# 4.22.0-okd-scos.10
Created: 2026-09-09 08:47:05 +0000 UTC
Image Digest: `sha256:65f272bc84b5e235aa7f3026f08d69f00adebc3fd1228ea7f29e99c5580165af`
Promoted from registry.ci.openshift.org/origin/release-scos:4.22.0-0.okd-scos-nightly-2026-09-09-010118
## Changes from 4.22.0-okd-scos.ec.16
### Components
* Kubectl 1.35.2
* Kubernetes upgraded from 1.35.4 to 1.35.6
* Kubernetes Tests 1.35.1
* CentOS Stream CoreOS 10 upgraded from 10.0.20260428-0 to 10.0.20260806-0
### FeatureGate Changes
| FeatureGate | Default
Hypershift | Default
SelfManagedHA | DevPreviewNoUpgrade
Hypershift | DevPreviewNoUpgrade
SelfManagedHA | OKD
Hypershift | OKD
SelfManagedHA | TechPreviewNoUpgrade
Hypershift | TechPreviewNoUpgrade
SelfManagedHA |
| :------ | :---: | :---: | :---: | :---: | :---: | :---: | :---: | :---: |
| EVPN
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| VSphereMixedNodeEnv
(0 tests)| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled| Enabled
(Changed)| Enabled
(Changed)| Enabled| Enabled |
| NoRegistryClusterInstall
(0 tests)| Disabled| Enabled
(Changed)| Disabled| Enabled| Disabled| Enabled
(Changed)| Disabled| Enabled |
| GCPSovereignCloudInstall
(0 tests)| | | Enabled
(New)| Enabled
(New)| | | Enabled
(New)| Enabled
(New) |
### New images
* [installer-etcd-artifacts](https://github.com/openshift/etcd) git [6bd01267](https://github.com/openshift/etcd/commit/6bd01267dc858aca6ff21632f95e98dc62ba33e7) `sha256:63fd1fdc7731fe7928035d30258a802577923b28dec40aab643e2a3f49df231e`
* [installer-kube-apiserver-artifacts](https://github.com/openshift/kubernetes) git [19365a06](https://github.com/openshift/kubernetes/commit/19365a06f558a5c5dc7f5654fa99a8318e4a77f4) `sha256:359d64776e96a3768d2204e6cf8b538cc47a0bf4cacc13b450e5a412125ebddf`
### Rebuilt images without code change
* [apiserver-network-proxy](https://github.com/openshift/apiserver-network-proxy) git [5e33c228](https://github.com/openshift/apiserver-network-proxy/commit/5e33c22867d59ddd9392a2c6b3194d2f3c6bdfc7) `sha256:1bd87da8832223f7e20c18199141bfc96efd0617bb0079559b185f2086694780`
* [aws-kms-encryption-provider](https://github.com/openshift/aws-encryption-provider) git [19e7b623](https://github.com/openshift/aws-encryption-provider/commit/19e7b623429799c9c549690a1b5ab499844411f9) `sha256:64df7ceb79216e49512daebf9cf5afb8d4964efc8951f522d741ea76a3ea9451`
* [aws-machine-controllers](https://github.com/openshift/machine-api-provider-aws) git [1a0ccbcf](https://github.com/openshift/machine-api-provider-aws/commit/1a0ccbcfc0a7dc06f3a494f0e2b78aa0a0256b9c) `sha256:7439b972c227209447b8ae200054f4ea35c22c71aa56857a352f32fc84ad2e5b`
* [aws-node-termination-handler](https://github.com/openshift/aws-node-termination-handler) git [341ed3a0](https://github.com/openshift/aws-node-termination-handler/commit/341ed3a086925b17671c5349343fedf988a1139e) `sha256:8645eb4a468a2c93d508419f6a8f96a193c7f5ce4158ebcf7b526c34e806354b`
* [aws-pod-identity-webhook](https://github.com/openshift/aws-pod-identity-webhook) git [82088287](https://github.com/openshift/aws-pod-identity-webhook/commit/8208828799b6c4f91fd9b80128668f7765599e84) `sha256:3cdaa627200529bd2d504dca397c4e8a64b1a87ad607b8bd68a550dbf753ae93`
* [azure-service-operator](https://github.com/openshift/azure-service-operator) git [b44d4444](https://github.com/openshift/azure-service-operator/commit/b44d444422f5a7eb21b9ca65f3975a2d13ec9b36) `sha256:f459247b7577169cf5621f108ff5130174a4064a799f1818d3342f1a785c7bf9`
* [azure-workload-identity-webhook](https://github.com/openshift/azure-workload-identity) git [a8fb3bf1](https://github.com/openshift/azure-workload-identity/commit/a8fb3bf1a6296d6cbf69142db458aa9b59cb3a45) `sha256:e4c72469b4cea65eeed8a4c51c29ca7bd6e15f4e61273cac4427303aa04ed092`
* [baremetal-machine-controllers](https://github.com/openshift/cluster-api-provider-baremetal) git [8d863b95](https://github.com/openshift/cluster-api-provider-baremetal/commit/8d863b9505a5cfc0b01e33f985a3edf9d3c69f4b) `sha256:de2533054e22a4a0678f9ccbe19240d52e3c52046bc48f4cdb0a4c208fb5ae8f`
* [cluster-bootstrap](https://github.com/openshift/cluster-bootstrap) git [e6be0fdf](https://github.com/openshift/cluster-bootstrap/commit/e6be0fdfbf43883e2301dbf2d0eb3ab4a4f93383) `sha256:460b6b136e41fbd2306786cf995fb105a3f869029dff54e898216adc7aafb896`
* [cluster-capi-controllers](https://github.com/openshift/cluster-api) git [f1718df9](https://github.com/openshift/cluster-api/commit/f1718df9c13b0cee5ede1b6354e29acc466607a4) `sha256:0d0a68b1f91121ebbc328f2495ac0850e1280ee7f84e1ba39626c0a9d44dcb67`
* [cluster-config-operator](https://github.com/openshift/cluster-config-operator) git [e0c2428e](https://github.com/openshift/cluster-config-operator/commit/e0c2428e4618493ad9db0681e3b91444746ddf2c) `sha256:735f953d1e5de813da0bf511435e686a6a1d79d595fa50b744e86a2108bbc916`
* [cluster-dns-operator](https://github.com/openshift/cluster-dns-operator) git [3d214118](https://github.com/openshift/cluster-dns-operator/commit/3d2141182243cde1ec6417bd005c76d29aa88a01) `sha256:236807ea16d9f5c8bdee6839b613149e77cf939be90c409eca41ea45fa09ee9e`
* [cluster-update-keys](https://github.com/openshift/cluster-update-keys) git [3b5c59cc](https://github.com/openshift/cluster-update-keys/commit/3b5c59cc6461663751bc510b4f9f1954ed8c9b50) `sha256:779704ec7ee18798d72a5852dbc4f9a009a962ac9e73cef4b5ceaaf7a94f74d7`
* [configmap-reloader](https://github.com/openshift/configmap-reload) git [94e41c4c](https://github.com/openshift/configmap-reload/commit/94e41c4c6a5832dfd19750173d6544784ba235ec) `sha256:6d3f046783688fbbb01047201e1b37dc5c0d5864efef244030dae4682ce29de4`
* [csi-livenessprobe](https://github.com/openshift/csi-livenessprobe) git [4d5e959a](https://github.com/openshift/csi-livenessprobe/commit/4d5e959a182b4db70dc52302bd89eebfec40d5a5) `sha256:b6b7960839457517089d1fd14ce657f543d18b6a918c2e9012cf69e6ccd1edc3`
* [driver-toolkit](https://github.com/openshift/driver-toolkit) git [7aa4007a](https://github.com/openshift/driver-toolkit/commit/7aa4007a8601bf4bb23b696f580c022f58877223) `sha256:10c2f165ad619577e924bf49f579fea9c7ba227b3552c1ad1cba9a826f9ec9a9`
* [gcp-machine-controllers](https://github.com/openshift/machine-api-provider-gcp) git [0073bd11](https://github.com/openshift/machine-api-provider-gcp/commit/0073bd1187c07febc963fc67f0df67cd33c8f218) `sha256:813fcae0b6eec4a8ffe2f257b39fca4a10e9e15aace52e4b2f73b3247431c164`
* [gcp-workload-identity-federation-webhook](https://github.com/openshift/gcp-workload-identity-federation-webhook) git [d7675f31](https://github.com/openshift/gcp-workload-identity-federation-webhook/commit/d7675f312ffdc8501032ff8217776cd7172b6bb0) `sha256:105a0918e88703a26bcf0afa761f4d24343e88a777366b62e4d920302c69c3ee`
* [insights-runtime-exporter](https://github.com/openshift/insights-runtime-extractor) git [70256457](https://github.com/openshift/insights-runtime-extractor/commit/70256457b507ec09737800ee7ea022143ed6c3c2) `sha256:534ddbbd71d0125a57953548770768374d64017351ff9f5586390cce2362f675`
* [insights-runtime-extractor](https://github.com/openshift/insights-runtime-extractor) git [70256457](https://github.com/openshift/insights-runtime-extractor/commit/70256457b507ec09737800ee7ea022143ed6c3c2) `sha256:e8b9091b79e9b0017b347eb9683ab70b175cd3f9a395f41f8b77024aa323833a`
* [ironic-machine-os-downloader](https://github.com/openshift/ironic-rhcos-downloader) git [9953d2b7](https://github.com/openshift/ironic-rhcos-downloader/commit/9953d2b77da077c28f9486a5d965a43149ce30c1) `sha256:ad2ffe532ec1fed89697195173a64a237df61e2b399b98d3fb60178278ac3e24`
* [ironic-static-ip-manager](https://github.com/openshift/ironic-static-ip-manager) git [a379d09f](https://github.com/openshift/ironic-static-ip-manager/commit/a379d09f228d93f2beab1c73d67764c64b21e3cb) `sha256:3b5eeab00b02b8285934f6e377a36fd363901fcb7512c57a7a8ba332ac13c976`
* [kube-metrics-server](https://github.com/openshift/kubernetes-metrics-server) git [38c16c46](https://github.com/openshift/kubernetes-metrics-server/commit/38c16c4698d131ab0e2da0d4b4b76d5322a89bab) `sha256:d83826a058c1d274d03f64601d711548bd53370d326800cd5e32b92b433b6039`
* [kube-rbac-proxy](https://github.com/openshift/kube-rbac-proxy) git [d12e2746](https://github.com/openshift/kube-rbac-proxy/commit/d12e274605248f6c59373240a7eae7a7a357dcb3) `sha256:ffd8b92344801439c544006ef87cec00fc4cf67f2ab6ec6196616c436a8ab97d`
* [kube-storage-version-migrator](https://github.com/openshift/kubernetes-kube-storage-version-migrator) git [72835e43](https://github.com/openshift/kubernetes-kube-storage-version-migrator/commit/72835e43c7754356645e41031f3a99926b4d42e6) `sha256:8b7f124e41ca19371c5a5615e10f4e29540d5f7c7d3dc55655c63a7ca980df9d`
* [machine-image-customization-controller](https://github.com/openshift/image-customization-controller) git [a43d9c97](https://github.com/openshift/image-customization-controller/commit/a43d9c977f6332577efcd383cf173a2ff5805a4d) `sha256:0412dc6494bc71b80fc1feabc5f86dc24178eb68ed7da3c6b98f04f22662c51b`
* [multus-networkpolicy](https://github.com/openshift/multus-networkpolicy) git [834a093f](https://github.com/openshift/multus-networkpolicy/commit/834a093f693e521b8dc4ec7168d03cfba2c1cba1) `sha256:93174b9c6f3a51d97529956d7c4da845c5f1be028340ac4c65d2829762180ffa`
* [multus-route-override-cni](https://github.com/openshift/route-override-cni) git [08af4127](https://github.com/openshift/route-override-cni/commit/08af4127c77976510cad1c096d9aca977d8ae5af) `sha256:7c9a43560ca6ac4db5be16a2346a433b746b054d2c2a790ad5a5d7fde93ff7ee`
* [multus-whereabouts-ipam-cni](https://github.com/openshift/whereabouts-cni) git [d691040e](https://github.com/openshift/whereabouts-cni/commit/d691040e509bb20c26b5e8366c0d6f3bb45a5e02) `sha256:b544e0e88cb4fb7fd158b36ad4096cb4f4ffd2e589db50898bed7c25122c943b`
* [must-gather](https://github.com/openshift/must-gather) git [8554213f](https://github.com/openshift/must-gather/commit/8554213fa214e8e165e7bedaf8d892bb824d83ef) `sha256:3312f4a63d28d4f2d61aef9cbab10aa6f64d963f50b22d03e3766012ad927ad7`
* [network-metrics-daemon](https://github.com/openshift/network-metrics-daemon) git [5b233ea1](https://github.com/openshift/network-metrics-daemon/commit/5b233ea1d80733c1b00c6bad65dec0620dbf783a) `sha256:65453a1a26a442a94f926071384d3b7a5b4fb23d4ed3473414f21aa3683029f7`
* [network-tools](https://github.com/openshift/network-tools) git [5c4b905c](https://github.com/openshift/network-tools/commit/5c4b905c09ccd6edadb2ff359f45b70ed334f948) `sha256:091461fb89af925398084fef8069ff4c286ea099601633c475d12f11ee328c0a`
* [nutanix-cloud-controller-manager](https://github.com/openshift/cloud-provider-nutanix) git [8e75679a](https://github.com/openshift/cloud-provider-nutanix/commit/8e75679a965b80fee0332f8758471a7d3a75a4e8) `sha256:ae6b6eaae143ec8aa5f31fbc81e413860629e8cb0f5a9475c94bb3b1127e20d2`
* [nutanix-machine-controllers](https://github.com/openshift/machine-api-provider-nutanix) git [60559fdd](https://github.com/openshift/machine-api-provider-nutanix/commit/60559fdd7092dd29aa1c72797c49279aa2da39ee) `sha256:3623035649b5d6c802edb24c7daccea13ec341c5284ab42cce82003e561e6bd8`
* [oauth-apiserver](https://github.com/openshift/oauth-apiserver) git [4c002a91](https://github.com/openshift/oauth-apiserver/commit/4c002a9114937ea9c20213f00892761c2013e60b) `sha256:a6dde1f5365de687698ca66b23d0574603c40911bccba154894f5b9a19804ae0`
* [openshift-controller-manager](https://github.com/openshift/openshift-controller-manager) git [26d20fea](https://github.com/openshift/openshift-controller-manager/commit/26d20feae8892f648f5b06ed3f5492fe6ffb4532) `sha256:c03e6cddd121a23bfa2037c1506dfbb04c08ebd135e43ce56f51bee954d3909d`
* [openshift-state-metrics](https://github.com/openshift/openshift-state-metrics) git [e71e0996](https://github.com/openshift/openshift-state-metrics/commit/e71e09969f11a47c87b87c43b762ad1d01f6b04f) `sha256:365ca355fd188528fc0fc8ed16d497dd2777b28f0e00ec713057d60d12885f37`
* [openstack-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-openstack) git [06d95461](https://github.com/openshift/cluster-api-provider-openstack/commit/06d95461581f9374ae05959b66fc50e2a17d077c) `sha256:513495fa4738957abe9c31b7126d6d59128fc16dd0cff863b2ebb0debafbcbbf`
* [openstack-resource-controller](https://github.com/openshift/openstack-resource-controller) git [cbea7a9c](https://github.com/openshift/openstack-resource-controller/commit/cbea7a9cab145c32e2f347be69996b649893cc22) `sha256:867cfa44302914ecd39fe354b2f2985afa89eefd17e83a19cc6388fd867e608e`
* [operator-marketplace](https://github.com/operator-framework/operator-marketplace) git [38da2ef7](https://github.com/operator-framework/operator-marketplace/commit/38da2ef78cc429f67aea7fb4e589df21ac1ed327) `sha256:b462bff2de2924cb0e58a3d69580588e4d8746f545dfe92e1bd91c682894535e`
* [powervs-cloud-controller-manager](https://github.com/openshift/cloud-provider-powervs) git [766c0952](https://github.com/openshift/cloud-provider-powervs/commit/766c0952fd19f8225fe59b2be8e8c8932b24ebd7) `sha256:c83b8db37574888b49fa2b1e504f7413ab011174bf7041850791060b226062d1`
* [powervs-machine-controllers](https://github.com/openshift/machine-api-provider-powervs) git [e88cf81d](https://github.com/openshift/machine-api-provider-powervs/commit/e88cf81dd9ad174f395b86f9cdc40fa30cb06bf4) `sha256:aa66fc27f7ae17138a717eb6a757dbfd4f297e850222339594f377140e61e9a9`
* [prom-label-proxy](https://github.com/openshift/prom-label-proxy) git [c4c99a30](https://github.com/openshift/prom-label-proxy/commit/c4c99a3071808f466ee6c3d7b7fa87108b457feb) `sha256:0792f108b67516b8d2927a06030b7dcd7f69b04c0469ebb6889ef817aac07345`
* [prometheus-config-reloader](https://github.com/openshift/prometheus-operator) git [70e38466](https://github.com/openshift/prometheus-operator/commit/70e38466b9b9143f48283dab8bd0c227f35efe69) `sha256:6a8be22479880397b0b4e6b41f7680c86c4c26bfc148969780a32651272f279e`
* [prometheus-node-exporter](https://github.com/openshift/node_exporter) git [6c4fc012](https://github.com/openshift/node_exporter/commit/6c4fc0126407c8404b8604faa2f1230f385b9f44) `sha256:9b8478c5d89a11a52dd7b59096588c6569b989b0d20068302f98c713b7f0c91f`
* [prometheus-operator](https://github.com/openshift/prometheus-operator) git [70e38466](https://github.com/openshift/prometheus-operator/commit/70e38466b9b9143f48283dab8bd0c227f35efe69) `sha256:1edb2118c4415255c0db15886374c3ab321d3f737f9962f4f4499bca4fa08188`
* [prometheus-operator-admission-webhook](https://github.com/openshift/prometheus-operator) git [70e38466](https://github.com/openshift/prometheus-operator/commit/70e38466b9b9143f48283dab8bd0c227f35efe69) `sha256:9fa7f88afc05ad48b1ccff49999222e5bf8d6baae284f94506182e609781eea0`
* [service-ca-operator](https://github.com/openshift/service-ca-operator) git [9fff46a5](https://github.com/openshift/service-ca-operator/commit/9fff46a576033685f66fbb1121eb0a2f134a29be) `sha256:a608c4db25a4ea967bd4115792c74cb28eec7a6ee741bbac9f455e731113ea56`
* [volume-data-source-validator](https://github.com/openshift/volume-data-source-validator) git [8e176cec](https://github.com/openshift/volume-data-source-validator/commit/8e176cec394709cac728423cbbb6c3c914be8485) `sha256:6d52894df789f8b9c190b7e307ccd1f3e4f021b783c70475336d4f7f225d745d`
* [vsphere-cloud-controller-manager](https://github.com/openshift/cloud-provider-vsphere) git [39008107](https://github.com/openshift/cloud-provider-vsphere/commit/39008107b1463e3299b0d60c3ac1f7e71ad3e014) `sha256:ffb8440d2b6e4bf60a586c344d3421b6ac786c9884204c6b23528edd232a9830`
### [agent-installer-api-server](https://github.com/openshift/assisted-service/tree/d31ed58ac20a5c181f21a42e5adf900bbd69f52a)
* [OCPBUGS-121355](https://issues.redhat.com/browse/OCPBUGS-121355): Fix NUMAResourcesOperator CR name so it can be applied [#10934](https://github.com/openshift/assisted-service/pull/10934)
* [OCPBUGS-120755](https://issues.redhat.com/browse/OCPBUGS-120755): added missing subscription name for lvms-operator [#10918](https://github.com/openshift/assisted-service/pull/10918)
* [OCPBUGS-105805](https://issues.redhat.com/browse/OCPBUGS-105805): golang.org/x/crypto bump to v0.52.0 [#10796](https://github.com/openshift/assisted-service/pull/10796)
* [OCPBUGS-104521](https://issues.redhat.com/browse/OCPBUGS-104521): manifest_generator add a label to LUKS root [#10755](https://github.com/openshift/assisted-service/pull/10755)
* [AGENT-1559](https://issues.redhat.com/browse/AGENT-1559): Remove LSO and LVMS as CNV operator dependencies [#10666](https://github.com/openshift/assisted-service/pull/10666)
* [OCPBUGS-98693](https://issues.redhat.com/browse/OCPBUGS-98693): PATCH /v2/clusters/{id} does not return updated operator_bundles [#10608](https://github.com/openshift/assisted-service/pull/10608)
* [OCPBUGS-93786](https://issues.redhat.com/browse/OCPBUGS-93786): Simplify IRI api dependency [#10539](https://github.com/openshift/assisted-service/pull/10539)
* [OCPBUGS-92056](https://issues.redhat.com/browse/OCPBUGS-92056): Stop setting DevPreviewNoUpgrade for TNF clusters [#10516](https://github.com/openshift/assisted-service/pull/10516)
* [OCPBUGS-90638](https://issues.redhat.com/browse/OCPBUGS-90638): Add sourcedir /run/chrony-dhcp to generated chrony.conf [#10488](https://github.com/openshift/assisted-service/pull/10488)
* [OCPBUGS-83542](https://issues.redhat.com/browse/OCPBUGS-83542): Mark raw FC/iSCSI multipath members as ineligible [#10150](https://github.com/openshift/assisted-service/pull/10150)
* [Full changelog](https://github.com/openshift/assisted-service/compare/148c557ea39a1edb7026e347b0fb5930c6c1c0bd...d31ed58ac20a5c181f21a42e5adf900bbd69f52a)
### [agent-installer-csr-approver, agent-installer-orchestrator](https://github.com/openshift/assisted-installer/tree/d5515fa077062f9bfcb763d8131b0302bba6a144)
* [OCPBUGS-96592](https://issues.redhat.com/browse/OCPBUGS-96592): Bump golang.org/x/net to v0.55.0 [#2250](https://github.com/openshift/assisted-installer/pull/2250)
* [OCPBUGS-104498](https://issues.redhat.com/browse/OCPBUGS-104498): Wait for all nodes to join before exiting for ABI [#2245](https://github.com/openshift/assisted-installer/pull/2245)
* [OCPBUGS-69953](https://issues.redhat.com/browse/OCPBUGS-69953): Updating ose-agent-installer-csr-approver-container image to be consistent with ART for 4.22 [#1406](https://github.com/openshift/assisted-installer/pull/1406)
* [Full changelog](https://github.com/openshift/assisted-installer/compare/a9bfcccdade3dec5e6d71dbbc6e03fe137a1660b...d5515fa077062f9bfcb763d8131b0302bba6a144)
### [agent-installer-node-agent](https://github.com/openshift/assisted-installer-agent/tree/2dd2e384dfc739a26763b4e18e7d63ca0de192e2)
* [OCPBUGS-101855](https://issues.redhat.com/browse/OCPBUGS-101855): Bump golang.org/x/net from v0.47.0 to v0.53.0 [#1595](https://github.com/openshift/assisted-installer-agent/pull/1595)
* [OCPBUGS-84392](https://issues.redhat.com/browse/OCPBUGS-84392): Bump go-jose in v4.22 [#1488](https://github.com/openshift/assisted-installer-agent/pull/1488)
* [Full changelog](https://github.com/openshift/assisted-installer-agent/compare/f562f3539125da83145eb1012ea8a4f4d62d0807...2dd2e384dfc739a26763b4e18e7d63ca0de192e2)
### [agent-installer-ui](https://github.com/openshift-assisted/assisted-installer-ui/tree/9380434565d3f9b0031b353a008ae97050b038a0)
* [OCPBUGS-104555](https://issues.redhat.com/browse/OCPBUGS-104555): Bump tmp to ^0.2.6 to address CVE-2026-44705 (#4014) [#4014](https://github.com/openshift-assisted/assisted-installer-ui/pull/4014)
* [CVE-2026](https://issues.redhat.com/browse/CVE-2026): 44990: bump sanitize-html to v2.17.4 (#4008) [#4008](https://github.com/openshift-assisted/assisted-installer-ui/pull/4008)
* Add LVM as an operator for OVE (#4005) [#4005](https://github.com/openshift-assisted/assisted-installer-ui/pull/4005)
* Allow LSO to be selected as a standalone operator (#4003) [#4003](https://github.com/openshift-assisted/assisted-installer-ui/pull/4003)
* NoRegistryClusterInstall has been promoted to default in the OpenShift API, (#3984) [#3984](https://github.com/openshift-assisted/assisted-installer-ui/pull/3984)
* Update OWNERS file (#3990) [#3990](https://github.com/openshift-assisted/assisted-installer-ui/pull/3990)
* [OCPBUGS-100526](https://issues.redhat.com/browse/OCPBUGS-100526), [OCPBUGS-103014](https://issues.redhat.com/browse/OCPBUGS-103014): Bump ip-address to 10.5.0 to fix CVE-2026-54272 and CVE-2026-69192 (#3987) [#3987](https://github.com/openshift-assisted/assisted-installer-ui/pull/3987)
* [OCPBUGS-109783](https://issues.redhat.com/browse/OCPBUGS-109783): Bump tar pkg to version ^7.5.21 to address CVE-2026-73566 (#3970) [#3970](https://github.com/openshift-assisted/assisted-installer-ui/pull/3970)
* [OCPBUGS-104483](https://issues.redhat.com/browse/OCPBUGS-104483): Pin minimatch to ^10.2.6 and brace-expansion to ^5.0.9 (CVE-2026-14257) (#3959) [#3959](https://github.com/openshift-assisted/assisted-installer-ui/pull/3959)
