makefile test-changed for OCP 5.0 [#9115](https://github.com/openshift/hypershift/pull/9115)
* [CNTRLPLANE-3893](https://issues.redhat.com/browse/CNTRLPLANE-3893): Add product-cli unit tests for destroy cluster [#9116](https://github.com/openshift/hypershift/pull/9116)
* NO-JIRA: ci(deps): bump actions/checkout from 6.0.2 to 7.0.1 [#9090](https://github.com/openshift/hypershift/pull/9090)
* NO-JIRA: ci(deps): bump actions/setup-python from 6.2.0 to 7.0.0 [#9089](https://github.com/openshift/hypershift/pull/9089)
* NO-JIRA: ci(deps): bump actions/setup-go from 6.4.0 to 7.0.0 [#9029](https://github.com/openshift/hypershift/pull/9029)
* [OCPBUGS-86494](https://issues.redhat.com/browse/OCPBUGS-86494): fix(nodepool): preserve KubeVirt userdata Secrets during NodePool rollout [#8581](https://github.com/openshift/hypershift/pull/8581)
* [Full changelog](https://github.com/openshift/hypershift/compare/872a7e821c3fe01b2f866ceada3749a899e3d64f...a26a7a40e5993ceaee71154720f5bf53fe677169)
### [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm/tree/11bc35dd6fd5163259023a6f1dfcc59ce813ab5f)
* [OCPCLOUD-3593](https://issues.redhat.com/browse/OCPCLOUD-3593): Rebase from upstream IBM-Cloud/cloud-provider-ibm release-1.36 (K8s 1.36.2) [#109](https://github.com/openshift/cloud-provider-ibm/pull/109)
* [Full changelog](https://github.com/openshift/cloud-provider-ibm/compare/ef8fcc288d9248cd149f181e7f5c896f4a10eb3b...11bc35dd6fd5163259023a6f1dfcc59ce813ab5f)
### [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver/tree/3a89d7d17d25727270414b07d3daaa3bc329d743)
* NO-JIRA: standardize build paths [#155](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/155)
* [STOR-2921](https://issues.redhat.com/browse/STOR-2921): Rebase to v5.2.27 for OCP 5.0 [#154](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/154)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver/compare/f78abbb3502a875b7ddf769cf6b7c1b8e3ebba29...3a89d7d17d25727270414b07d3daaa3bc329d743)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/286dd2de7957e9c2897e152417f16907d324d819)
* 🚀 OCPCLOUD-3602: Merge https://github.com/kubernetes-sigs/cluster-api-provider-ibmcloud:v0.14.0 (5d081d1) into main [#161](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/161)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/be3192e4c05659282c3d1f1720f8cd93b59b399a...286dd2de7957e9c2897e152417f16907d324d819)
### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/2615d13b730255b21ccb401d3dc039006c54a4fe)
* [OCPCLOUD-3618](https://issues.redhat.com/browse/OCPCLOUD-3618): Bump k8s 1.36 [#100](https://github.com/openshift/machine-api-provider-ibmcloud/pull/100)
* [OCPBUGS-96827](https://issues.redhat.com/browse/OCPBUGS-96827): bump golang.org/x/net to v0.57.0 [#98](https://github.com/openshift/machine-api-provider-ibmcloud/pull/98)
* [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/a31f65a766150264daac38fcebe1d111c5ad79a0...2615d13b730255b21ccb401d3dc039006c54a4fe)
### [insights-operator](https://github.com/openshift/insights-operator/tree/8494b69b8075fd1e8eac49db77bcda7588078155)
* [CCXDEV-16647](https://issues.redhat.com/browse/CCXDEV-16647): add create gatherer skill [#1335](https://github.com/openshift/insights-operator/pull/1335)
* NO-JIRA: remove katarina [#1336](https://github.com/openshift/insights-operator/pull/1336)
* [CCXDEV-16629](https://issues.redhat.com/browse/CCXDEV-16629): Add network policy [#1331](https://github.com/openshift/insights-operator/pull/1331)
* [CCXDEV-15210](https://issues.redhat.com/browse/CCXDEV-15210): secrets and configmap revisions count gathering [#1316](https://github.com/openshift/insights-operator/pull/1316)
* [OCPBUGS-98690](https://issues.redhat.com/browse/OCPBUGS-98690): Fix indentation bug on livenessProbe [#1320](https://github.com/openshift/insights-operator/pull/1320)
* [OCPBUGS-96894](https://issues.redhat.com/browse/OCPBUGS-96894): Update net and crypto libraries [#1321](https://github.com/openshift/insights-operator/pull/1321)
* [Full changelog](https://github.com/openshift/insights-operator/compare/46db2e2ca9b0b7576e0b66f4521a2cf83aad8893...8494b69b8075fd1e8eac49db77bcda7588078155)
### [insights-runtime-exporter, insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor/tree/d70c566bcd4a2af3825fe5cfa6383d73530d6a0f)
* NO-JIRA: Add new owners required for managing OCP CI config [#86](https://github.com/openshift/insights-runtime-extractor/pull/86)
* [Full changelog](https://github.com/openshift/insights-runtime-extractor/compare/ce30b4f9bc3ec867b976886a5207d36c50a396d9...d70c566bcd4a2af3825fe5cfa6383d73530d6a0f)