* [CVE-2026](https://issues.redhat.com/browse/CVE-2026): 9595: Bumped webpack-dev-server to 5.2.5 (#3924) [#3924](https://github.com/openshift-assisted/assisted-installer-ui/pull/3924)
* [OCPBUGS-99025](https://issues.redhat.com/browse/OCPBUGS-99025): Bump dompurify to 3.4.7+ in 4.22 (#3895) [#3895](https://github.com/openshift-assisted/assisted-installer-ui/pull/3895)
* [OCPBUGS-91629](https://issues.redhat.com/browse/OCPBUGS-91629): Bump ws to 8.21.0 for CVE-2026-45736 (#3906) [#3906](https://github.com/openshift-assisted/assisted-installer-ui/pull/3906)
* [OCPBUGS-96710](https://issues.redhat.com/browse/OCPBUGS-96710): Bump basic-ftp to 5.3.1 for CVE-2026-44240 (#3823) [#3823](https://github.com/openshift-assisted/assisted-installer-ui/pull/3823)
* [CVE-2026](https://issues.redhat.com/browse/CVE-2026): 59873 openshift4/ose-agent-installer-ui-rhel9: node-tar: Denial of Service via crafted gzip bomb [openshift-4.22] (#3890) [#3890](https://github.com/openshift-assisted/assisted-installer-ui/pull/3890)
* Update OWNERS file (#3883) [#3883](https://github.com/openshift-assisted/assisted-installer-ui/pull/3883)
* [OCPBUGS-98431](https://issues.redhat.com/browse/OCPBUGS-98431): Bump js-yaml to 4.3.0 in 4.22 (#3865) [#3865](https://github.com/openshift-assisted/assisted-installer-ui/pull/3865)
* Apply patches (#3873) [#3873](https://github.com/openshift-assisted/assisted-installer-ui/pull/3873)
* [MGMT-24444](https://issues.redhat.com/browse/MGMT-24444): Apply sentence case to networking management type labels … (#3747) (#3871) [#3747](https://github.com/openshift-assisted/assisted-installer-ui/pull/3747)
* [MGMT-24152](https://issues.redhat.com/browse/MGMT-24152): UI allows editing pull secret in draft cluster (#3662) (#3870) [#3662](https://github.com/openshift-assisted/assisted-installer-ui/pull/3662)
* [OCPBUGD-89707](https://issues.redhat.com/browse/OCPBUGD-89707): bump form-data from 4.0.5 to 4.0.6 to address CVE-2026-12143 (#3869) [#3869](https://github.com/openshift-assisted/assisted-installer-ui/pull/3869)
* patch CVE-2026-9277 and CVE-2026-42338 via yarn resolutions (#3851) [#3851](https://github.com/openshift-assisted/assisted-installer-ui/pull/3851)
* AGENT-1519 | [Below-the-sea UI] Allow the user to select IPv6 in the Networking Stack Type field (#3806) [#3806](https://github.com/openshift-assisted/assisted-installer-ui/pull/3806)
* [MGMT-23950](https://issues.redhat.com/browse/MGMT-23950): [Staging] [UI] - Cluster name missing in page header for draft clusters (#3669) (#3835) [#3669](https://github.com/openshift-assisted/assisted-installer-ui/pull/3669)
* Fix disk encryption parsing for cluster details (#3737) (#3843) [#3737](https://github.com/openshift-assisted/assisted-installer-ui/pull/3737)
* [MGMT-19002](https://issues.redhat.com/browse/MGMT-19002): [nmstate] UI form view missing autoconf field for ipv6 (#3681) (#3836) [#3681](https://github.com/openshift-assisted/assisted-installer-ui/pull/3681)
* Tweak discovery ISO modal sizing (#3792) (#3846) [#3792](https://github.com/openshift-assisted/assisted-installer-ui/pull/3792)
* [MGMT-23490](https://issues.redhat.com/browse/MGMT-23490): Refactor Troubleshooting Web Console (#3688) (#3839) [#3688](https://github.com/openshift-assisted/assisted-installer-ui/pull/3688)
* [OCPBUGS-88249](https://issues.redhat.com/browse/OCPBUGS-88249), [OCPBUGS-88400](https://issues.redhat.com/browse/OCPBUGS-88400): Ensure axios version is resolved to 1.18.1 (#3857) [#3857](https://github.com/openshift-assisted/assisted-installer-ui/pull/3857)
* Pull secret appears editable in draft cluster but changes are not applied (#3597) (#3831) [#3597](https://github.com/openshift-assisted/assisted-installer-ui/pull/3597)
* [MGMT-24099](https://issues.redhat.com/browse/MGMT-24099): UI redirects to Custom Manifest page before host discovery when cluster is OCI platform (#3739) (#3844) [#3739](https://github.com/openshift-assisted/assisted-installer-ui/pull/3739)
* Fix machine network autoselect to work with IPv6 only clusters (#3813) (#3848) [#3813](https://github.com/openshift-assisted/assisted-installer-ui/pull/3813)
* Fix nested expandable sections (#3798) [#3798](https://github.com/openshift-assisted/assisted-installer-ui/pull/3798)
* [OCPBUGS-86813](https://issues.redhat.com/browse/OCPBUGS-86813): Custom manifests are broken in local assisted UI (#3768) [#3768](https://github.com/openshift-assisted/assisted-installer-ui/pull/3768)
* [OCPBUGS-86258](https://issues.redhat.com/browse/OCPBUGS-86258): Static ip prefill for ove below the sea (#3767) [#3767](https://github.com/openshift-assisted/assisted-installer-ui/pull/3767)
* Operators section should not be displayed on review and installation progress pages when no operators are selected (#3750) [#3750](https://github.com/openshift-assisted/assisted-installer-ui/pull/3750)
* Remove Arbiter button (#3748) [#3748](https://github.com/openshift-assisted/assisted-installer-ui/pull/3748)
* fix monted pull secret parsing (#3724) [#3724](https://github.com/openshift-assisted/assisted-installer-ui/pull/3724)
* Allow to install SNO topology (#3721) [#3721](https://github.com/openshift-assisted/assisted-installer-ui/pull/3721)
* [OCPBUGS-85230](https://issues.redhat.com/browse/OCPBUGS-85230): Ensure follow-redirects pkg resolves to ^1.16.0 (#3705) [#3705](https://github.com/openshift-assisted/assisted-installer-ui/pull/3705)
* [OCPBUGS-85265](https://issues.redhat.com/browse/OCPBUGS-85265): [release-4.22] OCPBUGS-84038 | [Below the sea UI] Lack of visual feedback (spinner) on disabled "Next" button during background validation (#3703) [#3703](https://github.com/openshift-assisted/assisted-installer-ui/pull/3703)
* [OCPBUGS-84318](https://issues.redhat.com/browse/OCPBUGS-84318): fix operators list in ABI below the sea (#3645) [#3645](https://github.com/openshift-assisted/assisted-installer-ui/pull/3645)
* Hide internally generated custom manifests on the Cluster Review page (#3700) [#3700](https://github.com/openshift-assisted/assisted-installer-ui/pull/3700)
* [OCPBUGS-85199](https://issues.redhat.com/browse/OCPBUGS-85199): [release-4.22] OCPBUGS-84147 | [Below the sea UI] Leaky Abstraction: Transient 500 errors exposed during host binding process (#3683) [#3683](https://github.com/openshift-assisted/assisted-installer-ui/pull/3683)
* Remove 2 node arbiter option from the control plane dropdown option (#3702) [#3702](https://github.com/openshift-assisted/assisted-installer-ui/pull/3702)
* [OCPBUGS-85220](https://issues.redhat.com/browse/OCPBUGS-85220), [OCPBUGS-85222](https://issues.redhat.com/browse/OCPBUGS-85222), [OCPBUGS-85224](https://issues.redhat.com/browse/OCPBUGS-85224), [OCPBUGS-85226](https://issues.redhat.com/browse/OCPBUGS-85226), [OCPBUGS-85228](https://issues.redhat.com/browse/OCPBUGS-85228): Bump axios to ^1.15.1 (#3693) [#3693](https://github.com/openshift-assisted/assisted-installer-ui/pull/3693)
* [OCPBUGS-84272](https://issues.redhat.com/browse/OCPBUGS-84272): bump axios to ^1.15.0 for fixing CVE-2026-40175 (#3638) [#3638](https://github.com/openshift-assisted/assisted-installer-ui/pull/3638)
* [Full changelog](https://github.com/openshift-assisted/assisted-installer-ui/compare/e9c0dbce8387f158ce1cecb4b3f2182d69be939f...9380434565d3f9b0031b353a008ae97050b038a0)
### [agent-installer-utils](https://github.com/openshift/agent-installer-utils/tree/817b11805be82a177657128eac624df2e969d9b2)
* [OCPBUGS-105451](https://issues.redhat.com/browse/OCPBUGS-105451): Update Konflux references [#337](https://github.com/openshift/agent-installer-utils/pull/337)
* [OCPBUGS-101760](https://issues.redhat.com/browse/OCPBUGS-101760): Update Konflux references [#329](https://github.com/openshift/agent-installer-utils/pull/329)
* [OCPBUGS-100105](https://issues.redhat.com/browse/OCPBUGS-100105): Use Operator catalog in 4.22 for OVE [#325](https://github.com/openshift/agent-installer-utils/pull/325)
* [AGENT-1568](https://issues.redhat.com/browse/AGENT-1568): Add lvms-operator to config [#324](https://github.com/openshift/agent-installer-utils/pull/324)
* [OCPBUGS-99906](https://issues.redhat.com/browse/OCPBUGS-99906): Update Konflux references [#302](https://github.com/openshift/agent-installer-utils/pull/302)
* [OCPBUGS-99556](https://issues.redhat.com/browse/OCPBUGS-99556): Use agent-preinstall-image-builder from quay-proxy [#321](https://github.com/openshift/agent-installer-utils/pull/321)
* [OCPBUGS-98743](https://issues.redhat.com/browse/OCPBUGS-98743): Update cluster-logging and loki operator versions [#316](https://github.com/openshift/agent-installer-utils/pull/316)
* [OCPBUGS-89320](https://issues.redhat.com/browse/OCPBUGS-89320): bump mtv-operator to release-v2.12 [#310](https://github.com/openshift/agent-installer-utils/pull/310)
* [OCPBUGS-86042](https://issues.redhat.com/browse/OCPBUGS-86042): Filter out link-local IPv6 addresses [#306](https://github.com/openshift/agent-installer-utils/pull/306)
* [OCPBUGS-85525](https://issues.redhat.com/browse/OCPBUGS-85525): update konflux references [#296](https://github.com/openshift/agent-installer-utils/pull/296)
* [Full changelog](https://github.com/openshift/agent-installer-utils/compare/113794d5b89d0caa153fe763d42627cfe0c2f845...817b11805be82a177657128eac624df2e969d9b2)
### [aws-cloud-controller-manager](https://github.com/openshift/cloud-provider-aws/tree/b4bad3f89f54ea5df70e49d1fbf3ea3cbc8e59a3)
* [OCPBUGS-83898](https://issues.redhat.com/browse/OCPBUGS-83898): UPSTREAM: <drop>: bump google.golang.org/grpc to v1.79.3 [#155](https://github.com/openshift/cloud-provider-aws/pull/155)
* [Full changelog](https://github.com/openshift/cloud-provider-aws/compare/e73d6a3821655afc6fb19d88a66907078e6854f2...b4bad3f89f54ea5df70e49d1fbf3ea3cbc8e59a3)
### [aws-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-aws/tree/f60301561fe801da499b22f58aae57eae16ada5a)
* 🌱 [release-4.22] OCPBUGS-119954: UPSTREAM: <carry>: Remove upstream .github files unused in OpenShift CI [#633](https://github.com/openshift/cluster-api-provider-aws/pull/633)
* 🐛 [release-4.22] OCPBUGS-112305: UPSTREAM: 6132: Persist ProviderID immediately after instance creation [#626](https://github.com/openshift/cluster-api-provider-aws/pull/626)
* [OCPBUGS-84393](https://issues.redhat.com/browse/OCPBUGS-84393): Bump github.com/go-jose/go-jose/v4 to 4.1.4 [#606](https://github.com/openshift/cluster-api-provider-aws/pull/606)
* [Full changelog](https://github.com/openshift/cluster-api-provider-aws/compare/905f4a9f558075b7957e44dabd255410022b55ad...f60301561fe801da499b22f58aae57eae16ada5a)
### [aws-ebs-csi-driver](https://github.com/openshift/aws-ebs-csi-driver/tree/51d6bc760234ffccb0348937a5cfd70b326119b9)
* [OCPBUGS-83900](https://issues.redhat.com/browse/OCPBUGS-83900): UPSTREAM: 2911: bump google.golang.org/grpc v1.80.0 to fix CVE-2026-33186 [#316](https://github.com/openshift/aws-ebs-csi-driver/pull/316)
* [Full changelog](https://github.com/openshift/aws-ebs-csi-driver/compare/0927af1c1397b6f3c7545c715e1a87e0263ae2bf...51d6bc760234ffccb0348937a5cfd70b326119b9)
### [aws-ebs-csi-driver-operator, azure-disk-csi-driver-operator, azure-file-csi-driver-operator, csi-driver-manila-operator, openstack-cinder-csi-driver-operator](https://github.com/openshift/csi-operator/tree/dc8b3b3ca8c6930b4f90ff4eaf262f093a4ef368)
* [OCPBUGS-119697](https://issues.redhat.com/browse/OCPBUGS-119697): Add proxy hook for HyperShift CSI driver controller deployments [#619](https://github.com/openshift/csi-operator/pull/619)
* [OCPBUGS-101882](https://issues.redhat.com/browse/OCPBUGS-101882), [OCPBUGS-101889](https://issues.redhat.com/browse/OCPBUGS-101889), [OCPBUGS-101890](https://issues.redhat.com/browse/OCPBUGS-101890), [OCPBUGS-102000](https://issues.redhat.com/browse/OCPBUGS-102000): Bump golang.org/x/net to v0.53.0 [#602](https://github.com/openshift/csi-operator/pull/602)
* [OCPBUGS-109635](https://issues.redhat.com/browse/OCPBUGS-109635): csi-driver-smb: DeleteVolume call fails to mkdir under /tmp [#597](https://github.com/openshift/csi-operator/pull/597)
* [OCPBUGS-91947](https://issues.redhat.com/browse/OCPBUGS-91947): maxOpenShiftVersion should be bumped to 5.0 [#572](https://github.com/openshift/csi-operator/pull/572)
* [OCPBUGS-85532](https://issues.redhat.com/browse/OCPBUGS-85532): Add init container for Manila node daemonset [#555](https://github.com/openshift/csi-operator/pull/555)
* [OCPBUGS-85116](https://issues.redhat.com/browse/OCPBUGS-85116): Mount writable /tmp in SMB CSI driver [#550](https://github.com/openshift/csi-operator/pull/550)
* [Full changelog](https://github.com/openshift/csi-operator/compare/29ce27e3cb149599158f7d56ded23b1426d0048f...dc8b3b3ca8c6930b4f90ff4eaf262f093a4ef368)
### [aws-karpenter-provider-aws](https://github.com/openshift/aws-karpenter-provider-aws/tree/f607badaa794779517b2a16a9d978f05a502ce8e)
* [OCPBUGS-118884](https://issues.redhat.com/browse/OCPBUGS-118884): default max-pods to 250 for Custom AMI family [#43](https://github.com/openshift/aws-karpenter-provider-aws/pull/43)
* [OCPBUGS-101842](https://issues.redhat.com/browse/OCPBUGS-101842): Fix CVE-2026-33814 [#35](https://github.com/openshift/aws-karpenter-provider-aws/pull/35)
* [Full changelog](https://github.com/openshift/aws-karpenter-provider-aws/compare/f0be9c72e5bf25caeb2ca45c14e67e4d397a52cb...f607badaa794779517b2a16a9d978f05a502ce8e)
### [azure-cloud-controller-manager, azure-cloud-node-manager](https://github.com/openshift/cloud-provider-azure/tree/a17a3e3eb36b14f0348b003018879a32394c7264)
* [OCPBUGS-88485](https://issues.redhat.com/browse/OCPBUGS-88485): Bump golang.org/x/net from v0.49.0 to v0.55.0 [#193](https://github.com/openshift/cloud-provider-azure/pull/193)
* [OCPBUGS-85706](https://issues.redhat.com/browse/OCPBUGS-85706), [OCPBUGS-85707](https://issues.redhat.com/browse/OCPBUGS-85707): UPSTREAM: <drop>: bump google.golang.org/grpc to v1.79.3 [#185](https://github.com/openshift/cloud-provider-azure/pull/185)
* [Full changelog](https://github.com/openshift/cloud-provider-azure/compare/4c7a764630c621d5e1700649fc056800d35bb6d1...a17a3e3eb36b14f0348b003018879a32394c7264)
### [azure-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-azure/tree/dd79471cc2f34c7c0b074ee8abc6f43a069811c2)
* [OCPBUGS-105465](https://issues.redhat.com/browse/OCPBUGS-105465): Address CVE-2026-39829 [#396](https://github.com/openshift/cluster-api-provider-azure/pull/396)
* [Full changelog](https://github.com/openshift/cluster-api-provider-azure/compare/a6ffab6a17878cb9b9eeaa6337c996989d1e7ee3...dd79471cc2f34c7c0b074ee8abc6f43a069811c2)
### [azure-disk-csi-driver](https://github.com/openshift/azure-disk-csi-driver/tree/b9046c19b05e2dc75a929328e698ab2cc7e279c9)
* UPSTREAM: 3635: OCPBUGS-96598: Bump golang.org/x/net to v0.55.0 [#165](https://github.com/openshift/azure-disk-csi-driver/pull/165)
* [OCPBUGS-106152](https://issues.redhat.com/browse/OCPBUGS-106152): UPSTREAM: 3756: fix: optionally skip reading the config from the API server [#163](https://github.com/openshift/azure-disk-csi-driver/pull/163)
* [OCPBUGS-83633](https://issues.redhat.com/browse/OCPBUGS-83633): Bump spdystream to v0.5.1 [#150](https://github.com/openshift/azure-disk-csi-driver/pull/150)
* [OCPBUGS-85193](https://issues.redhat.com/browse/OCPBUGS-85193): check for node name in waitForDiskManagedByTobeRemoved [#146](https://github.com/openshift/azure-disk-csi-driver/pull/146)
* [Full changelog](https://github.com/openshift/azure-disk-csi-driver/compare/a995719b8666626dbffe09c03f039611feb48612...b9046c19b05e2dc75a929328e698ab2cc7e279c9)
### [azure-file-csi-driver](https://github.com/openshift/azure-file-csi-driver/tree/32f7275441afca97750de9f1e415bad7c8fbdee3)
* [OCPBUGS-101874](https://issues.redhat.com/browse/OCPBUGS-101874): Bump golang.org/x/net to v0.53.0 [#154](https://github.com/openshift/azure-file-csi-driver/pull/154)
* [OCPBUGS-95536](https://issues.redhat.com/browse/OCPBUGS-95536): Bump golang.org/x/crypto to v0.48.0-sec.1 [#144](https://github.com/openshift/azure-file-csi-driver/pull/144)
* [Full changelog](https://github.com/openshift/azure-file-csi-driver/compare/403f856e29605126b2711a1bfe7a4f6c276b344d...32f7275441afca97750de9f1e415bad7c8fbdee3)
### [azure-kms-encryption-provider](https://github.com/openshift/azure-kubernetes-kms/tree/42b1def6c429806b08ca71c0275aba7924f5ced0)
* [CNTRLPLANE-4024](https://issues.redhat.com/browse/CNTRLPLANE-4024): support sovereign Managed HSM endpoints- #56 [#56](https://github.com/openshift/azure-kubernetes-kms/pull/56)
* [OCPBUGS-101846](https://issues.redhat.com/browse/OCPBUGS-101846): [release-4.22] Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [#57](https://github.com/openshift/azure-kubernetes-kms/pull/57)
* [CNTRLPLANE-4024](https://issues.redhat.com/browse/CNTRLPLANE-4024): [release-4.22]: Correct Managed HSM endpoints [#53](https://github.com/openshift/azure-kubernetes-kms/pull/53)
* [Full changelog](https://github.com/openshift/azure-kubernetes-kms/compare/99b9a3a33d8edfd0a2d2876aa7ef1382b2c75a39...42b1def6c429806b08ca71c0275aba7924f5ced0)
### [azure-machine-controllers](https://github.com/openshift/machine-api-provider-azure/tree/bad7e9447fa66002e5ec7b0b7952545e7e8a6c9f)
* [OCPBUGS-98074](https://issues.redhat.com/browse/OCPBUGS-98074): Bump golang.org/x/crypto from v0.47.0 to v0.54.0 [#205](https://github.com/openshift/machine-api-provider-azure/pull/205)
* [OCPBUGS-86996](https://issues.redhat.com/browse/OCPBUGS-86996): Don't permanently fail Machines after provisioning [#195](https://github.com/openshift/machine-api-provider-azure/pull/195)
* [PIXAA-7](https://issues.redhat.com/browse/PIXAA-7): Leverage SpotRebalanceRecommendation for instance termination when available [#198](https://github.com/openshift/machine-api-provider-azure/pull/198)
* [Full changelog](https://github.com/openshift/machine-api-provider-azure/compare/69d049094ee36ad9c706d65694a8cd42e9a64800...bad7e9447fa66002e5ec7b0b7952545e7e8a6c9f)
### [baremetal-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-metal3/tree/6481b52008f0991912f80fdf9d74af3e631a7269)
* [OCPBUGS-86688](https://issues.redhat.com/browse/OCPBUGS-86688): Adopt existing Metal3 Remediation CRDs on upgrade [#83](https://github.com/openshift/cluster-api-provider-metal3/pull/83)
* [Full changelog](https://github.com/openshift/cluster-api-provider-metal3/compare/ad4eb8a5e67dc08c0686f006641847df4370d599...6481b52008f0991912f80fdf9d74af3e631a7269)
### [baremetal-installer, installer, installer-artifacts](https://github.com/openshift/installer/tree/e9327a5587a02cff8aae7e41a06ef86382334b4c)
* [OCPBUGS-100061](https://issues.redhat.com/browse/OCPBUGS-100061): openstack: Reserve addresses for load balancer [#10725](https://github.com/openshift/installer/pull/10725)
* [OCPBUGS-114639](https://issues.redhat.com/browse/OCPBUGS-114639): OCPBUGS-112550, OCPBUGS-112549: Release 4.22 GCD and KMS support [#10783](https://github.com/openshift/installer/pull/10783)
* [AGENT-1583](https://issues.redhat.com/browse/AGENT-1583): post-feature promotion (NoRegistryClusterInstall) openshift/api dependencies bump [#10817](https://github.com/openshift/installer/pull/10817)
* [OCPBUGS-112471](https://issues.redhat.com/browse/OCPBUGS-112471): Update timeout in GetMarketplaceImage to 5 minutes [#10784](https://github.com/openshift/installer/pull/10784)
* [OCPBUGS-111885](https://issues.redhat.com/browse/OCPBUGS-111885): pin argcomplete for yq on Python 3.9 (release-4.22) [#10766](https://github.com/openshift/installer/pull/10766)
* Bug OCPBUGS-99399: baremetal: fix provisioning ISO kernel arguments [#10703](https://github.com/openshift/installer/pull/10703)
* [AGENT-1546](https://issues.redhat.com/browse/AGENT-1546): Backport NoRegistryClusterInstall feature to release-4.22 [#10683](https://github.com/openshift/installer/pull/10683)
* [OCPBUGS-87814](https://issues.redhat.com/browse/OCPBUGS-87814): [release-4.22] Add omitempty to vSphere and Nutanix MachinePool slice fields [#10606](https://github.com/openshift/installer/pull/10606)
* [OCPBUGS-95555](https://issues.redhat.com/browse/OCPBUGS-95555), [OCPBUGS-99017](https://issues.redhat.com/browse/OCPBUGS-99017): bump golang.org/x/crypto to 0.52.0 [#10695](https://github.com/openshift/installer/pull/10695)
* [OCPBUGS-98982](https://issues.redhat.com/browse/OCPBUGS-98982): Update RHCOS-release-4.22 bootimage metadata to 9.8.20260715-1 / 10.2.20260715-0 [#10692](https://github.com/openshift/installer/pull/10692)
* [OCPBUGS-98701](https://issues.redhat.com/browse/OCPBUGS-98701): cluster-api: disable diagnostics endpoint for local CAPI controllers [#10685](https://github.com/openshift/installer/pull/10685)
* [OCPBUGS-87812](https://issues.redhat.com/browse/OCPBUGS-87812): [release-4.22] fix: reset associatedVCenter in failure domain validation loop [#10604](https://github.com/openshift/installer/pull/10604)