### [karpenter-operator](https://github.com/openshift/karpenter-operator/tree/560232d2b6962e041dc332f08026adda14552d41)
* [AUTOSCALE-166](https://issues.redhat.com/browse/AUTOSCALE-166): Add make target and scripts for karpenter core regression e2e tests [#20](https://github.com/openshift/karpenter-operator/pull/20)
* [AUTOSCALE-871](https://issues.redhat.com/browse/AUTOSCALE-871): allow Karpenter Operator to run in ManagementCluster mode [#19](https://github.com/openshift/karpenter-operator/pull/19)
* no-jira: change karpenter CR singleton name to default [#17](https://github.com/openshift/karpenter-operator/pull/17)
* [Full changelog](https://github.com/openshift/karpenter-operator/compare/79a93d5b4221424832a247a618e20b8177ec71ed...560232d2b6962e041dc332f08026adda14552d41)
### [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server/tree/3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71)
* [OCPBUGS-93753](https://issues.redhat.com/browse/OCPBUGS-93753): Bump openshift/kubernetes-metrics-server to v0.9.0 [#71](https://github.com/openshift/kubernetes-metrics-server/pull/71)
* [Full changelog](https://github.com/openshift/kubernetes-metrics-server/compare/e24eb97b02b3d39095c70675f5594ae5bc98d238...3d2e9cd0469d636e32dc0e4d4b6f65957eb27d71)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/0db39ee372bf7b75f56898fd2df555e063d32952)
* [OCPBUGS-85110](https://issues.redhat.com/browse/OCPBUGS-85110): Move required-scc annotation to pod template for machine-api-controllers [#1511](https://github.com/openshift/machine-api-operator/pull/1511)
* [OCPBUGS-100056](https://issues.redhat.com/browse/OCPBUGS-100056): fix: skip Multisubnet test for single network infra [#1527](https://github.com/openshift/machine-api-operator/pull/1527)
* [OCPBUGS-99903](https://issues.redhat.com/browse/OCPBUGS-99903): Fixing test issue where error result was for other resource type [#1524](https://github.com/openshift/machine-api-operator/pull/1524)
* [OCPBUGS-100067](https://issues.redhat.com/browse/OCPBUGS-100067): Deduplicate unchanged status upgrade events [#1526](https://github.com/openshift/machine-api-operator/pull/1526)
* [CORS-4521](https://issues.redhat.com/browse/CORS-4521): GCP: Add regional permission [#1523](https://github.com/openshift/machine-api-operator/pull/1523)
* [OCPCLOUD-3614](https://issues.redhat.com/browse/OCPCLOUD-3614): bump k8s and openshift deps [#1520](https://github.com/openshift/machine-api-operator/pull/1520)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/3be0a58b3e9d168eb2dd746c58d79e9081f10c73...0db39ee372bf7b75f56898fd2df555e063d32952)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/84999756cf4ca5b20cc0b1f3b20cfda9bd22fdd6)
* [OCPBUGS-105432](https://issues.redhat.com/browse/OCPBUGS-105432): fix nil pointer panic in IRI controller informer race [#6385](https://github.com/openshift/machine-config-operator/pull/6385)
* NO-ISSUE: Adapt vsphere bootimage tests for mult-vcenter scenarios [#6317](https://github.com/openshift/machine-config-operator/pull/6317)
* [OCPBUGS-92062](https://issues.redhat.com/browse/OCPBUGS-92062): reduce memory usage in MCC and MCD [#6259](https://github.com/openshift/machine-config-operator/pull/6259)
* [OCPBUGS-100433](https://issues.redhat.com/browse/OCPBUGS-100433): Update AMI Whitelist [#6358](https://github.com/openshift/machine-config-operator/pull/6358)
* [MCO-2275](https://issues.redhat.com/browse/MCO-2275): Part2 Migrate MCO OCB [#6340](https://github.com/openshift/machine-config-operator/pull/6340)
* [MCO-1814](https://issues.redhat.com/browse/MCO-1814), [MCO-2377](https://issues.redhat.com/browse/MCO-2377): Setup metrics for builds, Add metric to gather how many people are using OCL [#6316](https://github.com/openshift/machine-config-operator/pull/6316)
* [OCPNODE-4040](https://issues.redhat.com/browse/OCPNODE-4040): Use single KubeletConfigAccepted condition type with True/False status [#5854](https://github.com/openshift/machine-config-operator/pull/5854)
* [OCPBUGS-92182](https://issues.redhat.com/browse/OCPBUGS-92182): OCPBUGS-99219: Use providerSpec.Template in vSphere machineset reconciliation [#6234](https://github.com/openshift/machine-config-operator/pull/6234)
* [OCPBUGS-99696](https://issues.redhat.com/browse/OCPBUGS-99696): Add extension verification failure test cases OCP-89090 and OCP-89095 [#6333](https://github.com/openshift/machine-config-operator/pull/6333)
* [MCO-2485](https://issues.redhat.com/browse/MCO-2485): Mark scale-up test as 'informing' [#6364](https://github.com/openshift/machine-config-operator/pull/6364)
* [OCPBUGS-100458](https://issues.redhat.com/browse/OCPBUGS-100458): Adapt bootimage tests for CAPI migration [#6363](https://github.com/openshift/machine-config-operator/pull/6363)
* [MCO-1540](https://issues.redhat.com/browse/MCO-1540): Set up events for builds [#6252](https://github.com/openshift/machine-config-operator/pull/6252)
* [MCO-2482](https://issues.redhat.com/browse/MCO-2482): Revert "MCO-2470: Disable scale-up test support for AWS and vSphere" [#6356](https://github.com/openshift/machine-config-operator/pull/6356)
* [TRT-2875](https://issues.redhat.com/browse/TRT-2875): Revert #6303 "MCO-2205: Make ImageModeStatusReporting MCP count test more resilient on SNO" [#6359](https://github.com/openshift/machine-config-operator/pull/6359)
* [MCO-2205](https://issues.redhat.com/browse/MCO-2205): Make ImageModeStatusReporting MCP count test more resilient on SNO [#6303](https://github.com/openshift/machine-config-operator/pull/6303)
* [OCPBUGS-98316](https://issues.redhat.com/browse/OCPBUGS-98316): Fix SHA idempotency test in nmstate-configuration.sh [#6291](https://github.com/openshift/machine-config-operator/pull/6291)
* [OCPBUGS-100389](https://issues.redhat.com/browse/OCPBUGS-100389): machine-config-daemon-firstboot: disable ostree fsync during bootstrap [#6122](https://github.com/openshift/machine-config-operator/pull/6122)
* [MCO-2275](https://issues.redhat.com/browse/MCO-2275): Part 1 Migrate OCB test cases from openshift-tests-private [#6080](https://github.com/openshift/machine-config-operator/pull/6080)
* NO-ISSUE: test MCC proxy. Refactor TC 52373 proxy test. [#6355](https://github.com/openshift/machine-config-operator/pull/6355)
* [MCO-2468](https://issues.redhat.com/browse/MCO-2468): Cache backed OSImageStreams for PIS [#6329](https://github.com/openshift/machine-config-operator/pull/6329)
* NO-ISSUE: Fix setArchitectureAndCheckStatus corrupting multi-label annotations [#6347](https://github.com/openshift/machine-config-operator/pull/6347)
* [OCPBUGS-100277](https://issues.redhat.com/browse/OCPBUGS-100277): Fix TC 43278 failing when release payload has no MCO commit info [#6349](https://github.com/openshift/machine-config-operator/pull/6349)
* NO-ISSUE: Fix incorrect OSImageStreams log [#6338](https://github.com/openshift/machine-config-operator/pull/6338)
* [MCO-2244](https://issues.redhat.com/browse/MCO-2244): Update MCO dependencies to Kubernetes 1.36 [#6321](https://github.com/openshift/machine-config-operator/pull/6321)
* [MCO-2470](https://issues.redhat.com/browse/MCO-2470): Disable scale-up test support for AWS and vSphere [#6344](https://github.com/openshift/machine-config-operator/pull/6344)
* NO-ISSUE: fix fencing_validator ocdebug fence dispatch race condition [#6341](https://github.com/openshift/machine-config-operator/pull/6341)
* [OCPBUGS-82139](https://issues.redhat.com/browse/OCPBUGS-82139): Add control-plane NoSchedule taint support alongside master taint [#6313](https://github.com/openshift/machine-config-operator/pull/6313)
* NO-JIRA: vendor: bump github.com/openshift/api to latest master [#6334](https://github.com/openshift/machine-config-operator/pull/6334)
* NO-ISSUE: Use context instead of discrete signal [#6337](https://github.com/openshift/machine-config-operator/pull/6337)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/3b4a5c7d9fa127981c57efac6fa29bc76eac019d...84999756cf4ca5b20cc0b1f3b20cfda9bd22fdd6)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/bf618aac93c71a56e8249669c579f0a782742e2e)
* [OCPBUGS-86888](https://issues.redhat.com/browse/OCPBUGS-86888): Add IDMS mirror support for disconnected aarch64 ISO extraction [#108](https://github.com/openshift/machine-os-images/pull/108)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/7e514b05e0825994d858d0a142e255abdd0e8f2d...bf618aac93c71a56e8249669c579f0a782742e2e)
### [metallb-frr](https://github.com/openshift/frr/tree/54a6ea48902d81460536b81ea6bdceb89c12e622)
* [OCPBUGS-104452](https://issues.redhat.com/browse/OCPBUGS-104452): Fix TLS ciphers for MinVersion=1.3 [#135](https://github.com/openshift/frr/pull/135)
* [Full changelog](https://github.com/openshift/frr/compare/5d3b12b6ce0a7def4a7a4d1df7ff9e88deb430f5...54a6ea48902d81460536b81ea6bdceb89c12e622)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/2abd16ff885db25f1211cc9daf591c8c35e399b7)
* [OCPBUGS-98488](https://issues.redhat.com/browse/OCPBUGS-98488): security: fix js-yaml vulnerable version [#1115](https://github.com/openshift/monitoring-plugin/pull/1115)