* [OCPBUGS-97964](https://issues.redhat.com/browse/OCPBUGS-97964): destroy/aws: delete vpc endpoints earlier [#10674](https://github.com/openshift/installer/pull/10674)
* no-jira: images: bump UPI image dependencies to 4.22 [#10582](https://github.com/openshift/installer/pull/10582)
* [OCPBUGS-84402](https://issues.redhat.com/browse/OCPBUGS-84402): Bump go-jose/v4 to 4.1.4 [#10597](https://github.com/openshift/installer/pull/10597)
* [OCPBUGS-84643](https://issues.redhat.com/browse/OCPBUGS-84643): Update RHCOS-release-4.22 bootimage metadata to 10.2.20260521-0 / 9.8.20260520-0 [#10572](https://github.com/openshift/installer/pull/10572)
* [OCPBUGS-85407](https://issues.redhat.com/browse/OCPBUGS-85407): PowerVS: Add port 80 security group rule [#10548](https://github.com/openshift/installer/pull/10548)
* [OCPBUGS-85503](https://issues.redhat.com/browse/OCPBUGS-85503): PowerVS: Fix supported system types retrieval [#10521](https://github.com/openshift/installer/pull/10521)
* [Full changelog](https://github.com/openshift/installer/compare/b8a967b9336275a333e96a658dcccebbc0fb8fea...e9327a5587a02cff8aae7e41a06ef86382334b4c)
### [baremetal-operator](https://github.com/openshift/baremetal-operator/tree/7fc3bd6c4f36acec9944d5adcd2083ae21a8df4b)
* [OCPBUGS-90570](https://issues.redhat.com/browse/OCPBUGS-90570): Reject non-empty checksum for OCI images [#501](https://github.com/openshift/baremetal-operator/pull/501)
* [OCPBUGS-99420](https://issues.redhat.com/browse/OCPBUGS-99420): Create ports if they are already inspected and machine is re-registering [#518](https://github.com/openshift/baremetal-operator/pull/518)
* [OCPBUGS-83866](https://issues.redhat.com/browse/OCPBUGS-83866): Include image URL and checksum in provisioning error message [#500](https://github.com/openshift/baremetal-operator/pull/500)
* [OCPBUGS-94109](https://issues.redhat.com/browse/OCPBUGS-94109): cherry-pick reconciler optimizations [#503](https://github.com/openshift/baremetal-operator/pull/503)
* [OCPBUGS-97940](https://issues.redhat.com/browse/OCPBUGS-97940): Add BMH finalizer on PreprovisioningImage [#505](https://github.com/openshift/baremetal-operator/pull/505)
* [OCPBUGS-87963](https://issues.redhat.com/browse/OCPBUGS-87963): Fix preprovisioning network Secret lifecycle during BMH deletion [#491](https://github.com/openshift/baremetal-operator/pull/491)
* [Full changelog](https://github.com/openshift/baremetal-operator/compare/c5e5048987427f58d3ca76238537e74bd3175e0f...7fc3bd6c4f36acec9944d5adcd2083ae21a8df4b)
### [baremetal-runtimecfg](https://github.com/openshift/baremetal-runtimecfg/tree/1df165545dd61e73101e73ec174e7bd2c930887a)
* [OCPBUGS-112618](https://issues.redhat.com/browse/OCPBUGS-112618): Cloud Platforms: Filter out node's own IP from Upstreams [#401](https://github.com/openshift/baremetal-runtimecfg/pull/401)
* [Full changelog](https://github.com/openshift/baremetal-runtimecfg/compare/dca8cb1be0cce1ce404dfd407ead1326a3c8bb40...1df165545dd61e73101e73ec174e7bd2c930887a)
### [cli, cli-artifacts, deployer, tools](https://github.com/openshift/oc/tree/96ed0f43f0b5adf771ce3bd4fbc86809e93139f8)
* [OCPBUGS-114734](https://issues.redhat.com/browse/OCPBUGS-114734): Fix windows builds of oc rpm [#2383](https://github.com/openshift/oc/pull/2383)
* [OCPBUGS-98547](https://issues.redhat.com/browse/OCPBUGS-98547): bump x/crypto to the latest version [#2309](https://github.com/openshift/oc/pull/2309)
* [OCPBUGS-85066](https://issues.redhat.com/browse/OCPBUGS-85066): Add required-scc annotation to node-joiner pod [#2266](https://github.com/openshift/oc/pull/2266)
* [Full changelog](https://github.com/openshift/oc/compare/66dee73f66c4f048c333c6a77d76871872027896...96ed0f43f0b5adf771ce3bd4fbc86809e93139f8)
### [cloud-credential-operator](https://github.com/openshift/cloud-credential-operator/tree/26005d211cfdd678a036d06316d783a09eab2446)
* [OCPBUGS-114669](https://issues.redhat.com/browse/OCPBUGS-114669): Enable GCP custom universe domain support for CCO [#1083](https://github.com/openshift/cloud-credential-operator/pull/1083)
* NO-JIRA: Revert "OCPBUGS-87828: Scope minted AWS IAM policies to cluster-owned resources" [#1059](https://github.com/openshift/cloud-credential-operator/pull/1059)
* [OCPBUGS-87828](https://issues.redhat.com/browse/OCPBUGS-87828): Scope minted AWS IAM policies to cluster-owned resources [#1045](https://github.com/openshift/cloud-credential-operator/pull/1045)
* [Full changelog](https://github.com/openshift/cloud-credential-operator/compare/c23bddf58e561b725ab5eb012252091e7a472084...26005d211cfdd678a036d06316d783a09eab2446)
### [cloud-network-config-controller](https://github.com/openshift/cloud-network-config-controller/tree/8bc05a827fe54e1421013a198ffefe776efa5b6f)
* : [release-4.22] OCPBUGS-115316: GCP: Set Universe Domain [#264](https://github.com/openshift/cloud-network-config-controller/pull/264)
* [Full changelog](https://github.com/openshift/cloud-network-config-controller/compare/2d69ad953cfaa419e9b6221da9edb152ded91e0b...8bc05a827fe54e1421013a198ffefe776efa5b6f)
### [cluster-authentication-operator](https://github.com/openshift/cluster-authentication-operator/tree/5a44cc2a8c36d144f8782e23f47bc31e2e4ead88)
* [OCPBUGS-85105](https://issues.redhat.com/browse/OCPBUGS-85105): Fix OAuth page showing OKD branding instead of OpenShift [#888](https://github.com/openshift/cluster-authentication-operator/pull/888)
* [Full changelog](https://github.com/openshift/cluster-authentication-operator/compare/20e02b519a694fee38169221eeb8e6bfa421539b...5a44cc2a8c36d144f8782e23f47bc31e2e4ead88)
### [cluster-autoscaler](https://github.com/openshift/kubernetes-autoscaler/tree/89f51dcb39919234f4b9b1efb37ffecb68ba7366)
* [OCPBUGS-102038](https://issues.redhat.com/browse/OCPBUGS-102038): [4.22] Fix OCPBUGS-102038 [#434](https://github.com/openshift/kubernetes-autoscaler/pull/434)
* [OCPBUGS-99551](https://issues.redhat.com/browse/OCPBUGS-99551): [release-4.22] UPSTREAM: 10001: chore(clusterapi): add machine phase check for failed machines [#431](https://github.com/openshift/kubernetes-autoscaler/pull/431)
* [Full changelog](https://github.com/openshift/kubernetes-autoscaler/compare/521e545fb92e7138b2ce2bc05f871f53a6c112fb...89f51dcb39919234f4b9b1efb37ffecb68ba7366)
### [cluster-autoscaler-operator](https://github.com/openshift/cluster-autoscaler-operator/tree/effcafeed5e4ab9cee8e312de2aa123331eea9fa)
* [OCPBUGS-101883](https://issues.redhat.com/browse/OCPBUGS-101883): Bump x/net package in release-4.22 [#387](https://github.com/openshift/cluster-autoscaler-operator/pull/387)
* [Full changelog](https://github.com/openshift/cluster-autoscaler-operator/compare/260ea1b5967f47768a0727e8c84d451dc9de5ced...effcafeed5e4ab9cee8e312de2aa123331eea9fa)
### [cluster-baremetal-operator](https://github.com/openshift/cluster-baremetal-operator/tree/4e98263f296f7886468df2f15f8354fb265b4d91)
* [OCPBUGS-99390](https://issues.redhat.com/browse/OCPBUGS-99390): Make CBO progress in non-baremetal platforms [#646](https://github.com/openshift/cluster-baremetal-operator/pull/646)
* [OCPBUGS-99390](https://issues.redhat.com/browse/OCPBUGS-99390): Cluster Operator baremetal did not report Progressing=True during a cluster update [#634](https://github.com/openshift/cluster-baremetal-operator/pull/634)
* [OCPBUGS-99501](https://issues.redhat.com/browse/OCPBUGS-99501): Apply cluster TLS profile to ironic-proxy container [#635](https://github.com/openshift/cluster-baremetal-operator/pull/635)
* [OCPBUGS-87212](https://issues.redhat.com/browse/OCPBUGS-87212): Add watcher for both TLS Adherence policy and profile changes [#610](https://github.com/openshift/cluster-baremetal-operator/pull/610)
* [OCPBUGS-86226](https://issues.redhat.com/browse/OCPBUGS-86226): Fix empty IRONIC_BASE_URL [#606](https://github.com/openshift/cluster-baremetal-operator/pull/606)
* [OCPBUGS-85640](https://issues.redhat.com/browse/OCPBUGS-85640): Fix webhook to validate the actual admission request object [#602](https://github.com/openshift/cluster-baremetal-operator/pull/602)
* [OCPBUGS-84936](https://issues.redhat.com/browse/OCPBUGS-84936): Fix webhook server not starting due to missing WithValidator [#598](https://github.com/openshift/cluster-baremetal-operator/pull/598)
* [Full changelog](https://github.com/openshift/cluster-baremetal-operator/compare/69a9d699a9dd3ffc151c1a73e135d4823b75ef6c...4e98263f296f7886468df2f15f8354fb265b4d91)
### [cluster-capi-operator](https://github.com/openshift/cluster-capi-operator/tree/5430ff7a34d4c0a946740dcdcd98690c14c63cf9)
* [OCPBUGS-96609](https://issues.redhat.com/browse/OCPBUGS-96609): Bump golang.org/x/net to v0.56.0 to fix CVE-2026-27136 [#624](https://github.com/openshift/cluster-capi-operator/pull/624)
* [OCPBUGS-86353](https://issues.redhat.com/browse/OCPBUGS-86353): fix: scope webhook to capi namespace, remove unused webhook endpoints [#568](https://github.com/openshift/cluster-capi-operator/pull/568)
* NO-JIRA: Allow sustaining engineering to self serve dependency updates [#555](https://github.com/openshift/cluster-capi-operator/pull/555)
* [Full changelog](https://github.com/openshift/cluster-capi-operator/compare/6c7ba9cea681f90fbab82d9e2e222e5afbacd885...5430ff7a34d4c0a946740dcdcd98690c14c63cf9)
### [cluster-cloud-controller-manager-operator](https://github.com/openshift/cluster-cloud-controller-manager-operator/tree/e893bf67ceaaf4c0305ea821faf7cb3b98bd3efa)
* [OCPBUGS-114394](https://issues.redhat.com/browse/OCPBUGS-114394): [release-4.22] GCP Alternate Universe Domain Support [#508](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/508)
* [OCPBUGS-112665](https://issues.redhat.com/browse/OCPBUGS-112665): Moved node sync job creation from manifest to operator controller [#507](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/507)
* [OCPBUGS-105883](https://issues.redhat.com/browse/OCPBUGS-105883): Created new job to update vSphere nodes to have vsphere label [#501](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/501)
* [OCPBUGS-94184](https://issues.redhat.com/browse/OCPBUGS-94184): OCPBUGS-65582: [release-4.22] OCPBUGS-65582: manifests: Shift operator Deployment and ClusterOperator after CredentialsRequests [#484](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/484)
* [SPLAT-2794](https://issues.redhat.com/browse/SPLAT-2794): Create OTE Binary and add vSphere hybrid e2e tests [#471](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/471)
* [OCPBUGS-92656](https://issues.redhat.com/browse/OCPBUGS-92656): e2e/ccm-aws-ote: support to dual-stack IPv6 primary [#480](https://github.com/openshift/cluster-cloud-controller-manager-operator/pull/480)
* [Full changelog](https://github.com/openshift/cluster-cloud-controller-manager-operator/compare/1eccfe33d83686e74769ea196660b8d09d249b04...e893bf67ceaaf4c0305ea821faf7cb3b98bd3efa)
### [cluster-config-api](https://github.com/openshift/api/tree/42fb550ea02a47ab1de1ee81d798706cb74035a1)
* [OCPBUGS-116848](https://issues.redhat.com/browse/OCPBUGS-116848): Add Sovereign cloud feature gate and UniverseDomain field to GCPPlatformStatus [#3022](https://github.com/openshift/api/pull/3022)
* [OCPBUGS-113639](https://issues.redhat.com/browse/OCPBUGS-113639): move empty CRIOCredentialProviderConfig CR to run-level 0000_10 [#3010](https://github.com/openshift/api/pull/3010)
* [SPLAT-2718](https://issues.redhat.com/browse/SPLAT-2718): Promote FeatureGateVSphereMixedNodeEnv to GA [#2949](https://github.com/openshift/api/pull/2949)
* [OCPBUGS-113600](https://issues.redhat.com/browse/OCPBUGS-113600): [release-4.22] OCPBUGS-112479: Handle Sippy date-only format in featuregate-test-analyzer [#3008](https://github.com/openshift/api/pull/3008)
* [OCPBUGS-105168](https://issues.redhat.com/browse/OCPBUGS-105168): Add haproxyVersion in IngressController API [#2971](https://github.com/openshift/api/pull/2971)
* [AGENT-1578](https://issues.redhat.com/browse/AGENT-1578): Promote NoRegistryClusterInstall feature to default [#2979](https://github.com/openshift/api/pull/2979)
* [AGENT-1544](https://issues.redhat.com/browse/AGENT-1544): Backport NoRegistryClusterInstall feature to release-4.22 [#2930](https://github.com/openshift/api/pull/2930)
* [OCPBUGS-98222](https://issues.redhat.com/browse/OCPBUGS-98222): add new serviceAccountToken fs type [#2922](https://github.com/openshift/api/pull/2922)
* Promote EVPN Feature Gate to GA [#2826](https://github.com/openshift/api/pull/2826)
* [OCPBUGS-85102](https://issues.redhat.com/browse/OCPBUGS-85102): Add labelSelector to MachineSet status for scale subresource [#2831](https://github.com/openshift/api/pull/2831)
* [Full changelog](https://github.com/openshift/api/compare/e9fad7d4cba1537b8af99b972370e76370de72e9...42fb550ea02a47ab1de1ee81d798706cb74035a1)
### [cluster-control-plane-machine-set-operator](https://github.com/openshift/cluster-control-plane-machine-set-operator/tree/55dea4dc947da2d8a9c1ffba451a41c3b3662718)
* [OCPBUGS-87968](https://issues.redhat.com/browse/OCPBUGS-87968): Fixed issue where nameserver is not set when recreating cpms [#409](https://github.com/openshift/cluster-control-plane-machine-set-operator/pull/409)
* [Full changelog](https://github.com/openshift/cluster-control-plane-machine-set-operator/compare/b2e26b937e7f6dab36b63ace9c8453ba9654011c...55dea4dc947da2d8a9c1ffba451a41c3b3662718)
### [cluster-csi-snapshot-controller-operator](https://github.com/openshift/cluster-csi-snapshot-controller-operator/tree/e9b3b21fbc322cb410a58b5f147ac76893d851ea)
* [OCPBUGS-101892](https://issues.redhat.com/browse/OCPBUGS-101892): Bump golang.org/x/net from v0.52.0 to v0.53.0 [#286](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/286)
* [OCPBUGS-88472](https://issues.redhat.com/browse/OCPBUGS-88472): Fix group snapshots on HyperShift [#280](https://github.com/openshift/cluster-csi-snapshot-controller-operator/pull/280)
* [Full changelog](https://github.com/openshift/cluster-csi-snapshot-controller-operator/compare/108f37f0e378accc322cbeb68136ec500ec35b94...e9b3b21fbc322cb410a58b5f147ac76893d851ea)
### [cluster-etcd-operator](https://github.com/openshift/cluster-etcd-operator/tree/14ecb163d4a69d1e53802c21d799d6f16b2303dc)
* [OCPBUGS-100120](https://issues.redhat.com/browse/OCPBUGS-100120): Revert 'OCPBUGS-88490: fix etcd operator deadlock when etcd-endpoints configmap is stale' [#1661](https://github.com/openshift/cluster-etcd-operator/pull/1661)
* [OCPBUGS-90542](https://issues.redhat.com/browse/OCPBUGS-90542): fix etcd operator deadlock when etcd-endpoints configmap is stale [#1636](https://github.com/openshift/cluster-etcd-operator/pull/1636)
* [OCPBUGS-86960](https://issues.redhat.com/browse/OCPBUGS-86960): validate snapshot before destructive operations in cluster-restore-tnf.sh [#1627](https://github.com/openshift/cluster-etcd-operator/pull/1627)
* And 2 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/cluster-etcd-operator/compare/3698b93d071f8b279b1721f90ced478f0b90b426...14ecb163d4a69d1e53802c21d799d6f16b2303dc)
### [cluster-image-registry-operator](https://github.com/openshift/cluster-image-registry-operator/tree/c331da28c42721724ed5229c972c956cd1d9502c)
* [OCPBUGS-88489](https://issues.redhat.com/browse/OCPBUGS-88489): Fix image registry deployment failure on aws-ovn-edge-zones [#1366](https://github.com/openshift/cluster-image-registry-operator/pull/1366)
* [release 4.22] OCPBUGS-114413: GCP Universe Domain Support [#1364](https://github.com/openshift/cluster-image-registry-operator/pull/1364)
* [OCPBUGS-112349](https://issues.redhat.com/browse/OCPBUGS-112349): Improve GCS KMS encryption error handling and documentation [#1362](https://github.com/openshift/cluster-image-registry-operator/pull/1362)
* [OCPBUGS-96612](https://issues.redhat.com/browse/OCPBUGS-96612): Bump golang.org/x/net from v0.47.0 to v0.55.0 [#1355](https://github.com/openshift/cluster-image-registry-operator/pull/1355)
* [OCPBUGS-85342](https://issues.redhat.com/browse/OCPBUGS-85342): Fix stale config cache causing incorrect deployment [#1342](https://github.com/openshift/cluster-image-registry-operator/pull/1342)
* [Full changelog](https://github.com/openshift/cluster-image-registry-operator/compare/ad611da1488fdf6604a66d0ac9da5ccf39d79d65...c331da28c42721724ed5229c972c956cd1d9502c)
### [cluster-ingress-operator](https://github.com/openshift/cluster-ingress-operator/tree/656d475a0bc76b31b8e387abd9e19458531cc4a3)
* [OCPBUGS-105168](https://issues.redhat.com/browse/OCPBUGS-105168): Bump openshift/api which adds HAProxy version API [#1545](https://github.com/openshift/cluster-ingress-operator/pull/1545)
* [OCPBUGS-98728](https://issues.redhat.com/browse/OCPBUGS-98728): Add missing include annotations to IBM Cloud and PowerVS ingress CredentialsRequests [#1506](https://github.com/openshift/cluster-ingress-operator/pull/1506)
* [OCPBUGS-97563](https://issues.redhat.com/browse/OCPBUGS-97563): Detect orphaned OSSM subscription after noOLM migration [#1495](https://github.com/openshift/cluster-ingress-operator/pull/1495)
* [OCPBUGS-91967](https://issues.redhat.com/browse/OCPBUGS-91967): Guard OLM watches with capability check in gatewayclass controller [#1481](https://github.com/openshift/cluster-ingress-operator/pull/1481)
* [OCPBUGS-87164](https://issues.redhat.com/browse/OCPBUGS-87164): Add referencegrants and backendtlspolicies to Gateway API RBAC [#1461](https://github.com/openshift/cluster-ingress-operator/pull/1461)
* [OCPBUGS-87167](https://issues.redhat.com/browse/OCPBUGS-87167): Add configuration override for X-SSL strip [#1468](https://github.com/openshift/cluster-ingress-operator/pull/1468)
* [OCPBUGS-86074](https://issues.redhat.com/browse/OCPBUGS-86074): Update grpc-go and x/net [#1449](https://github.com/openshift/cluster-ingress-operator/pull/1449)
* [OCPBUGS-85024](https://issues.redhat.com/browse/OCPBUGS-85024): TestUnsupportedConfigOverride: Ignore featuregate and defaults [#1432](https://github.com/openshift/cluster-ingress-operator/pull/1432)
* [Full changelog](https://github.com/openshift/cluster-ingress-operator/compare/e2858baee56d58f7b98aea897b18ed1114c280fd...656d475a0bc76b31b8e387abd9e19458531cc4a3)
### [cluster-kube-apiserver-operator](https://github.com/openshift/cluster-kube-apiserver-operator/tree/a2ba9c6a2d1ed76ea98a40885cf9a824eb9b9071)
* [OCPBUGS-120318](https://issues.redhat.com/browse/OCPBUGS-120318): [release-4.22] Backport 10-minute degraded inertia [#2294](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2294)
* [OCPBUGS-87844](https://issues.redhat.com/browse/OCPBUGS-87844): Fix kube-apiserver-to-kubelet-signer refresh interval [#2187](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2187)
* [OCPBUGS-85269](https://issues.redhat.com/browse/OCPBUGS-85269): fsync static pod cert and manifest writes for crash durability [#2143](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2143)
* [OCPBUGS-85260](https://issues.redhat.com/browse/OCPBUGS-85260): operator should not override authentication config serviceAccountIssuer with the default one during the operator initialization [#2142](https://github.com/openshift/cluster-kube-apiserver-operator/pull/2142)
* [Full changelog](https://github.com/openshift/cluster-kube-apiserver-operator/compare/d03062f8d205f1923362c008c86f9bcdd35f931c...a2ba9c6a2d1ed76ea98a40885cf9a824eb9b9071)
### [cluster-kube-controller-manager-operator](https://github.com/openshift/cluster-kube-controller-manager-operator/tree/c5c678b3e04a64214ae62f5ad6d873c8899ac363)
* [OCPBUGS-116225](https://issues.redhat.com/browse/OCPBUGS-116225): [release-4.22] Add 10-minute degraded inertia [#966](https://github.com/openshift/cluster-kube-controller-manager-operator/pull/966)
* [Full changelog](https://github.com/openshift/cluster-kube-controller-manager-operator/compare/95150ed5dbf11370b4a06e6959c77efa13768561...c5c678b3e04a64214ae62f5ad6d873c8899ac363)
### [cluster-kube-scheduler-operator](https://github.com/openshift/cluster-kube-scheduler-operator/tree/da4bf66b8f6d057ab1562b6640261d8fe9ded28f)
* [OCPBUGS-120133](https://issues.redhat.com/browse/OCPBUGS-120133): [release-4.22] Backport 10-minute degraded inertia [#664](https://github.com/openshift/cluster-kube-scheduler-operator/pull/664)
* [Full changelog](https://github.com/openshift/cluster-kube-scheduler-operator/compare/51ea59abd057d0cef56b29b8a74efc28411d5427...da4bf66b8f6d057ab1562b6640261d8fe9ded28f)
### [cluster-kube-storage-version-migrator-operator](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/tree/9afe66875bff8b5926f2bf6dec4eade1e4a09bab)
* [OCPBUGS-85570](https://issues.redhat.com/browse/OCPBUGS-85570): add PodDisruptionBudget for migrator deployment [#174](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/174)