* NO-JIRA: feat: add renovate configuration [#1113](https://github.com/openshift/monitoring-plugin/pull/1113)
* [OCPBUGS-104374](https://issues.redhat.com/browse/OCPBUGS-104374): upgrade go stdlib and patch vulnerabilities [#1111](https://github.com/openshift/monitoring-plugin/pull/1111)
* [OU-1409](https://issues.redhat.com/browse/OU-1409): fix: remove deprecation in favor of k8sListItems to fetch agentic runs [#1110](https://github.com/openshift/monitoring-plugin/pull/1110)
* [OU-1466](https://issues.redhat.com/browse/OU-1466): swap dashboard-list-page to use shared table setup [#1109](https://github.com/openshift/monitoring-plugin/pull/1109)
* NO-JIRA: don't filter silences based on namespace in acm [#1108](https://github.com/openshift/monitoring-plugin/pull/1108)
* [OCPBUGS-98877](https://issues.redhat.com/browse/OCPBUGS-98877): fix: upgrade linkify-it [#1104](https://github.com/openshift/monitoring-plugin/pull/1104)
* [OU-1389](https://issues.redhat.com/browse/OU-1389): remove default features from plugin-backend [#1078](https://github.com/openshift/monitoring-plugin/pull/1078)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/9fbf9a64cdd3659c677452193e9afbc3d87ad702...2abd16ff885db25f1211cc9daf591c8c35e399b7)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/f099946680e376f722674e684aec96a73c58e919)
* [OCPBUGS-86046](https://issues.redhat.com/browse/OCPBUGS-86046), [OCPBUGS-94044](https://issues.redhat.com/browse/OCPBUGS-94044): DS Merge 07/24/2026 [#335](https://github.com/openshift/multus-cni/pull/335)
* [CORENET-7233](https://issues.redhat.com/browse/CORENET-7233): Update OWNERS file [#304](https://github.com/openshift/multus-cni/pull/304)
* [Full changelog](https://github.com/openshift/multus-cni/compare/15a47271dcfda5c0e57a0a79720bab4e0baabdd8...f099946680e376f722674e684aec96a73c58e919)
### [must-gather](https://github.com/openshift/must-gather/tree/fd47ab2c1d183a1e66a1a74fe30cf6a26f433409)
* [MG-233](https://issues.redhat.com/browse/MG-233): compress service and window node logs (#554) [#554](https://github.com/openshift/must-gather/pull/554)
* [Full changelog](https://github.com/openshift/must-gather/compare/9bb48fe05db060476f9a380b9d6ea16f1e94a98b...fd47ab2c1d183a1e66a1a74fe30cf6a26f433409)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/33788405f30ef023250fd8fab71caeab57ec6b90)
* IP address & Adapter model columns [#465](https://github.com/openshift/networking-console-plugin/pull/465)
* [OCPNETUI-58](https://issues.redhat.com/browse/OCPNETUI-58): Add Health and Backend health columns to Services and Routes list pages [#457](https://github.com/openshift/networking-console-plugin/pull/457)
* [OCPNETUI-38](https://issues.redhat.com/browse/OCPNETUI-38): Virtual Machines tab on NAD/UDN/CUDN detail pages [#442](https://github.com/openshift/networking-console-plugin/pull/442)
* [OCPNETUI-21](https://issues.redhat.com/browse/OCPNETUI-21), [OCPNETUI-25](https://issues.redhat.com/browse/OCPNETUI-25): made form for creating services [#453](https://github.com/openshift/networking-console-plugin/pull/453)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/2d8f85d257952c1a90467b6ee397334d49b7820e...33788405f30ef023250fd8fab71caeab57ec6b90)
### [oauth-server](https://github.com/openshift/oauth-server/tree/ffad196a95584670d3a2e20e270cb23a64e6a327)
* [RFE-9629](https://issues.redhat.com/browse/RFE-9629): Add copy to clipboard buttons to display token page [#200](https://github.com/openshift/oauth-server/pull/200)
* [Full changelog](https://github.com/openshift/oauth-server/compare/af32a04e7a91c538afe3808d51a5d28cf3480b22...ffad196a95584670d3a2e20e270cb23a64e6a327)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/cf65286ba31b6e4eda0ecb03ae10581a7e1ac688)
* [OCPBUGS-89330](https://issues.redhat.com/browse/OCPBUGS-89330): Synchronize From Upstream Repositories [#779](https://github.com/openshift/operator-framework-operator-controller/pull/779)
* NO-ISSUE: Synchronize From Upstream Repositories [#776](https://github.com/openshift/operator-framework-operator-controller/pull/776)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/be80e0c78d4e2ff3d29fd89df29dff79b00b15f6...cf65286ba31b6e4eda0ecb03ae10581a7e1ac688)
### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/58298ec3f0772b16598ca8df5ce29c0a3e5f022c)
* [OCPBUGS-85429](https://issues.redhat.com/browse/OCPBUGS-85429): hack/update-openapi-spec: prefer REGISTRY_AUTH_FILE over cluster profile pull secret [#669](https://github.com/openshift/openshift-apiserver/pull/669)
* [OCPBUGS-78480](https://issues.redhat.com/browse/OCPBUGS-78480): address review feedback on project watcher [#664](https://github.com/openshift/openshift-apiserver/pull/664)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/3725a4aafba556cc24626541f5121ccbab54916a...58298ec3f0772b16598ca8df5ce29c0a3e5f022c)
### [openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/aa9a8100e87ff13abf4dd6343c84c9f4948debef)
* [OCPBUGS-96822](https://issues.redhat.com/browse/OCPBUGS-96822): Bump golang.org/x/net to v0.55.0 [#405](https://github.com/openshift/cloud-provider-openstack/pull/405)
* [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/f8bb5994f3cee8ee2bb5cca25e3e9783ad7dd57c...aa9a8100e87ff13abf4dd6343c84c9f4948debef)
### [openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/756f6b8bb00400e3d72437876a820a950c393eb3)
* [STOR-2998](https://issues.redhat.com/browse/STOR-2998): Remove legacy gcp-pd-csi-driver-operator [#592](https://github.com/openshift/csi-operator/pull/592)
* [STOR-3060](https://issues.redhat.com/browse/STOR-3060), [STOR-3061](https://issues.redhat.com/browse/STOR-3061): implement TLS adherence for AWS EFS and SMB CSI driver operator [#587](https://github.com/openshift/csi-operator/pull/587)
* [STOR-2998](https://issues.redhat.com/browse/STOR-2998): Copy the test manifests from the `legacy` dir to a top-level `test` dir [#589](https://github.com/openshift/csi-operator/pull/589)
* [STOR-2997](https://issues.redhat.com/browse/STOR-2997): Auto generate assets for gcp pd csi driver [#585](https://github.com/openshift/csi-operator/pull/585)
* [OCPBUGS-99199](https://issues.redhat.com/browse/OCPBUGS-99199): Add networking.k8s.io group policy [#579](https://github.com/openshift/csi-operator/pull/579)
* [STOR-2914](https://issues.redhat.com/browse/STOR-2914): Bump all deps for 5.0.0 [#582](https://github.com/openshift/csi-operator/pull/582)
* [Full changelog](https://github.com/openshift/csi-operator/compare/50f79e773ab432a91299a06003191a1fc2535746...756f6b8bb00400e3d72437876a820a950c393eb3)
### [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack/tree/4f65df9309c97435fc53c05f6ea4b6135b243166)
* [OSPRH-33339](https://issues.redhat.com/browse/OSPRH-33339): Add rebasebot post-rebase hook script [#428](https://github.com/openshift/cluster-api-provider-openstack/pull/428)
* [OCPBUGS-94057](https://issues.redhat.com/browse/OCPBUGS-94057): UPSTREAM: 3265: :bug: allow unconditional providerID updates in OpenStackMachine [#425](https://github.com/openshift/cluster-api-provider-openstack/pull/425)
* [Full changelog](https://github.com/openshift/cluster-api-provider-openstack/compare/51bafa8bfb18064eae0ca9502fb4bb6c6963ff61...4f65df9309c97435fc53c05f6ea4b6135b243166)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/ebb46755980dd2c08d186e79cd7e98029a5adc2a)
* NO-ISSUE: Synchronize From Upstream Repositories [#1343](https://github.com/openshift/operator-framework-olm/pull/1343)
* NO-ISSUE: Synchronize From Upstream Repositories [#1340](https://github.com/openshift/operator-framework-olm/pull/1340)
* [OCPBUGS-96749](https://issues.redhat.com/browse/OCPBUGS-96749), [OCPBUGS-96752](https://issues.redhat.com/browse/OCPBUGS-96752): Synchronize From Upstream Repositories [#1338](https://github.com/openshift/operator-framework-olm/pull/1338)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/56b3931de4636f7e0d212001f2074b9dddb45a8f...ebb46755980dd2c08d186e79cd7e98029a5adc2a)
### [operator-marketplace](https://github.com/operator-framework/operator-marketplace/tree/089b758a29524877a831d3b91a0655bfa5b72424)
* NO-ISSUE: Bump github.com/prometheus/client_golang from 1.24.0 to 1.24.1 [#772](https://github.com/operator-framework/operator-marketplace/pull/772)
* NO-ISSUE: Bump github.com/operator-framework/operator-lifecycle-manager from 0.45.0 to 0.46.0 [#771](https://github.com/operator-framework/operator-marketplace/pull/771)
* [Full changelog](https://github.com/operator-framework/operator-marketplace/compare/1b7ac84cc2c8bdef32807efa5650752a46bca96c...089b758a29524877a831d3b91a0655bfa5b72424)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/7ef6640e2f19f9fa01aa4e24b3c831a08004ea28)
* NO-JIRA: openshift: fix lint issues [#3301](https://github.com/openshift/ovn-kubernetes/pull/3301)
* [CORENET-7229](https://issues.redhat.com/browse/CORENET-7229): OTE: Add test list validation tooling [#3221](https://github.com/openshift/ovn-kubernetes/pull/3221)
* [OCPBUGS-83863](https://issues.redhat.com/browse/OCPBUGS-83863): Remove RHEL 8 binary build [#3149](https://github.com/openshift/ovn-kubernetes/pull/3149)