* [OCPBUGS-84312](https://issues.redhat.com/browse/OCPBUGS-84312): schedule migrator pods on control-plane nodes [#162](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/pull/162)
* [Full changelog](https://github.com/openshift/cluster-kube-storage-version-migrator-operator/compare/e4e983adfde0ccf999efca551fc07b9e28562a10...9afe66875bff8b5926f2bf6dec4eade1e4a09bab)
### [cluster-machine-approver](https://github.com/openshift/cluster-machine-approver/tree/fa7bb0222038fdeb51ddeae57b4c193d1b44a0fa)
* [OCPBUGS-86773](https://issues.redhat.com/browse/OCPBUGS-86773): fix: use feature-gate annotation for CAPI manifests [#305](https://github.com/openshift/cluster-machine-approver/pull/305)
* [Full changelog](https://github.com/openshift/cluster-machine-approver/compare/a9edd695aca56fb58e739b774670a01428360dd8...fa7bb0222038fdeb51ddeae57b4c193d1b44a0fa)
### [cluster-monitoring-operator](https://github.com/openshift/cluster-monitoring-operator/tree/0354fe76edacf5fbb2a01c9e56d1e467d8621c79)
* [OCPBUGS-105469](https://issues.redhat.com/browse/OCPBUGS-105469): enable read-only rootfs for all containers [#3047](https://github.com/openshift/cluster-monitoring-operator/pull/3047)
* [OCPBUGS-112572](https://issues.redhat.com/browse/OCPBUGS-112572): [release-4.22] Makefile: version-stamp golangci-lint binary to prevent stale linter [#3064](https://github.com/openshift/cluster-monitoring-operator/pull/3064)
* [OCPBUGS-105304](https://issues.redhat.com/browse/OCPBUGS-105304): [release-4.22] wrap library-go resourceCache with mutex for thread safety [#3045](https://github.com/openshift/cluster-monitoring-operator/pull/3045)
* [OCPBUGS-104852](https://issues.redhat.com/browse/OCPBUGS-104852): [release-4.22] e2e: scale down CVO and MCO to prevent node reboots during proxy config watch test [#3052](https://github.com/openshift/cluster-monitoring-operator/pull/3052)
* [OCPBUGS-104536](https://issues.redhat.com/browse/OCPBUGS-104536): Backport e2e stabilization 4.22 [#3026](https://github.com/openshift/cluster-monitoring-operator/pull/3026)
* [OCPBUGS-100367](https://issues.redhat.com/browse/OCPBUGS-100367): [release-4.22] fix: watch cluster wide proxy changes and apply changes accordingly [#3020](https://github.com/openshift/cluster-monitoring-operator/pull/3020)
* [OCPBUGS-99748](https://issues.redhat.com/browse/OCPBUGS-99748): fall back to kube-system/global-pull-secret for telemeter-client token [#3001](https://github.com/openshift/cluster-monitoring-operator/pull/3001)
* [OCPBUGS-93722](https://issues.redhat.com/browse/OCPBUGS-93722): [release-4.22] Prometheus: Information disclosure of Azure OAuth client secret via config API [#2976](https://github.com/openshift/cluster-monitoring-operator/pull/2976)
* [OCPBUGS-92193](https://issues.redhat.com/browse/OCPBUGS-92193): set Prometheus shards value explicitly [#2974](https://github.com/openshift/cluster-monitoring-operator/pull/2974)
* [OCPBUGS-88321](https://issues.redhat.com/browse/OCPBUGS-88321): fix(TestDocExamples) flake: use internal registry for test pods [#2965](https://github.com/openshift/cluster-monitoring-operator/pull/2965)
* [OCPBUGS-86807](https://issues.redhat.com/browse/OCPBUGS-86807): jsonnet: exclude ReplicationController from catch-all … [#2940](https://github.com/openshift/cluster-monitoring-operator/pull/2940)
* [OCPBUGS-86990](https://issues.redhat.com/browse/OCPBUGS-86990): increase lookup interval [#2945](https://github.com/openshift/cluster-monitoring-operator/pull/2945)
* [OCPBUGS-86034](https://issues.redhat.com/browse/OCPBUGS-86034): fix: use numeric ports in NetworkPolicies and add enforcement e2e test [#2929](https://github.com/openshift/cluster-monitoring-operator/pull/2929)
* [Full changelog](https://github.com/openshift/cluster-monitoring-operator/compare/f6a7969c5c070e4deb6136c3561af60ab44780e1...0354fe76edacf5fbb2a01c9e56d1e467d8621c79)
### [cluster-network-operator](https://github.com/openshift/cluster-network-operator/tree/fe422f7670aa55e037c2180f1b7f2dc4e3d34cde)
* [OCPBUGS-105556](https://issues.redhat.com/browse/OCPBUGS-105556): [4.22] frr-k8s: use Recreate strategy for statuscleaner deployment [#3130](https://github.com/openshift/cluster-network-operator/pull/3130)
* [OCPBUGS-105512](https://issues.redhat.com/browse/OCPBUGS-105512): Remove version-specific CNI binary copy logic [#3114](https://github.com/openshift/cluster-network-operator/pull/3114)
* [OCPBUGS-99744](https://issues.redhat.com/browse/OCPBUGS-99744): Bump frr-k8s MAX_FDS from 1024 to 65536 [#3090](https://github.com/openshift/cluster-network-operator/pull/3090)
* [OCPBUGS-97939](https://issues.redhat.com/browse/OCPBUGS-97939): bump containernetworking/cni v0.8.0 -> v1.3.0 [#3044](https://github.com/openshift/cluster-network-operator/pull/3044)
* [OCPBUGS-86033](https://issues.redhat.com/browse/OCPBUGS-86033): Revert "[release-4.22] OCPBUGS-90721: NVIDIA-596: Enable dpu healthcheck" [#3042](https://github.com/openshift/cluster-network-operator/pull/3042)
* [OCPBUGS-84739](https://issues.redhat.com/browse/OCPBUGS-84739): Use dedicated service accounts for multus pods [#2985](https://github.com/openshift/cluster-network-operator/pull/2985)
* [OCPBUGS-90721](https://issues.redhat.com/browse/OCPBUGS-90721): NVIDIA-596: Enable dpu healthcheck [#3009](https://github.com/openshift/cluster-network-operator/pull/3009)
* [OCPBUGS-89244](https://issues.redhat.com/browse/OCPBUGS-89244): NVIDIA-554: DPU-host mode: use ConfigMap for OVN feature enablement instead of per-node script gating [#3029](https://github.com/openshift/cluster-network-operator/pull/3029)
* [OCPBUGS-88307](https://issues.redhat.com/browse/OCPBUGS-88307): Remove --enable-interconnect flag from OVN-K manifests [#3028](https://github.com/openshift/cluster-network-operator/pull/3028)
* [Full changelog](https://github.com/openshift/cluster-network-operator/compare/e20b9cb9a0b3bc293e622ef1caf70a813710ffa8...fe422f7670aa55e037c2180f1b7f2dc4e3d34cde)
### [cluster-node-tuning-operator](https://github.com/openshift/cluster-node-tuning-operator/tree/3cd3ee48a5e99051d4392af47db09e976b180992)
* [OCPBUGS-113579](https://issues.redhat.com/browse/OCPBUGS-113579): Update PPC help description [#1613](https://github.com/openshift/cluster-node-tuning-operator/pull/1613)
* [OCPBUGS-112554](https://issues.redhat.com/browse/OCPBUGS-112554): Use Add() instead of AddRateLimited() for routine Profile enqueues [#1601](https://github.com/openshift/cluster-node-tuning-operator/pull/1601)
* [OCPBUGS-104615](https://issues.redhat.com/browse/OCPBUGS-104615): E2E: LLC: Restore uncore cache annotation to true [#1577](https://github.com/openshift/cluster-node-tuning-operator/pull/1577)
* [OCPBUGS-105873](https://issues.redhat.com/browse/OCPBUGS-105873): BUG-FIX Latency Test [#1583](https://github.com/openshift/cluster-node-tuning-operator/pull/1583)
* [OCPBUGS-105535](https://issues.redhat.com/browse/OCPBUGS-105535): Add missing annotations to NetworkPolicy manifests [#1580](https://github.com/openshift/cluster-node-tuning-operator/pull/1580)
* [OCPBUGS-99265](https://issues.redhat.com/browse/OCPBUGS-99265): E2E: LLC: Pass fresh ctx variable to DeferCleanup functions [#1567](https://github.com/openshift/cluster-node-tuning-operator/pull/1567)
* [OCPBUGS-92011](https://issues.redhat.com/browse/OCPBUGS-92011): e2e: fix: clear hugepages before switching kernelPageSize to 4k [#1554](https://github.com/openshift/cluster-node-tuning-operator/pull/1554)
* [OCPBUGS-99290](https://issues.redhat.com/browse/OCPBUGS-99290): e2e: fix broken checks and rework netqueue tests to avoid ARM ethtool blackout flakes [#1568](https://github.com/openshift/cluster-node-tuning-operator/pull/1568)
* [OCPBUGS-98400](https://issues.redhat.com/browse/OCPBUGS-98400): E2E: Add functional test cases checking GOMAXPROCS [#1561](https://github.com/openshift/cluster-node-tuning-operator/pull/1561)
* [OCPBUGS-98062](https://issues.redhat.com/browse/OCPBUGS-98062): E2E: Fix tuned active profile check for wrapped performance profiles [#1559](https://github.com/openshift/cluster-node-tuning-operator/pull/1559)
* [OCPBUGS-87153](https://issues.redhat.com/browse/OCPBUGS-87153): E2E: Refactor OVS affinity tests into shared helpers and add new workload-partitioning and control-plane reboot test cases. [#1537](https://github.com/openshift/cluster-node-tuning-operator/pull/1537)
* [OCPBUGS-93924](https://issues.redhat.com/browse/OCPBUGS-93924): Let cri-o manage the GOMAXPROC for burstable pods [#1555](https://github.com/openshift/cluster-node-tuning-operator/pull/1555)
* [OCPBUGS-86071](https://issues.redhat.com/browse/OCPBUGS-86071): perf: latency: compute memory resources dynamically [#1520](https://github.com/openshift/cluster-node-tuning-operator/pull/1520)
* [OCPBUGS-87891](https://issues.redhat.com/browse/OCPBUGS-87891): Enable timer migrations for all use-cases [#1542](https://github.com/openshift/cluster-node-tuning-operator/pull/1542)
* [OCPBUGS-87158](https://issues.redhat.com/browse/OCPBUGS-87158): e2e: Remove unnecessary len(numa) < 2 skip gates [#1538](https://github.com/openshift/cluster-node-tuning-operator/pull/1538)
* [OCPBUGS-84431](https://issues.redhat.com/browse/OCPBUGS-84431): Bump github.com/moby/spdystream from v0.5.0 to v0.5.1 [#1529](https://github.com/openshift/cluster-node-tuning-operator/pull/1529)
* [OCPBUGS-86247](https://issues.redhat.com/browse/OCPBUGS-86247): Revert stalld backend to sched_debug [#1523](https://github.com/openshift/cluster-node-tuning-operator/pull/1523)
* [OCPBUGS-86024](https://issues.redhat.com/browse/OCPBUGS-86024): Requeue PerformanceStatus update when status write fails [#1518](https://github.com/openshift/cluster-node-tuning-operator/pull/1518)
* [OCPBUGS-85020](https://issues.redhat.com/browse/OCPBUGS-85020): e2e: Add irqbalance StartLimitBurst >= 100 config test [#1506](https://github.com/openshift/cluster-node-tuning-operator/pull/1506)
* [Full changelog](https://github.com/openshift/cluster-node-tuning-operator/compare/3d98f7ee7fe0651d182b8a780956512eb407a963...3cd3ee48a5e99051d4392af47db09e976b180992)
### [cluster-olm-operator](https://github.com/openshift/cluster-olm-operator/tree/f66065f7ae39fefe3058d72aa100d41d4327a407)
* [OCPBUGS-94187](https://issues.redhat.com/browse/OCPBUGS-94187): Scale to replicas=2 and enable PDB on HighlyAvailable topology [release-4.22] [#215](https://github.com/openshift/cluster-olm-operator/pull/215)
* [Full changelog](https://github.com/openshift/cluster-olm-operator/compare/d131450b2645623089b26353a309015c95c8871c...f66065f7ae39fefe3058d72aa100d41d4327a407)
### [cluster-openshift-apiserver-operator](https://github.com/openshift/cluster-openshift-apiserver-operator/tree/8417fa98338c2adab73386c63c6d84af14ef99e4)
* [OCPBUGS-100168](https://issues.redhat.com/browse/OCPBUGS-100168): Allow Prometheus to scrape check-endpoints metrics on port 17698 [#743](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/743)
* [OCPBUGS-105443](https://issues.redhat.com/browse/OCPBUGS-105443): Add HostToContainer mountPropagation to node-pullsecrets volume mount [#748](https://github.com/openshift/cluster-openshift-apiserver-operator/pull/748)
* [Full changelog](https://github.com/openshift/cluster-openshift-apiserver-operator/compare/1924cf6f12c632d56f1d41341f08ff9ff6eae7d6...8417fa98338c2adab73386c63c6d84af14ef99e4)
### [cluster-openshift-controller-manager-operator](https://github.com/openshift/cluster-openshift-controller-manager-operator/tree/2d2699e4f3fabc80e402f4c090c8cf80c4517977)
* [OCPBUGS-86054](https://issues.redhat.com/browse/OCPBUGS-86054): e2e network policy tests [#436](https://github.com/openshift/cluster-openshift-controller-manager-operator/pull/436)
* [Full changelog](https://github.com/openshift/cluster-openshift-controller-manager-operator/compare/e1c3674198c6c1274fd3fd3c3108eb4cade4eb0a...2d2699e4f3fabc80e402f4c090c8cf80c4517977)
### [cluster-policy-controller](https://github.com/openshift/cluster-policy-controller/tree/2e306e143051492a84c5e47a7b3126e096fdf76a)
* [OCPBUGS-98222](https://issues.redhat.com/browse/OCPBUGS-98222): add serviceAccountToken volume type to psalabelsyncer [#192](https://github.com/openshift/cluster-policy-controller/pull/192)
* [Full changelog](https://github.com/openshift/cluster-policy-controller/compare/44985a1306411101c84dd5081598fc928b432321...2e306e143051492a84c5e47a7b3126e096fdf76a)
### [cluster-samples-operator](https://github.com/openshift/cluster-samples-operator/tree/191a6aec444bfdbe5d70f7a23a20ee2fd25b7080)
* [OKD-379](https://issues.redhat.com/browse/OKD-379): Fix missing namespace in database template image triggers [#701](https://github.com/openshift/cluster-samples-operator/pull/701)
* [Full changelog](https://github.com/openshift/cluster-samples-operator/compare/317b21a930d074951c27c45c77c02ea211c43f14...191a6aec444bfdbe5d70f7a23a20ee2fd25b7080)
### [cluster-storage-operator](https://github.com/openshift/cluster-storage-operator/tree/8f4ce04189e9c5496548ed53e33943aba8756279)
* [OCPBUGS-112334](https://issues.redhat.com/browse/OCPBUGS-112334): Pass management cluster proxy env vars to CSI driver operator deployments [#740](https://github.com/openshift/cluster-storage-operator/pull/740)
* [OCPBUGS-96622](https://issues.redhat.com/browse/OCPBUGS-96622): Bump golang.org/x/net to v0.55.0 [#722](https://github.com/openshift/cluster-storage-operator/pull/722)
* [Full changelog](https://github.com/openshift/cluster-storage-operator/compare/8dfdf2ef3310358f3559a5481df43b98b2294791...8f4ce04189e9c5496548ed53e33943aba8756279)
### [cluster-version-operator](https://github.com/openshift/cluster-version-operator/tree/6ac86dc99c02366314381b720ab1d4a38d38f1c2)
* [OCPBUGS-104545](https://issues.redhat.com/browse/OCPBUGS-104545): pkg/cvo/egress: Disable Proxy respect on HyperShift [#1438](https://github.com/openshift/cluster-version-operator/pull/1438)
* [OCPBUGS-98572](https://issues.redhat.com/browse/OCPBUGS-98572): Tolerate unknown template fields during payload loading [#1421](https://github.com/openshift/cluster-version-operator/pull/1421)
* [OCPBUGS-77681](https://issues.redhat.com/browse/OCPBUGS-77681): Updating cluster-version-operator-container image to be consistent with ART for 4.22 [#1331](https://github.com/openshift/cluster-version-operator/pull/1331)
* [Full changelog](https://github.com/openshift/cluster-version-operator/compare/e9c1c39e21ec353ff5993d386c42bc1b15063dbf...6ac86dc99c02366314381b720ab1d4a38d38f1c2)
### [console](https://github.com/openshift/console/tree/82fd3852d347de8f31c78b3f0c9266d1e0c453a2)
* [OCPBUGS-115003](https://issues.redhat.com/browse/OCPBUGS-115003): Validate chart URL in /api/helm/verify to prevent SSRF [#17118](https://github.com/openshift/console/pull/17118)
* [OCPBUGS-114725](https://issues.redhat.com/browse/OCPBUGS-114725): display operators in catalog when Tech Preview enabled [#17114](https://github.com/openshift/console/pull/17114)
* [OCPBUGS-111417](https://issues.redhat.com/browse/OCPBUGS-111417): make cloud provider fields optional during operator install [#17014](https://github.com/openshift/console/pull/17014)
* [OCPBUGS-109521](https://issues.redhat.com/browse/OCPBUGS-109521): Remove unscoped CSV watch from ClusterNotUpgradeableAlert [#17013](https://github.com/openshift/console/pull/17013)
* [OCPBUGS-100519](https://issues.redhat.com/browse/OCPBUGS-100519), [OCPBUGS-101795](https://issues.redhat.com/browse/OCPBUGS-101795): Fix CVE-2026-69153 and CVE-2026-45623 - Bump postcss [#17054](https://github.com/openshift/console/pull/17054)
* [OCPBUGS-112271](https://issues.redhat.com/browse/OCPBUGS-112271): Fix flaky TestAsyncCache backend test [#17045](https://github.com/openshift/console/pull/17045)
* [OCPBUGS-105478](https://issues.redhat.com/browse/OCPBUGS-105478): [release-4.22] OCPBUGS-83799: Fix Workloads sidebar ordering when DeploymentConfig is unavailable [#16928](https://github.com/openshift/console/pull/16928)
* Fix OCPBUGS-99414: CVE-2026-59877 [#16834](https://github.com/openshift/console/pull/16834)
* [OCPBUGS-95402](https://issues.redhat.com/browse/OCPBUGS-95402): Fix orphaned shell processes in pod terminal on WebSocket disconnect [#16694](https://github.com/openshift/console/pull/16694)
* Fix for OCPBUGS-101812: CVE-2026-69152 [#16930](https://github.com/openshift/console/pull/16930)
* Fix for OCPBUGS-105894: CVE-2026-73086 [#16965](https://github.com/openshift/console/pull/16965)
* [OCPBUGS-87832](https://issues.redhat.com/browse/OCPBUGS-87832): Use stable username hash for user-settings ConfigMap names [#16565](https://github.com/openshift/console/pull/16565)
* [OCPBUGS-105611](https://issues.redhat.com/browse/OCPBUGS-105611): [release-4.22] Fix leading whitespace in Quick Start execute code snippets [#16951](https://github.com/openshift/console/pull/16951)
* [OCPBUGS-89705](https://issues.redhat.com/browse/OCPBUGS-89705): Fix CVE-2026-12143 form-data CRLF injection [#16644](https://github.com/openshift/console/pull/16644)
* [OCPBUGS-100059](https://issues.redhat.com/browse/OCPBUGS-100059): quickstart page i18n misses (Fix Quick Starts i18n bundle lookup for zh-CN) [#16869](https://github.com/openshift/console/pull/16869)
* [OCPBUGS-100317](https://issues.redhat.com/browse/OCPBUGS-100317): Fix pod terminal not rendering until resize [#16892](https://github.com/openshift/console/pull/16892)
* [OCPBUGS-100307](https://issues.redhat.com/browse/OCPBUGS-100307): Re-enable Knative Cypress e2e tests [#16889](https://github.com/openshift/console/pull/16889)
* Fix OCPBUGS-98791: CVE-2026-48801 [#16852](https://github.com/openshift/console/pull/16852)
* [OCPBUGS-99545](https://issues.redhat.com/browse/OCPBUGS-99545): '0 B' is shown on details page when create pvc with 'EiB' unit [#16807](https://github.com/openshift/console/pull/16807)
* [OCPBUGS-99548](https://issues.redhat.com/browse/OCPBUGS-99548): Incorrect translations for 'CatalogSources' and 'OperatorGroups' in l… [#16809](https://github.com/openshift/console/pull/16809)
* [OCPBUGS-99259](https://issues.redhat.com/browse/OCPBUGS-99259): Disable Knative e2e Cypress tests in CI [#16784](https://github.com/openshift/console/pull/16784)
* [OCPBUGS-98437](https://issues.redhat.com/browse/OCPBUGS-98437): CVE-2026-59869 bump js-yaml [#16768](https://github.com/openshift/console/pull/16768)
* [OCPBUGS-97600](https://issues.redhat.com/browse/OCPBUGS-97600): Fix devfile sample import by adding fallback for parent resolution failures [#16706](https://github.com/openshift/console/pull/16706)
* [OCPBUGS-88028](https://issues.redhat.com/browse/OCPBUGS-88028): Bump follow-redirects from 1.15.3 to 1.16.0 to fix CVE-2026-40895 [#16665](https://github.com/openshift/console/pull/16665)
* [OCPBUGS-95580](https://issues.redhat.com/browse/OCPBUGS-95580): Fix unnecessary error on Node Terminal tab [#16696](https://github.com/openshift/console/pull/16696)
* [OCPBUGS-88748](https://issues.redhat.com/browse/OCPBUGS-88748): [release-4.22] webpack-dev-server: Information disclosure and denial of service via improper proxy configuration [#16656](https://github.com/openshift/console/pull/16656)
* [OCPBUGS-89337](https://issues.redhat.com/browse/OCPBUGS-89337): Use fixed artifacts directory to prevent stale temp dir accumulation [#16638](https://github.com/openshift/console/pull/16638)
* [OCPBUGS-90636](https://issues.redhat.com/browse/OCPBUGS-90636): Fix RoleBindings tab error for non-cluster-admin users [#16662](https://github.com/openshift/console/pull/16662)
* [OCPBUGS-90495](https://issues.redhat.com/browse/OCPBUGS-90495): Projects cannot be filtered by display name [#16652](https://github.com/openshift/console/pull/16652)
* [OCPBUGS-90110](https://issues.redhat.com/browse/OCPBUGS-90110): Fix ColumnManagementModal not showing NamespaceColumnHelpText [#16643](https://github.com/openshift/console/pull/16643)
* Fix for OCPBUGS-84470: CVE-2026-4800 [#16573](https://github.com/openshift/console/pull/16573)
* [OCPBUGS-87933](https://issues.redhat.com/browse/OCPBUGS-87933), [OCPBUGS-87985](https://issues.redhat.com/browse/OCPBUGS-87985): Bump protobufjs and shell-quote [#16619](https://github.com/openshift/console/pull/16619)
* [OCPBUGS-87997](https://issues.redhat.com/browse/OCPBUGS-87997): Bump fast-uri to 3.1.2 to fix CVE-2026-6322 [#16605](https://github.com/openshift/console/pull/16605)
* [OCPBUGS-88304](https://issues.redhat.com/browse/OCPBUGS-88304): Allow VolumeSnapshot restore when parent PVC is deleted [#16592](https://github.com/openshift/console/pull/16592)
* [OCPBUGS-87096](https://issues.redhat.com/browse/OCPBUGS-87096): fixing severity not showing number of issues [#16575](https://github.com/openshift/console/pull/16575)
* [OCPBUGS-86580](https://issues.redhat.com/browse/OCPBUGS-86580): Fix macOS Option key in pod terminal [#16504](https://github.com/openshift/console/pull/16504)