* [OCPBUGS-87283](https://issues.redhat.com/browse/OCPBUGS-87283), [OCPBUGS-87530](https://issues.redhat.com/browse/OCPBUGS-87530), [OCPBUGS-87532](https://issues.redhat.com/browse/OCPBUGS-87532), [OCPBUGS-93623](https://issues.redhat.com/browse/OCPBUGS-93623), [OCPBUGS-95512](https://issues.redhat.com/browse/OCPBUGS-95512), [OCPBUGS-98138](https://issues.redhat.com/browse/OCPBUGS-98138): DownStream Merge [07-31-2026] [#3332](https://github.com/openshift/ovn-kubernetes/pull/3332)
* [OCPBUGS-65865](https://issues.redhat.com/browse/OCPBUGS-65865), [OCPBUGS-86223](https://issues.redhat.com/browse/OCPBUGS-86223), [OCPBUGS-89327](https://issues.redhat.com/browse/OCPBUGS-89327): DownStream Merge [07-17-2026] [#3298](https://github.com/openshift/ovn-kubernetes/pull/3298)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/88e9f0f146784e8525f6304a1f6f7c986eba2319...7ef6640e2f19f9fa01aa4e24b3c831a08004ea28)
### [prometheus](https://github.com/openshift/prometheus/tree/01d8335673aa6f88f5742ef510e133efee88a7bf)
* NO-JIRA: [bot] Bump openshift/prometheus to v3.13.2 [#351](https://github.com/openshift/prometheus/pull/351)
* [OCPBUGS-100192](https://issues.redhat.com/browse/OCPBUGS-100192): [bot] Bump openshift/prometheus to v3.13.2 [#350](https://github.com/openshift/prometheus/pull/350)
* [Full changelog](https://github.com/openshift/prometheus/compare/52ee2d3abf00f3c31611cd9fff36e97cdfd28dcc...01d8335673aa6f88f5742ef510e133efee88a7bf)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce)
* [OCPBUGS-104610](https://issues.redhat.com/browse/OCPBUGS-104610): bump dependencies from the golang-org-x group [#156](https://github.com/openshift/prometheus-alertmanager/pull/156)
* [OCPBUGS-98190](https://issues.redhat.com/browse/OCPBUGS-98190): bump github.com/hashicorp/memberlist from 0.5.4 to 0.6.0 [#155](https://github.com/openshift/prometheus-alertmanager/pull/155)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/5434dc397b4590f2906a9cd774d711113fc9f25b...89bdff8b5b885e4a3d0f7d0327fe39221f3d2dce)
### [prometheus-config-reloader, prometheus-operator, prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator/tree/49894fa3421065dfd2378f664240d07f5bd208cd)
* NO-ISSUE: [bot] Bump openshift/prometheus-operator to v0.93.0 [#388](https://github.com/openshift/prometheus-operator/pull/388)
* [OCPBUGS-96853](https://issues.redhat.com/browse/OCPBUGS-96853): [bot] Bump openshift/prometheus-operator to v0.92.1 [#385](https://github.com/openshift/prometheus-operator/pull/385)
* [Full changelog](https://github.com/openshift/prometheus-operator/compare/6a36acbd5ecd5a308bc81267f3b0567f93377247...49894fa3421065dfd2378f664240d07f5bd208cd)
### [prometheus-node-exporter](https://github.com/openshift/node_exporter/tree/4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07)
* [OCPBUGS-100376](https://issues.redhat.com/browse/OCPBUGS-100376): fibre_channel: fix crash when attempting to dereference invalid count… [#183](https://github.com/openshift/node_exporter/pull/183)
* [Full changelog](https://github.com/openshift/node_exporter/compare/6241c74e49baed25b1479c1786a6fc69b57b5a5b...4f34a00889b48dd7d28ee8cb7ef6b4c229dcaa07)
### [rhel-coreos, rhel-coreos-10, rhel-coreos-10-extensions, rhel-coreos-extensions](https://github.com/openshift/os/tree/bf90b219ae4ba42e07bf8c010b725401b5402cc8)
* Revert "Revert "OCPBUGS-104572: NetworkManager-ovs has moved up to RHCOS"" [#1955](https://github.com/openshift/os/pull/1955)
* Revert "OCPBUGS-104572: NetworkManager-ovs has moved up to RHCOS" [#1954](https://github.com/openshift/os/pull/1954)
* [OCPBUGS-104572](https://issues.redhat.com/browse/OCPBUGS-104572): NetworkManager-ovs has moved up to RHCOS [#1952](https://github.com/openshift/os/pull/1952)
* [Full changelog](https://github.com/openshift/os/compare/5ffc1da076e834332482544182c22d984dbf76d2...bf90b219ae4ba42e07bf8c010b725401b5402cc8)
### [service-ca-operator](https://github.com/openshift/service-ca-operator/tree/ed872ba14b615ca5726ae90e987268877a0b0b20)
* [CNTRLPLANE-3898](https://issues.redhat.com/browse/CNTRLPLANE-3898): Bump kubernetes dependencies to v1.36.2 [#366](https://github.com/openshift/service-ca-operator/pull/366)
* [MON-4515](https://issues.redhat.com/browse/MON-4515): Migrate Prometheus targets discovering from Endpoints to EndpointSlices [#319](https://github.com/openshift/service-ca-operator/pull/319)
* [Full changelog](https://github.com/openshift/service-ca-operator/compare/e260be2b3710137012814ce9ca48f155f24f0b02...ed872ba14b615ca5726ae90e987268877a0b0b20)
### [tests](https://github.com/openshift/origin/tree/a302321dc817cc65ea1806e167da941ba17d8908)
* [OCPBUGS-84491](https://issues.redhat.com/browse/OCPBUGS-84491): Remove openshift-ingress terminationMessagePolicy exemption [#31435](https://github.com/openshift/origin/pull/31435)
* [OCPBUGS-99492](https://issues.redhat.com/browse/OCPBUGS-99492): remove storage NetworkPolicies from validation skip list [#31429](https://github.com/openshift/origin/pull/31429)
* NO-ISSUE: Skip Additional Storage tests on HyperShift - MachineConfig API not available [#31489](https://github.com/openshift/origin/pull/31489)
* [NE-2788](https://issues.redhat.com/browse/NE-2788): exempt ingress Upgradeable=False for deprecated HAProxy versions [#31494](https://github.com/openshift/origin/pull/31494)
* NO-JIRA: Remove Istio configmap workaround from ClusterResourceQuota test [#31444](https://github.com/openshift/origin/pull/31444)
* [OCPEDGE-2787](https://issues.redhat.com/browse/OCPEDGE-2787): fix: skip MCPs with non-ready nodes during MCN property validation [#31380](https://github.com/openshift/origin/pull/31380)
* [OCPEDGE-2785](https://issues.redhat.com/browse/OCPEDGE-2785): fix: adjusting DaemonSet test to dynamically compute expected pod count [#31378](https://github.com/openshift/origin/pull/31378)
* [OCPCLOUD-3074](https://issues.redhat.com/browse/OCPCLOUD-3074): Validate Azure dual-stack load balancers [#31452](https://github.com/openshift/origin/pull/31452)
* [CNTRLPLANE-2157](https://issues.redhat.com/browse/CNTRLPLANE-2157): Migrate tests of Prometheus, Audit and TLS to OTE [#31360](https://github.com/openshift/origin/pull/31360)
* [TRT-2618](https://issues.redhat.com/browse/TRT-2618): Add env var support to selectively enable resource monitor tests and event collection [#31420](https://github.com/openshift/origin/pull/31420)
* Bug OCPBUGS-104497: Fix [sig-ci] prow job name OS version test for 4.23 rhcos9 [#31481](https://github.com/openshift/origin/pull/31481)
* [OCPBUGS-100392](https://issues.redhat.com/browse/OCPBUGS-100392): Exclude openshift-debug-* namespaces from CPU Partitioning annotation check [#31465](https://github.com/openshift/origin/pull/31465)
* NO-ISSUE: Automated - Update synthetic test data [#31459](https://github.com/openshift/origin/pull/31459)
* Revert "TRT-2869: Revert "NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO"" [#31462](https://github.com/openshift/origin/pull/31462)
* [OCPBUGS-101912](https://issues.redhat.com/browse/OCPBUGS-101912): derive cluster quota from namespace configmaps [#31476](https://github.com/openshift/origin/pull/31476)
* [STOR-3065](https://issues.redhat.com/browse/STOR-3065): Add storage CSI tests for cloning PVC to a larger volume [#31443](https://github.com/openshift/origin/pull/31443)
* [OCPBUGS-100386](https://issues.redhat.com/browse/OCPBUGS-100386): test: scope hosted etcd leader metrics by namespace [#31456](https://github.com/openshift/origin/pull/31456)
* [OCPBUGS-63219](https://issues.redhat.com/browse/OCPBUGS-63219): Remove NLB hairpin workaround from dual-stack test [#31453](https://github.com/openshift/origin/pull/31453)
* [OCPBUGS-99899](https://issues.redhat.com/browse/OCPBUGS-99899): add os name exception for runc jobs [#31479](https://github.com/openshift/origin/pull/31479)
* [CORENET-6714](https://issues.redhat.com/browse/CORENET-6714): Adding netobserv namespace exception for prometheus endpoint auth [#31447](https://github.com/openshift/origin/pull/31447)
* [OCPBUGS-100388](https://issues.redhat.com/browse/OCPBUGS-100388): Fix project name collision in test framework [#31464](https://github.com/openshift/origin/pull/31464)
* [OCPBUGS-100385](https://issues.redhat.com/browse/OCPBUGS-100385): MonitorTest: measure the union of ClusterOperator wait intervals [#31457](https://github.com/openshift/origin/pull/31457)
* [OCPBUGS-99397](https://issues.redhat.com/browse/OCPBUGS-99397): remove custom MCP and pause master pool in mirror-set tests to prevent PDB drain deadlock and suite timeout [#31408](https://github.com/openshift/origin/pull/31408)
* Revert: Fix APIs for openshift.io must have stable versions check [#31468](https://github.com/openshift/origin/pull/31468)
* [OCPBUGS-99916](https://issues.redhat.com/browse/OCPBUGS-99916): exclude openshift-debug-* namespaces from best-effort QoS invariant [#31437](https://github.com/openshift/origin/pull/31437)
* [TRT-2869](https://issues.redhat.com/browse/TRT-2869): Revert #31440 "NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO" [#31460](https://github.com/openshift/origin/pull/31460)