* [OCPBUGS-77804](https://issues.redhat.com/browse/OCPBUGS-77804): Update Console 4.22 plugin SDK CHANGELOG [#16521](https://github.com/openshift/console/pull/16521)
* [OCPBUGS-86700](https://issues.redhat.com/browse/OCPBUGS-86700): Fix and re-enable operator e2e tests disabled for createRoot [#16518](https://github.com/openshift/console/pull/16518)
* [OCPBUGS-77804](https://issues.redhat.com/browse/OCPBUGS-77804): prep for 4.22 GA SDK publish [#16508](https://github.com/openshift/console/pull/16508)
* [OCPBUGS-86410](https://issues.redhat.com/browse/OCPBUGS-86410): Fix Shipwright detail pages crashing with React error #310 [#16485](https://github.com/openshift/console/pull/16485)
* [OCPBUGS-86239](https://issues.redhat.com/browse/OCPBUGS-86239): Adapt dashboard Prometheus polling interval based on query response time [#16469](https://github.com/openshift/console/pull/16469)
* [OCPBUGS-84963](https://issues.redhat.com/browse/OCPBUGS-84963): Remove DataViewToolbar wrapper from bottom pagination [#16483](https://github.com/openshift/console/pull/16483)
* [OCPBUGS-86227](https://issues.redhat.com/browse/OCPBUGS-86227): Show empty state instead of 403 error for users without projects [#16467](https://github.com/openshift/console/pull/16467)
* [OCPBUGS-86222](https://issues.redhat.com/browse/OCPBUGS-86222): Use ETag conditional requests for OpenAPI v2 fetching [#16466](https://github.com/openshift/console/pull/16466)
* [OCPBUGS-86228](https://issues.redhat.com/browse/OCPBUGS-86228): Re-enable add-flow-ci.feature e2e tests disabled for createRoot adoption [#16468](https://github.com/openshift/console/pull/16468)
* [OCPBUGS-86064](https://issues.redhat.com/browse/OCPBUGS-86064): Enable Topology e2e tests [#16458](https://github.com/openshift/console/pull/16458)
* [OCPBUGS-83940](https://issues.redhat.com/browse/OCPBUGS-83940): bump gRPC-Go to v1.79.3 [#16443](https://github.com/openshift/console/pull/16443)
* [OCPBUGS-83416](https://issues.redhat.com/browse/OCPBUGS-83416): [release-4.22] CVE-2026-26996 Bump minimatch library [#16278](https://github.com/openshift/console/pull/16278)
* [OCPBUGS-85505](https://issues.redhat.com/browse/OCPBUGS-85505): Add Suspense boundary to LazyRoutePage for plugin routes [#16438](https://github.com/openshift/console/pull/16438)
* [OCPBUGS-85494](https://issues.redhat.com/browse/OCPBUGS-85494): Prevent binary secret data corruption when editing [#16435](https://github.com/openshift/console/pull/16435)
* NO-JIRA: enable multi-architecture yarn builds [#16415](https://github.com/openshift/console/pull/16415)
* [OCPBUGS-85196](https://issues.redhat.com/browse/OCPBUGS-85196): Remove `@console` imports from SDK dist [#16407](https://github.com/openshift/console/pull/16407)
* [OCPBUGS-84843](https://issues.redhat.com/browse/OCPBUGS-84843): i18n upload/download routine task - version 4.22 [#16382](https://github.com/openshift/console/pull/16382)
* [OCPBUGS-85114](https://issues.redhat.com/browse/OCPBUGS-85114): Fix SDK publish workflow for Yarn Berry [#16403](https://github.com/openshift/console/pull/16403)
* And 3 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/console/compare/f6de0e73b88eeed1f0cbc73d751f5e629d817813...82fd3852d347de8f31c78b3f0c9266d1e0c453a2)
### [console-operator](https://github.com/openshift/console-operator/tree/35170581874b91514a9459766758fa0aa5da22f6)
* [OCPBUGS-81121](https://issues.redhat.com/browse/OCPBUGS-81121): clone bump documentation base url [#1154](https://github.com/openshift/console-operator/pull/1154)
* [OCPBUGS-100387](https://issues.redhat.com/browse/OCPBUGS-100387): Sort plugin list to make them deterministic [#1165](https://github.com/openshift/console-operator/pull/1165)
* [OCPBUGS-97828](https://issues.redhat.com/browse/OCPBUGS-97828), [OCPBUGS-97829](https://issues.redhat.com/browse/OCPBUGS-97829): Stabilize telemetry config to prevent continuous console pod rollouts [#1183](https://github.com/openshift/console-operator/pull/1183)
* [OCPBUGS-94186](https://issues.redhat.com/browse/OCPBUGS-94186): Add retry for transient API errors to prevent Degraded blips [#1181](https://github.com/openshift/console-operator/pull/1181)
* [OCPBUGS-94188](https://issues.redhat.com/browse/OCPBUGS-94188): use ObservedGeneration to determine Progressing status [#1180](https://github.com/openshift/console-operator/pull/1180)
* [OCPBUGS-92829](https://issues.redhat.com/browse/OCPBUGS-92829): Clean up old temp directories in downloads pod [#1177](https://github.com/openshift/console-operator/pull/1177)
* [OCPBUGS-86118](https://issues.redhat.com/browse/OCPBUGS-86118): Add unit and e2e test coverage for cert rotation redeployment [#1161](https://github.com/openshift/console-operator/pull/1161)
* [OCPBUGS-83941](https://issues.redhat.com/browse/OCPBUGS-83941): bump gRPC-Go package [#1157](https://github.com/openshift/console-operator/pull/1157)
* [NETOBSERV-2296](https://issues.redhat.com/browse/NETOBSERV-2296): add missing annotations on netobserv quickstart [#1097](https://github.com/openshift/console-operator/pull/1097)
* [OCPBUGS-85507](https://issues.redhat.com/browse/OCPBUGS-85507): feat: use 2 replicas for console on tnf [#1155](https://github.com/openshift/console-operator/pull/1155)
* [Full changelog](https://github.com/openshift/console-operator/compare/f0619391890c61e1a4ebdf5c1c0b247b30f81248...35170581874b91514a9459766758fa0aa5da22f6)
### [container-networking-plugins, containernetworking-plugins-microshift](https://github.com/openshift/containernetworking-plugins/tree/db552ad333e84b99ca279a9c01ca2d918ec00c99)
* [OCPBUGS-83942](https://issues.redhat.com/browse/OCPBUGS-83942): Bump grpc to 1.79.3 to address CVE-2026-33186 [#243](https://github.com/openshift/containernetworking-plugins/pull/243)
* [OCPBUGS-87165](https://issues.redhat.com/browse/OCPBUGS-87165): CI build root image tag sync with ART 4.22 [#240](https://github.com/openshift/containernetworking-plugins/pull/240)
* [Full changelog](https://github.com/openshift/containernetworking-plugins/compare/747ad66caa1109b2b490aebad01af42bd2d738f1...db552ad333e84b99ca279a9c01ca2d918ec00c99)
### [coredns](https://github.com/openshift/coredns/tree/9a71d9a6b788437e755b5ed3bfad78c63fa7c6f4)
* [OCPBUGS-86189](https://issues.redhat.com/browse/OCPBUGS-86189): [release-4.22] OCPBUGS-83943: Bump gRPC to v1.79.3 to resolve CVE-2026-33186 [#185](https://github.com/openshift/coredns/pull/185)
* [Full changelog](https://github.com/openshift/coredns/compare/0dded2d232dab43c107b1dab9d0d9fdfd8259622...9a71d9a6b788437e755b5ed3bfad78c63fa7c6f4)
### [csi-driver-manila, openstack-cinder-csi-driver, openstack-cloud-controller-manager](https://github.com/openshift/cloud-provider-openstack/tree/710a2aea744fd04546d11ac781fb874694e33ad8)
* [OCPBUGS-83552](https://issues.redhat.com/browse/OCPBUGS-83552): Bump google.golang.org/grpc to 1.79.3 [#395](https://github.com/openshift/cloud-provider-openstack/pull/395)
* UPSTREAM-SYNC: Sync release-4.22 with upstream release-1.35 [#381](https://github.com/openshift/cloud-provider-openstack/pull/381)
* [OCPBUGS-85241](https://issues.redhat.com/browse/OCPBUGS-85241): Updating ose-openstack-cloud-controller-manager-container image to be consistent with ART for 4.22 [#392](https://github.com/openshift/cloud-provider-openstack/pull/392)
* [OCPBUGS-85239](https://issues.redhat.com/browse/OCPBUGS-85239): Updating ose-openstack-cinder-csi-driver-container image to be consistent with ART for 4.22 [#390](https://github.com/openshift/cloud-provider-openstack/pull/390)
* [OCPBUGS-85240](https://issues.redhat.com/browse/OCPBUGS-85240): Updating csi-driver-manila-container image to be consistent with ART for 4.22 [#391](https://github.com/openshift/cloud-provider-openstack/pull/391)
* [Full changelog](https://github.com/openshift/cloud-provider-openstack/compare/fd31b5da11d75a7a80e7c4a6c7a56acf304e2661...710a2aea744fd04546d11ac781fb874694e33ad8)
### [csi-driver-nfs](https://github.com/openshift/csi-driver-nfs/tree/b69115537b79a5b3516e2a900f9095f4ebb3cbe5)
* [OCPBUGS-84434](https://issues.redhat.com/browse/OCPBUGS-84434): Bump github.com/moby/spdystream@v0.5.1 [#190](https://github.com/openshift/csi-driver-nfs/pull/190)
* [Full changelog](https://github.com/openshift/csi-driver-nfs/compare/5a8887df841e38a71c82d78922380c6027a2b486...b69115537b79a5b3516e2a900f9095f4ebb3cbe5)
### [csi-external-attacher](https://github.com/openshift/csi-external-attacher/tree/95a1979700f021e20879480b98b953bc382a0eaf)
* [OCPBUGS-83947](https://issues.redhat.com/browse/OCPBUGS-83947): Bump google.golang.org/grpc to v1.79.3 [#107](https://github.com/openshift/csi-external-attacher/pull/107)
* [Full changelog](https://github.com/openshift/csi-external-attacher/compare/98b1f4acf9c004687ef55e9f187703768933bb56...95a1979700f021e20879480b98b953bc382a0eaf)
### [csi-external-provisioner](https://github.com/openshift/csi-external-provisioner/tree/253b987d5233b1adb93b5ae2c63102c0d06c01cf)
* [OCPBUGS-96626](https://issues.redhat.com/browse/OCPBUGS-96626): Bump golang.org/x/net to v0.57.0 [#148](https://github.com/openshift/csi-external-provisioner/pull/148)
* [OCPBUGS-84435](https://issues.redhat.com/browse/OCPBUGS-84435): Bump github.com/moby/spdystream to v0.5.1 in 4.22 [#136](https://github.com/openshift/csi-external-provisioner/pull/136)
* [OCPBUGS-82033](https://issues.redhat.com/browse/OCPBUGS-82033): Bump google.golang.org/grpc to 1.79.3 [#133](https://github.com/openshift/csi-external-provisioner/pull/133)
* [Full changelog](https://github.com/openshift/csi-external-provisioner/compare/f90c06a3113696cdb757e4b7c9dcfeb0e9dddb81...253b987d5233b1adb93b5ae2c63102c0d06c01cf)
### [csi-external-resizer](https://github.com/openshift/csi-external-resizer/tree/20f7fbe41654ebe10d2d4f50ae423c9686ce1c25)
* [OCPBUGS-101944](https://issues.redhat.com/browse/OCPBUGS-101944): Bump golang.org/x/net to v0.53.0 [#209](https://github.com/openshift/csi-external-resizer/pull/209)
* [OCPBUGS-82031](https://issues.redhat.com/browse/OCPBUGS-82031): Bump google.golang.org/grpc to v1.79.3 [#199](https://github.com/openshift/csi-external-resizer/pull/199)
* [Full changelog](https://github.com/openshift/csi-external-resizer/compare/4e74a4aa52a2046d6b97a47dff7a60ddb73d0bbd...20f7fbe41654ebe10d2d4f50ae423c9686ce1c25)
### [csi-external-snapshot-metadata](https://github.com/openshift/csi-external-snapshot-metadata/tree/b48f04782c567b8759292085b7ad554dce013d8a)
* [OCPBUGS-83948](https://issues.redhat.com/browse/OCPBUGS-83948): Bump google.golang.org/grpc to v1.79.3 [#19](https://github.com/openshift/csi-external-snapshot-metadata/pull/19)
* [Full changelog](https://github.com/openshift/csi-external-snapshot-metadata/compare/7652318579a38838931a5be492cee3573c7c8ecf...b48f04782c567b8759292085b7ad554dce013d8a)
### [csi-external-snapshotter, csi-snapshot-controller](https://github.com/openshift/csi-external-snapshotter/tree/28f6e06357f2840c241b9cfe09d301516e681c87)
* [OCPBUGS-88723](https://issues.redhat.com/browse/OCPBUGS-88723): UPSTREAM: 1392: Fix VolumeSnapshotContent deletion [#222](https://github.com/openshift/csi-external-snapshotter/pull/222)
* [OCPBUGS-83949](https://issues.redhat.com/browse/OCPBUGS-83949), [OCPBUGS-83952](https://issues.redhat.com/browse/OCPBUGS-83952): Bump google.golang.org/grpc to v1.79.3 [#216](https://github.com/openshift/csi-external-snapshotter/pull/216)
* [Full changelog](https://github.com/openshift/csi-external-snapshotter/compare/d1bc3ffaa9759c13a06c2ec61c541342e71bd109...28f6e06357f2840c241b9cfe09d301516e681c87)
### [csi-node-driver-registrar](https://github.com/openshift/csi-node-driver-registrar/tree/bb6a6378d2af235b3b253cb422d406bd3d7e30b1)
* [OCPBUGS-84436](https://issues.redhat.com/browse/OCPBUGS-84436): Bump github.com/moby/spdystream to v0.5.1 [#105](https://github.com/openshift/csi-node-driver-registrar/pull/105)
* [Full changelog](https://github.com/openshift/csi-node-driver-registrar/compare/cf174b30fad107d354afb0f0b09030a7c97fd296...bb6a6378d2af235b3b253cb422d406bd3d7e30b1)
### [docker-builder](https://github.com/openshift/builder/tree/3dead2dcc98d83fb97f42d46b05c5253752e7910)
* [OCPBUGS-86910](https://issues.redhat.com/browse/OCPBUGS-86910): Updating openshift-enterprise-builder-container image to be consistent with ART for 4.22 [#538](https://github.com/openshift/builder/pull/538)
* [Full changelog](https://github.com/openshift/builder/compare/fcd4ce2d96613a27bd1ab7f53ff47225976c4ba9...3dead2dcc98d83fb97f42d46b05c5253752e7910)
### [docker-registry](https://github.com/openshift/image-registry/tree/179d7925210490c5de4846540e01c33601cd8cd1)
* [release 4.22] OCPBUGS-114405: GCP: Support Alternate Universe Domain [#476](https://github.com/openshift/image-registry/pull/476)
* [Full changelog](https://github.com/openshift/image-registry/compare/9eae44fcf44142a705031fa16a613c450dbe685a...179d7925210490c5de4846540e01c33601cd8cd1)
### [egress-router-cni](https://github.com/openshift/egress-router-cni/tree/af8f30136791fa3f3dc9e5638bdb062db133bbbd)
* [OCPBUGS-97939](https://issues.redhat.com/browse/OCPBUGS-97939): bump containernetworking/cni to v1.3.0 [#103](https://github.com/openshift/egress-router-cni/pull/103)
* [Full changelog](https://github.com/openshift/egress-router-cni/compare/5e0f8d1b545899fda27c5e1cc8707d33cba1b534...af8f30136791fa3f3dc9e5638bdb062db133bbbd)
### [etcd](https://github.com/openshift/etcd/tree/6bd01267dc858aca6ff21632f95e98dc62ba33e7)
* [OCPBUGS-82497](https://issues.redhat.com/browse/OCPBUGS-82497): Rebase v3.6.13 for openshift-4.22 [#393](https://github.com/openshift/etcd/pull/393)
* [Full changelog](https://github.com/openshift/etcd/compare/d8d67b8ce849f816d6d23c904098336632e2348f...6bd01267dc858aca6ff21632f95e98dc62ba33e7)
### [gcp-cloud-controller-manager](https://github.com/openshift/cloud-provider-gcp/tree/2e28a1aa036a64a1f315170b70b912f1f8ab9f92)
* [OCPBUGS-99228](https://issues.redhat.com/browse/OCPBUGS-99228): Fix node.kubernetes.io/exclude-from-external-load-balancers on masters [#130](https://github.com/openshift/cloud-provider-gcp/pull/130)
* [OCPBUGS-83965](https://issues.redhat.com/browse/OCPBUGS-83965), [OCPBUGS-84447](https://issues.redhat.com/browse/OCPBUGS-84447): Update grpc and spdy dependencies [#117](https://github.com/openshift/cloud-provider-gcp/pull/117)
* [Full changelog](https://github.com/openshift/cloud-provider-gcp/compare/4d9707e182c4f8734d83ebf21e3ffcc4c38d04e9...2e28a1aa036a64a1f315170b70b912f1f8ab9f92)
### [gcp-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-gcp/tree/e7674ede9ce8d021a878a6d5e81942875387e5eb)
* UPSTREAM-SYNC: Merge https://github.com/kubernetes-sigs/cluster-api-provider-gcp:v1.12.0 (b9b055d) into release-4.22 [#294](https://github.com/openshift/cluster-api-provider-gcp/pull/294)
* [OCPBUGS-83966](https://issues.redhat.com/browse/OCPBUGS-83966): Merge https://github.com/kubernetes-sigs/cluster-api-provider-gcp:v1.11.2 (14609a0) into release-4.22 [#293](https://github.com/openshift/cluster-api-provider-gcp/pull/293)
* [Full changelog](https://github.com/openshift/cluster-api-provider-gcp/compare/788dd01e734fbafb788d50a4848460c7ceca90aa...e7674ede9ce8d021a878a6d5e81942875387e5eb)
### [gcp-pd-csi-driver](https://github.com/openshift/gcp-pd-csi-driver/tree/e3556b4d8912f40ae4013f6bd597edd7c9cdb59d)
* [OCPBUGS-114412](https://issues.redhat.com/browse/OCPBUGS-114412): Add Universe Domain Support [#129](https://github.com/openshift/gcp-pd-csi-driver/pull/129)
* [Full changelog](https://github.com/openshift/gcp-pd-csi-driver/compare/48a7a1aa3f2200d01cf1b6e63a5a6cfd5004a8b0...e3556b4d8912f40ae4013f6bd597edd7c9cdb59d)
### [gcp-pd-csi-driver-operator](https://github.com/openshift/gcp-pd-csi-driver-operator/tree/d9cd6ca1661bb11dfbb828815665985830e32622)
* [OCPBUGS-115120](https://issues.redhat.com/browse/OCPBUGS-115120): detect GCP Dedicated and use hyperdisk-balanced StorageClass [#204](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/204)
* [OCPBUGS-86574](https://issues.redhat.com/browse/OCPBUGS-86574): VolumeSnapshot snapshot-c9v52 is not ready within 5m0s… [#193](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/193)
* [OCPBUGS-83968](https://issues.redhat.com/browse/OCPBUGS-83968): Bump google.golang.org/grpc to v1.79.3 [#183](https://github.com/openshift/gcp-pd-csi-driver-operator/pull/183)
* [Full changelog](https://github.com/openshift/gcp-pd-csi-driver-operator/compare/a8e71880c1c81c42bcb59b1c5b0fb615290f5dd9...d9cd6ca1661bb11dfbb828815665985830e32622)
### [haproxy-router](https://github.com/openshift/router/tree/b70b28c0380056950793382f42b9b2eaf9330945)
* [OCPBUGS-101956](https://issues.redhat.com/browse/OCPBUGS-101956): Bump golang.org/x/net from v0.48.0 to v0.53.0 [#834](https://github.com/openshift/router/pull/834)
* [OCPBUGS-87166](https://issues.redhat.com/browse/OCPBUGS-87166): Prevent SSRF via FQDN-typed EndpointSlices [#813](https://github.com/openshift/router/pull/813)
* [OCPBUGS-87167](https://issues.redhat.com/browse/OCPBUGS-87167): Strip X-SSL-* headers for plain HTTP [#793](https://github.com/openshift/router/pull/793)
* [OCPBUGS-83969](https://issues.redhat.com/browse/OCPBUGS-83969): Bump google.golang.org/grpc to v1.79.3 [#776](https://github.com/openshift/router/pull/776)
* [Full changelog](https://github.com/openshift/router/compare/896390778ebe15f57f87e6ca78f11c96e64c2652...b70b28c0380056950793382f42b9b2eaf9330945)
### [hyperkube, kube-proxy, pod](https://github.com/openshift/kubernetes/tree/19365a06f558a5c5dc7f5654fa99a8318e4a77f4)
* [OCPBUGS-98604](https://issues.redhat.com/browse/OCPBUGS-98604): Add NodeSelectorAdjuster admission plugin for HCP clusters (part 2) [#2767](https://github.com/openshift/kubernetes/pull/2767)
* [OCPBUGS-98604](https://issues.redhat.com/browse/OCPBUGS-98604): Add NodeSelectorAdjuster admission plugin for HCP clusters [#2718](https://github.com/openshift/kubernetes/pull/2718)
* NO-JIRA: Update openshift-hack/rebase.sh [#2733](https://github.com/openshift/kubernetes/pull/2733)
* [OCPBUGS-96637](https://issues.redhat.com/browse/OCPBUGS-96637): Bump golang.org/x/net from v0.47.0 to v0.55.0 [#2737](https://github.com/openshift/kubernetes/pull/2737)
* [OCPBUGS-91744](https://issues.redhat.com/browse/OCPBUGS-91744), [OCPBUGS-93526](https://issues.redhat.com/browse/OCPBUGS-93526), [OCPBUGS-93551](https://issues.redhat.com/browse/OCPBUGS-93551), [OCPBUGS-95549](https://issues.redhat.com/browse/OCPBUGS-95549), [OCPBUGS-95556](https://issues.redhat.com/browse/OCPBUGS-95556): Bump golang.org/x/crypto/ssh to v0.52.0 [#2725](https://github.com/openshift/kubernetes/pull/2725)
* [OCPBUGS-99766](https://issues.redhat.com/browse/OCPBUGS-99766): UPSTREAM: <carry>: upkeep cpu partitioning admission webhook [#2724](https://github.com/openshift/kubernetes/pull/2724)
* [OCPBUGS-90148](https://issues.redhat.com/browse/OCPBUGS-90148): Rebase v1.35.6 in release-4.22 [#2707](https://github.com/openshift/kubernetes/pull/2707)
* [OCPBUGS-93787](https://issues.redhat.com/browse/OCPBUGS-93787): backport kubernetes/conformance umbrella suite [#2705](https://github.com/openshift/kubernetes/pull/2705)
* [OCPBUGS-86898](https://issues.redhat.com/browse/OCPBUGS-86898): Fix performance related issues when selinux metrics are emitted [#2676](https://github.com/openshift/kubernetes/pull/2676)
* [OCPBUGS-85499](https://issues.redhat.com/browse/OCPBUGS-85499): Bump Kubernetes v1.35.5 to release-4.22 [#2664](https://github.com/openshift/kubernetes/pull/2664)
* [OCPBUGS-85415](https://issues.redhat.com/browse/OCPBUGS-85415): [release-4.22] Improve WatchList test robustness [#2663](https://github.com/openshift/kubernetes/pull/2663)
* [Full changelog](https://github.com/openshift/kubernetes/compare/80f28ac33ac111532fb8ba59b2e569085ee871b0...19365a06f558a5c5dc7f5654fa99a8318e4a77f4)
### [hypershift](https://github.com/openshift/hypershift/tree/7273000c23583d67eaa63db019318e5aa7381297)
* [CNTRLPLANE-4321](https://issues.redhat.com/browse/CNTRLPLANE-4321): Cherry-pick kube-scheduler metrics support [#9490](https://github.com/openshift/hypershift/pull/9490)
* [CNTRLPLANE-4024](https://issues.redhat.com/browse/CNTRLPLANE-4024): feat(azure): support managed HSM for KMS encryption [#9437](https://github.com/openshift/hypershift/pull/9437)
* [OCPBUGS-98328](https://issues.redhat.com/browse/OCPBUGS-98328): fix(kubevirt): use only first MachineInternalIP per family in EndpointSlice endpoints [#8979](https://github.com/openshift/hypershift/pull/8979)
* [CNTRLPLANE-3774](https://issues.redhat.com/browse/CNTRLPLANE-3774): [release-4.22] fix: control-plane-operator: improve opaque conditions [#9058](https://github.com/openshift/hypershift/pull/9058)
* [OCPBUGS-111083](https://issues.redhat.com/browse/OCPBUGS-111083): fix(hcco): run kas-connection-checker as non-root [#9320](https://github.com/openshift/hypershift/pull/9320)
* [OCPBUGS-105866](https://issues.redhat.com/browse/OCPBUGS-105866): remove redhat-marketplace catalog from HyperShift [#9289](https://github.com/openshift/hypershift/pull/9289)
* [OCPBUGS-105591](https://issues.redhat.com/browse/OCPBUGS-105591): [release-4.22] use in-cluster service for oauth-server [#9127](https://github.com/openshift/hypershift/pull/9127)
* [OCPBUGS-96711](https://issues.redhat.com/browse/OCPBUGS-96711): Apply MetricsSet relabel configs to KAS ServiceMonitor [#8901](https://github.com/openshift/hypershift/pull/8901)
* [OCPBUGS-105421](https://issues.redhat.com/browse/OCPBUGS-105421): fix(upsert): add desired-state hash to detect spec field removals [#9259](https://github.com/openshift/hypershift/pull/9259)
* [OCPBUGS-101964](https://issues.redhat.com/browse/OCPBUGS-101964): [release-4.22] OCPBUGS-98213: fix router component ordering to prevent missing HAProxy backends [#9212](https://github.com/openshift/hypershift/pull/9212)
* [OCPBUGS-100332](https://issues.redhat.com/browse/OCPBUGS-100332): fix(konnectivity): conditionally prefer IPv4 based on HCP network config [release-4.22] [#9191](https://github.com/openshift/hypershift/pull/9191)
* [OCPBUGS-100141](https://issues.redhat.com/browse/OCPBUGS-100141): Add proxy env vars to AWS cloud-controller-manager deployment [#9156](https://github.com/openshift/hypershift/pull/9156)
* [OCPBUGS-94518](https://issues.redhat.com/browse/OCPBUGS-94518): add ACR pull identity to worker cloud.conf and VMSS [#8865](https://github.com/openshift/hypershift/pull/8865)
* [OCPBUGS-100299](https://issues.redhat.com/browse/OCPBUGS-100299): Avoid printing errors twice [#9183](https://github.com/openshift/hypershift/pull/9183)
* [OCPBUGS-94170](https://issues.redhat.com/browse/OCPBUGS-94170): fix registry override matching and propagation to init containers [#8877](https://github.com/openshift/hypershift/pull/8877)
* [OCPBUGS-100176](https://issues.redhat.com/browse/OCPBUGS-100176): Remove hardcoded quay.io credentials from EnsureGlobalPullSecret test [#9169](https://github.com/openshift/hypershift/pull/9169)
* [OCPBUGS-90086](https://issues.redhat.com/browse/OCPBUGS-90086): [release-4.22] clear stale EtcdRecoveryActive failure condition when etcd is healthy [#8806](https://github.com/openshift/hypershift/pull/8806)
* [OCPBUGS-99554](https://issues.redhat.com/browse/OCPBUGS-99554): fix(backport): konnectivity agent auth to 4.22 [#9077](https://github.com/openshift/hypershift/pull/9077)
* [OCPBUGS-99299](https://issues.redhat.com/browse/OCPBUGS-99299): [release-4.22] OCPBUGS-86296: Propagate management cluster proxy env vars to konnectivity sidecar [#8592](https://github.com/openshift/hypershift/pull/8592)
* [CNTRLPLANE-3884](https://issues.redhat.com/browse/CNTRLPLANE-3884): Add spec.monitoring API for metrics forwarding [#8872](https://github.com/openshift/hypershift/pull/8872)
* [OCPBUGS-97921](https://issues.redhat.com/browse/OCPBUGS-97921): fix(nodepool): skip CNI-internal IPs in ClusterNetworkCIDRConflict check [#8948](https://github.com/openshift/hypershift/pull/8948)
* [OCPBUGS-98627](https://issues.redhat.com/browse/OCPBUGS-98627): Skip Azure topology LB scope override for ARO HCP IngressController [#8998](https://github.com/openshift/hypershift/pull/8998)
* [OCPBUGS-98220](https://issues.redhat.com/browse/OCPBUGS-98220): fix(cpo,hcco): prevent premature KAS convergence during KMS key rotation [release-4.22] [#8972](https://github.com/openshift/hypershift/pull/8972)
* [OCPBUGS-90083](https://issues.redhat.com/browse/OCPBUGS-90083): Fix NodePool reconciliation failure when updating mirrored immutable ConfigMaps [#8811](https://github.com/openshift/hypershift/pull/8811)
* [OCPBUGS-89236](https://issues.redhat.com/browse/OCPBUGS-89236): Handle CA bundle aggregation delay by requeuing revocation [#8746](https://github.com/openshift/hypershift/pull/8746)
* [CNTRLPLANE-3749](https://issues.redhat.com/browse/CNTRLPLANE-3749): feat(api,cpo): add observedGeneration to ControlPlaneComponentStatus [#8868](https://github.com/openshift/hypershift/pull/8868)
* [OCPBUGS-93921](https://issues.redhat.com/browse/OCPBUGS-93921): bump catalog image version cap from 4.21 to 4.22 [#8861](https://github.com/openshift/hypershift/pull/8861)
* [OCPBUGS-88325](https://issues.redhat.com/browse/OCPBUGS-88325): fix(cpo) delete terminated MCD pods to retry in-place upgrades [#8729](https://github.com/openshift/hypershift/pull/8729)
* [OCPBUGS-87364](https://issues.redhat.com/browse/OCPBUGS-87364): Gate Route watch on management cluster capability [#8692](https://github.com/openshift/hypershift/pull/8692)
* [CNTRLPLANE-3661](https://issues.redhat.com/browse/CNTRLPLANE-3661): add etcd data re-encryption after encryption key rotation (#8219) [#8790](https://github.com/openshift/hypershift/pull/8790)
* [OCPBUGS-88356](https://issues.redhat.com/browse/OCPBUGS-88356): fix(cpo): deduplicate VPC endpoint subnets by AZ [#8724](https://github.com/openshift/hypershift/pull/8724)
* [CNTRLPLANE-3619](https://issues.redhat.com/browse/CNTRLPLANE-3619): backport API-driven Azure topology and private connectivity (Phase 1) [#8721](https://github.com/openshift/hypershift/pull/8721)
* [OCPBUGS-90563](https://issues.redhat.com/browse/OCPBUGS-90563): Fix metrics-proxy unbounded memory growth [#8788](https://github.com/openshift/hypershift/pull/8788)
* [OCPBUGS-89352](https://issues.redhat.com/browse/OCPBUGS-89352): build(operator): drop hypershift-no-cgo from operator container images [#8756](https://github.com/openshift/hypershift/pull/8756)
* [OCPBUGS-86912](https://issues.redhat.com/browse/OCPBUGS-86912): [release-4.22] Stop controllers fighting over HCP status [#8632](https://github.com/openshift/hypershift/pull/8632)
* [OCPBUGS-86039](https://issues.redhat.com/browse/OCPBUGS-86039): OCPBUGS-62177: [release-4.22] Verify cert revocation against all KAS pods [#8538](https://github.com/openshift/hypershift/pull/8538)
* [OCPBUGS-86578](https://issues.redhat.com/browse/OCPBUGS-86578): bootstrap serving certs at hypershift operator startup [#8599](https://github.com/openshift/hypershift/pull/8599)
* [OCPBUGS-86354](https://issues.redhat.com/browse/OCPBUGS-86354): add Konflux pipeline definitions for CPO 4.22 [#8608](https://github.com/openshift/hypershift/pull/8608)
* [OCPBUGS-86354](https://issues.redhat.com/browse/OCPBUGS-86354): set limits for aro.openshift.io/swift-nic in request overrides for ARO swift [#8564](https://github.com/openshift/hypershift/pull/8564)
* [OCPBUGS-85620](https://issues.redhat.com/browse/OCPBUGS-85620): Fix webhook TLS failure after service-ca to self-managed cert migration [#8513](https://github.com/openshift/hypershift/pull/8513)
* [OCPBUGS-83836](https://issues.redhat.com/browse/OCPBUGS-83836): add missing RBAC for webhook configurations [#8295](https://github.com/openshift/hypershift/pull/8295)
* [OCPBUGS-84939](https://issues.redhat.com/browse/OCPBUGS-84939): [release-4.22] add CP pull-secret watches for in-place propagation [#8408](https://github.com/openshift/hypershift/pull/8408)
* [OCPBUGS-86026](https://issues.redhat.com/browse/OCPBUGS-86026): Fix metrics-proxy deployment failure due to dots in volume names [#8534](https://github.com/openshift/hypershift/pull/8534)
* [OCPBUGS-85779](https://issues.redhat.com/browse/OCPBUGS-85779): Add AWS ISO domains to konnectivity IsCloudAPI [#8447](https://github.com/openshift/hypershift/pull/8447)
* [OCPBUGS-85659](https://issues.redhat.com/browse/OCPBUGS-85659): Clarify --base-domain flag default behavior [#8525](https://github.com/openshift/hypershift/pull/8525)
* [ACM-33601](https://issues.redhat.com/browse/ACM-33601): use the latest ubi9 nginx image [#8465](https://github.com/openshift/hypershift/pull/8465)
* [OCPBUGS-78988](https://issues.redhat.com/browse/OCPBUGS-78988): bump go builder and ubi images [#8457](https://github.com/openshift/hypershift/pull/8457)
* [CNTRLPLANE-2939](https://issues.redhat.com/browse/CNTRLPLANE-2939): Coordinate CRD lifecycle with Cluster CAPI Operator [#8442](https://github.com/openshift/hypershift/pull/8442)
* [OCPBUGS-85104](https://issues.redhat.com/browse/OCPBUGS-85104): fix, cno, skip cloud-network-config-controller check on non-cloud platforms [#8438](https://github.com/openshift/hypershift/pull/8438)
* [Full changelog](https://github.com/openshift/hypershift/compare/807ebc5d7bed2608aa5ea59ff85991cc242246c6...7273000c23583d67eaa63db019318e5aa7381297)
### [ibm-cloud-controller-manager](https://github.com/openshift/cloud-provider-ibm/tree/24cff9a691e1ebee94669c834320c6ea974a2010)
* [OCPBUGS-83973](https://issues.redhat.com/browse/OCPBUGS-83973): Upgrade grpc for CVE-2026-33186 [#105](https://github.com/openshift/cloud-provider-ibm/pull/105)
* [Full changelog](https://github.com/openshift/cloud-provider-ibm/compare/d9222a1c00c37d635da02b65606fde1e54b2ec03...24cff9a691e1ebee94669c834320c6ea974a2010)
### [ibm-vpc-block-csi-driver](https://github.com/openshift/ibm-vpc-block-csi-driver/tree/d362aef240c280676249fa34c80fa1b39c684560)
* [OCPBUGS-83974](https://issues.redhat.com/browse/OCPBUGS-83974): Bump google.golang.org/grpc to v1.79.3 [#147](https://github.com/openshift/ibm-vpc-block-csi-driver/pull/147)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver/compare/aa40cd7e1a37e2f48f238fc8d293b0546d5d4caf...d362aef240c280676249fa34c80fa1b39c684560)
### [ibm-vpc-block-csi-driver-operator](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/tree/3d5956ddd2292c381309106d23fff1765380c55e)
* [OCPBUGS-83774](https://issues.redhat.com/browse/OCPBUGS-83774): Bump google.golang.org/grpc to v1.79.3 [#171](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/pull/171)
* [Full changelog](https://github.com/openshift/ibm-vpc-block-csi-driver-operator/compare/f859eac9612d8fff52013b809840b015cee6742d...3d5956ddd2292c381309106d23fff1765380c55e)
### [ibmcloud-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-ibmcloud/tree/c378efee05fd02323d241e86244dee3b56e32a45)
* [OCPBUGS-101965](https://issues.redhat.com/browse/OCPBUGS-101965): Replace golang.org/x/net with openshift-sustaining/net [#176](https://github.com/openshift/cluster-api-provider-ibmcloud/pull/176)
* [Full changelog](https://github.com/openshift/cluster-api-provider-ibmcloud/compare/03b143d588768a18fd8afa1534ea7d7a04b4d1f3...c378efee05fd02323d241e86244dee3b56e32a45)
### [ibmcloud-machine-controllers](https://github.com/openshift/machine-api-provider-ibmcloud/tree/9e5537cd7d239a31d6b2eb56cd44af3ec7b47dd5)
* [OCPBUGS-96641](https://issues.redhat.com/browse/OCPBUGS-96641): bump golang.org/x/net to v0.57.0 [#99](https://github.com/openshift/machine-api-provider-ibmcloud/pull/99)
* [Full changelog](https://github.com/openshift/machine-api-provider-ibmcloud/compare/46b8c72c675770295f5c2c8f85f5f705ca35787c...9e5537cd7d239a31d6b2eb56cd44af3ec7b47dd5)
### [insights-operator](https://github.com/openshift/insights-operator/tree/a46094471cfb564f3224975a2b1ea6c12d9d057b)
* [OCPBUGS-105227](https://issues.redhat.com/browse/OCPBUGS-105227): secrets and configmap revisions count gathering [#1339](https://github.com/openshift/insights-operator/pull/1339)
* [OCPBUGS-100173](https://issues.redhat.com/browse/OCPBUGS-100173): Update installer dependency to use tagged version [#1332](https://github.com/openshift/insights-operator/pull/1332)
* [OCPBUGS-100154](https://issues.redhat.com/browse/OCPBUGS-100154): [release-4.22] Fix indentation bug on livenessProbe [#1330](https://github.com/openshift/insights-operator/pull/1330)
* [OCPBUGS-96642](https://issues.redhat.com/browse/OCPBUGS-96642): [release-4.22] Upgrade Golang and net library [#1327](https://github.com/openshift/insights-operator/pull/1327)
* [OCPBUGS-98383](https://issues.redhat.com/browse/OCPBUGS-98383): controlplanemachinesets gatherer [#1318](https://github.com/openshift/insights-operator/pull/1318)
* [OCPBUGS-98153](https://issues.redhat.com/browse/OCPBUGS-98153): update HyperShift deployment manifest [#1315](https://github.com/openshift/insights-operator/pull/1315)
* [OCPBUGS-98381](https://issues.redhat.com/browse/OCPBUGS-98381): Optimize the CPU usage of insights-runtime-extractor [#1317](https://github.com/openshift/insights-operator/pull/1317)
* [OCPBUGS-88026](https://issues.redhat.com/browse/OCPBUGS-88026): fall back to kube-system/global-pull-secret for Insights token [#1305](https://github.com/openshift/insights-operator/pull/1305)
* [OCPBUGS-86818](https://issues.redhat.com/browse/OCPBUGS-86818): extractor controller [#1296](https://github.com/openshift/insights-operator/pull/1296)
* [OCPBUGS-86013](https://issues.redhat.com/browse/OCPBUGS-86013): add trusted-ca-bundle to gatherin job [#1290](https://github.com/openshift/insights-operator/pull/1290)
* [OCPBUGS-83976](https://issues.redhat.com/browse/OCPBUGS-83976): Bump google.golang.org/grpc to v1.79.3 [#1287](https://github.com/openshift/insights-operator/pull/1287)
* [Full changelog](https://github.com/openshift/insights-operator/compare/d7b9c77e6565d4452ff79cd346f3ee6b8535698c...a46094471cfb564f3224975a2b1ea6c12d9d057b)
### [ironic](https://github.com/openshift/ironic-image/tree/5d16ca14c3c757816c95e5830255912e8b8d8b49)
* [OCPBUGS-105863](https://issues.redhat.com/browse/OCPBUGS-105863): update ironic pin to include CVE-2026-54423 fix (release-4.22) [#889](https://github.com/openshift/ironic-image/pull/889)
* [OCPBUGS-100167](https://issues.redhat.com/browse/OCPBUGS-100167): Update openstack-ironic commit hash for CVE-2026-44918 [#874](https://github.com/openshift/ironic-image/pull/874)
* [OCPBUGS-88478](https://issues.redhat.com/browse/OCPBUGS-88478): Update openstack-ironic commit hash in requirements.cachito that addresses CVE-2026-43003 [#860](https://github.com/openshift/ironic-image/pull/860)
* [OCPBUGS-98873](https://issues.redhat.com/browse/OCPBUGS-98873): Selectively backport Redfish firmware update fix to 4.22 [#870](https://github.com/openshift/ironic-image/pull/870)
* [OCPBUGS-84369](https://issues.redhat.com/browse/OCPBUGS-84369): selectively backport servicing patches to 4.22 [#848](https://github.com/openshift/ironic-image/pull/848)
* [Full changelog](https://github.com/openshift/ironic-image/compare/f934d2cdf0bebbde4992980a770dd799056ab867...5d16ca14c3c757816c95e5830255912e8b8d8b49)
### [ironic-agent](https://github.com/openshift/ironic-agent-image/tree/be386561e40cc3bb56ddd05fbf73a7c9ead5198c)
* [OCPBUGS-99897](https://issues.redhat.com/browse/OCPBUGS-99897): Bump ironic-python-agent pinned commit for CVE-2026-66138 [#294](https://github.com/openshift/ironic-agent-image/pull/294)
* [OCPBUGS-88478](https://issues.redhat.com/browse/OCPBUGS-88478): Update commit SHA in requirements.cachito to address CVE-2026-43003 [#266](https://github.com/openshift/ironic-agent-image/pull/266)
* [OCPBUGS-95061](https://issues.redhat.com/browse/OCPBUGS-95061): Replace individual package removal with a single rpm -e loop [#282](https://github.com/openshift/ironic-agent-image/pull/282)
* [OCPBUGS-95061](https://issues.redhat.com/browse/OCPBUGS-95061): Replace dnf remove with rpm -e to prevent dependency removal [#270](https://github.com/openshift/ironic-agent-image/pull/270)
* [Full changelog](https://github.com/openshift/ironic-agent-image/compare/0336e6383c98f4f0c6b35c71e00116d3c3160c43...be386561e40cc3bb56ddd05fbf73a7c9ead5198c)
### [keepalived-ipfailover](https://github.com/openshift/images/tree/6035d101dbc9a7fdd8861d864aeb6f66bacd964b)
* [OCPBUGS-99767](https://issues.redhat.com/browse/OCPBUGS-99767): Reinstall tzdata if /usr/share/zoneinfo is missing [#247](https://github.com/openshift/images/pull/247)
* Updating openshift-enterprise-base-rhel9-container image to be consistent with ART for 4.22 [#229](https://github.com/openshift/images/pull/229)
* [OCPBUGS-72552](https://issues.redhat.com/browse/OCPBUGS-72552): Updating openshift-enterprise-base-rhel9-minimal-container image to be consistent with ART for 4.22 [#220](https://github.com/openshift/images/pull/220)
* [Full changelog](https://github.com/openshift/images/compare/95eb21f013e39ba2100917591bfa18546f0980a3...6035d101dbc9a7fdd8861d864aeb6f66bacd964b)
### [kube-state-metrics](https://github.com/openshift/kube-state-metrics/tree/0a5ea07ca01263c4273a1a929854969e11a69bea)
* [OCPBUGS-87957](https://issues.redhat.com/browse/OCPBUGS-87957): embed timezone data in kube-state-metrics binary [#150](https://github.com/openshift/kube-state-metrics/pull/150)
* [OCPBUGS-87957](https://issues.redhat.com/browse/OCPBUGS-87957): fix: don't panic on CronJobs with unparseable schedules [#147](https://github.com/openshift/kube-state-metrics/pull/147)
* [OCPBUGS-86653](https://issues.redhat.com/browse/OCPBUGS-86653): [Backport] Handle DeletedFinalStateUnknown panic [#142](https://github.com/openshift/kube-state-metrics/pull/142)
* [Full changelog](https://github.com/openshift/kube-state-metrics/compare/6fa06eac4c3942ba64bff18ca93b5a019ea5c976...0a5ea07ca01263c4273a1a929854969e11a69bea)
### [kubevirt-cloud-controller-manager](https://github.com/openshift/cloud-provider-kubevirt/tree/09a0a5beaa65fb589d7b571dc47f9748d2463b1c)
* [OCPBUGS-69842](https://issues.redhat.com/browse/OCPBUGS-69842): Updating ose-kubevirt-cloud-controller-manager-container image to be consistent with ART for 4.22 [#59](https://github.com/openshift/cloud-provider-kubevirt/pull/59)
* [Full changelog](https://github.com/openshift/cloud-provider-kubevirt/compare/76dd5a6fa9e86573bf3dfb79be17edf832e3bae1...09a0a5beaa65fb589d7b571dc47f9748d2463b1c)
### [kubevirt-csi-driver](https://github.com/openshift/kubevirt-csi-driver/tree/90f14506c2d4fecfba2c355934bde87e6f101a20)
* [OCPBUGS-83883](https://issues.redhat.com/browse/OCPBUGS-83883): Bump google.golang.org/grpc to v1.79.3 [#107](https://github.com/openshift/kubevirt-csi-driver/pull/107)
* [Full changelog](https://github.com/openshift/kubevirt-csi-driver/compare/771b562d4875296007850a4d3709a7ae1c6ed3e2...90f14506c2d4fecfba2c355934bde87e6f101a20)
### [machine-api-operator](https://github.com/openshift/machine-api-operator/tree/e38046acfe255e67aa5ab9c9a6f4efd882ed7dbb)
* [OCPBUGS-101989](https://issues.redhat.com/browse/OCPBUGS-101989): Bump golang.org/x/net from v0.49.0 to v0.53.0 [#1541](https://github.com/openshift/machine-api-operator/pull/1541)
* [OCPBUGS-115165](https://issues.redhat.com/browse/OCPBUGS-115165): CORS-4521: GCP: Add regional permission [#1538](https://github.com/openshift/machine-api-operator/pull/1538)
* [OCPBUGS-85102](https://issues.redhat.com/browse/OCPBUGS-85102): Populate status label selector for scale subresource [#1497](https://github.com/openshift/machine-api-operator/pull/1497)
* [Full changelog](https://github.com/openshift/machine-api-operator/compare/33cb2da02d57004711bd09dd8f288ed6174f48fc...e38046acfe255e67aa5ab9c9a6f4efd882ed7dbb)
### [machine-config-operator](https://github.com/openshift/machine-config-operator/tree/90b269666abb8df37c46bf49d9b54dcf2604447c)
* [OCPBUGS-121849](https://issues.redhat.com/browse/OCPBUGS-121849): Fix vsphere network absolute paths [#6512](https://github.com/openshift/machine-config-operator/pull/6512)
* [OCPBUGS-120671](https://issues.redhat.com/browse/OCPBUGS-120671): Skip vsphere fd-unmatched machinesets for bootimage updates [#6494](https://github.com/openshift/machine-config-operator/pull/6494)
* [OCPBUGS-119936](https://issues.redhat.com/browse/OCPBUGS-119936): Increase TC-74751 Eventually timeout for vSphere OVA upload [#6492](https://github.com/openshift/machine-config-operator/pull/6492)
* [OCPBUGS-115401](https://issues.redhat.com/browse/OCPBUGS-115401): Update message for MachineOSBuildFailed condition [#6479](https://github.com/openshift/machine-config-operator/pull/6479)
* [OCPBUGS-116943](https://issues.redhat.com/browse/OCPBUGS-116943): Update AMI Whitelist [#6489](https://github.com/openshift/machine-config-operator/pull/6489)
* [OCPBUGS-112785](https://issues.redhat.com/browse/OCPBUGS-112785): Revert TNF Graceful node shutdown [#6461](https://github.com/openshift/machine-config-operator/pull/6461)
* [OCPBUGS-114418](https://issues.redhat.com/browse/OCPBUGS-114418): [release-4.22] OCPBUGS-113615: Azure confidential clusters should be flagged by skew enforcement [#6459](https://github.com/openshift/machine-config-operator/pull/6459)
* [OCPBUGS-114392](https://issues.redhat.com/browse/OCPBUGS-114392): Use kubernetes scheme in drain controller event recorder [#6458](https://github.com/openshift/machine-config-operator/pull/6458)
* [AGENT-1583](https://issues.redhat.com/browse/AGENT-1583): post-feature promotion (NoRegistryClusterInstall) openshift/api dependencies bump [#6418](https://github.com/openshift/machine-config-operator/pull/6418)
* [OCPBUGS-112618](https://issues.redhat.com/browse/OCPBUGS-112618): Fix upstreams for CoreDNS pods on Cloud platforms [#6438](https://github.com/openshift/machine-config-operator/pull/6438)