* [OCPBUGS-100308](https://issues.redhat.com/browse/OCPBUGS-100308): Fix test `APIs for openshift.io must have stable versions` [#31458](https://github.com/openshift/origin/pull/31458)
* [OCPBUGS-99047](https://issues.redhat.com/browse/OCPBUGS-99047): Fix flaky oc adm storage-admin test [#31400](https://github.com/openshift/origin/pull/31400)
* [OCPBUGS-84695](https://issues.redhat.com/browse/OCPBUGS-84695): [TNF] Fix update-setup job discovery to limit check to active job [#31451](https://github.com/openshift/origin/pull/31451)
* [OCPBUGS-99921](https://issues.redhat.com/browse/OCPBUGS-99921): Dump istiod logs and gateway state on GatewayAPI test failure [#31454](https://github.com/openshift/origin/pull/31454)
* NO-JIRA: Re-enable tests for the recommend cmd if alertsByCVO [#31440](https://github.com/openshift/origin/pull/31440)
* [OCPBUGS-100183](https://issues.redhat.com/browse/OCPBUGS-100183): Always tear down upgrade tests after setup failures [#31450](https://github.com/openshift/origin/pull/31450)
* [OCPBUGS-98576](https://issues.redhat.com/browse/OCPBUGS-98576): Improve test output for nodes should be ready test [#31419](https://github.com/openshift/origin/pull/31419)
* [OCPBUGS-78480](https://issues.redhat.com/browse/OCPBUGS-78480): handle bookmark events in project watch tests [#31313](https://github.com/openshift/origin/pull/31313)
* NO-JIRA: Update minio image to use source with all supported architectures [#31441](https://github.com/openshift/origin/pull/31441)
* [OCPBUGS-85529](https://issues.redhat.com/browse/OCPBUGS-85529): Fix IPv6 prefix in MultiNetworkPolicy test (/32 → /64) [#31407](https://github.com/openshift/origin/pull/31407)
* [OCPBUGS-99535](https://issues.redhat.com/browse/OCPBUGS-99535): Skip Squid proxy configuration [#31423](https://github.com/openshift/origin/pull/31423)
* NO-ISSUE: Skip additional storage support E2E test for on single-node - MCP rollouts timeout [#31439](https://github.com/openshift/origin/pull/31439)
* [CNTRLPLANE-3789](https://issues.redhat.com/browse/CNTRLPLANE-3789): images: Add squid image used in CAO e2e tests [#31434](https://github.com/openshift/origin/pull/31434)
* [OTA-1814](https://issues.redhat.com/browse/OTA-1814): Skip tests temporarily for the new output of the recommend cmd [#31417](https://github.com/openshift/origin/pull/31417)
* [STOR-3063](https://issues.redhat.com/browse/STOR-3063): Add GCP regional PD e2e test for cross-zone data sync [#31416](https://github.com/openshift/origin/pull/31416)
* [CNTRLPLANE-3741](https://issues.redhat.com/browse/CNTRLPLANE-3741): PKI config tests for service-ca and kube-apiserver-operator [#31341](https://github.com/openshift/origin/pull/31341)
* NO-JIRA: Replace a bug id: 25739 -> 92835 [#31345](https://github.com/openshift/origin/pull/31345)
* [OCPNODE-4055](https://issues.redhat.com/browse/OCPNODE-4055): Add e2e testcase for additional storage support feature [#31399](https://github.com/openshift/origin/pull/31399)
* NO-ISSUE: Automated - Update synthetic test data [#31260](https://github.com/openshift/origin/pull/31260)
* [OCPNODE-4494](https://issues.redhat.com/browse/OCPNODE-4494): e2e test case for RHCOS upgrade from 9 → 10 [#31393](https://github.com/openshift/origin/pull/31393)
* [OCPSTRAT-3036](https://issues.redhat.com/browse/OCPSTRAT-3036): Rebase 1.36.2 [#31237](https://github.com/openshift/origin/pull/31237)
* [Full changelog](https://github.com/openshift/origin/compare/a7b3bba9780389699e8426c6d3f1afee8464a5ad...a302321dc817cc65ea1806e167da941ba17d8908)
### [thanos](https://github.com/openshift/thanos/tree/75fa632b483716e53aec19f6adf7d4c4652a4453)
* [OCPBUGS-104611](https://issues.redhat.com/browse/OCPBUGS-104611): vendor: bump vulnerable Go dependencies for CVE remediation [#198](https://github.com/openshift/thanos/pull/198)
* NO-JIRA: [bot] Bump openshift/thanos to v0.42.4 [#196](https://github.com/openshift/thanos/pull/196)
* NO-ISSUE: [bot] Bump openshift/thanos to v0.42.3 [#195](https://github.com/openshift/thanos/pull/195)
* [Full changelog](https://github.com/openshift/thanos/compare/7923992496585d7471b26abbd15bfa7aaa745755...75fa632b483716e53aec19f6adf7d4c4652a4453)
### [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator/tree/ee9cd7aba4e096a9a957386ef20777e8950df352)
* [STOR-2917](https://issues.redhat.com/browse/STOR-2917): Rebase to v1.7.0 for OCP 5.0 [#16](https://github.com/openshift/volume-data-source-validator/pull/16)
* [Full changelog](https://github.com/openshift/volume-data-source-validator/compare/a6c21eee63d1fae58b63d8493aeb0fd662d1c91e...ee9cd7aba4e096a9a957386ef20777e8950df352)