* [OCPBUGS-112614](https://issues.redhat.com/browse/OCPBUGS-112614): OCPBUGS-109739: Increase rpm-ostree rebase retry backoff and preserve error [#6436](https://github.com/openshift/machine-config-operator/pull/6436)
* [OCPBUGS-105521](https://issues.redhat.com/browse/OCPBUGS-105521): Fix SHA idempotency test in nmstate-configuration.sh [#6392](https://github.com/openshift/machine-config-operator/pull/6392)
* [OCPBUGS-105929](https://issues.redhat.com/browse/OCPBUGS-105929): Fix duplicate template error and e2es [#6397](https://github.com/openshift/machine-config-operator/pull/6397)
* Fixes OCPBUGS-105190: increase LRU cache and prefetch timeout for PinnedImageSet [#6372](https://github.com/openshift/machine-config-operator/pull/6372)
* [OCPBUGS-105447](https://issues.redhat.com/browse/OCPBUGS-105447): fix nil pointer panic in IRI controller informer race [#6390](https://github.com/openshift/machine-config-operator/pull/6390)
* [OCPBUGS-105212](https://issues.redhat.com/browse/OCPBUGS-105212): [release-4.22] Part2 Migrate OCB test-case [#6374](https://github.com/openshift/machine-config-operator/pull/6374)
* [OCPBUGS-105213](https://issues.redhat.com/browse/OCPBUGS-105213): Update AMI Whitelist [#6375](https://github.com/openshift/machine-config-operator/pull/6375)
* [OCPBUGS-104563](https://issues.redhat.com/browse/OCPBUGS-104563): Use providerSpec.Template in vSphere machineset reconciliation [#6370](https://github.com/openshift/machine-config-operator/pull/6370)
* [OCPBUGS-100583](https://issues.redhat.com/browse/OCPBUGS-100583): [release-4.22] Part 1 Migrate OCB test cases from openshift-tests-private [#6361](https://github.com/openshift/machine-config-operator/pull/6361)
* [OCPBUGS-104576](https://issues.redhat.com/browse/OCPBUGS-104576): [release-4.22] Add extension verification failure test cases OCP-89090 and OCP-89095 [#6367](https://github.com/openshift/machine-config-operator/pull/6367)
* [OCPBUGS-104451](https://issues.redhat.com/browse/OCPBUGS-104451): [release-4.22] fix fencing_validator ocdebug fence dispatch race condition [#6360](https://github.com/openshift/machine-config-operator/pull/6360)
* [OCPBUGS-100293](https://issues.redhat.com/browse/OCPBUGS-100293): Fix TC 43278 failing when release payload has no MCO commit info [#6351](https://github.com/openshift/machine-config-operator/pull/6351)
* [AGENT-1548](https://issues.redhat.com/browse/AGENT-1548): Backport NoRegistryClusterInstall feature to release-4.22 [#6323](https://github.com/openshift/machine-config-operator/pull/6323)
* [OCPBUGS-99712](https://issues.redhat.com/browse/OCPBUGS-99712): Add TC 88940- Apply password only if changes exist [#6339](https://github.com/openshift/machine-config-operator/pull/6339)
* [OCPBUGS-98962](https://issues.redhat.com/browse/OCPBUGS-98962): [release4.22] MCO-1997: MCO-2297: MCO-2440 Add osImagestream test-cases [#6301](https://github.com/openshift/machine-config-operator/pull/6301)
* [OCPBUGS-93804](https://issues.redhat.com/browse/OCPBUGS-93804): move cleanUpDuplicatedMC to avoid double reboot on first updated Master node [#6240](https://github.com/openshift/machine-config-operator/pull/6240)
* [OCPBUGS-97904](https://issues.redhat.com/browse/OCPBUGS-97904): Inject proxy into MCC deployment [#6275](https://github.com/openshift/machine-config-operator/pull/6275)
* [OCPBUGS-96145](https://issues.redhat.com/browse/OCPBUGS-96145): Update AMI Whitelist [#6260](https://github.com/openshift/machine-config-operator/pull/6260)
* [OCPBUGS-89329](https://issues.redhat.com/browse/OCPBUGS-89329): Fix kubelet certificate wait loop in criometricsproxy.yaml [#6200](https://github.com/openshift/machine-config-operator/pull/6200)
* [OCPBUGS-93743](https://issues.redhat.com/browse/OCPBUGS-93743): Fix bootupd workaround in old nodes [#6239](https://github.com/openshift/machine-config-operator/pull/6239)
* [OCPBUGS-92026](https://issues.redhat.com/browse/OCPBUGS-92026): OCPEDGE-2474: TNF - Add fencing taint/untaint alert agent scripts [#6230](https://github.com/openshift/machine-config-operator/pull/6230)
* [OCPBUGS-92022](https://issues.redhat.com/browse/OCPBUGS-92022): MCO-2275: Migrate OS layering tests from openshift-tests-private [#6218](https://github.com/openshift/machine-config-operator/pull/6218)
* [release:4.22] OCPBUGS-88330: MCO-2209 MCO-2213 MCO-2207: Migrate security, daemon, and kernel TCs from mco.go [#6171](https://github.com/openshift/machine-config-operator/pull/6171)
* [OCPBUGS-91958](https://issues.redhat.com/browse/OCPBUGS-91958): Boot image skew check silently passes when MachineSets are reconcile-skipped [#6227](https://github.com/openshift/machine-config-operator/pull/6227)
* [OCPBUGS-91954](https://issues.redhat.com/browse/OCPBUGS-91954): Make vsphere template updates atomic [#6226](https://github.com/openshift/machine-config-operator/pull/6226)
* [OCPBUGS-88184](https://issues.redhat.com/browse/OCPBUGS-88184): Replace wildcard permissions with explicit verbs and resources in MCC ClusterRole [#6170](https://github.com/openshift/machine-config-operator/pull/6170)
* [OCPBUGS-88683](https://issues.redhat.com/browse/OCPBUGS-88683): Process rebuild annotation on machine-os-builder restart [#6190](https://github.com/openshift/machine-config-operator/pull/6190)
* [OCPBUGS-87981](https://issues.redhat.com/browse/OCPBUGS-87981): Fix MCP.status.osImageStream [#6164](https://github.com/openshift/machine-config-operator/pull/6164)
* [OCPBUGS-88496](https://issues.redhat.com/browse/OCPBUGS-88496): Update custom containerfile OCB test to work in a disconnected environment [#6188](https://github.com/openshift/machine-config-operator/pull/6188)
* [OCPBUGS-88001](https://issues.redhat.com/browse/OCPBUGS-88001): Add mco_extensions.go e2e test suite for MCO extension install, enable, and validation [#6184](https://github.com/openshift/machine-config-operator/pull/6184)
* [OCPBUGS-88329](https://issues.redhat.com/browse/OCPBUGS-88329): In OCB to check when a image is removed the old build is triggered again and the MC should start updating directly and no new MOSB should be triggred [#6175](https://github.com/openshift/machine-config-operator/pull/6175)
* [OCPBUGS-87019](https://issues.redhat.com/browse/OCPBUGS-87019): fix: update arbiter crio config [#6142](https://github.com/openshift/machine-config-operator/pull/6142)
* [OCPBUGS-88487](https://issues.redhat.com/browse/OCPBUGS-88487): make test 69755 more stable [#6186](https://github.com/openshift/machine-config-operator/pull/6186)
* [OCPBUGS-88331](https://issues.redhat.com/browse/OCPBUGS-88331): [release-4.22] Remove skopeo-install script [#6176](https://github.com/openshift/machine-config-operator/pull/6176)
* [OCPBUGS-84679](https://issues.redhat.com/browse/OCPBUGS-84679): add RootCA cert to the sysContextBuilder certs [#5897](https://github.com/openshift/machine-config-operator/pull/5897)
* [OCPBUGS-87840](https://issues.redhat.com/browse/OCPBUGS-87840): vSphere boot image hot loop detection is non-functional due to stable template names [#6157](https://github.com/openshift/machine-config-operator/pull/6157)
* [OCPBUGS-87900](https://issues.redhat.com/browse/OCPBUGS-87900): [release-4.22] OCPBUGS-87181: MCO-2211: MCO-2210: MCO-2234 MCO-Migrate MCO tests from openshift-tests-private [#6148](https://github.com/openshift/machine-config-operator/pull/6148)
* [OCPBUGS-88114](https://issues.redhat.com/browse/OCPBUGS-88114): Skip chrony-wait on first node join [#6168](https://github.com/openshift/machine-config-operator/pull/6168)
* [OCPBUGS-88120](https://issues.redhat.com/browse/OCPBUGS-88120): daemon: don't pull/extract extensions for all OS updates [#6169](https://github.com/openshift/machine-config-operator/pull/6169)
* [OCPBUGS-87811](https://issues.redhat.com/browse/OCPBUGS-87811): [release-4.22] OCPBUGS-87550: Update TC-88366 to check osImageStream status after update completes [#6153](https://github.com/openshift/machine-config-operator/pull/6153)
* [OCPBUGS-87161](https://issues.redhat.com/browse/OCPBUGS-87161): [release-4.22] OCPBUGS-87027: MCO-2212: MCO-2213: Migrate mco_observability and mco_daemon test-suite [#6143](https://github.com/openshift/machine-config-operator/pull/6143)
* [OCPBUGS-86865](https://issues.redhat.com/browse/OCPBUGS-86865): Stabilize ocl 4.22 [#6115](https://github.com/openshift/machine-config-operator/pull/6115)
* [OCPBUGS-86985](https://issues.redhat.com/browse/OCPBUGS-86985): MCO-2297: Add OCP-88366 and OCP-88814 for osImageStream with osImageURL [#6083](https://github.com/openshift/machine-config-operator/pull/6083)
* [OCPBUGS-87163](https://issues.redhat.com/browse/OCPBUGS-87163): Remove trailing newline (\n) characters in klog message strings [#6147](https://github.com/openshift/machine-config-operator/pull/6147)
* [OCPBUGS-86893](https://issues.redhat.com/browse/OCPBUGS-86893): Add version guard for OSStream rendering [#6123](https://github.com/openshift/machine-config-operator/pull/6123)
* [OCPBUGS-86997](https://issues.redhat.com/browse/OCPBUGS-86997): [release-4.22] OCPBUGS-86984: MCO-2273: MCO-2215: MCO-2183: Migrate remaining TCs from mco.go to MCO, units, kublet suite [#6126](https://github.com/openshift/machine-config-operator/pull/6126)
* [OCPBUGS-86297](https://issues.redhat.com/browse/OCPBUGS-86297): configure-ovs: copy lldp mode to br-ex port [#6073](https://github.com/openshift/machine-config-operator/pull/6073)
* [OCPBUGS-86870](https://issues.redhat.com/browse/OCPBUGS-86870): Update AMI Whitelist [#6116](https://github.com/openshift/machine-config-operator/pull/6116)
* [OCPBUGS-86732](https://issues.redhat.com/browse/OCPBUGS-86732): remove tests using base images older than 4.13 [#6104](https://github.com/openshift/machine-config-operator/pull/6104)
* [OCPBUGS-86769](https://issues.redhat.com/browse/OCPBUGS-86769): Adapt test '54922 - daemon: add check before updating kernel [#6103](https://github.com/openshift/machine-config-operator/pull/6103)
* [MCO-2233](https://issues.redhat.com/browse/MCO-2233): Migrate Kernel related MCO test-cases [#5860](https://github.com/openshift/machine-config-operator/pull/5860)
* [OCPBUGS-86262](https://issues.redhat.com/browse/OCPBUGS-86262): Verify extension packages are installed [#6071](https://github.com/openshift/machine-config-operator/pull/6071)
* [OCPBUGS-85127](https://issues.redhat.com/browse/OCPBUGS-85127): Fix wrong early exit during kubelet MCs regeneration [#6009](https://github.com/openshift/machine-config-operator/pull/6009)
* [OCPBUGS-86267](https://issues.redhat.com/browse/OCPBUGS-86267): Fix CVE-2026-33186 [#6072](https://github.com/openshift/machine-config-operator/pull/6072)
* [OCPBUGS-85341](https://issues.redhat.com/browse/OCPBUGS-85341): Apply password only if changes exist [#6053](https://github.com/openshift/machine-config-operator/pull/6053)
* [OCPBUGS-86047](https://issues.redhat.com/browse/OCPBUGS-86047): Manually uncordoned nodes are not automatically re-cordoned [#6060](https://github.com/openshift/machine-config-operator/pull/6060)
* [OCPBUGS-85124](https://issues.redhat.com/browse/OCPBUGS-85124): use `--delete-if-present` for karg removal [#6007](https://github.com/openshift/machine-config-operator/pull/6007)
* [OCPBUGS-85626](https://issues.redhat.com/browse/OCPBUGS-85626): only check password hash in /etc/shadow [#6042](https://github.com/openshift/machine-config-operator/pull/6042)
* [OCPBUGS-85651](https://issues.redhat.com/browse/OCPBUGS-85651): BareMetal skew e2e fails patching provisioning CR after CBO webhook fix [#6047](https://github.com/openshift/machine-config-operator/pull/6047)
* [OCPBUGS-85198](https://issues.redhat.com/browse/OCPBUGS-85198): Add `terminationMessagePolicy` to build pod containers [#6012](https://github.com/openshift/machine-config-operator/pull/6012)
* [OCPBUGS-85481](https://issues.redhat.com/browse/OCPBUGS-85481): Add fix for ossImagestream status [#6026](https://github.com/openshift/machine-config-operator/pull/6026)
* [OCPBUGS-84813](https://issues.redhat.com/browse/OCPBUGS-84813): Include RootCA in the temporal CC [#5904](https://github.com/openshift/machine-config-operator/pull/5904)
* [OCPBUGS-84406](https://issues.redhat.com/browse/OCPBUGS-84406): Fix CVE-2026-34986 [#5986](https://github.com/openshift/machine-config-operator/pull/5986)
* [OCPBUGS-85156](https://issues.redhat.com/browse/OCPBUGS-85156): Bootloader update attempt should be conditional [#6011](https://github.com/openshift/machine-config-operator/pull/6011)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/machine-config-operator/compare/6a6d654f0c1f00f130fd58c1494196eee4ee6a84...90b269666abb8df37c46bf49d9b54dcf2604447c)
### [machine-os-images](https://github.com/openshift/machine-os-images/tree/e5342c9905a94069e6801737dd6aeddfb74bbac4)
* [OCPBUGS-87872](https://issues.redhat.com/browse/OCPBUGS-87872): Add support for hermetic builds via Cachi2 prefetched CoreOS ISOs [#96](https://github.com/openshift/machine-os-images/pull/96)
* [OCPBUGS-85477](https://issues.redhat.com/browse/OCPBUGS-85477): Force rebuild for OCP 4.22 [#88](https://github.com/openshift/machine-os-images/pull/88)
* [Full changelog](https://github.com/openshift/machine-os-images/compare/df9a652cb1572172e404655bb021525be2e3d8ab...e5342c9905a94069e6801737dd6aeddfb74bbac4)
### [metallb-frr](https://github.com/openshift/frr/tree/1277b2387272397d3479d74d2d65112112f985b8)
* [OCPBUGS-86568](https://issues.redhat.com/browse/OCPBUGS-86568): Generate fallback BGP router-id on IPv6-only nodes [#133](https://github.com/openshift/frr/pull/133)
* [Full changelog](https://github.com/openshift/frr/compare/843347fdc9460e0fd064d68a003eae5459cac1fa...1277b2387272397d3479d74d2d65112112f985b8)
### [monitoring-plugin](https://github.com/openshift/monitoring-plugin/tree/8416b67c1bd96dfca3796e208c27c44ffd375a74)
* [OLS-3921](https://issues.redhat.com/browse/OLS-3921): disable button shrink [#1189](https://github.com/openshift/monitoring-plugin/pull/1189)
* [OCPBUGS-98787](https://issues.redhat.com/browse/OCPBUGS-98787): replace outdated react-linkify dependency [#1150](https://github.com/openshift/monitoring-plugin/pull/1150)
* [OCPBUGS-98787](https://issues.redhat.com/browse/OCPBUGS-98787): replace outdated react-linkify dependency [#1145](https://github.com/openshift/monitoring-plugin/pull/1145)
* [OCPBUGS-98432](https://issues.redhat.com/browse/OCPBUGS-98432): fix for CVE-2026-59869 [#1114](https://github.com/openshift/monitoring-plugin/pull/1114)
* [OU-1240](https://issues.redhat.com/browse/OU-1240): Makefile and package.json to enable test-frontend-ci [#1094](https://github.com/openshift/monitoring-plugin/pull/1094)
* [OCPBUGS-99032](https://issues.redhat.com/browse/OCPBUGS-99032): Fix CVE-2026-49978 - bump DOMPurify to >= 3.4.7 [#1085](https://github.com/openshift/monitoring-plugin/pull/1085)
* [OCPBUGS-99234](https://issues.redhat.com/browse/OCPBUGS-99234): graph redirect query parameter [#1070](https://github.com/openshift/monitoring-plugin/pull/1070)
* [OU-651](https://issues.redhat.com/browse/OU-651): Fix AlertRules page to display user defined loki alerts [#1057](https://github.com/openshift/monitoring-plugin/pull/1057)
* Fix for OCPBUGS-89698: CVE-2026-12143 [#1053](https://github.com/openshift/monitoring-plugin/pull/1053)
* Fix for OCPBUGS-91628: CVE-2026-45736 [#1023](https://github.com/openshift/monitoring-plugin/pull/1023)
* NO-JIRA: fix unit test severitySort and incidents [#1036](https://github.com/openshift/monitoring-plugin/pull/1036)
* Fix for OCPBUGS-94005: CVE-2026-13676 [#1028](https://github.com/openshift/monitoring-plugin/pull/1028)
* [OU-1396](https://issues.redhat.com/browse/OU-1396): [release-4.22] fix: use replace to set variables to avoid navigation trap [#1019](https://github.com/openshift/monitoring-plugin/pull/1019)
* [OCPBUGS-87979](https://issues.redhat.com/browse/OCPBUGS-87979): [release-4.22] fast-uri: URI authority bypass due to improper delimiter handling [#989](https://github.com/openshift/monitoring-plugin/pull/989)
* [OCPBUGS-88413](https://issues.redhat.com/browse/OCPBUGS-88413): [release-4.22] Fix CVE-2026-44494: bump axios to ^1.16.0 via overrides [#997](https://github.com/openshift/monitoring-plugin/pull/997)
* [OU-1360](https://issues.redhat.com/browse/OU-1360): reset queries when namespace changes in dev perspective [#934](https://github.com/openshift/monitoring-plugin/pull/934)
* [OU-1366](https://issues.redhat.com/browse/OU-1366): prevent namespace and project desync [#935](https://github.com/openshift/monitoring-plugin/pull/935)
* [Full changelog](https://github.com/openshift/monitoring-plugin/compare/f3f3c199a35f28b5a3cb7e5e123d3f34c25dcdfd...8416b67c1bd96dfca3796e208c27c44ffd375a74)
### [multus-admission-controller](https://github.com/openshift/multus-admission-controller/tree/d4dd42ba9c17b04e0e5003147f4e140ea5e34749)
* [OCPBUGS-85569](https://issues.redhat.com/browse/OCPBUGS-85569): Bump Go version to 1.25.0 for ML-KEM/PQC support [#116](https://github.com/openshift/multus-admission-controller/pull/116)
* [Full changelog](https://github.com/openshift/multus-admission-controller/compare/16ba7ef8026f5b6d0d08b19c707648d82b1ac592...d4dd42ba9c17b04e0e5003147f4e140ea5e34749)
### [multus-cni, multus-cni-microshift](https://github.com/openshift/multus-cni/tree/a87f7a50bdf2fba01fdf234bb878bd5dd16cdaa7)
* [OCPBUGS-120682](https://issues.redhat.com/browse/OCPBUGS-120682): [Release 4.22] Cherry-pick fix for the issue of stripping delegate datastore config on CNI DEL, leaking IPAM addresses [#350](https://github.com/openshift/multus-cni/pull/350)
* [OCPBUGS-114732](https://issues.redhat.com/browse/OCPBUGS-114732): [release-4.22] Revert "Sort DeviceIDs in GetPodResourceMap for deterministic ordering" [#346](https://github.com/openshift/multus-cni/pull/346)
* [Full changelog](https://github.com/openshift/multus-cni/compare/b4ec7d8239ce4bd3ed949bce9816a013377b44c7...a87f7a50bdf2fba01fdf234bb878bd5dd16cdaa7)
### [network-interface-bond-cni](https://github.com/openshift/bond-cni/tree/5ef2d3205f11fba65e3949c0c57897420a83974a)
* [OCPBUGS-97943](https://issues.redhat.com/browse/OCPBUGS-97943): Update OWNERS for release-4.22 [#119](https://github.com/openshift/bond-cni/pull/119)
* [Full changelog](https://github.com/openshift/bond-cni/compare/297eeb4320e07b18d559bc373b665479c760e8c7...5ef2d3205f11fba65e3949c0c57897420a83974a)
### [networking-console-plugin](https://github.com/openshift/networking-console-plugin/tree/a05766f6d5b6f2a4ff5967cf65ed732540465216)
* [OCPBUGS-82108](https://issues.redhat.com/browse/OCPBUGS-82108): Marked strings for i18n in NetworkPolicies list page [#475](https://github.com/openshift/networking-console-plugin/pull/475)
* [OCPBUGS-98788](https://issues.redhat.com/browse/OCPBUGS-98788): Updating linkify-it to 5.0.2 to fix CVE-2026-48801 [#464](https://github.com/openshift/networking-console-plugin/pull/464)
* [OCPBUGS-92205](https://issues.redhat.com/browse/OCPBUGS-92205): Updated doc links based on release [#438](https://github.com/openshift/networking-console-plugin/pull/438)
* [OCPBUGS-92196](https://issues.redhat.com/browse/OCPBUGS-92196): fixed translations of pod column titles [#437](https://github.com/openshift/networking-console-plugin/pull/437)
* [OCPBUGS-88314](https://issues.redhat.com/browse/OCPBUGS-88314): Trim subnet input in UDN creation form [#431](https://github.com/openshift/networking-console-plugin/pull/431)
* [CNV-90049](https://issues.redhat.com/browse/CNV-90049): [UDN] Add condition column to the list page [#432](https://github.com/openshift/networking-console-plugin/pull/432)
* [OCPBUGS-88025](https://issues.redhat.com/browse/OCPBUGS-88025): Fix empty state Create button links [#429](https://github.com/openshift/networking-console-plugin/pull/429)
* And 1 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/networking-console-plugin/compare/d73167a4d7fca871d64d3591aac388cfd2d37bbe...a05766f6d5b6f2a4ff5967cf65ed732540465216)
### [oauth-proxy](https://github.com/openshift/oauth-proxy/tree/367b72380a41025060d2372269d192cffb4167de)
* [OCPBUGS-93565](https://issues.redhat.com/browse/OCPBUGS-93565): update x/crypto to v0.52.0 and x/net to v0.55.0 [#369](https://github.com/openshift/oauth-proxy/pull/369)
* [OCPBUGS-86213](https://issues.redhat.com/browse/OCPBUGS-86213): Updating golang-github-openshift-oauth-proxy-container image to be consistent with ART for 4.22 [#366](https://github.com/openshift/oauth-proxy/pull/366)
* [Full changelog](https://github.com/openshift/oauth-proxy/compare/714292f5478e6c12da6a31710f72bc8fbe6fb925...367b72380a41025060d2372269d192cffb4167de)
### [oauth-server](https://github.com/openshift/oauth-server/tree/42031614956a88806d0503cd619b49975ad61682)
* [OCPBUGS-84381](https://issues.redhat.com/browse/OCPBUGS-84381): Bump github.com/go-jose/go-jose/v3 from v3.0.3 to v3.0.5 [#233](https://github.com/openshift/oauth-server/pull/233)
* [Full changelog](https://github.com/openshift/oauth-server/compare/6c6e96279eb140ef7b4e2028ac874d79fd5bdbc9...42031614956a88806d0503cd619b49975ad61682)
### [oc-mirror](https://github.com/openshift/oc-mirror/tree/739e1384c223aef6cbadab557301741332f96a52)
* [OCPBUGS-92814](https://issues.redhat.com/browse/OCPBUGS-92814): v1/e2e: reduce helm download flakiness [#1455](https://github.com/openshift/oc-mirror/pull/1455)
* [OCPBUGS-90149](https://issues.redhat.com/browse/OCPBUGS-90149): fix(helm): tolerate v-prefix version mismatch in disk-to-mirror [#1448](https://github.com/openshift/oc-mirror/pull/1448)
* [OCPBUGS-105777](https://issues.redhat.com/browse/OCPBUGS-105777): fix for CVE-2026-39829 [#1501](https://github.com/openshift/oc-mirror/pull/1501)
* [OCPBUGS-98716](https://issues.redhat.com/browse/OCPBUGS-98716): Include index image sub-digests in dry run mapping.txt [#1474](https://github.com/openshift/oc-mirror/pull/1474)
* [OCPBUGS-93773](https://issues.redhat.com/browse/OCPBUGS-93773): Make dry-run also generate cluster-resources [#1457](https://github.com/openshift/oc-mirror/pull/1457)
* [OCPBUGS-97946](https://issues.redhat.com/browse/OCPBUGS-97946): skip manifest list signatures [#1469](https://github.com/openshift/oc-mirror/pull/1469)
* [OCPBUGS-88484](https://issues.redhat.com/browse/OCPBUGS-88484): Include tag+digest images in both IDMS and ITMS [#1442](https://github.com/openshift/oc-mirror/pull/1442)
* [OCPBUGS-87806](https://issues.redhat.com/browse/OCPBUGS-87806): fixes race condition when mirroring operator catalogs [#1434](https://github.com/openshift/oc-mirror/pull/1434)
* [OCPBUGS-84389](https://issues.redhat.com/browse/OCPBUGS-84389): Upgrade go-jose to v4.1.4 to fix CVE-2026-34986 [#1419](https://github.com/openshift/oc-mirror/pull/1419)
* [Full changelog](https://github.com/openshift/oc-mirror/compare/ca5eebdcecf9650248f15fe6009b22788ba0c434...739e1384c223aef6cbadab557301741332f96a52)
### [olm-catalogd, olm-operator-controller](https://github.com/openshift/operator-framework-operator-controller/tree/433f3cc944ee4f7995a5d0b444aecb77c3891176)
* [OCPBUGS-102011](https://issues.redhat.com/browse/OCPBUGS-102011): Bump golang.org/x/net to v0.53.0 to address CVE-2026-33814 [#793](https://github.com/openshift/operator-framework-operator-controller/pull/793)
* [OCPBUGS-100305](https://issues.redhat.com/browse/OCPBUGS-100305): Fix cache path to avoid /var/cache/dnf conflict [#783](https://github.com/openshift/operator-framework-operator-controller/pull/783)
* [OCPBUGS-99298](https://issues.redhat.com/browse/OCPBUGS-99298): increase catalog HTTP client timeout from 10s to 5m [#768](https://github.com/openshift/operator-framework-operator-controller/pull/768)
* [OCPBUGS-94187](https://issues.redhat.com/browse/OCPBUGS-94187): enable OLMv1 topology-based deployment scaling e2e test [#761](https://github.com/openshift/operator-framework-operator-controller/pull/761)
* [OCPBUGS-94187](https://issues.redhat.com/browse/OCPBUGS-94187): Backport HA topology deployment scaling to release-4.22 [#758](https://github.com/openshift/operator-framework-operator-controller/pull/758)
* [Full changelog](https://github.com/openshift/operator-framework-operator-controller/compare/26b848969eabd4e1899439f40a4346552f08ff38...433f3cc944ee4f7995a5d0b444aecb77c3891176)
### [openshift-apiserver](https://github.com/openshift/openshift-apiserver/tree/7fa546d41a73b519e3af0e6428471c4aaf5c71e5)
* [OCPBUGS-87022](https://issues.redhat.com/browse/OCPBUGS-87022): fix concurrent map race in project authorization cache [#653](https://github.com/openshift/openshift-apiserver/pull/653)
* [OCPBUGS-84454](https://issues.redhat.com/browse/OCPBUGS-84454): Address CVE-2026-35469 [#651](https://github.com/openshift/openshift-apiserver/pull/651)
* [Full changelog](https://github.com/openshift/openshift-apiserver/compare/fbea5220c4fe13c20107d6c4631f4e53007ca761...7fa546d41a73b519e3af0e6428471c4aaf5c71e5)
### [openstack-machine-api-provider](https://github.com/openshift/machine-api-provider-openstack/tree/74bd2dd2e7bc5b93e78b6b204012b6b7d981a4ba)
* [OCPBUGS-97826](https://issues.redhat.com/browse/OCPBUGS-97826): Revendor CAPO [#175](https://github.com/openshift/machine-api-provider-openstack/pull/175)
* [Full changelog](https://github.com/openshift/machine-api-provider-openstack/compare/8a8c354b99ce83e3c05a91358aadec09944c2fce...74bd2dd2e7bc5b93e78b6b204012b6b7d981a4ba)
### [operator-framework-tools, operator-lifecycle-manager, operator-registry](https://github.com/openshift/operator-framework-olm/tree/5359e60525288af86885e14d89e3210878f87274)
* [OCPBUGS-101995](https://issues.redhat.com/browse/OCPBUGS-101995): Bump golang.org/x/net to v0.53.0 to address CVE-2026-33814 [#1362](https://github.com/openshift/operator-framework-olm/pull/1362)
* [OCPBUGS-95441](https://issues.redhat.com/browse/OCPBUGS-95441), [OCPBUGS-95458](https://issues.redhat.com/browse/OCPBUGS-95458): bumping containerd to v1.7.33 [#1353](https://github.com/openshift/operator-framework-olm/pull/1353)
* [OCPBUGS-84411](https://issues.redhat.com/browse/OCPBUGS-84411), [OCPBUGS-84412](https://issues.redhat.com/browse/OCPBUGS-84412): Update github.com/go-jose/go-jose/v4 to v4.1.4 [release-4.22] [#1292](https://github.com/openshift/operator-framework-olm/pull/1292)
* [Full changelog](https://github.com/openshift/operator-framework-olm/compare/e627823c743797da91b4ae8a318d2420a511b752...5359e60525288af86885e14d89e3210878f87274)
### [ovn-kubernetes, ovn-kubernetes-microshift](https://github.com/openshift/ovn-kubernetes/tree/e2082ef4a1aaad8fa5acc7b24880394b60a4e8ae)
* [OCPBUGS-112496](https://issues.redhat.com/browse/OCPBUGS-112496): NO-JIRA: Branch Sync main to release-4.22 [08-18-2026] [#3406](https://github.com/openshift/ovn-kubernetes/pull/3406)
* [OCPBUGS-99043](https://issues.redhat.com/browse/OCPBUGS-99043): Branch Sync main to release-4.22 [08-13-2026] [#3394](https://github.com/openshift/ovn-kubernetes/pull/3394)
* [OCPBUGS-105515](https://issues.redhat.com/browse/OCPBUGS-105515), [OCPBUGS-105604](https://issues.redhat.com/browse/OCPBUGS-105604): Branch Sync main to release-4.22 [08-10-2026] [#3373](https://github.com/openshift/ovn-kubernetes/pull/3373)
* [OCPBUGS-95560](https://issues.redhat.com/browse/OCPBUGS-95560): Branch Sync main to release-4.22 [08-04-2026] [#3358](https://github.com/openshift/ovn-kubernetes/pull/3358)
* [OCPBUGS-100119](https://issues.redhat.com/browse/OCPBUGS-100119), [OCPBUGS-95064](https://issues.redhat.com/browse/OCPBUGS-95064): Branch Sync main to release-4.22 [07-28-2026] [#3333](https://github.com/openshift/ovn-kubernetes/pull/3333)
* [OCPBUGS-99043](https://issues.redhat.com/browse/OCPBUGS-99043): Branch Sync main to release-4.22 [07-16-2026] [#3304](https://github.com/openshift/ovn-kubernetes/pull/3304)
* [OCPBUGS-88733](https://issues.redhat.com/browse/OCPBUGS-88733), [OCPBUGS-88734](https://issues.redhat.com/browse/OCPBUGS-88734): Branch Sync main to release-4.22 [06-16-2026] [#3252](https://github.com/openshift/ovn-kubernetes/pull/3252)
* [OCPBUGS-88718](https://issues.redhat.com/browse/OCPBUGS-88718): Branch Sync main to release-4.22 [06-10-2026] [#3244](https://github.com/openshift/ovn-kubernetes/pull/3244)
* [OCPBUGS-87214](https://issues.redhat.com/browse/OCPBUGS-87214): Branch Sync main to release-4.22 [06-05-2026] [#3232](https://github.com/openshift/ovn-kubernetes/pull/3232)
* [OCPBUGS-84384](https://issues.redhat.com/browse/OCPBUGS-84384): CORENET-6537: OTE: Add external container support to infra provider [#3147](https://github.com/openshift/ovn-kubernetes/pull/3147)
* [Full changelog](https://github.com/openshift/ovn-kubernetes/compare/14b5022bad5b21334e3ad9d500763474016b2a9c...e2082ef4a1aaad8fa5acc7b24880394b60a4e8ae)
### [powervs-block-csi-driver](https://github.com/openshift/ibm-powervs-block-csi-driver/tree/1173437f341d58a340d83cb87449af28228a1040)
* [OCPBUGS-101580](https://issues.redhat.com/browse/OCPBUGS-101580), [OCPBUGS-102012](https://issues.redhat.com/browse/OCPBUGS-102012), [OCPBUGS-93554](https://issues.redhat.com/browse/OCPBUGS-93554), [OCPBUGS-95566](https://issues.redhat.com/browse/OCPBUGS-95566), [OCPBUGS-96671](https://issues.redhat.com/browse/OCPBUGS-96671), [OCPBUGS-98019](https://issues.redhat.com/browse/OCPBUGS-98019): Fix CVE-2026-39828, 46597, 39835, 27136, 2502 and 33814 [#142](https://github.com/openshift/ibm-powervs-block-csi-driver/pull/142)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver/compare/02959a8d7096501e240d1d9f65da90b87bac45b9...1173437f341d58a340d83cb87449af28228a1040)
### [powervs-block-csi-driver-operator](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/tree/6e859b18170daf013897d09ce3ef4f915ada6757)
* [OCPBUGS-101993](https://issues.redhat.com/browse/OCPBUGS-101993): Mitigate CVE-2026-33814 by bumping golang.org/x/net to v0.57.0 [#121](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/121)
* [OCPBUGS-107713](https://issues.redhat.com/browse/OCPBUGS-107713): Mitigate CVE-2026-41178 by bumping go.opentelemetry.io/otel/sdk to v1.44.0 [#120](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/pull/120)
* [Full changelog](https://github.com/openshift/ibm-powervs-block-csi-driver-operator/compare/277478211cfc7302e9c09b41a0935fbba678614a...6e859b18170daf013897d09ce3ef4f915ada6757)
### [prometheus](https://github.com/openshift/prometheus/tree/868b9ce717fdde35c0769c6f22f35f3787ff1274)
* [OCPBUGS-93732](https://issues.redhat.com/browse/OCPBUGS-93732): fix for CVE-2026-42151 [#355](https://github.com/openshift/prometheus/pull/355)
* [OCPBUGS-93919](https://issues.redhat.com/browse/OCPBUGS-93919): fix(tsdb): temporarily ignore Direct IO enablement errors on unsupported filesystems [#339](https://github.com/openshift/prometheus/pull/339)
* [OCPBUGS-92818](https://issues.redhat.com/browse/OCPBUGS-92818): bump x/crypto, x/net, and otel dependencies to fix CVEs [#337](https://github.com/openshift/prometheus/pull/337)
* [OCPBUGS-88666](https://issues.redhat.com/browse/OCPBUGS-88666): remote: validate snappy decoded length before allocation in read endpoint [#330](https://github.com/openshift/prometheus/pull/330)
* [OCPBUGS-86248](https://issues.redhat.com/browse/OCPBUGS-86248): fix: TLS client cert rotation when no CA is configured [#313](https://github.com/openshift/prometheus/pull/313)
* [OCPBUGS-84010](https://issues.redhat.com/browse/OCPBUGS-84010): bump google.golang.org/grpc to v1.79.3 [release-4.22] [#310](https://github.com/openshift/prometheus/pull/310)
* [Full changelog](https://github.com/openshift/prometheus/compare/e1e355916c789607fe98c8832920e2218de4bad5...868b9ce717fdde35c0769c6f22f35f3787ff1274)
### [prometheus-alertmanager](https://github.com/openshift/prometheus-alertmanager/tree/f090d1413836ce12c0a2f70f862de5787dfe59d0)
* [OCPBUGS-98185](https://issues.redhat.com/browse/OCPBUGS-98185): build(deps): bump github.com/hashicorp/memberlist from 0.5.4 to 0.6.0 [#157](https://github.com/openshift/prometheus-alertmanager/pull/157)
* [OCPBUGS-99442](https://issues.redhat.com/browse/OCPBUGS-99442): embed tzdata in the alertmanager binary [#141](https://github.com/openshift/prometheus-alertmanager/pull/141)
* [Full changelog](https://github.com/openshift/prometheus-alertmanager/compare/02dc3e9e55cf7fa0279e22762d6ace19bbc65fde...f090d1413836ce12c0a2f70f862de5787dfe59d0)
### [route-controller-manager](https://github.com/openshift/route-controller-manager/tree/55f77ca4cf0328b7c4fd7736bce79ebe171a9b6b)
* [OCPBUGS-86184](https://issues.redhat.com/browse/OCPBUGS-86184): OCPBUGS-83892: Update grpc-go and x/net [#90](https://github.com/openshift/route-controller-manager/pull/90)
* [Full changelog](https://github.com/openshift/route-controller-manager/compare/624742d93f3a7885cf7f70985f1e23ff60da580d...55f77ca4cf0328b7c4fd7736bce79ebe171a9b6b)
### [stream-coreos, stream-coreos-extensions](https://github.com/openshift/os/tree/cf63d7a58a420b35b7f5e42ea0e7deffec56cf91)
* [OCPBUGS-105444](https://issues.redhat.com/browse/OCPBUGS-105444): NetworkManager-ovs has moved to RHCOS [#1956](https://github.com/openshift/os/pull/1956)
* NO-JIRA: Containerfile: restore meta.json as last layer in image [#1950](https://github.com/openshift/os/pull/1950)
* And 7 elided commits (e.g. from squash or rebase merges)
* [Full changelog](https://github.com/openshift/os/compare/398ab69c2acd04c17c7dfc41d1ef7d4dc3edf276...cf63d7a58a420b35b7f5e42ea0e7deffec56cf91)
### [telemeter](https://github.com/openshift/telemeter/tree/c2ffb0a7035e504a4ddc7292e4d12b7490eab0d4)
* [OCPBUGS-84021](https://issues.redhat.com/browse/OCPBUGS-84021): update google.golang.org/grpc [#605](https://github.com/openshift/telemeter/pull/605)
* [Full changelog](https://github.com/openshift/telemeter/compare/131e6761cbd50054e2588bee58ebf1997f3cc039...c2ffb0a7035e504a4ddc7292e4d12b7490eab0d4)
### [tests](https://github.com/openshift/origin/tree/6c62ada4b9b23dfc6a0431afd40db8cec506e2ca)
* [OCPBUGS-115199](https://issues.redhat.com/browse/OCPBUGS-115199): fix: skip MCPs with non-ready nodes during MCN property validation [#31525](https://github.com/openshift/origin/pull/31525)
* [OCPBUGS-114438](https://issues.redhat.com/browse/OCPBUGS-114438): Fix probe termination test to use pod status instead of kubelet event text [#31568](https://github.com/openshift/origin/pull/31568)
* [OCPBUGS-115161](https://issues.redhat.com/browse/OCPBUGS-115161): Raise status polling timeout and write bound [#31582](https://github.com/openshift/origin/pull/31582)
* [OCPBUGS-115191](https://issues.redhat.com/browse/OCPBUGS-115191): fix: adjusting DaemonSet test to dynamically compute expected pod count [#31522](https://github.com/openshift/origin/pull/31522)
* [AGENT-1583](https://issues.redhat.com/browse/AGENT-1583): post-feature promotion (NoRegistryClusterInstall) openshift/api dependencies bump [#31565](https://github.com/openshift/origin/pull/31565)
* [OCPBUGS-111831](https://issues.redhat.com/browse/OCPBUGS-111831): tolerate one NotReady CP node in EnsureNodesReady for degraded TNF [#31527](https://github.com/openshift/origin/pull/31527)
* [OCPBUGS-100438](https://issues.redhat.com/browse/OCPBUGS-100438): retry GetVotingMemberNames on transient etcd client fails [#31506](https://github.com/openshift/origin/pull/31506)
* [OCPBUGS-88711](https://issues.redhat.com/browse/OCPBUGS-88711): Backport node_e2e test migrations [#31306](https://github.com/openshift/origin/pull/31306)
* [AGENT-1549](https://issues.redhat.com/browse/AGENT-1549): Backport NoRegistryClusterInstall feature to release-4.22 [#31406](https://github.com/openshift/origin/pull/31406)
* [SPLAT-2802](https://issues.redhat.com/browse/SPLAT-2802): Added VVCDO OTE binary to extensionBinary list [#31321](https://github.com/openshift/origin/pull/31321)
* [SPLAT-2794](https://issues.redhat.com/browse/SPLAT-2794): Added 3CMO OTE binary to extensionBinary list [#31303](https://github.com/openshift/origin/pull/31303)
* [OCPBUGS-90522](https://issues.redhat.com/browse/OCPBUGS-90522): Use AdminPolicyBasedExternalRoute CR for external gateway test [#31317](https://github.com/openshift/origin/pull/31317)
* [OCPBUGS-87838](https://issues.redhat.com/browse/OCPBUGS-87838): support Parents field on origin test suites [#31270](https://github.com/openshift/origin/pull/31270)
* [OCPBUGS-92656](https://issues.redhat.com/browse/OCPBUGS-92656): bump openshift-tests-extension to fix klog stdout parsing on 4.22 [#31349](https://github.com/openshift/origin/pull/31349)
* [OCPBUGS-92048](https://issues.redhat.com/browse/OCPBUGS-92048): fix PDB AlwaysAllow test failure on IPv6-primary dualstack clusters [#31337](https://github.com/openshift/origin/pull/31337)
* [OCPBUGS-92047](https://issues.redhat.com/browse/OCPBUGS-92047): Fix AWS DualStack CI jobs consistently encounter 2 EgressFirewall Test Failures [#31336](https://github.com/openshift/origin/pull/31336)
* [OCPBUGS-85708](https://issues.redhat.com/browse/OCPBUGS-85708): Raise OpenStack operator watch limits [#31183](https://github.com/openshift/origin/pull/31183)
* [OCPBUGS-85655](https://issues.redhat.com/browse/OCPBUGS-85655): Validate no WAL corruption when both nodes shutdown gracefully [#31174](https://github.com/openshift/origin/pull/31174)
* [OCPBUGS-85515](https://issues.redhat.com/browse/OCPBUGS-85515): Verify dynamic revision bump for etcd during kernel crash [#31166](https://github.com/openshift/origin/pull/31166)
* [OCPBUGS-85339](https://issues.redhat.com/browse/OCPBUGS-85339): Add e2e tests for KubeletEnsureSecretPulledImages feature gate [#31148](https://github.com/openshift/origin/pull/31148)
* [OCPBUGS-85089](https://issues.redhat.com/browse/OCPBUGS-85089): Allow OVN-Kubernetes CIDROverlap pathological events [#31141](https://github.com/openshift/origin/pull/31141)
* [Full changelog](https://github.com/openshift/origin/compare/4dba979a14fc3a7523926d129683a1ad6c853575...6c62ada4b9b23dfc6a0431afd40db8cec506e2ca)
### [thanos](https://github.com/openshift/thanos/tree/98b433450fed7685ec04af89b4de20afbaf856ae)
* fix for OCPBUGS-107709: CVE-2026-41178 [#202](https://github.com/openshift/thanos/pull/202)
* [OCPBUGS-105471](https://issues.redhat.com/browse/OCPBUGS-105471): UPSTREAM: <carry>: bump google.golang.org/grpc to v1.82.1 (GHSA-hrxh-6v49-42gf) [#199](https://github.com/openshift/thanos/pull/199)
* [COO-2034](https://issues.redhat.com/browse/COO-2034), [OCPBUGS-105219](https://issues.redhat.com/browse/OCPBUGS-105219), [OCPBUGS-105223](https://issues.redhat.com/browse/OCPBUGS-105223), [OCPBUGS-105224](https://issues.redhat.com/browse/OCPBUGS-105224): [release-4.22] vendor: bump vulnerable Go dependencies for GovCloud CVE remediation [#197](https://github.com/openshift/thanos/pull/197)
* [OCPBUGS-96898](https://issues.redhat.com/browse/OCPBUGS-96898): Address CVE-2026-39882 [#192](https://github.com/openshift/thanos/pull/192)
* [OCPBUGS-92813](https://issues.redhat.com/browse/OCPBUGS-92813): Fix CVE-2026-39883 [#191](https://github.com/openshift/thanos/pull/191)
* [Full changelog](https://github.com/openshift/thanos/compare/5d9d0f387e5cc651470f27352b28674103bfdd77...98b433450fed7685ec04af89b4de20afbaf856ae)
### [vsphere-cluster-api-controllers](https://github.com/openshift/cluster-api-provider-vsphere/tree/ac542b5afbd9a3897cda34e7ea1852b61c945e36)
* [OCPBUGS-84028](https://issues.redhat.com/browse/OCPBUGS-84028): Merge https://github.com/kubernetes-sigs/cluster-api-provider-vsphere:v1.15.3 (e917f8e) into release-4.22 [#108](https://github.com/openshift/cluster-api-provider-vsphere/pull/108)
* [Full changelog](https://github.com/openshift/cluster-api-provider-vsphere/compare/f12e50512efa829a2df97c897862c3f45c201300...ac542b5afbd9a3897cda34e7ea1852b61c945e36)
### [vsphere-csi-driver, vsphere-csi-driver-syncer](https://github.com/openshift/vmware-vsphere-csi-driver/tree/19c75111d7d7c5d3ce23ea7154e36e03f49b6c1e)
* UPSTREAM: 187: OCPBUGS-96686: Bump golang.org/x/net to v0.50.0-sec.4 [#195](https://github.com/openshift/vmware-vsphere-csi-driver/pull/195)
* [OCPBUGS-95573](https://issues.redhat.com/browse/OCPBUGS-95573): Bump golang.org/x/crypto/ssh to v0.48.0-sec.1 [#189](https://github.com/openshift/vmware-vsphere-csi-driver/pull/189)
* [OCPBUGS-92190](https://issues.redhat.com/browse/OCPBUGS-92190): Rebase 3.6.2 on 422 [#188](https://github.com/openshift/vmware-vsphere-csi-driver/pull/188)
* [OCPBUGS-83636](https://issues.redhat.com/browse/OCPBUGS-83636): Bump spdystream to v0.5.1 [#180](https://github.com/openshift/vmware-vsphere-csi-driver/pull/180)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver/compare/cf21e1211225e3cf6baa27bdb12ae86c5c13db39...19c75111d7d7c5d3ce23ea7154e36e03f49b6c1e)
### [vsphere-csi-driver-operator](https://github.com/openshift/vmware-vsphere-csi-driver-operator/tree/9be965742961e7a84b0af8ff5ea17a852e015c98)
* [SPLAT-2802](https://issues.redhat.com/browse/SPLAT-2802): Port vSphere hybrid OTE to release-4.22 [#349](https://github.com/openshift/vmware-vsphere-csi-driver-operator/pull/349)
* [Full changelog](https://github.com/openshift/vmware-vsphere-csi-driver-operator/compare/d3668c9a9510f189604343e817cc79ab23367f40...9be965742961e7a84b0af8ff5ea17a852e015c98)
### [vsphere-problem-detector](https://github.com/openshift/vsphere-problem-detector/tree/885fd8b28b91323570ed6cbaf6aa171845d4c83c)
* [OCPBUGS-102050](https://issues.redhat.com/browse/OCPBUGS-102050): Bump golang.org/x/net to 0.53.0 [#229](https://github.com/openshift/vsphere-problem-detector/pull/229)
* [OCPBUGS-86866](https://issues.redhat.com/browse/OCPBUGS-86866): Fixed compute cluster permission logic for single fd with read-only custom resourcepool [#221](https://github.com/openshift/vsphere-problem-detector/pull/221)
* [Full changelog](https://github.com/openshift/vsphere-problem-detector/compare/842aed3df97005839ef5deaf560abbe6486b9daf...885fd8b28b91323570ed6cbaf6aa171845d4c83c)